Design consent as a continuous capability.
Allow users to review, modify, and revoke consent at any time.
Contents 7. Trust, Safety & Responsibility 1. Consent & Control
Who decides and when.
“Do users of your system retain control over actions affecting them or their data?”
“Do users retain meaningful control? Does the system continuously respect it?”
“Can users grant, withdraw, and trust control at all times?”
“Can users change their mind without penalty?”
“Does consent remain valid when context changes?”
“What exactly have users agreed to? Where does it apply?”
“Does control align with consequence?”
“What happens if control is unclear or contested?”
“Does the system default to restraint when uncertain?”
“Does automation remain subordinate to consent?”
“Is inferred intent treated as permission or authority?”
Allow users to review, modify, and revoke consent at any time.
Do not offer settings that lack meaningful impact.
Define clearly what actions or data are governed by consent.
Ensure users can revoke participation without harm.
Preserve user authority over automated actions.
Increase oversight and safeguards for high-consequence actions.
Require explicit user acknowledgment for consequential actions.
Do not broaden authority without renewed permission.
Ensure actions align with stated permissions at all times.