Skip to content
lagstyr.Register interest

The Lagstyr handbook

  1. For the person who decides
  2. What Lagstyr is for you
  3. Reading your console
  4. What needs your attention
  5. Deciding a proposal
  6. After the decision
  7. Operating the work
  8. Agents and their runs
  9. Governing the company
  10. Access, people and language
  11. For the person who administers
  12. Administering your console
  13. Bringing an agent into service
  14. Defining and promoting action classes
  15. Registering AI systems
  16. Emergency access, passwords and sessions
  17. Sources, structure and the operations index
  18. What this installation connects to
  19. For engineering and DevSecOps
  20. Planning an installation
  21. Installing Lagstyr
  22. Securing your installation
  23. Building and commissioning integrations
  24. Commissioning agents and retrieval
  25. Monitoring and routine operations
  26. Upgrading and managing releases
  27. Backups, restoration and recovery
  28. Responding to incidents
  29. Reference
  30. Glossary

Documentation · The Lagstyr handbook

Governing the company

The Govern section holds the registers that say who may do what, what the company owes, and under what rules. Register rows are authoritative. Anything derived from a clock — a review due, an exception expired — is computed when you load the page and labelled as such.

Authority

Authority shows the matrix of mandates and grants, the approval routes, and the routing gaps: governed skills whose route is missing. A mandate is an explicit grant of authority to a principal over an action, a subject, a legal entity and a value ceiling, within an effective window. Read the warning on the page literally: This register is not an authority oracle. A matching grant being recorded means only that; authority is decided from a real typed proposal, and until one exists no concrete action has been evaluated.

Approval routes also carry the rule about self-approval and may require a fresh, complete conflict disclosure. A route that forbids self-approval is the reason you sometimes cannot decide a proposal you raised; see Deciding a proposal.

Obligations

An obligation is a standing duty with an owner and a date, satisfied only against evidence. Obligations is attention-first: what is overdue comes before what is current. An obligation can be waived, cancelled or escalated, each with evidence, and an effect bound to it never closes it by itself.

Incidents

Incidents is the §10 register of what went wrong: severity, category, status and an accountable owner. It is read-only here — recording and reconciling an incident stays governed — and it lists only what is still live, so a closed incident is not shown. An integration break is owned by an incident, and the inc_ reference on a break leads here, which is where you learn whether anyone is working it.

Conflicts

Conflicts holds declared interests, their assessments and dispositions, and the recusals that followed. A recusal is the removal of a conflicted party from an approval, and Lagstyr applies it. Derived interests are shown beside declared ones and labelled as derived snapshots.

Disclosure is selective, not a universal copy of somebody’s interests into every proposal. An assessment covers the exact proposal, legal entity, subject and counterparty that need a decision; it records whether the statement is positive or “nothing to declare”, whether coverage is complete, and when it expires. A route may impose a shorter freshness window. The kernel refuses an approval when relevant declared or derived interests are not covered, derived coverage is uncertain, or a required assessment is incomplete, stale, expired or for a different scope.

Policies and board resolutions

A policy is a living rule that governs what may happen. Policies shows the instruments in force and, behind each, its immutable version history: a policy changes only by a new version, never by editing the old one. Board resolutions is the register of resolutions and the governed records that descend from each.

Action classes

An action class is the unit of autonomy: a kind of consequential action with its execution mode, its limits on value, rate, time, recipient and destination, its promotion state and its demotion triggers. Action classes lists them, and a class’s own page shows the head, its promoted revision, its limit counters and signal windows, and its pause history. The class head and its promoted revision are authoritative; the counters are operational state; the pauses are the event log. Defining, revising, promoting, demoting, restoring and retiring are governed proposals. Declared triggers pause the class automatically; an operator can also pause it immediately through the audited break-glass ceremony.

AI systems

AI systems is the operating register for the AI your organisation has procured, embedded or built, with each system’s workflow contracts and the standing of its impact assessment. Review-due and reassessment flags are derived from the clock. Registering a system, recording a contract and recording an assessment are each forms that produce a proposal.

Policy exceptions

An exception is a deviation that requires explicit handling and authority. In Lagstyr it is an expiring waiver: every exception has an accountable owner, compensating controls and an expiry, and its effective status is derived from the clock, so an expired one reads expired even while the row says active.

To raise one, open Policy exceptions and choose Grant an exception. The form asks for the entity the exception covers, the policy version it waives, your rationale, the compensating controls one per line, the accountable owner and the expiry, and then for your re-authentication. The button reads Submit for approval, and that is what it does: you are raising a proposal, not granting a waiver. The exception exists once an authorised approver decides it.

Disposing of an exception is the same shape. Close with evidence retires it against proof that the need has passed; Revoke ends the waiver immediately, with a reason. Neither extends its reach. A closed exception says of itself: It is a record now, not a waiver.

Previous chapter Next chapter
lagstyr.
ContactSecurityPrivacyTerms