Case study
03 Human-authoritative hybrid automation
PersonalWorthTracker
Prepare workbook updates while keeping uncertain categories and the final copy under human control.
- What I built
- An update workflow combining deterministic rules, constrained model suggestions, a complete dry run, and a separate working copy.
- My contribution
- My work separates categorization, suggestions, review decisions, and copied output. The development account includes AI assistance and boundary-focused checks, without claiming exclusively manual authorship.
- Important limit
- No public source run is verified. Dry-run review is an operator procedure, not a mandatory software approval lock or financial advice.
Workflow recording
One synthetic purchase needs review. Choosing Groceries (monthly) and applying the saved decision leaves zero review items and three proposed writes. Commit puts 450.25 DKK in the copy’s grocery cell; the original workbook stays unchanged.
Real Excel worksheets with automated cell edits and a labeled CLI recorder. Generated sample data only; recorded 8 September 2026. The CLI runs between workbook views.
For someone maintaining a workbook, repetitive categorization should not let an uncertain suggestion silently alter the original.
- What works
- Local source inspection informed this account; the browser demonstrates the sequence using three fictional rows.
- Key decision
- Keep model suggestions review-only. A person resolves uncertainty, inspects the dry run, and explicitly requests the copy.
- Next milestone
- Prepare a reproducible synthetic source run that verifies review boundaries and preservation of the original workbook.
- Snapshot
- Issue #20 architecture / synthetic dossier reviewed 2026-09-05
- Evidence date
- 2026-09-05
Intent
Why this work exists. The problem worth solving and the human judgment that frames it.
Suggestions become dangerous when they look final
Routine automation can reduce review effort, but an uncertain suggestion must not silently become a change. The approved project design separates deterministic work, model-assisted proposals, human confirmation, and copied-workbook output so responsibility remains visible at every step.
Uncertainty routes to review, not authority
A person resolves ambiguous categories and rejects unsafe proposals. They inspect the full dry run, request the copy, and decide whether to use its result. A high-confidence model proposal is still only a suggestion. Following the review procedure remains the operator’s responsibility; no mandatory approval screen is claimed.
- Problem
- Automation over sensitive records is risky when an uncertain suggestion can silently become a change to the original artifact.
- Constraints
- Keep the original artifact untouched and make copied output explicit. Use deterministic rules for known cases and route uncertainty to review-only suggestions. Review the dry run before explicitly requesting a copied-workbook write; this is an operator procedure, not a stored approval lock. Use synthetic records in the demonstration rather than real financial or private data.
Build
How the work was shaped. The workflow, tailoring, present capability, and next useful step.
Six steps before an eligible copy exists
Read the input, classify known cases with deterministic rules, and keep model suggestions review-only. A person resolves uncertain rows, inspects a fresh dry run, and explicitly requests a separate workbook containing eligible updates. This describes the operator workflow; the command does not require a stored record proving the operator inspected the dry run.
Test each safety boundary where it changes
The development account concerns building and checking the automation, rather than operating a monthly run. Local inspection found separate implementation and tests for deterministic categorization, review-only model suggestions, and copied-workbook behavior. This supports a boundary-focused development account, not a claim about test-first chronology or exclusively manual authorship. Public development evidence remains pending.
The dry run is the decision surface
Local inspection supports a workbook-update workflow with deterministic classification, constrained suggestions, human review, and an explicit copied-output command. The recording shows real Excel and CLI execution with generated sample data. The Portfolio plays that recording; it does not run the workbook commands or establish source-project release readiness.
Publish a reproducible synthetic source run
The recorded sample now shows a saved review decision, the resulting dry run, commit and an identifiable output copy with the original preserved. A reproducible public source release and independently reviewed failure cases remain the next evidence needed for release qualification. No private source material is required in the portfolio.
Project workflow
- Import — Read the selected input and workbook to prepare a proposed update.
- Classify — Apply deterministic rules to the rows that are already understood.
- Suggest — Keep model suggestions constrained to review; they cannot authorize a workbook write.
- Review — Ask a person to resolve ambiguous rows and approve the plan.
- Dry run — Inspect the full proposed update after resolving review rows and before requesting a copy.
- Copy — Explicitly request a separate workbook containing eligible updates; unresolved suggestions stay out.
Development workflow
- Frame the boundary — Define what deterministic automation may do and which decisions stay with the operator.
- Separate the changes — Keep categorization, model suggestions, review decisions, and workbook writing independently inspectable.
- Use synthetic fixtures — Exercise known and ambiguous cases without copying personal financial records into tests.
- Check the boundaries — Check that suggestions still require review and that the copied output preserves the original.
- Review the evidence — Compare implementation and tests with the intended authority rules; a test count alone does not prove model quality.
- Qualify the account — Separate local source inspection from a reproducible public release and approved portfolio claims.
Proof
What the evidence supports. The demonstration worth inspecting and the boundary it cannot cross.
Compare the plan, confirmation, and copied result
The recording enters Groceries (monthly) in an actual Excel review worksheet, saves it, applies the decision through the CLI and commits the output copy. The dry run reports zero review items and three proposed writes. The copy contains 450.25 DKK in the grocery cell; the original remains unchanged. Workbook edits are automated and the CLI recorder is labeled. Generated sample data demonstrates this workflow, not an owner financial decision or a measured model-quality result.
A demonstration is not release evidence
No personal financial record or private memory is published. The recording uses generated sample workbooks and preserves the original; this page performs no workbook writes. The sample does not establish source-project release readiness, independently validated performance, or financial or operational advice.
Synthetic workflow evidence
- Before / Proposed plan — Dry-run plan
A / B: Rules matched · C / 10: Needs review · Dry run / Dry run
- Decision / Confirmed plan — Review decision
Row C: Travel, not supplies · Dry run: 20 supplies / 40 travel · Approved / Approved
- After / Copied output — Copy record
Original: Untouched · Result: Working copy · Copied / Local only
Named human decisions
- Resolve uncertainty before it becomes change
A human decides how an ambiguous row should be classified and whether the suggestion is safe to include in the plan.
Why: Uncertainty should route to a person, not be disguised as a deterministic output or silently copied to a new artifact.
- Confirm the complete dry run
The operator inspects the complete dry run and explicitly requests the copied-workbook update. The documented sequence does not establish a mandatory software approval lock.
Why: A partial preview can hide a surprising row. Review should precede the write request even when the command can be invoked directly.
- Authorize the separate working copy
The operator checks the separate working copy before using it; a model suggestion cannot approve itself or authorize a write.
Why: The system may prepare a working copy, but it must not present a write as authorized until the responsible person confirms it.
Validation provenance / status
- Issue #20 / synthetic three-row workbook example
Evidence date: 2026-09-05 · Status: controlled · Environment: Static portfolio in a local browser · Evidence type: Controlled synthetic workflow demonstration
Result: Rows A and B follow deterministic rules; row C stays review-only until a fictional human decision. A complete dry run precedes a separate working-copy outcome.
Provenance: Purpose-built example based on the architecture approved in portfolio issues #15 and #20. All row labels and amounts are fictional.
Material limitations: The browser changes presentation state only. It does not run a model, process a workbook, or prove source-project write safety.
- Public source-project evidence pending
Evidence date: 2026-09-05 · Status: unverified · Environment: Owner-provided local source inspection; no public reproduction · Evidence type: Implementation and test review, not an executed release qualification
Result: Local inspection informed the distinction between review-only suggestions, operator dry-run review, and an explicit copied-workbook write request. No source-project test result is claimed here.
Provenance: Owner-directed local inspection. No private source files, workbooks, reports, repository links, or release identifiers are reproduced.
Material limitations: An independently reproducible source snapshot and approved public evidence are still needed.
No public source links are available here. The case study records the evidence and its limits.
Bounded proof: This is a synthetic explanation of the approved workflow, not financial advice, a financial product, a live model evaluation, or proof of autonomous writes. Source-project release verification remains pending. Dry-run review is an operator procedure, not a mandatory software approval lock.