Decision rights by band

Authority scales with stakes. Low-risk uses are decided close to the work; high-stakes uses go to bodies with broader accountability. Decision rights are one part of proportionality: the whole process scales with the band.

Stakes and breadth of accountability
BandWho scoresWho decidesTypical conditions
LowProposer, unit lead, local IT contactUnit or department leadFollow published guidance; register the use.
ModerateCross-functional review teamAI governance lead or committee delegateDocumented mitigations; review at the end of the pilot.
HighFull team plus specialist reviewersAI governance councilRequired safeguards, a monitoring plan, and efficacy evidence before scaling.
CriticalCouncil, specialists, and representatives of affected groupsExecutive sponsors, on council recommendationAlternatives considered first; extensive controls; time-limited approval.

Escalation rule. A 5 on ethics & compliance or stakeholder impact moves the decision up one level, whatever the total. A low total should never hide a single severe risk.

Role names are illustrative. Map them to your institution's governance structure.

Who's at the table

Every dimension needs the people who can see its risks. Use this as a checklist when convening a review team.

DimensionBring inWhy
Strategic fitInstitutional planning, deans or unit leaders, the proposerConfirms the link to defined strategic goals.
Ethics & compliancePrivacy, information security, legal or general counsel, accessibility, research compliance (IRB) where relevantCatches FERPA, ADA, data, bias, and contract issues before commitment.
Financial viabilityBudget office, procurement, the service ownerTests total cost, ongoing funding, and vendor terms.
Operations & innovationCentral IT, enterprise architecture, the staff whose workflow changesChecks integration, support load, and scalability.
Stakeholder impactStudents, faculty, and staff from affected groups; shared governance; communicationsThe people affected see harms and trust issues others miss.

Nothing about them without them. When an initiative scores 4 or higher on stakeholder impact, include people from the affected population in scoring, not only in later consultation.

Your governance structure shapes the Compass

The Compass isn't used the same way everywhere. How an institution organizes AI governance decides who scores, who decides, how formal each review is, and how much effort a proposal takes. Set those choices to fit your structure before you adopt the rubric.

CentralizedFederatedDistributed
Typical setupOne AI council or office reviews everythingA central council sets standards; colleges and divisions review their ownUnits govern AI locally with light central guidance
CriteriaOne rubric, applied the same way everywhereShared core rubric; units may add descriptors for their contextUnits adapt the rubric; central office sets minimum questions
Who decidesMostly the central council, even for low bandsUnits decide Low and Moderate; council takes High and CriticalUnits decide most bands; escalation is the main central check
FormalityConsistent, often heavier for small ideasScales with the band, as on this siteVaries by unit; hardest to compare
Effort and speedQueues build at the centerBalanced; depends on clear hand-offsFast locally; duplication across units
Watch forBottlenecks that push people around reviewUnits scoring the same risk differentlyGaps in high-risk review and no portfolio view

The defaults on this site assume a federated model. Most institutions are a mix: name yours, then adjust the decision rights, review formats, and timeframes to match.

How the roles work together

Each step of the Compass belongs to someone. This cross-functional view shows who does what, and where work hands off between roles.

Cross-functional workflowSix roles across the six Compass steps. Screen: the proposer describes the idea and drafts metrics; the AI governance office logs intake and convenes the team. Score: the review team scores independently then discusses, consulting specialist reviewers on privacy, legal, and accessibility. Select: the review team agrees the band and recommends; the decision-maker for the band decides and sets conditions. Plan: the project owner finalizes metrics and exit criteria; the governance office registers the initiative. Track: the owner runs the pilot and records actuals while the governance office watches re-review triggers. Reflect: the owner reports results and lessons; the decision-maker decides to scale, iterate, pause, or stop. Iterate loops back to Plan. ProposerReview teamcross-functionalSpecialistreviewersDecision-makerby bandProject ownerAI governanceofficeSCREENSCORESELECTPLANTRACKREFLECTIterateconsultmonitorDescribe idea;draft metricsLog intake;convene teamScore alone,then discussReview privacy,legal, accessAgree band;recommendDecide;set conditionsFinalize metrics& exit criteriaRegister theinitiativeRun pilot;record actualsWatch re-reviewtriggersReport results& lessonsScale, iterate,pause, or stop
The roles flex with proportionality: for a Low initiative the review team may be just the proposer and unit lead, and specialists join only if something is flagged. For High and Critical, every lane is staffed. The governance office records approved initiatives in the Campus AI Registry (see what carries over). The full loop logic is in the workflow flowchart.

Equity & accessibility check

Equity and accessibility run across all five dimensions, so they get an explicit check rather than being left implicit inside ethics. Answer these before the team settles on scores:

  • Who benefits, who bears the risk?Are benefits and burdens distributed fairly across student, faculty, and staff groups?
  • Does it work equally well for everyone?Is there evidence the AI performs consistently across demographic groups, languages, and disability status?
  • Is it accessible?Does it meet accessibility standards (e.g., WCAG, ADA), with accommodations for people who can't use it?
  • Can people opt out?Is there a non-AI path that doesn't disadvantage those who decline?
  • Does it close or widen gaps?Could it reinforce existing inequities in access, outcomes, or digital literacy?
  • Who was consulted?Were affected groups part of the design and review, or only informed afterwards?

Record answers in the ethics and stakeholder-impact comments, and track fairness through an efficacy measure, for example accuracy within a set margin across groups.

Disagreement & appeals

Disagreement is useful information. A clear process keeps it from turning into a stalemate or an override.

  1. Score independently first. Each reviewer scores alone before discussion, so the loudest voice doesn't anchor the room.
  2. Discuss the spreads. Any dimension where scores differ by 2 or more points gets discussed before the team agrees a score.
  3. Record dissent. If the team can't converge, note the minority view and its reasoning in the comments. It travels with the decision.
  4. The decision-maker rules. The authority for the band decides, with the scores, comments, and any dissent in front of them.
  5. Reconsideration and appeal. A proposer may request reconsideration with new evidence, or appeal one level up. Each initiative gets one appeal per decision.

Representative roles and timeframes. The deciders, review formats, and target times on this page are examples, not actual institutional policy. Set your own to fit your governance structure.