At 3:40 in the morning the denial goes out, and it is correct. The tumor carries a mutation nobody had sequenced when the coverage pathway was written, so the request lands outside the covered indication. A reviewer applied the policy as written to the facts as coded, and an auditor walking the file would find nothing out of place.
An appeal will follow, and it will ask one question: was the policy applied correctly? It will not ask whether a policy that cannot see this mutation should govern this patient.
Two different failures arrive in the same envelope. A person can fail to qualify under a sound rule. A rule can fail to describe the person. Almost every institution I have worked inside produces identical paperwork for both, then treats the paperwork as the finding.
The appeal leaves the category alone
An appeal is a decision-level instrument. It re-runs the determination against the same criteria, with the burden on you to show the criteria were misread. That matters — it is the difference between a bureaucracy and a whim — but it leaves the category untouched by design, and the stamina it demands does most of the sorting before anyone reaches a decision at all.
Watch where the mismatch goes in the meantime. When a case contradicts the model, the cheapest available move is to reclassify the person rather than the model. Michigan's MiDAS system issued unemployment fraud determinations without human review for two years; when the state finally examined the files, the error rate ran past ninety percent, and in the meantime tens of thousands of people had wages garnished on the strength of a pattern match. Britain's Post Office prosecuted hundreds of subpostmasters over shortfalls its Horizon accounting software had invented, because it read every discrepancy between a person and a computer as evidence about the person.
Neither institution broke its own rules. Both were structurally incapable of hearing the case against the rule. Instead the applicant becomes the crumple zone — the part designed to absorb the impact so the machinery survives it intact — and once the absorption works, the fraud story writes itself.
Two questions decide everything
When a life collides with an administrative category, the outcome turns on two things.
The first is who has to bend. Either the person bends to fit the rule, or the institution bends to fit the person.
The second is what you have standing to contest — standing in the sense of being able to force a system to metabolize your reality into an obligation, not in the sense of being believed. You may have standing over the decision. You may have standing over the rule that produced it. These are different powers, and most systems grant the first while treating the second as out of scope.
Cross them and you get four postures.
Exclusion. The rule is fixed, nobody outside has standing, and the person absorbs the difference. During the Madras famine of 1876, the colonial administration kept grain exports moving under a doctrine that treated relief as market interference. Starvation without purchasing power registers as zero demand, so the ledger stayed clean while the population it described died.
Managed accommodation. The institution notices the mismatch and adjusts around it while keeping control of the terms. Predictive child-welfare screening does this: the model routes a household into monitoring, and the agency may retune the model, but the family scored by it never acquires any say over what the score is for.
Adversarial correction. You get standing over the decision and nothing more. Goldberg v. Kelly established in 1970 that welfare benefits could not be cut off without a hearing first, a real protection, and it was won at cost. It still only asks about procedure. A claimant argues about fit; the statute that set the boxes is not a party to the argument.
Corrigibility. The mismatch counts as evidence against the category, and the people it excluded can force the category open. When ACT UP went after the FDA in the late 1980s, they were not asking for compassionate-use exceptions one patient at a time. They attacked the trial design itself, and the parallel track and accelerated approval pathways that came out of it changed what counted as evidence for everyone who came after.
Most reform stalls between the third and the fourth, because the third feels like justice and costs the institution nothing structural.
What the PACT Act did instead
The standard response to a category that keeps injuring people is to build another lane of process around it: an ombudsman, a review board, a second-level appeal. Each lane taxes time and literacy and stamina, and the person least able to pay is the one who pays. Together they convert a defective rule into a private endurance test.
Compare how the same problem got solved for veterans. Proving that a specific cancer came from a specific burn pit is close to impossible for an individual, and for decades the Department of Veterans Affairs let each dying claimant try. The PACT Act stopped requiring it: for more than twenty conditions, service in the relevant place and time now carries a presumption, and the institution absorbs the causal question it had been offloading. Congress finally read thousands of individually unwinnable cases as one badly written rule.
An ordinary appeal asks whether the agency applied the rule correctly. Almost nobody has standing to ask whether the pattern of failures shows the rule is wrong.(note 1)
Building the threshold
Stability is the fair objection here: if every losing claimant could reopen the statute, nothing would ever be settled. So the fix is a threshold rather than unlimited appeal — a point at which accumulated exceptions stop being individual variances and become an obligation to look at the category.
That requires an institution to keep the evidence in the first place. Near-misses and manual overrides and the cases a caseworker quietly fixed are currently administrative residue, discarded at the point where they would be most useful. An agency that logged them would know within a quarter which of its criteria were failing and for whom.
Everything else follows. Clustered reversals on appeal have to trigger rulemaking rather than another round of one-off settlements, since paying individual claimants is how an agency currently buys the right to keep the rule. Assumptions and training data behind a scoring model have to survive long enough to be inspected. And consequential classifications need to expire on a schedule, so that continuing to use one becomes a decision somebody makes rather than a default nobody revisits.
None of this is exotic. It is the difference between preaching at institutions and engineering them, and the mechanisms are boring on purpose.(note 2)
%% title: Where an adverse decision can travel
%% caption: Both paths start from a rule applied correctly. Only the threshold path can reach the rule itself.
flowchart LR
classDef actor stroke-width:1.6px;
classDef system stroke-width:1.2px;
classDef gate stroke-width:1.6px;
classDef binding stroke-width:3px,font-weight:bold;
classDef status stroke-dasharray:4 3;
classDef repair stroke-width:2.4px,font-weight:bold;
classDef failure stroke-width:2.2px,stroke-dasharray:6 3;
P([Person]):::actor --> A[Adverse decision]:::system
A --> G{Appeal}:::gate
G -- upheld --> D([Drop-off]):::failure
G -- reversed --> R([Individual reversal]):::repair
R -. closed as variance .-> V([Category untouched]):::status
D --> E[Exception logged]:::system
R ==> T{Cluster past threshold}:::gate
E ==> T
T ==> M[[Rulemaking obligation]]:::binding
M ==> C([Category rewritten]):::repair
Which direction the information runs
The technologist's version of this argument goes wrong in a specific way: if the institution's picture of you is too thin, collect more of you.
The Dutch childcare-benefits scandal is the counterexample. The tax authority's fraud model treated dual nationality as a risk signal and wrongly accused tens of thousands of families, driving parents into debt and children into foster care. That system was not short of data. It was rich in data and structurally deaf, and handing each family a printout of which coefficients ruined them would have changed nothing about their position. Transparency is not corrigibility. Showing someone the blueprint of the cage does not open it.
Sometimes fidelity runs the other way and requires the state to know less. The secret ballot and the limits on biometric collection are not friction waiting to be optimized away; they are what keeps a person from being sorted before they have acted. Everything depends on which way it flows. Downward, the citizen becomes legible to the system. Upward, the system becomes answerable to the citizen. Only one of those is a democratic property, and collecting more will never produce it.
The polite version is the dangerous one
No government can abolish scarcity or tragedy. Budgets end, beds run out, and majorities beat minorities. Political equality never promised that you would win.
It promises something narrower and harder: that nobody gets to arrange your loss out of view to keep a diagram clean.
Regimes worth fearing rarely announce themselves. They are the ones that answer within one business day, log the complaint, confirm that the manual was followed, and carry on unchanged — having built an architecture in which nothing a person actually experiences is admissible against the rule that governed them.
A democracy has to categorize and decide; it has no alternative. What happens after is the whole of it, and whether the threshold ever gets built before the bodies is the part I cannot answer. The PACT Act took decades and a great many funerals. Michigan, Horizon, the Dutch families — those are still open.
Note 1.
Legal machinery for this exists in the literature. Charles Sabel and William Simon call it a destabilization right: when an institution's failures are systemic rather than incidental, the remedy is a duty to restructure rather than damages for the person who happened to sue. On the cost of the endurance test the current arrangement substitutes for it, see Pamela Herd and Donald Moynihan on administrative burden, and Proof of Existence for what it feels like from underneath.
Note 2.
That exception log is the load-bearing one, and it is the one an institution has the least incentive to keep. A near-miss that a caseworker fixed by hand is evidence that the category is drifting, and it is also evidence that the category is currently working — which is exactly how a metric survives the thing it was meant to measure.