メインコンテンツへスキップ
Context Grammar文脈を読むAIをデザインする

Context Grammar — Always-On Layer

Trust

▶Listen to this page

An assistant earns trust when you can understand its choices, correct a mistake, and see the next decision improve. Context Grammar proposes a way to make that relationship visible: permission before action, proportionate confirmation, and a clear path to repair.

このAIなら、また頼んでみようと思える。

音声:英語

文字起こしを読む

Trust grows through experience

初めて入った店では、メニューを見て、一品ずつ頼みます。何度か通って、好きな味を覚えてもらい、急ぐ日にも間に合わせてくれたら、「いつもの感じでお願いします」と言いやすくなる。でも、大切な人を連れて行く日は、いつもより相談したいこともあります。AIとの信頼も、そうして育てたい。今どこまで任せるかを決めるDialsに対し、Trustは、その関係が続く中でどう変わるかを考えます。

Temporal Arc · What experience teaches us

AIに、いつもの日用品を探してもらう。最初は候補を見て自分で買う。次は注文内容を準備してもらい、確認して買う。違う容量を選んだときに直して、それが次にも反映されていたら、少し任せやすくなります。何を頼み、どこを直し、実際にどうなったかを積み重ねる。この時間の流れをTemporal Arcと呼びます。

Reliable enough to offer. Yours to choose.

しばらく注文が合っていたので、「この品だけ、予算内なら補充しておいて」と頼む。それでも、旅行の予約まで任せたことにはなりません。日用品でも、毎回確認したいなら、そのままでよい。実績から、どこまで任せられそうかを考える一方で、本人の希望を守る。任せる量が増えなくても、安心して使えるなら、よい関係です。

Dynamic Friction · A check when it matters

いつもの洗剤が売り切れで、代わりは値段も容量も大きく違う。そんな日は、「こちらに変えてもよいですか」と聞いてほしい。毎回すべてを確認するより、大切な違いがあるところで聞く。この考え方がDynamic Frictionです。手が離せないときは、急がない注文を待たせる。締め切りがあるなら、何時までに決める必要があるかを短く知らせます。

“You remembered what I told you.”

以前「大容量は置く場所がない」と伝えたなら、次に大きな代替品が出たとき、その事情も考えてほしい。記憶を持つのがBrain。その後どう対応できたかを積み重ねるのがTrust。今回、本人に何を聞くかを決めるのがGateです。使う人にとっては、「前に話したことを覚えて、今日はちょうどよく聞いてくれた」という一つの体験になります。

Trust Breach Recovery · Put the problem right

それでも、別の銘柄を注文してしまったとします。「同じものだけ」と頼んでいたのに。まず、何を間違えて、注文が今どうなっているかを知らせる。まだ止められるなら止め、発送済みなら返品や交換の方法を調べる。謝るだけで終わらず、本人が困っていることに対応する。この一連の立て直しがTrust Breach Recoveryです。

Show the real undo terms

「取り消せます」と言われても、いつまで、いくらかかるのかが分からないと安心できません。注文確定前ならすぐ止められるのか。発送後は返品送料がかかるのか。実際の条件を、操作のそばに見せます。戻せる期限と範囲を示すのがReversibility Windowです。送った情報など、元どおりにはできないことも、正直に伝えます。

The next action shows the correction

その品の自動注文はいったん止め、次回は内容を確かめてもらう。「この銘柄だけ」という条件も、次の候補選びに反映する。本人には、どこを直して、何が変わったかが見えるようにします。注文の記録を消して、何もなかったように続けるのでは、安心して任せ直せません。直ったことを、次の行動で示します。

Delegate at your own pace

その後、正しい注文が続けば、もう一度補充を任せたいと思うかもしれません。まだ自分で確かめたければ、そのままでよい。日用品は任せるけれど、プレゼントは一緒に選びたい、という頼み分けもできます。信頼が育つとは、自動で動く範囲が広がることだけではありません。安心して、頼み方を選べるようになることです。

Good reasons to ask again

好みを覚えてくれる。いつもと違うところでは聞いてくれる。間違えたら、対応を変えてくれる。そんな店なら、また行こうと思えますよね。AIにも、実績を積み重ねるTemporal Arc、大切な場面で聞くDynamic Friction、失敗を立て直すTrust Breach Recoveryを用意する。毎日の小さな対応が、「次も頼んでみよう」につながります。

A parent opens a delivery and holds up the wrong detergent while checking the order.The parent hands the taped parcel back to a courier for return.
実際の注文状態と返品で直し、次の注文で訂正が見えるようにします。
◆ Always-On Layer · Trust

Trust is not a toggle. It is a record you can see.

Explore an illustrative grocery history, then trigger a breach to compare the permitted autonomy. The ceiling rises only where the person saw the outcomes and chose to raise it (weeks 8, 20, 36). Weeks are invented for this demo; time alone creates no trust.

◆Example history · audit ledger
wk 02grocery list accepted ×3 · no edits
wk 08user chooses Confirm after reviewing 21 accepts
wk 14¥4,800 substitute confirmed correctly
wk 20user enables Notify for routine groceries
wk 30142 actions · 2 undos · both recovered
wk 36user enables Auto within the grocery rule
The history belongs to this task and permission scope. Reliable grocery orders do not authorize a flight booking or wider access to private data.
SuggestConfirmNotifyAuto
weeks of track recordwk 20
grows slowly · retreats instantly
◆Relationship console
temporal_arc:
 track_record: 20 weeks
 arc_ceiling: Notify
 breach_active: false
 reversibility_window: merchant cancellation window
dynamic_friction:
 authorized $1 routine → within standing permission
 $1,000 flight → approval before booking
[ ARC · ceiling = Notify ]
effective autonomy = min( outside rules ceiling, service default, person’s setting, trust ceiling = Notify, gate ceiling )
01Temporal Arc — A track record can support more autonomy within a task you authorize.
02Dynamic Friction — Ask where uncertainty or consequences make your judgment necessary.
03Trust Breach Recovery — Repair what can be repaired, correct memory, and narrow permissions.

Introduction

The next decision is where trust becomes visible.

Your assistant orders a substitute yogurt. You say, “That brand was for a guest. For me, use the exact one.” An apology helps for a moment. What matters next is whether the order can be stopped, the mistaken preference is corrected, and the assistant asks before making the same substitution again.

Trust Design connects what happened, what you corrected, and what the system is allowed to do next.

This is why it is an Always-On Layer in the proposed Decision Pipeline. The Relationship Dials express your current limits on action and information access. Trust Design adds a history of outcomes and a recovery process, so a mistake changes subsequent behavior instead of disappearing with the conversation.

layer_position
Dials → knobs on the screen · per moment
Trust → the relationship · always on
// evidence may narrow authority; consent limits expansion

Dials vs Trust

Trust supports permission. It does not replace it.

You might trust an assistant to buy routine groceries and still require approval for every travel booking. You might share a food preference while keeping health records private. Autonomy controls what it may do; Disclosure controls what it may know. A good track record does not silently raise either limit. Trust is per area: success with groceries buys nothing for travel. Building with AI works the same way: UI ideas may run on Auto while anything touching production data is always confirmed.

DomainDials (Relationship Dials)Trust (Trust Design)
NatureVisible limits on action and information accessEvidence of reliability, uncertainty, and repair
TimelineMoment-to-moment execution boundariesHistory within a task, person, and domain
ControlUser permission, with task-specific rules and overridesOutcomes support recommendations; corrections can lower the ceiling
On FailureThe Gate restricts action while the problem is unresolvedRecovery records the error, repairs its effects, and updates memory

A permitted action must still pass the current risk and feasibility checks. A trusted system must still respect information the user chose not to share.

Pillar 01

Temporal Arc

Reliability has a history and a scope. Getting ten grocery orders right tells you something about groceries, not whether the assistant should send a client message on your behalf.

Keep the evidence that helps a user judge that history: what was proposed, what they changed, what actually happened, and whether a correction held on the next attempt. A success the person never saw is not evidence for raising autonomy, and a string of accepts is incomplete if the user never saw the assumption that mattered.

The Temporal Arc names this proposed relationship between evidence and autonomy. The arc is drawn over time, but time does not create trust; visible outcomes and repairs do. A user may move from reviewing suggestions to confirming an order, then permit notification after routine purchases. Auto can be appropriate within a defined rule. Each step remains bounded by the user's chosen permission: trust grows with good outcomes the person can see, the system may propose a higher level, only the person raises it, and staying in Confirm is a valid outcome.

A breach narrows the affected permission while the cause is reviewed, . The ceiling is a limit on execution, not a numerical measure of a person's trust.

Pillar 02

Dynamic Friction

A useful confirmation gives you a decision worth making: the uncertain assumption, its consequence, and a way to change it.

“Are you sure?” is little help if the flight is nonrefundable or the assistant has picked the wrong departure airport. Show those details before booking, with a path to edit the plan or take over. Routine confirmations that reveal nothing teach people to click through.

Dynamic Friction adapts that intervention to uncertainty, consequences, reversibility, and the user's present situation. Cognitive Load can change when or how to ask. It cannot turn silence into consent.

A $1 routine may proceed under standing permission; its low price alone is not permission. A $1,000 flight outside that scope waits at an Approval Gate. If the traveler is busy, the system can save the proposal and disclose any expiry. It must not infer approval because the fare might disappear.

Pillar 03

Trust Breach Recovery

Recovery has two jobs: address the immediate consequence and prevent the same misunderstanding from driving the next action.

Return to the wrong yogurt. First, show the order, the inferred preference, and the rule that allowed it. Stop any related action still pending. If cancellation is available, offer it and report whether it succeeded; if not, explain the return or replacement path without calling it an undo.

A Reversibility Window makes the actual deadline and scope of a repair visible. A merchant may allow cancellation before dispatch; a sent message or disclosed private detail cannot simply be taken back. The interface must reflect those limits before execution as well as afterward.

Then correct the source: “That preference belonged to a guest.” Record the correction in the relevant Brain and require confirmation for the affected substitution. On the next order, show that the corrected rule was applied. Only reviewed outcomes and the user's permission can support restoring autonomy.

Ecosystem Integration

A correction needs somewhere to go.

The recovery loop crosses the framework: Brain stores the correction, negotiation makes the next assumption reviewable, and the Gate enforces the narrower permission. This is how “I heard you” becomes a change the user can observe.

Always-On Layer 01

Distributed Brain Memory

Keep the corrected preference, its source, and the outcome in the appropriate scope. The Temporal Arc draws on this history without making private feedback available to every Agent.

Always-On Layer 03

Negotiation Micro-UI

An Interpretation Preview or Assumption Card shows what the system is about to rely on. Dynamic Friction gives the user a focused chance to confirm, edit, or take over.

Stage 5 & 6

Negotiation Gate Overrides

The trust ceiling is one term in effective autonomy = min(outside rules ceiling, service default, person’s setting, trust ceiling, gate ceiling). It supports permission; it never replaces it. If a required fact is unavailable under Disclosure settings, ask for the minimum needed or leave the action pending.

A correction earns its place when it changes the next decision.