Imagine opening a government message late on a Friday. A benefit has been reduced, a permit refused or an appointment moved. The subject line says only that there is “an update”. The secure link expires, the portal asks for a password you no longer remember, and the letter explaining the deadline will arrive next week. The decision may have been made correctly. Yet the service has already created a second problem: the person cannot reliably discover what happened or act in time.
A public decision is not complete when a database changes state. It becomes effective in human life only when the affected person receives a trustworthy account, can understand its significance and has a realistic route to respond. That makes notification part of the decision itself, not administrative aftercare. Technology can deliver messages faster, across more channels and with better evidence. It cannot transfer the authority’s responsibility for ensuring that consequential communication is accurate, intelligible and recoverable when delivery fails.
Three events, not one
Notification systems often collapse three different events into a single status called “sent”. The first is dispatch: the authority’s system handed a message to a postal operator, email provider, SMS gateway or secure inbox. The second is delivery: the message reached a mailbox, device, account or identified recipient. The third is effective notice: the intended person had a fair opportunity to recognise the sender, understand the consequence and take the required action.
These events need different evidence. A server log can show that an email left the authority. A delivery receipt may show that another server accepted it. Neither proves that the right person read it, that a screen reader could parse the attachment, that the recipient understood the administrative language, or that the linked portal was available before the deadline. Conversely, the absence of an email “open” signal does not prove that it was unread: tracking pixels can be blocked, cached or loaded automatically. A technically neat binary field is therefore a poor substitute for a careful account of what the system actually knows.
European law illustrates the narrower problem that strong delivery infrastructure can solve. Under the current consolidated eIDAS Regulation, an electronic registered delivery service provides evidence about sending and receiving and protects transmitted data against loss, theft, damage or unauthorised alteration. A qualified service gains legal presumptions concerning integrity, identified sender and addressee, and the time of sending and receipt. The European Commission’s eDelivery building block similarly uses standardised exchanges, signatures, encryption and signed acknowledgements between participating systems.
Those are valuable capabilities. They establish provenance and a chain of custody. But a signed acknowledgement from an access point is not the same as comprehension by a person. The distinction matters because national rules determine when a notice is legally served, while service design determines whether formal service becomes effective access. A system must record both without pretending that one proves the other.
The message needs a small, truthful model of the decision
A consequential notification should not be a vague invitation to visit a portal. It should carry a compact representation of the decision: which matter it concerns, what changed, when the change takes effect, what the authority believes the person must do, which deadline applies, where the full reasons and evidence can be found, and how an error can be challenged. The notification does not need to reproduce an entire case file. It does need enough context for the recipient to recognise urgency without opening an untrusted link.
This is partly a content problem and partly a systems problem. The case-management system should generate structured facts, such as the case reference, decision version and deadline basis. A controlled template can turn those facts into consistent language. Channel adapters can then render an email, letter, secure-inbox message, SMS prompt or accessible document. The full reasons should come from the authoritative decision record, not from a parallel summary that staff must update by hand.
The design must preserve a distinction between summary and authority. If the short message says an appeal is due on one date while the signed decision says another, the citizen should not have to guess which system is right. The notification needs a version identifier linked to the decision, and staff need a visible correction mechanism. A corrected notice should not silently overwrite the first one; it should explain what changed, preserve the previous version and reset a deadline where law or fairness requires it.
Official design guidance already captures many practical elements. The UK Home Office’s email pattern says messages should identify why they were sent, state actions, provide a reference number, distinguish the user’s next steps from the service’s, include key dates and offer help. It also warns that limited connectivity and digital literacy affect the ability to receive and understand email. Those are not cosmetic writing choices. They are controls against a preventable administrative failure.
Channel choice is a risk decision
An authority may be tempted to declare one digital channel official because it is cheaper to operate and easier to audit. There is a serious case for that approach. A secure inbox can reduce postal delay, authenticate the recipient, keep documents together and provide a stable history. Multiple channels can create duplicates, inconsistent versions and uncertainty about which message starts a deadline. Standardisation also makes support and security more manageable.
The strongest version of this argument is not “digital by default” but “one authoritative record, many controlled routes to it”. The record should be singular; access should not be. The GOV.UK Service Standard requires teams to solve the whole problem, provide a joined-up experience across channels, make sure everyone can use the service, protect privacy and operate reliably. The OECD’s public-service design principles likewise frame services around user needs rather than the boundaries of an agency or channel.
The appropriate channel depends on consequence, urgency and known circumstances. An SMS is good at attracting attention but poor at carrying sensitive reasons. Email is cheap and searchable but vulnerable to spam filtering, account loss and shared devices. A secure portal protects confidential material but creates an authentication and availability dependency. A letter can reach people without internet access, yet addresses change and postal delivery can be slow. Telephone contact can clarify urgency but is difficult to evidence and may expose private information to whoever answers. In-person delivery can be appropriate in exceptional cases but may be intrusive or unsafe.
Good orchestration therefore begins with user preferences but does not treat preference as permanent consent to every consequence. The service should know which channels are verified, when they were last confirmed, whether the person has requested accessible formats, and whether a representative is authorised. It should apply a risk rule: routine information may use the preferred digital route, while a message affecting housing, subsistence, liberty, immigration status or a short appeal deadline may require a second channel or human check.
Multilingual communication needs the same discipline. A translated notification can widen access, but legal terminology, names of remedies and deadline conditions demand controlled glossaries and accountable review. Machine translation can help staff prepare a preliminary version or help a recipient orient themselves, but it should not silently become the authoritative explanation of a consequential decision. As Alkemata’s examination of machine translation and legal rights argued, assistance and authority must remain distinguishable.
Accessibility extends beyond a compliant portal
Accessibility is often tested on the destination page while the message that leads to it escapes scrutiny. A scanned PDF, an image-only letter, a link labelled “click here”, a countdown that cannot be extended or a one-time code that is hard to copy can block the journey before the accessible portal is reached. The W3C’s current Web Content Accessibility Guidelines 2.2 provide testable criteria for perceivable, operable, understandable and robust web content, including accessible authentication and adequate time. Meeting them is a necessary technical baseline, not evidence that every person understood a specific decision.
Effective access also includes cognitive load. A person receiving a refusal may be distressed, ill, caring for someone or reading in a second language. The essential outcome and deadline should appear early. Reasons should be written in plain language without erasing the legal basis. Dates should be explicit rather than described as “within fourteen days” unless the message also calculates the actual date and explains which event starts the period. Contact routes should say what kind of help is available and whether contacting support pauses a deadline.
Delegated recipients add another layer. A lawyer, relative, guardian or support worker may be authorised to receive messages, but delegation should be scoped, time-limited and visible to the person concerned. The system needs to distinguish permission to view, permission to receive formal notices and permission to act. It should record when authority begins or ends and prevent an old representative from retaining access. For especially sensitive matters, the service must also consider whether notifying a household address or shared phone could expose someone to coercion or harm.
Reminders are useful only when the first notice is sound
Reminders can prevent missed appointments and deadlines. They can also amplify an error. If the underlying decision has the wrong recipient, wrong date or wrong action, an automated sequence repeats the mistake with increasing urgency. The notification engine therefore needs a state model tied to the case: pending dispatch, dispatched, channel accepted, delivery failed, action completed, superseded, disputed and escalated. A reminder should be cancelled when the required action is recorded and paused when the notice is contested.
Frequency should be proportionate. Repeated messages may help where action is simple and time-sensitive; they can become pressure when a person needs advice, evidence or money before acting. The service should explain why reminders are being sent and offer a safe way to change channel without opting out of the underlying legal communication. Silence after a failed delivery is not an acceptable system state.
Failure recovery begins with honest telemetry. Email bounce, SMS rejection, undelivered letter, unread secure-inbox message and failed login are different signals. None should automatically be interpreted as refusal to engage. The system should route significant failures into a queue with clear ownership. Staff should see the decision, deadline, attempted channels, known accessibility needs and safe contact constraints. They need authority to correct contact data, resend a notice, switch channel and, where appropriate, protect or restore time to respond.
This is where automation should stop being the protagonist. A delivery platform can retry, reconcile receipts and flag anomalies at scale. It cannot decide, without a lawful policy and accountable human authority, that a person had a fair opportunity to act despite repeated failure. For high-consequence communications, a trained reviewer should check the recipient, decision version, reasons, deadline and available remedy before release, and examine unresolved delivery failures afterwards.
Measure whether people could act
Public bodies naturally count messages sent, delivery rates and unit cost. These operational measures are useful but dangerously incomplete. A service can report 99 per cent technical delivery while many recipients still miss deadlines because the sender was unrecognisable, the language inaccessible or the portal unavailable. The outcome measures should follow the journey: how often notices lead to the intended action, how many people request clarification, how frequently deadlines are restored after communication failure, whether particular languages or channels produce unequal burdens, and how long corrections take.
Comprehension cannot be reduced to surveillance. Authorities should not add invasive tracking simply to prove that a person looked at a message. Privacy-preserving research, usability testing, sampled follow-up and aggregated outcome analysis can reveal where people struggle. Logs should collect what is necessary for delivery, security, audit and remedy, with restricted access and defined retention. The purpose is to improve the service and resolve disputes, not to build a behavioural dossier.
The institutional test is simple to state and demanding to meet. For every consequential notification, someone must be able to answer: which record was sent, by which channel, to whom, on what authority, with what deadline, what the system knows about delivery, and what happens if any part is wrong. That responsibility cannot be distributed so widely among a case-management vendor, messaging supplier, postal operator and policy team that no one can correct the human consequence.
If you value examinations of technology that begin and end with the people affected by it, you can subscribe to Alkemata for future articles in this GovTech series.
The remaining decision
The central design choice is not whether government should communicate digitally. It is which consequences justify stronger proof, redundant channels and accountable human checking. Technology can make dispatch fast, records durable, language more adaptable and failures more visible. The authority must still decide when formal service is insufficient evidence of effective notice, and give its staff the power to repair the situation before a missed message becomes a lost right.