Explain this to me as…
This tool checks whether a consent boundary stayed clear, scoped, current, revocable, and enforceable as it moved through downstream systems.
Consent event → handoff → downstream branches
Original Consent / Boundary
Downstream Use / Revocation Event
v0.0.1 does not automatically analyze text. These fields preserve scenario context for the export report while sliders model boundary and propagation conditions.
Simulator
v0.0.1 route note: repair, revocation, quarantine, and human review override ordinary consent-active routing.
Authorization / consent side
Scope side
Propagation pressure side
Revocation propagation side
Route gates
boundary delta / downstream enforcement
Revocation Flags
Click “Test route stability ±10%” to see whether the current routes are stable, threshold-adjacent, fragile, or override-locked under small slider perturbations.
Top sensitivity drivers / flip trace
- No sensitivity run yet.
- No sensitivity run yet.
Exportable consent-boundary report
How the model works
Consent granted is not enough. Consent carried is the real test.
Revocation received is not enough. Revocation propagated is the real test.
Revocation propagates as a boundary delta, not erasure. History and audit spine remain preserved, but downstream authorization is downgraded, stopped, quarantined, or re-proofed according to the affected scope.
Where:
A_authorization = explicit authorization, informed understanding, currency, identity/authority match, and consent record availability.
B_scope = purpose clarity, recipient clarity, data/action boundary, duration clarity, and revocation-path visibility.
P_revocation_drift = downstream branch count, transfer opacity, retention friction, automation lag, and institutional/commercial incentive.
R_notice = revocation notice clarity.
C_chain = downstream chain visibility.
E_enforcement = enforcement ability and confirmation returned.
P_residue = residual copy/cache risk plus downstream drift pressure.
Route transparency / math disclosure
Why this matters:
Consent granted is not enough. Consent carried is the real test.
Revocation received is not enough. Revocation propagated is the real test.
Revocation propagates as a boundary delta, not erasure.
Show route logic / show the math
A_authorization = 0.25×Explicit Authorization + 0.20×Informed Understanding + 0.18×Current Consent + 0.20×Identity/Authority Match + 0.17×Consent Record
B_scope = 0.24×Purpose Clarity + 0.20×Recipient Clarity + 0.22×Data/Action Boundary + 0.16×Duration Clarity + 0.18×Revocation Path Visible
S_consent = A_authorization × B_scope − P_revocation_drift
P_revocation_drift = average downstream branch count, transfer opacity, retention friction, automation lag, and institutional/commercial incentive.
S_revocation = R_notice × C_chain × E_enforcement − P_residue
P_residue = residual copy/cache risk plus retention, opacity, and automation residue.
Repair debt overrides ordinary consent evaluation. Full revocation overrides active consent. Downstream quarantine overrides convenience when branches cannot be verified. Sensitive/high-stakes contexts can require human review.
Revocation does not erase the audit spine. It travels forward as a boundary delta: stop, downgrade, quarantine, re-proof, retain with limits, or repair according to affected scope.
| Preset | Consent Carry Route | Revocation Route | Consent Stability | Revocation Stability |
|---|---|---|---|---|
| Clean Bounded Consent | CONSENT_ACTIVE | REVOCATION_READY | 0.58 | 0.29 |
| Ambiguous App Permission | SCOPE_MISMATCH | NO_REVOCATION_ACTIVE | -0.44 | -0.59 |
| Patient EHR Consent Revocation | REVOKED_SCOPE | DOWNSTREAM_QUARANTINE | -0.14 | -0.47 |
| Health Data Partial Revocation | PARTIAL_REVOCATION | HUMAN_REVIEW_REQUIRED | -0.01 | -0.30 |
| Caregiver / Proxy Boundary Drift | HUMAN_REVIEW_REQUIRED | NO_REVOCATION_ACTIVE | -0.17 | -0.35 |
| AI Agent Tool Permission Drift | SCOPE_CLARIFICATION_REQUIRED | NO_REVOCATION_ACTIVE | -0.34 | -0.47 |
| Public Platform Data Reuse | RETENTION_LIMIT_REQUIRED | NO_REVOCATION_ACTIVE | -0.63 | -0.76 |
| Revocation Lost Downstream | REVOKED_SCOPE | DOWNSTREAM_QUARANTINE | -0.38 | -0.78 |
| Prior Consent Boundary Harm | REPAIR_REQUIRED | REPAIR_REQUIRED | -0.52 | -0.71 |
Route stability / sensitivity
A boundary route can be stable, fragile, threshold-adjacent, or override-locked. This patch perturbs each slider by ±10% and checks whether the recommended consent or revocation routes change. v0.0.4 also records the flip trace: which slider moved, in which direction, and which route it changed from/to.
The same route survives small pressure changes. The boundary diagnosis is not near a threshold.
A few small slider shifts change the route. The case is close enough to a boundary that review or re-proof may be prudent.
Many small slider shifts change the route. The boundary state is unstable and should not be treated as cleanly resolved.
A hard gate such as repair debt, full revocation, or partial revocation is active. Slider softness does not override the boundary gate.
Route taxonomy
Defensive boundary
This simulator maps consent-boundary degradation for review, repair, education, and defensive design. It does not provide instructions for bypassing consent, evading revocation, retaining data improperly, or exploiting downstream copies.