The Blue Book of UX Directives
7. Trust, Safety & Responsibility

1. Consent & Control

Contents 7. Trust, Safety & Responsibility 1. Consent & Control

Who decides and when.

First, ask yourself

“Do users of your system retain control over actions affecting them or their data?”

Mission statement

Ensure users retain agency by enabling informed choices and control over permissions.

Key heuristics Consent & Control

  1. Consent must remain reviewable, modifiable, and revocable at any time.
  2. User controls must produce meaningful system change.
  3. The scope of consent must be clearly defined.
  4. Users must be able to revoke consent without harm or friction.
  5. Automated processes must remain subject to user interruption.
  6. Control mechanisms must scale with consequence severity.
  7. Consequential actions must require clear user acknowledgment.
  8. Consent must not be broadened without renewed permission.
  9. System behavior must consistently reflect granted permissions.

Executive brief

The system must preserve ongoing user control and earn trust through behavior.

Core questions Consent & Control

“Do users retain meaningful control? Does the system continuously respect it?”

“Can users grant, withdraw, and trust control at all times?”

Focus areas

Temporal-first

“Can users change their mind without penalty?”

“Does consent remain valid when context changes?”

Scope-aware

“What exactly have users agreed to? Where does it apply?”

“Does control align with consequence?”

Failure-aware

“What happens if control is unclear or contested?”

“Does the system default to restraint when uncertain?”

AI-aware

“Does automation remain subordinate to consent?”

“Is inferred intent treated as permission or authority?”

UX directives Consent & Control

Directive71/01

Design consent as a continuous capability.

Allow users to review, modify, and revoke consent at any time.

Directive71/02

Ensure user controls produce actual system change.

Do not offer settings that lack meaningful impact.

Directive71/03

Make the scope of control explicit.

Define clearly what actions or data are governed by consent.

Directive71/04

Enable simple and penalty-free withdrawal.

Ensure users can revoke participation without harm.

Directive71/05

Keep automated processes interruptible.

Preserve user authority over automated actions.

Directive71/06

Scale control mechanisms with risk levels.

Increase oversight and safeguards for high-consequence actions.

Directive71/07

Do not allow implicit or overreaching defaults.

Require explicit user acknowledgment for consequential actions.

Directive71/08

Preserve consent integrity across updates.

Do not broaden authority without renewed permission.

Directive71/09

Enforce consent consistently in system behavior.

Ensure actions align with stated permissions at all times.

Executive summary

  • Consent & Control is continuous user authority, not one-time permission.
  • It ensures users can understand, modify, and revoke system power at any time.
  • The system must make the scope and consequence of consent explicit and enforceable.
  • Controls must produce real behavioral change and remain interruptible for automated processes.
  • Oversight must scale with risk, and authority must never expand without renewed permission.
  • Consent & Control succeeds when system behavior consistently aligns with user intent and granted authority.

Success indicators

  • Users can clearly see what they are agreeing to.
  • Users can review and change permissions at any time.
  • System controls produce real and immediate changes.
  • Users can withdraw consent without penalty.
  • Automated actions remain interruptible and under user control.

One-line summary

Before users can trust a system, they must retain meaningful control over what it does on their behalf.