Res Agentica
Reading

No saved reading position.

Reading

No saved reading position.

Chapter 8

Charters in Code

The Rule That Runs

27 min read
Aa
Text size

The Honest List

Boston's school guide advised parents to consider less popular schools for their first choice. There was nothing clandestine about the advice. It appeared in the district's own instructions, addressed to families who had been asked to put schools in order of preference. The words first choice had acquired a second meaning: the school you wanted most, or the school it would be prudent to say you wanted most. A parent had to know which question the form was really asking.1

The old assignment procedure made this more than a verbal difficulty. Schools first considered the children who had ranked them first, assigning available seats according to the district's priorities. Those assignments were final within the calculation. Only the remaining seats were available when the procedure moved to second choices. A child with high priority at a school could therefore arrive too late, displaced by a child with lower priority whose family had put that school one line higher. The parent deciding whether to try for a popular school was also deciding what to risk elsewhere.

There was useful advice to be had. Minutes from a Boston parent group recorded a recommendation to put a less sought-after school first if it was one the family liked; otherwise, a popular first choice needed a safer second. The advice was sensible under the rule. That is what makes it troublesome. The district required families to judge the schools, then added another occupation: judging the judgments of other families. Knowing what suited a child was insufficient. One needed some estimate of demand, an understanding of priorities, and a decision about how much disappointment to insure against.

People can become very good at work an institution should not have required them to do. Their ingenuity is real, and occasionally admirable, but it is a peculiar defense of an assignment system that it offers a further advantage to those who master its indirection. Nor were apparently reckless rankings necessarily mistakes. A family might prefer a gamble on two popular schools and have somewhere else to go if it failed. The researchers studying Boston could not read true preferences directly from the lists. They concentrated part of their analysis on children who remained unassigned by the procedure and nevertheless stayed in the public system, where an unsuccessful strategy had consequences that could not be explained away simply by an intention to leave. Their evidence was narrower, and more persuasive, than an inventory of parents who had failed to behave as an economist expected.2

The reform proposed to remove this work from the application. In July 2005 the Boston School Committee adopted student-proposing deferred acceptance. Schools would still have limited places, and children would still have priorities, but a seat held in an early round would now be provisional within the algorithm. When a later applicant arrived with higher priority, the calculation could reconsider the tentative assignment. What had been an irreversible decision made too early became a decision the procedure was obliged to keep open until it had processed the claims upon it.

For families, the consequence was simpler than the procedure. Under the specified mechanism, with priorities fixed, putting a preferred school first did not sacrifice a lower choice merely because it appeared farther down the list. Truthful ranking was a dominant strategy: no alternative ordering could secure a better assignment according to the family's own preferences, whatever lists the other families submitted. The alternatives considered also removed the old limit of five choices. The district could ask for a longer list without asking parents to become more accomplished gamblers.3

In recommending the reform, the district explicitly identified the advantage enjoyed by families with the resources and knowledge to strategize. What interests me is the kind of equality they could establish without first equalizing everything else. They could remove a reason for disguising a preference. They could not make every school equally good, give every parent time to visit, or make a desirable seat available to every child. Yet those remaining inequalities did not make the particular protection trivial. There is no reason to preserve an avoidable disadvantage until every disadvantage has been abolished.

Even among rules that made truthful ranking safe, Boston had a choice to make. A community task force had favored top trading cycles, in which priorities could support exchanges that gave children schools they preferred. The district ultimately chose deferred acceptance. The disagreement concerned what a priority was for. If one child had priority because a sibling already attended a school, was that a claim usable only at that school, or something whose exchange could improve an assignment elsewhere? A third family might see a lower-priority child admitted and find the explanation—that a permissible exchange had occurred—less satisfactory than the designers found it. The question was not whether exchanging was computationally possible. It was what the district had promised when it gave someone priority.4

Top trading cycles has an efficiency property that deferred acceptance need not have; it does not follow that it produces a better result for every child, or wins every comparison between the two. The dispute could not be settled by attaching the word efficient to one procedure. In retaining priorities against the relevant form of displacement, Boston also retained responsibility for choosing them. A rule that reliably respects neighborhood priority may reliably reproduce an advantage attached to a neighborhood. The algorithm has not concealed that choice from the designer. It can, however, help the designer conceal it from the public if the allocation is presented as what the computer decided.

The district would have to explain the reform to families who had learned the old game. A safe opportunity does not erase a well-founded suspicion merely by becoming available. Advice that was once prudent could now suppress a preference for no benefit. The institution had to undertake the communication needed to make its new promise credible, while families still had the substantial work of deciding which schools suited their children. Less strategic calculation was not less parental judgment. It was a chance to spend that judgment on the question the form purported to ask.

There was an awkward prospect for the district too. Its percentage of first-choice assignments might fall. A family that had named a safe school first could now put a more ambitious choice above it without the old penalty. The same eventual assignment could consequently appear lower on the submitted list. In January 2006 the researchers warned that Boston needed to prepare for this interpretation. A statistic that once flattered the system could become less flattering when the answers became more candid.5

The old procedure had helped produce the evidence of its own success. Improving the relation between the question and the answer meant surrendering the convenience of that evidence. Better demand information was one of the reform's promised benefits, useful for debates about zones and transport as well as schools. But the district would have to learn how to read it. The obligation changed on both sides of the form: parents could cease predicting other parents, and the institution could no longer treat a defensive answer as an uncomplicated expression of satisfaction.

The Promise and Its Creditors

A constitution is partly an arrangement for making certain calculations unnecessary. People should not have to estimate an official's mood every time they undertake something the law permits. A creditor who lends to a government wants more than an accurate forecast of the present ruler's gratitude. A minority needs protections that do not require winning the same argument afresh whenever it loses a vote. The uses differ, and so do the people protected. What they share is a demand that a favorable disposition be made less important than it otherwise would be.

Constitutional economics took that demand seriously as a problem for interested people. Buchanan and Tullock asked how someone who could not predict his position in a succession of collective decisions would choose the rules governing them. He had reason to consider both the harm others might impose on him and the difficulty of reaching agreement. Requiring everyone's consent could protect him against an adverse decision while making action prohibitively difficult. Allowing a smaller coalition to decide could make useful action possible while exposing him to losses. The rules set the terms on which he would have to live with other people's choices.6

The authors were explicit about the difficulty posed by durable advantages and predictable coalitions. Their constitutional individual was uncertain about his position; a ruling group need not be. A person can anticipate that his children will remain on the favored side of a boundary without knowing which bills the next legislature will pass. Uncertainty about events does not dissolve an interest in keeping others out. This matters when constitutional language is borrowed for a technical design: the designer's willingness to accept a restriction may tell us much about the restriction and little about the protection afforded to those who had no part in choosing it.

The English settlement after 1688 offers a more material account of a promise becoming dependable. North and Weingast made it a central case of credible commitment: constraints upon the Crown helped make public borrowing more reliable. The proposition is powerful because it makes restraint productive. A government capable of taking what it wants may find people unwilling to put much within its reach. Limiting that power can enlarge what it is able to obtain by agreement.7

But creditors do not lend to a clause. They lend into an arrangement of revenue, administration, political interests and powers that can be brought to bear when payment is endangered. A count of veto points leaves open who will use them, what supports repayment and who manages the debt. The money is also being raised for something. In Cox's account, ministerial responsibility helped Parliament control the conduct and financing of war, bringing royal advisers within reach of consequences that the monarch's creditors could not secure merely by making a debt more binding. The trouble was not only that a king might fail to repay. It was that the decisions producing the losses could be made by someone who did not bear their full cost.7

Dependability here enlarged the means of action. A more credible state could become a more formidable state. It could borrow, collect and fight with a capacity that an unreliable sovereign lacked. There is nothing in the idea of credible commitment that guarantees the innocence of the undertaking it finances. We should be able to admire the institutional achievement without allowing the word credible to pass unnoticed into the place reserved for just.

Restrictions can help a collectivity accomplish things it could not accomplish through unrestricted choice. Yet a constitution may bind other people rather than its makers, and an attempted binding may fail. Calling the arrangement self-restraint can disguise both facts.8 The difficult task is to identify what becomes possible through a restriction, who obtains that possibility, and who must endure the restriction when the original bargain no longer serves them.

Code supplies some unusually exact means of making a restriction operative. A payment can be refused without asking an official whether to overlook a missing authorization. A release can be held until an announced interval has elapsed. These protections save something more than clerical work. If the restriction is dependable, the weaker party need not persuade the person it restrains to honor it on this occasion. An administrator who wants a different result must confront the rule rather than merely the applicant.

The important phrase is must confront. Someone may possess the power to change the rule, and such a power may be necessary. Yet an amendment and an exception at the point of use are different political acts. A rule gives little protection if its operator can change its meaning for the next unwelcome applicant while continuing to present the result as execution of the old one. The institution must either keep the promise or make the change answerable as a change, with the notice, authority and protection of existing claims appropriate to it. Making the restriction executable creates an opportunity to enforce that distinction. It does not choose who should be entitled to amend it.

Grounds for Removal

An institution can also leave a person to guess the rule after it has acted. A restriction arrives, an account disappears, a payment stops; the recipient must reconstruct which provision mattered and what conduct supposedly brought it into play. The work resembles Boston's old indirection, though the moment is different. Before applying, a family had to discover how to make its preference count. After a restriction, a user may have to discover what objection would count as an answer.

The European Union's Digital Services Act makes part of that explanation a duty. For covered restrictions based on alleged illegality or incompatibility with terms, Article 17 requires hosting providers to supply an affected recipient with specific reasons. The account must connect the measure to its grounds and the facts relied upon, identify relevant use of automated means, and explain available redress. Its scope has exceptions, but within that scope the recipient is not supposed to obtain the explanation as a concession from a helpful employee. The provider has to give it when the restriction is imposed.9

There is a difference between saying that information is prohibited and committing to a reason why this information falls under the prohibition. The latter leaves the institution with a proposition that can be contradicted. A useful explanation reduces the amount of speculative pleading an affected person must undertake. It also makes it harder to defend a consequence by wandering among grounds as objections arrive. That is the purpose such a duty should serve; a fluent paragraph can fail to serve it as easily as an opaque code.

For online platforms subject to the additional obligations, the Act separately provides for free internal complaints and decisions under qualified supervision rather than solely automated means. Where a complaint establishes the specified grounds for reversing the decision, Article 20 requires reversal without undue delay. Article 21 provides access to certified out-of-court settlement, though those bodies cannot impose a binding settlement. The right to go to court remains. These differences matter to the person considering what to do next: a place that receives an objection, a body that finds it persuasive, and a power that changes the result are not interchangeable.10

The same legislation requires covered platforms to send statements to a public, machine-readable database without personal data. That permits scrutiny across decisions which would otherwise arrive separately and privately. It creates another reader of the institution's explanation. It does not turn the collection into a court. Nor does a large collection prove that the explanations are accurate or that an affected person obtained relief.11

Citron had already examined how software could change policy and erase the material needed to review a decision. Accountable Algorithms went beyond disclosure to ways of verifying procedural regularity and fidelity to specified substantive choices.12 The political work now is to make those possibilities obligations of the undertaking, carried through the versions and offices by which it acts. An institution should not earn the description accountable merely because it can supply an account after a determined outsider has reconstructed its operations.

The Eighth Server

Knight Capital had several controls. This is worth knowing before learning how much it lost.

Its systems checked orders before they reached the automated router. It had position limits for some trading groups and a tool for monitoring positions after execution. A compliance assessment had inventoried existing controls and asked whether they functioned as intended. The Securities and Exchange Commission would later find that the assessment had not adequately considered what could happen if the router itself malfunctioned, or whether the monitoring system could prevent orders that exceeded the firm's capital thresholds. The presence of safeguards had been established more successfully than their sufficiency.13

The router was called SMARS. It received a customer's order and could send smaller, representative orders to trading venues. Earlier in its life it had contained a function called Power Peg. Knight stopped using that function in 2003 but left its code available to be called. In 2005, the tracking of how many shares of an incoming order had already been executed was moved to an earlier point in the code. Power Peg was not retested after the move. Its obsolescence was administrative; the code could still run.14

In July 2012, Knight prepared to participate in the New York Stock Exchange's Retail Liquidity Program. New software was to replace the old function, reusing a flag that had once activated Power Peg. Deployment began on July 27 and proceeded across servers. One of the eight did not receive the new code. No second technician was required to review the deployment, and there was no written procedure requiring that review. On August 1, seven servers initially handled the new instructions correctly. The eighth understood the reused flag according to the older code.

Its child orders continued after the incoming order had been filled. Another part of Knight's system knew that the required quantity had been bought or sold; that information did not reach SMARS. The router had a way to act and had lost the relevant way to know that its work was finished. It needed no intention to exceed its task. A locally recognizable instruction, a callable remnant of an older system, and a missing connection were enough.

According to the SEC's order, 212 incoming orders generated millions of outgoing orders and more than four million executions in approximately forty-five minutes. More than 397 million shares in 154 stocks were traded. Knight accumulated billions of dollars in unwanted positions and ultimately lost more than $460 million. The executions moved prices faced by other participants, giving some worse prices and others better ones. The cost of the failure was not confined to the firm whose software had failed.15

Before the market opened, an internal system had sent ninety-seven messages referring to a Power Peg error. They were not designed as system alerts, and Knight's personnel did not act on them before the opening or use them to diagnose the problem afterward. Information about an error existed, traveled and arrived. The organization had not made its arrival an effective demand for attention.16

Once trading began, positions accumulated in an account used for several kinds of unmatched or otherwise temporarily held positions. It had a gross position limit, but the account was not connected to automated controls that would stop orders when the firm's aggregate exposure exceeded its thresholds. The monitoring tool depended on people knowing the limits; it did not display them or generate automated exposure alerts. Under heavy volume it could lag and report inaccurately. Staff could see that something was wrong without possessing, in the same moment, an adequate account of what was happening or an effective means of stopping its accumulation.

The attempt to repair the system became part of the event. Knight removed the new code from the seven servers that had received it correctly, activating the faulty old behavior on additional incoming orders. Reversing the recent change did not restore a safe past. It returned the system to inherited functionality whose circumstances had altered. Meanwhile, the firm remained connected to the markets.17

These are findings from an administrative settlement, accepted without Knight admitting or denying them apart from jurisdiction. They concern ordinary software, operational practice and market access, not a demonstration of an intelligence escaping its designers. That makes the case useful for a world about to delegate more. The institution did not need to know what every instruction would do in order to owe other participants protection against an accumulating exposure. It needed controls designed for the point at which its activity entered the market, and for the aggregate consequences of that activity. Checks earlier in the path were not enough when the router could generate the error afterward.

The market-access rule required reasonably designed controls and supervisory procedures, their maintenance and regular review. It did not demand that every order wait for a human decision or that every possible malfunction be foreseen. It placed an obligation on the firm that possessed access. Within that obligation there was room for engineering judgment, but the institution could not discharge it merely by showing that a number of component safeguards worked. A position monitor could report a loss while lacking the means to prevent the next order that enlarged it. The distinction had to be made before relying on the monitor as a limit.18

There is a political advantage in this division of labor. The public authority need not write the firm's router to require the firm to constrain what the router can impose on others. The firm can improve its methods without renegotiating every permitted act, provided it maintains the protection attached to its access. That freedom makes the obligation more exacting, not less. It owes evidence that the protection reaches the actual operation, including changes whose effects do not resemble the intention with which they were introduced.

Permission to Continue

A rule that runs can spare people a negotiation, prevent a prohibited act, or make a decision less dependent on who happens to administer it. Those are substantial accomplishments. The ambition is to let ordinary conduct proceed under conditions that do not require extraordinary vigilance. It should be possible to submit a preference without concealing it, to receive a reason without soliciting a favor, and to trade in a market without depending solely on another firm's ability to recognize and repair its own runaway activity after the losses have begun.

The institution undertaking this work must accept a restriction upon itself. Its permission to operate a consequential process cannot amount to permanent permission to operate whatever that process becomes. Changes to the relevant priorities, inputs, executable rules and means of intervention have to be assessed against the protection being promised. Some changes leave it intact. Others alter the promise. A person who relied on the old arrangement should not have to discover which occurred by suffering the new one.

This does not require a hearing before every maintenance release. It requires distinguishing maintenance from a change in the terms on which others are governed, and making that distinction verifiable outside the convenience of the operator. The institution must preserve the evidence needed to establish which rule governed an act, who authorized a consequential alteration, and whether the limits attached to the delegation remained effective. Where the dispute concerns the rule's authority rather than its execution, an impeccable trace of execution will not answer it. A receipt helps carry the question to the place empowered to decide it; it cannot supply that power by listing it.

Some limits should operate before anyone has time to object. If an automated process can impose losses faster than an affected person can obtain review, a later explanation cannot do all the protective work. The institution must define the conditions under which the process may continue, the controls that enforce those conditions, and a response when there is evidence that the controls no longer hold. Stopping can itself hurt people who depend on a service. That is a reason to prepare a bounded continuation or a safer fallback, with responsibility for authorizing it. It is not a reason to let uncertainty default, indefinitely, to unrestricted operation.

A posted penalty cannot settle the matter in advance. It may be too small for the external gain, fall upon the wrong party, or become difficult to collect precisely when the protection fails. Even an adequate payment afterward does not always restore the opportunity or safety that was lost. Incentives matter, but an institution offering protection through a constraint must be able to show where the constraint takes effect. Calling the operator rational will not put the missing control in its path.

The power an institution must relinquish is the power to call every consequential change an internal matter. An institution that invites reliance on a publicly defended rule cannot reserve an undisclosed freedom to alter the terms of that reliance. It may have good reasons for changing them. Then those reasons, the interests being displaced and the authority to proceed must become part of the decision. The operator's desire to get on with its work cannot settle what other people have to accept.

This is where a charter in code earns the constitutional name. It makes an undertaking possible while withdrawing some of the means by which its operator could make other people bear the cost. When the protection can no longer be sustained, the operator owes more than a description of the departure. It must repair the condition, obtain authority for a different arrangement, or give up the activity that depended upon it. The people whom the rule was meant to spare should not become its emergency staff.

Source notes

Footnotes

  1. Atila Abdulkadiroğlu, Parag A. Pathak, Alvin E. Roth and Tayfun Sönmez, Changing the Boston School Choice Mechanism, January 7, 2006 version, pp. 4–7. The district guide and parent-group advice are documented there; this account does not infer a particular family's conduct from either. The public parent-group minutes are dated October 27, 2003. Pinned paper. ↩

  2. Ibid., pp. 17–19, especially §§5.3–5.4 and their qualifications about outside options, unobserved preferences and the selected unassigned pupils. The chapter does not generalize the researchers' inferred strategic mistakes to all unsuccessful applicants or infer motives from demographics. ↩

  3. Ibid., pp. 7–9, 24–27; the committee vote was July 20, 2005. Strategy-proofness concerns a student's preference ordering under the specified student-proposing procedure with fixed priorities. It does not establish truthful revelation on every other margin of participation, implementation correctness, or equal outcomes. Tentative assignments are internal stages of the calculation. ↩

  4. Ibid., pp. 9–10 and 25–26, including n. 31. Top trading cycles is student-Pareto-efficient; student-proposing deferred acceptance generally is not. Neither conclusion establishes that TTC Pareto-dominates DA; the paper expressly notes stronger comparisons that can favor DA. The policy account attributes the objections to trading priorities and concerns about explaining the procedure to the participants in the reform, rather than endorsing every objection as a theorem. ↩

  5. Ibid., pp. 24–27, including the May 11 and September 12, 2005 memoranda. Better preference data and potentially lower first-choice rates are reasons and anticipated consequences in this January 2006 paper. No post-reform outcome estimate is claimed here. The application also left choices about school information, timing and other matters outside the ranking guarantee. ↩

  6. James M. Buchanan and Gordon Tullock, The Calculus of Consent (1962), ch. 6, especially “Some Qualifications” and “Implications”; authorized text. Their discussion explicitly restricts the argument where predictable coalitions and entrenched advantage defeat the requisite uncertainty. It supplies neither a historical law about constitution-making nor a proof that rational interests yield just constitutions. ↩

  7. Douglass C. North and Barry R. Weingast, “Constitutions and Commitment” (1989), opening thesis; David Stasavage, “Credible Commitment in Early Modern Europe” (2002), stated argument in the author-deposited abstract; Gary W. Cox, “War, Moral Hazard, and Ministerial Responsibility” (2011), pp. 133–134, 151–153, 157, published article. The discussion retains disagreement over mechanisms of credibility. Its detailed account of ministerial responsibility follows Cox's interpretation, not an independent historical demonstration. The research record identifies the retrieval limits on North–Weingast and Stasavage; no uninspected detail from those papers is required here. ↩ ↩2

  8. Stephen Holmes, Passions and Constraint (1995), ch. 5, discussion of collective action and self-binding; Jon Elster, Ulysses Unbound (2000), II.2, pp. 92–95. Holmes's enabling argument and Elster's objections are distinct. The latter explicitly rejects treating society as an individual writ large. The body adds no historical episode from these discussions and claims no invention of enabling constraint. ↩

  9. Regulation (EU) 2022/2065, official original text, Article 17. The duty applies to specified restrictions grounded in allegedly illegal content or incompatibility with terms, where electronic contact details are known; it excludes deceptive high-volume commercial content and does not apply to Article 9 orders. Reasons must identify the measure and relevant scope/duration, facts, use of automation where applicable, legal or contractual grounds, and redress. The statutory specificity requirement is intended to enable effective exercise of redress. ↩

  10. Ibid., Articles 19–21. The additional platform obligations have the Article 19 micro/small-enterprise exemption, its twelve-month transition, and the exception for designated very large platforms. Article 20 provides at least six months for electronic complaints, free of charge, and specifies grounds requiring reversal without undue delay. Decisions on complaints require appropriately qualified supervision and cannot rest solely on automated means. Article 21 requires good-faith engagement subject to its prior-resolution exception; the certified body cannot impose binding settlement. User fees must be absent or nominal, with expense allocation specified in 21(5). Court access remains. These are legal provisions, not findings that each provider fulfills them. ↩

  11. Ibid., Article 24(5), subject to Article 19; European Commission, consultation summary, September 1, 2023; database search documentation, inspected September 7, 2026. Public submissions exclude personal data. The existence and inspectability of reports establish no rate of accurate moderation or effective remedy. ↩

  12. Danielle Keats Citron, “Technological Due Process” (2008), pp. 1299–1300, 1306–1307, journal text; Joshua A. Kroll et al., “Accountable Algorithms” (2017), pp. 633–634, 646, 678. The latter already distinguishes procedural regularity from fidelity to specified substantive choices and keeps policy interpretation open. The chapter's proposed synthesis concerns the institution's continuing obligations; these antecedents already supply substantial parts of that account. Citron's then-current account of judicial deference is not asserted as present law. ↩

  13. SEC, In the Matter of Knight Capital Americas LLC, Exchange Act Release 70694, October 16, 2013, official order, findings 20–31, particularly 28. The assessment's inventory and functional checks did not adequately examine router malfunction or the inability of post-execution monitoring to prevent orders. The order does not say Knight had no controls. ↩

  14. Ibid., findings 12–16, 26. Deployment began July 27, 2012; new functionality was intended for August 1. The absence of retesting is documented; a private motive for not retesting is not supplied. Power Peg remained callable, rather than being newly introduced on the day of failure. ↩

  15. Ibid., findings 1, 17–18. Incoming customer orders, routed orders and executions are distinct counts. The order reports over four million executions and over 397 million shares; these are not four million customers or four million separate retail instructions. Its account of prices includes both favorable and unfavorable effects on other participants. ↩

  16. Ibid., finding 19. The pre-market orders generating these messages were distinct from the 212 incoming orders behind the unwanted executions. The messages were not designed as system alerts. The SEC identifies a potential diagnostic opportunity; the chapter does not describe a deliberate refusal to heed recognized alarms. ↩

  17. Ibid., findings 22–27. The 33 Account's $2 million gross position limit was not linked to firm-wide automated controls; PMON monitored after execution, lacked automated exposure alerts and displayed no account limits, and could lag. Removing the new code from the seven updated servers worsened the problem. Not every attempted response had that effect. ↩

  18. Ibid., Part II and findings 4–10, 20–31. The settlement's non-admission provision is distinct from the Commission's findings. Rule 15c3-5 imposes reasonably designed controls, supervision and continuing review, not infallibility. The final constitutional argument is the author's proposal about protection and continued permission; it is not presented as a quotation of the SEC rule or a finding that one architecture is universally required. ↩

Search the book

Use ↑ ↓ to move through results; Escape to close.

Search every published chapter, section and reference.

    In this chapter