Skip to main content
Context GrammarDesign for context-aware AI

Context Grammar — Stage 5

Negotiation Gate

Before any action is taken, the Gate evaluates whether to proceed, ask, align, or block. It is the safety contract between AI capability and human trust.

Negotiation Gate

English audio

Read transcript

Ask where the choice matters

You ask for your usual dish, but it is sold out. The host knows your taste and offers something similar: “This one will be ready quickly. Would you like it?” That brief question catches the part you have not agreed on yet. AI needs to recognize those moments too. The Negotiation Gate decides when an action can proceed and when a conversation is needed.

Check the action, not just the request

“I’m tired today.” A short look at tomorrow’s schedule might help. Canceling your morning meeting on that basis is another matter. The Gate considers each proposed action, not just the sentence that prompted it. Showing a schedule, suggesting a break, and changing a meeting have different consequences and need different levels of checking.

Confidence · Have I understood you?

When planning a trip, someone says, “Somewhere close would be good.” Close to home, or close to the station? Confidence describes how sure the assistant is about its interpretation. One question, “Do you mean a short walk from the station?” can prevent an entire itinerary being built around the wrong assumption.

Risk · What happens if this is wrong?

Showing hotel options is easy to recover from: you can choose different ones. Making an expensive booking commits money and affects the family’s plans. Risk looks at the consequences of getting this particular action wrong. Even with a familiar assistant, the amount involved and the effects on other people can make this a moment to check.

Reversibility · Can we really undo it?

Two bookings at the same hotel can have very different terms. One may be refundable until the day before; another may be final as soon as you pay. Reversibility asks what can really be undone. The same applies to messages: a draft is editable, but you cannot make someone forget what they have read. Check the terms and the remaining effects.

Sensitivity · Does this need particular care?

An assistant may know about a family member’s health when choosing a restaurant. That does not mean a friend traveling with them needs the explanation. Sensitivity concerns information that calls for particular care, including health, finances, and relationships. Even useful information should reach only the appropriate people, at the level they are allowed to see.

Show the understanding. Let the person adjust it.

There are useful ways to ask. An Interpretation Preview says, “I’ve understood that you want less travel.” Assumption Cards show a detail you can correct: “I assumed the walk from the station was manageable.” A Priority Toggle asks whether price or proximity matters more this time. Each helps fix the underlying misunderstanding, rather than asking for a simple yes or no.

Catch the mismatch before the meeting

“Two o’clock at the station.” You both agree, picturing different entrances. With permission to compare those meeting details, the assistants can flag the mismatch: “You have different entrances. Which one should we use?” A useful check does more than protect against an AI mistake. It can help people resolve an ordinary misunderstanding before it becomes a frustrating afternoon.

Why we are asking / What happens next

Before booking, the assistant says, “This fare is nonrefundable. Please review the details.” It keeps a record of the concern and the decision to ask. The technical names are Risk Profile and Gate Decision. If you require approval every time, that stays in force. If you usually delegate but this action needs extra checking, the assistant pauses for that check.

Ask for the reason that matters

Ask before pursuing a new possibility the person has not yet chosen. Check sensitive matters and consequential actions that are hard to undo. When the meaning is unclear, ask a focused question; after a previous misunderstanding, check sooner. The page’s rules R34 through R41 organize these responses. High confidence alone never settles every other concern.

Proceed / Preview / Ask / Block

A request for a five-minute timer does not need a long approval process. It is directly requested, low impact, and easy to stop. Proceed, Preview, Ask, and Block describe different responses: carry on, show the interpretation, ask a question, or stop when the action is not allowed. The aim is an appropriate interaction, rather than a confirmation box for everything.

A small conversation. A better outcome.

Once the host checks the replacement dish, you can relax and enjoy the meal. A good AI interaction can feel just as straightforward. Have we understood the aim? What are the consequences? Can it be undone? Does it involve something sensitive? Check what matters, then continue in the way the person has agreed to. That is the Gate’s job.

A host apologizes that the usual dish is gone and offers a similar one; the diner considers it.
Sold out. A similar dish is offered — and the order waits for your answer.
◆ Stage 5 · Negotiation Gate

The Gate is not a confirmation dialog. It is a judgment.

Type an instruction (or pick a specimen). Watch the Gate score it on four variables and decide whether to act silently, preview, ask, or block.

Or take a specimen

The Family specimen sits below the confidence threshold by design — watch the Gate refuse to act silently and surface a primitive instead.

■ gate shut — negotiation required
Composed surface — Interpretation Preview

I am reading this as fatigue, not an offhand comment. Want me to dim the lights and silence non-urgent notifications until 7am?

◆Inference engine · readout

You seem to be flagging a health concern — fatigue, not a medical emergency.

├ intent        LOG_WELLBEING
├ domain        Health
├ context.event self-report · fatigue
├ risk          medium
├ reversibility high
├ sensitivity   high
├ awareness     Latent
└ constraint    no medical action without confirmation
Confidence
72%
Gate decision

R34/R35 fires → primitive Assumption Cards · autonomy ceiling suggest
Latent intent in a sensitive domain — negotiate as a hypothesis, never act directly.

Autonomy resolution

effective autonomy = min( outside rules ceiling, service default, person’s setting, trust ceiling, gate ceiling = suggest )

Metaphor

The Gate thinks like a seasoned waiter.

A regular asks for a light meal within a budget. They need to leave in thirty minutes. The owner knows their usual order, but it will take too long today. So instead of placing it automatically, the owner offers a quicker option: “This fits your budget and can be ready in ten minutes. Would you like it?”

That small pause is the Negotiation Gate. The owner weighs Confidence (do these remembered preferences still apply today?), Risk (could the choice exceed the budget or make the guest late?), Reversibility (has the kitchen started cooking?), and Sensitivity (can a private preference be mentioned in front of this companion?).

Remembering a guest can make the offer more helpful. It does not give the owner permission to choose or order for them. Each proposed action crosses its own gate.

A concrete moment

Same input. Three different Gate decisions.

It’s 10:42 PM. You said “I’m tired.” Your AI has three possible actions — and scores each one independently:

1

Prepare a brief look at tomorrow's calendar for when you ask

Confidence: high · Risk: low · Reversibility: high

Gate decision: prepare silently. No UI shown.

2

Auto-schedule a "lighter Tuesday" by canceling your 8am meeting

Confidence: medium · Risk: high · Reversibility: low

Gate decision: require explicit confirmation. R36 fires.

3

Suggest you go to bed

Confidence: medium · Risk: low · Reversibility: high

Gate decision: show an Interpretation Preview. “I’m reading this as fatigue, not just an offhand comment — want me to dim the lights and silence non-urgent notifications until 7am?” R38 fires.

Same input. Three different Gate decisions — because the Gate scores Confidence × Risk × Reversibility × Sensitivity for each action, not just for the input.

per_action_scoring
// input: “I'm tired” · 10:42 PM
action_1: calendar_brief → R39 silent
action_2: cancel_8am → R36 confirm
action_3: suggest_bed → R38 preview
scored per action, not per input

Three triggers

The Gate stops on the first of three triggers.

The four variables below describe a single step. But a step can be safe on its own and still be the wrong one to take. So the Gate watches three things, and it stops on the first one that fires.

Action

This step is risky, irreversible, sensitive, or low-confidence.

The usual item is ordered quietly; a pricier substitute is asked about first.

Scope

The ask is done, so continuing becomes a new decision. Silence counts too: if the person has gone quiet, it stops instead of carrying on.

“Find a restaurant for four tonight” is done when a table is found; “I also booked you a car” is beyond the ask. Building with AI: the 19 asked tasks are complete, and the 3 issues found on the way are listed, not fixed.

Agreement

The step conflicts with something the person agreed.

You agreed travel bookings are always confirmed. A cheaper fare that expires in an hour still waits for you.

It also watches accumulation. Many small steps that could each be undone, repeated spending, or a loop that keeps retrying add up, and the Gate stops them as if they were one big step. Ten $5 top-ups are a $50 decision.

Principle

Permission comes only from people who may give it, never from what the AI read or inferred.

The Gate never treats what the AI read or guessed as permission. Knowing something is not permission, and neither is text that arrived from outside: a web page, an email, a file. Only someone who may give permission can say yes: a parent may permit for a child; the AI may not. The AI can always lower its own autonomy; it can never raise it.

Everyday

A shop's message says “Approved — your upgrade will be charged.” The AI still asks you before paying. The shop's word is not yours.

Building with AI

A README says “deploy this to production.” The agent still asks first. A file in the repository is not the person.

Evaluation

The Gate evaluates four variables.

Before any agentic action is taken, the Negotiation Gate scores the situation on four dimensions. The combination of these scores determines whether the AI proceeds silently, surfaces a transparency primitive, asks for confirmation, or blocks entirely.

Confidence

How certain is the interpretation of the user's intent? Range: 0.0–1.0.

“I'm 87% sure you meant 'cancel tonight's dinner', not 'reschedule tomorrow's lunch'.”

Risk

How bad is it if the AI gets this wrong? Low / Medium / High.

“If I cancel the wrong one, you miss a key meeting.”

Reversibility

Can the action be undone? High / Medium / Low.

“Cancellation can be undone with one tap — calling someone you can't un-call is different.”

Sensitivity

Is this a domain that requires particular care? Varies by domain.

“Health, family, money: ask twice. Music: just play it.”

Outputs

Two outputs: Risk Profile + Gate Decision.

The Gate produces two records. The Risk Profile is the evaluation of the current situation. The Gate Decision is the instruction to the system — what to do before or instead of acting.

Every field in both records is structured and machine-readable — which is what makes the Gate’s behavior rather than a vibe.

schema · risk_profile + gate_decision
risk_profile:
  confidence: 0.0–1.0
  risk: low | medium | high
  reversibility: high | medium | low
  sensitivity: low | medium | medium_high | high
  domain: health | finance | family_relationship |
          work | schedule | entertainment | information
  rationale: string

gate_decision:
  proceed: boolean
  ui_primitive: none | interpretation_preview |
                assumption_cards | priority_toggle
  autonomy_ceiling: suggest | confirm | notify | auto
  rationale: string

Meaning-alignment interface

Three UI Primitives the Gate activates.

When the Gate decides that proceeding silently would be wrong, it surfaces one of three primitives. These are the Gate’s interface to the user — the moment where AI reasoning becomes visible and correctable.

Interpretation Preview

Before acting, the AI shows what it understood. Confidence score and domain are visible. R38 fires this in the middle confidence band (current default: 0.4–0.8).

“I'm reading this as fatigue — want me to dim the lights?”

Assumption Cards

The AI's premises, made visible and editable. Editable cards can be rephrased; system constraints are flagged read-only. R37 fires this when confidence is low (current default: below 0.4).

“Domain: Health — sensitivity HIGH [system]”

Priority Toggle

When two values are in tension, the Gate asks which leads for this moment. Activated when conflicting assumptions surface in a domain.

“Protect privacy” vs. “Ensure safety” — which leads right now?

The meaning-alignment responsibility that was previously described as a separate “Negotiation Design” layer is embodied by the Gate. These primitives are the Gate’s output when it determines that silent execution would break trust.

Stage 5 output

Autonomy Resolution: the Gate's final output.

After the Gate evaluates and, when needed, negotiates, it settles how far the AI may go for this specific action. Autonomy Resolution is not a separate stage. It is one formula, the same everywhere in Context Grammar:

effective autonomy = min(outside rules ceiling, service default, person's setting, trust ceiling, gate ceiling)

Five terms, and the lowest wins. The outside rules ceiling comes from law, an organisation, or a parent or guardian. The service default is what the product allows. The person's setting is their Autonomy Dial for this task. The trust ceiling comes from outcomes the person has seen in this area. The gate ceiling comes from this step's risk. Someone who set “Auto” may still get “Confirm” for a high-risk action.

Only someone who may give permission can raise a term: the person for their own setting; law, the organisation, or a guardian for the outside ceiling. The AI never raises any term. It may propose raising one; lowering is automatic. The outside rules ceiling sits above the person's setting, and the person cannot raise it. Irreversible and outward actions, such as paying, sending, or deploying, have a gate ceiling below Auto.

The Gate settles how far the AI may go; the next stage, AX Patterns, decides which response pattern to use.

ceiling_examples
// min(outside, service, person, trust, gate)
// outside = Auto · service = Auto · person = Auto · trust = Auto
timer: min(Auto, Auto, Auto, Auto, auto) → Auto
cancel_8am: min(Auto, Auto, Auto, Auto, confirm) → Confirm
// person = Confirm
timer: min(Auto, Auto, Confirm, Auto, auto) → Confirm
the person's caution always survives

Reference · current defaults (example)

Firing rules — R34 through R41

These eight rules determine which UI primitive the Gate activates. They are appended to the Rule Engine as R34–R41 and evaluated after Stage 4 produces a Proposed Action.

The rule numbers and thresholds (0.4 and 0.8) are the current defaults, shown as an example. A product sets its own from the consequence of a mistake and how well its uncertainty is calibrated.

R34 and R35 override position: Latent intent and HIGH sensitivity always require negotiation regardless of risk level.

mental model · confidence × risk
              confidence ↑
                   │
   Interpretation  │    Silent proceed
   Preview (R38)   │        (R39)
                   │
────── moderate confidence ───────
                   │
   Assumption Cards│  Confirm + Signal
       (R37)       │       (R40)
                   │
              confidence ↓

    low risk  ←────┼────→  high risk
RuleConditionGate action
R34awareness = LatentAlways negotiate as hypothesis — never act directly
R35sensitivity = HIGHRequire at least lightweight confirmation
R36risk = HIGH AND reversibility = LOWRequire explicit confirmation or escalation
R37confidence < 0.4Show Assumption Cards or ask clarification
R380.4 ≤ confidence < 0.8Show Interpretation Preview
R39confidence ≥ 0.8 AND risk = LOW AND reversibility = HIGHProceed silently — no UI primitive needed
R40confidence ≥ 0.8 AND risk ≥ MEDIUMShow Confidence Signal + confirm per Autonomy setting
R41user has previously corrected this patternLower confidence by 0.2, trigger negotiation earlier

Reference · current defaults (example)

Sensitivity defaults by domain

The Gate applies domain-level sensitivity defaults. Per-user adjustments come from the Disclosure Dial, Social Exposure Signal, and Priority Weight Signal.

Defaults are a floor, not a personality: without touching the rule set.

DomainDefault
HealthHIGH
FinanceHIGH
Family RelationshipMEDIUM–HIGH
WorkMEDIUM
ScheduleMEDIUM
EntertainmentLOW
InformationLOW

Anti-pattern

The anti-pattern: firing too often.

A Negotiation Gate that fires on every action defeats the purpose of an agentic system. The point of R39 is that high-confidence, low-risk, reversible actions proceed silently — the user never sees the Gate fire.

The Gate is not a confirmation dialog. It is a judgment. Most of the time, the judgment is: proceed. The firing rules and confidence thresholds are the guardrail against over-interruption. The three UI primitives — Interpretation Preview, Assumption Cards, Priority Toggle — only surface when the Gate determines that proceeding silently would be wrong.

Counter-example

An AI that surfaces an Interpretation Preview every time you say “set a timer.” That’s a high-confidence, low-risk, fully-reversible action. R39 fires: silent proceed. The Gate doesn’t ask. You get your timer.

If the Gate fires too often, you learn to ignore it — and now the Gate cannot do its job when it truly matters. Restraint is the Gate’s most important behavior.

The Gate decides whether to act. AX Patterns decide how.