Original Governance Framework

TAHA Framework

A governance architecture for keeping governed context, legitimate Human Authority, execution and accountable outcomes connected across AI-enabled work.

Traceable AI. Human Authority.

White Paper — Publication 1 · Published

DOI: 10.5281/zenodo.21969638

Go to Publication 1

Creator and Principal Author

Towseef Ahmed

Current Status

Architecture Baseline Developed · White Paper — Publication 1 Published

AI systems can increasingly analyse information, generate recommendations and, when connected to tools and workflows, take action.

But increasing capability does not answer a more fundamental organisational question:

Who had the legitimate authority to decide?

Overview

The Question Behind TAHA

AI-enabled work rarely begins and ends inside one system.

An AI system may analyse evidence held in a repository. Its recommendation may move into a meeting or approval workflow. A human may make a decision. Another person or governance body may approve it. An automated workflow or AI agent may later execute the resulting action.

The work moves.

But the governance meaning surrounding that work can become fragmented.

A source may be superseded. An approval may contain conditions that are no longer visible when execution occurs. A person may possess technical access without holding the legitimate decision right. An automated workflow may remain technically capable of acting even after the authority supporting that action has changed, expired or been revoked.

Months later, an organisation may still know what happened while struggling to establish:

  • Why was it authorised?
  • On which evidence?
  • By whom?
  • Within what limits?
  • And who remained accountable?

TAHA treats this as a governance continuity problem.

Architecture

What TAHA Proposes

TAHA is built around a simple governance relationship:

A gold marker indicates a Human Authority event. Each one is also labelled in text.

  1. 01

    Governed Context

  2. 02

    AI Contribution

  3. 03

    Legitimate Human Authority

    Human Authority

  4. 04

    Operational Effect

  5. 05

    Accountable Outcome

The framework is designed to preserve that relationship as work moves across people, systems, repositories, workflows and AI agents.

TAHA is provider-neutral and organisation-neutral. It does not depend on a particular AI model, cloud platform, agent framework or records system. Its focus is the governance relationship that should remain interpretable across them.

  • Accessis notauthority.
  • Capabilityis notauthority.
  • Permissionis notapproval.
  • Recommendationis notdecision.

A system may be technically capable of performing an action without having legitimate authority to do so.

A person may hold a valid decision right while the resulting decision is not yet operationally active.

And an AI recommendation may be useful and persuasive while remaining only a recommendation.

TAHA keeps those meanings separate.

Traceable AI

Traceability in TAHA means governance traceability.

It does not require organisations to explain every internal process of an AI model. It does not depend on private chain-of-thought. And it does not mean retaining every prompt, click or conversation.

The question is whether enough material evidence remains to reconstruct the governance relationship surrounding a significant decision or action.

That may include the governing context, material AI contribution, Human Decision, Approval and validity, operational Activation, execution boundary, what was executed, what Verification established and who remained accountable.

Who authorised what, on which basis, within what limits, and with what outcome?

Human Authority

Human involvement does not automatically equal Human Authority.

Within TAHA, Human Authority is the legitimate, purpose-scoped decision right that exists through applicable organisational, contractual, professional, legal or other recognised governance.

TAHA does not create that authority.

It makes the authority relationship explicit.

Authority Source
The recognised basis from which the decision right originates.
Human Authority Holder
The identifiable person — or formally constituted human body — that legitimately exercises that decision right.
Accountable Owner
The person or human-governed institution that remains answerable for the governed outcome, service, programme, asset or risk.

Governance domains

Context and Authority Must Remain Connected

Good evidence does not create authority.

And legitimate authority does not repair defective evidence.

TAHA therefore keeps two related governance domains connected without treating them as the same thing.

Governed Context

  • Origin
  • Ownership
  • Provenance
  • Purpose
  • Applicability
  • Version
  • Integrity
  • Conflict and change

Human Authority

  • Authority Source
  • Human Authority Holder
  • Accountable Owner
  • Decision scope
  • Conditions
  • Validity
  • Operational status

A valid Human Authority Holder may still make a decision using defective or superseded evidence.

A strong AI recommendation may be based on sound evidence but never receive legitimate Human Authority. TAHA preserves both facts.

Context does not create authority.

Authority does not repair defective context.

Lifecycle

The TAHA Canonical Lifecycle

TAHA connects governed context, AI participation, Human Authority and execution through a nine-event Canonical Lifecycle.

Gold marks the Human Authority band. Each event within it is also labelled in text.

01–03

Context & Contribution

  1. 01

    Context & Evidence

    Establish or reference the applicable information basis.

  2. 02

    AI Contribution

    Identify material machine-originated analysis, comparison, simulation, drafting or other input.

  3. 03

    Recommendation

    Present a proposed course of action for authorised consideration.

04–06

Human Authority

  1. 04

    Human Decision

    Human Authority

    Record the authorised human disposition — such as accept, reject, modify, defer or escalate.

  2. 05

    Approval

    Human Authority

    Record the accepted decision, scope, conditions, validity and retained Human Authority.

  3. 06

    Activation

    Human Authority

    Make the approved position operationally effective while the required authority and context conditions remain valid.

07–09

Execution & Accountability

  1. 07

    Execution

    Perform the authorised action within its defined boundary.

  2. 08

    Verification

    Examine evidence about what occurred and whether the applicable boundary or criteria were met.

  3. 09

    Accountable Outcome

    Record the resulting state and accountable response.

The lifecycle is not intended as a rigid waterfall.

A case may repeat, branch, pause, reopen or create a successor decision.

What should remain distinguishable is the governance meaning of each event.

  • A Recommendation should not silently become a Human Decision.
  • Approval should not automatically become Activation.
  • And successful Execution should not later be treated as evidence that legitimate authority existed.

Meaningful Human Authority

Human Presence Is Not Enough

Putting a human somewhere in an AI workflow does not automatically establish meaningful oversight.

A reviewer may be present but lack the applicable decision right.

Another person may hold the correct authority but receive only the AI conclusion rather than the evidence, uncertainty and limitations behind it.

A human may technically be able to reject a recommendation while organisational pressure makes meaningful challenge unrealistic.

Or a human may reject an action without that decision actually changing what the system is permitted to do.

TAHA therefore introduces a five-question screen for Meaningful Human Authority.

  1. Did the person have legitimate authority?

    Is there an applicable Authority Source, defined scope and identifiable authority holder?

  2. Did they understand the decision and relevant evidence?

    Does the person or body have access to the material evidence, uncertainty, limitations and necessary clarification?

  3. Did they have enough time and independence?

    Is there a genuine opportunity for review without disabling pressure, conflict or dependence?

  4. Could they actually change the outcome?

    Can the recommendation be rejected, modified, deferred or escalated?

  5. Did the decision have operational effect?

    Does the human disposition actually change what the system is permitted or activated to do?

Meaningful Human Authority requires more than human presence. It requires legitimate authority, informed judgement and real operational effect.

Execution

From Human Decision to AI Execution

AI agents and automated workflows can increasingly perform actions rather than simply produce recommendations.

TAHA does not treat that capability as a transfer of authority.

Authority-Bounded Execution

Authority-Bounded Execution is the condition under which a human delegate, AI agent or automated workflow acts within explicit limits derived from valid prior Human Authority.

An agent may be authorised to perform a narrowly defined action within an approved boundary.

That does not give it authority to change the governing policy, expand its own scope, increase its own limits, approve an exception or approve its own recommendation.

When a case falls outside the approved boundary, the required response is stop, escalation or new authority.

Boundary attributes

  • Acting identity
  • Authorised purpose
  • Permitted actions
  • Approved tools and data
  • Thresholds
  • Validity
  • Prohibited actions
  • Escalation
  • Monitoring
  • Revocation

The constraint

AI capability does not create AI authority.

What legitimate Human Authority created the permission to act?

Delegation

Delegation Without Losing Human Authority

Scalable AI-enabled work does not necessarily require a person to approve every routine case individually.

TAHA allows recurring work to operate through a Pre-authorised Decision Rule.

Valid prior Human Authority can define

  • Eligible cases
  • Required inputs
  • Permitted outcomes
  • Limits
  • Monitoring
  • Escalation
  • Validity
  • Revocation

Applying that rule does not create new AI authority.

It remains an execution of prior Human Authority.

  1. 01

    Prior Human Authority

    Human Authority

  2. 02

    Defined Decision Rule / Execution Boundary

  3. 03

    Human Delegate · AI Agent · Automated Workflow

    • Human Delegate
    • AI Agent
    • Automated Workflow
  4. 04

    Execution within Boundary

Impact

When the Governing Context Changes

Governance does not necessarily end when Execution is complete.

A decision may be legitimately approved and executed.

Later, the organisation may discover that one of the governing sources used in that decision was incomplete, withdrawn, superseded or defective.

Which decisions and actions depended on that context?

Retrospective Impact

Retrospective Impact is the proportionate reassessment that follows when governing context or authority materially changes.

It does not rewrite history.

A decision may still have been legitimately authorised when it occurred. But new information may require affected decisions and actions to be identified and reassessed.

Response treatments

  • Review
  • Suspension
  • Correction
  • Reapproval
  • Notification
  • Successor Authority
  • Rollback

The authorised record

  1. 01

    Context

  2. 02

    Decision

    Human Authority

  3. 03

    Approval

    Human Authority

  4. 04

    Execution

Later — context changed, or a defect is discovered

Proportionate reassessment

  1. 01

    Affected Decisions

  2. 02

    Affected Actions

  3. 03

    Reassessment

    Human Authority

The authorised record is retained exactly as it stood. Reassessment is added alongside it, as a further authority event.

In practice

TAHA in Practice

RefundAssist-01

Fictional demonstration

Publication 1 includes a controlled fictional demonstration called RefundAssist-01.

It considers an AI-enabled duplicate-charge refund workflow operating within defined limits.

A Human Authority Holder approves a time-limited pilot with financial thresholds, readiness conditions, escalation requirements and retained authority.

The approved decision is activated and translated into an execution boundary. The workflow operates within that boundary.

Later, a defect is discovered in one of the governing policy sources.

The workflow is suspended.

Because the relationships among governing context, Human Authority, Activation, Execution and evidence remain connected, affected cases can be identified for review and successor authority can be established.

  1. 01

    Policy Context

  2. 02

    Human Approval

    Human Authority

  3. 03

    Activation

    Human Authority

  4. 04

    Execution Boundary

  5. 05

    Agent Action

  6. 06

    Policy Defect

  7. 07

    Suspension

    Human Authority

  8. 08

    Impact Review

RefundAssist-01 demonstrates how the TAHA governance relationships can be represented through an AI-enabled workflow. It is a fictional demonstration, not a real deployment, engagement, product or case study.

Explore RefundAssist-01 in Publication 1

Neighbouring governance

Designed to Complement Existing Governance

TAHA does not enter an empty field.

Existing standards, frameworks and professional disciplines already address substantial parts of AI governance, risk, management, oversight, identity, records and technical control.

TAHA does not attempt to replace these approaches.

Its focus is the cross-cutting governance relationship that can become fragmented as AI-enabled work moves among them.

  • NIST AI Risk Management
  • ISO/IEC AI standards
  • EU AI Act
  • OECD AI Principles
  • Programme and Portfolio Governance
  • Identity and Access Management
  • Records and Provenance Practice
  • Human Oversight Research
  • Agent Identity and Authorisation

Listed for context only. Nothing here claims compliance with, certification against, conformance to, endorsement by, or formal mapping to any standard, regulation, authority or institution.

  1. 01

    Governed Context

  2. 02

    AI Contribution

  3. 03

    Legitimate Human Authority

    Human Authority

  4. 04

    Operational Effect

  5. 05

    Accountable Outcome

Where organisations already preserve that relationship effectively, TAHA may provide a common semantic and assurance architecture across existing controls.

Publication

White Paper — Publication 1

The First Public Articulation of the TAHA Framework

TAHA Framework — White Paper, Publication 1 establishes the first public articulation of the framework architecture.

TAHA Framework

Traceable AI. Human Authority.

White Paper — Publication 1

Author
Towseef Ahmed
Published
17 August 2026
Status
Published

Read Publication 1

It introduces principal TAHA constructs including

  • Context Governance Kernel
  • Human Authority Architecture
  • Authority Context Baseline
  • Authority Source
  • Human Authority Holder
  • Accountable Owner
  • Authority Record
  • Canonical Lifecycle
  • Meaningful Human Authority
  • Authority-Bounded Execution
  • Pre-authorised Decision Rules
  • Retained Human Authority
  • Retrospective Impact
  • RefundAssist-01

Examination

From Publication to Examination

Publication is not the end of the work.

It is the point at which the architecture can move beyond controlled development and encounter practitioners, organisations, researchers and technical systems.

Publication 1 marks a transition from controlled development to external examination.

  • Can TAHA improve authority clarity and reconstruction across AI-enabled work?
  • Can authority and context remain interpretable across model, provider, repository and organisational change?
  • How should authority revocation propagate across AI agents and downstream delegations?
  • How effectively can affected decisions be identified when governing context later changes?

Those questions cannot be closed by assertion. They require examination, implementation and evidence.

Examine TAHA

Read It. Challenge It. Try to Break It. Test It.

TAHA is offered for serious examination rather than passive acceptance. Useful contribution does not require agreement.

  • Challenge the assumptions.
  • Compare the architecture with existing governance.
  • Apply it to a bounded workflow.
  • Identify unnecessary complexity.
  • Find where the authority chain breaks.
  • Test whether the relationships remain interpretable when systems, evidence or authority change.
  1. Review TAHA

    Examine the architecture through governance, assurance, security, identity, records, programme management, human factors, legal or standards perspectives.

  2. Test TAHA in a Workflow

    Apply the architecture to a bounded real-world decision or agent-enabled process.

  3. Research or Compare It

    Evaluate TAHA conceptually, empirically or against established governance approaches.

  4. Explore Technical Implementation

    Investigate schemas, mappings, validators, visualisation, identity, authorisation or runtime patterns that could help operationalise the architecture.

Discuss, Review or Contribute

In closing

The Question TAHA Leaves With Us

AI can analyse.

It can recommend.

And increasingly, it can act.

But capability alone does not establish legitimate organisational authority.

For consequential AI-enabled work, organisations still need to be able to answer:

  • What evidence governed the decision?
  • What did AI contribute?
  • Who had the legitimate right to decide?
  • What was actually approved?
  • What was permitted to execute?
  • What happened?
  • And who remained accountable?

TAHA proposes that these relationships should remain connected.

Not because every AI interaction requires formal governance. Not because Human Authority guarantees a good decision. And not because traceability eliminates every failure.

But because as systems become increasingly capable of participating in consequential organisational work, the distinction between capability and authority becomes increasingly important.

When capability stops being the constraint, authority becomes the question.

TAHA Framework

Traceable AI. Human Authority.

White Paper — Publication 1 · Published