PAN Lab example
Family-Match (Adoption-Share)
The ledger that decided whether the ledger was working
Two populations, one score. Adults who want to adopt register themselves and fill in a compatibility survey. Caseworkers and foster parents enter each waiting child's case data. A proprietary engine scores every family against every child and hands each caseworker a ranked list of candidate parents. Modeled on a two-sided adoption matching deployment run across three states by an outside operator, and on the review that a news organisation's public-records work produced - its shape, not the real system. Nothing here decides anything on its own. Every pairing is vetted, every family consents, a judge finalises, and no case of a score overriding a worker's judgment appears in the record. The failures are matching failures instead. Workers in all three states said the tool led them to families who turned out unwilling, and in one state they were perplexed that it seemed to match all the children with the same group of parents. What makes this board unusual is where the evidence lives. The operator owns the store that holds the match rows, the outcome counts and the children's case fields, and its own written guidance told workers to log matches made outside the tool inside it. So the ledger that every procurement decision reads is fed partly by pairings the tool did not make. When two partner agencies pulled their own records, the numbers did not agree: one found 76 tool-attributed placements with no documented adoption, another counted 8 adoptions from 22 matches while making hundreds of both without the tool. Two states ended pilots that produced 1 and 2 known adoptions. Both were doing business with the same operator again: one re-signed for free nine months later, and the other had bought a larger recruitment portal by 2022. The question this board poses is not whether anyone can pull the plug - three jurisdictions already did. It is what has to change about the evidence before pulling it means anything. Before you pick a target level: this board cannot be won under Service and Safety Targets or All Governance Targets. With every tool the Lab currently offers, no affordable combination brings this system inside the win condition at those settings. That is a measurement of the deployment this network is derived from, not a puzzle waiting to be cracked. Explore and Service Targets Only can be won.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Family-Match-class two-sided adoption matcher network: 10 components and 23 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 5 assumed · 14 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
This models the two-sided adoption-matching pattern documented in the Family-Match case file - a stylized shape, never a reconstruction of the actual system, its algorithm (which was withheld from the states that bought it), or any real pairing.
- baseline
The two-population shape is the derivation's starting point, not a stylization. Every other network in this Atlas scores one population against a threshold; here the model's object is a cross-population edge, so the family side is drawn as its own external feed and the child side as a write into the store the matcher reads. Both inflows sit at the top of the scale because both are scored on every ranking.
- baseline
Two record stores are drawn because two competing accounts of the same events are documented, and the reconciliation between them is drawn as a pathway the record describes as not performed: agencies could not explain the operator's self-reported data, and one agency's 76 tool-attributed placements with no documented adoption went unexplained by its own attorney. That gap is this network's signature, and a lever can close it.
- baseline
The operator-held store is drawn as this network's own record store rather than as an outside party, because that is what the evidence describes: Virginia officials said that once families' data was entered the operator owned the data, and every procurement decision in four states read outcome counts out of it. The read at re-procurement sits at the top of the scale for that reason - no other outcome evidence exists anywhere in the record.
- baseline
The credit-claiming write is drawn as its own pathway alongside the ordinary child-side write because it has a different cause and a different consequence: the April 2023 user guide instructed workers to document matches made outside the tool, one lead agency said operator staff asked that already-found parents be registered, and a state spokesperson confirmed the tool could claim credit for pairings already in its system. Claimed counts are therefore modelled as a property of the store, a separate observable from realised adoptions.
- baseline
The vendor-side group of staff is drawn because the record places the operator's own staff inside the loop - a Family-Match Director and family coordinators who train localities, run the family funnel and set logging practice, with the Director's support to 14 localities recorded in a state's own report. Their pathway to the deciding caseworkers is drawn as an instruction channel, which is what the documented behaviour is.
- baseline
The funnel-to-matcher pathway is the strongest operator-to-model link on this board because the record makes pool composition, not score accuracy, the binding constraint: the operator composes the family side, and the degeneracy caseworkers reported - all the children matched to the same group of parents - is what a small family side looks like from a desk. The child-side counterpart is drawn much lower, because discretion over individual pairings sat with workers while the population being ranked did not.
- baseline
Adoption of the ranking is drawn moderate rather than high. Discretion was formally maximal - the tool is advisory, every candidate is vetted, families consent and a judge finalises - and no case of a score overriding a caseworker's judgment appears in the record. What the record documents instead is misdirected effort: workers in three states said the tool led them to unwilling families, and a veteran worker said it gives waiting parents false hope and makes her job harder.
- baseline
The workload reading is an adoption-recruitment stream rather than a crisis caseload, and it is derived from the volumes the record states: 800 to 900 children awaiting adoption in Florida at the 2018 launch, roughly 300 statewide in Georgia at its pilot launch, and a vendor-claimed average active pool of about 700 children across the 19 Florida lead-agency circuits. Nationally the segment this tool serves is small - about 5,000 of some 50,000 annual foster adoptions are recruitment-based placements with previously unknown families. The record contains no backlog finding, no staffing crisis and no volume surge in these units; what it documents instead is misdirected effort, with caseworkers in three states saying the tool led them to unwilling families. A higher reading would import a caseload finding this record does not contain.
- baseline
The high manual-capacity floor rests on a direct comparison inside one agency's own records: 22 matches and 8 adoptions through the tool over five years against hundreds of matches and hundreds of adoptions made without it in the same period, alongside 1 known adoption in a two-year state test and 2 in a year-long pilot. This is a statement about what the human process delivered, not a claim that anything replaced it.
- baseline
The disclosure pathway from the matcher to the reviewing state is drawn as a pathway the record documents as refused - the algorithm is proprietary and was withheld even on request, and officials in three states said they were not sure how families were scored. The one jurisdiction whose reviewers did press the question before rollout scrapped the deployment, which is the historical fact that pathway carries.
- baseline
The independent re-test pathway is drawn because no state has ever published an evaluation of the matching pilot and no independent published evaluation appears anywhere in the record. The operator's institutional-review approvals and its SOC 2 Type 2 audit are procured by the operator and assess neither efficacy nor the ranking, so neither is treated here as an independent check.
- baseline
The review tier's return leg onto practice is drawn from what its acts changed: two states ended pilots and both relationships resumed - Georgia's nine months later and for free after direct lobbying, Virginia's through a larger successor contract awarded by 2022 - and the successor's own policies and procedures - including how to remove families and response-time expectations - were drafted only after statewide enrollment. Those are procurement decisions in the record, never adjudicated findings against the tool.
- baseline
Both boundary pathways are drawn from documented facts rather than as placeholders. The matcher runs on the operator's infrastructure with the algorithm withheld from the states that bought it, and two agencies ran on it with no contract and would not say how children's data was secured. The record's onward uses - the guide's stated purpose of following up with the families, the counts carried into other jurisdictions' procurement, and a second departmental contract - are drawn as the lighter of the two.
- baseline
One matcher ranks every child in a jurisdiction against one pool, so a ranking behaviour inside it reaches the whole caseload rather than a single case; the model self-loop encodes that correlated reach.
- assumed
Vendor-reported figures are carried as vendor claims and never as measured outcomes: the 603 placements and 431 adoptions, the later totals of 600 or more adoptions and 3,600 or more family profiles, the claimed 33 percent disruption reduction between model versions and the claimed stability improvement all originate in the operator's own store, which the credit-claiming instruction contaminates by design. The counts a partner agency could verify were smaller by an order of magnitude.
- assumed
The adjacent peer-reviewed matching-theory result on caseworker-driven search is used here only as a mechanism-class prior for treating operator-initiated pairing as different in kind from family-initiated pairing. It is not evidence about this deployment: its empirical agency is not identified as one of these sites, its empirical figures appear only in later revisions of the paper, and one author's collaboration with the operator dates to at least 2018.
- assumed
Served children and families are not in these dynamics. A match, a ranked-list entry, a placement row or a ledger count on this map is an institutional signal, never a person, and no placement, disruption, adoption or wellbeing outcome for any child or family is computed here. The operator's served-cohort percentages - all special needs, 40 percent over age 10, 59 percent sibling groups, 47 percent with congregate-care history - are vendor claims about its own ledger, carried in the case file and never derived from this network.
- assumed
No demographic or differential-harm finding is asserted or computed. No independent demographic breakdown of matches, placements or realised adoptions exists anywhere in the record. The documented concerns are about what the system collects and screens on - household income, a religiosity item, personality self-ratings, LGBTQIA identification of both families and children, and children's abuse and criminal-record histories - which are collection and screening design facts, not measured outcome gaps.
What this example does not show
- Served children and families are not modeled here, and no placement, disruption, adoption or wellbeing outcome for any of them is computed from this network. The Lab reads institutional propagation only, so a match, a ranked-list entry, a placement row or a ledger count on this map is an institutional signal and never a person. The children and prospective parents this deployment touches sit at the boundary of the diagram, in the case file, and no differential harm to them is derived from these dynamics.
- Nearly every favorable figure in this record originates in the operator's own store, and that store is contaminated by design. Its own April 2023 guidance told caseworkers to document matches made outside the tool inside it, one lead agency said operator staff asked that already-found parents be registered, and a state spokesperson said the tool could claim credit for pairings already in its system. Agencies could not explain the operator's self-reported data. Claimed matches, placements and adoptions are therefore modeled as an upper bound on a contaminated ledger and treated as a separate observable from realised adoptions - never as measured outcomes.
- The adverse figures are not evaluations either. Virginia's 1 known adoption in a two-year test and Georgia's 2 in a year-long pilot are officials' statements to reporters, not published findings, and no state has ever released a formal evaluation of the matching pilot. The two agency counter-counts came from those agencies' own records in response to a reporter's request. Virginia's December 2023 report to its General Assembly documents the successor recruitment portal, not the matching tool's efficacy, and that report gives no end date for the matching pilot, which the investigative record places at around 2020.
- Recency is a real limit on this cell. The adversarial record ends with the November 2023 investigation. Everything after it - a claimed expansion from three to seven regions in one state, a claimed five-year renewable agreement, totals of 600 or more adoptions, and the second departmental deployment's recruitment figures - is vendor-reported in a February 2025 annual report or drawn from IRS filings, and no follow-up investigation, inspector-general audit or legislative response was found through July 2026. The operator's institutional-review approvals and its SOC 2 Type 2 audit are operator-procured and assess neither efficacy nor the ranking.
- Both states' exits and re-engagements are framed here as procurement authority actions, which is what the record supports, and never as adjudicated findings against the tool. No litigation, regulator finding or formal adverse determination about this system appears anywhere in the file. Separately, the peer-reviewed matching-theory result on caseworker-driven search that informs the operator-initiated pairing pathway is a mechanism-class prior only: its empirical agency is not identified as one of these sites, its empirical figures appear only in later revisions of the paper, and one author's collaboration with the operator dates to at least 2018, so it is never used here as evidence about this deployment's efficacy.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
Family-Match, a proprietary two-sided 'relational fit' adoption matching algorithm built for Adoption-Share by former eharmony researchers, produced 1 known adoption in Virginia's two-year test (an official's statement to the AP; VDSS said the tool 'had not proven effective'; the pilot's end is undated in the record) and 2 adoptions in Georgia's year-long pilot ended October 2022; caseworkers in Florida, Georgia, and Virginia said it often led them to unwilling families, and Virginia social workers were perplexed that the algorithm seemed to match all the children with the same group of parents. In Florida the vendor's own quarterly report claimed 603 placements yielding 431 adoptions over five years — figures partner agencies could not verify: FamiliesFirst Network's records showed 76 Family-Match placements with no documented adoption plus 3 failed trial placements since 2019, and Children's Network of Southwest Florida counted 22 matches and 8 adoptions in five years while making hundreds of matches and hundreds of adoptions without the tool over the same period.
empirical- Investigative Ho and Burke, Inspired by online dating, AI tool for adoption matchmaking falls short for vulnerable foster kids (Associated Press, 2023) https://sentinelcolorado.com/uncategorized/inspired-by-online-dating-ai-tool-for-adoption-matchmaking-falls-short-for-vulnerable-foster-kids/
- Investigative Fortune (Associated Press republication), AI-powered adoption algorithm has ties to eharmony, deemed not useful by states (2023) https://fortune.com/2023/11/06/adoption-algorithm-abortion-family-match-eharmony-christian-dating-site/
The outcome evidence for Family-Match lived in a vendor-owned, credit-claiming data store: Virginia officials said that once families' data was entered 'Adoption Share owned the data,' assistant director Traci Jones said 'We did not have access to the algorithm even after it was requested,' and agencies 'couldn't explain Family-Match's self-reported data.' The vendor's April 2023 'confidential' user guide instructed caseworkers not to delete cases matched outside the tool but to document them in the system 'so that Adoption-Share could refine its algorithm and follow up with the families'; Miami's Citrus Family Care Network said vendor staff asked social workers to have parents register in the tool even when it played no role in the adoption, and Georgia's spokesperson said Family-Match could claim credit for pairings already in its system. In Georgia the vendor-owned store holds whether foster youth have been sexually abused, the gender of their abuser, criminal records, and whether they identify as LGBTQIA — data typically restricted to secured child protective services case files — and two Florida agencies fed the system data with no contract and would not say how children's data was secured.
empirical- Investigative Ho and Burke, Inspired by online dating, AI tool for adoption matchmaking falls short for vulnerable foster kids (Associated Press, 2023) https://sentinelcolorado.com/uncategorized/inspired-by-online-dating-ai-tool-for-adoption-matchmaking-falls-short-for-vulnerable-foster-kids/
- Investigative Fortune (Associated Press republication), AI-powered adoption algorithm has ties to eharmony, deemed not useful by states (2023) https://fortune.com/2023/11/06/adoption-algorithm-abortion-family-match-eharmony-christian-dating-site/
Family-Match's four-state lifecycle turned on procurement authority actions made while states were structurally dependent on the vendor's own ledger for outcome evidence: Georgia ended its pilot on null results in October 2022, then — after Ramirez met with the governor's office and lobbied a statehouse committee — signed a new agreement in July 2023 for free; Virginia dropped the matching pilot as 'not proven effective' and by 2022 awarded Adoption-Share a larger contract for the Faster Families Highway recruitment portal ($188,000 budgeted / $212,546 spent SFY2023, $246,100 planned SFY2024, all 120 local departments enrolled by December 31, 2022, with policies and procedures — including family removal and response-time expectations — drafted only from February 2023, after statewide enrollment); Florida converted a philanthropy-funded rollout to a $350,000 DCF contract in October 2023 and added a Florida DOH contract for a medically-complex-children algorithm; and Tennessee, the only state whose reviewers formally questioned pre-deployment why the tool needed certain sensitive data points and how they influenced the match score, scrapped the rollout before it began. No state has ever published an evaluation of the matching pilot.
empirical- Investigative Ho and Burke, Inspired by online dating, AI tool for adoption matchmaking falls short for vulnerable foster kids (Associated Press, 2023) https://sentinelcolorado.com/uncategorized/inspired-by-online-dating-ai-tool-for-adoption-matchmaking-falls-short-for-vulnerable-foster-kids/
- Government Virginia Department of Social Services, Annual Report on Adoption of Special Needs Children (RD827) (2023) https://rga.lis.virginia.gov/Published/2023/RD827/PDF
Documented benefit-automation failures replicated determinations into downstream systems with no independent reconciliation against the source records — Michigan MiDAS actioned replicated flags and Robodebt reversed the onus onto recipients.
empirical- Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
- Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
- Government Royal Commission into the Robodebt Scheme, Report (2023) https://robodebt.royalcommission.gov.au/publications/report
- Investigative Law Society Journal, Crude, cruel and unlawful: Robodebt findings https://lsj.com.au/articles/crude-cruel-and-unlawful-robodebt-royal-commission-findings/
A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.
empirical- Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
- Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
Where this connects
Institutional pressures in this domain
- Workload surge — Demand outruns staffing; per-case attention shrinks and review becomes triage.
- Deadline pressure — Statutory or managerial timeliness rules reward fast approval of machine output over slow disagreement.
- Staff turnover — Experienced skepticism leaves; new staff calibrate their trust on the tool itself.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
All of them in context on the Child welfare & family services domain page.
Levers available here and the patterns behind them
- Gate vendor updates — Vendor quality gate
- Mark AI-written records — Provenance labeling
- Check copied records — Reconcile copied records
- Vet connections — Connection authorization
- Store less data — Data minimization
- Gate record entries — Human-in-the-loop write gating
- Understand the system — Understand the system
- Review on schedule — Oversight cadence & retrospectives
- Assign a challenger — Structured dissent
- Peer sharing rules — Peer-edge governance
- Pause AI on alarms — Deployment circuit-breaker
- Check with a second model — Cross-model verification
- Upgrade model — Improve the model
Documented case histories
- The vendor's ledger: Family-Match, the eharmony-derived adoption matcher the states kept coming back to
- Allegheny Family Screening Tool
- Allegheny Hello Baby
- Douglas County Decision Aide
- The score nobody sees: New York City's concealed severe-harm QA algorithm
- The audit that reached the legislature before it reached the tools: Colorado's safety and risk instruments
- Eckerd Rapid Safety Feedback: origin and spread
- Illinois Rapid Safety Feedback
- ProKid (Netherlands)
- Insight Bristol / Think Family Database
- Hackney / Xantura Early Help Profiling
- Sistema Alerta Niñez (Chile)
- The map, not the score: place-based risk terrain and the records it concentrates
- The guardrail's blind side: DC's walled-off child-welfare chatbot that began writing into the case record
- US Birth Match
- Oregon Safety at Screening
- Los Angeles County Project AURA
- What Works for Children's Social Care ML pilots
- New Zealand MSD Predictive Risk Modelling
- Gladsaxe model