L4.01.2automation level assigns accountabilitydesignresearch

The level determines who is accountable

Aliases: LOA and responsibility · who is accountable at this level · supervisory accountability

What it is

Every mark on the ruler allocates “whose fault if it goes wrong.” At an advisory level the person chooses and the person carries it; at an execution level the machine has already changed the world, yet the person’s employee number is still often on the form. Automation level assigns accountability: the division of labour is the allocation of blame, not a clause added afterwards.

Products write the level into the feature name and the duty into the terms of use. When those two documents disagree, the person who signed takes the hit.

Why it happens

Supervisory control turns the operator into a manager. A manager’s duty should follow the authority to manage: stop, change, veto — or there is nothing to carry. As automation rises, that authority shrinks — fewer options, shorter windows, harder vetoes — while the duty language rarely steps down with it. That is the irony Bainbridge named: people are left the residual tasks the machine cannot do, and are still asked to own the whole chain.

Legal copy likes “finally confirmed by the user.” If the confirm sits at an advisory level, the person is a difference-maker; if it sits on a receipt after execution, the person is a witness. Leave the level unmarked, and allocation slides toward whatever is convenient for the organisation.

Studying it

Tell the same incident two ways — was the system advising or had it already acted — and ask different roles (operator, supervisor, designer) for a percentage split of responsibility. Independent variables: actual authority (could they have stopped it), the level the UI claimed, the story told afterwards. Dependent variables: allocation of blame, judgement of “who should stop it next time,” willingness to keep using the system.

Duty-allocation interviews from aviation accident investigation are a ready paradigm. Do not only ask “who should be responsible”; ask “who had the authority to stop it then.” The two answers often split.

Where it stops holding

Fully manual work has no mismatch: duty and person line up. Fully autonomous systems that declare the machine carries the duty (some industrial safety loops) are also outside this entry. The grey zone is an agent that looks advisory while its permissions are executive. Whether users know which level they are on is a separate question; this entry only treats the mapping from level to duty.

Applying it

  • For each level write three things: who proposes, who releases, whose name is on a failure. Operators must be able to read all three on the spot, not only in an appendix to the terms.
  • When authority shrinks, shrink the duty language with it. A level that cannot stop should not still say “confirmed by you.”
  • Check: stage a fault at the current level and ask the operator and counsel separately “whose is this one.” If the answers disagree, change the level label or the permissions until they match.

Related

  • Same group: L4.01.1 From suggestion to full autonomy is a continuum · L4.01.3 The level must be adjustable by the user
  • Nearby: L4.15 Accountability and Traceability · L4.04 Takeover and Handoff Design · L1.09 Intervention Points in the Human Loop
  • Search terms: automation accountability · supervisory control responsibility · levels of automation

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/L4.01.2