SUMMARY: A decision receipt gives an affected participant a durable, structured record of a consequential outcome, its basis, its recipients, and the route to challenge or correction. It turns an opaque status into a portable verification object.
Start with one high-consequence workflow and synthetic cases. Assign an accountable service owner, evidence custodian, privacy reviewer, and operator with authority to correct the source state.
1. Issue a Stable Reference
Create a unique case identifier at intake and preserve it across retries, transfers, vendors, appeals, account changes, and exports. Include issuance time and schema version.
2. Name the Event and Consequence
State what occurred, the current institutional state, when it became effective, what action followed, and which party or system has authority over that state.
3. Preserve the Material Inputs
List the fields and evidence that materially affected the result. Include source, collection time, freshness, confidence, conflicts, and whether the participant can dispute each item.
4. Identify the Rule and Authority
Record policy, rule, or model version; threshold; responsible organization; automated and human actions; and any exception that changed the ordinary path.
5. Expand the Reason Chain
Pair every reason code with plain language, event order, supporting evidence, and the specific condition that would alter the outcome. Do not make the participant infer causality from a category label.
6. List Recipients and Effects
Name each system or organization that received the decision, its delivery state, and the action it may take. Preserve acknowledgment identifiers for later correction.
7. Expose Uncertainty and Withholding
Show unresolved conflicts, missing evidence, confidence limits, and narrowly withheld categories. Record the basis, reviewer, expiration, and independent challenge route for every redaction.
8. Attach a Working Challenge Path
Provide the submission channel, accepted evidence, accountable owner, review deadline, temporary-relief policy, escalation route, and available remedies. Keep every response attached to the original reference.
9. Record Correction Completion
Append the corrected state, reason, time, authority, and recipient acknowledgments. Run a distributed correction test to confirm stale copies no longer drive action.
10. Make the Receipt Portable
Offer a human-readable view and signed machine-readable export. Include integrity evidence, field definitions, retention date, and a verification endpoint without exposing unrelated personal data.
Anchor the receipt in the participant status ledger so it reflects durable state history rather than a one-time snapshot.
Operator rule: every consequential decision should leave the affected participant with a record that can be inspected, challenged, and verified after correction.
Continue the discussion in the Clandestinia forum.
Follow the Digital Systems Accountability guide to connect evidence, explanations, challenge routes, and the work of correction.