top of page

Your Algorithm Has Decision Rights Nobody Granted It

Aug 13
15 min read

Updated: Aug 24

Real estate got there first. The question is already sitting under every regulated decision in your company.


Your Algorithm Has Decision Rights Nobody Granted It


A blank signature line on a printed form.

A leasing agent at a 300-unit property in a major market works through a stack of applications every week.


An application comes in. She pulls the screening report. There is a number on it. The number is below the threshold her company set. She clicks decline, sends the adverse action notice, and moves to the next one. Total elapsed time, ninety seconds.


Ask her who decided to deny that applicant and she will tell you the system said decline. She is not dodging. That is an accurate description of what happened.


Now ask everybody above her.

  • The screening vendor will tell you it does not make leasing decisions. It provides information.

  • The property manager will tell you it applied the criteria the owner approved.

  • The owner will tell you it hired a professional manager and a licensed screening provider precisely so it would not be making these calls one unit at a time.

  • The regional VP will tell you she had full authority to override.


Every one of those statements is true. A chain ends somewhere. This one closes into a circle. One property, hundreds of regulated decisions last year, and nobody on it will say they made one.


That is not an AI problem. That is an operating model with a hole in the middle of that circle, and the software found it.


Three words get used interchangeably in this conversation and should not be.

  • Authority is who is allowed to decide.

  • Judgment is how the decision actually gets made.

  • Decision rights define who owns both.


Hold onto that, because the rest of this is about an organization that kept the first and quietly lost the other two.

Software does not take decision rights. Organizations transfer them, usually without noticing, and everything that follows is evidence of how.

If you have run properties you are already objecting: the owner set that threshold once, with counsel, and the agent is executing policy. Fair. So go find the person who set the number.


I have been in the room where that number gets set. On the client side I led the property management system implementation for our multifamily portfolio, partnered with operations start to finish. It is an implementation meeting. The vendor brings a default, somebody asks what peer properties use, you move it a few points against your approval rate, and you move on to the next screen because there are ninety more of them.


An operator will tell me that number does move, and they are right. It gets set differently by market and asset class, tightened when bad debt spikes, loosened when occupancy goes soft, revisited after an acquisition. It moves for real business reasons.


That is the harder version of the problem, not the easier one. Ask who approved the last change, why it was made, and whether anyone documented the business necessity that week. The answers are usually a name nobody remembers and a reason nobody recorded.


Listen to the language in those meetings, too. I have heard operators explain market-level differences by pointing to demographics. They almost always mean income mix and credit profile, and they are describing something real. It is still a sentence you do not want read back to you in a deposition with nothing written next to it.


So the drift is not a number sitting frozen. It is a number that moves repeatedly, for legitimate operating reasons, while nothing links those moves back to the regulated decision underneath.


There is a clean test for it. Call it the Change Log Test.


Pull the change history for your screening criteria and see whether each entry has an owner and a reason next to it. If it does, this section is not about you. If it does not, six years of changes stops being an audit trail and becomes the case.


The regional who approved the last one left in 2021. The policy is real and the document exists. What does not exist is a living owner for the judgment inside it, which is the same hole, one floor up.


For the past eighteen months the residential real estate industry has been writing settlement checks over decisions that came out of that hole. Not one of them was written because a company used artificial intelligence. Every one was written because a court asked who decided, and nobody could produce a name.


The legal attention has landed on multifamily, so it is easy to read this as an apartment story and move on. It is not.


The same question sits under every property type where software influences approvals, pricing, staffing, purchasing, or capital decisions, and it does not stop at the property line. Automated claims adjudication. Credit underwriting. Clinical triage. Resume screening. Anywhere a regulated decision now arrives as a recommendation on somebody's screen.


I am going to argue this through real estate, because real estate is where it got asked out loud first and where the answers are already public and expensive. Read the leasing office as your loan committee, your claims desk, or your intake queue. The mechanics do not change.


I have spent a decade on each side of this table, first running technology for a real estate owner, then building and selling the software. The same problem looks completely different from each chair, which is why neither side noticed the transfer happening.

The industry's biggest mistake now would be concluding it bought bad technology.


Here is why, from both chairs.


The Buyer's Chair: We Bought It to Kill Variance

Why owners bought systems that standardized operating decisions


On the owner side you are drowning in variance. Forty sites doing the same job forty ways, results you cannot compare, and no way to tell whether a bad month is the market or the manager. Every operating problem you have looks like inconsistency, because most of them are.


So you buy the system that makes everybody work the same way. That is not a technology decision in anyone's mind. It is an operating decision, and it is the right one.


Then you ask the vendor for the report that shows you who is not going along with it.

Nobody in that room is thinking about decision rights. We were thinking about comparability. Standard process, standard data, finally an apples-to-apples read across the portfolio.


The report that ranks properties by how closely they follow the system is the thing you have wanted for years, because it separates the operators who execute from the ones who improvise.


What you have actually just done is make deviation expensive. Not forbidden. Expensive.


Nobody wrote that down either, because from the buyer's chair it did not look like a transfer of authority. It looked like finally getting control.


The Vendor's Chair: We Sold It as a Recommendation

How recommendation design quietly transfers decision rights


Enterprise software lives or dies on adoption, so every roadmap conversation lands on the same question. How do we get people to actually use the number?

The answers are mechanical, and none of them were invented in a product meeting.

  • Put the recommendation at the top of the screen.

  • Make accepting it one click and overriding it four. Log the exceptions.

  • Give the regional manager a dashboard of acceptance rates by property.


Buyers like me had been asking for every piece of that by name for years. Vendors did not set out to own those decisions. They built what their customers specified.


Nobody ever said we were moving decision rights. The product was a recommendation engine, recommendations are advisory, and every deck said humans stayed in the loop.


All of that was true. Both chairs were occupied by competent people solving a real problem, and the transfer happened in the gap between them.


The buyer assumed the vendor's compliance language meant a human still decided. The vendor assumed governance was somebody else's department.


Here is what is clearer today.


A recommendation you measure, and penalize people for ignoring, is not a recommendation.


That leasing agent has an override button and has never touched it, because using it means writing a justification her regional VP reads on a Monday report. The authority is hers. The judgment left the building.


What the Settlements Took Away

Tenant screening algorithm liability and the return of human judgment


Two applicants holding federal housing vouchers sued a tenant screening company over its score. The model leaned on credit history and old debt while ignoring the voucher, which meant it punished applicants whose rent was mostly guaranteed by a public agency.


It settled for about $2.3 million. Skip the money and read the operational terms. The vendor agreed to stop putting an accept-or-decline recommendation in front of a leasing agent for voucher holders, and to hand over background information instead of a score that worked like a verdict.


That is not a model fix. That is a transfer of decision rights.


The settlement took the call away from the score and handed it back to the person clicking the button.


A lot of operators will read that as exactly backwards. The industry spent twenty years pulling judgment out of the leasing office on purpose. Discretion at the site level is where inconsistent treatment lives, and inconsistent treatment is the first thing a plaintiff's lawyer goes looking for. Nobody wants forty agents freelancing on who gets an apartment.


That is not the argument. Consistent criteria are good. Unexamined criteria are the exposure. The question was never whether the agent overrides the score. It is whether anyone above her can explain the number she is applying and defend how it was built.


Consistency without that is not compliance. It is the same decision, made wrong, at scale.


Notice where it landed for the vendor, too. That company never denied anyone an apartment, and its own product description said so in writing.


It got named as a defendant anyway, and the Fair Housing Act claims survived a motion to dismiss. Influence was enough.


The Bill

What the rent-pricing settlements actually cost, and who could have prevented them


Pricing ran the same play at a much larger scale, and the number attached to it is worth sitting with.


Roughly forty property management companies have agreed to put nearly $360 million into a settlement fund over rent-setting software, with individual shares running past $50 million and nobody admitting a thing. Read who is covered in that class definition: not every renter who was overcharged, but every renter at a property where the system was licensed.


The license is the trigger. A federal court just defined a class by which companies installed a system, which is this entire argument stated back to you in someone else's words.


Operators had always said a human reviewed every number. On paper the pricing manager decided. The adherence reports are what took that apart.


Now price the thing nobody did. A decision rights inventory across screening, pricing, renewals, and collections runs two days of working sessions and about six weeks of follow-through. Low six figures in consulting fees and a quarter of one executive's attention, set against tens of millions in exposure at the same single company.


Be honest about what the cheaper number buys, though. It would not have made an antitrust claim go away. Nobody governs their way out of the underlying conduct.

What it buys is the question, early, in front of the person who could act on it.


An operator in a conference room in 2019 asking who owns the pricing decision now, and finding out the honest answer is a vendor's default configuration and a manager whose bonus depends on adherence. That is a survivable discovery in 2019. In 2025 it is an expensive one, and by then you are not the one asking. A plaintiff's lawyer is.


Pricing, screening, collections, renewals, and approvals already belong to operations. They were never IT decisions. They are operating decisions that happen to be supported by technology, and the distinction determines who notices when the support quietly becomes the decision.


Every major operating metric already has an executive owner. Occupancy does. Bad debt does. Employee turnover does. Decision rights should too.


So the person who could have called that meeting was the COO. Not the general counsel, and not compliance. Not the CIO either, and that distinction is worth being precise about. The CIO is the architect of the decision environment, accountable for how decisions get made across the enterprise. Owning a specific operating decision is a different job, and it sits with the executive whose numbers move when that decision goes wrong.


Nobody called the meeting because nobody called it a decision. It got called a technology purchase, and technology purchases go to procurement.


The Rules Got Looser. You Did Not Get Safer.

Why deregulation increases automated decision-making compliance risk


Here is where a lot of executive teams are at risk of getting this wrong.

The compliance floor is dropping. HUD has proposed scrapping its discriminatory effects regulations, and Colorado repealed and replaced the first serious state AI framework before it ever took effect.


That reads like relief. It is not. Kill the framework and you kill the safe harbor with it. A written test tells you what passing looks like. Without one, passing gets decided case by case, by a plaintiff's lawyer picking his facts, in front of a jury. The statute never moved. What you lost is the rulebook you were planning to hold up while explaining your criteria. Ambiguity is not permission.


Then read what Colorado put back in place of what it took out. Starting in 2027: tell people when automated technology materially influences a decision about them, explain a bad outcome, and provide meaningful human review.


Three questions, in plain English.

  • Did a machine drive this?

  • Can you say why?

  • Can a person overrule it?


Answering question three means going down to the leasing office and finding out whether the agent can reach all three outcomes on her own. Approve. Approve with conditions. Deny. All three exist in the system, and the middle one is the tell. The conditions are configured too. The deposit multiple, the cosigner trigger, the income ratio that moves an applicant from approved to approved-with-a-guarantor are thresholds somebody set once. Judgment did not disappear from that outcome. It got configured. The question is not whether she is allowed to get there. It is whether anyone owns the rule that puts her there.


Loosening or tightening the rules does not change any of that. It only changes who shows up to ask.


A Consent Decree Is an Org Chart Somebody Else Wrote

Technology governance versus decision governance


Every settlement in this space has the same bones.

  • What data goes into the model.

  • What it is allowed to output.

  • Which calls need a human.

  • Who inside the company answers for it.

  • What records prove any of it.


That is a decision rights document. Authority, escalation, owner.


The only real difference between a consent decree and a governance framework is who wrote it. One gets written by your team, on your calendar, in language that fits how your business actually runs. The other gets written by a regulator or a plaintiff's firm, on their calendar, in the shape of your worst quarter.


Skip the first and you get the second.


So be clear about who writes it, because this is where most organizations hand the work to the wrong floor. There are two governance jobs, and most companies staffed only one.

Technology governance asks:

  • Is the system secure?

  • Does it perform?

  • Does it integrate?

Decision governance asks:

  • Who owns this decision?

  • Why is this threshold here?

  • Can we defend it?


Most organizations run the first list well. Few have ever named, let alone managed, the second.

Decision rights are not a new idea. MIT Sloan Management Review and Tata Consultancy Services put it plainly: leaders who do not hand out decision rights on purpose will watch their systems take them by default. What is new is how many of those rights left the building while everyone was watching the uptime dashboard.


Nobody owns that second list by default. Technology owns the systems, legal owns compliance, operations owns execution, and each one assumes another has the framework. It cannot go to procurement, which is scoring vendors, and it cannot go to IT, which answers for the system rather than the judgment inside it. Executive leadership owns it, for the same reason it owns the org chart. Nobody else is positioned to say which decisions the company is willing to let a system make.


If you cannot name who owns an algorithm's business rules, you have already lost control of the decision.


Real Estate Is Just Early

AI decision rights in healthcare, lending, insurance, and hiring


So swap the nouns, as promised, and watch the shape hold.

  • A health system runs AI triage and reports clinician override rates.

  • A lender automates underwriting and leaves a manual exception path nobody uses, because exceptions slow the pipeline.


One is deciding who gets seen and one is deciding who gets funded, and both have somebody clicking accept all day. Both moved a regulated decision out of a person and into a system without anyone approving the move, because nobody ever called it a move.


Real estate is about two years ahead on the litigation curve. It did not buy worse software. It bought software that influenced regulated decisions at enormous volume, in an industry with organized plaintiffs' counsel. Everybody else bought the same thing later.


Agentic systems shorten whatever time is left. One that executes instead of recommending removes the last practical opportunity for human judgment.


What Leaders Should Assess Next

An AI decision rights framework: the Change Log Test, the Signature Audit, and decision governance


This is smaller than most AI governance programs. It needs an inventory, not a committee, and nobody has to understand the math.


Start by counting, and be strict about what counts. Not every process with software in it. The ones where a system produces a recommendation about a specific person and somebody accepts it. In a real estate operation that is applicant screening, fraud screening, rent pricing and renewals, collections and eviction filing, and how advertising gets targeted. Five or six processes, bought at different times, from different vendors, by different people, none of whom were assigning authority.


Apply the same test in your own business and the list will be about that long. Short enough to inventory in an afternoon. Long enough that nobody has.


Three pieces.


So run the Signature Audit. Six questions. One hour. One inventory. The name is the point: you are looking for the decisions that lost their signature.


For each one:

  • What is the decision? Not the tool. Not the use case. The decision. Screening is a process. Deny this application is a decision. Only one of the two can be handed to a person.

  • Who owns it, by name? Not a department. Not a committee. Not a vendor. Someone whose bonus moves when the outcome moves.

  • Is the override real? Pull the rate. Near zero across thousands of decisions means the criteria are carrying the decision, not your people. That is not automatically wrong. It does mean your exposure sits entirely in the criteria, which is where the Change Log Test earns its keep.

  • Can you explain a denial to the person you denied? Plain language, thirty days, without calling the vendor. Needing a third party's help to explain your own decision means you gave away something you cannot give away.

  • What would you hand over in discovery? The test is not whether the framework exists. It is whether the paper it throws off backs up your story.

  • Where did the contract move the decision? Read the indemnification clause beside the product description. Vendors say in writing that they supply information, not decisions. That sentence is a liability transfer, and it usually works.


Two answers come back from that audit more often than any others. Both are findings, not dead ends.


The first is the vendor citing proprietary logic. Ask a screening or pricing provider to explain the business-necessity basis for a threshold and you will sometimes get trade secret in reply. Take the refusal as your answer. A rule you cannot explain to an applicant or a regulator is a rule that has taken authority you are not able to defend, and the contract protecting the vendor's model does nothing to protect you.


The second is no owner at all. It comes back as a committee, a vendor default, or somebody who left in 2021. Do not wait for a policy rewrite to fix that. Assign the name that week, to the P&L leader whose budget carries the workflow, and give that person authority to reaffirm the current thresholds or pause them. An interim owner who reaffirms a threshold has made a decision. An empty box has not.


Then make four things standing practice rather than a project.

  1. Identify every significant automated recommendation in the business.

  2. Assign a named business owner to each decision it drives.

  3. Put the assumptions behind it on a review schedule, the way you would any other operating number.

  4. And write down when a threshold changes and why, because the version of that answer you reconstruct three years later under oath is worth far less than the one you wrote the week you made the change.


Review them on the same cadence as any other material policy. If pricing assumptions get looked at quarterly, so do the rules behind automated pricing. The goal is not changing numbers more often. It is that changes happen on a calendar, in front of the accountable executive, with the reason written down the week it was decided.


None of that requires a data scientist. It requires an executive deciding that these are business decisions, and treating them the way the company already treats every other decision that matters.


The Signature Line

Restoring named accountability to automated decisions


Decisions like this used to carry a signature. That was never a formality. It was the moment the company worked out who was on the hook, and it happened by itself, because nothing moved until somebody signed.


Automation removed the signature line. Nobody noticed, because the work still got done.


Go back to the leasing office. She is not doing anything wrong. She is applying the criteria she was given, quickly and the same way every time, which is what she was hired to do and what her company would tell a court it wanted.


The judgment that used to live in those ninety seconds did not disappear when the software arrived. It moved, one configuration screen at a time, into business rules that somebody adjusts whenever conditions demand it, without ever writing down who, or why.


That is the part worth naming, because in most companies it is not coming. It already happened. Not artificial intelligence seizing decisions from executives.


Judgment migrating quietly out of people and into process, with no meeting, no approval, and nobody's name on it.


Put your name back on the form.


A version of this argument, written for a different room, is live at Lumerai Advisors.


There are four seats in the name. The fifth one is yours.

Comments


bottom of page