RSS Amplifier

Before the Meeting · Apr 8, 2026

Trustworthy by Design

0
Sign in to vote or save

Dave Bayless · Before the Meeting

Generated with Gemini

Sailors don’t trust harbors to be safe because someone stands on the dock and promises calm water. They trust harbors because the geography makes rough water structurally impossible. The breakwater makes the harbor safe.

I think about safe harbors when I think about what it takes to get honest input from people who have something to lose. Most of the approaches I encounter in facilitation, organizational design, and leadership practice attempt to elicit candor behaviorally. That is, they set ground rules (“There are no bad ideas”) and rely on a facilitator’s personal warmth. These are promises, and promises require you to trust the person making them. This is exactly the problem when the person making promises holds power over you.

Safe harbors as social architectures have a long history. Greek temples functioned as asyla, places where people facing prosecution could seek refuge. The protection afforded the persecuted didn’t stem from a priest’s personal courage. Safety was assured because violating the sanctuary meant offending the gods.

Medieval churches formalized this into the right of sanctuary. The Crown couldn’t override sanctuary without confronting the institutional authority of the Church.

Diplomatic immunity followed the same logic to resolve a coordination problem. If you killed your counterpart’s messenger, communication collapsed. Certain roles had to be structurally protected from the host’s power for the system to function.

More recently, consider the difference between a secret ballot and a show of hands. The ballot doesn’t make voters courageous. It makes courage unnecessary. No one can reward or punish your vote if no one can see it.

In the case of attorney-client privilege, the attorney isn’t just promising confidentiality. They’re legally barred from disclosure by an external system.

The pattern is remarkably stable:

  • A power asymmetry exists.

  • The vulnerable party has something the system needs, such as information.

  • Behavioral assurances from the powerful party aren’t credible.

  • A structural mechanism is introduced that constrains the powerful party’s ability to punish the vulnerable party.

The needed behavior emerged, not because people became braver, but because the environment was made safer.

The strongest safe harbors seem to share a few design principles:

  • They work by removal rather than addition. What’s absent from the space (identifying information, the ability to retaliate, the option to compel disclosure) matters more than what’s present.

  • They’re legible. Participants can understand why the space is safe without taking anyone’s word for it. A sealed ballot box explains itself.

  • They involve precommitment. The more powerful party constrains their future behavior in ways that are difficult to reverse in the moment.

Consider a pre-mortem conducted before a major product decision. In its typical form, it’s a behavioral intervention: the facilitator asks people to imagine the project has failed and speak up. But the structural version looks different. Contributions are submitted in writing before the session, stripped of names, and routed to a neutral party who synthesizes themes before anyone speaks out loud. The leader sees the synthesis, not the source. That’s removal (no attribution), legibility (participants can see exactly how they’re protected), and precommitment (the leader has agreed in advance to receive only the aggregated output). The people, setting, and agenda haven’t changed. The architecture has.

The problem is that most conversational spaces, rooms where teams are supposed to think honestly and openly about hard problems, rarely have any of these properties.

The typical behavioral approach asks participants to trust people and their promises:

  • The facilitator or leader who says, “I really want to hear what you think.”

  • The norm that says, “We challenge ideas, not people.”

These aren’t meaningless, but they’re promises, not systems. The people who most need protecting — the ones holding minority viewpoints, the ones who see a risk no one wants to name — are very likely the people with the most experience with unfulfilled promises.

It strikes me that a key question isn’t “how do we make people feel safe?” It’s “what structural conditions currently suppress honest contribution, and which of those can we remove rather than counteract with encouragement?” That’s a fundamentally different design orientation. The first asks what to add to the room. The second asks what to take away from it.

Three variables tend to determine whether a conversational space is structurally safe or merely feels that way: who can be identified, when they must respond, and where their contribution goes. Each is a lever. Pull any one of them, and you change the risk equation for the person with something to lose.

Attribution is often the threat. People frequently have the insight but are wary of attaching their name to it. Any design that decouples contribution from identity is doing structural work, but anonymity can’t always be guaranteed. For example, anonymity is probabilistic in small groups, because people can often infer who said what from context alone. No architecture fully solves this, and I’m increasingly convinced that honesty about that limitation is crucial.

Synchronous presence amplifies social pressure. Real-time conversation forces people to calculate social cost in the moment. Temporal separation between encountering a question and responding can change the calculus. It doesn’t make people braver, but it mitigates the time pressure that can trigger self-censorship in the first place.

Then there’s the question of what happens to the perspectives people share. Who sees it, in what form, and what can the recipients do with it? A conversational space becomes safer not through anonymity alone, but through control of information routing. Grand jury proceedings work this way. Intelligence briefings work this way. The recipient gains insight; the source remains protected.

If structural design is so much more credible than behavioral promises, why don’t we build conversational safe harbors more frequently?

The obvious objection is that structural anonymity can create its own problems. If no one can be identified, no one can be held accountable. Anonymous input can be bad-faith, unfalsifiable, or simply noise. Such objections are worth taking seriously. But notice that the objection applies most forcefully to open-ended anonymity, such as a suggestion box or an anonymous survey. The structural designs that work best aren't fully anonymous; they're selectively anonymous:

  • The grand jury hears testimony without revealing the witness to the accused, but the prosecutor knows who spoke.

  • The sealed-bid auction hides bids from competitors, not from the auctioneer.

The goal isn't to eliminate accountability. It's to decouple the contribution from the specific power asymmetry that suppresses it. Accountability to the system can coexist with protection from the person in the room.

One reason we don’t build safe harbors is that structural safety and the trustworthiness it creates are invisible when they work. A well-designed safe harbor produces candor that feels natural. No one walks out of a room saying, “I spoke up because the attribution chain was severed.” They just spoke up. Meanwhile, behavioral moves (e.g., the facilitator or leader who says “great question” and holds eye contact) are visible. We tend to invest in interventions we can see, while effective structural conditions go unnoticed until they fail, like good plumbing and reliable electric power.

Furthermore, structural safety requires the powerful party to constrain themselves. The sponsor, the leader, the person commissioning the conversation, has to deliberately reduce their own access to who said what, to raw input, to the ability to act on attribution. Most people in power experience this as a loss. It takes an unusual kind of discipline to understand that limiting what you’re allowed to know is how you get access to what you actually need to hear.

In addition, behavioral interventions are just easier. Writing ground rules on a whiteboard takes two minutes. Designing an information architecture that structurally prevents attribution is much harder. Organizations overwhelmingly choose the easy thing, especially when the easy thing feels like it’s working, because the silence of self-censoring participants is, by definition, inaudible.

It also seems likely that there is a professional identity problem at work. Facilitation, as a field, draws on psychology and group dynamics, which are disciplines that emphasize relational and behavioral interventions. The traditions that think structurally about trust, including law, cryptography, auction design, and institutional governance, operate in separate intellectual spheres. The person designing a team offsite and the person designing a sealed-bid auction may be solving structurally similar problems, but they’ve never read each other’s work.

It may also be true that people confuse the feeling of safety with the fact of safety. A warm, well-facilitated room feels safe. That feeling is real but unreliable: it can exist without structural protection, and structural protection can exist without the feeling. Because the feeling is more immediate, it gets our attention. The result is rooms that feel safe and aren’t, which may be worse than rooms that feel unsafe, because at least in the latter case, people’s self-censorship is calibrated to actual risk.

If sponsors resist giving up informational power and facilitators favor the behavioral toolkit they were trained to use, who actually reaches for the structural alternative? I suspect it might be people with scars:

  • The leader who held the offsite, hired the facilitator, set the ground rules, and then made a bad decision because no one told the leader what they actually needed to hear

  • The restructuring that went sideways

  • The product launch, where everyone privately knew the timeline was fiction

  • The acquisition, where the integration problems were visible to everyone except the people who approved the deal

These people have learned, at great cost, that the power to know who said what was actually the power to not hear the thing that mattered.

There may also be situations where the relational approach is pretty clearly inadequate, so no one needs persuading:

  • A new CEO inheriting a team they didn’t hire

  • A leader managing a merger in which half the room reports to someone who might be eliminated

  • A board chair who is trying to get honest input from executives whose compensation they influence

In these moments, “I really want to hear your perspective” is so plainly insufficient that the structural gap becomes self-evident.

And some contexts have regulatory or legal reasons to want structural anonymity:

  • Whistleblower-adjacent situations

  • Culture assessments after a public incident

  • Board governance reviews

In these cases, “we asked people to be honest and promised it was safe” isn’t just insufficient, it’s indefensible if something goes wrong.

The historical pattern suggests that conversational safe harbors don’t usually get adopted because people choose them proactively. They get built after a systemic failure reveals that the behavioral approach was inadequate. Secret ballots weren’t adopted because voters asked for them. They were mandated after decades of electoral corruption. Whistleblower protections weren’t adopted because organizations wanted them. They were legislated after spectacular corporate frauds.

I don’t know how to feel about this. It means the people most likely to understand the arguments for creating structure to protect unwelcome but much-needed information are those who have already paid the price for its absence. And the people most resistant are the ones who haven’t yet paid that price. Given the invisibility of the cost of self-censorship, that may well include people who are accruing the cost right now and don’t know it.

The most important design question for conversational spaces remains what it has been for a few thousand years: not what to put into the room, but what to make structurally impossible within it. The fact that this question is so rarely asked doesn’t mean it’s the wrong question. It might mean we haven’t had enough visible failures yet. Or it might mean we’ve had plenty, and just haven’t connected them to the architecture of the rooms where the thinking went wrong. That gap presents both an opportunity and a significant challenge for those of us working on the design of conversational safe harbors.

No posts

Read the original on beforethemeeting.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.