Evidence Bounded Trust Governance¶
Accept vulnerability only within an explicit, evidence-bounded reliance envelope that can expand, contract, repair, or end as behavior and conditions change.
Essence¶
Evidence-Bounded Trust Governance treats trust as a decision to accept vulnerability in relation to a specific party, behavior, domain, context, stake, and period. It does not ask whether someone is globally trustworthy. It asks what reliance is warranted by which evidence, what loss is being accepted by whom, and what boundaries, alternatives, monitoring, renewal, revocation, remedy, and exit keep that reliance legitimate.
Trust is not the absence of controls. Appropriate verification can make cooperation possible; excessive or unilateral surveillance can destroy privacy, dignity, psychological safety, and meaningful consent. The archetype therefore connects evidence grade to the smallest useful exposure, then expands or contracts reliance from relevant performance while preserving challenge and fallback.
After breach, protection and remedy come before reputation repair. Acknowledgment, restitution, causal correction, demonstrated change, and renewed consent may support gradual re-reliance, but no party is owed forgiveness or restoration of vulnerability.
Compression statement¶
Trust is neither a global trait nor the absence of controls. It is a voluntary decision to rely on another party in a specified domain despite incomplete monitoring and possible loss. This archetype identifies trustor, trustee, beneficiaries, relationship, action, stakes, alternatives, and exposure; distinguishes ability, reliability, honesty, care, alignment, and constraint evidence; calibrates a domain-specific trust tier; stages vulnerability with proportional verification and fallback; records commitments and exceptions; watches outcomes without converting the relationship into coercive surveillance; responds quickly to breach; and separates restitution, demonstrated change, renewed consent, and gradual re-reliance from demanded forgiveness or automatic restoration.
Canonical formula: trust_purpose_relationship_and_stakes + trustee_evidence_profile + trustor_exposure_capacity_and_alternatives + domain_specific_reliance_envelope + proportional_verification_and_signal_plan + commitment_accountability_and_remedy_structure + breach_containment_revocation_and_repair_path + calibration_outcome_and_drift_review -> warranted_cooperation_under_incomplete_monitoring
When to Use This Archetype¶
Use it when cooperation requires a party to rely before future behavior can be fully observed and the resulting exposure is meaningful but can be bounded. It fits team delegation, professional advice, supplier dependence, institutional services, fiduciary relationships, platform governance, and human reliance on automated systems.
Triggers include incomplete or conflicting evidence, large power asymmetry, a proposed expansion of authority, changing capability or incentives, stale reputation, concentrated dependence, a breach, or pressure to “just trust” without specifying the behavior. Use it when undertrust also creates harm through duplicated work, exclusion, delay, or denial of agency.
Do not use trust language where a hard constraint should prevent intolerable harm, where consent is impossible under coercion, or where one claim merely needs independent verification. Access control implements permissions; this archetype decides the evidence and exposure logic that may justify a bounded permission. Generic relationship-building can improve goodwill but does not substitute for a reliance envelope.
Structural Problem¶
Global labels collapse different behaviors, stakes, evidence, contexts, and power relationships. A skilled clinician may not be reliable about billing; a reliable supplier may lack surge capacity; a well-calibrated model on one population may fail after drift; a caring colleague may lack authority. Halo and stigma transfer one observation across domains.
Evidence is also asymmetric. Status, credentials, charisma, reputation, dashboards, references, and compliant behavior can be relevant while remaining incomplete, stale, adversarially produced, or shaped by unequal opportunity. Powerful trustees often define what counts as evidence and impose monitoring on weaker trustors. People with fewer alternatives bear larger exposure for the same nominal arrangement.
Without an explicit envelope, trust expands silently through delegation, scope creep, automation, convenience, and dependency. Monitoring can create a false sense of certainty while incentives change off-screen. After breach, institutions may conceal warnings to protect reputation or rush reconciliation to restore operations. The structural challenge is enabling useful reliance without blind faith, coercive control, or irreversible dependence.
Intervention Logic¶
- Frame the reliance. Name trustor, trustee, beneficiaries, affected third parties, relied-on behavior, domain, context, duration, stakes, dependencies, alternatives, monitoring limits, and decision authority.
- Separate trust dimensions. Assess ability, reliability, honesty, care, alignment, authority, incentives, conflicts, and external constraints independently. A weakness in one dimension should not contaminate or be hidden by another.
- Grade evidence. Distinguish direct representative performance, independent verification, relevant track record, corroborated reference, credible signal, self-report, proxy, absence of incidents, and rumor. Record relevance, recency, independence, coverage, manipulability, provenance, uncertainty, and contrary evidence.
- Profile exposure and power. Identify possible loss, recoverability, reversibility, dependence, bargaining power, fallback, consent quality, and who actually bears downside. Set tighter bounds where alternatives are weak or harm is concentrated.
- Create the reliance envelope. Define allowed actions, data, resources, decisions, amounts, duration, subdelegation, checkpoints, exceptions, verification, escalation, suspension, revocation, renewal, exit, and remedy.
- Begin with bounded representative exposure. Use the smallest trial that exercises the behavior and conditions relevant to the proposed tier while keeping loss recoverable. A low-risk courtesy task does not prove high-stakes judgment.
- Monitor proportionally. Select outcome signals, samples, disclosures, audits, and challenge routes matched to stakes and uncertainty. Minimize collection, restrict access, protect dignity, and monitor the arrangement as well as the trustee.
- Govern delegation and escalation. State whether reliance can be passed to agents or automated systems, what evidence transfers, which limits tighten, and when uncertainty or exceptions require a higher authority. Delegation never silently expands scope.
- Renew, contract, or revoke. Trust tiers expire. Renew from current evidence; contract on drift, missing evidence, conflicts, dependency, or changed stakes; revoke promptly on intolerable warning. Preserve safe fallback and continuity for affected parties.
- Respond to breach. Protect exposed parties, stop propagation, preserve evidence, enable independent reporting, classify the failure, investigate fairly, correct decisions, remedy harm, and decide exit or optional repair.
- Repair only through evidence and consent. Require acknowledgment, restitution, causal correction, demonstrated behavior in a bounded tier, and renewed willingness to be vulnerable. Compliance with remedy is necessary evidence, not entitlement to restoration.
- Audit calibration. Compare tiers, monitoring burdens, exceptions, outcomes, incidents, subgroup effects, dependence, and alternatives. Identify overtrust, undertrust, inequitable evidence burdens, and stale or adversarial evidence.
Use a decision vocabulary such as observe_only, limited_reliance, bounded_delegation, expanded_reliance, hold, contract, suspend, revoke, renew, and exit. Each state needs entry evidence, maximum exposure, monitoring, expiry, and transition conditions.
Key Components¶
| Component | Description |
|---|---|
| Purpose, Relationship, Domain, and Stakes Frame ↗ | prevents global trust labels. |
| Trustee Ability, Reliability, Honesty, Care, and Constraint Profile ↗ | separates dimensions and preserves evidence uncertainty. |
| Trustor Exposure, Recoverability, Power, and Alternative Profile ↗ | centers vulnerability distribution and meaningful consent. |
| Domain-Specific Trust Tier and Reliance Envelope ↗ | converts evidence into revocable permissions, limits, delegation, checkpoints, expiry, escalation, and exit. |
| Proportional Evidence, Signal, Verification, and Privacy Plan ↗ | defines evidence grades, monitoring burden, access, challenge, and retention. |
| Commitment, Exception, Accountability, and Remedy Structure ↗ | links promises and disclosures to deviations, causes, effects, ownership, correction, and remedy. |
| Breach, Containment, Revocation, and Repair Path ↗ | protects exposed parties and keeps repair optional. |
| Calibration, Outcome, Dependency, and Drift Review ↗ | detects overtrust, undertrust, spillover, stale evidence, concentrated dependence, and changed conditions. |
Common Mechanisms¶
The Domain-Specific Trust Evidence and Exposure Matrix crosses relied-on behaviors with trust dimensions, evidence grade, recency, contrary evidence, exposure, alternatives, and proposed limits. The Graduated Reliance and Bounded-Exposure Trial tests representative behavior at recoverable stakes and produces tier evidence.
The Independent Reference, Claim, and Conflict Verification triangulates credentials, authority, track record, incentives, conflicts, omissions, and source independence. The Commitment, Disclosure, Exception, and Outcome Log preserves what was promised, what changed, why, who was affected, and whether remedy closed.
The Trust-Breach Triage, Containment, and Repair Protocol protects people, preserves evidence, suspends relevant reliance, classifies failure, remedies harm, and establishes exit or optional repair gates. The Trust-Calibration and Dependency Audit compares reliance with outcomes and monitoring burden, including undertrust, overtrust, subgroup disparity, spillover, alternatives, and concentrated dependency.
- Commitment Disclosure Exception and Outcome Log
- Domain-Specific Trust Evidence and Exposure Matrix
- Graduated Reliance and Bounded-Exposure Trial
- Independent Reference Claim and Conflict Verification
- Trust-Breach Triage Containment and Repair Protocol
- Trust-Calibration and Dependency Audit
Parameter / Tuning Dimensions¶
Tune domain breadth and behavior specificity; evidence grade, relevance, recency, independence, and contrary-evidence burden; exposure amount, duration, reversibility, and third-party reach; and the representativeness of graduated trials.
Tune monitoring frequency, intrusiveness, data minimization, access, retention, transparency, and challenge. Tune delegation depth, subdelegation, automation, exception authority, checkpoint cadence, renewal period, revocation latency, continuity fallback, and escalation independence.
Tune remedy to harm and power, not institutional convenience. Tune repair gates separately from restitution, and allow permanent non-restoration. Higher stakes, weaker alternatives, adversarial evidence, rapid drift, or irreversible harm require stronger evidence and smaller exposure.
Invariants to Preserve¶
- Trust remains specific to party, behavior, domain, context, stakes, and time.
- Ability, reliability, honesty, care, alignment, authority, incentives, and constraints remain distinct.
- Evidence retains provenance, grade, relevance, recency, independence, coverage, uncertainty, and contrary findings.
- Exposure, recoverability, power, alternatives, and third-party burden remain visible.
- Permissions, delegation, limits, expiry, checkpoints, escalation, renewal, suspension, revocation, remedy, and exit are inspectable.
- Consent is meaningful; asking for evidence or declining exposure is not punished.
- Monitoring remains proportional, privacy-preserving, contestable, and psychologically safe.
- Stale, missing, or adversarial evidence cannot silently sustain a tier.
- Breach response protects affected parties before reputation or rapid reconciliation.
- Repair requires demonstrated change and renewed consent; non-restoration remains legitimate.
Target Outcomes¶
The desired state is useful cooperation proportionate to warranted confidence. Reliance should expand where relevant performance supports it, contract where evidence weakens, and stop before loss propagates. The system should reduce both exploitation from overtrust and friction, exclusion, duplicated work, or denial of agency from undertrust.
Measures include outcome calibration by behavior and tier; evidence quality and age; exception and override rate; exposure versus declared bounds; renewal and revocation latency; breach detection and containment; correction and remedy completion; monitoring burden and privacy incidents; subgroup evidence and exposure disparity; fallback readiness; dependency concentration; repair recurrence; and voluntary durability of renewed reliance.
Tradeoffs¶
Cooperation speed competes with exposure. Verification reduces uncertainty while costing privacy, autonomy, money, and relational quality. Standard tiers support consistency but can erase context; individualized judgment can reproduce favoritism. Transparency supports challenge but can expose confidential evidence. Preserving alternatives reduces dependency while sacrificing efficiency. Fast revocation protects trustors while risking unfair interruption to trustees and beneficiaries. Repair may restore valuable cooperation while reopening harm or coercing forgiveness. These tensions require explicit thresholds and appeal, not a universal trust score.
Failure Modes¶
Blind trust or authority halo expands exposure from charisma, status, credentials, affinity, or one success. Separate dimensions and domains. Indiscriminate distrust imposes maximal verification despite strong evidence, causing exclusion and defensive cost; audit undertrust as well as overtrust.
Stale-evidence persistence renews a tier from old credentials or historical reputation after role, capability, incentive, or context changes. Attach expiry and current representative evidence. Adversarial evidence theater uses curated metrics, friendly references, compliant demonstrations, or absence of reports to manufacture confidence. Triangulate provenance, manipulability, blind spots, and contrary cases.
Domain spillover transfers success in one behavior into unrelated authority. Delegation creep lets a trustee pass access or decisions to agents whose evidence was never reviewed. Enforce scope and subdelegation rules. Surveillance substitution treats more monitoring as trustworthiness while burdening weaker parties; require proportionality and challenge.
Dependency capture makes exit nominal because alternatives decay. Track concentration and preserve fallback. Breach concealment suppresses warnings to protect reputation. Use independent reporting and remedy duties. Revocation paralysis delays contraction during investigation; allow protective temporary suspension. Coerced repair treats apology, restitution, or compliance as consent to renewed exposure; keep repair voluntary and staged.
Recovery first protects exposed parties and continuity beneficiaries, stops propagation, preserves evidence, and creates a safe reporting channel. It then classifies capability error, honest bounded mistake, negligence, concealment, opportunism, or malicious betrayal; corrects affected decisions; provides remedy; recalibrates related but not unrelated domains; investigates governance and monitoring failure; and either exits or starts a new bounded repair trial with independent review.
Neighbor Distinctions¶
Credible Signaling creates hard-to-fake evidence about hidden quality; this archetype decides how that evidence justifies bounded reliance. Independent Verification Oversight checks claims; this parent integrates verification with exposure, consent, monitoring, renewal, breach, and exit.
Iterative Reciprocity and Repeated Interaction governs cooperation and defection across exchanges; trust governance also applies to asymmetric professional, institutional, and technical reliance without balanced reciprocity. Social Capital Activation mobilizes existing relational resources; it does not create an evidence-expiry and revocation lifecycle.
Proxy Mediation delegates through an intermediary and defines authority boundaries; evidence-bounded trust determines whether, where, and for how long reliance on the proxy is warranted. Access control enforces permissions but does not determine the normative evidence, vulnerability, equity, renewal, and repair logic behind them. Generic trust-building activities can create rapport and candor but do not substitute for a bounded reliance envelope.
Cross-Domain Examples¶
For a new team lead, the envelope grants bounded commitment authority, requires disclosure of uncertainty and conflicts, samples outcomes, and expands only after representative delivery. Questions are protected from retaliation.
For a financial adviser, credentials are weak evidence for product-specific alignment. Conflict verification, fiduciary commitments, independent statements, transaction limits, renewal, and rapid revocation protect the client. Repair after concealed commission requires restitution and may still end the relationship.
For a public-benefit agency, residents need dependable standards, notice, challenge, correction, and remedy, not personal faith. Monitoring examines agency promises and subgroup outcomes without demanding invasive claimant surveillance.
For a critical supplier, reliability evidence is graded by volume and stress conditions. Exposure is staged, sub-suppliers disclosed, alternatives preserved, and the tier contracts when capacity evidence becomes stale.
For clinical care, licensing, relevant outcomes, communication, consent, second opinions, privacy, and complaint routes support bounded professional reliance. A status halo cannot erase patient evidence or force reconciliation after harm.
For an automated triage model, reliance is task- and population-specific. Performance, uncertainty, drift, data provenance, failure modes, human review, override, incident correction, and fallback define the envelope; access controls merely implement it.
For a community partnership, historic undertrust and unequal evidence demands are audited. Small reciprocal commitments generate evidence without requiring the less powerful group to accept larger unrecoverable exposure.
Non-Examples¶
Loyalty demanded as proof of trust is coercion. Reputation or credentials alone are insufficient evidence. Total surveillance is control, not trust. A permanent blanket approval is not a revocable envelope. A one-time background check is verification only. An access-control list is implementation. A team retreat is relationship-building. “No incidents reported” is weak evidence when reporting is unsafe. Compensation does not compel forgiveness, and apology does not restore permission.
Related Abstractions¶
Abstractions this archetype builds on — directly (a source ingredient) or as a related pattern. Links follow the typed catalog namespace.
Built directly on (4)
- Information Asymmetry: Parties to an interaction hold unequal private knowledge.
- Reputation: An aggregated signal of past behaviour that shapes how others treat an agent.
- Social Capital: Value of relationships.
- Trust: Willingly accepting vulnerability to another party's future behavior under incomplete monitoring, based on positive expectations about their competence and intentions.
Also references 24 related abstractions
- Access Control: Restrict system access.
- Accountability: Responsibility for actions.
- Adverse Selection: Hidden pre-contractual types make participation under uniform terms systematically more attractive to the types worst for the uninformed side, degrading or unraveling the pool.
- Agency Problem: Misaligned incentives.
- Boundary: Defines system limits.
- Calibration: Aligning a system's output to a trusted reference by measuring deviation, adjusting to reduce it, and monitoring for drift.
- Conflict of Interest: Competing incentives.
- Consent: Voluntary agreement.
- Delegation of Authority: Assign responsibility.
- Feedback: Outputs influence inputs.
Variants¶
Narrower or domain-specific specializations that share this archetype's core structure. Recognized variants are established; candidate variants are provisional.
Interpersonal and Team Trust Calibration · domain variant · recognized
Calibrates reliance in direct working and personal relationships through relevant behavior bounded vulnerability consent and repair.
- Distinct from parent: Narrows the parent by context, emphasis, or implementation conditions.
- Typical domains: teams, partnerships, mentorship, community
- Common mechanisms: graduated reliance and bounded exposure trial, commitment disclosure exception and outcome log
Institutional and Professional Reliance Governance · governance variant · recognized
Calibrates reliance on organizations and professionals through role authority evidence oversight remedy and exit.
- Distinct from parent: Narrows the parent by context, emphasis, or implementation conditions.
- Typical domains: medicine, finance, government, supply chains
- Common mechanisms: independent reference claim and conflict verification, trust calibration and dependency audit
Technical and Automated-System Trust Calibration · implementation variant · recognized
Calibrates human reliance on technical and automated systems by task capability uncertainty limits access failure response and human fallback.
- Distinct from parent: Narrows the parent by context, emphasis, or implementation conditions.
- Typical domains: decision support, robotics, platforms, infrastructure
- Common mechanisms: domain specific trust evidence and exposure matrix, trust calibration and dependency audit
Near names: Trust Calibration, Calibrated Reliance, Trust Repair Protocol.