Chapter 25
The Dissent Log
The Utopia of the Agentic Enterprise, Part IV. Doing Less
The case for optimism is the freed time. An agent drafts what used to take days, and the people who wrote it could spend the rest of the week on the part of the work the draft leaves out.
But that only comes true if they get to decide what the freed time is for, and nobody above them quietly takes it back, and nothing in the software provides either. Left to itself, the time goes the other way: into more drafts, or a new review step.
So those conditions have to be produced on purpose. That means taking things away or rewiring who answers to whom, with as few new artefacts as possible, because governance obeys what Graeber called the iron law of liberalism, where a reform meant to cut paperwork ends up producing more of it. A register nobody with authority reads is a box ticker, and AI governance, with its own vendors and budget line, is a ready place for the next round of them to grow.
None of this is new. The Tavistock Institute’s studies of British coal mines in the early 1950s found that mechanisation had been introduced by redesigning the technology and leaving the work organisation to fall out of it, with the result that productivity fell and absence rose.1 Their answer, worked out over the following 20 years, was to design the technical and the social system together. Albert Cherns wrote the principles down in 1976, and two of them do most of the work here.2 Specify only what is critical and leave the rest to the people doing the work, because every unnecessary rule removes a place where they could have adapted. And handle variance where it arises rather than exporting it up the hierarchy, because a problem that travels three levels up gets decided late, by people further away from it, in a meeting about something else.
Amy Edmondson’s hospital study in the 1990s found that the nursing teams with the best leadership reported the most drug errors.3 They weren’t making more. They were the teams where reporting one didn’t cost you anything, so the errors were visible and got fixed. A status report that softens at every level on its way up, red at the bottom and a reassuring amber at the top, is what a large organisation looks like without that condition. The structure has to make speaking up cheap.
Subtractions and Rewires
Subtraction Before Addition
Every AI deployment gets a deletion ledger before it gets a budget: the meetings and reports it will retire, with a name against each and a date. To decide what goes on it, you ask of each item who still opens it, and what would happen if it stopped for a month. Sometimes the only person who still opens a report is the one who writes it. A deployment with an empty ledger after two quarters has added a machine to the operating system, and it gets reported that way.
Every new rule, review step or artefact introduced alongside an AI system gets an expiry date. On that date it stops, unless someone with budget authority renews it in writing. The officials in C. Northcote Parkinson’s Admiralty, who multiplied while the fleet shrank, never had to justify their continued existence, because nobody asked. The renewal is where somebody would have.
Rewire. The deletion ledger belongs to the sponsor who claimed the savings, and the savings only count once the ledger’s lines have actually stopped. Booking the saving and keeping the report is misreporting.
Project Classification
Every AI-related initiative gets a label before it gets funded: task automation, human-plus-AI decision support, modernisation that happens to use AI, a time-boxed experiment, or theatre meant to signal AI investment. Nobody will pick the last one for their own project, of course. A data-warehouse migration delivering lookup responses via an AI interface is still a data-warehouse migration. If the label holds through the life of the initiative, the feedback loop stays intact. At delivery, the organisation knows whether it paid for transformation and got transformation, or paid for transformation and got its legacy systems modernised under a better-sounding banner.
Rewire. Project credit and bonus allocation are tied to the classification. AI funding obtained by relabelling modernisation work gets no AI-impact credit when it delivers.
Full-Cost Budgeting
Business cases count the whole stack, from inference and review labour to the work moved onto customers and other teams. Totalling only payroll measures the line that fell. Totalling across ledgers shows whether the labour moved somewhere less visible, to the team next door that now checks the output, for instance.
Rewire. Finance doesn’t approve business cases that omit the lines. The numbers can be estimates. They can’t be absent.
Authority With the Accountability
Every significant deployment appoints a constraint designer, an auditor and a liable party. When the person in one of those roles changes, the documentation updates before the handover completes, not when an incident review comes looking for someone.
The same goes for everyone placed near a machine. If the system depends on someone’s signature, that person needs the time and the standing to withhold it. If they have neither, the signature comes out of the process. Left in, it is just a liability sink with a login.
Rewire. The auditor’s performance review isn’t written by the constraint designer. Otherwise the auditor’s independence depends on the designer’s goodwill.
Reporting-Sanction Separation
If the person who writes the status report upward also decides who stays on the technical team, they can’t be the only one who interprets what the engineers agreed on. So project reviews hear from named technical representatives, not only through their managers. And there is a way to escalate that doesn’t pass through the manager being contradicted.
Rewire. Technical representatives who bring uncomfortable news to a review get credit for it, and if bad news keeps being followed by a bad performance review, that pattern is tracked as a governance signal. This is Edmondson’s condition built into the structure rather than requested of the culture.
Dissent Log
When a major decision is taken against substantial internal technical objection, the objection is logged with the decision. The log records that the concern existed and was heard, and nobody is punished by it. Later reviews of the outcome reference the log. It’s a cheap way for an organisation to remember what it chose not to know. Without it, the post-mortem has to piece that together from old email threads, if anyone kept them.
Rewire. Decision-makers who override dissent are accountable for the override if the predicted risk materialises. Decision-makers who heed dissent that turns out to be wrong aren’t penalised for having listened.
Rewires Without Artefacts
Some measures need no register, only a decision someone has to defend.
Verification as a career path. Review, QA and test design become a ladder with its own compensation band rather than a rotation on the way somewhere else, so that the people with the authority to stop a release aren’t the people waiting to be cycled out.
A named owner for freed time. For each deployment, one person decides where the hours go, and the decision is written down before the tool is live. Otherwise someone decides anyway, later and without writing it down.
Unassisted practice in the schedule. Where people built their expertise by doing the work that’s now automated, they keep a protected share of it, done without the tool, as a deliverable rather than a cost. Lisanne Bainbridge’s point applies: monitoring isn’t practice.4
None of the measures works alone. A deletion ledger without classification lets the sponsor delete a meeting and call the migration transformation. A dissent log without reporting-sanction separation is a tidy list of the people who objected, which comes in handy for whoever is managing them out. An organisation that installs only one of a pair should expect it to degrade.
Harder Signals
Adoption metrics measure contact with the tool. Seats licensed and training completed are what the dashboards report. They say nothing about whether the organisation got better at knowing what is happening and acting on it. A few harder signals can.
- Reality contact. How long does a frontline signal take to reach someone who can act on it? How often are model outputs successfully challenged?
- Coordination. Handoffs per completed case; meetings and approvals added against meetings and approvals retired.
- Exception burden. How many cases leave the standard path, and who ends up with the hard ones.
- Learning. Do juniors get unassisted practice? Do overrides feed process redesign?
- Simplification. Which systems were decommissioned, and which manual reconciliations disappeared?
None of these is as easy to collect as a login count.
The measures are cheap to build and expensive to hold politically. A dissent log costs almost nothing technically. The cost is paid by whoever has to tell a project lead, before any failure, that the objections to their decision will be written down next to it. An expiry date on a review step costs nothing until the day the head of compliance has to argue, in writing, for renewing it. Those conversations need the executive team behind them, which no PMO rollout can provide.
Measures like these are easy to install after a failure nobody can ignore: a deployment that hurt a customer, or a regulatory finding. After that, not changing costs more than changing. The better time is while the measures still look optional. But at that stage the visible costs are all anyone sees: friction with project leads, and reviews with findings the sponsor can’t smooth over.
Measures as Ceremony
The economics don’t require any of this. Cheap output lets an organisation do less, and it equally lets one produce more rules and more supervision, and only the first of those needs anyone to decide anything.
Every one of the measures can also be installed as a ceremony. A deletion ledger can be filled with items nobody was going to keep, and a dissent log can be kept faithfully and never read again. The test is the one for any report: who reads this, and what do they do next? If the answer is a committee that reviews it quarterly and never sees the system in motion, the measure has joined the apparatus it was meant to constrain. It should then be deleted, before it acquires a constituency and somebody’s job depends on it.
Checklist
- Does each deployment have a deletion ledger before it has a budget, with a name and a date against every line? Is it still empty after two quarters?
- Does every rule, review step and artefact added alongside an AI system have an expiry date, after which it stops unless someone with budget authority renews it in writing?
- Do the claimed savings count only once the ledger’s lines have stopped?
- For each deployment, who decides where the freed hours go, and was it written down before the tool went live?
- For each measure you’ve put in place: is the artefact there, and has the incentive behind it been rewired? A measure without its rewire is cosmetic.
- Is the auditor’s performance review written by the constraint designer?
- Does finance approve business cases that leave out the hidden cost lines?
- For each measure, who pays the political cost of installing it?
- For each measure, who reads it and what do they do next? If the answer is a committee that never sees the system in motion, delete the measure.