<!-- generated by scripts/generate-agent-docs.ts -->

> **HALA: Human-AI Layered Architecture**
> A pattern language for designing AI systems that can say what humans cannot due to social cost, political risk, or career consequences. 28 patterns across 5 layers for building AI that surfaces uncomfortable truths.
>
> Source: https://jasonstiltner.com/writing/hala/

---

[Writing](https://jasonstiltner.com/writing/) · HALA

# HALA: Human-AI Layered Architecture

A pattern language for the things AI can say that humans can't.

Updated Jan 2026

> “If a role is socially costly, politically dangerous, or career-limiting for a human, it is a prime candidate for an AI pattern.”

28 patterns · 5 layers · 6 new in v2

5 processing layers, plus a separate Decision Output stage that isn't a layer itself — it's where every layer's output has to land: a signed human decision.

Try the Demo · [Download PDF](https://jasonstiltner.com/HALA_v2_Pattern_Language.pdf) · Explore Patterns

## The Problem

Organizations systematically fail to surface certain truths—not because people don't know them, but because **saying them carries unacceptable personal cost**.

“This project should be killed”
→ Career risk if you championed it

“The executive's proposal has fatal flaws”
→ Political suicide

“We're slowly abandoning our stated values”
→ Labeled as not a team player

“This decision will hurt us in 5 years”
→ Dismissed as speculation

HALA addresses this by designing AI systems that can occupy these roles—saying what needs to be said without the human bearing the social cost.

## Accountability, Not Laundering

A sharp reader will have already spotted the problem with the framing above: if the AI says the uncomfortable thing, does that just let the human off the hook? “The system said it” is a benefit right up until it becomes a way to launder a decision without anyone owning it. That isn't a hypothetical edge case — it's the central objection to this entire pattern language, and it deserves a design answer, not a disclaimer.

The resolution is a first-class design principle, not an afterthought:

A HALA pattern may own the claim. It never owns the decision. Every worked example in this language — including the EHR migration scenario below — ends the same way: a named human reviews the pattern's output, the evidence and dissent behind it, and signs the decision. Not “the system was right.” [Override Protocol](#patterns) makes overriding any Agency-layer output a first-class, low-friction action; [Decision Historian](#patterns) makes the record of who decided, and on what basis, permanent and searchable. Together they're what make this a resolution instead of a promise.

There is a second objection this language has to face honestly: the social cost of dissent may not be eliminated — it may be relocated. Someone chooses to deploy Mr Unpopular; someone invokes Kill Switch Advocate in the meeting where the CFO's project is on the table; and everyone in the room knows who. Whether AI truth-telling reduces the total social cost of surfacing uncomfortable truths, or merely transfers it to the invoker, is an empirical question — the central one, in fact. It is stated as a falsifiable hypothesis in Open Problems below, not assumed away.

See each pattern's **Connections** section in the gallery below for the specific trigger/gate/complete/police relationships this creates.

## Situating HALA

HALA did not emerge in a vacuum. The problem it addresses has been documented for decades in organizational behavior, and its riskiest bets have been tested — sometimes unfavorably — in adjacent forms. Situating the patterns in that literature is part of the epistemic discipline the patterns themselves demand: the strongest published challenge to this language is engaged below, not omitted.

### Organizational silence and the economics of voice[5](#references)[6](#references)[7](#references)[8](#references)[9](#references)[10](#references)

HALA's core question — what true and valuable things go unsaid — is not a private observation; it names a phenomenon this literature has documented for decades. Morrison and Milliken described organizational silence as a systemic property, produced by managerial structures, not individual timidity \[5\], and later found that the most common reason employees withhold input is fear of being seen as troublemakers, with futility close behind \[6\]. Detert and Edmondson traced the self-censorship rules people carry between jobs — "don't embarrass the boss in public" — that operate even when the current environment is safe \[7\]. Edmondson showed psychological safety is a team-level condition that predicts learning behavior \[8\]; Hirschman framed voice as one of only three responses to organizational decline \[9\]; Dutton and Ashford showed that even raising an issue is an act of impression management with career stakes \[10\]. HALA's premise restates this literature as an engineering constraint: silence is incentive-compatible, so truth-telling must be made incentive-compatible by design — by moving the costly role onto infrastructure that cannot pay career costs.

### Structured dissent — and its documented failure mode[2](#references)[3](#references)[4](#references)[11](#references)

Organizations have tried institutionalizing dissent before: Janis prescribed devil's advocacy as an antidote to groupthink \[2\], and Schwenk's meta-analysis found structured dissent techniques do improve decision quality over expert-led consensus \[4\]. But the strongest challenge to HALA's Uncomfortable Agency layer comes from the same tradition: Nemeth and colleagues found that an assigned devil's advocate underperforms an authentic dissenter — people discount dissent they know is role-played, and it fails to stimulate the divergent thinking real dissent provokes; worse, it can create the illusion of having considered alternatives \[3\]. Argyris documented how organizational defensive routines absorb and neutralize exactly such rituals \[11\]. An AI dissenter is, in one reading, the ultimate assigned dissenter — so if AI dissent behaves like Nemeth's devil's advocate, this layer produces theater, not decisions. HALA's wager is that AI dissent differs on the dimensions that plausibly drive the discounting: it is evidence-gated (Grounding Contract), persistent rather than performed on request, career-blind rather than strategically motivated, and its track record is auditable (Trust Calibrator). Whether that wager pays is the Nemeth Test in Open Problems — the single most important empirical question this language faces.

### Escalation of commitment[12](#references)

Kill Switch Advocate is a direct response to Staw's escalation-of-commitment findings: decision-makers who initiated a failing course of action allocate more resources to it, precisely because they are responsible for it \[12\]. The pattern institutionalizes the counter-position — a standing, dispassionate voice for stopping, triggered by adoption and cost data rather than by anyone's willingness to confront a sponsor.

### Institutional precedents: whistleblowers, ombuds, and theater[13](#references)[14](#references)[15](#references)

Uncomfortable Agency has pre-AI ancestors. Whistleblowing research documents both the value and the severe personal cost of formal truth-telling channels \[13\] — cost being exactly the variable HALA tries to redesign. The organizational ombuds role, as described by Rowe, is a designed, neutral, confidential channel for surfacing what cannot be said through the hierarchy \[14\] — Proxy Confrontation Agent is best understood as a partial automation of that institution, inheriting its safeguards (confidentiality, corroboration) and its risks. And Meyer and Rowan's account of decoupling — formal structures adopted as ceremony while actual practice proceeds untouched \[15\] — is the theoretical basis for HALA's bluntest contraindication: an organization that wants compliance theater will make these patterns part of the theater.

### Judgment de-biasing and the outside view[16](#references)

Base-Rate Enforcer automates what Lovallo and Kahneman called taking the outside view: correcting the planning fallacy by forecasting from the distribution of comparable past cases rather than from the inside story of the current one \[16\]. The pattern's contribution is making the reference-class lookup a default step in the pipeline rather than a discipline individuals must remember to apply under exactly the conditions that make them forget it.

### Appropriate reliance on AI judgment[17](#references)[18](#references)[19](#references)[20](#references)[21](#references)

Whether humans will weight these patterns' outputs correctly is its own literature. Lee and See framed the goal as appropriate reliance — trust calibrated to actual capability, not maximal trust \[17\]. Dietvorst showed people abandon algorithms after seeing them err, even when the algorithm outperforms them \[18\]; Logg found the opposite bias — deference to algorithmic judgment — in other conditions \[19\]. Buçinca showed that cognitive forcing functions reduce overreliance but at a cost users dislike \[20\], and Bansal found that AI explanations can increase acceptance of wrong recommendations rather than improving complementary performance \[21\]. Trust Calibrator and Trace UX are HALA's response: surface auditable track records and inspectable reasoning, and treat calibration itself as a designed, measured property. Whether a displayed track record is sufficient to produce calibrated reliance is an open problem below.

### The pattern-language form[1](#references)

The form of this document — Context, Problem, Forces, Solution, and typed connections between named patterns — follows Alexander's original conception of a pattern language as a grammar of solutions in tension, not a checklist \[1\]. The connection grammar here (triggered-by, gated-by, completed-by, policed-by, composes-with) extends the form with explicit governance edges: every pattern that can say something dangerous names the pattern that polices it.

## Architecture

Five layers, each building on the layers below.

### HALA Architecture

Click a layer to explore its patterns

#### Meta-Governance

Patterns that govern the patterns

Adoption Gradient · Trust Calibrator · Capture Detector · +3 more

6

patterns

#### Foundation Infrastructure

Patterns that make everything else possible

Semantic Interface · Semantic Compiler · Event-Sourced Memory · +1 more

4

patterns

#### Epistemic Integrity

Patterns that ensure reasoning quality

Grounding Contract · Base-Rate Enforcer · Confidence Collar · +3 more

6

patterns

#### Organizational Perception

Patterns that see what humans can't or won't

Org-Shadow Modeler · Incentive Translator · Status-Blind Analyst · +2 more

5

patterns

#### Uncomfortable Agency

Patterns that say what humans can't

Mr Unpopular · Kill Switch Advocate · Long-Horizon Advocate · +3 more

6

patterns

#### Decision Output

Where patterns meet human decisions

Decision Historian

1

patterns

New in v2

Data flows down

Governance flows up

## Pattern Gallery

28 patterns organized by layer. Each pattern includes its function and failure mode.

Foundation Infrastructure(4) · Epistemic Integrity(6) · Organizational Perception(5) · Uncomfortable Agency(6) · Meta-Governance(6) · Decision Output(1)

### Uncomfortable Agency

Patterns that say what humans can't

#### Mr Unpopular

Surface inconvenient but high-value truths suppressed by human incentives

Failure mode: Weaponized for agendas, undermines trust

Click for context, connections, and a worked instance →

#### Kill Switch Advocate

Continuously argue for stopping/sunsetting initiatives to counter sunk cost

Failure mode: Decision paralysis, excuse for inaction

Click for context, connections, and a worked instance →

#### Long-Horizon Advocate

New

Argue for consequences beyond current planning horizons (5-10+ years)

Failure mode: Unfalsifiable predictions

Click for context, connections, and a worked instance →

#### Proxy Confrontation Agent

Mediate sensitive issues anonymously to enable truth flow

Failure mode: Enables cowardice, erodes direct norms

Click for context, connections, and a worked instance →

#### Moral Injury Sentinel

Detect patterns where people repeatedly act against stated values

Failure mode: Surveillance creep, moralizing

Click for context, connections, and a worked instance →

#### Stakeholder Ghost

New

Represent interests of absent parties (future employees, communities)

Failure mode: Paternalism, misrepresentation

Click for context, connections, and a worked instance →

## HALA in Action

Illustrative scenario — projected outcomes to show the intended mechanics, not a measured case study.

### EHR Migration Decision

A hospital system is 18 months into a $40M EHR migration. Adoption is at 30%. No one wants to say "kill it" because the CFO championed it.

#### Without HALA

The project limps along for 2 more years, eventually "succeeds" at 45% adoption, $60M over budget.

#### With HALA

At month 12, the system surfaces: "Projects with <40% adoption at 12 months have 8% probability of reaching target. Three prior decisions assumed 60% adoption by now. Recommend formal kill/pivot review." The VP of Clinical Operations reviews the recommendation, the counterfactual analysis, and a dissenting note from the implementation lead, and signs the decision to begin a formal pivot review — the system surfaced the case; a named human owns the call.

Kill Switch Advocate · Counterfactual Auditor · Override Protocol · Decision Historian

## Interactive Demo

### 🔬Try It: HALA Pattern Analyzer

Describe a decision scenario and see which HALA patterns would activate.

Describe a decision scenario your organization is facing:

0/2000 characters

Analyze Scenario

or try an example: · EHR Migration · Sprint Burnout · Departing Engineer · Rushed AI Launch

## Meta-Principles

> The Core Question
>
> “What true and valuable things go unsaid in organizations, and how can AI safely say them?”

1

#### Adoption Principle

A pattern that organizations reject provides zero value. Design for gradual trust-building.

2

#### Failure Mode Principle

Every pattern has shadow-sm applications. Name them explicitly or they'll be discovered adversarially.

3

#### Override Principle

Humans must always be able to override AI patterns, but overrides must be logged and reviewable.

4

#### Sunset Principle

Patterns that aren't providing value should be removable without organizational trauma.

5

#### Calibration Principle

The goal is appropriate trust, not maximum trust. Humans should know when to override.

6

#### Accountability Principle

A pattern may own the claim it surfaces. It never owns the decision that follows. A named human signs the answer.

## When to Use HALA

### HALA is appropriate when:

-   Organization has baseline psychological safety
-   Leadership genuinely wants better decisions (not decision theater)
-   There's tolerance for uncomfortable outputs
-   Technical infrastructure can support traceability
-   Clear escalation paths exist

### HALA is contraindicated when:

-   Organization will weaponize outputs for political purposes
-   No one has authority to act on uncomfortable truths
-   Compliance theater is the actual goal
-   Trust between humans is already critically damaged
-   Legal/regulatory constraints prevent transparency
-   Employee-monitoring restrictions apply (works councils, GDPR-covered behavioral metadata) and no privacy-preserving design or consultation has been done — the Perception-layer patterns are monitoring systems in the legal sense

## Implementation Guide

### Minimum Viable Deployment

Start with Foundation Infrastructure + one pattern from Uncomfortable Agency:

Semantic Interface · → · Event-Sourced Memory · → · Mr Unpopular · → · Decision Historian

Provides: Structured input, audit trail, one uncomfortable truth-teller, and decision capture

### Expansion Path

1

#### Epistemic Integrity

Trigger: When users trust the infrastructure

Add reasoning quality patterns to ensure claims are grounded and challenged

2

#### Organizational Perception

Trigger: When leadership is ready to see power dynamics

Add patterns that surface informal structures and incentive misalignments

3

#### Meta-Governance

Trigger: When the system is mature enough to govern itself

Add patterns that monitor and adjust the HALA system itself

## Open Problems

HALA is an architecture proposal, and its load-bearing assumptions are empirical claims that have not yet been tested. These are the questions that would falsify or validate it — stated as hypotheses with proposed tests, because a pattern language that demands disconfirmation from organizations owes the same to itself.

### 1.The Invocation-Cost Hypothesis

Does AI truth-telling reduce the total social cost of dissent, or merely relocate it to whoever deploys or invokes the pattern?

**Why it matters:** This is the null hypothesis for the entire Uncomfortable Agency layer. Everyone in the room knows who brought Kill Switch Advocate to the meeting. If the career cost simply transfers from the speaker to the invoker, HALA changes who pays without changing the price — and adoption will collapse for exactly the reason the patterns predict silence in the first place.

**Proposed test:** Vignette and panel studies varying the messenger of an identical uncomfortable finding — a peer, an assigned devil's advocate, an AI system, and an AI system invoked by a named colleague — measuring both acceptance of the message and blame or status penalty attributed to the human closest to it. Pilotable cheaply with LLM-simulated panels before human-subject replication.

### 2.The Nemeth Test

Is AI dissent discounted like assigned dissent, weighted like authentic dissent, or received as something new?

**Why it matters:** Nemeth's finding that assigned devil's advocacy underperforms authentic dissent — and can create an illusion of deliberation — is the strongest published challenge to this language. An AI dissenter is the ultimate assigned dissenter unless the properties that distinguish it (evidence-gating, persistence, career-blindness, auditable track record) actually change how its dissent is processed. If they don't, Uncomfortable Agency delivers theater.

**Proposed test:** Extend Nemeth's paradigm with AI-voiced dissent conditions: measure divergent thinking, alternative generation, and decision quality in groups receiving authentic human dissent, assigned human devil's advocacy, and grounded AI dissent, with and without a displayed track record. A direct, publishable extension of a classic paradigm.

### 3.Status-Blind Measurement

How much do author-status cues shift the evaluation of identical proposals, and does the two-stage blind/reattach protocol actually recover the blind assessment?

**Why it matters:** Status-Blind Analyst assumes both that authority bias distorts evaluation (well supported in general) and that recording a blind merit pass before reattaching authorship preserves its value (untested). If the reattached context simply overwrites the blind judgment, the pattern is ceremony.

**Proposed test:** Present identical proposals with varied authorship cues to human and LLM evaluators; then test whether evaluators who first record a blind assessment retain it after authorship is revealed, versus assimilating to the status cue. The most tractable single-pattern experiment in this language.

### 4.Calibrated Reliance

Is a displayed per-pattern track record sufficient to produce appropriate reliance — neither algorithm aversion nor rubber-stamping?

**Why it matters:** Trust Calibrator bets that showing 'upheld in 8 of the last 10 reviews' induces calibrated weighting. But the reliance literature shows both aversion after observed errors and uncritical deference in other conditions, and shows that explanations can increase acceptance of wrong outputs. If track-record display doesn't calibrate, the meta-governance layer needs cognitive-forcing designs it currently lacks.

**Proposed test:** AI-assisted decision tasks varying track-record display (none, aggregate, per-pattern with recency), measuring reliance on correct versus incorrect outputs against the appropriate-reliance criterion of the trust-in-automation literature.

If you work on organizational behavior, human-AI interaction, or judgment and decision-making and want to collaborate on any of these, [get in touch](mailto:jason@jasonstiltner.com).

## Origin

Building production AI within HCA Healthcare's advanced-technology division, I observed repeatedly that **organizational dynamics—not technical limitations—were the binding constraint on AI impact**. Those observations inspired HALA. To be unambiguous about the relationship: the pattern language was developed independently and afterward. It was never proposed, piloted, or used at HCA Healthcare, and nothing here describes an HCA system.

To be precise about what that means: the patterns below are **designed** from that observation, not themselves battle-tested at any scale. The worked examples (including the EHR migration scenario below) are illustrative, not case studies of HALA in production. Treat this as an architecture proposal grounded in real observation, not a track record.

One more precision point, since a pattern language for “AI that says what humans can't” invites an obvious objection: if the system says it, does that just let the human off the hook? That's a design failure mode, not a feature — see [Accountability, not laundering](#accountability) above.

### Version History

v1.0 · — Initial pattern language (Jan 2026). Its size was restated twice — early drafts and notes circulated counts from 18 to 22 as the layered taxonomy firmed up. The reconciled figure is the current total minus the patterns flagged new in v2 (see getV1PatternCount): the v1 set is whatever v2 did not add.

v2.0 · — Added layered taxonomy, failure modes, 6 new patterns, meta-governance layer, boundary conditions (28 patterns total)

v2.1 · — Added Context/Problem/Forces/Solution/Implementation/Connections/Worked-instance/When-not-to-use structure to every pattern, plus the explicit Accountability Principle

v2.2 · — Situated HALA in the organizational-behavior and human-AI reliance literatures (Situating HALA + references), published Open Problems as falsifiable research questions, named the invocation-cost tension, added legal/works-council boundary conditions to surveillance-shaped patterns, machine-validated the connection graph

Derived, so it can't drift: v1 = 22 patterns (28 total − 6 added in v2).

[Download Full PDF](https://jasonstiltner.com/HALA_v2_Pattern_Language.pdf) · v2.2 — 28 patterns across 5 layers

## References

1.  \[1\] Alexander, C., Ishikawa, S., & Silverstein, M. (1977). A Pattern Language: Towns, Buildings, Construction. Oxford University Press.
2.  \[2\] Janis, I. L. (1972). Victims of Groupthink. Houghton Mifflin.
3.  \[3\] Nemeth, C., Brown, K., & Rogers, J. (2001). Devil's advocate versus authentic dissent: Stimulating quantity and quality. European Journal of Social Psychology, 31(6).
4.  \[4\] Schwenk, C. R. (1990). Effects of devil's advocacy and dialectical inquiry on decision making: A meta-analysis. Organizational Behavior and Human Decision Processes, 47(1).
5.  \[5\] Morrison, E. W., & Milliken, F. J. (2000). Organizational silence: A barrier to change and development in a pluralistic world. Academy of Management Review, 25(4).
6.  \[6\] Milliken, F. J., Morrison, E. W., & Hewlin, P. F. (2003). An exploratory study of employee silence: Issues that employees don't communicate upward and why. Journal of Management Studies, 40(6).
7.  \[7\] Detert, J. R., & Edmondson, A. C. (2011). Implicit voice theories: Taken-for-granted rules of self-censorship at work. Academy of Management Journal, 54(3).
8.  \[8\] Edmondson, A. (1999). Psychological safety and learning behavior in work teams. Administrative Science Quarterly, 44(2).
9.  \[9\] Hirschman, A. O. (1970). Exit, Voice, and Loyalty: Responses to Decline in Firms, Organizations, and States. Harvard University Press.
10.  \[10\] Dutton, J. E., & Ashford, S. J. (1993). Selling issues to top management. Academy of Management Review, 18(3).
11.  \[11\] Argyris, C. (1990). Overcoming Organizational Defenses: Facilitating Organizational Learning. Allyn & Bacon.
12.  \[12\] Staw, B. M. (1976). Knee-deep in the big muddy: A study of escalating commitment to a chosen course of action. Organizational Behavior and Human Performance, 16(1).
13.  \[13\] Miceli, M. P., & Near, J. P. (1992). Blowing the Whistle: The Organizational and Legal Implications for Companies and Employees. Lexington Books.
14.  \[14\] Rowe, M. P. (1991). The ombudsman's role in a dispute resolution system. Negotiation Journal, 7(4).
15.  \[15\] Meyer, J. W., & Rowan, B. (1977). Institutionalized organizations: Formal structure as myth and ceremony. American Journal of Sociology, 83(2).
16.  \[16\] Lovallo, D., & Kahneman, D. (2003). Delusions of success: How optimism undermines executives' decisions. Harvard Business Review, 81(7).
17.  \[17\] Lee, J. D., & See, K. A. (2004). Trust in automation: Designing for appropriate reliance. Human Factors, 46(1).
18.  \[18\] Dietvorst, B. J., Simmons, J. P., & Massey, C. (2015). Algorithm aversion: People erroneously avoid algorithms after seeing them err. Journal of Experimental Psychology: General, 144(1).
19.  \[19\] Logg, J. M., Minson, J. A., & Moore, D. A. (2019). Algorithm appreciation: People prefer algorithmic to human judgment. Organizational Behavior and Human Decision Processes, 151.
20.  \[20\] Buçinca, Z., Malaya, M. B., & Gajos, K. Z. (2021). To trust or to think: Cognitive forcing functions can reduce overreliance on AI in AI-assisted decision-making. Proceedings of the ACM on Human-Computer Interaction, 5 (CSCW1).
21.  \[21\] Bansal, G., Wu, T., Zhou, J., Fok, R., Nushi, B., Kamar, E., Ribeiro, M. T., & Weld, D. S. (2021). Does the whole exceed its parts? The effect of AI explanations on complementary team performance. Proceedings of CHI 2021.

## Interested in Applying These Patterns?

Whether you're building AI systems for enterprise decision-making or researching human-AI collaboration, I'd love to discuss how HALA might apply to your context.

[Get in Touch](mailto:jason@jasonstiltner.com) · [Back to Writing](https://jasonstiltner.com/writing/)
