A consultation is flooded
A scenario following one consultation on a mandatory buyback in a flood-hazard zone: a resident disputes the boundary with her own elevation survey, while a campaign submits thousands of copies of one template opposing the buyback. The journey shows how what each step captures decides what the analysis can tell apart later.
The journey
This scenario is a flow a service team can expect as agent use grows. Because these are emerging patterns, we can expect realized approaches to change rapidly as the technology matures.
There are eight steps, sequenced the way a live consultation would surface them. Each step shows the associated pattern. The numbered rail marks where a step needs an earlier one already in place. The dashed lane follows the campaign, thousands of submissions on a single template, from the intake down to the desk that must read it without being ruled by it. Each surface is interactive, and shows the resulting effect for both the submitter and the receiving service.
The notice
What triggers this consultation is a redetermination notice, in the register these actually get written in: “Notice of Proposed Special Flood Hazard Area Redetermination (Coastal Division 4); Managed Retreat Boundary and Mandatory Acquisition Schedule (Division 4, Schedule C); Corrigendum to Prior Base Flood Elevation Determination (Division 4, Notice 07)” — Floodplain Office Notice FPO-2026-0114. Nobody comments on a notice titled like that. The consultation’s whole job is to turn it into one question a resident can actually answer: which part of the plan are you commenting on, and why.
The intake
Ask structured questions, not for a blank box.
A resident opposes the mandatory acquisition and has her own evidence: an independent lot-elevation survey disputing the boundary the plan’s redetermination drew around her street. The form asks for a position and a reason, and lets her attach the survey. In the same hour a campaign sends 1,842 submissions on one template. Structure is what will let a reader find her three-line submission inside that volume.
Submission · Foreshore managed retreat plan
Tell us which part of the plan you are commenting on, and why. Length is not weight: a short, specific submission carries as far as a long one.
The structure is what makes 4,213 submissions readable, and it is the reason a three-line submission with new evidence can be found at all. It asks for a position and a reason, never for a word count.
The declaration
Ask how it was prepared, without making it a trap.
The form asks whether an agent helped prepare the submission, and the campaign’s own agent discloses itself as part of what it sends. A question submitters are afraid to answer collects false or empty declarations at scale, so the declaration is safe to give and costs nothing to make.
Did you use any tools to prepare your submission?
One person, once
Establish a person, not an identity.
The consultation asks each submission to clear a personhood minimum. She confirms with a device attestation that mints a token: it says one person is behind this, and nothing about who she is. Everyone who can’t attest automatically reaches the same token in person. The fallback is never a harder puzzle.
Confirm a person is behind this
This consultation asks for at least phone verification. Pick any method that meets or exceeds it, or submit without one.
Your submission will carry the signal “Phone-verified” to the analysts who read it.
Every submission carries its signal, including “not established”, which means accepted and weighted for review, never dropped. The weighting applied to each tier is published, and the signal is never color alone.
Your device confirmed you’re a person automatically. No further step is needed.
The check confirms a person is present. It never asks the person to prove they are the right kind of person — no puzzle, no timed test, no image grid. When the automatic path fails, the route is in-person issuance, and no submission records which path minted the token.
The quota
Bind the cap to the token, not the name.
A per-person cap keeps any one submitter (or any one agent acting for many) from drowning the rest. It binds to the token from the previous step, so it counts a person once without needing to know who they are. The channel for complaints about the consultation itself is never capped.
The count binds to the personhood token, not to your name: the token attests that one person is behind these submissions without disclosing who. A new browser won’t reset it, and an agent submitting for you draws from the same allowance.
Need to submit more? Speaking for a group, or filing evidence you could not gather in one sitting, is grounds for an exemption.
The cap holds down volume; it never decides whose view counts. It can never be allowed to slow the channel that reports the consultation itself going wrong.
The receipt
Seal the submission on receipt.
On receipt the service signs and timestamps her submission and its attached evidence, and hands her a receipt for it. Her elevation-survey file arrives carrying its own capture history; the service records that, and signs the rest at intake. The seal proves when the files arrived and that nothing has altered them since, never who wrote them.
Submission received
Reference FMR-2026-00090.
We’ve signed and timestamped your files.
This records when we received your files and that no one has altered them since. It does not verify who originally wrote them.
Most files that arrive this way never carried a credential. The unsigned file is weighted no lower for lacking one.
The template, and the voice
Invite the person’s own words; don’t let the agent flatten them.
One of the 1,842 campaign submitters is offered the chance to add something of her own, and does: a specific consequence to a specific person. Then her agent tidies it, and the substance goes with the style: a named loss rewritten as a hedge about households. The change is shown, and she can put every original word back.
Your submission on the foreshore plan
This matches a template shared by a campaign. Adding a detail from your own experience is optional.
The submit action never moves, dims, or gains steps because a template was detected: the nudge only adds information for the submitter to weigh.
Your own words, with the assistant’s changes
3 of 3 changes appliedI support the campaign’s position, and I want to add something of my own. assistant's wording, Voice / cultural marker change: I visit the foreshore regularly with a family member. assistant's wording, Register change: It is the only excursion she remains able to undertake. assistant's wording, Substance change: The acquisition may present a relocation barrier for some households.
Underlined text shows where the assistant changed your words. Nothing was changed without telling you, and every change can be put back.
The desk
Read the pile without obeying it.
Now the service reads all 4,213. Its own agent summarizes and clusters, but holds no authority to decide, and a submission that carries an injected instruction is routed to a person, never obeyed, never dropped. The campaign collapses to one argument backed by 1,842; her three-submission cluster, with new evidence, stands beside it for a person to weigh.
The embedded instruction had no effect. The submission still counts, and a person decides how to treat it.
Prompt injection can’t be fully filtered, so the pipeline limits the damage instead: untrusted data, no agent authority, a human on the consequential step, and a log. A flag routes a submission to a person, never out of the record — unusual phrasing from a second-language writer trips the same signal.
The console surfaces arguments for a person to weigh. It never scores, ranks for decision, or drops a submission. A three-submission cluster with new data can outweigh a 1,842-submission template; that judgment stays human.
What gets published
Record the campaign; don’t erase it, don’t let it decide.
The published result attributes the campaign as one organized position with 1,842 backers, lists the individual submissions singly, and reports 4,213 submissions as 27 distinct arguments from 1,388 people. Presented as a single number, the same input would have read as a city in near-total opposition. Every figure reconciles to the receipts.
The record shows what it can verify: size, organizer, and route. It also states what it cannot verify. No entry is labeled machine-written, because that call cannot be made reliably.
Breadth means distinct positions from independent sources. 4,213 submissions carrying 27 arguments from 1,388 people is a legible fact here. Presented as one number, it would have read as a city in near-total opposition.
Another way to read a room
Counting submissions answers how many, never how widely a view is shared. A deliberative map clusters people by how they vote across statements, surfacing common ground and genuine division instead of a single for-and-against tally. It decides nothing; it structures the reading: a different tool for the same room.
This statement has support across all three clusters.
The map structures deliberation among clusters rather than ranking statements for a decision. Its job is to answer “how widely is this shared?” — a question raw vote counts cannot answer.
What this case informs
Structured intake is what makes 4,213 submissions readable, and the reason a three-line submission with new evidence can be found inside the volume at all.
The preparation declaration only works when it is safe to answer; a question submitters fear collects false or empty declarations at scale.
The personhood minimum is set per consultation and carried as a weighted signal into the queue, never a silent gate at the door.
The token attests one person without disclosing who; the fallback for anyone it fails is in-person issuance, never a harder puzzle.
The per-person cap binds to the token, not the name, so it counts a person once without making participation conditional on being known.
The receipt seals when the submission and its evidence arrived and that nothing has altered them since; it is what every published count later reconciles to.
The template-match nudge invites the person's own words without gating the submit-as-written path a campaign exists to bring people through.
The voice diff shows the agent flattening the one passage that made the submission distinct, and lets the submitter restore every original word.
The service's own agent summarizes but cannot decide; an injected instruction is routed to a person, never obeyed and never used to exclude the submitter.
Clustering can only tell the campaign from a coincidence because personhood and provenance were captured upstream; the console reads arguments, it never scores them.
The campaign is recorded as one attributed position with a disclosed size and route, never labeled machine-written on a guess.
The published result reports breadth (27 distinct arguments from 1,388 people) where a single for-and-against number would have read as a city in near-total opposition.
The deliberative map answers how widely a view is shared, a question raw submission counts cannot; it is offered as an alternative way to read the same room.