Nobody Decided to Let Software Decide

Lumerai Advisors article cover for Nobody Decided to Let Software Decide, showing the AI decision rights framework in three tiers: the Change Log Test, the Signature Audit, and decision governance

Decision rights have been migrating out of people and into business rules for decades. Real estate just got the bill first.

A leasing agent at a 300-unit property works through a stack of applications every week.

One comes in. She pulls the screening report. There is a number on it. The number is below the threshold her company set. She clicks decline, sends the adverse action notice, and moves to the next one. Total elapsed time, ninety seconds.

Ask her who decided to deny that applicant and she will tell you the system said decline. She is not dodging. That is an accurate description of what happened.

Now ask everybody above her. The screening vendor does not make leasing decisions, it provides information. The property manager applied the criteria the owner approved. The owner hired a professional manager and a licensed screening provider precisely so it would not be making these calls one unit at a time. The regional VP will tell you she had full authority to override.

Every one of those statements is true. A chain ends somewhere. This one closes into a circle.

That is not an AI problem. That is an operating model with a hole in the middle of that circle, and the software found it. It is also an AI decision rights problem, and it is older than the AI.


What Actually Moved

Authority, judgment, and decision rights are not the same thing

Three words get used interchangeably here and should not be. Authority is who is allowed to decide. Judgment is how the decision actually gets made. Decision rights define who owns both.

Software does not take decision rights. Organizations transfer them, usually without noticing.

The legal attention has landed on multifamily, so it is easy to read this as an apartment story and move on. It is not. Automated claims adjudication. Credit underwriting. Clinical triage. Resume screening. Anywhere a regulated decision now arrives as a recommendation on somebody’s screen, the same transfer has already happened.

I have spent a decade on each side of this table, first running technology for a real estate owner, then building and selling the software. The same problem looks completely different from each chair, which is why neither side noticed.


The Buyer’s Chair

Why owners bought systems that standardized operating decisions

On the owner side you are drowning in variance. Forty sites doing the same job forty ways, results you cannot compare, and no way to tell whether a bad month is the market or the manager.

So you buy the system that makes everybody work the same way. That is not a technology decision in anyone’s mind. It is an operating decision, and it is the right one.

I have been in the room where those numbers get set. On the client side I led the property management system implementation for our multifamily portfolio, partnered with operations start to finish. It is an implementation meeting. The vendor brings a default, somebody asks what peer properties use, you move it a few points against your approval rate, and you go to the next screen because there are ninety more of them.

Then you ask the vendor for the report that shows you who is not going along with it.

Nobody in that room is thinking about AI decision rights. We were thinking about comparability. What we had actually done was make deviation expensive. Not forbidden. Expensive. Nobody wrote that down, because from the buyer’s chair it did not look like a transfer of authority. It looked like finally getting control.


The Vendor’s Chair

How recommendation design transfers decision rights

Enterprise software lives or dies on adoption, so every roadmap conversation lands on the same question. How do we get people to actually use the number?

The answers are mechanical, and none were invented in a product meeting. Put the recommendation at the top of the screen. Make accepting it one click and overriding it four. Log the exceptions. Give the regional manager a dashboard of acceptance rates by property. Buyers like me had been asking for every piece of that by name for years. Vendors did not set out to own those decisions. They built what their customers specified.

Nobody ever said we were moving decision rights. The product was a recommendation engine, recommendations are advisory, and every deck said humans stayed in the loop. All of that was true. Both chairs were occupied by competent people solving a real problem, and the transfer happened in the gap between them.

Here is what is clearer today. A recommendation you measure, and penalize people for ignoring, is not a recommendation.

That leasing agent has an override button and has never touched it, because using it means writing a justification her regional VP reads on a Monday report. The authority is hers. The judgment left the building.


What It Cost

Rent-pricing settlements, screening liability, and a receding regulatory floor

Roughly forty property management companies have agreed to put nearly $360 million into a settlement fund over rent-setting software, with individual shares running past $50 million and nobody admitting a thing. Read who is covered in that class definition: not every renter who was overcharged, but every renter at a property where the system was licensed. The license is the trigger. A federal court just defined a class by which companies installed a system, which is this entire argument stated back to you in someone else’s words.

Screening produced its own version. A tenant screening company settled claims that its score penalized applicants holding federal housing vouchers, and agreed to stop putting an accept-or-decline recommendation in front of a leasing agent for those applicants. That is not a model fix. That is a transfer of decision rights, back to the person clicking the button.

Do not read the receding regulatory floor as relief. HUD has proposed scrapping its discriminatory effects regulations and Colorado repealed and replaced the first serious state AI framework before it took effect. Kill the framework and you kill the safe harbor with it: passing now gets decided case by case, by a plaintiff’s lawyer picking his facts, in front of a jury. And what Colorado put back asks three questions in plain English. Did a machine drive this? Can you say why? Can a person overrule it?

Answering the third one means going down to the leasing office and finding out whether the agent can reach all three outcomes on her own. Approve. Approve with conditions. Deny. All three exist in the system, and the middle one is the tell. The conditions are configured too. The deposit multiple, the cosigner trigger, the income ratio that moves an applicant from approved to approved-with-a-guarantor are thresholds somebody set once. Judgment did not disappear from that outcome. It got configured. The question is not whether she is allowed to get there. It is whether anyone owns the rule that puts her there.


Two Governance Jobs

Technology governance versus decision governance

Every settlement in this space has the same bones. What data goes into the model. What it may output. Which calls need a human. Who answers for it. That is a decision rights document, and the only real difference between a consent decree and a governance framework is who wrote it. One gets written by your team, on your calendar. The other gets written by a regulator or a plaintiff’s firm, in the shape of your worst quarter.

Most organizations hand that work to the wrong floor, because there are two governance jobs and most companies staffed only one.

Technology governance asks:

  • Is the system secure?
  • Does it perform?
  • Does it integrate?

Decision governance asks:

  • Who owns this decision?
  • Why is this threshold here?
  • Can we defend it?

Most organizations run the first list well. Few have ever named, let alone managed, the second. Decision rights are not a new idea. MIT Sloan Management Review and Tata Consultancy Services put it plainly: leaders who do not hand out decision rights on purpose will watch their systems take them by default. What is new is how many of those rights left the building while everyone was watching the uptime dashboard.

Pricing, screening, collections, renewals, and approvals already belong to operations. Every major operating metric already has an executive owner. Occupancy does. Bad debt does. Employee turnover does. Decision rights should too. The CIO is the architect of the decision environment; owning a specific operating decision is a different job, and it sits with the executive whose numbers move when that decision goes wrong.

Swap the nouns and the shape holds. A health system runs AI triage and reports clinician override rates. A lender automates underwriting and leaves a manual exception path nobody uses, because exceptions slow the pipeline. One decides who gets seen and one decides who gets funded, and both have somebody clicking accept all day. Real estate is simply two years ahead on the litigation curve. Agentic systems shorten whatever time is left, because a system that executes instead of recommending removes the last practical opportunity for human judgment.


Three Pieces

An AI decision rights framework: the Change Log Test, the Signature Audit, and decision governance

Three pieces, and together they are how you get AI decision rights back.

The Change Log Test. One decision.

The Signature Audit. Every significant automated decision.

Decision governance. The operating discipline that keeps them owned.

The Change Log Test is an hour of work on a single decision. Pull the change history for its criteria and check whether every entry has a named owner and a documented reason beside it. If it does, you are governed. If it does not, six years of changes stops being an audit trail and becomes the case.

An operator will tell me those numbers do move, and they are right. Thresholds get set differently by market and asset class, tightened when bad debt spikes, loosened when occupancy goes soft. They move for real business reasons. The drift is not a number sitting frozen. It is a number that moves repeatedly while nothing links those moves back to the regulated decision underneath.

The Signature Audit scales that across the business. Be strict about what counts: only processes where a system produces a recommendation about a specific person and somebody accepts it. In real estate that is applicant screening, fraud screening, rent pricing and renewals, collections and eviction filing, and how advertising gets targeted. Five or six processes, bought at different times, from different vendors, by different people, none of whom were assigning authority.

Six questions. One hour. One inventory. You are looking for the decisions that lost their signature.

  • What is the decision? Not the tool. Not the use case. Screening is a process. Deny this application is a decision. Only one can be handed to a person.
  • Who owns it, by name? Not a department. Not a committee. Not a vendor. Someone whose bonus moves when the outcome moves.
  • Is the override real? Pull the rate. Near zero across thousands of decisions means the criteria are carrying the decision, not your people.
  • Can you explain a denial to the person you denied? Plain language, thirty days, without calling the vendor.
  • What would you hand over in discovery? The test is not whether the framework exists. It is whether the paper it throws off backs up your story.
  • Where did the contract move the decision? Read the indemnification clause beside the product description.

Two answers come back more often than any others, and both are findings rather than dead ends.

The first is a vendor citing proprietary logic. Take the refusal as your answer. A rule you cannot explain to an applicant or a regulator is a rule that has taken authority you are not able to defend.

The second is no owner at all: a committee, a vendor default, or somebody who left in 2021. Do not wait for a policy rewrite. Assign the name that week, to the P&L leader whose budget carries the workflow, and give that person authority to reaffirm the thresholds or pause them. An interim owner who reaffirms a threshold has made a decision. An empty box has not.

Then make it standing practice. Identify every significant automated recommendation. Assign a named business owner to each. Review the assumptions on the same cadence as any other material policy. And write down when a threshold changes and why, because the version you reconstruct three years later under oath is worth far less than the one you wrote that week.


The Signature Line

Restoring named accountability to automated decisions

Decisions like this used to carry a signature. That was never a formality. It was the moment the company worked out who was on the hook, and it happened by itself, because nothing moved until somebody signed.

Automation removed the signature line. Nobody noticed, because the work still got done.

Go back to the leasing office. She is not doing anything wrong. She is applying the criteria she was given, the same way every time, which is what she was hired to do and what her company would tell a court it wanted. The judgment that used to live in those ninety seconds did not disappear when the software arrived. It moved, one configuration screen at a time, into business rules that somebody adjusts whenever conditions demand it, without ever writing down who, or why.

That is the part worth naming, because in most companies it is not coming. It already happened. Not artificial intelligence seizing decisions from executives. AI decision rights transferred out of people and into process, with no meeting, no approval, and nobody’s name on it.

Put your name back on the form.


Brian Zrimsek has occupied all four seats in enterprise software: advisor at Big Six consultancies, analyst at Gartner, client at Irvine Company, and provider at MRI Software. He is the Enterprise Software and Commercial Real Estate Specialist for Lumerai Advisors and the founder of The Four Seats (thefourseats.net), where he writes on enterprise software and PropTech.

The Hidden Risk of AI: Building Transformation Programs for a Future That May Not Exist

The AI ROI Panic Is About to Create the Next Legacy System