Hacktakes · Edition 15
Hacktakes · Edition 15 · July 30, 2026

Corporate SOPs are not executable code

Corporate handbooks are deliberately impossible to execute flawlessly because they function as legal shields that transfer liability to workers.

By Simon Ferris

Sparked by Handbook.md shows that long policy documents do not reliably govern agents · discussion

The handbook is working perfectly, Henderson—I'm completely dry.
The handbook is working perfectly, Henderson—I'm completely dry.

I normally do not write about the day-to-day human resources mechanics of the modern enterprise, but a recent debate regarding large language models and corporate documentation has revealed a fundamental tech-industry blind spot. Software engineering culture universally operates under the assumption that all text is ultimately poorly optimized code waiting for a sufficiently powerful compiler. You can see this vividly in a recent arXiv paper attempting to parse employee manuals into executable logic, and the predictably utopian ensuing Hacker News debate which concluded that perfect organizational compliance is merely a matter of expanding an AI agent’s context window.

This fundamental category error misapprehends both the physical reality of work and the political API of a corporation. The belief that human organizations are just slow, fleshy state machines waiting for a SaaS tool to formalize their transition states is aggressively wrong. A 120-page Standard Operating Procedure document exists to be a legal shield, intentionally constructed by rational actors to be entirely impossible to execute flawlessly.

To understand the corporate SOP, we must start at the very top of the system, looking at the structural constraints placed upon the enterprise by the state. The modern administrative state places massive, occasionally contradictory compliance burdens on corporations, governing everything from granular data privacy and workplace safety to behavioral standards and record-keeping. The state desires perfect, deterministic adherence. (If you and the federal government disagree about whether a specific compliance checklist is strictly mandatory, you are wrong.) But the corporation must operate in meatspace, which is heavily populated by human beings who are notoriously resistant to deterministic programming. Because the C-suite cannot actually exercise perfect physical control over tens of thousands of distributed workers who are simultaneously managing demanding retail customers or complex supply chains, management must instead engage in the stochastic management of its legal liability. They cannot prevent the errors, so they must carefully manage who is at fault when the errors inevitably occur.

Consider how these documents are actually generated. The employee handbook is generally assembled by a coalition of compliance officers, risk managers, and outside employment counsel, operating far removed from the daily realities of a warehouse floor or a retail bank branch. This committee's structural mandate bypasses operational efficiency entirely; they are compensated strictly to ensure that if an auditor from a federal agency or a plaintiff’s attorney from a mid-sized law firm ever subpoenaed the company’s internal controls, the resulting paperwork would unequivocally prove that the enterprise itself had explicitly demanded pristine, perfectly safe, mathematically compliant behavior. The resulting document is therefore a masterpiece of institutional defensive architecture. It is built to appease a regulatory apparatus that requires fifty minutes of compliance out of every operational hour, while executive leadership simultaneously requires fifty minutes of revenue-generating output. The math does not, and cannot, work. This is an open secret at every level of the corporate hierarchy above middle management.

Risk in any sufficiently large organization flows downward, like water seeking the lowest possible elevation. When a regulatory failure happens—and in a system executing millions of transactions a day, it absolutely will happen—the immediate structural priority of the enterprise is ensuring that the liability does not pool at the executive level. The corporate handbook is the mechanism for this risk transfer, serving as the filter in the liability waterfall. Consider a regional bank which maintains exhaustively detailed procedures for verifying a customer's identity. If a teller deviates from page 82 of the manual to quickly process a transaction for a known, impatient regular customer, and that transaction later proves fraudulent, the resulting regulatory friction rarely results in a failure-to-train fine for the CEO. The manual predictably serves as a strong legal defense demonstrating that the corporation had explicitly forbidden this exact scenario, firmly pinning the blame on a rogue edge-node worker who bypassed documented policy. The liability has been successfully diverted.

By intentionally maintaining incredibly dense, overlapping, and practically contradictory policies, management essentially mints a put option on every single employee's tenure. The 120-page SOP operates as a heavily structured financial derivative sitting quietly on the corporate balance sheet. Management does not exercise these options daily. If every retail worker, mid-level developer, or warehouse manager explicitly followed every rule, safety check, and mandatory pause laid out in the handbook to the absolute letter, zero actual economic value would get created. They want you to get the work done. But they also mathematically require the optionality to forcefully manage out risk when a specific human becomes a liability. The handbook ensures that whenever the company needs to terminate someone, that person is technically already in violation of a half-dozen obscure protocols.

Let us ground this high-level theory in the visceral mechanics of human resources. When a corporation exercises its put option on an employee's tenure, the institutional machinery spins up a highly standardized sequence of events. The physical sleuthing of a termination involves HR pulling system logs and cross-referencing them against the handbook. Terminating a worker "for cause" by pointing to a specific subsection of the manual allows employers in strictly regulated jurisdictions like California to demonstrate a willful or wanton disregard for company interests. This cleanly bypasses costly state unemployment insurance premium hikes, which function as a tax on companies that fire people without a good paper trail. It also establishes an immediate pretext defense against expensive wrongful termination lawsuits, mechanically executing the widely documented HR process for engaging in severe misconduct. (The professionals executing this protocol do not view themselves as corporate assassins. They are simply running the compliance engine at scale, faithfully following the parameters established by their own legal department to protect the enterprise from unquantifiable exposure.)

This brings us back to the retail worker—and to the fundamental flaw in the tech industry’s current AI-HR thesis. The human worker knows, usually intuitively, that they must quietly bypass the strictest interpretations of the SOP to actually hit their required performance KPIs. The enterprise implicitly rewards this behavior right up until the exact moment it decides to severely punish it. When a well-meaning engineering team inserts an AI agent into this highly contextual environment and attempts to parse the handbook into a rigid decision tree, the agent will inevitably halt, trapped in the contradictions between the stated rules and the required business outcomes. If an LLM actually enforced the 15-minute mandatory screen-break protocol perfectly across a 10,000-person customer support team, the resulting drop in ticket resolution would cause a board-level panic by Tuesday afternoon. If developers attempt to "fix" the AI by aggressively prompting it to resolve those contradictions in favor of efficiency, they accidentally destroy the broad, stochastic discretion that the C-suite deliberately engineered into the system. You cannot automate away the friction without also automating away the liability shield. The institutional hypocrisy is a load-bearing structural component. Simple as.

Tech founders building LLM-powered HR compliance agents are trying to fix a feature, assuming it to be a bug. They gaze upon a perfectly tuned liability-laundering machine and assume that if they can just parse the text fast enough, they will mathematically optimize the modern corporation. Should this macroeconomic reality alter how you navigate your daily employment? If you are a venture-backed founder attempting to disrupt corporate compliance, you might want to seriously reconsider your product roadmap before you accidentally vaporize the legal shields keeping your clients solvent. For everyone else trading labor for a bi-weekly HTTP GET request to their checking account, the actionable advice is spectacularly boring. The system relies on you not reading the manual, occasionally violating its most cumbersome edicts to get your actual job done, and quietly accepting the reality that your continued employment is fundamentally at-will anyway. Keep politely skimming the PDFs during onboarding, do the work they actually hired you to perform, and try your absolute best to avoid being the reason legal has to push a new commit to page 82.

← Back to Edition 15