AI Governance Memo
Reviewed: 2026-07-22 · Canon: generation 8, effective 2026-07-21
TL;DR: the doctrine is non-negotiable. AI compresses the work. Source systems prove the facts. Humans make every credentialing, privileging, hiring, and clinical decision. Agents are the labor layer, never the judge. Every agent action is designed to be typed, budgeted, logged, and replayable, and every regulated decision binds to a named human with the exact evidence and policy versions in front of them. This memo states what the agents may do, what they may never do, and the legal posture that governs the recruiting surface.
1. The doctrine
Rōvn does the work. They approve.
Three failure modes the doctrine prevents:
- AI-decides framing. "AI approves clinicians" is a procurement red flag and a regulatory boundary violation. AI has no standing to grant a privilege or attest a primary-source verification. We never frame it that way.
- Source-substitute framing. AI extraction is not verification. Sources prove facts. The distinction is the regulatory boundary, and it is enforced in the evidence-class model below.
- Human-removed framing. Credentialing committees and named approvers are non-negotiable. AI never auto-rejects; the rule is score the packet, not the person.
2. What agents may do
Per canon section 19, agents may:
- detect risk and open or update Resolution Cases;
- request missing evidence and chase workers and organizations;
- extract and reconcile documents;
- perform allowed source checks and preserve receipts;
- draft communications for human approval;
- prepare files, explain gaps, and compute impact;
- monitor expirations and changes;
- prepare recommendations and version-bound external actions.
3. What agents may never do
- invent evidence, or mark uploaded evidence source-verified;
- independently hire, reject, credential, privilege, assign, or schedule;
- make an adverse action;
- exceed consent or cross tenant boundaries;
- silently fall back to an unapproved model or tool;
- mutate regulated state outside typed domain commands and approval gates.
4. Three-party architecture
| Party | Authority |
|---|---|
| Worker Agent | Acts only for the worker, under explicit consent and standing preferences |
| Organization Workforce Agent | Operates only from organization-authored policy and delegated authority |
| Neutral Rōvn Trust Layer | Enforces identity, consent, scope, policy, provenance, tenant isolation, human gates, disputes, and receipts |
The experience may feel like two agents coordinating. The legal and technical authority is deliberately asymmetric, and the trust layer is the referee.
5. Evidence classes: how AI output is labeled
Every evidence item carries an honest class label at every moment, and labels never silently upgrade:
| Class | Meaning | Who produces it |
|---|---|---|
| Imported | Ingested from an upload or external feed | System intake |
| Worker-attested | Affirmed by the worker | Worker |
| Extracted, unconfirmed | AI-extracted structured fields awaiting confirmation | AI, with human confirmation pending |
| Source-verified | A primary source returned a matching record, with a preserved receipt | The source, never the AI |
| Approved | A named human approved for a specific organization and context | The named human |
Imported or uploaded evidence never becomes source-verified merely because it entered Rōvn, and no AI step can produce the source-verified or approved classes.
6. Agent runtime controls
The agent control plane is designed with:
- durable workflow cases and steps;
- typed tool calls with budgets and rate limits;
- model and prompt versioning, with no silent fallback to unapproved models;
- separation of duties and least-privilege credentials;
- PHI classification on every payload;
- approval tasks for anything that crosses a human gate;
- idempotency, replay safety, and dead-letter recovery;
- complete trace records so any agent action can be reconstructed.
Provider posture. Anthropic-first is a routing choice, not a hard dependency; the runtime is model-agnostic. The investor-room agent on this site runs Gemini 2.5 Flash on Vertex AI, pinned to the hash-verified canon. PHI or regulated data may reach any provider only after the contractual, configuration, minimization, and logging gates are satisfied.
No specialist-model claim. Rōvn does not claim a proprietary model accuracy advantage. That claim requires a held-out evaluation set, a frontier-model baseline, and a CTO-confirmed measured delta. Until that evidence exists, the AI moat is prospective and is stated that way.
7. Employment-law posture for the recruiting surface
This is the corrected legal premise, stated in full because it governs the recruiting agent design:
- "No placement fee" defeats the state employment-agency licensing theory, because most state statutes are fee-gated.
- It is legally irrelevant to the Title VII "employment agency" theory. Section 701(c) has no fee element; a free employment agency is still one.
- The Title VII answer is a different stack: explicit worker opt-in before any agent-initiated contact; a protected-class allow-list enforced at the schema layer so prohibited attributes cannot enter ranking; human-authored, job-relevant requirements only; a four-fifths-rule bias audit run and published before any ranking or agent-contact surface ships; and a human decision on every contact.
Every legal position in this memo is a recommended default pending counsel review (Jason Acevedo, Klehr Harrison), never settled advice. Agent-initiated opportunity contact does not ship until the counsel opinion, the schema-layer allow-list, and the published bias audit are all in place.
8. Consent
- Consent is purpose-specific, recipient-specific where required, revocable, and receipted.
- An agent may never exceed the consent grant that authorizes it.
- A dispute can suspend or qualify downstream use of the disputed evidence.
- Disclosure history is worker-inspectable.
9. Honest current state
- Agent workflows and the provider architecture are designed and partly implemented; current-capability claims require the exact deployed endpoint, evaluation results, and data controls per canon section 42.
- The deployed environment runs synthetic data only. No agent has contacted a real worker or operated on real PHI.
- The investor-room agent is live on this site and is the currently proven AI surface: same-origin, canon-pinned, with deterministic fallback.
10. Why the doctrine wins
- Procurement-safe by design. A hospital General Counsel can read every line of this memo and sign. Vendors marketing autonomous hiring or AI-verified credentials get flagged; governed labor with named-human decisions gets approved.
- Auditable by replay. Every agent action is designed to write a trace; every fact carries an evidence class; every regulated decision binds to a named human.
- Honest about the boundary. We never claim AI does what it cannot. That discipline is what keeps the AI story durable while the market's overclaims get flagged out of healthcare procurement.
End of AI governance memo.