Step 2 · Refine

Requirements, permissions, and approval design when a municipality-linked NGO introduces Robo Claw

Once the target business is decided, concretize the As-Is/To-Be, target projects, regions, service desks, responsibility boundaries in contracts/agreements with municipalities, inputs/outputs, data classification, personal information/sensitive information, read/write permissions, separation of staff and volunteer authority, human approvals, professional confirmations, logs, and KPIs.

Conclusion

The purpose of the Refine STEP is to document "who will automate which tasks and under what approvals." In particular, at this stage, clarify the classification of personal and sensitive information of support recipients, purpose of use, consent, legal basis, responsibility boundaries with municipalities, and separation of authority among staff, volunteers, and external contractors. If you proceed to the Pilot while these are unclear, redesign in later stages will occur.

Who This Is For

Who This Is For

Targets are business managers, information system personnel (including concurrent roles), consultation support staff, and board members who decided the target business in the Discover STEP.

What You'll Decide

What You'll Decide in This Step

In the Refine STEP, document the scope of the target operations, classification of the data to be handled, connected systems, read/write permissions, approval conditions, responsibility boundaries with the local government, separation of authority between staff and volunteers, and KPIs, and break them down into requirements that can be verified in Build & Validate.

Industry Challenges

Challenges specific to NGOs/NPOs cooperating with local governments

01

Insufficient organization of data classification

In many cases, it has not been clarified which classification consultation records and support records containing personal information and sensitive information belong to, and how far they can be used.

02

Rules for responsibility boundaries with local governments are not yet established

In some cases, the scope of personal information sharing and the approver of reports in commissioned projects and agreements are not clearly documented.

03

Roles of staff and volunteers are unclear

There are cases where operations are being conducted without clearly defined roles for full-time employees, part-time staff, and volunteers.

04

Accountability is unclear

In some cases, it is not clarified who bears the final accountability for results that utilize outputs from AI agents.

Method

Implementation Steps

1. Organize As-Is/To-Be

We organize by comparing the current business flow with the business flow aimed for after the introduction of Robo Claw.

2. Define the target projects, regions, and contact points

Clarify the scope of the target projects, regions, and consultation contact points.

3. Design Agents, Skills, and Tools

Design the roles of Agents required for the target tasks, the Skills for business procedures, and the scope of Tools for system operations.

4. Check data classification, purposes of use, and legal basis

Check whether the input/output data corresponds to personal information or sensitive information, and verify the purpose of use, consent of the individual, and legal basis.

5. Design Tool Policy and permissions

Define as Policy the operations that the Tool is allowed to perform (read/write, Allow/Deny) and whether external transmission is permitted.

6. Confirm responsibility boundaries with local governments

Based on the commissioning specifications and agreements, confirm the data sharing scope and report approval process with the local government personnel.

7. Define the separation of authority between staff and volunteers

Access rights are separated for full-time employees, part-time staff, volunteers, and external contractors.

8. Define human approval and professional escalation

Define approvers for results using outputs and professional escalation destinations when danger assessment, etc., is required.

9. Define logs, retention periods, and KPIs

Define the scope and retention period of operation logs and audit trails, and effectiveness measurement KPIs.

Data & Systems

Data and Systems Used

Counseling records and support records (within the range confirmed for classification) Municipal notifications, consignment specifications, and agreements Grant guidelines and performance data Access rights ledger Document management and cloud storage Mechanism for authority and ID management

Human-in-the-loop

Where Human Approval Is Required

  • Clearly define the reviewers of outputs that lead to acceptance, treatment, and danger assessment of support recipients by role
  • Obtain confirmation from professionals and legal affairs regarding the scope handling personal and sensitive information
  • Clearly define the approvers of outputs involving reporting to municipalities and sending to residents
  • Obtain approval from the project manager for granting permissions that span employees and volunteers

Measurement

KPI

In the Refine STEP, define candidate KPIs to be verified in Build & Validate

Target level for primary classification time of inquiries

Target time required for inquiry classification

Lead time until approval

Time from output creation to human approval

Number of detected permission deviations

Number of detected operations exceeding the defined permission scope

Checklist

Requirements definition checklist

  • The target projects, regions, and service desks (including included tasks and excluded tasks) are documented
  • Input data and outputs (draft summaries, report drafts, classification results) are defined
  • The classification of the data handled (personal information, sensitive information, etc.), purpose of use, consent from the individual, and legal basis are confirmed
  • Access rights for reading and writing are defined separately
  • The division of responsibilities with local governments (data sharing scope and report approval processes) has been confirmed.
  • The separation of authority among staff, volunteers, and external contractors has been defined.
  • Escalation points and flows to specialists have been defined.
  • Responsibility for explaining the use of outputs is defined
  • The scope and retention period for operational logs and audit trails have been defined.
  • KPIs used for effect measurement are defined

Pitfalls

Common Pitfalls

01

Omit checking data classification

If you proceed without confirming data classification, significant rework related to handling personal and sensitive information may occur later.

02

Proceed with the approver unclear

If you determine the approver by individual name rather than position, operations may halt during transfers or retirements.

03

Do not specify the location of the final decision in writing

To prevent AI output from being treated as the final decision, it is necessary to document the division of responsibilities.

FAQ

Frequently Asked Questions

Who should lead requirements definition?

It is recommended that the person responsible for the relevant project and the information systems personnel (including concurrent roles) jointly lead the process, and involve specialists, legal staff, and local government personnel if personal/sensitive information or data transmission to local governments is involved.

How detailed should authority design be?

At a minimum, clarify the read/write scope for each business unit and the approvers for outputs related to the supported individuals. The level of detail should be adjusted according to the risk of the relevant tasks.

How do you confirm the division of responsibilities with local governments?

It is recommended to individually confirm with local government personnel the data sharing scope and report approval processes based on the contents of commission specifications, agreements, and grant guidelines.

Shall we organize requirements, authorities, and approval design together?

The scope of the target operations, data classification, responsibility boundaries with municipalities, authority, and approval flow can be concretized through consultations on the official LP.

Organize introduction requirements, authority, and responsibility division