Solutions · public benefits & citizen rights

Benefits decisions run at machine speed. Citizen rights outrank the algorithm.

Between 2005 and 2019, the Dutch childcare-benefits system flagged families through risk selection that used nationality, recovered benefits all-or-nothing, and served decisions its own reviewers could not explain. Tens of thousands of families were harmed; the 2020 parliamentary inquiry found a rule-of-law failure. The KYE Public Benefits & Citizen Rights Authority Profile™ from KYE Protocol™ binds every benefits action to the Rights-Bounded Authority Stack™ — so no policy rule, risk score or agent ever outranks the rights above it.

The worked failure

What the childcare-benefits scandal actually broke.

The Toeslagenaffaire was not a model accuracy problem. Every layer that should have bound the system — rights, statute, proportionality, explanation, appeal — was silently overridden by the layers below it. Four documented failures, stated factually and with respect for the families who carried them:

Risk selection used nationalityThe risk-classification model processed (dual) nationality as an input. The Dutch Data Protection Authority found the processing unlawful and discriminatory in its 2020 investigation.a policy rule overrode fundamental rights
Review without explanationsFamilies received stop-and-repay decisions that caseworkers and courts could not reconstruct the reasons for. Human review existed on paper; explanation did not.decision without notice or reasons
All-or-nothing recovery, contest laterA formal error was treated like fraud: full repayment of years of support, enforced first, contested after — bankrupting households before any appeal was heard.consequence before contestability
Population-scale harm, invisible per caseRoughly tens of thousands of families were affected. Each file looked procedurally routine; the aggregate pattern carried the signal for years. The parliamentary inquiry, Unprecedented Injustice (2020), concluded fundamental rule-of-law principles had been violated.no aggregate harm monitor
The doctrine

The Rights-Bounded Authority Stack™ — ten layers, one invariant.

Every benefits action a system or agent proposes is admitted — or refused — against a fixed ordering of authority. Your policy rules and models live at layer 6. They can narrow what the layers above permit. They can never widen it.

  1. Fundamental rights non-discrimination, due process, proportionality as a right — the floor nothing below may cross
  2. Legislation the statute that confers the power being exercised
  3. Judicial constraints binding court rulings interpreting both
  4. Institutional mandate the agency’s lawful remit
  5. Delegated authority the named official or system acting, with a live delegation chain
  6. Policy rules eligibility criteria, risk models, recovery rules — narrowing only
  7. Case evidence the recorded facts of this citizen’s case, sufficient for this decision state
  8. Proportionality means-end fit for this case, recorded before finality
  9. Decision the determination — admissible only when every layer above holds
  10. Notice, challenge, remedy the explained receipt, the live challenge route, the correction path

The invariant: no lower layer overrides a higher layer. A risk score that a right forbids is refused at the action boundary — whatever the score says. That single mechanical rule is what the scandal lacked.

Ungoverned vs governed

The Benefits Scandal That Cannot Happen™

The same five failure modes, run twice: once as they executed in an ungoverned stack, once against a stack where KYE Protocol™ sits at the action boundary. Each governed refusal is a named rule with its own reason code, evidenced and replayable.

Ungoverned, as it happened

  • Nationality flows into risk selection; nobody above the model authorised it.
  • A risk score is treated as fraud — signal, suspicion, error and consequence collapse into one automated step.
  • Recovery executes first; the family contests later, from under the debt.
  • The decision arrives with no reasons a caseworker, court or citizen can reconstruct.
  • Each case looks routine; the discriminatory aggregate pattern runs for years.

Governed by KYE™

  • A protected attribute or proxy without a recorded lawful-basis justification is refused before the model output moves anywhere.
  • Decision states never collapse: risk signal ≠ suspicion ≠ error ≠ fraud ≠ consequence — each transition needs its own named authority and state-sufficient evidence.
  • An open challenge window pauses enforcement; genuine urgency rides a separate, time-boxed emergency authority with its own sign-off and hard expiry.
  • Every served determination carries a Citizen Decision Receipt™ — plain-language reasons, the challenge route, and a verifiable evidence reference.
  • The Population Harm Monitor watches disparity, appeal-reversal and complaint rates per rule — a breached trigger suspends the rule until a named authority reviews it.
The governed action set

23 governed actions, 5 decision states, 1 immutable history.

The profile binds 19 benefits-specific action classes — from flagging a risk signal to compensating a citizen — plus four reused data and legal classes for collecting, disclosing, exporting and producing case data. Every class carries its reversibility, its consequence tier, and its default human-oversight mode; the irreversible ones wait for two named people, some with legal review.

Signal → investigationA risk signal is a lead, not a finding. It authorises exactly one thing: a named official opening a review with case-specific grounds recorded.per-transition authority
Error is not fraudAn honest mistake triggers correction and proportionate adjustment. A fraud label needs the highest evidence bar and legal review before it attaches.two-person with legal
Consequences waitSuspension, termination, repayment, offset, prosecution referral — admissible only from an established error or fraud state, with proportionality recorded and the challenge window clear.contestability first
Corrections supersedeHistory is written once and kept forever; a correction is a new, linked decision — with reinstatement and compensation where due. Evidence finality is not decision irreversibility.immutable history · linked remedy

For your audit and legal teams the payoff is concrete: reconstructing the full legal basis of any decision — who authorised it, at which state, under which layer — goes from months of file archaeology to minutes of replay against the sealed Evidence Pack™, and it cuts exam-preparation for an oversight review from weeks to days.

Who this is for — and what it honestly is

Benefits administrations, their integrators, and the bodies that oversee them.

One authority spine, three wedges — and an honest boundary around what KYE™ does and does not claim.

Benefits administrationsTax, welfare and family-benefit agencies deploying AI-assisted casework: grant machine speed to the routine, and make the consequential wait for layered, named authority you can defend to a parliament.
GovTech integrators“Our casework agent cannot exceed its authority, and here is the replayable proof” is the sentence that survives procurement, DPIA review and the ombudsman’s first letter.
Oversight bodiesOmbudsmen, DPAs, courts and inquiries get what the Toeslagenaffaire archaeology never had: the decision-state chain, the authority basis per layer, and the aggregate harm signals — replayable on demand.

The honest boundary: KYE Protocol™ governs whether a benefits action may proceed — under which named authority, at which decision state, with contestability intact — and proves that basis. It does not adjudicate Dutch or EU law, does not replace the court or the ombudsman, and claims conformance only with frameworks it has actually mapped. The scandal is cited here as a worked failure mode, never as a claim that any protocol would have undone a specific historical injustice. Start with the authority diagram of your own benefits stack, then a scoped pilot on your highest-consequence action class.