Hands That Wait
Most “assistants” act first and explain later. They run, take steps, change things — and you find out what they did afterward, if at all. This system is built the other way around: the part that acts is dark by default. It can think, propose, and lay out exactly what it would do — but the doing doesn’t happen until a person deliberately turns it on.
This isn’t caution for its own sake. An automatic helper that’s free to act is convenient right up until the moment it does something you didn’t want, and by then it’s done. So here, the hands wait.
Two ideas make that wall hold.
First, stopping is not all-or-nothing. There are two kinds of pause. One is about truth — if something doesn’t add up, a check fails, a result doesn’t match — and that pause never clears itself. A person has to look. The other is about presence — something was slow or briefly unavailable — and that one can resume, but only after the system re-confirms everything is sound. Being slow can be forgiven automatically. Being possibly-wrong cannot.
Second, the rules are plain and fixed, not a mood. Whether to stop is decided by simple, checkable logic — not by asking the system “do you feel okay?” Anything that can be flattered or talked into a mistake can’t be the thing guarding against mistakes. So the gate is simple, fixed, and inspectable, and anything unexpected defaults to stop and ask the human, never proceed and hope.
The shorthand: the system’s hands stay dark — capable, ready, fully designed — until a person brings the light. Hands that wait are the price of being trustworthy, and it’s a price worth paying.