Step 2 · Refine

Requirements, Permissions, and Approval Design for GovTech Startups Deploying Robo Claw

For the target workflows selected in Discover, define the scope of target municipalities, departments, and programs; classify the data handled; specify connected systems, read and write permissions, approval conditions, responsibility boundaries among municipalities, startups, and subcontractors; and establish KPIs. The purpose of this step is to keep the design within a scope that a small team can maintain while clearly separating administrative actions, benefit, eligibility, and identity-verification decisions from AI outputs.

Who This Is For

Who This Is For

It is aimed at product managers, government sales and local government sales representatives, information security personnel, personal information protection personnel, and legal personnel who have determined the target business in Discover step.

What You'll Decide

What You'll Decide in This Step

In Refine step, we document the scope of the target local government, department, system, and resident contact points, the classification of the data to be handled, the system to be connected, read/write authority, approval conditions, the responsibility of the local government, startup, and subcontractor, and KPIs.

Industry Challenges

Challenges Specific to GovTech Startups

01

Inadequate organization of data classification

There are many cases where residents' information and consideration information are not organized according to which category they belong to and how far they are available.

02

Responsibility Boundaries Among Municipalities, Startups, and Subcontractors Are Not Defined

In some cases, the scope of information sharing and approvers are not specified in contracts or specifications.

03

Requirements and styles vary by municipality

Even in the same business, the requirements and forms required by each local government are different, and it is difficult to fall into the definition of common requirements.

04

Accountability is unclear

In some cases, it is not clear who will ultimately be held accountable for the results of using the AI agent's output.

Method

Implementation Steps

1. Organize As-Is/To-Be

Compare and organize the current workflow with the workflow you aim to achieve after the introduction of Robo Claw.

2. Define the target local government, department, system, and resident contact points

Clarify the scope of the target municipality, department, system, and resident contact points (inquiries, applications, reservations, etc.).

3. Design Agent/Skill/Tool

Design the range of Agent roles, Business Procedure Skills, and System Operations Tools required for the job.

4. Confirm the handling of resident information, identity verification information, and consideration required information

Organize the source of each information, how to update it, and how to check its accuracy.

5. Confirm the purpose of use, legal basis, and consent of personal and sensitive information

We will handle residents' personal information and considerate information, or confirm the purpose of use, personal consent, and legal basis.

6. Design Tool Policy and read and write permissions

Define the operations that the Tool may perform (Read/Write, Allow/Deny) and whether external transmission/resident information can be updated as a policy.

7. Confirm separation from benefits, eligibility, and identity verification decisions

Check whether the determination of benefits, qualifications, and identity verification is designed to go through the confirmation of the person in charge of the local government and the department in charge.

8. Confirm separation from application approval/rejection/resident information update

Check if the design is approved by the local government to approve/reject the application or update the resident record.

9. Confirm the contract, procurement, and handling of specific personal information

Confirm whether specific personal information such as contracts, procurement, and expenditures are confirmed and handled separately from the scope of automation of AI.

10. Confirm Responsibility Boundaries Among Municipalities, Startups, and Subcontractors

Confirm the scope of data sharing and approval processes with municipal representatives based on contracts and specifications.

11. Define People Approval/Responsibility Check

Define the approver of the result using the output and the escalation destination to the department in charge when it is necessary to determine benefits, qualifications, and identity verification.

12. Define logs, retention period, double execution/duplicate application processing prevention, and KPIs

Define the storage range and storage period of the operation log and audit trail, measures to prevent double execution, duplicate application processing and erroneous transmission, and effect measurement KPIs.

Data & Systems

Data and Systems Used

Resident information (confirmed classification range) Identity verification information/consideration information Local Government Requirements and Specifications Contracting and Procurement Information Demonstration Project Records Access Permission Ledger Inquiry management/application reception management system How Permissions and Identity Management Works

Human-in-the-loop

Where Human Approval Is Required

  • Clarify the confirmer of the output leading to the determination of benefits, qualifications, and identity verification on a role-by-role basis
  • Obtain confirmation from the person in charge of personal information protection and the department in charge regarding the scope of handling personal information and information requiring consideration
  • Clarify the approvers of the output with important notices to residents and local government officials
  • Obtain project-owner approval for access grants that span startups, municipalities, and subcontractors

Measurement

KPI

Refine step defines a candidate KPI to be validated in Build & Validate.

Contact Primary Classification Time Target Level

Contact primary classification time goal

Lead time to approval

Time from output creation to human approval

Number of detected deviations/duplicate application processing candidates

Number of operations that exceeded the defined scope of authority and duplicate application processing candidates detected

Checklist

Requirement definition checklist

  • Target local governments, departments, systems, and resident contact points (including and excluding work) are documented
  • Input data and outputs (response proposal, report proposal, missing item candidate, etc.) are defined
  • The classification of the data handled (resident information, personal information, consideration required information, identity verification information, etc.) and the purpose of use, identity consent, legal basis have been confirmed
  • Read/Write permissions are defined
  • Responsibility boundaries among municipalities, startups, and subcontractors, including data-sharing scope and approval processes, are confirmed
  • The handling of specific personal information such as My Number (excluded or strictly separated) is defined
  • The escalation destination and flow to the local government department/information policy/security/personal information protection personnel are defined
  • Location of accountability for output usage results is defined
  • The storage range and storage period of operation logs and audit trails are defined, and measures to prevent double execution, duplicate application processing, and erroneous transmission are defined.
  • KPIs used to measure effectiveness are defined

Pitfalls

Common Pitfalls

01

Bypass data classification confirmation

If you proceed without confirming the data classification, there will be a serious rework related to the handling of residents' personal information and considerate information later.

02

Approver remains ambiguous

If you decide the approver by personal name instead of title, it will cause the operation to stop at the time of transfer or change of responsibility.

03

Does not specify the location of the final decision

It is necessary to clarify the boundaries of responsibility so that the output of AI is not treated as an administrative disposition, benefit, or qualification judgment.

FAQ

Frequently Asked Questions

Who should participate in the requirements definition?

We recommend that the Product Owner, Information Security Officer, Privacy Officer, and Legal Officer participate as a minimum. Issues related to the boundary of responsibility with the local government must also be confirmed with the person in charge of the local government.

What is Tool Policy?

It is a rule that clarifies the operation range that the Tool may execute (read/write, whether external transmission is allowed, whether resident information update process is allowed, etc.). Robo Claw designs Tool Policies for each job.

How detailed should permission separation be?

At a minimum, we recommend separating permissions across three groups: within the startup, municipal representatives, and subcontractors. When the number of municipalities served grows, also consider separation by municipality and department.

Should specific personal information such as my number be included in the requirements?

We recommend not including it in your initial rollout. Designed with strict segregation and individual review by a professional or local authority.

Why not organize requirements, authority, and approval designs together?

You can confirm the target local government, department, data classification, responsibility demarcation, and approval system, and discuss the requirements definition with the official LP.

Consult requirements definition