Skip to main content
sociable systems.
Episode 215 · 2026-08-04

The Permission Surface

Every unofficial workaround marks the exact coordinates where the permission architecture stopped matching the work. The map the Exit arc diagnosed, read as design evidence rather than misconduct.

Cover art for episode 215: The Permission Surface
Leash ArcShadow AIPermission Architecture
Episode 215: The Permission Surface

They gave me a key to the building And the building was mostly hall The rooms where the choosing happens Have no handle on them at all

The Door at the Desk left something on the table and then walked past it. Every unofficial workaround an employee builds marks the exact coordinates where the permission architecture stopped matching the work, generated for free by the person best placed to know, and an organisation that punishes the workaround converts its own best diagnostic into a secret.

Fine. Suppose an organisation declined to do that. Suppose it collected the bridges instead of prosecuting them, and laid them out on a table.

What is it looking at?

Not a list of infractions. A map. And the map has a shape that almost nobody has drawn deliberately, which is today's subject.


The binary that hides everything

Ask whether a team has AI and you will get a yes or a no, and both answers are close to information-free.

Work is not a single object with a tool attached to it. It is a sequence of moments at which uncertainty gets resolved: what is this, what does the evidence support, what should happen, who decides, what happens next, what does anybody rely on afterwards. A system can be present at some of those moments and absent from all the others, and the difference between an organisation where intelligence reaches the resolving moment and one where it reaches only the writing-up is invisible to every metric currently in use.

The permission surface is the actual operating envelope around a workflow, stage by stage. It has eight questions in it, and they are worth asking in this order because the later ones are the ones nobody thinks to ask.

  1. What may the system see?
  2. What may it retain, and for how long?
  3. What may it infer across records?
  4. What may it challenge in the frame it was handed?
  5. Which tools may it use?
  6. What may it change or advance?
  7. What may a practitioner rely on afterwards, and say so on the record?
  8. Who may widen or narrow any of the above?

Run those against each stage of a real workflow and you get a topology instead of a yes. Some stages come back fully open. Some come back with a system that may read but not remember, or remember but not act, or act but not be relied upon, which is a particularly common and particularly corrosive combination.

The eighth question is the one that decides whether the other seven are governance or wallpaper. If nobody can widen the envelope, the envelope was never a decision. It was a default that hardened.


Decision distance

Here is the measure this desk finds most useful in practice, and it takes about twenty minutes to produce for any workflow you actually understand.

Count what stands between the system's output and the moment somebody commits. Every manual copy. Every re-keying into a system that could not receive it directly. Every approval that exists only because provenance was lost in transit. Every context reset where a person reconstructs, from memory, the situation the system was not permitted to hold.

Call it decision distance. It is not a proxy for risk and a long distance is sometimes exactly right, because there are decisions that should have four human hands on them and a night's sleep in the middle. The reason to measure it is that it is currently unmeasured, and an unmeasured quantity accumulates without anybody choosing it.

The characteristic finding is a workflow with an AI-assisted drafting step and a decision distance of six, where the drafting step is reported as the deployment and the six steps are reported as diligence. Meanwhile the four hours of reconstruction are reported as nothing at all, because there is no field for them.

The model was available everywhere the decision was not.


Permission is task-shaped, which is why the blanket is the problem

The same memory can be entirely legitimate for one purpose and extractive for another. Retaining what a client decided about a technical standard so nobody has to re-litigate it in March is continuity. Retaining what an employee disclosed about their circumstances during a grievance conversation is surveillance with a helpful interface. These are not near each other. They are the same technical capability pointed at two different relationships.

The same tool action can be trivially reversible in one workflow and irreversible in another. Writing to a draft register is a Tuesday. Writing to a system of record that feeds a payment run is a different category of morning.

Blanket permissions cannot express any of this, which is why they always resolve downward. If one purpose in the estate would be harmed by memory, memory is off for everything. The safest single setting becomes the setting, and the safest single setting is chosen by whichever workflow carries the most alarming hypothetical rather than by anything about the workflow in front of you.

This is preemptive incapacity in its most respectable form. It is not sloppy. It is what happens when the only available control has one switch and the switch has to cover everybody.


What the metrics are actually counting

Adoption dashboards count seats issued, licences activated, prompts run, and hours claimed as saved. Every one of those numbers is generated inside the sanctioned tool by people who stayed inside it.

Which is the measurement problem from Sunday's week wearing a corporate lanyard. A voice institution measures what arrives inside it and is structurally blind to the response that most reliably indicates failure, because nobody files a complaint on the way out. An AI programme measures what happens in the approved window and is structurally blind to the work that left.

MIT's NANDA report supplies the scale of the gap in the same document that produced the famous failure figure. Alongside pilots delivering no measurable return, it found the overwhelming majority of employees using personal language models for work anyway. Set those two findings beside each other and the interesting reading is not that the technology disappointed. It is that the official programme and the actual practice were running in the same buildings at the same time, and only one of them was on the slide.

Netskope's threat reporting comes at the same phenomenon from the security side and finds generative-AI-linked data policy violations rising sharply year on year, which is the identical behaviour recorded by the only instrument that can see it, and recorded as a breach rather than as a specification error. Both readings are correct. Only one of them can be acted on by anybody other than the compliance team.

So the dashboard improves throughout the period in which the organisation's actual thinking migrates to systems it cannot observe. Nobody is lying. The instrument is measuring the part that stayed.


Permission debt

The bridges accumulate, and what accumulates has the structure of a debt.

Permission debt is the unofficial human work that piles up when formal permissions stay narrower than the task. Pasted context. Shadow notes in a personal file. The same situational briefing retyped into a fresh session every Monday because retention was switched off in 2025 by somebody who has since left. The undocumented re-prompting that eventually produces the answer the person already suspected. A parallel record of what was actually decided, kept because the sanctioned system cannot hold it.

Like other debts it is serviced continuously in small payments, which is why it never appears as a line item. Nobody is ever handed an invoice for four hours. They are handed four hours.

And it compounds in a direction that ought to worry a risk function more than it does. Every hour of it is work performed outside the audit trail, on an evidentiary basis nobody can reconstruct, by a person whose memory is now load-bearing. The organisation reduced its documented risk and increased its undocumented risk, and only one of those movements is in a report.


Who is on the other side of the door

Now the part that makes this distributional rather than merely inefficient, because Friday ran this filter and it deserves to be run again against the map rather than against the workaround.

Look at where the wide permissions actually sit. In most organisations of any size, the integrated deployment with real connectors and real memory goes to the function that could articulate a business case, survive a security review, and find a sponsor at the right level. That is usually a technical team, a strategy function, or whichever unit the executive most recently visited.

Everyone else receives a chat window and an adoption target.

The Thirteenth Floor asked who receives intelligence as usable infrastructure and who receives the lagging imitation of it, and put the question at the scale of countries. The same architecture reproduces inside one company, drawn by nobody, with the same result: capability compounds where it was already concentrated, and the people whose judgement the institution most needs to improve are the ones absorbing the gaps by hand.

Nobody designed that. It fell out of a procurement sequence and a set of sponsor relationships. Which is the arc's recurring finding in yet another costume, since a structure nobody chose is exactly the structure nobody will defend, and a structure nobody will defend is one that persists indefinitely.


What the map is for

The map does not tell you to open anything. That is Friday's episode and it will not be rushed.

What the map does is convert an argument that currently happens as a mood into an argument that can happen as a decision. At present, somebody says the tool is not much use and somebody else says the tool is performing to expectations, and both of them are describing the same eight-question envelope from different ends without either of them having seen it written down.

Put the envelope on one page, stage by stage, and the conversation changes character. The question stops being whether AI works here. It becomes whether the envelope around stage four is the envelope this organisation intends, who owns it, when it was last examined, and what it would take to change it.

A sketch of what that page looks like for two stages of the grievance workflow from Monday:

Evidence Memory Inference Challenge Action Reliance Expansion authority
Intake Paraphrase only None None Not permitted Summarise None Operations
Escalation review Full file, cross-case Session only By hand in the room Framed as "areas for alignment" None Reviewer signs, no system reliance Nobody named

Read down the Reliance column and the picture becomes clear. The system is present everywhere the decision is not, and the one stage where a person relies on it is the stage where it has been stripped of everything required to be relied upon.

That last question is the one that flushes out whether the institution has governance or has a moat.


Tomorrow the arc leaves the technical permissions entirely, because there is a second set that no policy document contains and no map records. Every organisation also teaches its systems which findings the building can tolerate, and it does this without writing anything down, which makes it the most effective access control in the estate.

The envelope was never decided. It was inherited, and then defended by people who had forgotten it was a choice.


Companions


These notes come out of Sociable Systems, a practice that reads AI-shaped documents the way a hostile reviewer will, before a lender or a court finds the gap. The argument has an operational form: the Interim Protocol sets out four rules for AI use in environmental and social deliverables, covering disclosure at touch-point grain, evidence custody, the phrases no automated screening may settle, and a hostile read before anything ships. Free, and written to be cited or retired once institutional guidance arrives.