{
  "schema": "qaeda.public-decision-tests.v1",
  "canonical": "https://qaeda.org/decision-tests",
  "updated": "2026-09-02",
  "publication": "Questioning Accepted Ethics, Dogma & Authority",
  "purpose": "A non-numeric review framework for proposed safety, governance, moderation, surveillance, censorship, identity, infrastructure, and access restrictions. The tests expose what evidence, scope, safeguards, chokepoints, preservation duties, and rollback conditions should be examined before a restriction is treated as justified.",
  "boundary": "These tests do not replace law, technical risk assessment, domain expertise, or emergency judgment. They are not a certification or compliance score. A proposal can fail for one serious reason even if it looks strong elsewhere.",
  "role_vocabulary": {
    "threshold": "A question that should be answered before broad intervention is presumed justified.",
    "design_constraint": "A requirement that narrows how a legitimate intervention should be implemented.",
    "procedural_safeguard": "A protection against opaque, erroneous, or unreviewable use of authority.",
    "feedback_control": "A mechanism for testing efficacy, limiting persistence, and reversing failure."
  },
  "outcome_vocabulary": {
    "proceed_bounded": "The proposal may warrant a narrow, reviewable implementation or pilot if domain-specific legal and technical requirements are also met.",
    "redesign": "A legitimate objective may exist, but the proposed mechanism is broader, more invasive, or less reviewable than necessary.",
    "pause_or_reject": "The proposal lacks a sufficiently defined harm, nexus, safeguard, or evidence basis to justify the liberty/privacy cost as presented."
  },
  "tests": [
    {
      "id": "QAEDA-TST-001",
      "slug": "harm-specificity",
      "title": "Name the harm precisely",
      "role": "threshold",
      "question": "What specific harm is the intervention meant to prevent, and what evidence establishes its severity, probability, and affected population?",
      "purpose": "Separate demonstrated harms from broad labels such as safety, extremism, misinformation, dangerousness, or wellbeing that can hide disagreement about the actual problem.",
      "pass_condition": "The proposal defines a concrete harm, identifies evidence and uncertainty, distinguishes severity from mere offensiveness or controversy, and states what would count as meaningful reduction of that harm.",
      "warning_signs": [
        "The justification relies mainly on undefined risk language or emotionally salient examples.",
        "Prevalence, probability, or causal mechanism is unspecified.",
        "The stated harm shifts when narrower remedies are proposed.",
        "Success is measured only by flags, removals, surveillance volume, or compliance activity."
      ],
      "evidence_to_demand": [
        "Incident or prevalence data appropriate to the domain.",
        "A causal or capability model connecting the intervention target to the harm.",
        "Known uncertainty, false-positive cost, and affected-population estimates.",
        "A predeclared outcome measure for actual harm reduction."
      ],
      "failure_mode": "A vague threat definition can make almost any person, topic, or behavior appear relevant and therefore expand discretion without proving benefit.",
      "argument_ids": [
        "QAEDA-ARG-004",
        "QAEDA-ARG-008",
        "QAEDA-ARG-012"
      ],
      "position_ids": [
        "evidence-before-identity",
        "expansion-risk"
      ],
      "claim_ids": [
        "QAEDA-CLM-015",
        "QAEDA-CLM-016",
        "QAEDA-CLM-018"
      ],
      "article_ids": [
        "QAEDA-ART-006",
        "QAEDA-ART-007",
        "QAEDA-ART-009"
      ],
      "collection_ids": [
        "QAEDA-COL-001",
        "QAEDA-COL-003"
      ]
    },
    {
      "id": "QAEDA-TST-002",
      "slug": "harm-nexus",
      "title": "Prove the nexus to harmful capability or conduct",
      "role": "threshold",
      "question": "Does the intervention act on conduct, capability, or a transaction closely connected to the harm—or merely on a topic, identity, association, or inferred character?",
      "purpose": "Keep subject matter and lawful curiosity from becoming stand-ins for harmful intent when a more direct behavioral or capability signal exists.",
      "pass_condition": "The proposal identifies a reasonably direct connection between what it restricts and the harmful outcome, and explains why topic-level or identity-level proxies are necessary if they are used at all.",
      "warning_signs": [
        "Researching a subject is treated as evidence of intending to act on it.",
        "Political, religious, demographic, or associational identity becomes a risk proxy.",
        "The mechanism cannot explain why a benign researcher and a harmful actor should be treated differently.",
        "A durable person-level profile is created from isolated lawful queries."
      ],
      "evidence_to_demand": [
        "Validation showing the chosen signal predicts the relevant harmful behavior rather than merely correlating with topic interest.",
        "False-positive analysis across legitimate research, journalism, education, prevention, and fiction use cases.",
        "Evidence that more direct request-, tool-, transaction-, or capability-level controls are insufficient."
      ],
      "failure_mode": "Weak proxies can convert curiosity into suspicion and make protected inquiry bear the cost of uncertainty.",
      "argument_ids": [
        "QAEDA-ARG-001",
        "QAEDA-ARG-002",
        "QAEDA-ARG-007"
      ],
      "position_ids": [
        "query-non-suspicion",
        "least-restrictive-safety",
        "cognitive-liberty"
      ],
      "claim_ids": [
        "QAEDA-CLM-011",
        "QAEDA-CLM-013",
        "QAEDA-CLM-016"
      ],
      "article_ids": [
        "QAEDA-ART-002",
        "QAEDA-ART-004",
        "QAEDA-ART-010"
      ],
      "collection_ids": [
        "QAEDA-COL-002",
        "QAEDA-COL-003"
      ]
    },
    {
      "id": "QAEDA-TST-003",
      "slug": "least-restrictive-means",
      "title": "Test the least-restrictive means",
      "role": "design_constraint",
      "question": "Can the same safety objective be achieved with less restriction on lawful inquiry, privacy, identity, speech, access, or user agency?",
      "purpose": "Force comparison among architectures rather than accepting the first administratively convenient control as technically necessary.",
      "pass_condition": "The proposal compares meaningful alternatives and explains why warnings, user controls, friction, rate limits, sandboxing, local classifiers, anonymous credentials, targeted warrants, or narrower capability controls would not adequately address the harm.",
      "warning_signs": [
        "A broad ban is proposed before narrower controls are tested.",
        "Administrative convenience is treated as necessity.",
        "The proposal centralizes identity or inquiry data even though the safety function does not require it.",
        "The burden falls on all users to prevent abuse by a small subset."
      ],
      "evidence_to_demand": [
        "Comparative testing of at least one materially less restrictive alternative.",
        "Expected harm reduction and error costs for each alternative.",
        "Operational explanation of why the broader mechanism adds necessary marginal benefit."
      ],
      "failure_mode": "Without comparative design review, exceptional controls become defaults because they are easier to administer, not because they are necessary.",
      "argument_ids": [
        "QAEDA-ARG-002",
        "QAEDA-ARG-003",
        "QAEDA-ARG-012"
      ],
      "position_ids": [
        "least-restrictive-safety",
        "privacy-preserving-safety"
      ],
      "claim_ids": [
        "QAEDA-CLM-014",
        "QAEDA-CLM-016",
        "QAEDA-CLM-019"
      ],
      "article_ids": [
        "QAEDA-ART-005",
        "QAEDA-ART-006",
        "QAEDA-ART-009"
      ],
      "collection_ids": [
        "QAEDA-COL-003"
      ]
    },
    {
      "id": "QAEDA-TST-004",
      "slug": "data-minimization",
      "title": "Minimize data and separate identity",
      "role": "design_constraint",
      "question": "What is the minimum information the system must collect, retain, link, and reveal to perform the legitimate safety function?",
      "purpose": "Treat data minimization as architecture rather than a promise to behave well after comprehensive collection has already occurred.",
      "pass_condition": "The design limits raw-history retention, separates identity from inquiry where feasible, constrains secondary use, defines deletion, and prefers aggregate, local, ephemeral, or attribute-only processing when those patterns can achieve the objective.",
      "warning_signs": [
        "Full identity is required when only an eligibility attribute is needed.",
        "Raw prompts, searches, or browsing histories are retained indefinitely for unspecified future safety uses.",
        "Data collected for one safety purpose can silently flow into advertising, employment, insurance, policing, immigration, or political profiling.",
        "Deletion depends only on policy promises while the architecture keeps unnecessary copies."
      ],
      "evidence_to_demand": [
        "A data-flow map showing collection, linkage, retention, access, and deletion.",
        "Justification for each persistent identifier and retained field.",
        "Technical evidence for isolation, aggregation, local processing, or anonymous credentials where claimed.",
        "A secondary-use policy enforceable through technical or institutional controls."
      ],
      "failure_mode": "A safety database can become a general-purpose behavioral dossier even when the original objective was narrow and legitimate.",
      "argument_ids": [
        "QAEDA-ARG-002",
        "QAEDA-ARG-003",
        "QAEDA-ARG-004"
      ],
      "position_ids": [
        "privacy-preserving-safety",
        "query-non-suspicion",
        "expansion-risk"
      ],
      "claim_ids": [
        "QAEDA-CLM-011",
        "QAEDA-CLM-014",
        "QAEDA-CLM-019"
      ],
      "article_ids": [
        "QAEDA-ART-002",
        "QAEDA-ART-005",
        "QAEDA-ART-008"
      ],
      "collection_ids": [
        "QAEDA-COL-002",
        "QAEDA-COL-003"
      ]
    },
    {
      "id": "QAEDA-TST-005",
      "slug": "lawful-inquiry-protection",
      "title": "Protect lawful inquiry explicitly",
      "role": "design_constraint",
      "question": "Does the intervention contain a clear rule preventing lawful reading, research, journalism, education, criticism, fiction, prevention work, or curiosity from being treated as harmful conduct by itself?",
      "purpose": "Make the inquiry boundary explicit rather than assuming automated intent inference will reliably reconstruct why a person asked a question.",
      "pass_condition": "The policy and implementation distinguish information seeking from operational assistance or harmful conduct, define escalation criteria beyond subject matter alone, and preserve confidential inquiry where possible.",
      "warning_signs": [
        "The same topic label triggers both content safeguards and person-level suspicion.",
        "A user cannot tell whether a refusal or warning also changes a persistent risk profile.",
        "Youth safety rules remove confidential access to health, identity, abuse, or civic information rather than targeting manipulative amplification.",
        "Academic, journalistic, or defensive use is acknowledged rhetorically but lacks a practical pathway."
      ],
      "evidence_to_demand": [
        "Benchmark cases covering benign high-risk-domain inquiry.",
        "Documented escalation criteria that require more than topic interest.",
        "Evidence that confidential or anonymous access survives ordinary lawful use.",
        "For minors, testing that pull-based inquiry remains distinct from push-based recommendation controls."
      ],
      "failure_mode": "People may self-censor long before any formal sanction if lawful inquiry can silently contribute to a durable risk judgment.",
      "argument_ids": [
        "QAEDA-ARG-001",
        "QAEDA-ARG-006",
        "QAEDA-ARG-007"
      ],
      "position_ids": [
        "query-non-suspicion",
        "minors-pull-push",
        "chilling-effect"
      ],
      "claim_ids": [
        "QAEDA-CLM-012",
        "QAEDA-CLM-013",
        "QAEDA-CLM-017"
      ],
      "article_ids": [
        "QAEDA-ART-004",
        "QAEDA-ART-008",
        "QAEDA-ART-003"
      ],
      "collection_ids": [
        "QAEDA-COL-002",
        "QAEDA-COL-003"
      ]
    },
    {
      "id": "QAEDA-TST-006",
      "slug": "notice-and-recourse",
      "title": "Require notice, reasons, and recourse",
      "role": "procedural_safeguard",
      "question": "If the system materially restricts a person, can they understand what happened, contest the relevant evidence, and obtain meaningful human review?",
      "purpose": "Prevent classifiers and risk scores from becoming final authorities merely because their reasoning is difficult to inspect.",
      "pass_condition": "Consequential actions provide intelligible reason categories, disclose the governing rule, permit correction or appeal, and track whether review can actually reverse erroneous decisions.",
      "warning_signs": [
        "Visibility, access, eligibility, or account standing changes without notice.",
        "Appeals are routed into the same automated classifier with no independent review.",
        "The operator cannot identify which rule or evidence drove the action.",
        "Error rates and reversal rates are unavailable even in aggregate."
      ],
      "evidence_to_demand": [
        "Appeal latency and overturn-rate data.",
        "Examples of reason notices for representative cases.",
        "Evidence that reviewers have authority to reverse automated decisions.",
        "Independent or adversarial evaluation of false positives."
      ],
      "failure_mode": "Opaque automation can convert uncertain inference into unreviewable deprivation and train users to conform to invisible rules.",
      "argument_ids": [
        "QAEDA-ARG-005",
        "QAEDA-ARG-008",
        "QAEDA-ARG-012"
      ],
      "position_ids": [
        "algorithmic-due-process",
        "evidence-before-identity"
      ],
      "claim_ids": [
        "QAEDA-CLM-020",
        "QAEDA-CLM-018"
      ],
      "article_ids": [
        "QAEDA-ART-003",
        "QAEDA-ART-009",
        "QAEDA-ART-019"
      ],
      "collection_ids": [
        "QAEDA-COL-001",
        "QAEDA-COL-002"
      ]
    },
    {
      "id": "QAEDA-TST-007",
      "slug": "scope-and-sunset",
      "title": "Bound scope, secondary use, and duration",
      "role": "procedural_safeguard",
      "question": "What prevents a narrow authority, dataset, classifier, or emergency control from being reused for broader purposes or persisting after its justification changes?",
      "purpose": "Design against function creep in advance instead of relying on future institutions to voluntarily surrender useful powers and datasets.",
      "pass_condition": "The intervention defines who and what is outside scope, limits retention and secondary use, assigns independent review, and contains a meaningful sunset or renewal burden tied to evidence.",
      "warning_signs": [
        "Terms such as relevant, dangerous, safety, or systemic risk have no limiting definition.",
        "The same dataset can be reused for unrelated enforcement or commercial purposes.",
        "Emergency powers renew automatically or without efficacy evidence.",
        "Oversight depends entirely on the operator that benefits from the authority."
      ],
      "evidence_to_demand": [
        "Explicit exclusions and purpose-limitation language.",
        "Retention and deletion schedules.",
        "Independent review authority and access to necessary records.",
        "Sunset dates or renewal criteria linked to measured need and benefit."
      ],
      "failure_mode": "Infrastructure built for a narrow emergency can become a normalized platform for unrelated surveillance or control.",
      "argument_ids": [
        "QAEDA-ARG-004",
        "QAEDA-ARG-008",
        "QAEDA-ARG-009"
      ],
      "position_ids": [
        "expansion-risk",
        "provenance-correction"
      ],
      "claim_ids": [
        "QAEDA-CLM-015",
        "QAEDA-CLM-016"
      ],
      "article_ids": [
        "QAEDA-ART-006",
        "QAEDA-ART-007",
        "QAEDA-ART-015"
      ],
      "collection_ids": [
        "QAEDA-COL-003",
        "QAEDA-COL-004"
      ]
    },
    {
      "id": "QAEDA-TST-008",
      "slug": "efficacy-and-rollback",
      "title": "Measure efficacy and make rollback real",
      "role": "feedback_control",
      "question": "How will we know the intervention reduced the stated harm, what adverse effects will be measured, and what mechanism actually reverses or narrows the system if it fails?",
      "purpose": "Prevent activity metrics from masquerading as safety outcomes and make reversibility an operational property rather than a rhetorical promise.",
      "pass_condition": "The proposal predeclares success and failure measures, evaluates privacy/liberty/error costs, publishes aggregate evidence where possible, and identifies who can narrow, suspend, or terminate the intervention.",
      "warning_signs": [
        "More flags, more removals, or more surveillance are treated as proof of effectiveness.",
        "No baseline or counterfactual exists for comparing outcomes.",
        "Adverse effects such as false positives, chilling, exclusion, security risk, or bias are not tracked.",
        "There is no practical rollback path once infrastructure and institutional dependencies form."
      ],
      "evidence_to_demand": [
        "Pre/post or comparative outcome measures tied to the original harm.",
        "Adverse-effect metrics and subgroup error analysis where relevant.",
        "Independent evaluation or reproducible audit evidence.",
        "A named authority, technical mechanism, and timetable for rollback or redesign."
      ],
      "failure_mode": "A system can become permanent because it produces measurable enforcement activity even when its marginal contribution to safety remains unknown.",
      "argument_ids": [
        "QAEDA-ARG-004",
        "QAEDA-ARG-005",
        "QAEDA-ARG-012"
      ],
      "position_ids": [
        "algorithmic-due-process",
        "expansion-risk",
        "provenance-correction"
      ],
      "claim_ids": [
        "QAEDA-CLM-015",
        "QAEDA-CLM-018",
        "QAEDA-CLM-020"
      ],
      "article_ids": [
        "QAEDA-ART-006",
        "QAEDA-ART-007",
        "QAEDA-ART-009"
      ],
      "collection_ids": [
        "QAEDA-COL-001",
        "QAEDA-COL-003"
      ]
    },
    {
      "id": "QAEDA-TST-009",
      "slug": "intermediary-chokepoints",
      "title": "Inspect intermediary chokepoints",
      "role": "procedural_safeguard",
      "question": "Does the restriction operate through payments, hosting, app distribution, identity, network access, ranking, translation, or another intermediary in a way that obscures who is responsible and what process applies?",
      "purpose": "Prevent indirect implementation from receiving less scrutiny merely because the visible restriction is executed by a private or technical intermediary.",
      "pass_condition": "The proposal identifies the initiating and executing actors, lawful authority, specific mechanism, appeal path, alternatives, and whether the intermediary is meaningfully replaceable.",
      "warning_signs": [
        "Responsibility is split so no actor accepts accountability for the restriction.",
        "A financial or infrastructure dependency makes nominally voluntary enforcement effectively unavoidable.",
        "The same restriction would face greater procedural scrutiny if imposed directly.",
        "Users cannot tell whether a visibility or access loss came from law, platform policy, commercial risk, or technical failure."
      ],
      "evidence_to_demand": [
        "Documented chain of authority or contractual responsibility.",
        "Market and technical analysis of practical alternatives to the intermediary.",
        "Notice and appeal records for affected speakers or users.",
        "Evidence separating ordinary commercial enforcement from viewpoint- or state-driven pressure."
      ],
      "failure_mode": "Indirect restriction can hide coercion, eliminate recourse, and convert concentrated infrastructure into an unreviewable speech-governance layer.",
      "argument_ids": [
        "QAEDA-ARG-013",
        "QAEDA-ARG-017",
        "QAEDA-ARG-008"
      ],
      "position_ids": [
        "mechanism-before-label",
        "algorithmic-due-process"
      ],
      "claim_ids": [
        "QAEDA-CLM-022",
        "QAEDA-CLM-027",
        "QAEDA-CLM-021"
      ],
      "article_ids": [
        "QAEDA-ART-022",
        "QAEDA-ART-026",
        "QAEDA-ART-024"
      ],
      "collection_ids": [
        "QAEDA-COL-007"
      ]
    },
    {
      "id": "QAEDA-TST-010",
      "slug": "record-preservation",
      "title": "Protect the record and independent verification",
      "role": "procedural_safeguard",
      "question": "Can the evidence, historical record, and reasons for the restriction be independently preserved and reviewed, or can one authority erase the material and the audit trail at the same time?",
      "purpose": "Keep information governance contestable by preserving enough authenticated evidence for later review, correction, research, and accountability.",
      "pass_condition": "The system preserves a proportionate, access-controlled audit record; protects lawful archival and journalistic preservation; supports independent review; and does not give one actor unilateral power to erase both contested material and evidence of the intervention.",
      "warning_signs": [
        "Deletion destroys the only copy needed to evaluate a disputed enforcement action.",
        "Historical or journalistic archives are treated the same as active distribution contexts without analysis.",
        "Classification or secrecy has no review, declassification, or independent preservation path.",
        "A single platform, state, or archive controls both the record and the account of why it disappeared."
      ],
      "evidence_to_demand": [
        "Retention and deletion rules for enforcement records.",
        "Independent archival or escrow design where appropriate.",
        "Provenance and integrity mechanisms for preserved records.",
        "A lawful access/review process that protects privacy and genuine security needs."
      ],
      "failure_mode": "A restriction becomes difficult to contest when it can erase both the disputed information and the evidence required to prove what happened.",
      "argument_ids": [
        "QAEDA-ARG-015",
        "QAEDA-ARG-011",
        "QAEDA-ARG-017"
      ],
      "position_ids": [
        "plural-custody",
        "provenance-correction",
        "mechanism-before-label"
      ],
      "claim_ids": [
        "QAEDA-CLM-026",
        "QAEDA-CLM-035",
        "QAEDA-CLM-025"
      ],
      "article_ids": [
        "QAEDA-ART-025",
        "QAEDA-ART-027",
        "QAEDA-ART-024"
      ],
      "collection_ids": [
        "QAEDA-COL-005",
        "QAEDA-COL-008"
      ]
    }
  ]
}
