Requirements, Permissions and Approval Design for Municipal Robo Claw Deployments
Once the target process is chosen, you specify the departments, processes and resident services in scope, the classification of resident data, the legal basis, read and write permissions, cross-department sharing, external transmission, the boundary with electronic approval workflow, human approval, segregation of duties, logs and audit trails, and KPIs.
The purpose of the Refine step is to document, for the target process, who automates what, how far, and under whose approval. In particular, settle at this stage the purpose of use, legal basis and data classification for resident information, the scope of cross-department sharing and external transmission, the boundary with electronic approval workflow, the review process with legal, personal-information-protection and information-security staff, and the segregation of duties across departments, job grades and contractors. Moving to the pilot while these remain vague means redoing the design later.
Who This Is For
Who This Is For
This applies to information systems departments, responsible department heads, and personal information protection officers whose tasks have been determined by Discover STEP.
What You'll Decide
What You'll Decide in This Step
In the Refine STEP, we document the scope of the target departments, operations, and resident services, the data classification of resident information handled, legal grounds, read/write permissions, inter-departmental sharing, external transmission, approval conditions, division of duties, responsibility boundaries, and KPIs, and convert them into requirements that can be validated in Build & Validate.
Industry Challenges
Challenges unique to local governments
The concept of permissions differs by department
The existing permission operations differ by department, making it difficult to create a unified permission design.
Classification and legal grounds of resident information are unorganized
In many cases, there is no clear documentation of the legal grounds or classification for how resident information can be used in operations.
Role sharing with electronic approval is unclear
Sometimes the relationship between AI agent outputs and existing electronic approval processes is not organized.
Behavior upon re-execution (prevention of duplicate execution) has not been considered.
In some cases, designs to prevent double updates of resident records or duplicate transmissions when re-executing the same process have not been considered.
Method
Implementation Steps
1. Define the target departments, operations, and resident services
Clearly define the scope of the target departments, operations, and related resident services.
2. Design Agents, Skills, and Tools
Design the roles of Agents necessary for the target operations, the Skills for operational procedures, and the scope of Tools for document management and groupware operations.
3. Define the Tool Policy
Define the operations that the tool is allowed to perform (read/write, Allow/Deny) as a policy. Final updates to resident records should be Denied.
4. Organize data classification and legal basis for resident information
Organize the data classification, purpose of use, and legal basis for the resident information handled, and define the scope of minimal use.
5. Design read/write permissions, inter-departmental sharing, and external transmission
Design access permissions by department and position, the scope of data sharing between departments, and whether external transmission is allowed and the approval conditions.
6. Define the boundary with electronic approvals
Define the boundary where the AI agent’s output is only a draft or candidate, and formal approval is carried out through the existing electronic approval process.
7. Define approvals, division of duties, and escalation
Define approvers for operations requiring human approval, division of duties by department, position, and contractor, and escalation paths to legal, personal information protection, and information security officers.
8. Define logs, audit trails, prevention of duplicate execution, and KPIs
Define the operation logs and input/output records to be stored, design to prevent incorrect updates upon re-execution, and effectiveness measurement KPIs.
Data & Systems
Data and Systems Used
Human-in-the-loop
Where Human Approval Is Required
- Clarify the final approvers for administrative actions, benefits eligibility, and review by position
- Clarify approval conditions for third-party provision or external transmission of resident information
- Obtain confirmation from Legal and Personal Information Protection Officers regarding classification and legal basis of resident information
- Obtain approval from the Information Systems Department for cross-departmental authority granting and data sharing
Measurement
KPI
In the Refine STEP, define candidate KPIs to be verified in Build & Validate
Target level for primary classification time for in-house inquiries
Time target for inquiry classification
Lead time until approval
Time required from draft creation to human approval
Number of detected permission deviations
Number of detected operations exceeding the defined permission scope
Checklist
Requirements definition checklist
- Target departments, tasks, and resident services (including and excluding tasks) are documented
- Input data and outputs (classification proposals, summaries, drafts) are defined
- Data classification, purpose of use, and legal basis for resident information are organized
- Access rights for read and write are defined by department and position
- Scope and approval conditions for inter-departmental sharing and external transmission are defined
- Boundaries with electronic approval are defined
- Approval conditions and approvers for administrative actions, benefits eligibility, and reviews are defined
- Confirmation process with Legal, Personal Information Protection, and Information Security Officers is defined
- The duties of departments, positions, and contractors are defined.
- Designs to prevent duplicate execution and incorrect updates are being considered.
- The scope and retention period for operation logs and input/output records are defined.
- KPIs used for effect measurement are defined
Pitfalls
Common Pitfalls
Postpone authority design.
If you try to adjust permissions after running it first, there will be significant rework when deployed across multiple departments.
Proceed with the approver unclear
Deciding approvers by individual name rather than position will cause operations to stop during transfers or resignations.
Make the boundary with electronic approval ambiguous.
If you do not explicitly deny final updates to resident records and official approvals in the Tool Policy, there is a risk of granting unintended write permissions.
FAQ
Frequently Asked Questions
Which department should lead the requirement definition?
It is recommended that the department responsible for the target business and the information system department take joint leadership. When handling resident information, the personal information protection officer should be involved, and if external transmission is involved, the information security and legal departments should also participate.
How detailed should authority design be?
At a minimum, clarify the read/write scope at the department and position level, as well as the approvers for administrative actions, eligibility for benefits, and reviews. The level of detail should be adjusted according to the risk of the target business.
When handling resident information, is confirmation from the personal information protection officer always required?
The necessity varies depending on the purpose of use, legal basis, data classification, and whether external transmission is involved, but when handling sensitive personal information or when inter-departmental sharing or external transmission is involved, it is strongly recommended to obtain confirmation.
What is prevention of duplicate execution?
It refers to a design where the same process can be executed multiple times without causing duplicate updates to resident records or duplicate notifications. This becomes important for retries in case of communication errors.
Shall we organize requirements, authorities, and approval design together?
The scope of the target business, authority over resident information, approval flows, and responsibility boundaries can be concretized through formal LP consultations.