Dispatches from the fault lines



Part 1: Who Does the System Think You Are?

This is Part 1 of “What Lies Beneath”, a five-part public service “thriller” series exploring administrative truth: what it is, how it works, where it breaks down, and what better-designed systems could look like for people and public servants. Read the intro here.


Scott is 44*. He has worked in construction for twenty years, most recently as a site supervisor for a mid-sized contractor in Vancouver, British Columbia, Canada. He has two teenagers at home. He divorced about a year ago. 

Last month his employer lost a major contract and laid off a third of the workforce. Scott was among them.

Scott knows what happened in his life. His employer knows also, because they filed the Record of Employment (ROE) with the federal government. But as Scott starts navigating the systems that are supposed to help him — Employment Insurance (EI) federally, income assistance provincially, retraining support via WorkBC — he begins to notice something that does not make sense.

The systems do not seem to know who he is. Not the current version of him, anyway…

*Scott is a fictional character in a speculative fiction story to illustrate the concept of administrative truth. His story returns at the beginning and end of every chapter and serves as a vignette to tell a bigger story. It is set in a not so distant, imperfect future, where (mostly invisible) computers – not humans – handle public service delivery.

The Truth Ladder

What is happening to Scott? Before we can start to see what is going on, we need to be precise about something that gets blurred often in conversations about digital government: the difference between data, data record, authoritative data, administrative truth, and administrative untruth. These are not the same thing. So bear with me as it may get a bit technical here, introducing a “truth ladder”. Each rung of the ladder adds a layer of institutional consequence. It is only at the top that the stakes become fully visible.

Data is the smallest meaningful unit of recorded information, such as a timestamp, a name, a dollar figure or a code indicating employment status. On its own, data describes (and it can be wrong, yes) but does not determine. It has no inherent authority and no inherent consequence for the person it refers to.

A data record is data that has been formally captured and structured by an institution. It follows defined standards for quality, interoperability, and sharing. An institution has decided this data is worth keeping in a governed form. Scott’s Record of Employment, filed by his employer with Service Canada, is a data record. It exists and it is structured. It meets a defined standard, and yes… it could also be wrong.

Authoritative data is data recognised through governance, law, or common acceptance as the source of origin for accurate information on a specific topic. A designated data custodian could be responsible for its accuracy and fitness for use throughout its lifecycle. Scott’s employment history as held by Service Canada is authoritative data. It is the designated source of truth for his employment record for the purposes of Employment Insurance (EI). 

A system of record is the authoritative source where data for a specific domain is created, maintained, and shared. A “source of truth” may be the same as the system of record, or it may be a governed copy made available when the original cannot be directly accessed. For example, Service Canada’s digital systems are the system of record for Scott’s EI contributions. Canada Revenue Agency (CRA) holds the system of record for his tax history.

Data-interoperability refers to making it technically possible for digital systems to securely share and reuse information across programs or jurisdictions. The technical parts are accompanied with laws, regulation and governance mechanisms, such as: when does what kind of data get shared with whom?

Administrative truth is what happens at the top of the ladder and is relevant for enabling connected service experiences in life events. It is the specific authoritative data, drawn from one or more systems of record (by a human government worker or a computer), that an institution treats as operative for the purposes of making a consequential determination about a specific person at a specific moment in time. For example, a government worker pulls authoritative and non-authoritative data from different sources to establish Scott’s eligibility for employments benefits. Once a new (service-level) administrative truth is established, either by a human or computer (ie. “Yes, Scott is eligible for EI”), other services could use this truth and offer their services pro-actively. The public administration now believes something that happened in Scott’s life to be true, and others (ie. other service providers) can act on it.

Administrative untruth is what happens when an error or outdated record is registered as an administrative truth and used as if it were reliable. It is a formally recorded falsehood (ie. married but divorced) that the system treats as operative and may propagate to other systems as if it were still true and can be used to determine eligibility (ie. marital status in an income means test). It was accurate once, but no longer accurate now. A corrective mechanism should always exist to identify and fix an administrative untruth to provide transparency and agency to people. In most current systems, it is not possible to see a full administrative picture of you across a country, state, province.

Administrative Truth Ladder – By: Marlieke Kieboom.

To conclude, data is pretty good at describing things, but administrative truth ultimately governs service decisions, and therefore outcomes in people’s lives. Administrative truth is about what data does to Scott’s life, to his ability to access support, to what the state believes him to be eligible for. Therefore administrative truth is an important design material in public service: a truth can become a misleading administrative untruth, but the system and its workers (or computing machines) may not recognize the difference, while states set the rules for service eligibility. Therefore it should invite us to explore.

Signals and Truths

There is one more distinction worth making before I return to Scott, because it matters for understanding how administrative truth gets established in the first place.

A signal is information received by government. It is not yet verified, but it is recorded and picked up. Scott’s employer files a Record of Employment. That is a signal. It says something, a life event happened. The system receives it, logs it and it triggers a service response. But the signal alone does not establish a new administrative truth. The signal has to be validated before it can be relied upon.

Administrative truth is what the signal becomes after government has officially verified and recorded it through an authoritative process. Only then does it become reusable by other services. Other programs can rely on the verified fact instead of asking Scott to prove it again. The signal said something changed. The administrative truth says what changed, confirmed with legal standing.

This distinction is foundational for understanding how connected and proactive service delivery work in practice. Systems that respond to unverified signals before they become administrative truths are systems that can cause harm at scale. Systems that wait for administrative truths before triggering service responses are systems that can be good, fast, accurate, proactive and … power-full. Governance of that boundary is where much of our thinking, discovery and design should live.

One Life, Many Systems

Back to Scott. Scott does not have one administrative truth. He has several, held by different institutions across several jurisdictions. Each is acting as if its version is complete. Service Canada knows he was laid off. CRA knows his income from last year. His bank holds his current address. His teenagers’ schools hold emergency contact information that reflects the pre-divorce arrangement.

But, wait a minute. The provincial income assistance system thinks he is still married, though his divorce was finalized 12 months ago. It just never made it into the administration…

Scott gets chopped into pork bits when looking at him from an administrative picture perspective. How to bring things closer together? Image by: Marlieke Kieboom.

What makes this consequential is that each institution will make decisions on its record of his situation, as of the last time that record was updated. The income assistance program will now assess his household against a two-person adult income. It may use an old address. It may request paperwork he doesn’t have or can’t find.

Additionally, none of these institutions know what the others know, or check in with each other. Each holds a partial, temporally uneven and frozen record of the same person. Together this “feral” data constitutes a distributed, fragmented administrative picture that Scott must now navigate at exactly the moment when his capacity to do so is most stretched. Scott himself has not misrepresented anything. He simply did not know which systems to update, in which order, with what documentation, according to whose process. The administrative untruth persists, invisible to Scott, until it surfaces as a consequence. Scott bears the cost of that divergence.

The labour to apply for services and course correct when things are wrong is referred to as “administrative burden”, as introduced by Pamela Herd and Donald P. Moynihan (2018).  James C. Scott, in his work Seeing Like a State (1998), argued that states have an obligation to simplify complex social realities into legible administrative categories to be able to act on them. It’s true that categories make administration possible, but they lag because life moves faster than the administrative picture. But not only that: each service has its own process to establish a service-level administrative truth about Scott, and none of them look across their own (programme, Ministry, jurisdictional) borders. This is not only seriously complex for Scott, but comes with an immense pressure on public services: medical checks, income checks all try to pull from the same data sources, to verify the same truths, while none of them look across, or assess the knock-on effects for both systems and people.

When a major life event occurs such as layoff, combined with a divorce, a move or having an injury, the gap between what is actually true about a person and what the system believes to be true, and the gap between what a person needs and what governments have an offer in terms of support (albeit completely uncoordinated), becomes not just inaccurate, but quite burdensome and consequential. Yet, government knowing exactly everything about you at every moment in your life, can be a dangerous thing. How to design for this tension?

Discovery and Design for Life Events

‘What does the user need?’ is often the design question designers start with when designing for a (new or existing) public service, or a digital product within. It’s always been a powerful question, as it encourages public institutions to look outwards. Yet, looking at what is going on for Scott, this question may not give him a better or fair result quickly, given we already know that his administrative picture sits chopped across across many services, systems and jurisdictions. This means our design questions need to move across those boundaries as well, across multiple services, data sets and land boundaries, and into the heart of how governments work, asking different questions:

What do systems already believe to be true about Scott, even before he applies for something he thinks he needs?

And… what does the institution think he can have (in terms of services, support)?

How can we bring his ground truth and the operational belief about Scott closer together, without overpowering the State? How could we coordinate these data-level and service-level administrative truths better across boundaries? What are the downstream design consequences? How does it change services, how does it change work for government workers (or computers)? Does streamlining data and policy across boundaries result in lowering the administrative burden on Scott, the government, and ultimately create better outcomes?

Discovery spine with discovery questions, the areas they influence, and the places where design could have more influence.

These are the design questions that come with exploring discovery for complex life events such as becoming unemployed, having a baby, or handling end-of-life care in widened ways. Yet, it is worth pointing out that there is a peculiar tension at play in the world of public institution designers who work in the field of discovery for life and business events to connect services and improve outcomes.

An internal-to-government designers’ strategic influence becomes less the higher up they go in the discovery spine. The influence of the designer is dependent on the influence of public service executives at leadership level (ie. executive director, Assistant Deputy Minister). Yet, the public service executive’s influence itself also isn’t endless. It typically ends where the law (created in the legislature) begins, and stops at the jurisdictional land boundary (ie. a province, a state, a city boundary), given they have little to no accountability outside of it. Yet, peoples lives don’t know such boundaries.

This inversion (influence going down, while potential impact scale going up) means that for public service designers’ work to be effective inside the institution, they need collaborations that go across traditional (organisational, hierarchical, jurisdictional, Ministerial) boundaries to influence those higher echelons of design (ie. interconnectedness, relation with society, advocacy groups). Equally, public service executives need to have incentives to go across. This kind of work requires deep connections and relations to make meaningful change outside traditional institutional boundaries. Simultaneously public service designers need to know and respect where their influence in the public service ends, and society’s democratic influence (societal design) begins.

To conclude

To me, administrative truth helps me to see, name and design for what happens internally in government, and across governments, beyond user needs without diminishing what their perspective has to offer in terms of problem expansion. It feels like a close design sibling to the concept of administrative burden (Herd & Moynihan, 2018), which is traditionally focussed more on the citizen experience. It’s looks like the more socio-anthropological cousin of the technological concept of data-interoperability. It makes it easier to talk about what needs to change with non-technical public servant colleagues.

How is this new concept landing for you? How would you use this in your work?

* * *

Back to Scott

Scott’s layoff is a fact. His divorce is completed. His two teenagers living with him half the time are really there His current address is real, he knows where he lives. But none of these facts exist, in their current and accurate form, in all of the systems combined that will determine what help he receives and when. Some of what the system believes about him is even an administrative untruth: a record that stopped being accurate and was never corrected.

Oh darn. Scott’s administrative picture is totally chopped up, kind of like looking at a pork cut, with some bacon bits here, and the loin over there. Gory!

Scott will spend the coming weeks and months performing his lived reality back into each system separately. Updating records, providing documentation, explaining his situation to institutions that should already know it, or at least know that they do not know it. It costs time. It feels frustrating. And not only for Scott. Think of all the government workers on the other end, having to adjudicate, verify or correct all these bits and pieces.

Scott is sadly not an edge case. He is what a fairly ordinary accumulation of life events looks like when it meets a system designed around static, single-event, nuclear-household assumptions.

How could we design things differently?

* * *

References

Scott, J. C. (1998). Seeing like a state: How certain schemes to improve the human condition have failed.

Herd, P., & Moynihan, D. P. (2018). Administrative burden: Policymaking by other means. 

What’s next

Here’s what’s coming next.

Part 2 looks at Canada specifically, where the fragmentation of administrative truth is constitutionally baked in, and where Scott may have to prove the same facts of his life separately to federal, provincial, and municipal systems, each operating under different definitions, different standards, different rules.

Part 3 looks at the dark side. What happens as administrative decisions move out of human hands and into automated systems? What happens when an administrative untruth is already in the system when the machines start talking? Who is accountable when no one makes the decision?

Part 4 looks at what better design could make possible, such as a “receipt” of administrative truth, informed navigation within a jurisdiction and portable truths across jurisdictions. It wouldn’t necessarily require digitizing the entire service. It would require governing the records that already exist, and where applicable, digitise those well in consistent ways. 

Part 5 makes the governance argument. Because the real problem is about who holds power over administrative truth, and what obligations come with that power.