Most organisational dysfunction starts in a document nobody reads carefully: the job spec. It's where a role is first defined — and where the defining is almost always half-done. To show what that looks like, we took a Chief of Staff description of the kind you'll find on any job board and ran it through ARA: three questions — what may this person decide, what must they deliver, and what must they be able to do.
Here's the spec, near enough verbatim.
- Manage the Chief Executive's schedule, including scheduling meetings and planning travel
- Provide department leaders with recommendations and consultation to improve teamwork across the organisation
- Assist the executive team to determine and prioritise business strategies
- Determine key performance indicators and how to measure team performance
- Experience with budget management
- Consulting experience with a focus on operations management
- Proven success in a project coordination role
- A nimble business mind with a focus on developing creative solutions
- Strong project reporting skills, with a focus on interdepartmental communication
It reads fine. It would pass a hiring manager, a recruiter, and probably the person taking the job. Now sort it.
Sorting it into A, R, and A
The Requirements & skills block is Ability — budget management, operations consulting, project coordination, project reporting. Fine, if a little soft: "experience with…" describes a CV, not a capability. Name the skill — budget management, management reporting — and you can teach it, hire for it, and assess it. "A nimble business mind" you can do none of those things with. It's the "team player" of executive specs: a phrase that survives because no one can disagree with it.
The Responsibilities are mostly Responsibility, and here they're decent — provide recommendations to department leaders, assist the exec team to prioritise strategy. Note that these are advisory: the Chief of Staff produces advice; someone else decides. That's exactly right. A recommendation is a deliverable, not a decision.
Which is where the fault line appears.
The bug: authority is never written down
Two of those "responsibilities" aren't responsibilities at all — they're decisions in disguise, and the spec never says so.
"Manage the Chief Executive's schedule" quietly bundles all three pillars into one line. There's an authority in there — the Chief of Staff may decline a meeting on the CEO's behalf, may rearrange the week. There's a responsibility — keep the calendar accurate. And there's an ability — they can actually run a calendar. Three different things, one vague verb, and no boundary on any of them. Which meetings may they cancel without asking? The spec is silent.
"Determine key performance indicators" is worse. Determine is a decision word. So does the Chief of Staff set the KPIs — a real authority — or propose them for the exec team to approve — a responsibility? The spec doesn't say, so in practice it's decided by whoever pushes hardest in the room. That's the ambiguity ARA exists to kill.
The whole spec is Responsibility and Ability, with Authority left implicit and unbounded. That's not an oversight in this one document — it's the default failure mode of every spec written this way.
Not one line states a decision the Chief of Staff may make without asking, with a limit. There's no may not either — can they commit the CEO to something externally? Speak for the company? Sign off spend? Undefined, undefined, undefined.
The rewrite
Same role, same person, same intent — sorted into the MAY / MUST / CAN format, with the buried authority pulled to the surface and bounded.
Notice what changed. The "manage the schedule" line split into an authority (may decline meetings, within priorities) and a responsibility (keep the calendar current). "Determine KPIs" resolved into a responsibility — propose, they approve — because that's what the role actually does. A MAY NOT appeared, naming the boundary that was silently assumed. And "a nimble business mind" is simply gone, because you can't hire for it or review against it.
Why it's worth the ten minutes
The rewrite isn't longer. It's not more bureaucratic. It's the same role — but now you can do three things you couldn't before. You can review the person against it, because every line is testable. You can hand it to an AI and have it act in the role without overstepping — the same three pillars keep a model in bounds exactly as they keep a person in bounds. And you can see where it connects: the KPI proposal goes to the exec team, the recommendations go to department leaders — the wiring is on the page.
Do this with any role in your organisation. Take its spec, sort each line into may decide, must deliver, must be able to do — and watch how much of the "authority" column you can't fill in. That empty column is where the meetings come from.
See the finished version, and a dozen more, in the role library.