Original Governance Framework
TAHA Framework
A governance architecture for keeping governed context, legitimate Human Authority, execution and accountable outcomes connected across AI-enabled work.
Traceable AI. Human Authority.
Creator and Principal Author
Towseef Ahmed
Current Status
Architecture Baseline Developed · White Paper — Publication 1 Published
AI systems can increasingly analyse information, generate recommendations and, when connected to tools and workflows, take action.
But increasing capability does not answer a more fundamental organisational question:
Who had the legitimate authority to decide?
Overview
The Question Behind TAHA
AI-enabled work rarely begins and ends inside one system.
An AI system may analyse evidence held in a repository. Its recommendation may move into a meeting or approval workflow. A human may make a decision. Another person or governance body may approve it. An automated workflow or AI agent may later execute the resulting action.
The work moves.
But the governance meaning surrounding that work can become fragmented.
A source may be superseded. An approval may contain conditions that are no longer visible when execution occurs. A person may possess technical access without holding the legitimate decision right. An automated workflow may remain technically capable of acting even after the authority supporting that action has changed, expired or been revoked.
Months later, an organisation may still know what happened while struggling to establish:
- Why was it authorised?
- On which evidence?
- By whom?
- Within what limits?
- And who remained accountable?
TAHA treats this as a governance continuity problem.
Architecture
What TAHA Proposes
TAHA is built around a simple governance relationship:
A gold marker indicates a Human Authority event. Each one is also labelled in text.
01
Governed Context
02
AI Contribution
03
Legitimate Human Authority
Human Authority
04
Operational Effect
05
Accountable Outcome
The framework is designed to preserve that relationship as work moves across people, systems, repositories, workflows and AI agents.
TAHA is provider-neutral and organisation-neutral. It does not depend on a particular AI model, cloud platform, agent framework or records system. Its focus is the governance relationship that should remain interpretable across them.
- Accessis notauthority.
- Capabilityis notauthority.
- Permissionis notapproval.
- Recommendationis notdecision.
A system may be technically capable of performing an action without having legitimate authority to do so.
A person may hold a valid decision right while the resulting decision is not yet operationally active.
And an AI recommendation may be useful and persuasive while remaining only a recommendation.
TAHA keeps those meanings separate.
Traceable AI
Traceability in TAHA means governance traceability.
It does not require organisations to explain every internal process of an AI model. It does not depend on private chain-of-thought. And it does not mean retaining every prompt, click or conversation.
The question is whether enough material evidence remains to reconstruct the governance relationship surrounding a significant decision or action.
That may include the governing context, material AI contribution, Human Decision, Approval and validity, operational Activation, execution boundary, what was executed, what Verification established and who remained accountable.
Who authorised what, on which basis, within what limits, and with what outcome?
Human Authority
Human involvement does not automatically equal Human Authority.
Within TAHA, Human Authority is the legitimate, purpose-scoped decision right that exists through applicable organisational, contractual, professional, legal or other recognised governance.
TAHA does not create that authority.
It makes the authority relationship explicit.
- Authority Source
- The recognised basis from which the decision right originates.
- Human Authority Holder
- The identifiable person — or formally constituted human body — that legitimately exercises that decision right.
- Accountable Owner
- The person or human-governed institution that remains answerable for the governed outcome, service, programme, asset or risk.
Governance domains
Context and Authority Must Remain Connected
Good evidence does not create authority.
And legitimate authority does not repair defective evidence.
TAHA therefore keeps two related governance domains connected without treating them as the same thing.
Governed Context
- Origin
- Ownership
- Provenance
- Purpose
- Applicability
- Version
- Integrity
- Conflict and change
Human Authority
- Authority Source
- Human Authority Holder
- Accountable Owner
- Decision scope
- Conditions
- Validity
- Operational status
A valid Human Authority Holder may still make a decision using defective or superseded evidence.
A strong AI recommendation may be based on sound evidence but never receive legitimate Human Authority. TAHA preserves both facts.
Context does not create authority.
Authority does not repair defective context.
Lifecycle
The TAHA Canonical Lifecycle
TAHA connects governed context, AI participation, Human Authority and execution through a nine-event Canonical Lifecycle.
Gold marks the Human Authority band. Each event within it is also labelled in text.
01–03
Context & Contribution
01
Context & Evidence
Establish or reference the applicable information basis.
02
AI Contribution
Identify material machine-originated analysis, comparison, simulation, drafting or other input.
03
Recommendation
Present a proposed course of action for authorised consideration.
04–06
Human Authority
04
Human Decision
Human Authority
Record the authorised human disposition — such as accept, reject, modify, defer or escalate.
05
Approval
Human Authority
Record the accepted decision, scope, conditions, validity and retained Human Authority.
06
Activation
Human Authority
Make the approved position operationally effective while the required authority and context conditions remain valid.
07–09
Execution & Accountability
07
Execution
Perform the authorised action within its defined boundary.
08
Verification
Examine evidence about what occurred and whether the applicable boundary or criteria were met.
09
Accountable Outcome
Record the resulting state and accountable response.
The lifecycle is not intended as a rigid waterfall.
A case may repeat, branch, pause, reopen or create a successor decision.
What should remain distinguishable is the governance meaning of each event.
- A Recommendation should not silently become a Human Decision.
- Approval should not automatically become Activation.
- And successful Execution should not later be treated as evidence that legitimate authority existed.
Execution
From Human Decision to AI Execution
AI agents and automated workflows can increasingly perform actions rather than simply produce recommendations.
TAHA does not treat that capability as a transfer of authority.
Authority-Bounded Execution
Authority-Bounded Execution is the condition under which a human delegate, AI agent or automated workflow acts within explicit limits derived from valid prior Human Authority.
An agent may be authorised to perform a narrowly defined action within an approved boundary.
That does not give it authority to change the governing policy, expand its own scope, increase its own limits, approve an exception or approve its own recommendation.
When a case falls outside the approved boundary, the required response is stop, escalation or new authority.
Boundary attributes
- Acting identity
- Authorised purpose
- Permitted actions
- Approved tools and data
- Thresholds
- Validity
- Prohibited actions
- Escalation
- Monitoring
- Revocation
The constraint
AI capability does not create AI authority.
What legitimate Human Authority created the permission to act?
Delegation
Delegation Without Losing Human Authority
Scalable AI-enabled work does not necessarily require a person to approve every routine case individually.
TAHA allows recurring work to operate through a Pre-authorised Decision Rule.
Valid prior Human Authority can define
- Eligible cases
- Required inputs
- Permitted outcomes
- Limits
- Monitoring
- Escalation
- Validity
- Revocation
Applying that rule does not create new AI authority.
It remains an execution of prior Human Authority.
01
Prior Human Authority
Human Authority
02
Defined Decision Rule / Execution Boundary
03
Human Delegate · AI Agent · Automated Workflow
- Human Delegate
- AI Agent
- Automated Workflow
04
Execution within Boundary
Impact
When the Governing Context Changes
Governance does not necessarily end when Execution is complete.
A decision may be legitimately approved and executed.
Later, the organisation may discover that one of the governing sources used in that decision was incomplete, withdrawn, superseded or defective.
Which decisions and actions depended on that context?
Retrospective Impact
Retrospective Impact is the proportionate reassessment that follows when governing context or authority materially changes.
It does not rewrite history.
A decision may still have been legitimately authorised when it occurred. But new information may require affected decisions and actions to be identified and reassessed.
Response treatments
- Review
- Suspension
- Correction
- Reapproval
- Notification
- Successor Authority
- Rollback
The authorised record
01
Context
02
Decision
Human Authority
03
Approval
Human Authority
04
Execution
Later — context changed, or a defect is discovered
Proportionate reassessment
01
Affected Decisions
02
Affected Actions
03
Reassessment
Human Authority
The authorised record is retained exactly as it stood. Reassessment is added alongside it, as a further authority event.
In practice
TAHA in Practice
RefundAssist-01
Fictional demonstration
Publication 1 includes a controlled fictional demonstration called RefundAssist-01.
It considers an AI-enabled duplicate-charge refund workflow operating within defined limits.
A Human Authority Holder approves a time-limited pilot with financial thresholds, readiness conditions, escalation requirements and retained authority.
The approved decision is activated and translated into an execution boundary. The workflow operates within that boundary.
Later, a defect is discovered in one of the governing policy sources.
The workflow is suspended.
Because the relationships among governing context, Human Authority, Activation, Execution and evidence remain connected, affected cases can be identified for review and successor authority can be established.
01
Policy Context
02
Human Approval
Human Authority
03
Activation
Human Authority
04
Execution Boundary
05
Agent Action
06
Policy Defect
07
Suspension
Human Authority
08
Impact Review
RefundAssist-01 demonstrates how the TAHA governance relationships can be represented through an AI-enabled workflow. It is a fictional demonstration, not a real deployment, engagement, product or case study.
Neighbouring governance
Designed to Complement Existing Governance
TAHA does not enter an empty field.
Existing standards, frameworks and professional disciplines already address substantial parts of AI governance, risk, management, oversight, identity, records and technical control.
TAHA does not attempt to replace these approaches.
Its focus is the cross-cutting governance relationship that can become fragmented as AI-enabled work moves among them.
- NIST AI Risk Management
- ISO/IEC AI standards
- EU AI Act
- OECD AI Principles
- Programme and Portfolio Governance
- Identity and Access Management
- Records and Provenance Practice
- Human Oversight Research
- Agent Identity and Authorisation
Listed for context only. Nothing here claims compliance with, certification against, conformance to, endorsement by, or formal mapping to any standard, regulation, authority or institution.
01
Governed Context
02
AI Contribution
03
Legitimate Human Authority
Human Authority
04
Operational Effect
05
Accountable Outcome
Where organisations already preserve that relationship effectively, TAHA may provide a common semantic and assurance architecture across existing controls.
Publication
White Paper — Publication 1
The First Public Articulation of the TAHA Framework
TAHA Framework — White Paper, Publication 1 establishes the first public articulation of the framework architecture.
TAHA Framework
Traceable AI. Human Authority.
It introduces principal TAHA constructs including
- Context Governance Kernel
- Human Authority Architecture
- Authority Context Baseline
- Authority Source
- Human Authority Holder
- Accountable Owner
- Authority Record
- Canonical Lifecycle
- Meaningful Human Authority
- Authority-Bounded Execution
- Pre-authorised Decision Rules
- Retained Human Authority
- Retrospective Impact
- RefundAssist-01
Examination
From Publication to Examination
Publication is not the end of the work.
It is the point at which the architecture can move beyond controlled development and encounter practitioners, organisations, researchers and technical systems.
Publication 1 marks a transition from controlled development to external examination.
- Can TAHA improve authority clarity and reconstruction across AI-enabled work?
- Can authority and context remain interpretable across model, provider, repository and organisational change?
- How should authority revocation propagate across AI agents and downstream delegations?
- How effectively can affected decisions be identified when governing context later changes?
Those questions cannot be closed by assertion. They require examination, implementation and evidence.
Examine TAHA
Read It. Challenge It. Try to Break It. Test It.
TAHA is offered for serious examination rather than passive acceptance. Useful contribution does not require agreement.
- Challenge the assumptions.
- Compare the architecture with existing governance.
- Apply it to a bounded workflow.
- Identify unnecessary complexity.
- Find where the authority chain breaks.
- Test whether the relationships remain interpretable when systems, evidence or authority change.
Review TAHA
Examine the architecture through governance, assurance, security, identity, records, programme management, human factors, legal or standards perspectives.
Test TAHA in a Workflow
Apply the architecture to a bounded real-world decision or agent-enabled process.
Research or Compare It
Evaluate TAHA conceptually, empirically or against established governance approaches.
Explore Technical Implementation
Investigate schemas, mappings, validators, visualisation, identity, authorisation or runtime patterns that could help operationalise the architecture.
Original work
Related Insights
Articles and commentary.
In closing
The Question TAHA Leaves With Us
AI can analyse.
It can recommend.
And increasingly, it can act.
But capability alone does not establish legitimate organisational authority.
For consequential AI-enabled work, organisations still need to be able to answer:
- What evidence governed the decision?
- What did AI contribute?
- Who had the legitimate right to decide?
- What was actually approved?
- What was permitted to execute?
- What happened?
- And who remained accountable?
TAHA proposes that these relationships should remain connected.
Not because every AI interaction requires formal governance. Not because Human Authority guarantees a good decision. And not because traceability eliminates every failure.
But because as systems become increasingly capable of participating in consequential organisational work, the distinction between capability and authority becomes increasingly important.
When capability stops being the constraint, authority becomes the question.
TAHA Framework
Traceable AI. Human Authority.
White Paper — Publication 1 · Published
