“Make trust scopes visible and editable.”
Trust granted invisibly is trust that cannot be revoked deliberately. When what an agent may do — and what it remembers — is a first-class object the human can inspect and edit, authorization becomes a design surface instead of an accumulating liability.
The Context Matrix
Where this principle has been tested. Untested cells are honest gaps, not passing grades — seen evidence for one? Tell us.
| Chat | IDE | CLI | Canvas / Doc | Ambient / Background | |
|---|---|---|---|---|---|
| Coding | ● | ◐ | |||
| Knowledge Work | ● | ||||
| Consumer | ● | ||||
| Enterprise Ops | |||||
| Creative |
● supports · ◐ boundary · ✕ violates · blank untested
Linked Patterns
Boundary Conditions
- coding × ambient-background × background
Mid-run scope editing is unreachable for background agents — the scope you granted at dispatch is the scope you live with until the run ends. Visibility holds; editability breaks.
Evidence
Claude Code allow rules: granted permissions persist as an inspectable, editable list.
Mid-run scope editing is unreachable for background agents — the scope you granted at dispatch is the scope you live with until the run ends. Visibility holds; editability breaks.
ChatGPT memory: review-and-delete settings surface makes what the agent retains editable.
MCP Apps: declared surface contracts make what a third-party server may render an explicit, inspectable scope.
Tagged Stories
The Agents & Humans Briefing
Agentic experience design, coding agents, MCP, and the signals that matter — weekly, free, in about five minutes.
Free. No spam. Unsubscribe anytime.