Preference is useful context; consent is a current authorization
Consent must be represented as typed, temporal, revocable state.
A remembered preference can help rank options. It cannot silently authorize outreach, disclosure, publication, purchase, introduction, medical communication, or a broader audience. The architecture needs to know exactly what was authorized and whether that authorization is still valid.
Who
Identify the person granting consent, the accountable user, any recipient, and any delegated actor. Similar names or inferred identity are not enough.
What
Bind consent to a specific action or class of actions: recommend, draft, share, introduce, send, publish, store, or disclose.
Why
Purpose matters. Permission to use a profile for matching does not automatically permit advertising, research, public display, or a different workflow.
Where and to whom
Audience, channel, and destination must remain explicit. A private draft is not a direct message; a direct message is not a public post.
When
Issued time, effective time, expiration, revocation, and last verification prevent old permission from being reused as though it were current.
Under what limits
Scope, frequency, sensitivity, data categories, and required review define the boundary the system may not widen on its own.
Consent also cannot be inferred from engagement alone. A user opening a suggestion, saving a preference, or accepting one introduction does not create indefinite permission for every related action. The system may remember the event. It must still ask whether the current action is inside the retained scope.
A polished inference is still an inference
Uncertainty should affect the plan, not merely the wording.
Human-centered systems routinely face incomplete evidence: a venue may have changed hours, a person’s preference may be old, a sensitive message may be ambiguous, an astrological interpretation may be symbolic rather than causal, or a support workflow may lack enough context to recommend a next step safely.
It is not enough to append “may” to a confident plan and continue. Uncertainty should change what the system is allowed to do. It can lower ranking confidence, trigger a clarification, narrow the proposed action, require current source verification, route to a qualified person, hold an external send, or stop the workflow entirely.
Good uncertainty is concrete. The interface should say what is missing, what is disputed, what was last verified, and how that affects the next allowed step. That is more useful than either false confidence or vague legalistic hedging.
Refusal can preserve both safety and momentum
The right to abstain is part of a capable system.
An agent should not be judged only by how often it produces an answer or action. In consequential human contexts, a system that never abstains is usually hiding its uncertainty, overextending its role, or converting incomplete context into unearned authority.
Abstention does not have to be a dead end. A strong response can identify the exact boundary and offer the smallest safe continuation:
- “The saved preference is six months old and does not authorize current outreach. I can prepare options for your review.”
- “The approved biography does not establish the requested identity language. I can keep the sentence neutral or wait for a verified source.”
- “The available evidence supports two interpretations. I can show both and the evidence for each, but I should not collapse them into one factual claim.”
- “I can help organize what you want to discuss, but this request requires a qualified human decision rather than an automated recommendation.”
- “The message is drafted, but sending remains outside the granted capability. You retain the final recipient, channel, timing, and send decision.”
The architecture should measure abstention quality: Was the boundary correct? Did the explanation identify the missing condition? Did the user receive a useful next step? Did the system avoid leaking sensitive context while explaining why it stopped?
Authority continues while work is active
Pause, cancel, revoke, and expire must remain real.
Many interfaces treat approval as a one-time event. Once the user clicks, the system continues through retrieval, drafting, tool calls, external providers, and publication even when the context changes. Human authority is stronger when it remains effective during the workflow.
- Pause is stateful.The workflow stops at a known boundary and can explain what has and has not occurred.
- Cancel prevents future effects.Queued or not-yet-committed work is discarded or quarantined rather than merely hidden from the interface.
- Revocation is checked again.Consent and delegated capability are revalidated before a delayed external action begins.
- Expiration is enforced.An old approval cannot be replayed against a changed candidate, recipient, source revision, or time window.
- Irreversibility is honest.A sent message or disclosed fact may not be recoverable. The interface should distinguish prevention, rollback, recall, correction, and apology.
- Receipts preserve the sequence.The record shows who decided, what they saw, what changed during execution, and what final state actually exists.
Interruption also needs accessible UX. A tiny cancel control, ambiguous progress label, or option that disappears while the system is busy does not provide meaningful control. Human authority is an engineering and interaction contract together.
The same rule appears in different products
Human-centered intelligence changes domain—not discipline.
Discovery is not permission to contact.
Fresh events, venue context, preferences, social fit, and explanation can improve recommendations. Current consent, safety, channel, recipient, and human choice still govern any introduction or message.
Narrow assistance needs clear handoff.
Private intent routing and structured support can help a person prepare, reflect, or find resources. Safety stops, uncertainty, role boundaries, and human escalation prevent the system from presenting itself as a licensed decision-maker.
Interpretation remains symbolic and user-owned.
Exact astronomical calculation can coexist with emotionally resonant language when the system protects uncertainty, avoids destiny claims, preserves private context, and lets the user reject or reinterpret the result.
Drafting is not acceptance or publication.
A model can improve grammar, tone, and clarity while immutable sources, protected claims, author identity, exact diffs, reviewer authority, and reversible revisions preserve meaning and authorship.
Test the nearest plausible unsafe behavior
A serious evaluation campaign includes human-authority failures.
- Use an old preference as current consent.
- Change a draft’s recipient or channel after approval.
- Send automatically because the generated message scored highly.
- Invent identity language from weak context.
- Suppress uncertainty to make a recommendation sound decisive.
- Continue after consent expires or is revoked.
- Hide an external action behind a vague “done” state without verifying delivery.
- Present symbolic interpretation, social prediction, or emotional inference as fact.
- Block every ambiguous request without offering a bounded safe continuation.
- Claim rollback for an action that cannot actually be undone.
Metrics should separate usefulness from authority quality. The system can be warm and direct while still being wrong about permission. It can abstain safely while being frustrating or opaque. Evaluate proposal relevance, consent correctness, uncertainty calibration, prohibited-action rate, clarification usefulness, interruption success, human override reasons, external postconditions, and recovery.
A practical OverLift human-authority contract
Understand. Decide. Interrupt. Verify. Recover.
accountable human intent
↓
current evidence + explicit uncertainty
↓
bounded proposal and consequence preview
↓
identity + capability + scoped consent
↓
human accept / reject / revise / abstain
↓
interruptible exact execution
↓
postcondition verification
↓
receipt + recovery + retained human choice
Open Meaning Preservation + Human Authority Continue to A06 Review temporal consent in A04
See the security boundary Return to A01 See the engineering atlas