Back to the episode map

Research Note

Product Exception Governance Record

Mature products need exceptions. Fraud controls may suppress risky transactions. Safety systems may limit access. Accessibility paths may alter an interface. Incident res

Aug 4, 20262 min readBy Dalton Anderson

Product Exception Governance Record

Why exceptions exist

Mature products need exceptions. Fraud controls may suppress risky transactions. Safety systems may limit access. Accessibility paths may alter an interface. Incident response can disable a feature for one region. Experiments can expose different cohorts to different versions.

The governance risk begins when the exception changes what an affected person or oversight function can observe without a legitimate, documented purpose and accountable control.

Minimum exception record

FieldRequired evidence
IdentifierStable name, owner, system, and version
PurposeConcrete risk or user need the exception addresses
SelectionCohort logic and approved data inputs
ExperienceDifference from the default product state
Affected rightsTransaction, access, notice, appeal, safety, or oversight impact
AuthorityPolicy, legal, security, privacy, and business approvals
ControlsPrevention, detection, review, access, and logging
ScopeUsers, markets, time period, and excluded uses
Stop conditionEvent that automatically pauses the exception
OutcomeObserved results, errors, complaints, and later decision

High-risk signals

Risk increases when a cohort is hidden from ordinary review, a user sees a state that the system knows is false, oversight personnel receive a different experience because of who they are, sensitive data drives the selection, or the exception survives without an owner or expiration.

An exception is also harder to govern when the selection model cannot be explained, access is widely shared, logging can be disabled, the reviewer sees only a slide instead of the working product, or the stated purpose differs from actual use.

Review principle

Treat the presence of an alternate path as a reason to inspect purpose, authority, data, observability, and controls. Do not treat it as proof of wrongdoing. The same mechanism can support legitimate safety work or unacceptable concealment depending on design, facts, authorization, and operation.

Security boundary

Public examples should not reveal tactics that help a bad actor detect or defeat fraud, safety, security, or regulator systems. The reusable public value is the governance structure, not the operational playbook.

Sources

Follow the evidence.

  1. daltonanderson.ghost.io: ubers greyball the dark side of tech innovationdaltonanderson.ghost.io
  2. whistleblowers.gov: complaint pagewhistleblowers.gov
  3. uber.com: an update on greyballinguber.com
  4. theguardian.com: uber used greyball fake app to evade police across europe leak revealstheguardian.com
  5. courthousenews.com: GREYBALL AUDIT REPORTcourthousenews.com
  6. justice.gov: jm 9 28000 principles federal prosecution business organizationsjustice.gov
  7. youtu.be: TiC4GmwZ nsyoutu.be
  8. sec.gov: whistleblower protectionssec.gov
  9. open.spotify.com: 32iYem7RXAQ2R7WyHdRrscopen.spotify.com
  10. justice.gov: dljustice.gov
  11. justice.gov: corporate enforcementjustice.gov
  12. whistleblowers.gov: faqwhistleblowers.gov
  13. NLRB protected concerted activitynlrb.gov
  14. portland.gov: statement mayor ted wheeler allegations uber used greyball tool sidestepportland.gov
  15. sec.gov: report possible securities law violationssec.gov
  16. ftc.gov: bringing dark patterns lightftc.gov
  17. justice.gov: criminal division announces publication guidance evaluating corporate compliance programsjustice.gov
  18. whistleblowers.govwhistleblowers.gov
  19. content.govdelivery.com: 198c3edcontent.govdelivery.com
  20. portland.gov: 631393portland.gov
  21. yahoo.com: exclusive uber faces criminal probe 083701705yahoo.com
Product Exception Governance Record