Source-linked AI summary

From Event Logs to Governed Action: A BlueSky Agenda for Agentic Process Mining

Yiyuan Yang, Zheshun Wu, Yong Chu, Zhenghua Chen, Zenglin Xu, Qingsong Wen

arXiv:2609.07984v1cs.AIcs.CE

TL;DR

Process mining lacks a target for deciding whether logged evidence authorizes action under uncertainty, privacy, authority, and downstream risk. This paper proposes event-to-action process mining through four connected artifacts—representations, evidence packages, governance contracts, and evaluation tasks—and concludes that accountable systems must support action, deferral, and refusal. Its scope is bounded by partial observations, meaningful missingness, changing distributions, and absent outcomes for many unchosen actions.

  • Problem

    Process models and logs do not by themselves justify organizational actions under uncertainty, privacy limits, authority constraints, and downstream risk.

  • Method

    The paper proposes four connected artifacts: event-object representations, action evidence packages, governance objects, and evaluation tasks for governed action recommendations.

  • Results

    The paper's supported conclusion is that process mining should produce recommendations carrying evidence, constraints, privacy accounting, local verification, and authority conditions, with deferment or refusal as valid outputs.

  • Takeaways & Limitations

    Accountable event-to-action process mining requires systems that can verify, limit, defer, or refuse organizational action rather than only automate or visualize processes.

  • Takeaways & Limitations

    The agenda assumes event logs are partial observations with meaningful missingness, negotiated labels, distribution shift after agent action, and no single ground-truth outcome for many actions.

Abstract

from arXiv · show

Process mining has long turned event logs into process knowledge: discovered models, conformance evidence, bottleneck diagnoses, and runtime predictions. Agentic AI changes the target. Process-aware agents will not only ask what happened. They will ask whether a proposed action should be taken, given the available evidence, privacy budget, organizational authority, and downstream risk. This BlueSky paper proposes event-to-action process mining: a process-mining agenda for transforming heterogeneous operational event data into governed action. The goal is not another dashboard, a generic enterprise simulator, or a language interface over logs. We argue that the community needs four mineable artifacts: event-object representations, action evidence packages, governance contracts, and benchmarks where act, defer, ask, and refuse are all valid outputs. This agenda is timely because agentic business process management (BPM), LLM-assisted process mining, object-centric event standards, causal process monitoring, and privacy-preserving learning are maturing separately. Bringing them together defines a data-mining target inside process mining: mining logged organizational behavior for accountable action, not only retrospective insight.

I. THE BLUESKY IDEA

Process mining should move beyond reconstructing and evaluating past processes toward mining operational data for governed action. The proposed target requires recommendations that expose causal support and uncertainty while respecting privacy, authority, and the possibility of refusal.

  • I. THE BLUESKY IDEA: Classical process mining reconstructs observed work, discovers models, checks conformance, predicts outcomes, and analyzes performance from event logs.Event logs can include cases, activities, timestamps, resources, objects, costs, text, and policy attributes.
  • I. THE BLUESKY IDEA: Agentic operations require deciding whether to reroute, relax rules, contact suppliers, approve claims, escalate patients, or wait for better evidence.This shifts the central question from what happened to whether a specific intervention should occur.
  • I. THE BLUESKY IDEA: Discovered process models describe the past but do not alone justify actions under uncertainty, privacy limits, organizational authority, and downstream risk.The action decision requires more than a Petri net, directly-follows graph, or object-centric model.
  • I. THE BLUESKY IDEA: The paper defines event-to-action process mining as mining operational data into evidence about a specified action rather than stopping at log-to-model analysis.The target is a data-mining problem centered on evidence for action.
  • I. THE BLUESKY IDEA: The agenda specifies four mineable artifacts—representation, evidence, governance, and evaluation—to make agentic process mining a testable research program.These artifacts address explicit assumptions about prescriptive monitoring, prompting-based safety, and cross-organizational effects.

II. WHY NOW: THE ACTION GAP IN PROCESS MINING

The action gap has emerged as agentic BPM, LLM-assisted process mining, object-centric logs, causal monitoring, and privacy-preserving learning mature in parallel. Together, these streams expose the need to mine heterogeneous, drifting, cross-organizational data into governed action evidence rather than dashboards alone.

  • II. WHY NOW: THE ACTION GAP IN PROCESS MINING: Agents are shifting BPM toward autonomy and data-driven management, while process-aware systems require explicit constraints, explanations, adaptation, goals, and guardrails.Digital twins and formal agentic BPM work identify organizational needs but leave process-mining requirements unresolved.
  • II. WHY NOW: THE ACTION GAP IN PROCESS MINING: LLM-based process mining improves natural-language and code access, but local computation, metadata grounding, and process-data adaptation expose a remaining grounding gap.These approaches address interaction and data exposure without fully defining what event evidence should authorize.
  • II. WHY NOW: THE ACTION GAP IN PROCESS MINING: Object-centric logs represent many-to-many relations among events and operational objects, making cross-object intervention effects more visible than flattened case traces.OCEL 2.0 adds evolving object attributes and exchange formats.
  • II. WHY NOW: THE ACTION GAP IN PROCESS MINING: Prescriptive and causal process mining address intervention under uncertainty, but unchosen actions remain difficult to evaluate without counterfactual outcomes.SimBank and ProCause provide controlled or learned-generator settings for evaluating intervention policies.
  • II. WHY NOW: THE ACTION GAP IN PROCESS MINING: Federated process mining and secure aggregation support cross-organizational learning without pooling raw logs, while privacy becomes part of the action contract.Cross-boundary processes make federation and privacy central rather than optional preprocessing concerns.
  • II. WHY NOW: THE ACTION GAP IN PROCESS MINING: The missing target is governed action: four inspectable artifacts—representation, evidence, governance, and evaluation—connect case logs and dashboards to auditable recommendations.The agenda map frames this shift as a data-mining target for computable and auditable action.
  • II. WHY NOW: THE ACTION GAP IN PROCESS MINING: The broader gap combines heterogeneous event streams, drift, schema alignment, causal signals from biased logs, uncertainty, privacy, and missing ground truth for unchosen actions.These challenges motivate a governed action object that binds the required evidence and constraints together.

III. FROM EVENT LOGS TO GOVERNED ACTION

Event-to-action process mining shifts the target from retrospective process views to governed recommendations that can be inspected before organizational action. Its agenda centers on shared artifacts and benchmarks that evaluate usefulness, uncertainty, privacy, authority, and justified refusal.

  • A governed action recommendation combines the proposed action, predicted consequences, evidence tier, privacy and authority conditions, and an audit trail.Recommendations may direct action, condition it on approval or privacy budget, defer for more evidence, or refuse unsupported or unauthorized action.
  • The target is a governed evidence object that can be inspected before an action changes the organization.This differs from discovered models, predictive labels, dashboards, and ordinary prescriptive monitoring.
  • The agenda treats cross-organizational process mining as action governance because one actor’s decisions can shift cost, delay, or risk to others.Federated mining is therefore a component of governance rather than the endpoint.
  • Evaluation should reward action quality under distribution shift, honest uncertainty, privacy preservation, evidence traceability, and refusal of unauthorized actions.The proposal explicitly rejects credit based only on plausible narratives or next-event accuracy.
  • The agenda prioritizes four artifacts before deployed agents normalize weaker outputs.

A. Four Mineable Artifacts

The agenda defines four mineable artifacts for turning operational event data into governed action: representations, evidence, governance, and evaluation. Together they preserve process semantics, expose causal support and uncertainty, document authorization, and test when agents should act or abstain.

  • R1: Representation object: R1 represents operational state as an inspectable event-object graph linking objects, events, resources, policies, decisions, and conditions through time.It must address concurrency, missing events, repeated work, long-tail variants, and semantic drift, while supporting state and action-effect mining tasks.
  • R2: Evidence object: R2 attaches causal status and uncertainty to recommendations instead of returning only a score.Its evidence object combines temporal structure, relational objects, domain constraints, partial experiments, and realistic process generators across evidence tiers.
  • R3: Governance object: R3 records the computation, log view, causal assumption, privacy rule, spent budget, and authority permitting an action.
  • R4: Evaluation object: R4 defines benchmarks where act, defer, request approval, or refuse can be correct outcomes.Evaluation must assess usefulness with restraint, including process evidence, privacy conditions, and action authority.

IV. STRESS TESTS AND SUCCESS CRITERIA

The agenda evaluates governed process action through stress tests that expose uncertainty, causal support, governance constraints, feedback effects, refusal, and benchmark design. Success requires measuring action quality and accountability over complete decision episodes, not only component prediction scores.

  • Representation and evidence: Event-to-action systems must expose uncertain labels, contested case boundaries, and incomplete object relations because operational logs are policy-shaped and behaviorally produced.The same event label can have different organizational meanings, so representation should not conceal these uncertainties inside embeddings.
  • Causal support: Action evidence must distinguish causal support from persuasive association and report the support tier behind each estimate.The agenda links this requirement to the potential consequences of wrong interventions, including delayed care, denied benefits, compliance failures, and transferred costs.
  • Governance: Governance contracts should make policy constraints, privacy cost, tool provenance, approval boundaries, and risk transfer visible before action.Agent safety is treated as inseparable from process safety because local optimization or formal compliance can still worsen system-level fairness.
  • Feedback and deployment: Deployment evaluation must test action quality after feedback because workers and partners adapt, changing the distribution of subsequent event logs.Static prediction quality before deployment is insufficient for systems that recommend triage, supplier, exception, or resource changes.
  • Refusal and success criteria: Refusal, deferment, and approval should be legitimate benchmark outputs when evidence, privacy, authority, or risk conditions do not support intervention.Success criteria include open schemas, evidence tiers, privacy-aware protocols, local computation, uncertainty reporting, and evaluation over complete decision episodes.
  • Benchmark design: Benchmarks must combine logged data, realistic generators, expert-validated counterfactuals, adversarial logs, and online or quasi-experimental evidence because many actions lack ground-truth alternatives.The proposed E2A-Bench would test action-conditioned questions across realistic process ecosystems and score act, defer, ask, and refuse outcomes.

V. CONCLUSION

The paper extends process mining from revealing how work unfolds to supporting accountable organizational action. It proposes four connected artifacts and treats verification, limitation, deferral, and refusal as part of success.

  • Conclusion: Event-to-action process mining requires representations, evidence packages, governance contracts, and evaluation tasks that connect mined logs to verifiable, limited, deferrable, or refusible recommendations.The paper frames these artifacts as a foundation for accountable process action rather than a larger dashboard or unconstrained process agent.
Loading 2609.07984v1…