Apply the principles

Decision tests

A proposed restriction should not become legitimate merely because its goal sounds important. These ten tests ask what harm is demonstrated, what the intervention actually targets, whether narrower designs exist, what data it collects, what happens to lawful inquiry, and how errors or failed policies get reversed.

10 tests No composite score Failure can be decisive

Why no score?

Hard cases should not disappear into arithmetic.

A proposal with a strong security objective can still be indefensible if it relies on a weak proxy, destroys confidential inquiry, or creates an unreviewable permanent dossier. The tests therefore expose separate failure modes instead of averaging them into a reassuring number.

thresholdA question that should be answered before broad intervention is presumed justified. design constraintA requirement that narrows how a legitimate intervention should be implemented. procedural safeguardA protection against opaque, erroneous, or unreviewable use of authority. feedback controlA mechanism for testing efficacy, limiting persistence, and reversing failure.
01

QAEDA-TST-001 · threshold

Name the harm precisely

What specific harm is the intervention meant to prevent, and what evidence establishes its severity, probability, and affected population?

Separate demonstrated harms from broad labels such as safety, extremism, misinformation, dangerousness, or wellbeing that can hide disagreement about the actual problem.

Inspect test →
02

Does the intervention act on conduct, capability, or a transaction closely connected to the harm—or merely on a topic, identity, association, or inferred character?

Keep subject matter and lawful curiosity from becoming stand-ins for harmful intent when a more direct behavioral or capability signal exists.

Inspect test →
03

QAEDA-TST-003 · design constraint

Test the least-restrictive means

Can the same safety objective be achieved with less restriction on lawful inquiry, privacy, identity, speech, access, or user agency?

Force comparison among architectures rather than accepting the first administratively convenient control as technically necessary.

Inspect test →
04

QAEDA-TST-004 · design constraint

Minimize data and separate identity

What is the minimum information the system must collect, retain, link, and reveal to perform the legitimate safety function?

Treat data minimization as architecture rather than a promise to behave well after comprehensive collection has already occurred.

Inspect test →
05

QAEDA-TST-005 · design constraint

Protect lawful inquiry explicitly

Does the intervention contain a clear rule preventing lawful reading, research, journalism, education, criticism, fiction, prevention work, or curiosity from being treated as harmful conduct by itself?

Make the inquiry boundary explicit rather than assuming automated intent inference will reliably reconstruct why a person asked a question.

Inspect test →
06

QAEDA-TST-006 · procedural safeguard

Require notice, reasons, and recourse

If the system materially restricts a person, can they understand what happened, contest the relevant evidence, and obtain meaningful human review?

Prevent classifiers and risk scores from becoming final authorities merely because their reasoning is difficult to inspect.

Inspect test →
07

QAEDA-TST-007 · procedural safeguard

Bound scope, secondary use, and duration

What prevents a narrow authority, dataset, classifier, or emergency control from being reused for broader purposes or persisting after its justification changes?

Design against function creep in advance instead of relying on future institutions to voluntarily surrender useful powers and datasets.

Inspect test →
08

QAEDA-TST-008 · feedback control

Measure efficacy and make rollback real

How will we know the intervention reduced the stated harm, what adverse effects will be measured, and what mechanism actually reverses or narrows the system if it fails?

Prevent activity metrics from masquerading as safety outcomes and make reversibility an operational property rather than a rhetorical promise.

Inspect test →
09

QAEDA-TST-009 · procedural safeguard

Inspect intermediary chokepoints

Does the restriction operate through payments, hosting, app distribution, identity, network access, ranking, translation, or another intermediary in a way that obscures who is responsible and what process applies?

Prevent indirect implementation from receiving less scrutiny merely because the visible restriction is executed by a private or technical intermediary.

Inspect test →
10

QAEDA-TST-010 · procedural safeguard

Protect the record and independent verification

Can the evidence, historical record, and reasons for the restriction be independently preserved and reviewed, or can one authority erase the material and the audit trail at the same time?

Keep information governance contestable by preserving enough authenticated evidence for later review, correction, research, and accountability.

Inspect test →

Review sequence

Use the tests as gates, not a checklist ritual.

Start with the harm and nexus. If those fail, additional procedural polish does not rescue the intervention. If the objective survives, compare narrower architectures, minimize data, preserve lawful inquiry, require recourse, bound scope, and predefine rollback.

  1. QAEDA-TST-001Name the harm preciselyWhat specific harm is the intervention meant to prevent, and what evidence establishes its severity, probability, and affected population?
  2. QAEDA-TST-002Prove the nexus to harmful capability or conductDoes the intervention act on conduct, capability, or a transaction closely connected to the harm—or merely on a topic, identity, association, or inferred character?
  3. QAEDA-TST-003Test the least-restrictive meansCan the same safety objective be achieved with less restriction on lawful inquiry, privacy, identity, speech, access, or user agency?
  4. QAEDA-TST-004Minimize data and separate identityWhat is the minimum information the system must collect, retain, link, and reveal to perform the legitimate safety function?
  5. QAEDA-TST-005Protect lawful inquiry explicitlyDoes the intervention contain a clear rule preventing lawful reading, research, journalism, education, criticism, fiction, prevention work, or curiosity from being treated as harmful conduct by itself?
  6. QAEDA-TST-006Require notice, reasons, and recourseIf the system materially restricts a person, can they understand what happened, contest the relevant evidence, and obtain meaningful human review?
  7. QAEDA-TST-007Bound scope, secondary use, and durationWhat prevents a narrow authority, dataset, classifier, or emergency control from being reused for broader purposes or persisting after its justification changes?
  8. QAEDA-TST-008Measure efficacy and make rollback realHow will we know the intervention reduced the stated harm, what adverse effects will be measured, and what mechanism actually reverses or narrows the system if it fails?
  9. QAEDA-TST-009Inspect intermediary chokepointsDoes the restriction operate through payments, hosting, app distribution, identity, network access, ranking, translation, or another intermediary in a way that obscures who is responsible and what process applies?
  10. QAEDA-TST-010Protect the record and independent verificationCan the evidence, historical record, and reasons for the restriction be independently preserved and reviewed, or can one authority erase the material and the audit trail at the same time?

Trace the reasoning

The tests operationalize arguments; they do not replace them.

Follow the Argument Map for the underlying reasons, Claims for evidence status, and the Cognitive Liberty Audit for a broader system-level evaluation method.