Pattern 46

Autonomy has a visible boundary

Grant authority by capability and consequence rather than by personality.

Research-informed design proposal

Concrete takeaway

Name capabilities and limits.

Choose an approach

These are editorial decision conditions to validate. Some alternatives are successive states or can be combined; they are not always exclusive choices.

AlternativeUse whenTradeoff or requirement
A · Capability contractThe user grants capability-specific permissionVague trust is not a permission model
B · Bounded runA task is delegated within a defined scopeLimits and stopping conditions must be enforceable
C · Revoke and recoverThe user revokes permission or stops a taskState and partial results need review and recovery

The problem

A friendly agent can receive an ambiguous global permission that extends from drafting into sharing, scheduling or deleting.

The pattern

Name capabilities and limits. Distinguish advice, drafts, approved actions and bounded unattended work. State scope, expiry and stop conditions for standing authority; keep pause, revoke and available recovery visible.

Compare the alternatives

Grant authority by capability and consequence rather than by personality.

A · Capability contract

Assistant · Example interface
Explain passages
Allowed within selected sources.
Save notes
Ask before saving.
Share content
Ask for each audience.
Review permissions

Users can see what is permitted.

B · Bounded run

Assistant · Example interface
Prepare study material
Selected passage; selected sources; no sharing.
Stop after the agreed scope.
Pause this task

A delegated task has enforceable limits.

C · Revoke and recover

Assistant · Example interface
Stop the current task
Revoke this capability
Completed changes
Inspect results and available undo.

A permission remains under user control.

Original wireframe proposals · No live controls · Grey rows represent schematic text, not loading states · Labelled placeholders are not Scripture quotations

Download this wireframe as SVG

Failure modes

A single “trust me” switch; unenforced budgets; permissions expanding silently; a decorative stop button that does not stop execution.

Bible and faith considerations

Proactivity should not target grief, fear or private disclosures to increase dependence or sales.

What to validate

Test capability changes, expiry, budget exhaustion and revocation during a run. Compare the permission shown with actual tool and data access.

Evidence status

Research-informed design proposal. These visual alternatives have not been tested with users in this atlas. Source findings, documented behaviour and this proposed adaptation are different kinds of evidence.

Sources and adaptation

This card is an original design synthesis. The following sources inform its content distinctions, interaction approach or review requirements; they do not validate the whole pattern.

Common scenarios and flows

Design principles in this decision

Editorial application of Missional by Design. These values frame review questions; they do not validate a pattern’s effectiveness.

Compare alternatives using the task and evidence above. Record competing needs instead of treating a principle as an automatic verdict.