Twenty People Approved It by Not Questioning It
A Tuesday morning, a comp range, and the failure everyone will call an AI failure.
tldr;
A scenario: an AI recommends a comp range bump, everyone nods, and six months later there’s an equity issue nobody can trace. It’s hypothetical. The gap it exposes is not.
The dangerous tier of AI in your tenant isn’t agents taking action. It’s recommendations that humans rubber-stamp. That’s action with extra steps and the accountability boiled off.
Governance is four named answers before any recommendation stream goes live: who owns the objective, who reviews, how a human challenges it cheaply, and what the rollback is.
Plus one ledger entry every time an accepted recommendation changes a standing number. The system logs the transaction. Somebody has to log the decision.
When it goes wrong, it will not be an AI failure. It will be a governance failure. Those have owners.
Let me give you a Tuesday morning.
Your tenant is running an AI capability that analyzes talent pipeline data and suggests comp range adjustments for open requisitions. This is real functionality. This is the good stuff. This is what the roadmap slide promised.
The agent suggests moving a range from $85K to $105K. Market data, pipeline conversion rates, a tidy confidence figure sitting next to the number.
The recruiter sees it and thinks: cool, the system says so. Adjusts the range.
The hiring manager sees the adjusted range with a system recommendation attached and approves it, because approving things with system recommendations attached is what Tuesday is for.
The comp partner is cc’d and says nothing, because it came from the tool that Finance signed off on last year.
The offer goes out at the new range. The next req in that job family anchors on it. So does the one after that. Every subsequent approver inherits a number that arrived pre-blessed.
Nobody asked: what market data? Which pipeline, over what period? What was the model optimizing for? Time-to-fill, quality of hire, and retention are different targets, they conflict, and the model picked one. Somebody in your organization needs to know which one, and why, and nobody does.
Six months later you have a comp equity issue you cannot trace, because it started with a recommendation that twenty people approved by not questioning it.
That’s not an AI failure.
That’s a governance failure.
The dangerous tier is not the one you think
Everyone’s governance anxiety points at the scary tier: autonomous agents taking action in the tenant. And fine, that tier deserves respect. But it also gets respect. When an agent can execute a business process end to end, people instinctively demand approvals, logging, kill switches. Fear does the governance work for you.
The recommendation tier gets none of that, because recommendations feel safe. A human is “in the loop.” Except here’s what the loop actually looks like: we are phenomenal at deferring to something that sounds confident. Put a percentage next to a number and watch a whole meeting nod like it came down a mountain on a stone tablet. The research on automation bias has been saying this for decades. Your own last vendor demo said it louder.
A recommendation that humans reliably rubber-stamp is an action. It’s an action with extra steps, and the extra steps exist mainly to distribute the accountability until it evaporates. When the agent acts, the agent’s owner answers for it. When twenty people each add a nod, nobody answers for anything. The loop isn’t a control. The loop is a laundering mechanism.
So the question at this tier was never “can the AI do it?” It’s “can the human evaluate it?” And evaluation is a skill your org has to deliberately build and deliberately protect, because the default trajectory of every recommendation stream is toward the Tuesday morning above.
Why you can’t trace it
Notice the specific shape of the damage: not that the number was wrong. The number might have been right! Maybe $105K was correct for that req, that week, that market. The damage is that six months later, nobody can reconstruct why it happened, whether the conditions that justified it still hold, or how far the anchor has drifted through the job family since.
The system logged the transaction. Every click, every approval, timestamped and audit-ready. And none of it helps, because the audit trail records who touched it, not why anyone believed it. If you read the Why Ledger post a few weeks back, you already know where this lands: the what is everywhere and the why is nowhere. An accepted AI recommendation that changes a standing number is exactly the kind of decision that earns a ledger entry. Four lines. What the model claimed, what the human checked, what would have changed the answer. The day the equity question arrives, that entry is the difference between an explanation and an excavation.
Who holds the leash
Here’s the governance model that fits on an index card. Before any AI recommendation stream goes live in your tenant, four questions get answered with names. Not roles. Names.
Who owns the objective? Somebody approved what this model optimizes for, and knows what it trades away. If the answer is “the vendor’s default,” that’s an answer, and it’s a bad one, and now it has an owner anyway.
Who reviews? Not every recommendation, that’s fantasy. A sampling cadence. Somebody pulls ten accepted recommendations a month and interrogates them like they haven’t been pre-blessed.
How does a human say no, cheaply? If challenging the system costs a recruiter an awkward escalation and a reputation for being difficult, nobody will ever challenge the system. The override path has to be cheaper than the nod, or the nod wins every time. This is the question almost every org skips.
What’s the rollback? The model was right in March and wrong in September because the business changed and nobody told the model. Who notices? What’s the drift review? How do you unwind an anchor that’s already propagated through a job family?
Four names, a sampling cadence, a cheap override, a rollback plan, and a ledger entry per accepted change. That’s not a transformation program. That’s a Tuesday afternoon of decisions. You could have it done before the next release drops.
While it’s still hypothetical
Has the comp scenario actually happened? Not in my tenant. Not that I know of, which, if you’ve been paying attention, is exactly the problem: the whole failure mode is designed to be invisible until somebody goes looking.
The agents are coming either way. The recommendations are mostly already here, sitting in your tenant with tidy confidence figures, being nodded at. The dog always sees a squirrel named efficiency, and it just goes. Nobody’s arguing about the dog anymore.
The only open question is the leash, and the best time to answer it is while the scenario is still a scenario. Because the worst time to build a governance model is the Monday morning after you needed one.
— Mike
Director HR Tech | Keeper of the Leash
P.S. Justin’s sand volleyball club has exactly one governance rule: when the ball hopper runs low, everybody goes out and shags balls. Last week, nobody did. Not defiance; everyone just figured someone else had it. Play stopped, and a dozen kids stood on the sand looking at each other over an empty hopper until Coach snapped them out of it. It looked like the Spider-Man meme for a second. A rule assigned to everybody is a rule assigned to nobody. Twelve-year-olds learn this in one afternoon. We build recommendation streams on it.
The Department of First Things First. For the people who do the work.



