Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Trust Center

Responsible Automation

Automation is governed by consequence. ArtOfTheHack is designed so that the level of autonomy granted to the system is a deliberate institutional choice rather than a default.

Controls

Documented commitments

  1. Control 01

    Advisory mode

    ArtOfTheHack evaluates evidence and recommends an action to an authorized human decision-maker.

  2. Control 02

    Approval-gated mode

    ArtOfTheHack prepares an action, but execution requires approval from the correct authority.

  3. Control 03

    Bounded automatic mode

    ArtOfTheHack executes only predefined, reversible, policy-authorized actions within grantee organization-defined limits.

  4. Control 04

    Human authority

    Named humans hold authority for consequential classes of action, and that authority cannot be delegated to the system implicitly.

  5. Control 05

    Separation of duties

    Requesting, approving, and executing roles can be held by different people and different systems.

  6. Control 06

    Reversibility

    Automatic execution requires a validated rollback path recorded with the decision.

  7. Control 07

    Kill switch

    Automation can be halted immediately at workflow, environment, or tenant scope.

  8. Control 08

    Native fallback

    If ArtOfTheHack is unavailable, existing systems continue operating under their own controls.

  9. Control 09

    Maximum blast-radius limits

    Recipient organizations define the maximum scope any single automated action may affect.

  10. Control 10

    Expiring authorization

    Approvals carry validity windows and expiration conditions rather than standing permission.

  11. Control 11

    Continuous outcome monitoring

    Executed actions are monitored and their outcomes calibrate future decisions.

These are the operating commitments of the platform and the award agreement, described as designed and delivered. They are not a certification, an independent security audit, or a compliance attestation, and ArtOfTheHack does not claim any. Protections that depend on the deployment model are scoped in writing with each grantee before connection.