Trust inside the company: bot register and hiring protocol
Practicum for Book 3, The Economics of Trust (the Verifiability and Creation house, work track). Version: 2026-07. Time: one meeting. For a manager, small-business owner, or anyone who hires people.
People are no longer the only voices speaking for your company. The website chat, an email autoresponder, and an assistant inside the customer portal can all make promises to a client. Someone is responsible for each promise. Across the table, the same problem appears in reverse. The candidate on screen may be a constructed scene rather than the person you think you are interviewing.
These two problems have the same root. Work through them in order. Everything below costs nothing.
1. Company bot register
List every automated voice. Fill in the register once, then update it whenever you add a channel.
| Bot or channel | Where it speaks | Says it is software in the first line? | Owner of its words (name) | What it promises for us |
|---|---|---|---|---|
______________ |
||||
______________ |
||||
______________ |
||||
______________ |
Three rules for filling it in:
- The owner is a person, not a department. "Support" cannot take responsibility. A named person can.
- A bot's name and photo are decoration, not disclosure. They do not replace the line "You are speaking with a software system."
- An empty owner cell is an answer, not an omission. If you have not assigned an owner, you are responsible for the channel's words.
The line "You are speaking with an AI assistant" is cheap before a scandal and expensive after one.
This register is internal. Its public version is the Honest AI policy, which explains the same arrangement in language a client can use.
2. Hiring protocol: avoid hiring someone who does not exist
Faking a resume, face, and voice can cost less than completing an interview. A sharp eye is not enough. A procedure creates a trail and consequences, while a fake candidate tries to avoid both.
Before the interview
- Tell the candidate in writing and in advance if you will record the interview.
- Get consent to process personal data before the conversation, not after it.
- Check that the contact method leads to the same person named in the application.
During the interview
- Make at least one stage live and spontaneous rather than fully scripted.
- Use one move from this list: change language in the middle of the conversation, ask to see the working environment, ask an unplanned question, or return to a detail the candidate mentioned ten minutes earlier.
- Watch how the person improvises, not how polished the image looks. A prepared scene can survive the script. A departure from it is harder.
After the offer
- Before granting access, confirm identity through an independent channel, not the channel the candidate used to approach you.
- Do not grant access to money and data on the first day or through one approver.
- If something does not match, pausing before access costs almost nothing. Giving access to the wrong person can cost everything.
Person responsible for this protocol: __________
Result: one move this week
Do not implement everything at once. Choose the move that closes the most expensive gap:
Our move: ______________________________________________
Owner: __________ Due date: __________
The first move is often the least exciting one: assign a human owner to every bot.
Related worksheets: Honest AI policy, the public side of the register; Personal trust perimeter, the second channel for expensive instructions and a junior employee's right to verify; and Trust compass, which sorts a workweek by the cost of error and assigns a "trust" or "verify" mode to each task.