Big Tech Accountability

Cluster: consent-and-repair · Human-in-the-Loop

Designing for Repair, Not Just Prevention

By Michael Polzin, Regenerative Architect. Published 2026-07-01. A working essay in the IamHITL cluster on consent and repair.

Every safety-minded loop I have watched, from classrooms to clinical intake to onboarding software, starts with the same instinct: prevent the rupture. Write a policy that stops it, a form that catches it, a filter that keeps it from reaching a person. The instinct is kind. It is also, on its own, wrong.

Rupture in a human loop, a missed cue, a misread tone, a decision that lands as harm even when it was meant as help, is not a bug in an otherwise clean process. It is a feature of contact between people whose maps of the world do not perfectly overlap. Design that treats rupture as pure failure will hide it, not prevent it. Design that expects rupture can meet it out loud, and turn it into learning.

Why prevention-only fails

Trauma-informed frameworks in education and human services have moved, over the last decade, from a stance of "eliminate all triggering material" toward a stance of "build the muscle for regulation, rupture, and repair, together." (Class E) The shift is not permission to be careless. It is an acknowledgment that a rupture-free environment is not a real environment, and a person who has never rehearsed a repair is not resilient. They are untested.

In a human-in-the-loop system, prevention-only shows up as escalating gates: more consent checkboxes, more disclaimers, more review layers. Each one is defensible in isolation. Together they produce a loop where the humans stop being in the loop and start being routed around it. The system optimizes for the absence of a formal complaint, not for the presence of a good relationship. (Class F: this is a falsifier for prevention-first design. If a system reports zero incidents and its participants report chronic disengagement, prevention has failed on its own terms.)

What repair pathways look like in the design

A repair pathway is not an apology template. It is a set of structural affordances built in before the rupture happens, so that when the rupture happens the next step is legible to everyone in the loop. Concretely, on the systems I have watched work (Class B, from configuration inspection and session notes; Class U for the generalization beyond those settings), a repair pathway tends to include four things.

A named, low-friction signal. A way to say "that landed wrong" that does not require filing a grievance, opening a ticket, or writing a paragraph. A word, a card, a single button. The friction budget for surfacing a rupture must be lower than the friction budget for absorbing it silently, or the silence wins.

A default responder, not a default investigation. The first move after a signal is a person acknowledging that the signal was received, not a process opening a case. Investigations have their place, later, when they are warranted. As the default response they teach people to route around the signal next time.

A visible repair menu. Options that both sides can point at: pause, restate, revisit next session, bring in a third person, change the shape of the interaction. When the menu is written down, choosing one of its items stops feeling like conflict escalation and starts feeling like normal use of the system.

A learning loop the participants can see. If ruptures and repairs vanish into a private log, participants have no reason to trust that surfacing them changes anything. If a modest, anonymized summary of "here is what we heard, here is what we changed" comes back to the group on a regular cadence, the loop becomes visible, and consent to keep participating gets renewed on evidence rather than on faith.

The honest limit

This is a design posture, not a therapeutic claim. Repair pathways in a loop can hold ordinary rupture with dignity. They are not a treatment for anything, and I am not making one. Where a rupture reaches beyond what the loop is built to hold, the loop's job is to know that and to hand off to people whose work that actually is. (Class C: integration between the loop and the referral pathway is where most implementations fail; the design has to include the handoff, not assume it.)

The larger point is that a loop designed only to prevent will, in practice, become a loop designed to deny. A loop designed to expect and to repair keeps its participants in the room. That is the whole game.

Keep reading in this cluster

Frame: this essay is part of the IamHITL working track. It is written in the posture that UNI, our science program, is a working hypothesis on an attainable path toward General Natural Intelligence, natural not artificial. Do not take that claim on faith. Test the build, inspect the gates, and help us find where it fails.