Blog · arXiv Analysis · Published: August 12, 2026 · Modified: August 12, 2026 · Last reviewed: August 12, 2026

The Register Entry Becomes the Missing System Map

A public register can name an algorithm while leaving the relationships that govern error, oversight, complaint, and repair out of view.

Participatory mapping can expose those missing relations, but the map also inherits the boundaries, participants, and vocabulary of the process that made it.

The Paper

The source is Íñigo de Troya, Maurus Enbergs, Neelke Doorn, and Roel Dobbe's Co-constructing sociotechnical AI governance: participatory system mapping using algorithm registers, arXiv:2608.12166v1 [cs.CY], cross-listed in cs.AI and eess.SY and submitted August 12, 2026. The 16-page, CC BY 4.0 paper lists TU Delft as the authors' affiliation. Its case is not a generative model or a learned classifier. Avola is described as a no-code business-rule engine that codifies welfare-eligibility law and supports, rather than formally replaces, municipal caseworkers' decisions.

The paper identifies its name for the city as fictitious. That restraint matters: the study examines one listed system and its governance without inviting readers to reverse-engineer an unnamed municipality from contextual clues.

The Seed Record

The case-study section says the register entry already named datasets, legal provisions, caseworker discretion, complaint and information-request routes, and the existence of data-protection and fundamental-rights assessments. This is more than a bare software inventory. Yet it mostly presents components and assurances. It does not automatically show how an outdated record reaches a caseworker, how workload can shape an override, whether complaints are aggregated into maintenance signals, or what evidence an ombudsman receives when reviewing a contested decision.

The Dutch government's current register description says the register is meant to make systems discoverable and understandable and to strengthen public accountability. The paper asks what extra structure is needed for those aims to become usable rather than declarative.

Six Maps, Not One Public

The study has five stages: interviews, a preliminary map, a brainstorming workshop, participatory mapping, and an author-conducted System-Theoretic Process Analysis (STPA). Its eight participants were four municipal staff members, two municipal-ombudsman researchers, and one adviser from each of two civil-society organisations. Six of the eight joined the mapping stage.

In two three-hour workshops, participants annotated an author-made seed map derived from the register, internal material including a fundamental-rights assessment, municipal interviews, and public documentation. Each produced a map; the authors combined the six. Civil-society participants emphasized assessment provenance, incident reports, developer accountability, and additional routes for challenge. Municipal staff added political and reporting relationships. Ombudsman staff added support organisations but also questioned whether a systems diagram could represent the human experience of a benefit decision.

The Hazards Live Between Boxes

The STPA moves from a list of safeguards to possible control failures. Its loss scenarios connect technical data problems to caseworker reliance, complaint handling, ombudsman review, vendor maintenance, risk documentation, political oversight, and courts. The analysis names three broad potential losses: wrongful denial of eligibility, deterioration in system performance, and inability to contest a decision.

These are not observed incidents. They are prospective hazards produced by the analysts from documents, workshops, interviews, and the combined map. That distinction is essential. A register saying that human discretion exists does not prove automation bias occurred; a missing performance metric does not prove the rules engine failed. The paper's contribution is to make plausible failure paths inspectable so an institution can ask what evidence would confirm, prevent, or repair them.

Participation Has a Boundary

The label participatory should not be expanded beyond the participant table. The study did not enroll welfare applicants, frontline caseworkers, or the system developer. The external participants were intermediaries: ombudsman researchers and civil-society advisers selected for governance expertise and experience with public impacts. That is a defensible design for probing a register, but it does not substitute for lived accounts of application, refusal, appeal, or correction.

It also means the study's N=8 is not a representative survey. It is a small, single-case inquiry whose value lies in contrasting situated forms of expertise, not estimating how Dutch residents understand algorithm registers.

The Map Has Politics

The discussion is strongest when it turns the method back on itself. The authors chose STPA, drew the seed map, selected the participant groups, and merged the six maps. Those decisions establish a boundary and a grammar of controllers, feedback, hazards, and losses. They make some relations vivid while making a person's story harder to tell. The paper reports exactly that resistance from the ombudsman participants.

A system map is therefore not the final transparent object. It is a governed record of who was able to define the system, what they could see, what they disputed, and what remained outside the frame.

The Claim Boundary

The study reports no evidence of fundamental-rights violations in the assessment material the researchers obtained. It does report documentation gaps, including the absence of usable error metrics, and uses those gaps to construct possible loss scenarios. The paper does not evaluate Avola's accuracy, measure benefit outcomes, test the implemented legal rules, audit individual cases, or establish that the register caused harm.

The reviewed version 1 source archive supplies the manuscript and figure files, including the mapping worksheet and control-structure diagrams, but no de-identified workshop transcripts, participant maps, analysis code, or replication dataset. The published artifact supports close inspection of the method and claims, not independent reanalysis of the underlying qualitative material.

The System-Map Receipt

A system-map receipt should bind a register entry to the system version, legal basis, data sources, decision point, affected service, seed-map authors, evidence sources, invited and absent groups, workshop protocol, individual contributions, unresolved disagreements, author merges, control and feedback links, prospective hazards, observed incidents kept separate, assessment findings, missing evidence, complaint and appeal routes, vendor duties, reviewer, publication date, update trigger, and archived prior map. The receipt records how the picture was made, not only what it depicts.

The Governance Standard

Keep the register row: discovery is a necessary public function. Then require a second layer for high-impact systems that relates operation, oversight, recourse, maintenance, and political authority. Let affected people and intermediaries annotate that layer without pretending their perspectives collapse into consensus. A component inventory can disclose that safeguards exist. A reviewable system map can test whether those safeguards connect to the person who needs them.

Sources


Return to Blog