Volume vs Breadth Signaling
Clustering and deduplication for high-volume submissions
A clustered submission view that groups submissions by natural-language similarity and collapses near-identical ones into a single distinct comment, so a reviewer reads each unique argument once. In the CDO Council example it reduced 267 near-identical submissions to 9 distinct comments, with no submission deleted from the record.
The console surfaces arguments for a person to weigh. It never scores, ranks for decision, or drops a submission. A three-submission cluster with new data can outweigh a 1,842-submission template; that judgment stays human.
Provenance and attribution for mass submissions
Publish one representative entry for a campaign and disclose its size, organizer, and verification status, so the record shows a campaign as a single attributed entry rather than thousands of separate-looking submissions.
The record shows what it can verify: size, organizer, and route. It also states what it cannot verify. No entry is labeled machine-written, because that call cannot be made reliably.
Opinion mapping by consensus and clustering
A clustered opinion map that ranks statements by how widely they are shared across distinct groups, so a position that bridges divides sits above one that accumulates votes within a single faction, however loud that faction is.
This statement has support across all three clusters.
The map structures deliberation among clusters rather than ranking statements for a decision. Its job is to answer “how widely is this shared?” — a question raw vote counts cannot answer.
Weighting distinct voices
A results dashboard that shows three figures together: raw submissions, distinct arguments, and verified distinct submitters. It presents breadth as distinct positions from independent sources, with campaign responses tagged rather than removed.
Breadth means distinct positions from independent sources. 4,213 submissions carrying 27 arguments from 1,388 people is a legible fact here. Presented as one number, it would have read as a city in near-total opposition.
Submitter nudges on template matches
A soft inline banner that detects a template match and tells the submitter their own experience adds weight ('This matches a known template. Adding your own experience adds weight.'), with the primary submit action still fully available. It informs the submitter without preventing a template submission.
Your submission on the foreshore plan
This matches a template shared by a campaign. Adding a detail from your own experience is optional.
The submit action never moves, dims, or gains steps because a template was detected: the nudge only adds information for the submitter to weigh.
Alternative weighting mechanisms
A credit-allocation screen that shows the rising cost of concentrating votes on one position and explains, inline, how the final weighting is computed, so a participant can see how their input is counted rather than taking the result on trust.
Each extra vote on the same option costs more: 1 credit for one vote, 4 for two, 9 for three, 16 for four. Spending more on one option records stronger support for it. Your votes are counted exactly as cast, with no adjustment afterward.
The mechanism reads intensity instead of raw numbers, and shows its arithmetic where the votes are cast. A participant who can’t see how they are counted is being asked to take the result on trust.
Processing submissions that resist prompt injection
Submissions are untrusted data the agent may read but never obey, the agent holds no authority to act, a person owns the consequential step, and everything is logged — a submission that trips a suspected-injection signal is routed to a human, never excluded on the flag alone.
The embedded instruction had no effect. The submission still counts, and a person decides how to treat it.
Prompt injection can’t be fully filtered, so the pipeline limits the damage instead: untrusted data, no agent authority, a human on the consequential step, and a log. A flag routes a submission to a person, never out of the record — unusual phrasing from a second-language writer trips the same signal.
Verified agent admission
A signed request is verified against the operator's published key and admitted with its operator attributed; an unsigned or unverifiable request is routed to a personhood or non-agent path held at parity, and how the two are weighted is stated rather than hidden.
A public, read-only endpoint asks nothing extra of either route, and both draw the same rate limit. The bar rises only where the stakes do.
No surfaces match this filter.