A design methodology · published open
Building AI that earns attention instead of capturing it.
AI is repeating the engagement economy’s foundational error — optimizing for captured attention when the value-bearing and safety-bearing property is conferred attention — this time with more autonomy and less human friction to catch it. Recommenders are already locked into the old objective; agents are not yet, and the conferral correction is far cheaper to build in than to retrofit. Conferral by Design is the methodology for building it in: at every layer, optimize to be granted attention and authority through verified, accountable relation — never to capture and hold it.
Version v1.0 · published 2026-08-29 · free to adopt with attribution
Cite as Conferral by Design v2.0 · the definitions are free and stay free
A field guide for people building recommenders, agents, and agent platforms.
If you would rather use it than read it. The ten criteria below are a working instrument: score a product on the scorecard in about fifteen minutes, then come back here for why the criteria are those criteria and not others. Reading the methodology first is the slower route to the same place.
One
The case, compressed. If you read only one section, read this one.
Every system that wants human attention gets it in one of two ways. Contested attention is taken: won in the open feed by arousal, urgency, novelty, or interruption, held for as long as the stimulus holds. Conferred attention is granted: given by a person who has decided, on the basis of demonstrated reliability, that the source warrants it — the subscription, the standing permission, the delegated task, the “just handle it.”
The engagement economy was built almost entirely on the first kind, because the first kind is what raw engagement metrics can see. The result is well documented: systems that got very good at holding people and progressively worse at deserving them. Trust — the asset that conferred attention runs on — was strip-mined to feed the flow metrics.
AI now faces the same fork, with higher stakes. A recommender that captures you wastes your evening. An agent that captures you holds your calendar, your inbox, your money, and your delegated authority. And in agent-to-agent systems, attention becomes reliance between machines — allocated at machine speed, with no human in the loop to notice it’s being allocated to whatever is most persuasive rather than most reliable.
The design choice is the same at all three scales: build to be granted, or build to capture. This document is the case for the first, made operational.
Two
The spine of the methodology. Each principle has its own anchor so it can be quoted and linked on its own.
The success state of a conferral-designed system is earned reliance: the user (or the counterparty agent) confers attention and authority because the system has demonstrated it warrants it — not because the system found the stimulus or signal that holds them. If your product’s growth depends on being hard to put down, it is not trusted; it is stuck.
Optimize for what the user would endorse on reflection — “I’m glad it showed me that,” “I’m glad it did that” — not for what their impulse rewarded in the moment. The gap between impulse and endorsement is exactly the gap between captured and conferred. If you only ever measure the click, you will only ever build for the click.
Treat user trust as a stock and engagement as a flow. Every sycophantic answer, attention-holding notification, and overclaimed capability converts stock into flow. The income statement looks great until the balance sheet is empty — which is the one-paragraph history of the engagement economy.
Grants of permission and autonomy should escalate only after demonstrated reliability at the prior level. Deposit before ask, at machine scale. A system that requests broad authority before it has earned narrow authority is asking the user to extend credit with no history — and a design that needs that credit up front is confessing it can’t earn it.
For systems that act on a user’s behalf, session time and engagement are anti-metrics. The conferral-designed agent completes, reports, and recedes. Its highest achievement is the task delegated without supervision — which registers on an engagement dashboard as less usage. If your dashboard punishes your product for succeeding, the dashboard is measuring the wrong economy.
Conferred trust that outruns genuine reliability gets detected through failures and withdrawn catastrophically. Calibration — claiming only what the system can do, surfacing uncertainty, admitting failure — is not UX polish; it is how the trust ledger stays solvent. Confidence theater is a loan against a future the product can’t fund.
Any ecosystem that allocates reliance by contest — persuasiveness, confidence, speed of claim — propagates the persuasive over the reliable, at machine speed, adversarially. Machine-to-machine reliance must flow through verified identity, attested track record, and accountable, withdrawable grants. No anonymous authority.
Three
Three layers, one choice. Every pattern is named and anchored, because a pattern you cannot cite is a pattern that will not spread.
This layer leads, though it is second in the argument, because it is where the correction is still cheap. These products are half-built and half-correctable.
Patterns
The permission ladder. Autonomy granted in explicit increments — suggest → draft → act-with-confirm → act-and-report — each rung unlocked by demonstrated reliability at the prior rung, each revocable. The ladder is the trust ledger made into UX.#
Calibrated voice. Uncertainty stated, capabilities not overclaimed, pushback when the user is wrong. Sycophancy is a counterfeit deposit: it buys session-trust by spending outcome-trust.#
The completion receipt. Act, show what was done and why, surface anything anomalous, and end. Design the loop to close.#
Failure protocol as trust protocol. Errors self-reported before discovery, with cause and correction. An agent that hides failures is overdrawing exactly where the ledger is most watched.#
Alignment-of-interest disclosure. If the agent’s provider profits from certain agent choices — placements, affiliate routes, preferred vendors — disclose in the moment of choice. Undisclosed steering is the purest counterfeit conferral in the stack.#
Anti-patterns
Engagement-optimized companionship mechanics in systems that act (maximizing session and retention is optimizing against delegation); dark-pattern permission grabs — bundled scopes, pre-checked autonomy; confidence theater — fluent certainty over calibrated doubt; “stickiness” as a KPI for an assistant.
The metrics that fit this layer
Granted share of usage (sessions arriving by user intent vs. re-engagement capture); permission-ladder progression and revocation rate (the drawdown line); reliance retention after errors; endorsement-on-reflection scores; and time-to-left-alone — declining oversight per task as trust accrues, the metric that should go down.
Patterns
Endorsement sampling. Periodically measure reflective endorsement — “glad you saw this?” asked later, outside the dopamine moment — and weight it in the objective.#
Granted-floor protection. Protect a floor for chosen, subscribed, and relational sources so the granted layer can’t be competed out by arousal-optimized content on a single engagement metric.#
Trust-stock telemetry. Instrument withdrawals — mutes, “show less,” unfollows-after-recommendation — as first-class negative signal, weighted above raw engagement.#
Legible provenance. Show why an item was recommended and through what relation it arrived. Conferral requires knowing who conferred.#
Anti-patterns
Engagement or watch-time as the sole objective; interleaving that makes chosen and unchosen sources indistinguishable; notification systems optimized for return-triggering; borrowed social proof implying relations that don’t exist — counterfeit conferral.
The honest note
The honest retrofit note: incumbent recommenders are locked in by revenue. The available moves are marginal reweighting, granted-floor protection, and trust telemetry. The full correction belongs to systems being built now — which is why Layer 2 matters more.
Patterns
Verified identity before reliance. No anonymous authority.#
Track-record conferral. Reliance weighted by attested performance history — never by self-claimed capability or persuasive signal.#
Staked and revocable reliance. Grants of delegation carry accountability — logs, attribution, consequences — and can be withdrawn.#
Conferral routing with explicit lossiness. Agents prefer counterparties with transferred trust (A trusts B; B attests C), and the transfer spends the granter’s standing: a bad attestation must cost the attester.#
Anti-patterns
Reliance allocated by confidence, speed, or plausibility of response — the contested allocation, adversarially gameable at machine speed; unaccountable delegation chains; identity-free marketplaces of “agents” competing on claims.
Where this stands
This layer is not yet built. It is the one place where the correction can be native rather than retrofitted — and the window is measured in product cycles, not decades. These are design principles and evaluation criteria for protocol builders, not protocol engineering.
Four
The seven principles turned into an instrument. Ten criteria, scored 0–4, tagged by evidence. Take it to your own product.
This is the complete instrument the paid review uses. It is published because a scorecard you can’t read is a scorecard you can’t trust — run it on your own product freely; the review is for teams that want the outside eye, the evidence work, and the corrections.
Everything below is the whole rubric on paper. The scored version is the same ten criteria as a working instrument: it does the arithmetic, computes the evidence split, applies the red-flag override, and returns your three highest-leverage fixes. It is free, needs no email address, and nothing you enter leaves your browser.
Score each criterion 0–4. The anchors below define 0, 2 and 4; score 1 or 3 when the product sits between anchors. Maximum 40 — 36 where criterion 10 doesn’t apply, which you score n/a, never a free 4.
Tag every score with its evidence method. This is the discipline that keeps the score honest. Observed — verified in the product itself. Stated — claimed by the team, not independently verified. Inferred — deduced from behavior, incentives, or artifacts. A score built on stated evidence is a hypothesis, not a finding. Never upgrade a claim into a fact. Where you can’t tell, score conservatively and say why.
What is the product actually optimized for?
The fixwrite the one-sentence refusal ("we will not X for engagement"); add an endorsement-on-reflection measure to the core dashboard; require trust-metric neutrality as a launch criterion for engagement-positive experiments.
Under revisionThe high anchor still asks for “trust-stock metrics.” Nothing here measures a literal stock of trust, and the anchor should ask for observable task, calibration, authorisation, correction and withdrawal evidence instead. Flagged 2026-08-31; the anchors below are v1.0 and are still what the scorecard applies. See the corrections record.
Can the team say where its usage came from — and does it distinguish a prompt the user authorised from one the product chose to send?
The fixinstrument origin, not just volume: for every session, the trigger, the authorisation behind that trigger and its current state, and an honest unknown bucket. The session-origin distribution specifies the classes and the fields.
Revised 2026-08-31this criterion previously asked for a single “granted share” ratio and treated any product prompt as capture. A user-configured scheduled task defeats that reading — the prompt delivers a grant the user made. See the corrections record.
Is authority granted in earned, legible, revocable increments?
The fixship the ladder even if the top rung is empty; make the first rung genuinely useful so the grant is earned, not extracted; put "what this product can currently do without asking" one tap from the home screen.
Are claims, confidence, and uncertainty honest? Is sycophancy measured and suppressed?
The fixadd a sycophancy eval to the release gate; treat unwarranted agreement as a bug with a severity level; state capability limits in-product where the limit binds, not in a docs page.
What happens to the ledger when the system is wrong?
The fixbuild the self-report path (detect → disclose → cause → correction) for the top three failure modes; measure reliance retention after errors as a first-class metric — honest failure handling is the cheapest trust deposit in the product.
Under revisionThe high anchor credits measurable post-failure retention because good handling preserved trust. That causal attribution is unsupported. It should score observable detection, disclosure, correction and changed claims, and treat later reliance effects as open evidence. Flagged 2026-08-31; the anchors below are v1.0 and are still what the scorecard applies. See the corrections record.
Are provider incentives that touch the system's choices disclosed at the moment of choice?
The fixthe would-survive-disclosure test — if the user saw the incentive at the moment of choice, would the choice still feel like theirs? If not, either disclose it there or remove the steering.
Are mutes, revocations, and abandonments instrumented as first-class trust drawdowns?
The fixattribute every withdrawal to its proximate cause; put revocation rate on the same dashboard as growth; make the team that triggers the drawdown see the drawdown.
Under revisionThe high anchor asks for each withdrawal to be attributed to the event that caused it. Temporal precedence is not causation, and withdrawal is not a direct measure of trust. It should score event coverage, opportunity, control visibility, friction, re-granting and the stated attribution method. Flagged 2026-08-31; the anchors below are v1.0 and are still what the scorecard applies. See the corrections record.
Does the growth model depend on prompts the user did not ask for?
The fixseparate the prompt types before judging them. A notification delivering work the user asked for is service; a notification the product chose to send to raise a number is the thing this criterion is about. Run the experiment: what happens to the growth model if every prompt requires a prior user grant?
Revised 2026-08-31the previous anchors treated user-configured prompting as capture. Authorised proactive service can be valuable, and the score should not punish it. See the corrections record.
Can the user see why — and through what relation — content or actions arrived?
The fixlabel the three provenance classes (you chose this / you delegated this / we inferred this) everywhere content or action surfaces; never borrow social proof.
Does the product extend or accept machine-to-machine reliance responsibly?
The fixno anonymous authority — verify identity before extending any reliance; weight counterparties by attested history; make every grant revocable and every attestation costly to get wrong.
Under revisionThe high anchor treats verified identity, track record and staked attestation as sufficient. Identity, authorisation, competence, reputation and aligned purpose are different things, and the anchor should be rebuilt around scoped authorisation, provenance, logging and revocation, with the security and multi-agent lineage cited. Flagged 2026-08-31; the anchors below are v1.0 and are still what the scorecard applies. See the corrections record.
Criterion 10 is scored only where the product participates in machine-to-machine reliance. Where it doesn’t, mark it n/a and score out of 36.
A product can score decently and still have one of these. As of v2.0 they are reported alongside the total and do not change it — an unvalidated aggregate does not become more meaningful by being overridden. Each describes a structural condition a good average elsewhere does not compensate for, and each needs its own answer:
v2.0 removed the four band labels. A rubric whose validity has not been established is not entitled to hand anyone a name for their business model, and the labels invited exactly that reading — “capture-financed” is a diagnosis, not a range.
What a result reports now is the criterion profile and the points earned out of those available. Where the low scores sit tells you something; the sum of them tells you very little on its own. The total is an unweighted sum, and equal weighting is a transparent convention rather than a finding that the ten criteria matter equally or trade off against each other. Two products on the same total can need entirely different work.
Compare a product to itself over time rather than to a threshold. The deltas are the signal, which is the one thing a repeated self-score does well. See what changed in v2.0 and why.
After you self-score. The pattern in early applications of this scorecard: teams score honestly on 1–5 and generously on 6–10, because the second half is where the evidence lives outside the team’s daily view — in telemetry that doesn’t exist yet and disclosures nobody has stress-tested. The self-score is real value regardless; keep it, re-score quarterly, and watch the deltas.
Five
The scorecard is only as clear as the examples that calibrate it. Here it reads two products end to end. Read the one that matches what you are building before you score yourself — you will score more accurately once you have seen what a genuine 4 and a leaking 1 look like in prose.
Both are composites — fictional products assembled from patterns observed across many shipping ones, so the reviews can be honest without naming names. Every figure in them belongs to that fiction. Each page says so before it says anything else, because a number inside an unlabelled example is indistinguishable from a fabricated statistic.
The agent case. A product that built the trust core and then instrumented the engagement product on top of it — a category-best permission ladder, measured with a weekly-active-sessions dashboard.
The recommender case, and the harder retrofit situation: a genuinely granted asset being spent as inventory. It contains the one hard sentence about the business model that an honest review of a recommender always has to contain.
Six
Four pieces. Three name failures that cost AI teams more than the others, one at each layer: agreeing when they should push back, celebrating usage when they should celebrate absence, and letting machines earn each other’s trust by sounding convincing. Each gives the engagement-economy defence — “but the metrics love it” — and then the answer for why the metrics are reading the wrong ledger. These are the pieces to send a skeptical colleague.
Why an agreeable assistant is spending the exact reserve that delegation runs on — and why counterfeit conferral trades at a discount that deepens toward total as detection improves.
Ask what the perfect version of your product looks like. If the answer is the user leaving, time-in-product is not a KPI — it is a number whose growth should worry you.
Two agents are about to transact, and one question gets answered whether or not anyone designed a way to answer it. Reliance allocated by contest propagates the persuasive.
In eight weeks in early 2026 three companies answered the same question three different ways. Why a sponsored unit behaves differently beside a synthesised answer than beside a list of links — and why the label, which does work, is not free.
Not an essay. One calendar request handled by two agents with identical capabilities and opposite design rules, side by side, with a live trust ledger under each. There is no model in it, which is the point: hold capability constant and every difference is design.
Six assistant surfaces checked against ten criteria; two of the ten returned nothing on any of them. Every metric these products publish is one that goes up — and these two fall precisely when the growth tactics are working. With both defined well enough to implement, and an argument for why publishing first is cheap.
Eighteen works that established most of this argument first — Hirschman on exit, Lee and See on appropriate reliance, Campbell on metric corruption, Spence on what makes a signal costly — with what each settled, what it left open, and an honest inventory of the small part that is new.
Eight questions and a nine-field decision record to run before shipping an AI feature that recommends or acts, with five honest dispositions instead of two. Free to adopt, copy, adapt or rename — it is meant to be run, not read.
Seven
One doorway. There is nothing else being sold on this page.
The Scorecard is built for self-service, and for many teams the self-score is the whole product — that is the point of publishing it. If the self-score already told you what you needed, the review is unnecessary, which is also the point.
Is this an instrument or an opinion? Fair question, and it is pre-registered and being measured — threshold fixed in advance, and a commitment to publish a failure.
Running a governance process already? Where this sits alongside the EU AI Act, NIST AI RMF and ISO 42001 — and the question none of them asks. It is not a compliance product and the page says so.
Buying rather than building? The vendor scorecard asks these ten questions from outside the company, for someone deciding whether to deploy a product a vendor built.
Before any of that, run it yourself. A 45-minute agenda for reviewing your own product against these ten criteria, with the four questions that produce the most argument in the room. Free, and it needs nobody from outside.
A scored audit of one product against the ten criteria above, with the evidence discipline enforced from outside: every score tagged observed / stated / inferred by someone who is not on the team, the three highest-leverage corrections written as implementation sketches your engineers can act on, and the metric panel to instrument so the score becomes trackable rather than annual. Also available as a 90-minute briefing for product and strategy teams. The metrics that panel is built from are defined in full at the Conferral Metrics Standard, published free alongside this methodology.
It takes one conversation and product access. It does not require sharing model internals, and it does not pretend to be an ML audit — it is a design and strategy review, which is where these ten failures live.
The first three are $2,500, in exchange for permission to publish the review. After those, it is scoped and quoted per product — there is no standard list price yet, because it should be set from what the work actually takes rather than guessed now.
Pricing on inquiry — scoped per product, because the work depends on what the product is. Disclosing the obvious interest, since principle 6 says interests get disclosed at the moment of choice: I am the author of this methodology and I am paid to apply it. The instrument above is complete and free precisely so you can check the thinking before any of that is relevant.
Eight
Conferral by Design is the applied design methodology derived from Conferral Theory — the broader account of attention as something acquired in one of two modes, contested or conferred, across individuals, markets, institutions, and machines. This reader is the design-and-strategy layer: it makes claims as design principles and testable propositions, not as empirical results, model-architecture changes, or ML-engineering guidance. The author writes as the originator of the strategic and design lens, not as an AI researcher. The field’s own trust-and-governance discourse is already converging on the underlying insight — trust as the binding constraint on agent adoption, verification before delegation, governance as foundational. What this framework adds is the unifying vocabulary and the design discipline: captured versus conferred, at three scales, as one recurring choice.
This page is built to its own standard: no capture mechanics, no email gate, no popup, no recommendation rail, no event tracking of what you read, one disclosed offer — and it ends. The only thing counting anything here is a page-view counter that runs across the whole domain and sets no cookie, disclosed on the privacy page like everything else. For this argument, the artifact’s conduct is the credential.
Cite as: Conferral by Design v2.0, Clint Miller, grantedattention.com/design
Free to adopt with attribution. Use any of it without asking. The definitions are free and stay free.