Skip to main content
Context GrammarDesign for context-aware AI

Context Grammar — Always-On Layer

Trust

▶Listen to this page

An assistant earns trust when you can understand its choices, correct a mistake, and see the next decision improve. Context Grammar proposes a way to make that relationship visible: permission before action, proportionate confirmation, and a clear path to repair.

Trust

English audio

Read transcript

Trust grows through experience

On your first visit to a restaurant, you study the menu and choose each dish. After a few good visits, the host knows your taste and gets you out on time when you are rushing. “Something like last time” becomes easier to say. Yet you may want a closer conversation when bringing an important guest. Dials set today’s boundaries. Trust concerns how that relationship develops through experience.

Temporal Arc · What experience teaches us

Start by asking an assistant to find your usual supplies. You inspect the options and buy them yourself. Later, it prepares the order for approval. Once you correct the pack size, you see that correction reflected next time. These outcomes make delegation more comfortable. Temporal Arc follows what you entrusted to the assistant, what you corrected, and what actually happened over time.

Reliable enough to offer. Yours to choose.

After several correct orders, you might say, “Replenish this item within the budget.” That permission does not extend to booking holidays. You may also prefer to approve every supply order indefinitely. Experience helps establish what the assistant can reliably handle, while your preference still determines what you delegate. A good relationship does not require ever-increasing automation.

Dynamic Friction · A check when it matters

Your usual detergent is unavailable. The alternative comes in a much larger, more expensive pack. That is a good time to ask whether you want the change. Dynamic Friction puts a check where something important differs, instead of making every routine action cumbersome. If you are busy, a nonurgent order can wait. If there is a deadline, the assistant tells you when a decision is needed.

“You remembered what I told you.”

If you once explained that a large pack would not fit in the cupboard, that should matter when another large alternative appears. Brain retains the correction. Trust reflects the record of what followed. The Gate decides what this purchase needs now. For you, the result is simple: the assistant remembered what you said and asked a useful question.

Trust Breach Recovery · Put the problem right

Suppose the assistant orders another brand despite your instruction to buy only the same one. First, it explains the mistake and the actual order status. If the order can be stopped, stop it. If it has shipped, check the return or exchange options. Trust Breach Recovery means dealing with the problem the person now has, rather than ending with an apology.

Show the real undo terms

“You can cancel” is not enough if you do not know the deadline or cost. Can this order be stopped before confirmation? Would a return after shipping involve a fee? Show the actual terms alongside the action. Reversibility Window names that visible opportunity to undo something, with its limits. Some effects, including information already seen by someone else, cannot be fully reversed.

The next action shows the correction

Pause automatic ordering for the affected item and bring the next order back for review. Make sure the exact-brand requirement changes the options offered. Show what was fixed and how future behavior will differ. The person should be able to see the correction in the next action, with an honest record of the mistake and the remedy.

Delegate at your own pace

After a run of correct orders, you may feel ready to delegate replenishment again. Or you may keep checking it yourself. You can automate supplies and still choose gifts together with the assistant. Trust is not measured only by how much happens automatically. It also means feeling comfortable choosing, revising, or limiting the help you receive.

Good reasons to ask again

A host remembers your preferences, checks an important change, and puts things right after a mistake. Those experiences make you want to return. AI can be designed around the same three commitments: Temporal Arc, learning from a record of experience; Dynamic Friction, checking where it matters; and Trust Breach Recovery, responding properly when something goes wrong. Dependable everyday behavior gives you reasons to ask again.

A parent opens a delivery and holds up the wrong detergent while checking the order.The parent hands the taped parcel back to a courier for return.
Put it right: the real order status, the real return — and a next order that shows the correction.
◆ Always-On Layer · Trust

Trust is not a toggle. It is a record you can see.

Explore an illustrative grocery history, then trigger a breach to compare the permitted autonomy. The ceiling rises only where the person saw the outcomes and chose to raise it (weeks 8, 20, 36). Weeks are invented for this demo; time alone creates no trust.

◆Example history · audit ledger
wk 02grocery list accepted ×3 · no edits
wk 08user chooses Confirm after reviewing 21 accepts
wk 14¥4,800 substitute confirmed correctly
wk 20user enables Notify for routine groceries
wk 30142 actions · 2 undos · both recovered
wk 36user enables Auto within the grocery rule
The history belongs to this task and permission scope. Reliable grocery orders do not authorize a flight booking or wider access to private data.
SuggestConfirmNotifyAuto
weeks of track recordwk 20
grows slowly · retreats instantly
◆Relationship console
temporal_arc:
 track_record: 20 weeks
 arc_ceiling: Notify
 breach_active: false
 reversibility_window: merchant cancellation window
dynamic_friction:
 authorized $1 routine → within standing permission
 $1,000 flight → approval before booking
[ ARC · ceiling = Notify ]
effective autonomy = min( outside rules ceiling, service default, person’s setting, trust ceiling = Notify, gate ceiling )
01Temporal Arc — A track record can support more autonomy within a task you authorize.
02Dynamic Friction — Ask where uncertainty or consequences make your judgment necessary.
03Trust Breach Recovery — Repair what can be repaired, correct memory, and narrow permissions.

Introduction

The next decision is where trust becomes visible.

Your assistant orders a substitute yogurt. You say, “That brand was for a guest. For me, use the exact one.” An apology helps for a moment. What matters next is whether the order can be stopped, the mistaken preference is corrected, and the assistant asks before making the same substitution again.

Trust Design connects what happened, what you corrected, and what the system is allowed to do next.

This is why it is an Always-On Layer in the proposed Decision Pipeline. The Relationship Dials express your current limits on action and information access. Trust Design adds a history of outcomes and a recovery process, so a mistake changes subsequent behavior instead of disappearing with the conversation.

layer_position
Dials → knobs on the screen · per moment
Trust → the relationship · always on
// evidence may narrow authority; consent limits expansion

Dials vs Trust

Trust supports permission. It does not replace it.

You might trust an assistant to buy routine groceries and still require approval for every travel booking. You might share a food preference while keeping health records private. Autonomy controls what it may do; Disclosure controls what it may know. A good track record does not silently raise either limit. Trust is per area: success with groceries buys nothing for travel. Building with AI works the same way: UI ideas may run on Auto while anything touching production data is always confirmed.

DomainDials (Relationship Dials)Trust (Trust Design)
NatureVisible limits on action and information accessEvidence of reliability, uncertainty, and repair
TimelineMoment-to-moment execution boundariesHistory within a task, person, and domain
ControlUser permission, with task-specific rules and overridesOutcomes support recommendations; corrections can lower the ceiling
On FailureThe Gate restricts action while the problem is unresolvedRecovery records the error, repairs its effects, and updates memory

A permitted action must still pass the current risk and feasibility checks. A trusted system must still respect information the user chose not to share.

Pillar 01

Temporal Arc

Reliability has a history and a scope. Getting ten grocery orders right tells you something about groceries, not whether the assistant should send a client message on your behalf.

Keep the evidence that helps a user judge that history: what was proposed, what they changed, what actually happened, and whether a correction held on the next attempt. A success the person never saw is not evidence for raising autonomy, and a string of accepts is incomplete if the user never saw the assumption that mattered.

The Temporal Arc names this proposed relationship between evidence and autonomy. The arc is drawn over time, but time does not create trust; visible outcomes and repairs do. A user may move from reviewing suggestions to confirming an order, then permit notification after routine purchases. Auto can be appropriate within a defined rule. Each step remains bounded by the user's chosen permission: trust grows with good outcomes the person can see, the system may propose a higher level, only the person raises it, and staying in Confirm is a valid outcome.

A breach narrows the affected permission while the cause is reviewed, . The ceiling is a limit on execution, not a numerical measure of a person's trust.

Pillar 02

Dynamic Friction

A useful confirmation gives you a decision worth making: the uncertain assumption, its consequence, and a way to change it.

“Are you sure?” is little help if the flight is nonrefundable or the assistant has picked the wrong departure airport. Show those details before booking, with a path to edit the plan or take over. Routine confirmations that reveal nothing teach people to click through.

Dynamic Friction adapts that intervention to uncertainty, consequences, reversibility, and the user's present situation. Cognitive Load can change when or how to ask. It cannot turn silence into consent.

A $1 routine may proceed under standing permission; its low price alone is not permission. A $1,000 flight outside that scope waits at an Approval Gate. If the traveler is busy, the system can save the proposal and disclose any expiry. It must not infer approval because the fare might disappear.

Pillar 03

Trust Breach Recovery

Recovery has two jobs: address the immediate consequence and prevent the same misunderstanding from driving the next action.

Return to the wrong yogurt. First, show the order, the inferred preference, and the rule that allowed it. Stop any related action still pending. If cancellation is available, offer it and report whether it succeeded; if not, explain the return or replacement path without calling it an undo.

A Reversibility Window makes the actual deadline and scope of a repair visible. A merchant may allow cancellation before dispatch; a sent message or disclosed private detail cannot simply be taken back. The interface must reflect those limits before execution as well as afterward.

Then correct the source: “That preference belonged to a guest.” Record the correction in the relevant Brain and require confirmation for the affected substitution. On the next order, show that the corrected rule was applied. Only reviewed outcomes and the user's permission can support restoring autonomy.

Ecosystem Integration

A correction needs somewhere to go.

The recovery loop crosses the framework: Brain stores the correction, negotiation makes the next assumption reviewable, and the Gate enforces the narrower permission. This is how “I heard you” becomes a change the user can observe.

Always-On Layer 01

Distributed Brain Memory

Keep the corrected preference, its source, and the outcome in the appropriate scope. The Temporal Arc draws on this history without making private feedback available to every Agent.

Always-On Layer 03

Negotiation Micro-UI

An Interpretation Preview or Assumption Card shows what the system is about to rely on. Dynamic Friction gives the user a focused chance to confirm, edit, or take over.

Stage 5 & 6

Negotiation Gate Overrides

The trust ceiling is one term in effective autonomy = min(outside rules ceiling, service default, person’s setting, trust ceiling, gate ceiling). It supports permission; it never replaces it. If a required fact is unavailable under Disclosure settings, ask for the minimum needed or leave the action pending.

A correction earns its place when it changes the next decision.