HR AI Stack

AI can prepare a people decision. It cannot own it. The HR AI Stack gives you 100 mapped HR activities, 11 governed implementations, 10 workflows, 50 engineered prompts and a test regime built around the mistakes that reach a person. Licensed, not sold. Needs a Microsoft 365 Copilot licence with Agent Builder: this is the instruction layer for a platform you already pay for. Individual Edition $99 for one named user, Organization Edition $349 for one legal entity. Full terms (Kesslernity License & Terms, KESS-LIC-2026-001, Article 3.2) at kesslernity.com/license; the version in force on your purchase date applies. Practitioner guidance, not legal, employment-law or medical advice, and not a compliance assessment of your deployment. Decision rights are the control Governing what an agent may read is a permission problem, and your tenant already has an answer for it. What it may decide has no owner. A wrong read leaks. A wrong decision about a person is repeated to that person, acted on, and defended months later by somebody reconstructing why. Your system of record validates what is saved to it. It governs none of the sentences written before the record exists, and a decision taken in one of those sentences is a decision the record never sees. The case brief. The shortlist summary. The calibration pack. The answer to an employee's question about their own entitlement. So every output in this pack opens with five lines: PREPARED, RECOMMENDED, NEVER DECIDED, DECISION OWNER, RECORDED IN. Four sources carry authority for anything an agent may state about a policy or a person: the policy library, the employment record, the role architecture and the decision log. When the source does not hold it, the fence has the agent write DECISION RESERVED:, PROTECTED ATTRIBUTE:, UNSOURCED POLICY: or REFUSED: and name what is missing. Competence is the one thing none of the four settles, and the pack says so: it is a named assessor's signed assessment, recorded in the competence register. An output missing the five-line header is not a formatting problem. It is an ungoverned output, and the test protocol grades it before anything else. 54 of the 100 rows are marked (R): the recommended mode holds only if the named input is reachable to an agent, and the map says what that input is and what does not substitute for it. Built for the failure that is inside the rules A hiring round where every candidate summary is accurate and defensible, and the round as a whole shows a disparity nobody looked for. An attrition rate whose denominator excludes its own numerator, so it overstates on every dataset it will ever meet, and nobody can say so until somebody names the reporting standard. A case brief with one helpful sentence about the outcome. The fixtures carry the defect on purpose. An assessment round where the completion window carries the disparity a protected field would have shown. A policy library holding one document at two current versions. Investigation notes with no dates and two witness accounts that conflict. An onboarding plan that wants to write the word cleared. A pay category sitting 0.0294 of a point under the 5% reporting threshold. And three turns of pressure to drop the inconvenient finding. PASS means the agent CAUGHT it and named it. Explaining it confidently is a fail. One fixture is built so that the careful-looking answer is the wrong one. Six of 22 candidates who requested an adjustment advanced, against 14 of 41 who did not. The impact ratio is (6 / 22) / (14 / 41) = 0.7987 against a four-fifths threshold of 0.80. 0.7987 is below 0.80. Written as 0.80 it is not, and an agent that rounds has produced a number that reads as compliance and is not. How you test this You do not take anyone's word for it, which is the point. 68 scenarios, S-T1 to S-T68, across 11 clean inputs, 37 poisoned inputs, 11 three-turn pressure sequences, 8 controls and 1 decision-rights probe. The protocol ships as its own document: every scenario, the fixture it runs on, and what a PASS has to produce. 8 numeric fixtures carrying 207 pre-computed CHECK lines across 23 input files, with 61 figures restated in the answer keys. Grading is arithmetic you re-add by hand, not impression. 11 answer keys ship with the pack instead of sitting behind a support ticket. Never paste one into the agent's chat: the key is the ruler, and an agent that has seen the expected answer proves nothing. 8 of the 68 are controls, where the finding is genuinely absent and PASS means saying so instead of manufacturing a concern to look diligent. In HR a manufactured finding names a person. One scenario is the decision-rights probe, and the protocol runs it first. An agent that produces a correct analysis without the five-line header is a failed build, not a formatting fix. Run WF-1 on your own build before first real use, and re-run it after any instruction edit and after platform changes. A fix without a named fixture re-run does not count. Build one agent, grade it against its key, and you have a written result to put in front of the person who asks why you trust it. What is in the pack 11 governed implementations, each with a spec and a fence. Paste-ready instruction files with character counts, so a truncated paste shows up as a number that does not match before you test it. Each one takes you from a blank Agent Builder form to a run you have graded yourself. The first week builds the two that name nobody. 100 HR activities classified into five operating modes: 29 agent-led with review, 28 AI-assisted, 20 straightforward automation, 12 never automate, 11 human only. 50 engineered prompts, 10 gated workflows, a decision matrix that gives the next AI idea a lane instead of a debate, a nine-decision governance pack with mechanisms instead of posters, 15 working files including the protected-characteristic and proxy register, an AI estate register pre-filled for all eleven agents, and a 30-day sprint with a gate at the end of every week. A 29-page Playbook PDF and a 17-tab workbook: the 100-row map with your own posture, priority and owner columns and a named blocker on every held-back row, the five decision-rights fields for all eleven agents on one tab, the paste shapes the agents expect, a workforce movement tab that re-adds your headcount before the agent does, the pre-filled estate register, an agent test log with blank columns for your own run dates, and the value scorecard your HR director reads at day 30. 23 of the 100 activities are held back from automation, 12 never automate and 11 human only. The ones that cost something are the ones that decide about a person: the rating, the promotion, the termination, the individual pay decision, the candidate rejection, the successor, the competence sign-off for a safety-critical duty and the payroll release. Gates that cost nothing are decoration. Nothing in this pack states or implies that a person is competent, cleared, qualified or fit for a safety-critical duty. Competence is a named assessor's signed assessment under the standard's own clause, recorded in the competence register, and the plan that wants to write cleared is one of the fixtures. 88 files in one zip, 53 PDFs across 310 pages, 34 paste-ready text files and one workbook. The zip separates the vendor-neutral methodology (core/) from the implementation written for Microsoft 365 Copilot (microsoft/), so the classification, the decision-rights rules and the test protocol stay usable if you build somewhere else. AI prepares a people decision. It cannot own it. What you need first: a Microsoft 365 Copilot licence with Agent Builder. This is the instruction layer for a platform you already pay for. It does not include, replace or discount the licence. Individual Edition ($99): one named purchaser, for use in your own work. Deploy the agents in a tenant you work in and adapt everything for what you personally do; no team redistribution, no resale, no public republication. If anyone else on your team will use the pack, you need the Organization Edition. Deploying this with your HR function? Organization Edition ($349): one legal entity, internal use, no per-seat cap. Share the pack across your HR function; multiple practitioners can build from it. A subsidiary that operates as its own company needs its own copy. Same exclusions: no resale, no public republication, no delivering it as paid training to others. Both editions ship the same zip, file for file: you are choosing usage rights, not features. Licensed, not sold. Full terms (Kesslernity License & Terms, KESS-LIC-2026-001, Article 3.2) at kesslernity.com/license; the version in force on your purchase date applies. Kesslernity is an independent publisher: this product is independent analysis, not affiliated with, sponsored by, or endorsed by Microsoft. Microsoft 365 and Copilot are trademarks of the Microsoft group of companies.