Research Note
Product Exception Governance Record
Mature products need exceptions. Fraud controls may suppress risky transactions. Safety systems may limit access. Accessibility paths may alter an interface. Incident res
Product Exception Governance Record
Why exceptions exist
Mature products need exceptions. Fraud controls may suppress risky transactions. Safety systems may limit access. Accessibility paths may alter an interface. Incident response can disable a feature for one region. Experiments can expose different cohorts to different versions.
The governance risk begins when the exception changes what an affected person or oversight function can observe without a legitimate, documented purpose and accountable control.
Minimum exception record
| Field | Required evidence |
|---|---|
| Identifier | Stable name, owner, system, and version |
| Purpose | Concrete risk or user need the exception addresses |
| Selection | Cohort logic and approved data inputs |
| Experience | Difference from the default product state |
| Affected rights | Transaction, access, notice, appeal, safety, or oversight impact |
| Authority | Policy, legal, security, privacy, and business approvals |
| Controls | Prevention, detection, review, access, and logging |
| Scope | Users, markets, time period, and excluded uses |
| Stop condition | Event that automatically pauses the exception |
| Outcome | Observed results, errors, complaints, and later decision |
High-risk signals
Risk increases when a cohort is hidden from ordinary review, a user sees a state that the system knows is false, oversight personnel receive a different experience because of who they are, sensitive data drives the selection, or the exception survives without an owner or expiration.
An exception is also harder to govern when the selection model cannot be explained, access is widely shared, logging can be disabled, the reviewer sees only a slide instead of the working product, or the stated purpose differs from actual use.
Review principle
Treat the presence of an alternate path as a reason to inspect purpose, authority, data, observability, and controls. Do not treat it as proof of wrongdoing. The same mechanism can support legitimate safety work or unacceptable concealment depending on design, facts, authorization, and operation.
Security boundary
Public examples should not reveal tactics that help a bad actor detect or defeat fraud, safety, security, or regulator systems. The reusable public value is the governance structure, not the operational playbook.
Sources
Follow the evidence.
- daltonanderson.ghost.io: ubers greyball the dark side of tech innovationdaltonanderson.ghost.io
- whistleblowers.gov: complaint pagewhistleblowers.gov
- uber.com: an update on greyballinguber.com
- theguardian.com: uber used greyball fake app to evade police across europe leak revealstheguardian.com
- courthousenews.com: GREYBALL AUDIT REPORTcourthousenews.com
- justice.gov: jm 9 28000 principles federal prosecution business organizationsjustice.gov
- youtu.be: TiC4GmwZ nsyoutu.be
- sec.gov: whistleblower protectionssec.gov
- open.spotify.com: 32iYem7RXAQ2R7WyHdRrscopen.spotify.com
- justice.gov: dljustice.gov
- justice.gov: corporate enforcementjustice.gov
- whistleblowers.gov: faqwhistleblowers.gov
- NLRB protected concerted activitynlrb.gov
- portland.gov: statement mayor ted wheeler allegations uber used greyball tool sidestepportland.gov
- sec.gov: report possible securities law violationssec.gov
- ftc.gov: bringing dark patterns lightftc.gov
- justice.gov: criminal division announces publication guidance evaluating corporate compliance programsjustice.gov
- whistleblowers.govwhistleblowers.gov
- content.govdelivery.com: 198c3edcontent.govdelivery.com
- portland.gov: 631393portland.gov
- yahoo.com: exclusive uber faces criminal probe 083701705yahoo.com