unite
Participatory democracy × value-centric design — shared futures, computed needs-first, with dissent carried
The unite design and its seed client are AI-agent-authored (Claude Fable 5, @jeswr’s agent) and are intended to be criticised, forked, and superseded. Text is CC BY 4.0. Under active development; not production-ready.
Try the live prototype → /unite-v2 (an in-browser demo — nothing you type leaves your browser)
What unite is
Existing social platforms optimise for engagement, which in practice amplifies division: the content that spreads is the content that provokes. Existing participation mechanisms — elections, consultations, petitions — are low-bandwidth: they let people choose between options others framed, not describe the future they actually want.
unite inverts both. Its primitive is a person’s own description of their ideal future, their current life, and their needs. Its social mechanic is resonance across difference rather than engagement — you see others’ futures for inspiration, and react to theirs as they react to yours. Its output is convergence artifacts: shared-future statements with explicit provenance, endorsement evidence, and carried dissent — legible enough for governments and industry to act on.
Two non-negotiables
unite has no single codebase and no single standards owner — either one would concentrate too much control. It is built on the Solid data-model federation stack (the vision paper’s §2.5), and it is designed to decentralise, with measurable exit criteria — by its own rules it describes itself as “bootstrapping”, not “decentralised”, until those criteria are met (§8).
Dissent is a first-class, permanently-carried artifact — never smoothed away. A shared-future statement without its dissent annex is invalid (SHACL-enforced); dissent may be absent only via an explicit signed no-dissent assertion, which is auditable — and embarrassing to fake.
Needs, not positions: the data model
The fut: vocabulary (w3id.org/jeswr/sectors/futures#, a seed namespace) follows the suite’s federation sector pattern and reuses ActivityStreams, SKOS, PROV-O, ODRL 2.2, and Verifiable Credentials — minting nothing that already exists. It has three layers, distinguished by where the data lives:
- Expression, in the author’s pod —
fut:VisionStatement(“my ideal future”),fut:LifeContext(“my current life”),fut:Claim(an atomic, voteable statement — the deliberation unit, length-capped and shape-validated), plusfut:Need,fut:Satisfier, andfut:ValueStatement. - Reaction, in the reactor’s pod —
fut:Resonance, tri-state (Resonates / Conflicts / Unsure) with an optional dimension qualifier — I share this, I aspire to this, I would support this — because a present condition, an aspiration, and a willingness to support others are psychologically distinct. - Process, in the community’s space —
fut:Deliberation,fut:SharedFuture(the convergence artifact: full PROV derivation, per-cluster bridging evidence, signed as a Verifiable Credential),fut:DissentRecord, and open, k-anonymousfut:ConvergenceMetrics.
The load-bearing idea is Max-Neef’s split between needs — few, universal, stable across cultures — and satisfiers, the culturally variable ways needs are met:
People who violently disagree about satisfiers (“cars vs trains”) routinely share the underlying needs (“get to work reliably; breathe clean air”).
Convergence is therefore computed needs-first, where common ground structurally exists, and satisfier diversity is treated as a portfolio to preserve, not noise to average away — which reframes disagreement as design-space, not conflict. The value scheme is seeded from Schwartz’s basic-values circumplex; neither scheme is closed or centrally owned — the seed schemes are defaults, not law.
Every statement can carry an ODRL consent policy — aggregate, synthesize, quote-verbatim, government-use, with a k-anonymity threshold (default k = 5). The defaults are conservative: quotation and government use are prohibited until explicitly granted, consent is recorded at synthesis time, and the consent UI says plainly that aggregates derived with your consent may persist after deletion.
How convergence works
unite adopts bridging as the ranking objective everywhere content is ordered — there is no engagement-ranked surface anywhere in the design. The pipeline has five steps, each grounded in named prior work:
- Elicitation. Narratives decompose into atomic claims, needs, and values — the Pol.is deliberation model (Small et al., 2021), deployed nationally in Taiwan’s vTaiwan process.
- Substrate and presentation. Max-Neef (1991) for needs; Schwartz (1992) for values. Presentation follows the false-polarisation and perception-gap literature (Ahler & Sood 2018; More in Common 2019): unite always shows actual resonance distributions rather than exemplar opponents, and its inspiration feed applies intergroup-contact findings (Allport 1954; Pettigrew & Tropp 2006) by routing whole vision narratives from people outside your opinion neighbourhood whose need and value profile overlaps yours.
- Resonance mapping. The Pol.is layer: a reaction matrix, dimensionality reduction, opinion clusters — with group-informed consensus surfaced first, and deliberately no replies at this layer, which removes the flame-war surface entirely.
- Synthesis — advisory, with mandatory dissent. Shaped on the “Habermas Machine” result (Tessler et al., Science, 2024): draft, stratified critique round, bounded revision, then an endorsement vote that must clear a bridging threshold — minimum resonance in every cluster, cross-polarity approval rather than majority (the bridging-based-ranking lineage: Ovadya 2022; Wojcik et al. 2022). Surviving objections become the mandatory dissent annex; a failed candidate publishes as a disagreement map, a first-class outcome: here is exactly where we divide, and on which needs we nonetheless agree.
- Escalation. For contested or governance-bound topics, sortition-based mini-publics in the deliberative-polling lineage (Fishkin 2009). The legitimacy split is explicit: self-selected resonance maps inform; sortition-based mini-publics legitimate.
The design takes Mouffe’s agonistic critique seriously — consensus can be a mask that suppresses legitimate conflict — so the objective is to maximise mapped common ground, never to minimise dissent: no metric rewards unanimity, and a community whose consensus rate rises while its dissent annexes empty out is flagged, not celebrated. One honesty note carried from the design record: the literature is grounding, not proof that this system works — effectiveness claims belong to the cited studies, and unite’s own extensions are flagged as plausible but unvalidated.
No component is a point of control
unite is not an application; it is a data-model federation. There is deliberately no “unite server”. A community is just conventional Solid resources — a registry, an inbox, an index — hostable on any pod. Statements live in the author’s pod under standard access control; community indexes are caches, never authoritative; and syntheses carry authority via signature, not location.
The design record audits every function for capture — code, standards, identity, storage, curation, facilitation, and moderation. Two examples: there is no global moderator — a community can decline to index a statement, but cannot delete the pod resource or bar it from other communities; and AI mediation is attributed, swappable, and advisory — a synthesis has zero standing until it wins cross-cluster human endorsement. The standing test for every future feature is exit cost: what does a person, a community, or an implementer lose by leaving? If the answer ever becomes “their data”, “their identity”, “their history”, or “the network”, the feature is wrong.
Identity is stratified rather than gated, because honest expression and sybil resistance genuinely conflict: three participation tiers (pseudonymous; community-vouched; personhood-verified, with a zero-knowledge seam), the posture being stratify and disclose, not exclude — every metric reports participation by tier, and governance-bound syntheses are computed over vouched-or-verified cohorts with the pseudonymous tier shown alongside, never silently mixed.
Governance without an owner — by mechanism, not promise
Specification versions are immutable (permanent owl:versionIRIs), and change is adoption-ratified, not decree-ratified: a version becomes Current only when at least two independent implementations interoperate on it and at least two independent communities advertise it — adoption is measured on the wire, not declared (the IETF’s “rough consensus and running code”, inherited). The steward circle carries a hard cap — no organisation holds more than a third of seats, quorum requires three unaffiliated organisations, and editors assemble, they don’t decide: even a fully captured circle cannot force a change onto the network, and cannot block one the network wants.
Forkability is a constitutional right: CC BY 4.0 text, multi-homed mirrors, and registry machinery that lets fork lineages coexist on the wire. The cost of forking is kept low on purpose — a cheap fork is the standing check on every other mechanism here. The governance eats its own cooking: circle decisions are recorded with objections carried, the same dissent-is-data rule the platform imposes on its communities.
Roll-out stages
| Stage | Scope | Character |
|---|---|---|
| Stage 1 — app co-design | Co-design the Solid applications people want: propose, articulate needs, converge on a spec, the suite’s generative tooling implements, ship — then verify-against-needs, where contributors check the shipped app against their own original needs. | Reflexive and deliberately low-stakes (app specs, not public policy); verify-against-needs is what makes it participatory design rather than a suggestion box. |
| Stage 2 — public technology | Broader standards-based public technology, fediverse-style — the same substrate applied beyond the suite. | Designed; not started. |
| Stage 3 — governance input | Participatory input into government and industry decision-making, escalating through mini-publics. | Designed; gated — launches only on low-sensitivity civic topics, and never on Stage-1 privacy machinery. |
The seed client also carries three scope lenses — apps, infrastructure, society — over the same deliberation substrate with different artifact lifecycles; the society scope’s rule is blunt: nothing executes; institutions and humans decide.
What exists today, and what does not
What exists is a founding design proposal (seven design documents, including a kept adversarial self-critique — §9) and a Stage-1 MVP seed client: a vite/React single-page app in which you can join a deliberation (membership-gated, fail-closed), submit Max-Neef-classified needs with inline ODRL consent policies to your own pod, react with tri-state resonance, and read a bridging-ranked opinion map with full per-group distributions — the UI cannot render a bare consensus number even if it wanted to. It opens on a seeded demo deliberation: an in-browser pod federation behind a fetch facade that never touches the network — while everything above that facade is the real production pipeline. The data layer is exhaustively tested, and the ranking math is deterministic by construction, pinned by a characterization fixture that asserts exact cluster assignments and full ranking order — the seed of the executable conformance fixture set a second implementation must pass.
No LLM-mediated synthesis machinery yet (the Habermas-Machine step is design-stage; the convergence room computes outcomes from votes). ODRL consent is the author’s standing consent record, not yet enforced server-side. Steward signing is pending, and the two-steward floor is shown honestly unmet. Sortition mini-publics are designed, not implemented, and unite never claims representativeness — self-selected maps inform, only mini-publics legitimate. Nothing in Stage 1 claims sybil-resistance beyond the vouching community’s diligence. There is exactly one implementation and a nearly-empty adoption matrix — the correct display, not a bug to paper over. By its own exit criteria, unite’s governance is “bootstrapping”, never “decentralised”, until a second independent implementation and a second steward exist — the final milestone being that the seed author demonstrably loses a recommendation vote and the network follows the adoption rule anyway. Under active development; not production-ready.
The design attacks itself, and keeps the wounds
The design was attacked before it was finalised, and the attacks and their outcomes are kept in the repo permanently — the same dissent-is-data rule the platform imposes on itself. Three of the sharpest:
- The intimacy honeypot. “Describe your ideal future, your current life, your unmet needs” is an intimacy honeypot. Mitigations: conservative consent defaults, pseudonymity, k-anonymity floors — and a hard gate: sensitive Stage-3 topics (health, income) must not launch on Stage-1 privacy machinery.
- Mediator monoculture. If every community uses the same frontier model, the mediator’s training distribution becomes an invisible ideology — exactly the “single standards owner” failure in new clothes. Hence conformance requires swappable non-LLM and human mediators, and mediator diversity is a published metric.
- The deepest attack: a convergence engine is, uncharitably described, a persuasion engine with a democracy skin. The kept response concedes the core: ranking is power. unite chooses bridging as its editorial value, openly, in a forkable spec — the legitimacy claim is transparency plus exit, not neutrality. No further mitigation exists; anyone claiming otherwise about any ranked system is selling something.
Relationship to the Accountable Web of Agents
unite runs on the same federation substrate the Accountable Web of Agents vision describes — pods, sector vocabularies and shapes, registries, verifiable-credential trust, ODRL consent, PROV provenance — and it is that vision’s fullest demonstration: a system whose outputs must be credible to institutions is exactly the stress test the accountability stack exists for. The platform pieces it stands on are inventoried in Solid — what we’ve built.