0. Plain Statement
An interface remains stable only if it is continuously auditable, revocably consented, compatibility-verified, and restoration-capable.
Plain-language version:
An interface is not legitimate just because it works, is useful, is popular, is efficient, or creates value. It remains legitimate only while affected nodes can audit it, consent to it, revoke or revise coupling, verify compatibility, and obtain repair when it causes harm.
1. Formal Definition
The Interface Legitimacy Law states that interface usefulness does not prove interface legitimacy.
An interface is any boundary-crossing structure through which systems interact. Interfaces include software interfaces, AI chat systems, APIs, contracts, dashboards, forms, policies, institutions, governance pathways, moderation systems, medical intake processes, economic platforms, social rituals, identity systems, reporting systems, surveillance channels, complaint pathways, and human-machine interaction layers.
Interfaces create coupling. They decide what passes, what is blocked, what is classified, what is remembered, what is acted on, what is ignored, what is made visible, what is hidden, and what repair paths exist.
An interface may be useful while still being illegitimate. Usefulness measures function. Legitimacy measures whether the interface preserves coherence conditions under time, pressure, coupling, consent, audit, and repair.
For an interface to remain legitimate, it must remain:
- Continuously auditable
- Revocably consented
- Compatibility-verified
- Restoration-capable
If any of these fail, interface legitimacy begins to degrade, even if the interface continues to produce value.
2. Canonical Form
Core form:
Interface legitimacy ⇔ Au_continuous + Consent_revocable + Λ_verified + R_availableExpanded canonical form:
an interface remains legitimate only while auditability, revocable consent, compatibility verification, and restoration capacity remain active through timeFailure expression:
interface usefulness ≠ interface legitimacyInstability form:
useful interface + Au↓ / consent collapse / Λ failure / R=0 ⇒ pseudo-legitimacy / H↑Related variables:
O, H, ε, ι, Au, R, BΣ, K, µᵢ, Φ, Λ, ⊗, Γ, Π, Θ, Σ, Ψ, Τ, FIWhere:
| Variable | Meaning in this law |
|---|---|
Interface | Boundary-crossing structure enabling interaction, classification, access, exchange, or representation |
Au_continuous | Interface remains inspectable over time, not merely at launch |
Consent_revocable | Affected nodes can refuse, revoke, revise, or exit interface coupling |
Λ_verified | Compatibility between interface and affected-node/system state is checked and maintained |
R_available | Repair path exists when interface causes harm, mismatch, or invalid coupling |
BΣ | Boundary integrity preserved by the interface |
K / σ | Slack / sovereignty required for meaningful consent and revocation |
⊗ | Coupling produced by the interface |
Σ | Scope and boundary conditions of interface operation |
Γ | Classification performed by or through the interface |
Π | Rules, constraints, permissions, controls, or actions routed through the interface |
FI | Feedback integrity required for interface correction |
Ψ | Affected-node and field feedback about interface effects |
Τ | Time validation of ongoing legitimacy |
µᵢ | Meaning / agent integrity affected by interface representation and classification |
Φ | Usefulness or success proxy; insufficient proof of legitimacy |
O | Coherence; the interface must preserve or improve it |
H | Hidden debt produced by illegitimate interface coupling |
ι / Ξ | Inversion when usefulness, adoption, or efficiency is treated as legitimacy |
3. Core Mechanism
The Interface Legitimacy Law unfolds whenever a system uses an interface to mediate coupling.
Legitimate interface pathway
interface is introduced
→ scope and coupling are clear
→ compatibility is verified
→ consent is valid and revocable
→ auditability remains continuous
→ feedback can correct the interface
→ repair path exists
→ legitimacy is time-validatedIllegitimate interface pathway
interface is introduced
→ usefulness rises
→ adoption grows
→ scope expands
→ auditability weakens
→ consent becomes sticky or non-revocable
→ compatibility assumptions go stale
→ repair is unavailable
→ hidden debt accumulatesThe core mechanism is:
interfaces mediate power, classification, memory, access, and repair; therefore usefulness alone cannot certify legitimacyAn interface can become more useful and less legitimate at the same time if it deepens coupling while weakening audit, consent, compatibility, or restoration.
4. When This Law Applies
This law applies whenever a system uses an interface to connect, govern, classify, represent, mediate, automate, exchange, constrain, surveil, route, filter, moderate, store, decide, contract, or repair.
It is especially important in:
- AI chat interfaces;
- AI memory systems;
- AI agents and tool use;
- platform terms and consent flows;
- APIs;
- dashboards;
- moderation systems;
- complaint pathways;
- governance portals;
- medical intake systems;
- legal forms;
- employment processes;
- surveillance systems;
- data-sharing agreements;
- identity systems;
- payment systems;
- marketplaces;
- social media systems;
- educational platforms;
- security interfaces;
- restoration processes;
- public participation systems.
The law applies strongly when:
interface adoption or usefulness is treated as legitimacy proofor when:
an interface deepens coupling while auditability, revocability, compatibility, or repair remains weakTypical domains:
| Domain | Interface Legitimacy Expression |
|---|---|
| AI systems | AI interfaces require auditability, revocable memory/agency, compatibility verification, and repair |
| Security | security controls must remain auditable, scoped, reversible, and repair-capable |
| Governance | participation interfaces must be able to alter outcomes and repair harm |
| Economy | platforms and contracts must preserve exit, audit, compatibility, and restoration |
| Medicine | care interfaces must fit patient state, consent, review, and repair conditions |
| Institutions | forms and pathways must not create unauditable burden or invalid consent |
| Media systems | recommendation and engagement interfaces must preserve meaning and feedback integrity |
| Culture | symbolic or ritual interfaces must preserve boundary, meaning, and consent |
5. When This Law Does Not Apply
This law should not be used to reject interfaces because they are imperfect.
No interface is complete. Interfaces simplify, classify, route, and constrain. A coherent interface can remain legitimate even if it has limits, provided those limits are auditable, scoped, corrigible, consented, and repairable.
This law does not imply:
- every interface must expose every internal detail;
- every user must approve every design choice;
- every error invalidates legitimacy;
- every interface must be equally compatible with all contexts;
- all friction is illegitimate;
- all constraints are coercive;
- usefulness is irrelevant.
Interface legitimacy can remain intact when:
- limitations are clear;
- scope is honest;
- audit pathways exist;
- consent can be revoked or revised;
- compatibility is tested and updated;
- errors route into repair;
- affected-node feedback can change the interface;
- hidden coupling is minimized;
- exit remains possible.
False-positive cases:
| Case | Why it is not interface illegitimacy |
|---|---|
| An API limits access but documents scope and supports revocation | Constraint is auditable and scoped |
| An AI memory interface stores only user-approved items with review/delete pathways | Consent remains revocable |
| A medical intake form is incomplete but routes complex cases to human review | Interface limits are compensated |
| A moderation interface blocks harmful material with appeal and audit | Control remains reviewable |
| A platform changes scope and requires renewed consent | Scope change is not hidden |
Important distinction:
Interfaces do not need perfection. They need legitimacy-preserving correction.
6. Diagnostic Signature
Canonical diagnostic:
Interface legitimacy ⇔ Au_continuous + Consent_revocable + Λ_verified + R_availableWarning signature:
usefulness↑
coupling depth↑
Au↓
revocation hard
compatibility assumed
R absent
H↑
⇒ interface pseudo-legitimacyCommon indicators:
| Diagnostic | Expected movement | Interpretation |
|---|---|---|
Au_continuous | stable / ↑ | Interface can be inspected over time |
Consent_revocable | present | Affected nodes can revise, refuse, delete, or exit |
Λ_verified | maintained | Compatibility remains tested, not assumed |
R_available | present | Repair exists for harm or mismatch |
BΣ | intact | Boundaries remain protected |
K / σ | sufficient | Consent and revocation are meaningful |
⊗ depth | monitored | Coupling depth remains proportional to legitimacy |
Σ | clear | Interface scope is legible |
FI | intact | Feedback can correct the interface |
Φ | not sufficient | Usefulness does not prove legitimacy |
H | ↓ / stable | Interface does not accumulate hidden debt |
ι / Ξ | low | Adoption is not mistaken for legitimacy |
Additional diagnostics:
| Diagnostic | Use |
|---|---|
| Interface Legitimacy | Primary diagnostic |
| Effective Auditability | Tests continuous inspectability |
| Revocable Consent | Tests refusal, deletion, revision, exit |
| Compatibility | Tests whether interface fits state/context |
| Restoration Capacity | Tests repair availability |
| Boundary Integrity | Tests membrane effects |
| Scope Clarity | Detects hidden expansion |
| Feedback Integrity | Determines whether interface can learn |
| Exit Permission | Tests controlled decoupling |
| Hidden Debt | Tracks interface harm and burden |
| Inversion Index | Detects usefulness-as-legitimacy |
| Coherence Trajectory | Tests interface effect on O |
7. Failure Pattern
If ignored, this law produces useful but illegitimate interfaces.
General failure pathway:
interface becomes useful
→ adoption grows
→ coupling deepens
→ usefulness is treated as legitimacy
→ auditability falls
→ consent becomes hard to revoke
→ compatibility assumptions become stale
→ repair pathways are weak
→ hidden debt accumulates
→ legitimacy shock appears laterCommon failure modes:
- Interface Illegitimacy — interface fails audit, consent, compatibility, or restoration requirements.
- Useful but Illegitimate Interface — interface creates value while violating coherence conditions.
- Auditability Collapse — affected nodes cannot inspect interface effects.
- Consent Collapse — use becomes sticky, coerced, bundled, or non-revocable.
- Compatibility Failure — interface no longer fits affected-node state or context.
- Restoration Absence — harm routes into no repair path.
- Boundary Violation — interface crosses membranes without valid scope.
- Scope Creep — interface expands beyond consented or auditable use.
- Irrevocable Coupling — exit or rollback becomes impossible.
- Silent Extraction — interface extracts data, labor, attention, agency, or trust without legibility.
- Pseudo-Legitimacy — adoption or usefulness is treated as legitimacy.
- Legitimacy Shock — interface debt becomes visible under challenge.
Compact failure signature:
usefulness↑ + legitimacy stack↓ ⇒ pseudo-legitimate interface8. Restoration Implications
Restoration requires repairing the interface legitimacy stack, not merely improving usability.
The first restoration question is not:
Is the interface useful?The first restoration question is:
Can affected nodes audit it, revoke consent, verify compatibility, and obtain repair?Restoration priorities:
- Identify the interface and coupling depth.
- Audit scope and hidden coupling.
- Restore continuous auditability.
- Restore revocable consent.
- Verify compatibility across affected contexts.
- Build repair and restoration paths.
- Restore boundary integrity.
- Restore feedback integrity.
- Reduce or decouple illegitimate interface functions.
- Time-validate legitimacy under use, stress, and change.
Relevant restoration arcs:
| Restoration Arc | Why it applies |
|---|---|
| Interface Legitimacy Restoration | Primary restoration need |
| Auditability Restoration | Interface effects must be inspectable |
| Boundary Reconstitution | Interfaces operate through membranes |
| Controlled Decoupling | Illegitimate coupling may need reduction |
| Restoration Capacity Rebuild | Harm requires repair pathways |
| Origin-Layer Repair | Interface design failure must be repaired at source |
| Temporal Validation | Legitimacy must persist over time |
| Recurrence Reduction | Interface failures must not repeat |
| Basin Supersession | Required when illegitimate interface is core basin |
Minimal restoration sequence:
identify interface
→ map ⊗ and scope
→ restore Au
→ restore revocable consent / exit
→ verify Λ
→ add R
→ repair BΣ and FI
→ reduce hidden debt
→ validate legitimacy over timeTemporal validation requirement:
Au_continuous↑
consent remains revocable
Λ verified over time
R available and used
BΣ intact
FI intact
exit possible
H↓
recurrence↓
O stable or rising
usefulness remains subordinate to legitimacy9. Design Rule
Do not treat interface usefulness as interface legitimacy.
Operational design requirements:
- Design auditability into the interface.
- Design revocation and exit before deep coupling.
- Verify compatibility before and during use.
- Include repair pathways.
- Preserve boundary integrity.
- Make scope legible.
- Detect and prevent hidden coupling.
- Preserve feedback channels from affected nodes.
- Re-consent after scope changes.
- Time-validate interface legitimacy under stress.
- Keep adoption metrics subordinate to coherence.
Avoid:
- equating adoption with legitimacy;
- equating usefulness with consent;
- bundling consent into dependency;
- making exit punitive or impossible;
- hiding scope expansion;
- creating interfaces no one can audit;
- using popularity to avoid repair;
- treating user adaptation as compatibility proof;
- treating frictionless use as coherence;
- scaling interfaces before restoration paths exist.
10. Cross-Scale Expressions
| Scale / Layer | Expression of the Law |
|---|---|
| U0 — Substrate | physical interfaces must preserve material compatibility and repair |
| U1 — Energy / capacity | interfaces must not impose unabsorbable burden |
| U2 — Boundary / interface | primary layer; interfaces are membrane structures |
| U3 — Process / execution | process interfaces route action and responsibility |
| U4 — Classification / claim | interfaces classify users, cases, permissions, and signals |
| U5 — Time / delay | legitimacy must persist after repeated use and scope change |
| U6 — Field effect | affected-node outcomes reveal interface legitimacy |
| U7 — Recurrence / memory | repeated interface harm creates basin memory |
| U8 — Environment / forcing | environmental pressure tests interface validity |
11. Examples
Example A — AI Memory Interface
Scenario:
An AI memory feature is useful because it personalizes responses, but the user cannot easily audit stored memory, revise it, delete it, understand how it affects outputs, or repair harm from misremembering.
Law expression:
memory usefulness↑ while Au↓ / revocation weak ⇒ interface illegitimacyInterpretation:
AI memory requires continuous auditability and revocable consent.
Example B — AI Agent Tool Interface
Scenario:
An AI agent can act in email, files, code, or finance. It is useful, but tool actions are hard to trace, scope is unclear, and rollback is absent.
Law expression:
tool interface ⊗ depth↑ without Au + R ⇒ H↑Interpretation:
Agent usefulness does not prove legitimate tool coupling.
Example C — Platform Consent Flow
Scenario:
A platform bundles consent into use. Refusal prevents access to essential functions, and revocation is difficult.
Law expression:
consent not revocable ⇒ interface legitimacy failureInterpretation:
Consent must remain structurally valid, not merely clicked.
Example D — Institutional Complaint Portal
Scenario:
An institution offers a complaint portal. The portal accepts complaints, but users cannot track outcomes, appeal decisions, or obtain repair.
Law expression:
complaint interface useful for intake but R=0 ⇒ pseudo-legitimacyInterpretation:
An intake interface is not legitimate if it cannot route into repair.
Example E — Medical Intake Form
Scenario:
A patient’s complex condition is forced through a narrow form. The form is efficient for the institution but incompatible with patient-state variety.
Law expression:
Λ_form ≤ 0 for complex case ⇒ interface compatibility failureInterpretation:
Administrative efficiency cannot substitute for compatibility.
Example F — Security Dashboard
Scenario:
A dashboard gives useful status indicators, but hides uncertainty, alert suppression, and unreviewed anomalies.
Law expression:
Φ_dashboard↑ while Au_field↓ ⇒ interface pseudo-legitimacyInterpretation:
Security interfaces must preserve auditability, not only legible status.
12. Relationship to Nearby Laws
| Related Law | Relationship |
|---|---|
| LAW-013 — Auditability-Debt Law | Interfaces that cannot be audited issue debt |
| LAW-015 — Suppressed Auditability Debt Law | Hidden interface behavior creates debt |
| LAW-017 — Silent Extraction Law | Illegitimate interfaces can extract invisibly |
| LAW-030 — Slack Sovereignty Law | Revocation and consent require slack |
| LAW-031 — Observability Collapse Law | Interfaces can hide causal pathways |
| LAW-039 — Identity-Binding Hard Rule | Interfaces must not bind identity from low-information signals |
| LAW-040 — Filtering Law | Filtering interfaces must attenuate without deleting trace |
| LAW-041 — Boundary Membrane Law | Interfaces are selective membranes |
| LAW-042 — Consent Structurality Law | Consent must remain boundary-state valid |
| LAW-043 — Safe Coupling Law | Interfaces create coupling and require compatibility, scope, and audit |
| LAW-044 — Coupling Gradient Law | Interface depth must match shared invariants |
| LAW-045 — Force Debt Law | Interface enforcement creates debt unless repaired |
| LAW-046 — Contract Validity Law | Contracts are interface/coupling artifacts |
| LAW-047 — Controlled Decoupling Law | Legitimate interfaces require exit paths |
| LAW-048 — Feedback Integrity Law | Interface feedback must remain corrective |
| LAW-049 — Feedback Without Slack Becomes Extraction Law | Interface feedback burden must be absorbable |
| LAW-050 — Control-Restoration Separation Law | Interface control is not restoration |
| LAW-054 — Measurement Back-Action Law | Interfaces that measure users change behavior |
| LAW-058 — Resource Gatekeeping Law | Access-gated interfaces can distort selection |
| LAW-059 — Talent Drift Law | Illegitimate participation interfaces drive talent migration |
| LAW-061 — Restoration Sequencing Law | Interface repair must be sequenced |
| LAW-064 — Restoration Debt Reduction Law | Interface restoration must reduce hidden debt |
| LAW-068 — Boundary-First Restoration Law | Boundary repair precedes interface recoupling |
| LAW-070 — Reintegration Membrane Law | Reintegration requires legitimate recoupling interface |
| LAW-088 — Empathy–Sovereignty Law | Empathic interfaces must preserve sovereignty |
| LAW-102 — Legitimacy Audit Law | Interface legitimacy must be auditable |
| LAW-109 — High-Φ Legitimacy Scaling Law | High-power interfaces require stronger legitimacy constraints |
| LAW-115 — Surveillance–Restoration Law | Observation interfaces must route into repair |
| LAW-128 — AI Representation Law | AI representation is a high-risk interface |
Aliases folded into this law:
- Interface Legitimacy Law
- Useful Interface Is Not Legitimate Interface Law
- Revocable Interface Law
- Auditable Interface Law
- Restoration-Capable Interface Law
Deduplication note:
This law should remain the root interface-legitimacy law. Boundary, consent, coupling, contract, and AI representation laws should reference it as the higher-level interface validity condition.
13. Operator Mapping
| Operator | Role in this law |
|---|---|
Γ | Classifies interface state, user state, permissions, and legitimacy |
Π | Applies interface rules, constraints, actions, filters, or access decisions |
Ξ | Represents inversion when usefulness is treated as legitimacy |
⊗ | Interface creates coupling between systems |
ℛ | Repair path required for legitimacy |
Τ | Time-validates ongoing legitimacy |
Θ | Preserves uncertainty about compatibility and interface effects |
Σ | Defines interface scope, boundary, and revocation path |
Ψ | Affected-node and field feedback reveal interface effects |
Λ | Compatibility verification required before and during interface coupling |
Coherent operator sequence:
Γ(interface state) → Σ(scope / boundary) → Λ(compatibility check) → Au(continuous audit) → consent_revocable → Π(interface action) → Ψ(feedback) → ℛ(repair) → Τ(validate legitimacy)Inverted operator sequence:
interface usefulness↑ → adoption↑ → Γ(legitimate assumed) → scope expands → Au↓ / consent sticky / Λ stale / R=0 → Ξ / ι↑ → H↑ → legitimacy shock14. Machine-Readable Summary
id: "LAW-060"
name: "Interface Legitimacy Law"
type: "law"
status: "draft"
family:
- "Cybernetic and Meta-Theory Laws"
- "Interactions, Signals, and Couplings"
summary: "An interface remains stable only if it is continuously auditable, revocably consented, compatibility-verified, and restoration-capable."
canonical_statement: "An interface remains stable only if it is continuously auditable, revocably consented, compatibility-verified, and restoration-capable."
core_form: "Interface legitimacy ⇔ Au_continuous + Consent_revocable + Λ_verified + R_available"
failure_form: "interface usefulness ≠ interface legitimacy"
instability_form: "useful interface + Au↓ / consent collapse / Λ failure / R=0 ⇒ pseudo-legitimacy / H↑"
variables:
primary:
- "Interface"
- "Au_continuous"
- "Consent_revocable"
- "Λ_verified"
- "R_available"
- "BΣ"
- "⊗"
- "Σ"
- "FI"
secondary:
- "O"
- "H"
- "ε"
- "ι"
- "K"
- "σ"
- "µᵢ"
- "Φ"
- "Γ"
- "Π"
- "Θ"
- "Ψ"
- "Τ"
diagnostics:
- "Interface Legitimacy"
- "Effective Auditability"
- "Revocable Consent"
- "Compatibility"
- "Restoration Capacity"
- "Boundary Integrity"
- "Scope Clarity"
- "Feedback Integrity"
- "Exit Permission"
- "Hidden Debt"
- "Inversion Index"
- "Coherence Trajectory"
failure_modes:
- "Interface Illegitimacy"
- "Useful but Illegitimate Interface"
- "Auditability Collapse"
- "Consent Collapse"
- "Compatibility Failure"
- "Restoration Absence"
- "Boundary Violation"
- "Scope Creep"
- "Irrevocable Coupling"
- "Silent Extraction"
- "Pseudo-Legitimacy"
- "Legitimacy Shock"
restoration_arcs:
- "Interface Legitimacy Restoration"
- "Auditability Restoration"
- "Boundary Reconstitution"
- "Controlled Decoupling"
- "Restoration Capacity Rebuild"
- "Origin-Layer Repair"
- "Temporal Validation"
- "Recurrence Reduction"
- "Basin Supersession"
related_laws:
- "LAW-013"
- "LAW-015"
- "LAW-017"
- "LAW-030"
- "LAW-031"
- "LAW-039"
- "LAW-040"
- "LAW-041"
- "LAW-042"
- "LAW-043"
- "LAW-044"
- "LAW-045"
- "LAW-046"
- "LAW-047"
- "LAW-048"
- "LAW-049"
- "LAW-050"
- "LAW-054"
- "LAW-058"
- "LAW-059"
- "LAW-061"
- "LAW-064"
- "LAW-068"
- "LAW-070"
- "LAW-088"
- "LAW-102"
- "LAW-109"
- "LAW-115"
- "LAW-128"
related_invariants:
- "INV-001"
- "INV-078"
operator_sequence:
coherent:
- "Γ interface state"
- "Σ scope / boundary"
- "Λ compatibility check"
- "Au continuous audit"
- "consent_revocable"
- "Π interface action"
- "Ψ feedback"
- "ℛ repair"
- "Τ validate legitimacy"
inverted:
- "interface usefulness↑"
- "adoption↑"
- "Γ legitimate assumed"
- "scope expands"
- "Au↓ / consent sticky / Λ stale / R=0"
- "Ξ / ι↑"
- "H↑"
- "legitimacy shock"
aliases:
- "Interface Legitimacy Law"
- "Useful Interface Is Not Legitimate Interface Law"
- "Revocable Interface Law"
- "Auditable Interface Law"
- "Restoration-Capable Interface Law"
deduplication_note: "Root interface-legitimacy law. Boundary, consent, coupling, contract, and AI representation laws should reference it as the higher-level interface validity condition."
source: "content/archive/laws/technical.md"15. Compact Card Version
LAW-060 — Interface Legitimacy Law
An interface remains stable only if it is continuously auditable, revocably consented, compatibility-verified, and restoration-capable.
Core form:
Interface legitimacy ⇔ Au_continuous + Consent_revocable + Λ_verified + R_availablePlain meaning:
An interface is not legitimate just because it works, is useful, is popular, is efficient, or creates value. It remains legitimate only while affected nodes can audit it, consent to it, revoke or revise coupling, verify compatibility, and obtain repair when it causes harm.
Failure form:
interface usefulness ≠ interface legitimacyInstability form:
useful interface + Au↓ / consent collapse / Λ failure / R=0 ⇒ pseudo-legitimacy / H↑Primary variables:
Interface, Au_continuous, Consent_revocable, Λ_verified, R_available, BΣ, ⊗, Σ, FI, O, H, ι, K, µᵢ, Φ, Γ, Π, Θ, Ψ, Τ
Diagnostic signature:
Usefulness and coupling depth rise while auditability weakens, consent becomes sticky, compatibility is assumed rather than verified, repair is unavailable, and adoption is treated as legitimacy.
Failure risk:
Interface illegitimacy, useful but illegitimate interface, auditability collapse, consent collapse, compatibility failure, restoration absence, boundary violation, scope creep, irrevocable coupling, silent extraction, pseudo-legitimacy, legitimacy shock.
Restoration priority:
Map interface coupling and scope, restore continuous auditability, make consent revocable, verify compatibility, add restoration paths, repair boundaries and feedback integrity, reduce hidden debt, and time-validate legitimacy under use, stress, and change.