Ownership becomes visible on an ordinary bad day. The reviewer is absent, a permission changes, and a plausible but wrong result waits in the queue. Someone must be able to decide whether the work continues, changes route, or stops.
That decision rarely belongs to the person who bought the software by default. Configuration, professional review, and operating ownership call for different authority, even when a small team assigns all three to one person.
This article provides general operational education. It is not legal advice or a compliance determination. No attorney-client relationship exists, and none of its protections apply.
Own a result that can be observed
Start with a workflow that has a recognizable end. “AI adoption” is too broad for an operating owner. “Prepare a draft invoice record for a legal operations analyst to confirm” gives the owner something to manage.
Write down what counts as completed work, who receives it, and what the AI may change. Include the manual route when the system is unavailable.
The owner should know where errors appear and how people report them. They should also be able to find the current instructions and the evidence supporting continued use.
This is an operating recommendation. It is not a requirement to create a new job title or hire another person.
Three decisions that need names
The workflow owner manages the process. They set the operating scope, arrange review capacity, track exceptions, and coordinate changes. They decide whether the workflow remains useful within the authority the organization gives them.
The reviewer decides whether particular work is acceptable. They need the relevant expertise, source material, acceptance criteria, and authority to reject the output. Professional judgments stay with the appropriate qualified person.
The administrator controls the technical setup. They manage approved accounts, permissions, connections, and configuration. A request to add access goes through the organization's existing approval process.
One person may perform all 3 roles in a small team. Record which decision they are making, and use separate approval where the firm's rules require it. A small team still needs a workable absence route.
The NIST AI RMF Core supports documenting responsibilities and communication lines. Its GOVERN function also addresses human oversight. These are voluntary framework outcomes, not a prescribed staffing chart.
What the owner must be able to do
Ask the proposed owner to demonstrate 4 things:
- Find the current workflow instructions and approved inputs.
- See the queue of rejected, incomplete, or disputed outputs.
- Pause new work or reach the person authorized to pause it.
- Route affected work to an approved fallback and arrange a restart decision.
If the owner can only send a message to a busy developer, the pause procedure needs a named backup and a clear response route. Do not assume a software vendor can stop the organization's downstream work.
Pausing should not make records disappear. Identify work already sent, records already changed, and items still waiting. The owner needs that distinction to decide what requires follow-up.
The absence test
Consider a fictional invoice-intake workflow. An assistant extracts fields into a draft record. An analyst compares them with the invoice before the record enters the payment process.
The analyst is away. A backup reviewer has the required access and knows the acceptance criteria. The workflow can continue within its existing scope.
If the backup cannot verify the record, it remains queued or follows the approved manual process. Silence does not become approval. The workflow owner tells the receiving team about any delay.
This example adds no authority to approve invoices or release payments. Those decisions remain in the existing process.
An absence rehearsal can be short. Give the backup one ordinary item and one item with a missing field. Confirm they can find the evidence and choose the correct route without the usual reviewer explaining it.
A new permission changes the workflow
In a second fictional example, a contract-summary assistant reads files from one approved folder. Someone wants to connect the entire document repository to improve its answers.
That request changes the information boundary. The administrator should not treat it as a routine convenience setting. The workflow owner identifies the business need; the appropriate information owner decides the access question.
After approval, test retrieval and permissions using approved test material. Include a document the test user should not be able to retrieve. A correct summary does not prove that access controls work.
Record the change, affected workflows, test result, and return path. Keep the previous working configuration identifiable so the administrator can restore it if the change fails.
Stopping is incomplete without a restart rule
A system can produce plausible outputs while the owner is still investigating an error. Define who may restart it and what they need to see.
For example, a restart might require a corrected source connection, successful exception tests, and confirmation that affected records were checked. The conditions depend on the workflow and the consequences of the failure.
The NIST AI RMF Playbook includes guidance on bypassing or deactivating systems and planning continuity. Our suggested ownership card applies that idea to one operating process. Completing the card does not establish that a workflow is safe or compliant.
The test is the handoff
Ownership is not a name in a register. It is whether the process survives the owner's absence, a disputed output, and a changed permission without a call to the person who built it.
Run those 3 cases with the checkpoint and ownership card open. The assignment is real when all 3 hold. The backup can find the queue, the reviewer can say why an output was rejected, and the administrator can show the previous configuration. If any of the 3 still routes through the builder, the card is not finished and the workflow is not yet owned.
A small firm may put 1 person in all 3 roles. That is workable. What is not workable is having no answer for the day that person is out.
When the ownership questions are open across several workflows at once, Ortaire's AI Implementation Support can run this assignment with the team. The Toolkit's Human Oversight & Accountability framework covers the record on its own.
Sources used
- NIST AI RMF Core, AI RMF 1.0, January 2023; checked September 18, 2026. See GOVERN 2.1 and 3.2.
- NIST AI RMF Playbook: MANAGE, checked September 18, 2026. See MANAGE 2.4 on bypass, deactivation, and continuity.




