Skip to content

Field Personas & the Trust Economy

Charter fit: the courses teach what we inventory — this page teaches who feeds the inventory and why they would (or wouldn’t) feed it truthfully. Read it before designing any capture, approval, dispatch, or dashboard surface.

Source: a telecom operator’s detailed user-story corpus (v3.1.1, June 2026) — 45 roles across network inventory (record of the network), execution monitoring, and field-workforce management — read through a Jobs-to-be-Done lens and pressure-tested against field realities in India, Southeast Asia, and Europe. The companion philosophy that answers these findings is The Trust Machine.

One structure under 45 roles

Strip the role list and one structure remains: a chain of evidence and approval wrapped around a digital twin — capture → pre-validate → approve → reconcile → commit → pay. Every role produces evidence, judges it, routes work to evidence-producers, plans from the twin the evidence builds, or reports on the whole. The three most expensive events, in order: the avoidable second site visit, the approval queue that breaches SLA, the payment held on incomplete evidence.

The seven archetypes

1. The Capturer

(field technicians, engineers, survey users, hand-over users, last-mile agents, contractor technicians, patrollers)

  • Functional jobs: record what exists / what I did, where I did it, with proof; close the ticket; keep working with no signal.
  • Social jobs: be the one whose submissions don’t bounce; prove presence and work beyond dispute.
  • Emotional jobs: end the day with nothing pending against me; never make the second trip; never be surprised by a rejection I couldn’t have predicted.
  • Acute pains: the rejection→revisit loop; vague rejection remarks; offline fragility; sequence errors; missing parts; battery, data-pack and device poverty; language mismatch (thinks in vernacular, is corrected in English).
  • Decisive detail from the corpus: he prefers the app refusing a photo on the spot (with a reason) over silently accepting one that bounces later — field users choose strictness now over failure later. And: he “depends on the application to guide him rather than on technical knowledge” — the app carries his competence.

2. The Gatekeeper

(senior technicians, zone leads, GIS admins, QC managers, O&M owners, independent engineers, inspectors)

  • Jobs: clear a queue of other people’s evidence accurately; give actionable feedback; guard the twin. Emotionally: intervene before a breach rather than explain one afterwards — never be caught out.
  • The behavior that matters: approving carries personal audit risk; rejecting is safe. So gatekeepers over-reject defensively — which means rejection statistics partly measure gatekeeper fear, not field quality, and inflate the revisit rate. The counter is shared accountability (AI co-signature, audit defense files) plus symmetric error pricing: score the revisits a rejection causes as errors too.

3. The Orchestrator

(managers, dispatchers, vendor leads, field supervisors, NOC, ticket teams, escalation cells)

  • Jobs: match work to person × place × skill × time; recover jeopardy; mobilize on faults; no surprises.
  • The behavior that matters: assignment is income distribution — who gets which job decides who earns, so manual assignment attracts favoritism accusations. Dispatchers want visible rules-based assignment (with logged human override) as cover: “let them be angry at the rules.” Priority queue-jumping exists institutionally; its cost must land on the requester, not on crew SLA statistics.

4. The Planner

(GIS planners, splicers, equipment modelers, workforce/demand/roster planners)

  • Jobs: produce buildable designs; reconcile plan vs survey vs as-built; forecast and roster.
  • Pains: inherited as-builts are fiction; plan/field divergence surfaces late and is blamed on the plan; every planner keeps a private corrections file.
  • What fixes it: deviation as first-class data (plan vs surveyed vs built, span by span), and a plan-survival-rate metric with the planner’s name on it. Deviations feed the routing cost model so plans grow measurably more buildable.

5. The Executive

(corp users, SMEs, read-only viewers, programme managers, approving authorities)

  • Jobs: know status at scale; find the anomaly; report up; approve threshold breaches. Emotionally: a dashboard I cannot defend is a trap, not a tool — numbers must be armour.
  • The behavior that matters: executives who distrust the pipeline keep private spreadsheets and make verification phone calls before reviews. The cures are lineage (tap the number, see the evidence behind it), a reconciled scope→surveyed→built→accepted→paid spine that cannot disagree with itself, and a bad-news fast lane — the system discloses slippage automatically, so no human has to volunteer to be the messenger.

6. The System

(integration personas, schedulers, validation services)

Idempotent, versioned, authenticated, logged — the corpus treats integrations as first-class personas, correctly. The configurable validation service is strategically central: it is where learned rules become enforced rules (see principle 5 of the philosophy).

7. The System Owner

(tenant admins, technical admins, GIS admins wearing their configuration hats)

  • Jobs: keep the software matching the organization as the organization changes — reorgs, new contracts, new closure codes after an incident, new regulator mandates, renamed departments.
  • Emotional job: never having to say “we must wait for the vendor.” When the tool lags the org, they look incompetent — and every vendor-ticket week teaches the field another workaround.
  • Acute pains: change requests that arrive under deadline (audits, mandates) but take a procurement cycle to land; the remarks-field shadow schema and side-Excel that grow in the gap; inherited configuration whose reasons nobody recorded (the successor fears touching anything).
  • What fixes it: the malleability ladder and governed self-service change — see Malleable Software. Their needs are event-driven, so the metric that matters is need-identified → change-live time, measured on the client’s side.

The low-trust economy

In low-trust environments every actor runs a private defense, and the defenses are the latency:

DefenseWhoOrganizational cost
Defensive over-rejectiongatekeepersinflated revisits; queue latency
Sandbagged ETAs, cherry-pickingcrewsroster fiction, SLA chaos
WhatsApp shadow workflow, paper notebooksfieldthe real workflow is invisible; twin rots
Private spreadsheets via trusted aidesexecutivesthe sponsor distrusts the product
Photo-reuse arms race → stricter rules for alla few, taxing allhonest workers wear the handcuffs
Relationship-settled disputesvendors/ownerscorruption pressure in settlement
Knowledge hoarding (expertise = job security)expertsinstitutional memory never forms

Root cause, always the same: accountability is individual and asymmetric — evidence flows up, protection doesn’t flow down. Regional texture differs (petty-corruption friction and device/data/battery poverty in South Asia; typhoon logistics and materials theft in Southeast Asia; works councils, GDPR and permit chains in Europe) but the economy is identical. Notably, EU law mandates the worker-facing data symmetry that other markets merely reward — build the two-way ledger once and it is loyalty in Jakarta and compliance in Düsseldorf.

Voices worth keeping (synthetic composites from the analysis, not research quotes — validate in real discovery):

“If I approve fast, I am careless. If I approve slow, I am the bottleneck. If I reject, I am the villain. There are only ways to be safe.” — zone lead

“I don’t mind the tracking if the track is mine too — let me prove my dead time with it. Data that only flows upward is surveillance; data that flows both ways is a contract.” — sub-crew splicer

“I can survive slow payment. I cannot survive uncertain payment.” — contractor owner

The moments that decide the product

  1. The last 60 seconds on site, before submit — a pre-flight check here converts a revisit into a three-minute fix. The highest-leverage moment on the platform.
  2. Queue triage at 9am — which 20 of 200 need human eyes?
  3. The assignment decision — skill × proximity × load × parts × history, currently from memory.
  4. The pre-fault window — a prediction without a mobilization path is a report, not a product.
  5. The claim moment — completeness known before submission changes vendor economics.
  6. Monday morning, executive — three things changed; pushed, narrated, drillable.

Mechanisms that pay both sides

The design test from the philosophywho pays, who benefits? — applied per archetype:

ArchetypeOrganization getsThey getShared mechanism
Capturertrue evidence, first-time-rightno revisits; visible pay accrual; dispute immunity; safetypre-flight check; evidence→earnings ledger; GPS/selfie doubling as his proof; lone-worker alerts
Gatekeeperfast accurate queuesshared accountabilityAI co-signature + defense file; symmetric error pricing
OrchestratorSLA, utilizationcover, truthrules-visible assignment with logged override; displacement reports
Plannerbuildable plans, truer twinfield truth, creditdeviation pipeline; named plan-survival-rate
Executivehonest fast reportingarmour, early warninglineage; reconciled spine; bad-news fast lane
Vendorquality, low fraudpredictable cashcomputed quantities; symmetric SLA clocks; deadline-bound disputes

The data flywheel

Structured rejections with root-cause tags, geo-stamped photos, routes, closure codes, and AI-vs- human agreement form continuously labeled training data that competitors without the workflow cannot obtain. The loop: feedback → models → point-of-capture prevention → fewer rejections → faster queues → fresher twin → better predictions → more trust → more data. Two schema-grade prerequisites: design the rejection/RCA taxonomies with care, and log agreement on every AI suggestion from day one.

North-star metrics

ConstituencyMetric
Fieldfirst-time-right rate; revisits avoided; minutes-to-close
Gatekeepersqueue latency; decisions/hour; AI-agreement rate
OrchestratorsSLA attainment; jeopardy recovered pre-breach
Vendorsevidence-complete claims %; days work-to-payment
Executivestime-to-insight (→ 0, pushed)
NetworkMTTR; proactive-prevention rate; twin accuracy

If one number must stand for the platform: first-time-right rate — every persona’s life improves when it rises.