Jon W. Hansen, FCIPS · Procurement Insights | Hansen Models™
Tiffany Masson, Psy.D., published a post this week that names something every procurement and technology leader has lived through without a word for it. She calls it approval creep.
You approve a vendor once. Then the vendor keeps changing: new data, new integrations, new use cases. The approval stays the same while the scope quietly expands, until, in her words, action 4,000 is still running on day-one authority. Her three renewal questions are good ones: what changed since this was approved, who re-reviews the scope at renewal, and would today’s use case pass the original review?
Tiffany Masson’s original post is on LinkedIn.
A later snapshot is still a snapshot
Renewal reviews are necessary. But a renewal is a better snapshot than the original approval, not a different kind of thing. It closes the gap on the day of the review, and the gap starts reopening the day after. Between renewals, the system keeps acting on authority that nobody has checked against what it is actually doing now.
In 1998, there was no creep
In 1998, with funding from Canada’s Scientific Research and Experimental Development program, I developed a system for the Department of National Defence in which approval creep could not take hold, because approval was never a single moment. A supplier’s standing was rebuilt with every transaction.
The reason is that the advanced self-learning algorithms were compound. Every transaction fed what I call the Infinity Loopback, and the loop ran through the whole life of an order, not just the purchase:
- Before the order: each supplier was scored on two kinds of evidence. The first was historical performance: its record on delivery, on quality and, ultimately, on the service call closure rate. The second was real time: the price it quoted on this request, its geographic distance from the delivery point, the time of day the order was placed, and other variables in play at that moment. Every supplier was measured against the same standards on every parameter. A service call that failed to close counted against a supplier only when the cause traced back to that supplier: a wrong part shipped or a quality problem. If the technician had misdiagnosed the fault, the supplier was not penalized, because its responsibility was to get the right part to the right place on time.
- At delivery: delivery performance, verified by a third party rather than reported by the supplier.
- After delivery: product quality, measured by returns and dead-on-arrival parts, and whether the wrong part was shipped.
Each of those results looped back into the supplier’s standing for the next request. Nothing a supplier did after the first order was invisible to the system, so there was no gap between the approval and the reality for creep to grow in. The standing compounded, order by order.
That had a consequence most organizations would find surprising. The cheapest supplier could rank last, because once its delivery and quality history counted, price alone no longer won.
The buyer set the priorities
The algorithms did not decide what mattered. The buyers did. Each buyer could alter the rankings through weighted options: if delivery was the priority for a given need, the suppliers re-ranked one way; if cost was the priority, they re-ranked another. A supervisory role, which I called the train-yard manager, oversaw how the whole system operated.
So the evidence compounded continuously, and people decided how that evidence should be weighed.
What carries forward
Authority should compound from evidence, not erode from a signature. That was true in 1998, and it matters even more with AI, where models, integrations and operating behavior can all change between reviews.
The difference in one sentence
In Tiffany’s example, action 4,000 runs on day-one authority.
In 1998, action 4,000 ran on the compounded evidence of the first 3,999, weighted by the priorities the buyer set.
Governance is every day after the signature, as she says. The question is whether the signature is the last piece of evidence the system ever looks at, or the first.
Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™
The dated record
- 2005 keynote Q&A, at 18:33: I describe why the cheapest supplier could rank last once verified delivery and quality history were considered alongside price. Watch the recording
- March 18, 2008: Optimization Modeling and the Modern Supply Chain, an early written record of the approach, including its SR&ED provenance. Read the post
- September 6, 2026: Solving a 1998 Delivery Failure and a 2026 Traffic Anomaly With the Same Trace, a recent application of the 1998 method. Read the post
-30-
Related
In 1998, Action 4,000 Did Not Run on Day-One Authority (When Does AI Stop Learning?)
Posted on October 3, 2026
0
Jon W. Hansen, FCIPS · Procurement Insights | Hansen Models™
Tiffany Masson, Psy.D., published a post this week that names something every procurement and technology leader has lived through without a word for it. She calls it approval creep.
You approve a vendor once. Then the vendor keeps changing: new data, new integrations, new use cases. The approval stays the same while the scope quietly expands, until, in her words, action 4,000 is still running on day-one authority. Her three renewal questions are good ones: what changed since this was approved, who re-reviews the scope at renewal, and would today’s use case pass the original review?
Tiffany Masson’s original post is on LinkedIn.
A later snapshot is still a snapshot
Renewal reviews are necessary. But a renewal is a better snapshot than the original approval, not a different kind of thing. It closes the gap on the day of the review, and the gap starts reopening the day after. Between renewals, the system keeps acting on authority that nobody has checked against what it is actually doing now.
In 1998, there was no creep
In 1998, with funding from Canada’s Scientific Research and Experimental Development program, I developed a system for the Department of National Defence in which approval creep could not take hold, because approval was never a single moment. A supplier’s standing was rebuilt with every transaction.
The reason is that the advanced self-learning algorithms were compound. Every transaction fed what I call the Infinity Loopback, and the loop ran through the whole life of an order, not just the purchase:
Each of those results looped back into the supplier’s standing for the next request. Nothing a supplier did after the first order was invisible to the system, so there was no gap between the approval and the reality for creep to grow in. The standing compounded, order by order.
That had a consequence most organizations would find surprising. The cheapest supplier could rank last, because once its delivery and quality history counted, price alone no longer won.
The buyer set the priorities
The algorithms did not decide what mattered. The buyers did. Each buyer could alter the rankings through weighted options: if delivery was the priority for a given need, the suppliers re-ranked one way; if cost was the priority, they re-ranked another. A supervisory role, which I called the train-yard manager, oversaw how the whole system operated.
So the evidence compounded continuously, and people decided how that evidence should be weighed.
What carries forward
Authority should compound from evidence, not erode from a signature. That was true in 1998, and it matters even more with AI, where models, integrations and operating behavior can all change between reviews.
The difference in one sentence
In Tiffany’s example, action 4,000 runs on day-one authority.
In 1998, action 4,000 ran on the compounded evidence of the first 3,999, weighted by the priorities the buyer set.
Governance is every day after the signature, as she says. The question is whether the signature is the last piece of evidence the system ever looks at, or the first.
Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™
The dated record
-30-
Share this:
Like this:
Related