Overview
How might we design responsibility attribution so people can trust and act on AI output?
When to use
- Essential for multi-agent systems, enterprise automation, and shared collaborative environments where clear accountability across agents and humans is required for audits, incidents, and trust.
When to skip
- Solo sandboxes where a single user is always the actor.
- Anonymous public demos where identity is intentionally absent.
- High-volume telemetry where per-event attribution UI would overwhelm (summarize instead).
Rules
Commits or edits marked only as “AI” with no model or agent id.
Human users taking blame for silent agent side effects.
Attribution that disappears after merge or publish.
Ambiguous co-author tags that mix reviewer and generator.
Evidence
| Product | Implementation |
|---|---|
| Git | Co-authored-by trailers for human and tool contributors. |
| GitHub | Commit and PR attribution including Copilot-assisted changes. |
| Stripe Radar | Event logs that separate system and human decisions. |
| Kubernetes | Audit logs naming user, service account, and verb. |