Co-Designing & Pursuing Purposeful AI

Worked example

One group's complete run, from first note to signed commitment.

The problem below is not one of the eight on the slate, so no answer here fits your station. The four people are invented, and their wording is not a standard to match. Read it for the shape: how a group captures a note, how three candidates become one statement, and what a commitment looks like once it carries a price and a trigger.

  • Not on the slate
  • Names are illustrative
  • Read only

Diverge · problem · 0:22–0:42 · 20 minutes

Discover

AI light

What they captured

Each note carries the card it came from. Their own note means the group wrote it without a prompt.

Card 1

Skeptic went at the framing first. We call this a code quality problem. Everything we listed was a review capacity problem.

Priya N.
Card 1

Prototypes were never the complaint. The complaint starts the week something has to be maintained and defended.

Marcus O.
Card 2

Downstream: whoever gets paged at 2am for a service nobody in the building wrote by hand.

Dana L.
Card 2

Also downstream: the client security questionnaire. It asks who reviewed the change. We have no answer we would put in writing.

Colin W.
Card 3

2034 if nobody fixes it: eight more years of systems that run fine until they do not, and nobody left who can read them.

Priya N.
Card 4

Fair question back: should we frame it as a developer problem at all. We removed the friction on purpose, and the tool is doing what we asked.

Marcus O.
Their own note

Ours, not the prompt: whoever slows down to check gets called the blocker. That is half the problem in one sentence.

Dana L.

Converge · problem · 0:42–0:52 · 10 minutes

Define

AI active

What they captured

Card 5

Three clusters came back: review capacity, ownership after handoff, and briefs too vague to build from.

Colin W.
Card 5

The clustering kept the one-person note instead of averaging it away: the model forgets the project, and we never wrote the project down anywhere it could read.

Priya N.
Card 6

Gate caught that our first draft named nobody. The organization cannot own anything.

Dana L.
Card 6

Second draft covered every system we run. We bounded it to the services that touch customer data.

Marcus O.

The three statements they drafted

  1. Set aside

    Our teams ship AI-assisted changes faster than two reviewers can read them, so code reaches production that nobody has examined.

  2. Chosen

    When AI-assisted work reaches production, no named person can say who reviewed it or what the agent was allowed to reach, and whoever inherits it learns during an incident.

  3. Set aside

    Vague requirements produce confident, wrong code, and we do not find out until a customer does.

Why this one. The first is true and too narrow. The third sits upstream of anyone in this group. The second names who is missing and can be checked today.

The four-lens gate on the statement

The Skeptic
Asked what we assume review catches. Our approval is a signature, not a reading, so we stopped calling review a control.
The Systems Thinker
Named who we missed: the platform group, who issue the credentials the agents run on. They set the blast radius and were nowhere in this conversation.
The Futurist
Asked whether this is still the problem in five years. Yes, and bigger: the volume climbs while the people who can read the code retire out.
The Responsible Innovator
Asked whether framing this as a developer problem is fair. It is not. The exposure lands on the least experienced people, so the statement names the service, not the coder.

Diverge · solution · 0:52–1:14 · 22 minutes

Develop

AI light

What they captured

Card 7

At scale every service has an agent. The question stops being how much code it writes and becomes what it is allowed to touch.

Priya N.
Card 7

If it worked: a reviewer reads the four changes that carry risk instead of skimming all forty.

Marcus O.
Card 8

The trustworthy version keeps a refusal in it: the accountable person can still stop the release. An advisory gate is not a gate.

Dana L.
Card 8

Most exposed if we get it wrong: the junior developer, whose name is on the release. Give them something to point at when they say no.

Colin W.
Card 9

Where it breaks: a second model checking the first is theatre unless we tell it to attack the code. Asked for a summary, it approves everything.

Priya N.
Card 10

Shaped like ours: batch release in pharma. Nothing leaves without a named person signing, and slow is the point.

Marcus O.
Their own note

Ours: tier it by blast radius. Read-only agents run loose; anything that can write to customer data stops at a human.

Dana L.

Converge · solution · 1:14–1:24 · 10 minutes

Deliver

AI active

What they captured

Card 11

Clustered to three directions. Two of them need the platform group, which none of us control, and that shaped the choice.

Colin W.
Card 11

The pair it implies: our platform group with a university software engineering lab that already studies how review works.

Priya N.
Card 12

Gate asked what fails in the first 90 days. The exception path becomes the normal path. So every override gets logged with a name on it.

Marcus O.
Card 12

One direction we can staff beats three we cannot.

Dana L.

The directions they clustered

  1. Chosen

    Hard gate under the agent

    Deterministic checks the agent cannot talk its way past, run before anything merges. Twelve months: build it, then hold the line on exceptions.

  2. Set aside

    Scoped credentials per service

    Each agent gets its own narrow permissions, so we fix the blast radius before anyone writes the code. Needs the platform group to own it.

  3. Set aside

    Review tiered by blast radius

    Read-only work moves at speed; changes that touch customer data stop at a named human. Needs the gate underneath it first.

Why this one. The gate is the one piece we can build without anyone’s permission, and the tiering rides on top of it once it exists.

The four-lens gate on the direction

The Skeptic
First 90 days: a deadline lands, someone needs an exception, and the exception becomes the route everyone takes. Every override gets a name attached.
The Systems Thinker
The platform group again. They own the credentials the gate depends on, so they join the pilot rather than hear about it afterwards.
The Futurist
At scale the gate becomes the standard. Whatever we hard-code into it is what the next hundred services inherit, so keep the rules few and readable.
The Responsible Innovator
Because we can, should we: this makes developers slower on purpose. We say that out loud, and we measure the gate on what it catches, not on how little it delays.

Commit · 1:24–1:42 · 18 minutes

Commit

Dark

After Card 12, the AI Dial goes dark. The commitment is made human to human.

This group signed two commitments rather than one, and split the work between the pairs who could do it. Each one carries its price and the event that starts the clock.

When the payments rewrite kicks off in October, we will put a deterministic pre-merge gate under every coding agent that touches customer data, so that our two reviewers can spend their time on the changes that carry risk, by March 2027.

The price
Two engineering weeks to build it, and a slower first month while teams find out what it blocks.
The trigger
The payments rewrite kickoff on 6 October.

Priya N. and Marcus O.

When the next client security questionnaire arrives, we will publish a standing record of who reviewed each AI-assisted release and what the agent could reach, so that the team inheriting a service can name its owner before an incident, by January 2027.

The price
One person’s Friday afternoon every week, and a first report that shows how many services have no named reviewer.
The trigger
The next client security questionnaire.

Dana L. and Colin W.

Priya N., Marcus O., Dana L. and Colin W. are invented for this example. No participant is named on this page.

Back to the problem groups