Capstone: Run a Sociotechnical Review
LESSON
Capstone: Run a Sociotechnical Review
By the end of this lesson, you will be able to...
Produce a sociotechnical review memo for a concrete design, launch, renewal, governance, monitoring, or repair decision.
Connect system behavior, affected groups, power, encoded values, feedback, distribution, accountability, and exit in one bounded model.
Recommend an action with an owner, evidence, trade-off, monitoring signal, and revision trigger.
Idea in one sentence: A sociotechnical review is complete when it changes a named decision and leaves behind a usable path for ownership, evidence, monitoring, and repair.
Core Insight
The city must decide whether to renew CivicPass, the private platform that now provides identity, notifications, records, and help-chat for several public services. The provider wants a new identity check, per-verification pricing, and a contract that removes an export endpoint.
The renewal meeting has plenty of material:
- the engineering team has an architecture diagram;
- procurement has a cost comparison;
- the vendor has reliability numbers;
- the service department has completion averages;
- community organizations have stories about false flags and inaccessible recovery;
- the legal team has a draft contract.
Each artifact is useful. None answers the whole decision. The city needs one review that makes the coupled mechanism visible and says what must change before renewal.
This capstone turns the track into a reusable artifact: a short review memo plus an action register. The memo is not a moral essay and not a checklist of principles. It is a decision instrument. It should help a person who was not in the room understand:
what the system does -> who is exposed -> how power operates ->
what values and feedback it encodes -> who bears the outcome ->
who owns the response -> what changes next
Start With One Decision
Do not review “the platform” in the abstract. Choose one decision with a boundary and a time window.
For CivicPass:
Should the city renew CivicPass for housing applications under the proposed identity, pricing, and export changes, and what safeguards are required before launch?
This sentence identifies:
- the decision owner: the city program director and procurement authority;
- the system: CivicPass as used in housing access;
- the change: identity, pricing, and export;
- the time: before renewal and launch;
- the possible actions: renew with safeguards, dual-run, renegotiate, pause, or migrate.
A vague question such as “Is CivicPass ethical?” cannot produce a bounded recommendation. A good question tells the reviewer what evidence and authority matter.
The Review Memo Structure
Use these sections in order. The sections are not independent essays. Each one should make the next one more precise.
1. Decision, Promise, and Scope
State the public or user promise under review. For CivicPass:
Residents should be able to apply for housing support through a reliable, accessible, contestable service while the city protects limited program capacity and private records.
State what is inside the boundary:
- CivicPass identity and risk controls;
- housing application, notification, document, and appeal flows;
- city staff, provider staff, community organizations, and residents;
- contract, pricing, export, staffing, and policy constraints.
State what is outside for this decision. For example, do not attempt to review every CivicPass service or the entire city's housing policy. An explicit exclusion prevents scope from expanding until no decision can be made.
2. Coupled System Model
Describe what changes, waits, decides, and produces evidence. A compact sketch is enough if the arrows are meaningful:
resident submits application
-> CivicPass identity default and risk check
-> portal status and queue assignment
-> caseworker or vendor review
-> approval, delay, closure, or appeal
-> dashboard and contract metrics
-> renewal, rule change, or repair decision
Add the human and institutional parts that the component diagram would omit. The model should show where a technical state becomes a public consequence and where a metric or contract changes the next behavior.
3. Stakeholders, Exposure, and Power
Use the map from lesson 002. Do not merely list the buyer and builder.
| Group | Exposure | Benefit / harm | Agency | Decision rights | Missing-voice risk |
|---|---|---|---|---|---|
| Residents with stable records | High | Faster access; some privacy and lock-in cost | Can use normal path or seek help | Very low | Successful cases dominate evidence |
| Residents with unstable records or access | Very high | May be delayed, flagged, or excluded | Low; depends on advocates | None | Their absence looks like low demand |
| Caseworkers | Medium | Shared tools and lower duplication; workload and metric pressure | Can interpret and escalate | Low to medium | Workarounds remain hidden |
| Community organizations | High visibility into harm | Help residents; absorb unpaid repair work | Can surface patterns and public pressure | None formally | Knowledge may be extracted without support |
| City program owner | Medium | Reach and continuity; political and legal risk | Can set safeguards and budget | High | May defer to provider expertise |
| CivicPass provider | Medium direct, high system influence | Revenue, data, and platform expansion | Controls code, defaults, and exports | High for technical controls | Commercial metrics crowd out public outcomes |
Explain the asymmetry. The provider and city can change the system. Residents must live with the result and may not be able to leave. That difference should influence participation, evidence, appeal, and repair requirements.
4. Encoded Values and Control Surfaces
Use lesson 003 to inspect ordinary choices:
| Control | Encoded pressure | Who pays if it fails? | Review question |
|---|---|---|---|
| Identity check as default | Fraud prevention and speed | People with unusual records or limited access | Is the assisted path equally visible and usable? |
| Proprietary risk label | Administrative efficiency and provider authority | Applicants who cannot understand or contest a flag | What explanation and human review are available? |
| Per-verification pricing | Cost control and provider revenue | City budget or residents if access is rationed | Does pricing create a new access threshold? |
| Export deprecation | Provider simplicity and lock-in | City continuity and future residents | Can the city migrate with meaning and history intact? |
Resolved metric |
Throughput and reputational success | Applicants whose cases close without support | Which outcome and distribution signals must accompany it? |
Do not claim that a control is harmful only because a value is present. State what improves, what burden appears, and what evidence would reveal the boundary.
5. Feedback, Adaptation, and Delays
Use lesson 004 to trace at least one loop. For CivicPass:
more agencies adopt CivicPass
-> shared account becomes more convenient
-> more residents depend on one identity path
-> provider gains data and bargaining leverage
-> city tolerates opaque changes to avoid disruption
-> more agencies adopt the platform
Add one delayed failure:
new risk check -> false flags -> manual queue grows -> appeals wait
-> residents seek community help -> workaround effort rises
-> city sees lower duplicate rate but misses recovery cost
Name an observation that could weaken the loop. For example, a tested export may show that migration is easier than expected, or group-level recovery may show that the new check does not create a meaningful access gap. A model is a working hypothesis, not a story that explains every result after launch.
6. Safety, Equity, and Distribution
Use lesson 006's distributional grid. Compare at least two options:
| Option | Protected outcome | Burden | Reversibility | Evidence needed |
|---|---|---|---|---|
| Renew unchanged | Continuity and low duplicate effort | Opaque flags, lock-in, weak exit | Low | Not enough; existing gaps remain |
| Renew with safeguards | Continuity plus bounded risk controls | Contract and monitoring cost | Medium to high if export and dual path are funded | False flags, access, appeals, price, migration tests |
| Dual-run and prepare migration | Exit readiness and contestability | Duplicate operations and budget | High | Service continuity and resident outcomes during transition |
State who receives each benefit and who bears each burden. If the review cannot identify the group, it is still too abstract.
7. Governance, Accountability, and Repair
Use lesson 005's accountability chain:
outcome -> evidence -> owner -> challenge -> decision -> repair -> verification
Turn it into two action rows:
| Control | Owner | Evidence | Challenge | Repair | Trigger |
|---|---|---|---|---|---|
| CivicPass risk flag | City service owner with provider obligation | Model/version, reason code, false flags, wait, appeals | Resident human review within two days | Reopen case, correct flag, review threshold | False flags or recovery delay cross group threshold |
| Export and continuity | Procurement authority and platform owner | Export completeness, migration test, outage exercise | Public escalation and contract remedy | Restore endpoint, fund dual path, or initiate migration | Export fails or provider change threatens access |
The provider can perform technical work without becoming the sole accountable actor. Public authority still needs to own the service promise and the response to affected residents.
8. Recommendation and Action Register
End with a bounded recommendation. For example:
Renew for one year only if the provider preserves a tested export, exposes reason codes for consequential flags, funds a human appeal path, accepts change-control limits, and supports a dual-run migration exercise. Pause expansion if false flags or recovery delays cross the agreed threshold.
Then list actions:
| Action | Owner | Evidence of completion | Deadline | Review trigger |
|---|---|---|---|---|
| Publish identity-check reason categories | Provider + city service owner | Resident-readable reason and appeal test | Before launch | Appeals cannot identify what to correct |
| Test complete export and restore | Platform engineering | Migration and continuity exercise | Before renewal | Missing identifiers or history |
| Fund assisted verification | Service supervisor | Staff capacity and response-time report | Before launch | Manual queue exceeds target |
| Add group-level monitoring | Analytics owner | Outcome, delay, false flag, appeal dashboard | Monthly | Access gap or silent exit rises |
| Review contract change authority | Procurement authority | Approved change-control clause | Before renewal | Unilateral default or pricing change |
The action register is the part that prevents the memo from ending in principles with no owner.
Worked Example: A Decision in One Page
If the memo must be shortened, preserve these lines:
Decision: renew CivicPass for one year under safeguards, not unchanged.
Promise: reliable and contestable housing access while protecting program capacity.
Main risk: platform dependency lets opaque identity controls shift delay and repair work to residents.
Evidence gap: provider reason codes and tested export are missing.
Recommendation: require reason codes, human appeal, export, change control, and dual-run exercise.
Owner: city service owner for resident outcomes; procurement authority for contract; provider for controls.
Trigger: pause expansion if false flags, recovery delay, or access gaps exceed threshold for two review periods.
Residual risk: safeguards cost money and may not prevent every provider failure or future lock-in.
This is a synthesis because every line refers to a tool from the track. It does not introduce a new ethical theory. It makes a decision inspectable and revisable.
Common Failure Modes
The warehouse memo
It contains every possible stakeholder, metric, and risk but never identifies the decision. Reduce the boundary until the memo can recommend an action.
The moral verdict
It labels a platform fair or unfair without tracing a control, group, mechanism, or evidence. Replace the verdict with a claim that could be checked.
The average-only report
It reports uptime, completion, cost, or fraud reduction without distribution, appeals, recovery, or exit. Pair aggregate signals with group-level and repair signals.
The ownerless action list
It says “improve transparency” or “monitor equity” without an actor, deadline, evidence, or trigger. Convert each principle into an action register row.
The impossible certainty claim
It predicts every consequence or treats uncertainty as a reason to do nothing. State the model, uncertainty, falsifying evidence, and reversible next step.
Check Your Understanding
Check: A review says, “CivicPass creates unacceptable lock-in,” but names no dependency, exit cost, affected group, or decision. What is the first repair?
Think first, then reveal.
Answer: Bound the claim. Identify the essential outcome, the technical, economic, institutional, or social dependency, who bears the exit cost, and which renewal or migration decision the evidence should change.
Check: A memo recommends “more transparency” and “better monitoring.” What must be added before the recommendations are operational?
Think first, then reveal.
Answer: Name the control, owner, evidence, deadline, affected group, review trigger, and repair or rollback action. Otherwise the memo ends as a principle list.
Capstone Assignment
Choose a real or realistic technological system. Good candidates include:
- a public-benefits portal;
- a school enrollment or attendance system;
- a workplace scheduling or performance platform;
- a tenant-maintenance or housing platform;
- an identity, moderation, recommendation, or safety-control system;
- a private platform that has become essential infrastructure.
Write a sociotechnical review memo of 1,500–2,500 words plus an action register. The memo must state one decision under review and include:
- promise, scope, exclusions, and decision owner;
- coupled-system model with one worked trace;
- stakeholder and power map with a missing voice;
- encoded value in a default, threshold, metric, label, ranking, or friction point;
- feedback loop, adaptation, delayed effect, and falsifying signal;
- safety, equity, distribution, consent or notice, and reversibility analysis;
- governance, accountability, audit, contestability, and repair path;
- at least two options with explicit trade-offs;
- bounded recommendation and action register with owners, evidence, deadlines, and triggers;
- residual uncertainty and what would cause revision, pause, rollback, or migration.
Capstone Rubric
Score each dimension from 0 to 3:
- Decision boundary: 0 = topic only; 1 = decision named but broad; 2 = bounded decision and scope; 3 = clear promise, exclusions, owner, and time window.
- Mechanism: 0 = summary; 1 = components listed; 2 = trace with intermediate state; 3 = trace connects technical, human, institutional, and metric changes.
- Power and distribution: 0 = generic users; 1 = stakeholder list; 2 = exposure and power separated; 3 = missing voice, burden distribution, and recovery are evidenced.
- Values and feedback: 0 = principles only; 1 = one control named; 2 = encoded value and loop described; 3 = delayed adaptation and falsifying signal change the recommendation.
- Governance and repair: 0 = policy slogan; 1 = owner named; 2 = evidence and appeal path; 3 = accountability chain, individual/systemic repair, and verification are actionable.
- Trade-off and action: 0 = one preferred answer; 1 = costs mentioned; 2 = alternatives compared; 3 = bounded recommendation with residual risk, owners, triggers, and exit or rollback.
A strong capstone scores at least 2 on every dimension and 3 on mechanism, power/distribution, and governance/repair. A high total cannot compensate for an ownerless repair path.
Resources
- [BOOK] Design Justice - Use it to test whether the memo includes affected groups, power, and meaningful participation.
- [BOOK] Thinking in Systems - Reuse it for boundaries, feedback, delays, and intervention points.
- [BOOK] The Alignment Problem - Use it to question whether system objectives still represent the human outcome.
- [ARTICLE] Value Sensitive Design - Use it to connect stakeholders and values to concrete design controls.
Key Takeaways
- The capstone is a decision artifact, not a catalogue of ethical vocabulary.
- A complete review connects behavior, stakeholders, power, values, feedback, distribution, governance, repair, and exit.
- The recommendation must be bounded, evidence-backed, owned, and revisable.
- An action register turns principles into changes with deadlines and triggers.
- Residual uncertainty is acceptable when the system has a monitoring, appeal, rollback, or migration path.
← Back to Sociotechnical Systems, Ethics, and Technology