Documentation · The Lagstyr handbook
Registering AI systems
AI systems is the operating register for the AI your company has procured, embedded or built. Register rows are authoritative. Review-due and reassessment-due flags are derived from the clock when you load the page, and the console prints them as words, overdue and reassessment overdue, never only as a colour.
Registering a system
Register an AI system asks for a stable key, whether the system is procured, embedded or built, its name, the accountable owner, the supplier where there is one, its purpose, its prohibited uses, the data classes it handles and the populations it affects (one per line), and the date its review falls due. Your rationale and password complete it, and it is a proposal.
Revising a system is the same form filled from the current row, with one warning worth reading twice: revision replaces the content whole and returns the system to draft, surrendering approved standing until re-approved. A revision is not an edit. It is a new candidate that has to earn its standing again.
Workflow contracts
A workflow contract binds a system to the action class its workflow executes through, in a named environment: development, test, preproduction or production. It names the owner, the retention policy, the service objectives, the error budget and the operating budget, and the documents that hold the fallback and the runbook, and it carries its own review date. It is registered from the system’s page and it is a proposal.
Impact assessments
An impact assessment records the judgement your organisation has made about a system: the purpose and context, the people affected, the data and the proxies standing in for people, the harms and their likelihood, how affected people get information and human review, and the monitoring plan. The outcome is one of approved, approved with controls, or refused, and every assessment carries the date by which it must be reassessed.
Assessments are append-only. A reassessment names the assessment it supersedes, and a refused reassessment withdraws standing immediately. The assessor is named on the form; the console does not assume it is you.
The lifecycle acts
A system’s page carries two act panels, one for the system and one for its workflow contracts, and each offers the same five verbs: approve, activate, pause, retire, and complete a review. Two notes on those panels govern what the kernel will accept.
- System approval requires a current approving impact assessment; activation is write_kernel and refuses while a review is overdue or an assessment has lapsed.
- Activation binds the workflow’s agent and is a material change, so it carries a measurement contract or a recorded exemption.
Approval may name the approved versions. Pause and retire take a reason. Completing a review names the review evidence document and the next review date. Every act is a proposal, and a refused one returns everything you typed for correction.
What the register does not do
It does not supply your AI inventory, its owners, the impact judgements, the policy text, the risk appetite, the review dates or a regulatory conclusion. The product supplies governed records; your organisation supplies the facts and the accountable decisions. It is not a substitute for a specialist governance suite or an independent auditor, and it does not turn a registered system into a commissioned one.