Documentation · The Lagstyr handbook
Governing the company
The Govern section holds the registers that say who may do what, what the company owes, and under what rules. Register rows are authoritative. Anything derived from a clock — a review due, an exception expired — is computed when you load the page and labelled as such.
Authority
Authority shows the matrix of mandates and grants, the approval routes, and the routing gaps: governed skills whose route is missing. A mandate is an explicit grant of authority to a principal over an action, a subject, a legal entity and a value ceiling, within an effective window. Read the warning on the page literally: This register is not an authority oracle. A matching grant being recorded means only that; authority is decided from a real typed proposal, and until one exists no concrete action has been evaluated.
Approval routes also carry the rule about self-approval and may require a fresh, complete conflict disclosure. A route that forbids self-approval is the reason you sometimes cannot decide a proposal you raised; see Deciding a proposal.
Obligations
An obligation is a standing duty with an owner and a date, satisfied only against evidence. Obligations is attention-first: what is overdue comes before what is current. An obligation can be waived, cancelled or escalated, each with evidence, and an effect bound to it never closes it by itself.
Incidents
Incidents is the §10 register of what went wrong: severity, category, status and an
accountable owner. It is read-only here — recording and reconciling an incident stays governed —
and it lists only what is still live, so a closed incident is not shown. An integration break is
owned by an incident, and the inc_ reference on a break leads here, which is where you learn
whether anyone is working it.
Conflicts
Conflicts holds declared interests, their assessments and dispositions, and the recusals that followed. A recusal is the removal of a conflicted party from an approval, and Lagstyr applies it. Derived interests are shown beside declared ones and labelled as derived snapshots.
Disclosure is selective, not a universal copy of somebody’s interests into every proposal. An assessment covers the exact proposal, legal entity, subject and counterparty that need a decision; it records whether the statement is positive or “nothing to declare”, whether coverage is complete, and when it expires. A route may impose a shorter freshness window. The kernel refuses an approval when relevant declared or derived interests are not covered, derived coverage is uncertain, or a required assessment is incomplete, stale, expired or for a different scope.
Policies and board resolutions
A policy is a living rule that governs what may happen. Policies shows the instruments in force and, behind each, its immutable version history: a policy changes only by a new version, never by editing the old one. Board resolutions is the register of resolutions and the governed records that descend from each.
Action classes
An action class is the unit of autonomy: a kind of consequential action with its execution mode, its limits on value, rate, time, recipient and destination, its promotion state and its demotion triggers. Action classes lists them, and a class’s own page shows the head, its promoted revision, its limit counters and signal windows, and its pause history. The class head and its promoted revision are authoritative; the counters are operational state; the pauses are the event log. Defining, revising, promoting, demoting, restoring and retiring are governed proposals. Declared triggers pause the class automatically; an operator can also pause it immediately through the audited break-glass ceremony.
AI systems
AI systems is the operating register for the AI your organisation has procured, embedded or built, with each system’s workflow contracts and the standing of its impact assessment. Review-due and reassessment flags are derived from the clock. Registering a system, recording a contract and recording an assessment are each forms that produce a proposal.
Policy exceptions
An exception is a deviation that requires explicit handling and authority. In Lagstyr it is an expiring waiver: every exception has an accountable owner, compensating controls and an expiry, and its effective status is derived from the clock, so an expired one reads expired even while the row says active.
To raise one, open Policy exceptions and choose Grant an exception. The form asks for the entity the exception covers, the policy version it waives, your rationale, the compensating controls one per line, the accountable owner and the expiry, and then for your re-authentication. The button reads Submit for approval, and that is what it does: you are raising a proposal, not granting a waiver. The exception exists once an authorised approver decides it.
Disposing of an exception is the same shape. Close with evidence retires it against proof that the need has passed; Revoke ends the waiver immediately, with a reason. Neither extends its reach. A closed exception says of itself: It is a record now, not a waiver.