# DFEI Field Artifact Package — Broken Loop Diagnostic

## Public Boundary

**This diagnostic does not prove motive. It tests control.**

## User Path

1. **IDENTIFY** — Start with the Quick Diagnostic. Name the workflow, consequence, and risk tier.
2. **TEST** — If any result is **No** or **Unclear**, run the Full Worksheet and gather evidence.
3. **DECIDE** — Complete the Diagnostic Finding Sheet. Assign actions, owners, and review date.

## Status Legend

| Status | Meaning |
|---|---|
| Present / Yes | Function is assigned, reachable, evidenced, and usable before or after consequence. |
| Weak | Function exists but is delayed, narrow, informal, overloaded, or hard to use. |
| Missing / No | No practical actor, authority, path, or repair function is available. |
| Unclear | Evidence is insufficient. Treat as risk until verified. |

---

# Quick Diagnostic Card

**Core rule:** Do not ask whether the human is in the loop. Ask where the verbs went.

## Workflow Metadata

- Workflow name:
- Workflow owner:
- System / tool involved:
- Risk tier: Low / Medium / High
- Consequence type: Draft / Recommendation / Routing / Record change / Communication / Denial / Enforcement / Financial / Rights-affecting / Other

## Control Verb Table

| Control Verb | Core Question | Located? | Evidence / Note |
|---|---|---|---|
| Stop | Who can pause or halt the workflow before consequence? | Yes / No / Unclear |  |
| Reverse | Who can undo the outcome after action? | Yes / No / Unclear |  |
| Amend | Who can correct records, classifications, or outputs? | Yes / No / Unclear |  |
| Compensate | Who can remedy material or procedural harm where applicable? | Yes / No / Unclear |  |
| Refuse | Who can reject the system recommendation or action? | Yes / No / Unclear |  |
| Escalate | Who can move uncertainty to someone with authority? | Yes / No / Unclear |  |
| Verify | Who can check the result against independent evidence? | Yes / No / Unclear |  |
| Own | Who carries explanation, repair, and recurrence prevention? | Yes / No / Unclear |  |


**Compensate clarification:** compensate means remedying material, procedural, financial, access, reputational, or rights-affecting harm where applicable. It is not limited to money.

## Quick Result

- Mostly Yes: control functions are visible.
- Mixed / Unclear: run the full worksheet.
- Mostly No: the loop is likely broken; do not rely on human oversight or automation efficiency as sufficient justification.

---

# Full Worksheet

## 1. Workflow Identification

- Workflow name:
- Workflow owner:
- System / tool involved:
- Human role involved:
- Automated role involved:
- Affected party:
- Date reviewed:
- Risk tier: Low / Medium / High
- Consequence type: Draft / Recommendation / Routing / Record change / Communication / Denial / Enforcement / Financial / Rights-affecting / Other

## 2. Control Verb Location Table

| Verb | What it means | Who holds it? | Authority / Evidence | Status |
|---|---|---|---|---|
| Stop | Pause or halt action before consequence |  |  | Present / Weak / Missing / Unclear |
| Reverse | Undo the action or outcome |  |  | Present / Weak / Missing / Unclear |
| Amend | Correct a record, classification, output, or decision |  |  | Present / Weak / Missing / Unclear |
| Compensate | Remedy material, procedural, financial, access, reputational, or rights-affecting harm where applicable |  |  | Present / Weak / Missing / Unclear |
| Refuse | Reject, narrow, or block the system recommendation/action |  |  | Present / Weak / Missing / Unclear |
| Escalate | Move uncertainty or exception to authority |  |  | Present / Weak / Missing / Unclear |
| Verify | Check result against independent criteria or evidence |  |  | Present / Weak / Missing / Unclear |
| Own | Carry explanation, repair, closure, and recurrence prevention |  |  | Present / Weak / Missing / Unclear |


**Compensate clarification:** compensate means remedying material, procedural, financial, access, reputational, or rights-affecting harm where applicable. It is not limited to money.

## 3A. Inclusion Without Control

Complete this section if a human remains in the workflow.

- What does the human actually see?
- What does the human not see?
- Review happens before consequence? Yes / No / Unclear
- Human can refuse? Yes / No / Unclear
- Human can reverse or amend? Yes / No / Unclear
- Human can escalate uncertainty? Yes / No / Unclear
- Careful refusal is rewarded, not punished? Yes / No / Unclear
- Human responsible for system they cannot control? Yes / No / Unclear
- Break mode result: No clear break / Possible / Likely / Confirmed
- Evidence prompting this result:

## 3B. Removal Without Rebuilt Contestability

Complete this section if a human checkpoint has been removed, reduced, bypassed, or moved downstream.

- What human function was removed?
- Why was it removed?
- What improved after removal?
- What new risk appeared?
- Where is refusal rebuilt?
- Where is verification rebuilt?
- Where is appeal rebuilt?
- Where is rollback rebuilt?
- Where is repair ownership assigned?
- Affected party can challenge outcome? Yes / No / Unclear
- Break mode result: No clear break / Possible / Likely / Confirmed

## 4. Safe-to-Act Check

| Gate | Question | Status | Evidence Prompt |
|---|---|---|---|
| Action class | What kind of action can the system take? | Yes / No / Unclear |  |
| Authority boundary | What is the system allowed to do? | Yes / No / Unclear |  |
| Prohibited actions | What is the system forbidden to do? | Yes / No / Unclear |  |
| Blast radius | Who or what can be affected? | Yes / No / Unclear |  |
| Logging | Is action logged in a useful way? | Yes / No / Unclear |  |
| Validation | Is there an independent check? | Yes / No / Unclear |  |
| Escalation | What happens under uncertainty? | Yes / No / Unclear |  |
| Rollback | Can the action be undone? | Yes / No / Unclear |  |
| Contestability | Can affected parties challenge outcomes? | Yes / No / Unclear |  |
| Owner | Who owns consequence and recurrence prevention? | Yes / No / Unclear |  |


Safe-to-Act Result: Safe within bounds / Safe with review-limits / Not safe yet / Action class unclear

## 5. Safe-to-Repair Check

| Repair Function | Question | Status | Evidence Prompt |
|---|---|---|---|
| Explain | Can the organization explain what happened? | Yes / No / Unclear |  |
| Reverse | Can it undo the outcome? | Yes / No / Unclear |  |
| Amend | Can it correct records or classifications? | Yes / No / Unclear |  |
| Compensate | Can it remedy harm where applicable? | Yes / No / Unclear |  |
| Restore access | Can it restore service, status, eligibility, or opportunity? | Yes / No / Unclear |  |
| Notify | Can it notify affected parties clearly? | Yes / No / Unclear |  |
| Escalate | Can it move unresolved cases to authority? | Yes / No / Unclear |  |
| Prevent recurrence | Can it change the system to prevent repeat failure? | Yes / No / Unclear |  |
| Own closure | Is there a named owner for resolution? | Yes / No / Unclear |  |


Safe-to-Repair Result: Capacity matches action / Capacity weak / Capacity missing / Acts beyond repair capacity

**Field rule:** No agent should act beyond the institution's capacity to repair.

## 6. Affected-Party Check

| Contestability Function | Question | Status | Evidence Prompt |
|---|---|---|---|
| Notice | Does the affected party know automation shaped the outcome? | Yes / No / Unclear |  |
| Explanation | Can they understand the reason? | Yes / No / Unclear |  |
| Evidence | Can they see or request relevant evidence? | Yes / No / Unclear |  |
| Challenge | Can they contest the outcome? | Yes / No / Unclear |  |
| Authority | Can they reach someone who can change the result? | Yes / No / Unclear |  |
| Suspension | Can harm pause during review where appropriate? | Yes / No / Unclear |  |
| Reversal | Can the outcome be undone? | Yes / No / Unclear |  |
| Amendment | Can the record be corrected? | Yes / No / Unclear |  |
| Remedy | Can harm be remedied where applicable? | Yes / No / Unclear |  |
| Closure | Does the affected party receive resolution? | Yes / No / Unclear |  |


Affected-Party Result: Functional / Weak / Mostly symbolic / No meaningful contestability

## 7. Diagnostic Result Labels

- Green - Control Functions Located
- Yellow - Control Functions Weak or Unclear
- Orange - Broken Loop Risk
- Red - Broken Loop Confirmed

Final classification rationale:

## 8. Interpretation Notes / Repairs

- If stop is missing: create pause, kill-switch, or pre-action gate.
- If reverse is missing: define rollback before deployment.
- If amend is missing: assign correction authority and evidence requirements.
- If compensate is missing: define remedy path for material or rights-affecting consequences.
- If refuse is missing: give reviewers real rejection authority and protect its use.
- If escalate is missing: define exception thresholds and authority path.
- If verify is missing: add independent checks, tests, source access, or sampling.
- If own is missing: assign named ownership for explanation, repair, closure, and recurrence prevention.

## 9. Next Actions

- Immediate halt / pause needed:
- Verbs to assign:
- Evidence to gather:
- Owner to name:
- Review date:

---

# Diagnostic Finding Sheet

## Finding Metadata

- Workflow name:
- Workflow owner:
- System / tool involved:
- Human role involved:
- Automated role involved:
- Affected party:
- Date reviewed:
- Risk tier:
- Consequence type:

## Classification

- Green - Control Functions Located
- Yellow - Control Functions Weak or Unclear
- Orange - Broken Loop Risk
- Red - Broken Loop Confirmed

## Evidence Summary

- Evidence reviewed:
- Evidence missing / unclear:

## Broken Loop Finding

- Break mode found: Inclusion without control / Removal without rebuilt contestability / Both / No clear break
- Primary missing or weak verbs:
- Finding rationale:

## Required Action

- Immediate halt / pause needed:
- Owner named:
- Review date:
- Repairs required:
- Evidence to gather before action resumes:

---

# Fillable PDF Implementation Notes

- Use the HTML/PDF layout as the visual master, then add AcroForm fields on top using stable field names.
- Keep visible labels as static text. Add fields only in the write areas, checkbox squares, and result markers.
- Use grouped radio buttons for mutually exclusive statuses: Yes / No / Unclear; Present / Weak / Missing / Unclear; result labels.
- Use multiline text fields for evidence prompts, rationale, interpretation, and next action fields.
- Use consistent field-name prefixes: `quick_`, `workflow_`, `verb_`, `inclusion_`, `removal_`, `safe_act_`, `safe_repair_`, `affected_party_`, `finding_`, `action_`.
- Do not flatten the fillable master. Export a flattened public sample separately if needed.
- Test in Adobe Acrobat and a browser PDF viewer. Acrobat should be considered authoritative for form behavior.
- Preserve the public boundary line exactly: `This diagnostic does not prove motive. It tests control.`
