SKIP TO CONTENT
369 Hertz

← RECORD 004 / WRITING & REFERENCE BUILDSESSAY 001

CONSENT ARCHITECTURE · JUNE 2026 · 3 MIN READ · REVISED JULY 2026

Consent is a state machine, not a checkbox

Most consent UIs misrepresent what the system actually stored. This essay is about designing interfaces where the screen and the record can't disagree, and what that discipline costs.

A consent screen is usually rendered as a boolean: a toggle, a checkbox, a green dot. The record underneath it is never a boolean. It is a history: who asked, on what legal basis, for which stated purpose, when it was captured, and when it lapses. The gap between the shape of the screen and the shape of the record is where most consent interfaces quietly fail.

The failure is not cosmetic. When a subject-access request arrives, an operator reads the screen and answers from it. If the screen says "on" and the record says "expired eight months ago, renewal never requested," the operator has misreported the organisation's legal position, in writing, to the person most likely to escalate. The interface did that, not the operator.

01 · THE SCREEN AND THE RECORD

Our working rule: every consent state shown on screen must be explainable in one line of stored fact. Not derivable after a join across three tables; explainable next to the state, in the operator's line of sight. If a state can't be explained that way, treat it as a rendering decision pretending to be a state.

This inverts the usual hierarchy. The stored record stops being the implementation detail behind the UI and becomes the thing the UI exists to make legible. The toggle was never the product; the evidence was.

A granted state that never expires is a default with better typography, not a consent record.

02 · FOUR STATES, NOT TWO

Modelled honestly, the minimum machine has four states: granted, withdrawn, expired, and never asked. A toggle collapses the last three into "off," and they are not the same obligation. Withdrawn requires you to stop and to keep proof you stopped. Expired requires you to stop and invites you to re-ask. Never-asked means there is nothing to stop, and rendering it as "off" is the single most common way these interfaces mislead.

Withdrawal deserves its own paragraph because it is where auditors look first. Withdrawing consent does not erase the original grant; the record keeps both events, because the operator may later have to prove what was lawful when. An interface that shows only the current state has designed away the organisation's ability to defend its past.

03 · WHAT IT COSTS

Honesty has a price, and it is paid in scanning speed. Four labelled states are slower to read than a green dot. A lapse date the operator cannot avoid seeing adds a line to every row. We think the trade is obviously right (a consent surface is read carefully a few times a day, not skimmed a thousand times), but it is a trade, and pretending otherwise is how you lose the argument with your own product team.

We built a working version of this argument as a reference build, the Wrenfield Consent Desk, with the state machine and the stored record rendered side by side. The component is coded and keyboard-operable; the reasoning above is what it demonstrates.

SEE THE WRENFIELD REFERENCE BUILD

FILED UNDERCONSENT ARCHITECTUREPRIVACY UX

Reading this against a problem you have right now?

START A CONVERSATION A 30-minute call, no deck. Short form; a reply within two business days.