FORM NOT VOID, MIND NO CORE

Chapter 13: Openness, Surveillance, and the Boundaries of Privacy

2026.09.07

When institutions cannot hear their errors, people often demand more openness. This demand has solid grounds: without visible records of public decisions, those affected can hardly discover how standards changed, how resources were allocated, and at which level dissent disappeared. Yet openness can also be inverted into the continuous exposure of ordinary people. When decision-makers retain their secrets while executors and applicants are required to surrender their locations, relationships, moods, and every deviation, transparency turns from a principle of accountability into a condition of obedience. The following uses an explicitly fictional "Riverside Public Services Consortium" (hereafter the Riverside Consortium). The Consortium allocates maintenance budgets, arranges night watch duty, and provides residents with temporary subsidies. After a water pipe accident, the council requires all maintenance decisions to be made public. The technical team then proposes recording the real-time location of every person on watch, and the subsidy section further advocates publishing applicants' household income and expenditure to prove that the institution shows no favoritism. The three uses of openness share one word, yet they differ in their objects, purposes, and risks.

What this chapter draws is not a single scale of visibility applicable to all situations, but a set of relational boundaries: who observes whom, for which decision, what materials are collected, how long they are kept, who holds the authority to interpret, and what consequences errors bring. Openness should place power under observation; surveillance may instead keep the governed continuously adjusting themselves under a gaze whose boundaries they do not know; privacy protects the space in which life and judgment are formed, and must likewise accept the limits of public responsibility.

Public Justification and Continuous Surveillance

How the Consortium determines maintenance priorities, who approves budgets, and how corrections proceed after an accident — these matters affect common resources and should leave retrievable reasons and versions. The core of openness is not that everyone knows every detail, but that those who hold decision-making power cannot demand trust merely on the strength of their position. For a decision to be reviewable, it must at least state the applicable rules, the relevant materials, the location of discretion, conflicts of interest, and the avenue of remedy. With only the final figure and no process of judgment, the public still cannot know whether similar cases received similar treatment; publishing all raw materials without an account of the rules would in turn let the sheer quantity of information obscure the genuine choices of power.

Thousands of pages of logs, formally open yet lacking indexes, versions, and correspondence to decisions, remain unusable for ordinary members. An institution cannot hand the entire cost of organization to those with the least time and then, on the plea that "the materials are all there," evade its duty of explanation. At the same time, summaries must allow return to the original grounds, lest interpreters acquire a new monopoly through selective summarization. Openness therefore comprises two layers: an explanation sufficient for understanding, and grounds that can be traced when disputes arise. Both layers should be constrained by the boundaries of privacy, confidentiality, and security.

Work Records and Continuous Surveillance Are Not the Same

That the technical team records who took out a tool and when a repair was completed serves handover, accountability, and safety. Such records are bound to specific tasks, limited in fields, and put to definite use once the task is done. If a system continuously collects location, dwell time, interlocutors, and physiological states, and then feeds these signals into undisclosed performance judgments, observation has already exceeded the task. The difference does not lie merely in the quantity of data. A single field, if it links housing, income, and membership, may carry extreme consequences; a large volume of low-sensitivity logs used only for short-term equipment diagnostics poses comparatively limited risk. Judgment must consider scope, duration, expansion of use, and the coupling of consequences together.

Covert investigation may have justifiable conditions in cases of serious fraud or security risk, but it requires stricter authorization, proof of necessity, time limits, and subsequent review. Placing all daily work under invisible observation leaves members unable to distinguish task requirements from examinations of their person, and unable to correct erroneous data. Full disclosure still does not amount to voluntariness. Where a person on watch loses their sole income unless they accept being tracked, ticking the box of consent proves only that a procedure was completed. The institution must further demonstrate that the field is genuinely necessary, that no less intrusive alternative exists, and that the consequences of refusal are limited.

Surveillance Alters the Environment of Action of the Watched

Observation is not a reading of finished behavior from a standpoint outside reality. Knowing that every pause and conversation may be evaluated, members will choose actions that are easier to record and avoid negotiations that resist quantification yet remain necessary. The "efficiency pattern" the system later observes is partly an outcome the system itself has produced. This reflexivity does not prove all measurement invalid. Public schedules can reduce omissions; quality spot checks can uncover risks. The question is whether the institution acknowledges that records alter their object, and corrects this with on-site explanation, dissent, and multiple scales, rather than treating the data as a natural fact untouched by intervention.

To remain continuously online, a person on watch may no longer leave the terminal to check details in residents' homes; the technical team's response metrics improve while leaks recur. If evaluation recognizes only visible actions, members will rationally redirect their labor toward the metrics. Responsibility cannot be assigned wholly to individuals who "game the system," for the rules actively shape behavior as they distribute chances of survival. Conversely, deteriorating metrics do not necessarily prove resistance or harm. Equipment failure, changes in tasks, and shifts in recording criteria may all explain the anomaly. Surveillance data requires causal verification; deviation alone cannot automatically trigger punishment.

Privacy, Use, and Entitlement to Observe

Applying for a subsidy involves public funds, and the Consortium may verify conditions directly relevant to eligibility. An applicant cannot invoke privacy to refuse every necessary proof while demanding that the institution make high-consequence decisions unconditionally. But verifying income is not the same as acquiring a complete history of consumption, relationships, and health, still less as publishing it to all residents. Privacy does not protect an inner fortress stripped of all social relations. It limits others' introduction of a piece of information into unrelated judgments, and preserves for the person a space for trial and error, intimacy, rest, and the formation of opinion. In an environment where every exploration permanently affects eligibility, a person can hardly correct themselves.

Confidentiality is a restriction on dissemination imposed by the holder of information; privacy is the legitimate claim of the concerned subject over the boundaries of their life. When the council classifies budget discussions as confidential, this may protect negotiations or may conceal conflicts of interest; when an applicant's household information is kept confidential by the institution, this may realize privacy. The fact that both are "not public" does not entitle them to the same legitimacy. Trade secrets, investigative security, and the rights of others may all restrict openness, but such restrictions should state their object, duration, and conditions of review. Permanent and total secrecy most easily allows power to escape observation.

Data Minimization Alone Does Not Settle the Boundary Problem

Suppose the Consortium collects only a single "household reliability rating": the field appears minimal, yet it compresses a complex life into an overall evaluation. If data minimization merely counts fields, it overlooks the scope of inference and the consequences. Conversely, retaining several technical parameters to explain one maintenance accident may be more constrained than a single personality score. One should ask what proposition each field supports: can location prove presence, prove conscientious work, prove worthiness of a subsidy? The leap from a task fact to overall eligibility is a common logical expansion in surveillance systems.

Even without directly asking about relationships, an institution may infer them from shared addresses, frequency of contact, and behavioral patterns. The inference may be wrong, yet it acquires additional authority from its algorithmic form. Those inferred about should know the principal grounds of high-consequence conclusions and have the opportunity to correct them; the institution cannot let model secrecy render errors permanently beyond appeal. This requires no assumption that some technology can fully read human beings. The danger lies precisely in the union of imperfect inference with real power: the model need not understand the subject accurately; so long as it suffices to trigger supervision, delay, and exclusion, it can alter a life.

The Right to Observe Should Grow with Decision-Making Power

The council can allocate budgets, set eligibility, and decide punishments; its minutes, interests, and reasons should therefore bear stronger obligations of openness. An ordinary applicant requests only one limited service and thereby incurs no duty to display their life to all. The more a power can alter the conditions of others, the more it should accept observation directed at that power. In reality, the weak may also hold sensitive information about others, and public scrutiny may also harm executors. The principle is not fixed by identity, but matches visibility to specific authority and risk. Masking irrelevant personal information when publishing complaints does not weaken the review of institutional decisions.

Suppose the council requires all members to publish their real-time locations and pledges that managers will comply as well. The symmetry is superficial: it overlooks that managers have the authority to interpret deviations, adjust rules, and discipline others. With identical data but different institutional positions, the consequences of exposure differ. Genuine reciprocity should include the authority to interpret, the right to correct errors, and the bearing of responsibility for them — not merely that both sides are recorded. Those who control the back end of the system cannot prove equality merely by submitting their own data as well.

Security, Humiliation, and the Supervisors

A water pipe accident may indeed endanger residents, and emergency coordination needs to know whether key personnel are reachable. But "for safety" is too broad: almost any information can be imagined as useful. An institution should state the specific risk, the relation between the information and the risk, less intrusive alternatives, and when the emergency condition ends. If temporary location tracking continues to be used for performance after the accident, its initial legitimacy cannot extend automatically. A change of use amounts to a new decision and requires renewed authorization. That members consented during the emergency does not signify consent to permanent observation.

Reluctance to disclose location may stem from privacy, from duties of care, or from concern about the security of the system. If refusal itself is inscribed by the model as "suspicious," the institution forms a self-confirming loop: acceptance proves compliance, refusal proves the need for further observation. Risk judgments should be made from independent materials, not from whether one obeys the demand to be observed.

Public Humiliation Is Not Public Accountability

The Consortium projects the list of latecomers in the hall, claiming that in this way everyone can supervise. Publicizing individuals may be necessary in a few cases — for instance, a decision-maker still in office with an unresolved conflict of interest — but displaying low-level errors together with evaluations of character before everyone often merely adds punishment without improving the rules. Accountability concerns conduct, duties, consequences, and repair. Humiliation expands an event into an identity, enlists bystanders in sanction, and yet offers the labeled no reliable path of correction. The wider the publicity, the harder it is to retract an error, and the more the institution must prove that no alternative exists.

In a small community, details suffice to re-identify individuals, while anonymous statistics may erase the disparities a group persistently bears. Aggregation, masking, tiered access, or authorized disclosure should be chosen according to purpose, rather than treating "public" and "anonymous" as two buttons that are automatically correct.

Retaining accident logs for one year for equipment analysis may be reasonable; if a single lateness ten years past still affects subsidy eligibility, the record has turned from task memory into a personality dossier. Retention periods should be justified by disputes, legal liability, and the needs of repair; possible future usefulness is not an argument for indefinite retention. Deletion may also injure accountability. If the institution purges decision versions after a complaint, those affected cannot demonstrate how the rules changed. The more workable distinction is this: retain public decisions and their reasons, restrict the use of and access to sensitive personal materials; keep records under dispute under independent preservation rather than let the original decision-maker delete them unilaterally.

Who Watches the Watchers

An audit department can examine data use, yet it also concentrates more material. A new layer of supervision does not automatically bring safety. The supervisors' authority, access logs, conflicts of interest, and handling of errors must be made equally visible, and they must not simultaneously serve as advocates of the original decision. Supervision must yield real consequences: halting uses that overstep the boundary, correcting data, restoring opportunities, notifying those affected. Publishing compliance reports while changing no decisions turns transparency into institutional decoration.

The effects of continuous observation often appear as ceasing to try, ceasing to converse, or adapting in advance — lacking any single visible event. Applicants should not bear the entire cost of reconstructing the causality of a whole system. Since the institution holds both the design and the logs, it should account for use and consequence; the individual who raises a specific anomaly provides whatever materials they can obtain.

How Visibility Produces Asymmetry

The party that holds evaluation power may render daily behavior continuously visible, keep the rules vague, and then link records of deviation to basic opportunities. Members need not genuinely agree; so long as they display conformity to avoid unpredictable consequences, the institution will take this surface order for consensus. This is a severe risk derivable from the system of this book. It does not mean that surveillance necessarily succeeds, still less that it licenses the assertion that real institutions have already adopted it deliberately. Subjects develop covert cooperation, records become distorted, and executors may also resist. Establishing design intent requires concrete documents, authority, and evidence of benefit; even where intent is unclear, a structure that oversteps can still be constrained.

Understanding how visibility shapes behavior serves to identify disproportionate consequences, protect dissent, and build error correction. The text does not provide steps for selecting sensitive signals, arranging punishments, or increasing obedience. Institutional reform needs only the protective principles: restriction of use, time limits, minimum necessity, appealability, and the priority of openness for power.

If a meeting required every participant's remarks, drafts, and shifts of position to be published with attribution forever, people might voice only opinions already matured. Public reasons need to be visible; the entire process of forming opinion need not be exposed. Permitting probing, anonymous consultation, and temporary non-committal silence helps more responsible public judgment appear later. Here privacy is not withdrawal from public life but a preparatory condition of public judgment. Nor can it become a shelter for the secret manipulation of public decisions; those who hold formal power should disclose the interests and reasons bearing on their decisions.

The Consortium may publish subsidy approval rates across districts to discover allocation disparities, without immediately publishing the identity of every applicant. Aggregate data protect individuals, yet may also, because the samples are too coarse, conceal the persistent losses of a small group. The scale of disclosure should adjust to the problem: observe patterns first, let constrained reviewers examine individual cases when necessary, and never let curiosity displace the purpose of inquiry. When an individual case reveals institutional error, whether to make it public belongs to the teller; the institution cannot invoke privacy to shield itself, nor demand that individuals display trauma in the name of public education. Public reasons can be stated with irrelevant details masked.

A watcher's location data may simultaneously expose with whom they live and which places they have visited. The institution collects one person's work information, yet indirectly observes people who have entered no relation with it. The boundaries of third parties must enter the assessment of necessity; an employee's consent cannot authorize on behalf of family and friends. Relational inference may further inscribe normal mutual aid as a risk network. Frequent contact between two people can mean collaboration, intimacy, conflict, or a shared device. Converting association directly into intent is both error-prone and liable to make members avoid horizontal ties. Chapter Sixteen discusses the institutional value of horizontal ties; here it suffices to confirm that relational data should not automatically become a loyalty score.

Visibility Is Still More Asymmetric for Children, the Sick, and Those Seeking Help

Providing care requires knowing symptoms, contacts, and risks, but seeking help cannot amount to surrendering one's life as a whole to the institution. People in vulnerable conditions find it harder to refuse and are more likely to bear misclassification. Informed explanations should suit their capacity to understand; proxy authority should be limited; and the possibility of subsequent review and withdrawal should be preserved. Protective observation must sometimes precede full consent, as with necessary intervention in immediate danger. The stronger the exception, the more weighty the recording of reasons, time limits, and independent review. A single emergency authorization must not become a long-term behavioral dossier.

That a person temporarily cannot state preferences does not mean they have no privacy or that any material about them may be made public. Proxies should make minimal decisions according to concrete care needs, distinguishing information required for the person's own benefit from the institution's administrative convenience. Once capacity for expression is recovered, the person themselves should participate again.

Budget data published for oversight are later linked by commercial actors to personal profiles, generating evaluations beyond the original purpose of publication. Once information is widely copied, it can hardly be recalled by after-the-fact promises. Before publication, an institution must consider combinability rather than examining only whether a single table is anonymous. Restricting reuse may conflict with public research and journalistic investigation; no single rule eliminates the trade-off. One can keep public decisions highly transparent, adopt controlled access for sensitive individual data, and require that research conclusions not flow back into individual punishment. The value of openness should be certified by specific public purposes.

An applicant discovers that the "household reliability" judgment is wrong, yet is required to recount all their relationships in a public hearing before it can be corrected. The institution uses the appeal to repair one error while manufacturing a greater cost in privacy. Optional written, proxy, and closed-door review should be combined with publicly reasoned rulings, so that facts can be corrected without displaying a life that is irrelevant. Appeal records may likewise be labeled "uncooperative" later on. If using the channel of error correction itself lowers eligibility, the institution will draw a false satisfaction from silence. Good-faith appeals should be barred as a negative proxy indicator, while concrete handling of fraud and harassment is retained; protecting appeals must not be expanded into immunity for conduct.

Demanding that power be open is not demanding that managers have no private life. What should be public are interests, reasons, uses of authority, and public resources related to duty — not family, health, and unrelated associations. Turning oversight into a manhunt wounds individuals and diverts public discussion from institutional questions. The higher the office, the stronger certain duties of interest disclosure; yet the boundary still requires law and procedure rather than the sway of sentiment. Responsibility tracking should land on decisions and consequences, not manufacture a sense of justice through total exposure.

Centralized logs exist for safety and accountability, yet they also become a resource liable to misuse, leakage, or false association. The more that is collected, the higher the long-term costs of protection, access control, deletion, and incident notification. A single budget approval cannot underwrite unlimited maintenance; the institution must write these costs into the judgment of necessity itself. Security commitments likewise cannot be written as absolute guarantees. Every system can fail; what matters is reducing unnecessary collection, dispersing high-risk authority, logging access, and giving those affected realistic remedy after failure. Collecting everything on the plea "we will protect it" is not sufficient justification.

Transparent institutions must organize records, answer queries, and take part in reviews. If this labor falls entirely on front-line staff as an extra burden, openness may squeeze out service; if it falls entirely on applicants to search by themselves, it forms a threshold of capability. Public budgets should recognize accountability as a basic function, not a costless addendum. Nor can the public read all materials. Trusted intermediaries, sampling audits, and searchable structures are necessary, yet they acquire new powers of selection. Different intermediaries should be able to correct one another, with their methods and interests made public.

When the Consortium discovers an erroneous location record and merely changes the value in the database without restoring the subsidy and work thereby missed, correction remains at the level of information. Governance of high-consequence data must trace the chain of decisions: into which models, reports, and human judgments the error entered, and whether the related consequences can be withdrawn or compensated. Full restoration is sometimes impossible; published stigma is especially hard to recall. At minimum the institution should proactively notify recipients, publish corrections, halt further use, and let the party controlling the data and decisions bear the principal labor of repair. It cannot require individuals to prove, one by one, who has seen the error.

The Test of Limited Observation

Faced with a new demand to record or to publish, one can ask in sequence: which specific decision does it support; what articulable risk arises if it is not collected; who may access and interpret it; does it cross into new uses; how long is it retained; how are errors corrected; what does refusal lose; do the powerful bear commensurate duties of openness. These questions yield no uniform answer, yet they expose leaps in logic. One must further distinguish fact from value. That the system collects location is a fact; whether location accurately represents the performance of duty is an empirical judgment; using it to decide subsidy eligibility is an institutional choice; and whether that choice is justified is a value judgment. When the four layers are merged, technical capability masquerades as normative authorization.

If the Consortium first purchases a system that can only retain all trajectories permanently and discusses privacy afterward, many choices are already locked in by the technical structure. At the point of procurement it should specify the necessary fields, deletion capability, access logging, and data migration; vendor defaults cannot be taken for public authorization. Technical limitations may be real; the institution must still make their costs public and narrow the uses where boundaries cannot be met.

From Being Seen Back to Collective Judgment

The purpose of openness is to make the reasons for decisions over common resources verifiable and their errors corrigible; the purpose of privacy is to let people keep a space of life and judgment not occupied by irrelevant power; limited work records serve concrete responsibilities; continuous surveillance, where use and consequence are unclear, makes visibility itself a condition of eligibility. All four can coexist within one institution, and none can be characterized merely by the labels "transparent" or "secret." If the Riverside Consortium publishes budget rules and accident decisions, restricts location data to the watch shift in question, protects the applicant's irrelevant life, and lets high-consequence inferences be corrected, it can redirect observation toward power. If it leaves ordinary members indefinitely visible while the rules remain a black box, the appearance of obedience will grow ever more orderly while the institution knows ever less about its own errors.

The Burden of Visibility Is Not the Same across Groups

Publishing names, locations, or household information may be a slight inconvenience for those with stable positions and resources, yet for those who depend on subsidies or face relational retaliation or social stigma it may close real opportunities. Uniform disclosure rules are superficially equal; their consequences are not. Institutions should select materials by relevance to the decision and provide controlled verification, proxy, and anonymous channels. Differential protection may also be abused as secret privilege. The conditions for exception, the roles that approve them, and the audits need to be visible, without publishing the sensitive details of those protected. The institution should let the public see how power grants exceptions, rather than make individuals prove their worthiness of protection through renewed exposure. Managers too may encounter threats and irrelevant intrusion into their private lives. Public office raises their duty to account for decisions and interests; it does not turn family, address, and the whole of life into public assets. Dehumanizing the powerful lets accountability slide into revenge and gives the next officeholder further reason to expand secrecy. The genuinely symmetrical principle is not that all surrender identical materials, but that the greater the authority and the heavier the consequences of one's decisions, the more rules, reasons, and interests must be public; and the less decision-making power an individual holds, the more their irrelevant life should be protected. It is precisely this asymmetry that redirects observation toward power.

The boundaries of visibility should also regain their justification when the institution changes. The scope of recording authorized by one accident cannot automatically extend into daily administration merely because the system has already been purchased; new uses require a fresh comparison of necessity, risk, and exit. The next chapter takes up how this appearance is further amplified: why repeated voices look like a majority, and how number, independence of sources, and silence are to be distinguished.