trustbydefault.org  /  open record  /  thoughtful technology

No gate at the front

Every system decides, before it meets you, what kind of person you probably are. Most guess badly. This one guesses well.

Systems that assume good faith first and design for it. Not naivety, and not a softer wall. A different default: let people in, then watch what actually happens, instead of making everyone prove innocence at the door to stop the few who were never going to be stopped by a door.

01 What suspicion costs the bill is paid by the wrong people

A gate charges everyone to stop a few

Suspicion feels free because its cost never lands on the person who chose it. It lands on the honest majority, in small amounts, forever. The forgotten password at the worst moment. The receipt kept for a refund that was never in doubt. The manager's signature on a purchase smaller than the time spent approving it. Each one is trivial. Together they are most of what makes dealing with institutions feel like being accused of something.

The arithmetic is rarely written down, so here it is written down.

Ledger of a check applied to everyone
The checkPaid byActually stops
Prove you are not a robot every visitor, every visit robots, for about a season
Receipt required for return the person who lost one honestly a fraction of a fraction
Approval for small spend the whole team, in waiting less than the waiting costs
Identity check to read the curious and the quiet nobody determined

A rule aimed at the rare bad actor is a rule aimed mostly at everyone else, because everyone else is who shows up. Determined people route around gates. That is the definition of determined.

02 The doors go on. try them.

This page has no locked doors, and you can check

Below are the questions a system usually asks before it lets you do anything. Push on any of them. None will ask you for anything, because a page arguing for open defaults and then gating its own contents would be making the opposite case with its hands while making this one with its mouth.

  • Assumed. If that turns out to be wrong, the cost is one bad row in a database, not one honest person turned away.
  • Yes. Reading was never the risk. Writing might be, and that is a different door with a different answer.
  • There are none. Nothing here is collected, counted, or sent anywhere. The page has no memory of you and wants none.
  • Intent is not verifiable in advance by anyone, which is why systems that claim to check it are checking something else and calling it intent.

Doors on this page: 4. Doors that open: 4.

The point is not that checks are never warranted. It is that a check should be a response to something, not a greeting. Greeting everyone with a check tells every honest arrival what you assumed about them before they said a word.

03 Where the check goes not removed. moved.

Move the check behind the action, not in front of it

Trust by default is not the absence of enforcement. It is enforcement placed after the fact, where it can be aimed at the person who actually did something, rather than before the fact, where it can only be aimed at everyone.

Two designs for the same system The gated design puts a barrier before entry, blocking many honest people and admitting a determined few who route around. The trusting design admits everyone, then applies a reversible check after the action, catching harm without taxing arrivals. GATED everyone gate honest, turned back determined, routed around TRUSTED everyone, straight through check, after undo
Same enforcement, different placement. In front, it taxes arrivals and catches the careless. Behind, it costs nothing to arrive and catches the act.

This is why the practical question is never trust or verify. It is when, and who pays for the timing. Put the check first and the honest pay continuously. Put it after and the cost falls on the rare event that deserves it.

04 How to build one the conditions that make it safe

Good faith is a default, held up by design

Assuming good faith without building for it is how you get burned once and conclude that people are the problem. The assumption is only safe when the system around it has certain properties. These are the properties.

  1. i Make harm reversible before you make entry easy. Openness is affordable exactly as far as mistakes can be undone. An edit with history is safe to open. A wire transfer is not. Build the undo, then open the door.
  2. ii Cap the blast radius, not the entrance. Let anyone in, and limit what any single arrival can affect. A ceiling on damage does the work a gate pretends to do, without charging the people who were never going to do any.
  3. iii Keep the record open in both directions. A system that watches you while hiding itself has not extended trust, it has relocated it. If actions are logged, the log should be readable by the person in it.
  4. iv Respond to evidence, never to category. Restrict the account that did the thing. The moment a restriction attaches to a group rather than an act, the default has quietly flipped back to suspicion wearing better clothes.
  5. v Make the exit as easy as the entry. Leaving with your work intact is what proves the openness was real. A door that only swings inward was never trust. It was acquisition.
  6. vi Count the losses out loud. Some abuse will get through. Say how much, publicly, next to what the gate would have cost. Trust survives contact with its own failure rate. It does not survive being quietly abandoned after one bad week.
05 It already works not a theory. a track record.

The largest things ever built this way were built this way

The argument is not hypothetical, and the examples are not small. An encyclopedia let anyone edit any page and became the most consulted reference in human history. Package registries let anyone publish. Most open source projects accept a change from a stranger who has never proved anything except that the change was good.

Every one of them absorbs abuse. Every one of them has editors, revert buttons, and revocation. That is the pattern exactly: the front is open, the back is strong. The vandalism gets reverted in minutes by people who were only there because nobody made them register first.

The systems built on suspicion are not obviously safer. They are just smaller, slower, and worse to be inside. Their failures are invisible because a person who gave up at the door leaves no record, which is the real reason the arithmetic in section one so rarely gets done.

Any system that greets you with a test has told you its answer already.

The question is only whether it was right about you, and how many people it was wrong about to be right about the few.