Decisions · Buying does not move blame
When selection hides responsibility
Choosing among options is legitimate until the set contains paths that differ in authority, risk, or contested values. Then the selector made the higher decision, and nobody can see who owns it.
9 min read
Cover for Choosing a supplier does not move the blameThe dinner planner presents three weekly plans. Pick A, B, or C. All look reasonable. The household chooses B.
What the UI hid: Plan A respected the busy-Tuesday effort budget. Plan C violated the cashew check in one slot. Plan B was the only composition that used the spinach before Wednesday, but nobody showed why Tuesday mattered or that allergies were validated. Selection felt helpful. Responsibility landed on the user for failures they could not diagnose.
Selection among alternatives is legitimate and unavoidable. Cognitive work often ends in choosing among candidates, templates, strategies, or repair options. The warning label belongs here because selection is the pattern that can quietly swallow responsibility belonging above it.
Helpful context: Two questions that sort a decision, who should lead each judgment, and contestability. This page is where UX meets architecture in the Decisions track. It is also the final page in the Decisions sequence before the Mirror section.
Legitimate selection versus swallowed responsibility
The distinction is about what differs among options, not about whether pick-one UI exists.
Legitimate selection
Chooses among declared, similarly authorised alternatives: lentil traybake versus chickpea traybake, template variant A versus B, which sealed cognitive units fits this case shape.
Swallowed responsibility
Chooses outcomes that differ in risk, authority, or contested value: auto-approve versus escalate, substitute quietly versus ask, plan that passes allergy check versus one that does not.
Declaring the ceiling means writing what selection may choose among, and keeping contested values, high-consequence acts, and paths that bypass deterministic checks out of the set unless a person or higher contract authorised them. The ceiling document is an artifact that ships alongside the selection component, reviewed whenever the candidate pool changes, so that new options do not silently widen the authority the selector exercises.
The cognitive unit · Ch. 8This family needs a warning label, because it is the one that can quietly swallow responsibility belonging above it.
Both sides of the line in one product
Legitimate: RecommendMealSubstitution choosing between lentil and chickpea traybake. Alternatives carry identical authority. The household is unaffected either way on ownership grounds.
Swallowed: A selector choosing between offering a substitution and placing the grocery order. One branch spends money. A selector free to substitute quietly versus raising a change for confirmation differs in authority. Any selectable set containing a path around the deterministic cashew check lets routing override endorsed knowledge.
Presenting three complete plans without busy-day rationale, allergy validation visibility, or critique notes violates Collaboration Contract visibility and turns preferential composition into ceremonial user choice. The user "decided" among plans that differed in safety and feasibility checks they never saw.
Evaluate the choice, not the outcome
Selectors deserve evaluation on whether they picked the right capability or alternative for the terrain, not whether downstream results happened to look good. Poor selections are often rescued later in the chain. Rescue proves nothing about the selector. Evaluating the selector independently means asking whether it respected its ceiling, whether it considered the full candidate set, and whether it chose along the criteria its contract specified rather than by model preference or prompt bias.
Distinct options with different authority levels are exactly the dangerous case. Distinctness feels like a safeguard. It is not one when authority differs. Three plans that look like variety can smuggle three policy choices. When meta-agents and composing agents select capabilities from a library, the ceiling travels with them. Search may find candidates. Selection cannot silently widen a grant. Authority is granted, never inferred from fluent routing.
Ceilings, visibility, and closure
Before shipping pick-one UI, the team lists what differs among options beyond presentation: authority, risk, contested values, bypass of closed checks. If anything differs materially, selection is not the right abstraction. Splitting links or surfacing the judgment explicitly is the repair.
Attaching visible criteria (why these three, what was ruled out, which checks passed) keeps the user informed. Auto-approve versus escalate does not belong in the same selectable set unless policy explicitly authorises both and records the choice. Architecture that keeps ownership visible pairs with how decisions close. Users see closure and criteria, not outcomes alone. A plan that passed allergy validation says so. A plan marked marginal on Tuesday shows the effort grounds.
Selectors inside agent strategy
Composing agents choose tools, cognitive units, and repair paths. Each choice is selection. Strategy prompts that say "pick the best tool" without ceilings inherit swallowed responsibility at scale. Strategy consumes grants and contracts, not inventing them. Library search results are inputs to selection, not permission to act. A retrieved cognitive unit still needs applicability checks and authority fit before its output enters a user-visible set. Meta-agents that widen the set to "help" violate the same rule as UI that widens it for engagement.
What this looks like in practice
Auditing one selection surface in a product starts with asking whether the selector made a decision above its pay grade. Writing the ceiling document (what may appear in the set, what may not) and adding visibility requirements before options render rather than after user complaint closes the gap.
For invoice review, a selector that chooses between "post as-is" and "escalate to manager" is legitimate only if both paths were authorised at the same leadership level and the criteria for each are visible. A selector that chooses between "approve vendor" and "override allergy to expedite" would be absurd in a different domain. The structure is the same: authority levels match within the set.
Pick-one UI is often the last layer added before launch. That ordering guarantees swallowed responsibility. Designing ceilings before options, the same way schemas are designed before endpoints, prevents the problem. When ceilings are designed first, the candidate generation process already knows what it may not produce, and the UI layer does not carry the burden of filtering out options that should never have existed in the selectable set. Recovery when responsibility was already swallowed starts with sampling sessions where users picked among options, reconstructing what differed among options in authority and checks, then patching visibility first, splitting selectors second, and ceilings third. Visibility often restores trust fastest because users can finally see what they were accountable for.
Pairing with visible thinking
Visible thinking features show criteria users need to choose responsibly. Selection without visible thinking is engagement UI. Selection with visible thinking is architecture users can audit. Shipping them together or deferring pick-one surfaces until both exist keeps the contract intact.
That pairing closes the Decisions track on this site. The next section asks what human cognition can teach without anthropomorphising models.
Selection logs need owners
When a router picks among cognitive units, the log should name the selector, the candidates considered, and the human or policy owner accountable for that routing policy. Without that log, incident review cannot distinguish between a bad cognitive unit and a good cognitive unit selected for the wrong case, which are entirely different failure classes requiring different remediation paths.
Selection logs that name candidates considered make it possible to audit whether the router hid a judgment the team never named. Routers without logs look efficient until the first accountability review. Naming the selector owner closes the gap selection opened. That owner answers when the router chooses wrong.
What to do next
The practical starting point is auditing one selection surface in the product and asking whether the selector made a decision above its pay grade. Writing the ceiling document (what may appear in the set, what may not) and adding visibility requirements before options render completes the architectural repair.
Continue to what counts as thinking. The Decisions track ends here. The Mirror section opens with how human cognition informs architecture without anthropomorphising models.
Read next: What counts as thinking.