Skip to content
lagstyr.Register interest

The Lagstyr handbook

  1. For the person who decides
  2. What Lagstyr is for you
  3. Reading your console
  4. What needs your attention
  5. Deciding a proposal
  6. After the decision
  7. Operating the work
  8. Agents and their runs
  9. Governing the company
  10. Access, people and language
  11. For the person who administers
  12. Administering your console
  13. Bringing an agent into service
  14. Defining and promoting action classes
  15. Registering AI systems
  16. Emergency access, passwords and sessions
  17. Sources, structure and the operations index
  18. What this installation connects to
  19. For engineering and DevSecOps
  20. Planning an installation
  21. Installing Lagstyr
  22. Securing your installation
  23. Building and commissioning integrations
  24. Commissioning agents and retrieval
  25. Monitoring and routine operations
  26. Upgrading and managing releases
  27. Backups, restoration and recovery
  28. Responding to incidents
  29. Reference
  30. Glossary

Documentation · The Lagstyr handbook

Registering AI systems

AI systems is the operating register for the AI your company has procured, embedded or built. Register rows are authoritative. Review-due and reassessment-due flags are derived from the clock when you load the page, and the console prints them as words, overdue and reassessment overdue, never only as a colour.

Registering a system

Register an AI system asks for a stable key, whether the system is procured, embedded or built, its name, the accountable owner, the supplier where there is one, its purpose, its prohibited uses, the data classes it handles and the populations it affects (one per line), and the date its review falls due. Your rationale and password complete it, and it is a proposal.

Revising a system is the same form filled from the current row, with one warning worth reading twice: revision replaces the content whole and returns the system to draft, surrendering approved standing until re-approved. A revision is not an edit. It is a new candidate that has to earn its standing again.

Workflow contracts

A workflow contract binds a system to the action class its workflow executes through, in a named environment: development, test, preproduction or production. It names the owner, the retention policy, the service objectives, the error budget and the operating budget, and the documents that hold the fallback and the runbook, and it carries its own review date. It is registered from the system’s page and it is a proposal.

Impact assessments

An impact assessment records the judgement your organisation has made about a system: the purpose and context, the people affected, the data and the proxies standing in for people, the harms and their likelihood, how affected people get information and human review, and the monitoring plan. The outcome is one of approved, approved with controls, or refused, and every assessment carries the date by which it must be reassessed.

Assessments are append-only. A reassessment names the assessment it supersedes, and a refused reassessment withdraws standing immediately. The assessor is named on the form; the console does not assume it is you.

The lifecycle acts

A system’s page carries two act panels, one for the system and one for its workflow contracts, and each offers the same five verbs: approve, activate, pause, retire, and complete a review. Two notes on those panels govern what the kernel will accept.

  • System approval requires a current approving impact assessment; activation is write_kernel and refuses while a review is overdue or an assessment has lapsed.
  • Activation binds the workflow’s agent and is a material change, so it carries a measurement contract or a recorded exemption.

Approval may name the approved versions. Pause and retire take a reason. Completing a review names the review evidence document and the next review date. Every act is a proposal, and a refused one returns everything you typed for correction.

What the register does not do

It does not supply your AI inventory, its owners, the impact judgements, the policy text, the risk appetite, the review dates or a regulatory conclusion. The product supplies governed records; your organisation supplies the facts and the accountable decisions. It is not a substitute for a specialist governance suite or an independent auditor, and it does not turn a registered system into a commissioned one.

Previous chapter Next chapter
lagstyr.
ContactSecurityPrivacyTerms