Rubber-Stamp Approval
Human review that never changes outcomes
A commitment boundary requires genuine authority at the moment of decision — not the appearance of one.
A human sits at the commitment boundary. The system presents a recommendation. The human clicks approve. Nothing in the record distinguishes this from automation except latency and salary. The organisation believes accountability exists because a person signed. The record shows only that a person ratified what the machine already decided.
In software systems
The failure appears wherever a human-in-the-loop gate sits downstream of a model or rules engine but never alters outcomes. A fraud platform routes 40,000 daily alerts to analysts; override rate tracks at 0.02%. A content moderation queue shows the same pattern: humans confirm model removals in under four seconds per item. The UI may require a checkbox and a reason code, but the reason code is always the default.
Architecturally, the commitment event names a human authority — decidedBy: "reviewer.jones" — while the evidentiary payload is entirely model-derived. No field captures whether the human examined evidence, disagreed, or applied independent judgment. Audit logs show clicks, not deliberation. The commitment boundary has been placed correctly in the diagram and hollowed out in operation. Override rate is the diagnostic: sustained rates below 1% signal that the human is decorative, not authoritative.
In human organisations
Organisations install review boards, second signatures, and compliance checkpoints to satisfy regulators and risk committees. On paper, a senior underwriter approves every loan above a threshold. In practice, the underwriter receives a pre-scored application with a green recommendation banner and approves in batch at end of day. The board exists; the judgment does not.
The organisational failure is misallocated accountability. When something goes wrong, the named approver becomes the scapegoat — but the investigation reveals they had no meaningful discretion, no access to raw evidence, and no time budget to dissent. Training emphasises throughput. Metrics reward clearance rate, not override quality. The role is performative: it satisfies a control framework without transferring epistemic responsibility from the model to a certified human authority.
In socio-technical systems
The compounded case is most dangerous at catastrophic severity. A clinical decision support system recommends a treatment pathway; the physician approves with one tap because the interface defaults to acceptance and the ward is understaffed. The patient’s adverse outcome triggers review. The record shows physician commitment. The model’s confidence score and the evidence snapshot are buried in ancillary fields nobody reads during incident response.
Regulators see a human at the boundary and classify the system as supervised. Engineers see a human in the loop and defer calibration questions. Clinicians absorb liability for outputs they cannot realistically contest — including channels shaped by frozen collective subjectivity at training time. The socio-technical stack aligns to produce the appearance of shared accountability while concentrating actual decision authority in an unexamined model.
Structural causes
Epistemic tier collapse
Rubber-stamp approval is boundary theatre atop tier collapse: the record shows human L0 authority while the epistemic content is the machine’s unexamined L2 output. The UI and schema treat model inference as the substance of the decision; the human adds only a signature.
The commitment boundary pattern requires deliberate crossing with evidence and independent judgment — not a click that ratifies a pre-selected default. When override rate is near zero, recorded delegation — L0 policy with calibration evidence — is the honest alternative to decorative human gates. Seeded review cases detect rubber-stamp behaviour before override metrics lie; manual recency sampling keeps humans capable of real execution when automation dominates volume.