Step 2 · Refine

Requirements, Permissions and Approval Design for Municipal Robo Claw Deployments

Once the target process is chosen, you specify the departments, processes and resident services in scope, the classification of resident data, the legal basis, read and write permissions, cross-department sharing, external transmission, the boundary with electronic approval workflow, human approval, segregation of duties, logs and audit trails, and KPIs.

Bottom Line

The purpose of the Refine step is to document, for the target process, who automates what, how far, and under whose approval. In particular, settle at this stage the purpose of use, legal basis and data classification for resident information, the scope of cross-department sharing and external transmission, the boundary with electronic approval workflow, the review process with legal, personal-information-protection and information-security staff, and the segregation of duties across departments, job grades and contractors. Moving to the pilot while these remain vague means redoing the design later.

Who This Is For

Who This Is For

This applies to information systems departments, responsible department heads, and personal information protection officers whose tasks have been determined by Discover STEP.

What You'll Decide

What You'll Decide in This Step

In the Refine STEP, we document the scope of the target departments, operations, and resident services, the data classification of resident information handled, legal grounds, read/write permissions, inter-departmental sharing, external transmission, approval conditions, division of duties, responsibility boundaries, and KPIs, and convert them into requirements that can be validated in Build & Validate.

Industry Challenges

Challenges unique to local governments

01

The concept of permissions differs by department

The existing permission operations differ by department, making it difficult to create a unified permission design.

02

Classification and legal grounds of resident information are unorganized

In many cases, there is no clear documentation of the legal grounds or classification for how resident information can be used in operations.

03

Role sharing with electronic approval is unclear

Sometimes the relationship between AI agent outputs and existing electronic approval processes is not organized.

04

Behavior upon re-execution (prevention of duplicate execution) has not been considered.

In some cases, designs to prevent double updates of resident records or duplicate transmissions when re-executing the same process have not been considered.

Method

Implementation Steps

1. Define the target departments, operations, and resident services

Clearly define the scope of the target departments, operations, and related resident services.

2. Design Agents, Skills, and Tools

Design the roles of Agents necessary for the target operations, the Skills for operational procedures, and the scope of Tools for document management and groupware operations.

3. Define the Tool Policy

Define the operations that the tool is allowed to perform (read/write, Allow/Deny) as a policy. Final updates to resident records should be Denied.

4. Organize data classification and legal basis for resident information

Organize the data classification, purpose of use, and legal basis for the resident information handled, and define the scope of minimal use.

5. Design read/write permissions, inter-departmental sharing, and external transmission

Design access permissions by department and position, the scope of data sharing between departments, and whether external transmission is allowed and the approval conditions.

6. Define the boundary with electronic approvals

Define the boundary where the AI agent’s output is only a draft or candidate, and formal approval is carried out through the existing electronic approval process.

7. Define approvals, division of duties, and escalation

Define approvers for operations requiring human approval, division of duties by department, position, and contractor, and escalation paths to legal, personal information protection, and information security officers.

8. Define logs, audit trails, prevention of duplicate execution, and KPIs

Define the operation logs and input/output records to be stored, design to prevent incorrect updates upon re-execution, and effectiveness measurement KPIs.

Data & Systems

Data and Systems Used

Ordinances, regulations, guidelines, and internal administrative rules Resident Information / Application Information Tax, Insurance, and Welfare Related Information Access rights ledger Document Management / Electronic Approval System Resident Information System Authorization and ID management system

Human-in-the-loop

Where Human Approval Is Required

  • Clarify the final approvers for administrative actions, benefits eligibility, and review by position
  • Clarify approval conditions for third-party provision or external transmission of resident information
  • Obtain confirmation from Legal and Personal Information Protection Officers regarding classification and legal basis of resident information
  • Obtain approval from the Information Systems Department for cross-departmental authority granting and data sharing

Measurement

KPI

In the Refine STEP, define candidate KPIs to be verified in Build & Validate

Target level for primary classification time for in-house inquiries

Time target for inquiry classification

Lead time until approval

Time required from draft creation to human approval

Number of detected permission deviations

Number of detected operations exceeding the defined permission scope

Checklist

Requirements definition checklist

  • Target departments, tasks, and resident services (including and excluding tasks) are documented
  • Input data and outputs (classification proposals, summaries, drafts) are defined
  • Data classification, purpose of use, and legal basis for resident information are organized
  • Access rights for read and write are defined by department and position
  • Scope and approval conditions for inter-departmental sharing and external transmission are defined
  • Boundaries with electronic approval are defined
  • Approval conditions and approvers for administrative actions, benefits eligibility, and reviews are defined
  • Confirmation process with Legal, Personal Information Protection, and Information Security Officers is defined
  • The duties of departments, positions, and contractors are defined.
  • Designs to prevent duplicate execution and incorrect updates are being considered.
  • The scope and retention period for operation logs and input/output records are defined.
  • KPIs used for effect measurement are defined

Pitfalls

Common Pitfalls

01

Postpone authority design.

If you try to adjust permissions after running it first, there will be significant rework when deployed across multiple departments.

02

Proceed with the approver unclear

Deciding approvers by individual name rather than position will cause operations to stop during transfers or resignations.

03

Make the boundary with electronic approval ambiguous.

If you do not explicitly deny final updates to resident records and official approvals in the Tool Policy, there is a risk of granting unintended write permissions.

FAQ

Frequently Asked Questions

Which department should lead the requirement definition?

It is recommended that the department responsible for the target business and the information system department take joint leadership. When handling resident information, the personal information protection officer should be involved, and if external transmission is involved, the information security and legal departments should also participate.

How detailed should authority design be?

At a minimum, clarify the read/write scope at the department and position level, as well as the approvers for administrative actions, eligibility for benefits, and reviews. The level of detail should be adjusted according to the risk of the target business.

When handling resident information, is confirmation from the personal information protection officer always required?

The necessity varies depending on the purpose of use, legal basis, data classification, and whether external transmission is involved, but when handling sensitive personal information or when inter-departmental sharing or external transmission is involved, it is strongly recommended to obtain confirmation.

What is prevention of duplicate execution?

It refers to a design where the same process can be executed multiple times without causing duplicate updates to resident records or duplicate notifications. This becomes important for retries in case of communication errors.

Shall we organize requirements, authorities, and approval design together?

The scope of the target business, authority over resident information, approval flows, and responsibility boundaries can be concretized through formal LP consultations.

Organize implementation requirements and authority design