DP2 - Participant Agency & Empowerment
| ID: | ML-Draft-009 |
| Title: | DP2 - Participant Agency & Empowerment |
| Status: | approved |
| Authors: | The Meta-Layer Initiative |
| Date: | 2026-08-04 |
| Workgroup: | dp2-participant-agency |
| Revision: | 01 |
| Pages: | 11 |
| Words: | 5235 |
This draft defines participant agency as a system property, not an interface illusion. It argues that meaningful empowerment requires participants to observe, redirect, and withdraw from the forces shaping their digital experience—across data flows, automation, visibility, and governance. DP2 introduces a model of agency grounded in capability, legibility, and recourse, supported by enforceable controls over delegation, consent, and defaults. It reframes presence as something participants actively shape and insists that agency must persist across systems, not collapse at boundaries. Without these conditions, “control” becomes performative—what the draft bluntly treats as agency theater.
Power to the Participant — the Meta-Layer puts participants, not platforms, in control of how they show up, interact, and shape their online experience.
This ML-Draft articulates Desirable Property 2 (DP2) as the Meta-Layer's commitment that participants can meaningfully steer their digital lives. Beyond authentication (DP1) and governance (DP3), DP2 establishes that people and accountable agents hold real, usable power over presence, data flows, automation, and the conditions under which they are seen, acted upon, and counted.
DP2 responds to recurring failures of the contemporary Web:
This draft guides implementation, governance design, and future ML-RFC development. It is exploratory scaffolding, not a finalized specification.
Why "control" without capability fails.
For decades, platforms have described participants as "in control" while reserving decisive power for operators, opaque ranking systems, and unbounded automation. The result is not merely dissatisfaction; it is predictable harm: manipulation, lock-in, surveillance-by-default, and governance that responds to scale by narrowing what ordinary people can do or understand.
DP2 begins from a different premise: agency is not a feeling; it is a property of systems. A Meta-Layer earns the label human-first only if participants can observe, redirect, and withdraw from the forces that shape their experience—within the same zones where accountability (DP1) is enforced.
Authorization answers what a token allows. Agency answers whether a participant can shape outcomes: defaults, reach, automation, data use, and the rules that allocate visibility and risk.
Systems that conflate "logged in" with "empowered" routinely:
DP2 separates authentication and authorization (DP1) from participant-directed configuration of the lived interface.
Empowerment is capability + legibility + recourse:
A system lacking any one of these is not empowering, regardless of interface polish.
Agency fails in patterned ways. The failure modes below are named throughout this draft as consequences of specific mechanism gaps; collected here, they form the adversarial model against which a DP2 implementation should be tested. None of them requires a malicious operator. Most emerge from ordinary optimization pressure, interface convenience, or the accumulation of integrations over time.
Interfaces expose settings that do not alter execution. The participant experiences choice; the system behaves identically.
Example: A "limit data use for personalization" toggle changes a display preference but not the ranking pipeline that consumes the same signals.
Why this matters: Simulated control is worse than absent control, because it suppresses the demand for real control.
Agents act beyond the scope they were granted, either by accumulating permissions incrementally or by interpreting a mandate expansively.
Example: An assistant granted read access to a calendar begins composing and sending replies on the participant's behalf after a capability update.
Why this matters: Scope that is not continuously enforced is not scope; it is a suggestion.
Permissions persist beyond the participant's awareness, becoming "zombie consent" that no one remembers granting and no interface surfaces.
Example: A third-party integration authorized years earlier retains ongoing access with no expiry, review prompt, or visible record.
Why this matters: Consent that cannot be recalled cannot be revoked in any meaningful sense.
Defaults, flow design, and asymmetric friction steer participants toward choices that disadvantage them.
Example: Signup completes in one tap; cancellation requires locating a buried page, confirming twice, and waiting for an email.
Why this matters: Where entry and exit have unequal friction, the system has taken a position against the participant.
Agent activity exceeds human capacity to observe, intervene, or revoke, nullifying agency without ever formally removing it.
Example: Delegated agents transact hundreds of times per hour; the participant's kill switch works, but only after the consequential actions have already settled.
Why this matters: Oversight that cannot keep pace with execution is not oversight.
Leaving is technically permitted but practically infeasible, or the exported artifact is unusable elsewhere.
Example: An archive arrives containing content but no thread structure, permissions history, or stable identifiers.
Why this matters: Exit is the backstop for every other agency guarantee. When it fails, all remaining controls are granted at the operator's discretion.
Portability or integration is advertised, but core agency properties are silently lost in transit.
Example: A migration preserves posts but drops delegation states, so agents authorized in the source system silently gain or lose authority in the destination.
Why this matters: Undisclosed degradation is indistinguishable from misrepresentation.
Participant choices do not persist across systems, or the same permission is interpreted differently in a new context.
Example: A "no automated action without confirmation" preference is honored in one tool and treated as advisory by a downstream integration.
Why this matters: Agency that stops at a system boundary is agency the participant cannot rely on.
Participants cannot reconstruct what was done on their behalf, when, or under what authority.
Example: An automated decision changed a participant's visibility, but no log, summary, or attribution is available to review or contest.
Why this matters: Without auditability there is no recourse, and without recourse there is no agency.
Community-level mechanisms either concentrate power in a small group or suppress legitimate individual choices without pathways for challenge.
Example: A stewardship role accumulates permanent authority; or a zone-level setting silently overrides members' individual privacy configurations.
Why this matters: Collective agency must enhance individual agency, not substitute for it.
Agency is the ability to change outcomes, not merely configure preferences. Systems that do not preserve participant intent across automation, delegation, and scale do not provide agency.
Participant agency in the Meta-Layer is the combination of meaningful defaults, legible automation, durable delegation controls, and practical exit—enacted at the interface where people actually live.
Implications:
DP2 is enacted through mechanism families that together convert stated control into enforceable control. Each addresses a distinct point at which agency is typically lost.
The structural condition uniting these is enforceability under movement and scale. A control that holds in a single interface but fails on delegation, integration, or migration is not an agency mechanism; it is a display. DP2 therefore requires that every control either persist across a boundary or signal, at the boundary, that it no longer holds.
Three tensions are inherent to this design and are addressed rather than resolved: usability against configurability, automation against control, and safety against paternalism. These are treated first, because every mechanism that follows is a position taken within them.
Agency introduces configuration surfaces that can overwhelm. Hiding them removes control. DP2 requires graduated disclosure: simple defaults that are safe, with deeper controls accessible without specialized expertise.
Automation reduces effort but can displace agency. Participants must be able to answer:
DP2 requires visible delegation scopes, renewal, and revocation aligned with accountable binding (DP1).
Even fair rules can reproduce inequality when attention is the currency. DP2 does not promise equal outcomes; it guarantees equal access to the levers that govern one's participation and visibility within a zone, and transparent disclosure when algorithmic allocation is in play (touchpoint DP14).
Safety work can slide into infantilizing participants. DP2 pairs with DP1 to require that constraints be proportionate, explainable, and contestable, with pathways for competent self-determination inside high-trust zones.
DP2 treats presence as something participants sculpt, not merely a profile object.
Participants may present differently across zones (DP1). Agency requires per-zone controls for visibility, linkage, and discoverability so pseudonymous participation is not undermined by accidental correlation.
When systems can amplify (boost, recommend, cross-post), amplification settings are agency-bearing surfaces: who may amplify me, under what proofs, with what caps? This is where DP2 meets DP1's asymmetric constraints for AI scale.
DP2 assigns normative weight to default selection: the burden of proof lies on whoever proposes a default that increases extraction, surveillance, or irreversible commitment.
Strategic friction (confirmations, cooling-off periods for irreversible acts) protects agency when stakes are high. DP2 distinguishes protective friction from hostile friction designed to prevent exit or understanding.
Advanced controls may be layered, but never removed from accountability: search, assistive onboarding, and machine-readable policy summaries are part of agency infrastructure.
Beyond interface controls and defaults, DP2 requires a coherent agency system layer that persists across environments, interactions, and time. This layer ensures that participant intent, consent, and control remain enforceable under scale, automation, and interoperability.
Agency is not simply the presence of controls. It is the ability to reliably change outcomes across systems without loss of intent, visibility, or recourse.
Participant choices must persist across tools, zones, and integrations.
This requires:
A failure mode is agency fragmentation, where participant control is lost when moving across systems.
Delegation must remain bounded, legible, and enforceable.
All delegated authority must be:
Systems must prevent delegated agents from expanding scope beyond granted authority.
A failure mode is delegation drift, where agents act beyond intended scope without detection.
Consent must persist long enough to be meaningful, but remain revocable at all times.
This requires:
A failure mode is consent decay, where participants lose track of what they have authorized.
Defaults must not be used to extract consent or steer behavior against participant interests.
Systems must:
A failure mode is coercive configuration, where participants are nudged into decisions that undermine agency.
Agency signals do not carry identical meaning across all systems.
Systems must:
A failure mode is semantic drift, where participant intent is misapplied across systems.
Participants must be able to reconstruct what they authorized, when, and why.
This includes:
A failure mode is agency opacity, where participants cannot understand or audit system behavior.
This agency system layer ensures that participant control is not an illusion created by interface design, but a durable property that persists under real-world conditions.
Collection and use are tied to stated purposes with granular switches, not monolithic "privacy" toggles (deep coupling to DP4).
For any automated or AI-mediated actor operating with participant intent, the system exposes:
Not every action needs a click, but material actions (payments, legal commitments, public attributions, irreversible posts) require explicit human confirmation unless a community zone defines a higher-automation norm with informed opt-in.
Systems MUST remain safe under automated delegation at scale. This includes resisting coordinated agent behavior, preventing silent escalation of authority, and ensuring that human override remains effective even under high-volume automated activity.
A failure mode is automation overrun, where agent activity exceeds human capacity to observe, intervene, or revoke, effectively nullifying participant agency.
Agency must survive movement. If a participant's control disappears at boundaries, the system is coercive by design.
Exit must be feasible in human time (hours or days for standard data classes). Stalling tactics, hidden dependencies, or degrading exports constitute agency violations.
Systems MUST:
Failure modes:
Where communities fork norms or stacks (see DP1, Exit, Fork, and Kill Switches), participants retain identity continuity and portable artifacts where technically honest, avoiding punishment for disagreement.
Systems SHOULD support:
Failure mode: fork penalty, where dissent results in loss of history or access.
Interoperability claims MUST be truthful. If a system advertises portability or integration, it MUST specify:
Failure mode: interop deception, where portability is claimed but core agency properties are lost in transit.
Individuals act within communities. DP2 requires that collective mechanisms enhance, rather than erase, individual agency.
Communities MUST be able to:
Systems MUST ensure:
Failure modes:
DP2 is unusual among the Desirable Properties in that agency surfaces are not a supporting requirement but the property itself. A backend that faithfully enforces scoped delegation while exposing no way to see or change that scope has satisfied nothing. The condition DP2 imposes is therefore that the levers exist, that they are reachable without specialized expertise, and that pulling them demonstrably changes system behavior.
Participants must be able to:
Communities must be able to:
Example: A participant opens a single delegation view, sees that a shopping agent holds a spend limit expiring in nine days and a summarization agent with indefinite read access, revokes the second, and receives confirmation that the change took effect along with a log of what that agent had previously done.
Without these surfaces, the failure mode is agency by assertion, where a system's claims about participant control cannot be verified, adjusted, or contested by the participants those claims concern.
Agency is expensive to provide and profitable to withhold. Most agency failures are not the product of hostile design decisions but of ordinary optimization: the default that converts better ships, the export that no one is measured on degrades, the delegation scope that reduces friction expands.
The recurring pressures are:
Example: A system honors revocation faithfully but places the delegation view four levels deep, unlinked from any surface where agents actually act. No rule was broken; the lever was priced out of reach.
Why this matters: Power in agency systems accrues to whoever controls placement, default, and pace. DP2 treats those three as governed surfaces (DP3, DP12) precisely because they determine whether the formal guarantees are usable.
Recurring themes from public discourse (non-exhaustive) include both desires and tensions:
These signals reveal a core contradiction: participants want power without overload. DP2 addresses this through progressive disclosure, safe defaults, and auditability, rather than removing control.
DP2 assumes that agency will erode rather than break. Systems rarely remove controls; they let controls fall out of correspondence with behavior as pipelines are added, agents gain capability, and integrations multiply. The characteristic DP2 failure is a system whose settings page is accurate on the day it shipped and increasingly fictional thereafter.
Predictable degradation paths include:
These paths compound. Scope creep raises the volume of automated action, which raises the audit burden, which reduces the probability that drift is noticed at all.
DP2 therefore requires safeguards designed in advance:
Failure is expected. Silent drift is not. A DP2-aligned system is one where the gap between what the controls claim and what the system does is observable while it is still small.
Several of these couplings are load-bearing rather than thematic:
DP2 defines the conditions for agency; it does not promise universal outcomes.
DP2 does not:
DP2 also does not:
Failure mode: overreach, where DP2 is interpreted to justify unsafe or unaccountable behavior.
Minimum alignment is not a UX checklist. It is the threshold at which participant agency is real, enforceable, and resistant to coercion, drift, and automation capture.
A system that does not meet these conditions may expose controls, but it does not provide agency.
At minimum, a system claiming DP2 alignment MUST satisfy the following irreducible conditions:
Failure mode: agency theater, where interfaces imply control without changing outcomes.
Failure mode: delegation opacity, where systems act without legible authority or revocation.
Failure mode: consent bypass, where downstream systems ignore or reinterpret user intent.
Failure mode: coerced consent, where participants are steered into decisions against their interest.
Failure mode: exit obstruction, where users are technically allowed but practically unable to leave.
Failure mode: agency fragmentation, where control is lost across system boundaries.
Failure mode: agency opacity, where participants cannot understand or challenge system behavior.
These conditions define the minimum viable agency layer of the Meta-Layer.
Partial implementations that omit outcome control, delegation integrity, consent enforcement, or exit MUST NOT be considered aligned with DP2.
Further questions concern how agency is expressed, timed, and measured at the edges of a system:
Advancement from ML-Draft to ML-RFC should demonstrate that agency is not only described but operationally verified.
Key steps:
Graduation criteria SHOULD include:
DP2 asserts that participants are not merely subjects of systems, but operators within them.
When agency is real, people can:
When agency is simulated, systems accumulate hidden power: defaults decide, automation acts, and participants absorb the consequences.
DP2 is the commitment that control is not inferred, but demonstrable.
It is the difference between having settings and having a steering wheel.
DP1 asks who may act with integrity. DP2 asks whether participants hold the wheel—or only the liability.