Changkun's Blog欧长坤的博客

Science and art, life in between.科学与艺术,生活在其间。

  • Home首页
  • Ideas想法
  • Posts文章
  • Tags标签
  • Bio关于
  • TOC目录
  • Overview概览
Changkun Ou

Changkun Ou

Human-AI interaction researcher, engineer, and writer.人机交互研究者、工程师、写作者。

Bridging HCI, AI, and systems programming. Building intelligent human-in-the-loop optimization systems. Informed by psychology, sociology, cognitive science, and philosophy.连接人机交互、AI 与系统编程。构建智能的人在环优化系统。融合心理学、社会学、认知科学与哲学。

Science and art, life in between.科学与艺术,生活在其间。

284 Blogs博客
173 Tags标签
  • What Cannot Be Commanded
  • Good Intention and the Structure of Trustworthiness
  • Values Are Revealed When They Become Expensive
  • How Distrust Becomes Mutual
  • Why Repair Cannot Begin with Better Language
  • Trusting Trustworthiness
  • Selected References and Further Reading
    • Foundations of Trust and Trustworthiness
    • Trust, Candor, and Control
    • Trust Violation and Repair
  • 无法命令而来的东西
  • 善意与可信的结构
  • 价值观在代价出现时显形
  • 不信任如何变成双向的
  • 为什么修复不能从更好的话术开始
  • 信任「可信」
  • 参考资料与延伸阅读
    • 信任与可信的基础
    • 信任、坦率与控制
    • 信任破裂与修复
Changkun's Blog欧长坤的博客

A Reflection on Trusting Trustworthiness关于信任「可信」这件事

Published at发布于:: 2026-08-11   |   PV/UV: /   |   Reading阅读:: 20 min

“Perhaps it is more important to trust the people who wrote the software.”

— Ken Thompson, Reflections on Trusting Trust

Ken Thompson’s 1984 lecture is generally remembered for its unsettling demonstration that source-level inspection cannot establish the trustworthiness of a software system. A compiler can insert behavior that is absent from the program it compiles; it can even reproduce that behavior when compiling a clean version of itself. The visible source may tell one story while the mechanism interpreting it quietly produces another. At some point, the chain of verification reaches a foundation it cannot verify using its own instruments. Thompson’s conclusion is not simply that code is dangerous, but that technical trust eventually rests on judgments about the people and practices from which the code emerged.

There is a broader and more hopeful reading of this argument. The fact that verification cannot provide its own ultimate foundation does not make cooperation impossible. It means that every sufficiently complex system contains a point at which formal assurance gives way to trustworthiness. We build beyond what can be completely proved because we have learned, imperfectly but not irrationally, to identify people whose judgment remains dependable when the written rules no longer provide an answer.

Every shared undertaking has something resembling visible source code. It has stated principles, promises, procedures, and descriptions of how decisions are supposed to be made. Beneath them is something less visible: the actual ordering of values that determines what happens when those principles conflict. Honesty may conflict with reputation, autonomy with control, long-term care with immediate appearance, and fairness with personal loyalty. When no conflict exists, the visible source and the hidden mechanism produce the same result. Only when values become costly do we discover what has really been doing the interpreting.

People rarely commit themselves only to the visible text. They also commit themselves to a belief about how that text will be interpreted when circumstances become difficult. They contribute not only because a rule requires them to act, but because they believe their judgment, candor, and willingness to assume responsibility will not be turned against them. What they are trusting is not perfection. It is the character of the mechanism beneath the promises.

What Cannot Be Commanded

A considerable part of human effort can be specified. Tasks can be assigned, minimum standards established, deadlines imposed, and compliance observed. Yet some of the most valuable contributions appear before anyone has had the foresight to request them: an uncomfortable truth reported early, an error admitted before it becomes visible, help offered across a formal boundary, a risk taken for a future that remains uncertain, or care extended to the whole undertaking rather than only to the portion for which one can later be held accountable.

These contributions involve vulnerability. The person who speaks early may be wrong. The person who admits uncertainty may appear less competent. The person who challenges a prevailing account may become associated with the difficulty they identified. The person who accepts responsibility beyond a narrow assignment may inherit consequences without receiving corresponding authority. Such actions cannot be elicited reliably by telling people to be courageous. They become reasonable only when the surrounding conditions make interpersonal risk survivable.

Annette Baier placed vulnerability near the center of trust. To trust another is not merely to predict their behavior; it is to accept exposure to how they will use a power or discretion that cannot be entirely controlled. The distinction matters because reliable behavior can be produced by surveillance, incentives, fear, or coincidence. Trust concerns what another person will do with the freedom that remains after those mechanisms run out.

Amy Edmondson later described psychological safety as a shared belief that a setting is safe for interpersonal risk-taking. Her field research connected that belief with learning behavior, including asking for help, discussing errors, seeking feedback, and challenging assumptions. The point is not that people should feel permanently comfortable. It is that they must be able to undertake socially uncomfortable actions in service of the work without reasonably expecting humiliation or retaliation.

This helps explain why trust is productive in a way that cannot be reduced to morale. When people believe that truth remains usable even when it is inconvenient, they expose information before it becomes undeniable. When they believe that an honest mistake will be examined rather than weaponized, they permit others to learn from it. When they believe that responsibility will not become a one-way transfer of risk, they are more willing to exercise judgment beyond the minimum that can be defended afterward.

Control can secure a floor of behavior, but it does not necessarily produce this voluntary surplus. In an experimental principal-agent setting, Armin Falk and Michael Kosfeld found that imposing control often reduced voluntary performance because many participants interpreted the restriction as a signal of distrust. The overall effect of control was therefore nonmonotonic: it prevented some opportunistic behavior while crowding out some freely given effort.

This does not make control inherently misguided. Some risks should be constrained, some powers separated, and some decisions independently reviewed. The important distinction is between controls that limit the damage of error and controls that attempt to replace human judgment altogether. The first can make trust rational by bounding its consequences. The second may gradually teach people that the safest contribution is the one that follows the visible instruction exactly and offers nothing more.

Those who shape the conditions of a shared undertaking therefore cannot command discretionary care directly. They can only create a world in which offering it remains an intelligent choice.

Good Intention and the Structure of Trustworthiness

Suppose an actor’s values are genuinely positive. They do not seek domination, personal enrichment, or the suffering of others. They sincerely want to protect what is valuable, reduce harm, and leave the world better than they found it. Would that underlying orientation make them trustworthy even when a particular decision proves mistaken?

There are good reasons to answer yes, but not without qualification.

A widely used model developed by Roger Mayer, James Davis, and F. David Schoorman distinguishes three foundations of perceived trustworthiness: ability, benevolence, and integrity. The distinction matters because these qualities can come apart. Someone may care deeply but lack the competence required for a particular domain. Someone may be highly capable but use that ability in ways that subordinate others’ interests. Someone may possess both ability and goodwill yet abandon their stated principles when doing so becomes personally costly.

Good values therefore cannot guarantee correct action. An actor’s behavior also depends on their beliefs about the world, the information available to them, their capacity to understand the problem, and the way they resolve conflicts among values. Benevolence joined with a mistaken model can become paternalism. Integrity joined with inflexibility can become dogmatism. Confidence in a worthy purpose can become dangerous when it prevents evidence from changing the chosen path.

Yet it would be equally mistaken to conclude that values are irrelevant because they cannot guarantee outcomes. Values matter most where specifications become incomplete. A rule can determine what should happen in a familiar case; it cannot anticipate every novel conflict or tell an actor what deserves protection when two legitimate commitments collide. At that boundary, values provide continuity. They influence what the actor notices, which costs they are willing to impose on others, and whether another person’s vulnerability remains morally visible when expediency suggests ignoring it.

Karen Jones offers a particularly useful account of this point. She argues that trustworthiness is not a general property possessed equally in all circumstances. It is a three-place relation: one actor is trustworthy toward another in a particular domain. Competence is required, but so is responsiveness to the fact that another person is counting on them. The reliance itself must become a compelling reason within the actor’s deliberation.

This does not mean that another person’s reliance must always outweigh every competing consideration. A promise may need to be broken to prevent grave harm. A request may have to be refused because honoring it would violate another obligation. Trustworthiness does not require obedience without judgment. It requires that the reliance not disappear from the calculation, and that overriding it create obligations of explanation, accountability, and repair.

An actor with fundamentally positive values can therefore remain trustworthy after being wrong. We may continue to trust their underlying orientation while reducing our reliance on their judgment in a particular domain. We may believe that they sought a good outcome while concluding that they lacked the competence, information, or humility required to pursue it safely. Trust does not need to collapse into a binary choice between absolute confidence and total rejection.

The deepest evidence of good values may not be the absence of error, but what happens when error becomes undeniable. Does the actor permit the judgment to be revised? Do they acknowledge the harm independently of their intention? Can the people affected withdraw authority or impose new constraints? Does correction alter future behavior, or is it merely absorbed into a story in which the original decision remains fundamentally beyond challenge?

A trustworthy actor is not someone who never needs correction. It is someone whom correction can reach.

Values Are Revealed When They Become Expensive

Stated values are weakest as evidence when following them is convenient. Almost anyone can praise honesty when the truth is flattering, support dissent when disagreement changes nothing, or endorse autonomy when others independently arrive at the desired conclusion. Such behavior may be sincere, but it does not yet distinguish principle from convenience.

The more diagnostic moments occur when commitments compete. A difficult truth threatens prestige. A promise becomes expensive to keep. An independent judgment challenges the preferences of someone with greater authority. A long-term obligation conflicts with an immediate measure of success. These are the points at which people learn the actual ranking of values beneath the stated one.

Values are not revealed by what someone chooses when all values point in the same direction. They are revealed by what remains protected when values conflict.

This is why one decision can carry more evidential weight than years of ordinary behavior. The event may reveal not merely that someone acted badly on one occasion, but that the mechanism producing earlier good behavior was different from what others had believed. Apparent openness may be reinterpreted as openness tolerated only when nothing important was at stake. Apparent autonomy may become autonomy granted only while it generated approved results. Praise for candor may come to look like a way of extracting information rather than a commitment to acting on it.

Paul Slovic described an asymmetry in the formation and destruction of trust. Positive events are often diffuse and difficult to count, while negative events tend to be concrete, visible, and heavily weighted. Trust may accumulate through countless uneventful interactions, then decline sharply after one identifiable failure.

But some discoveries do more than outweigh earlier evidence. They change its meaning. Ursula K. Le Guin’s Omelas offers a precise literary form for this transformation. The suffering child is not simply one negative fact added to a prosperous city. Once the condition of the prosperity is understood, the music, beauty, and happiness of the city can no longer be interpreted in the same way. The revelation reaches backward.

Trust can collapse through the same mechanism. A harmful decision is damaging, but deception is more corrosive because it attacks the evidential channel through which trustworthiness was inferred. Once someone discovers that information was deliberately controlled, earlier statements become harder to interpret. The question is no longer only whether a particular claim was false. It is which earlier truths were presented strategically, which silences were deliberate, and whether apparent transparency was itself part of the performance.

Research on trust repair reflects this distinction. Peter Kim, Donald Ferrin, Cecily Cooper, and Kurt Dirks found that competence-based and integrity-based violations call for different responses. Acknowledging a competence failure may help because it identifies a correctable limitation. An integrity violation is harder because admitting it appears to confirm a defect in the very disposition on which future trust would have to depend.

Maurice Schweitzer, John Hershey, and Eric Bradlow found that trust damaged by untrustworthy conduct could recover when later behavior became consistently trustworthy, but prior deception produced more enduring harm. Promises could accelerate initial recovery, yet deception reduced their effectiveness because the credibility of the new promise depended on the same communication channel that had already been corrupted.

This is why a discovery of bad faith can feel disproportionate to the immediate event. It is not necessarily emotional excess. The discovery may force a rational revision of the model through which the entire relationship was understood.

A betrayal is sometimes not one bad data point.

It is a new account of how the earlier data were generated.

How Distrust Becomes Mutual

Once people become uncertain about how inconvenient truth will be received, their behavior changes. They speak later, disclose less, seek written protection, avoid ambiguous responsibility, and invest more effort in ensuring that their actions can be defended. These responses may be self-protective rather than hostile, but from elsewhere they can appear as declining commitment, reduced initiative, or unwillingness to cooperate.

Those who perceive this withdrawal may respond by increasing supervision. More evidence is demanded, discretion is narrowed, decisions require additional approval, and more of the work is translated into forms that can be inspected. From their perspective, this may seem necessary because people are indeed volunteering less and protecting themselves more carefully.

The new controls then confirm the original suspicion. People conclude that judgment is not trusted, that taking responsibility creates exposure without corresponding authority, and that the safest course is to remain within what can be formally demonstrated. Voluntary contribution falls further, providing fresh evidence that stronger control is required.

Both sides can now point to the other’s current behavior as a reason for distrust.

Falk and Kosfeld’s findings help explain one mechanism in this loop: control can be interpreted not only as a constraint, but as information about how the controlling party regards the controlled. It can therefore alter motivation rather than merely limiting action.

Michael Power’s account of the “audit society” describes a broader tendency for demands for accountability to generate increasingly formalized systems of inspection. These systems may begin as rational responses to uncertainty, yet eventually direct attention toward what can be made auditable rather than what is substantively valuable. Verification becomes a visible product of the system, while judgment, candor, and informal responsibility become harder to recognize.

This is the point at which a failure of trust becomes environmental rather than merely interpersonal. People no longer need to remember the original event in order to reproduce its effects. The procedures, defensive habits, and expectations created in response to it continue generating behavior consistent with low trust. Even newcomers can learn the equilibrium without knowing its history.

The surface may remain orderly. Required actions are completed, reports are produced, and fewer risks are taken without permission. What disappears is not necessarily effort in general, but the portion of effort that depends on believing that the whole undertaking deserves care beyond what can be demanded.

Repair is difficult because each side may now be responding rationally to the world the other side has helped create.

Why Repair Cannot Begin with Better Language

When trust has been damaged by misunderstanding or incompetence, explanation and apology can clarify what happened and provide evidence that the failure is understood. When the violation concerns integrity or deception, words face a deeper problem. The speaker is using the damaged channel to certify that the channel is now reliable.

This does not make apology meaningless, but it changes what an apology must be accompanied by. William Bottom, Kevin Gibson, Steven Daniels, and Keith Murnighan found that substantive amends had stronger effects on rebuilding cooperation than explanations alone. Their phrase “substantive penance” captures the basic requirement: repair becomes credible when the response is costly enough to provide information that inexpensive language cannot.

The relevant cost need not be punitive. It may consist of surrendering unilateral discretion, opening a previously closed decision to independent scrutiny, compensating those who bore the consequences, sharing risks that were previously imposed on others, or creating a route by which unwelcome information can travel without depending on the permission of the person it may implicate.

Repair begins when the revealed truth changes the conditions under which future truth will be handled.

This is also why some failures remain effectively irreparable. The actions capable of restoring trust may require precisely what the person or group responsible is unwilling to surrender: control over the account of what happened, the authority to decide whether enough has been done, or the power to preserve the same incentives while promising a different result. A declaration of renewed principle cannot repair a structure that still rewards violating the principle.

Positive values matter here in a way that is neither naive nor sentimental. They do not prove that the harmful act was secretly justified. They provide a reason for the actor to remain present to consequences that threaten their self-conception. Someone who genuinely cares about others can acknowledge that a good intention did not produce a good relationship, that an injury remains real even when it was unintended, and that becoming trustworthy again may require accepting less trust for a time.

Trust can therefore survive failure without becoming unconditional. It can distinguish motive from judgment, preserve belief in benevolence while reducing authority, and reopen gradually as new behavior provides evidence. What it cannot survive indefinitely is the claim that a positive purpose exempts the actor from correction.

Good values make repair possible only when they include the willingness to discover that one’s own interpretation of the good was incomplete.

Trusting Trustworthiness

To trust trustworthiness involves two judgments. First, we place some part of our welfare, work, knowledge, or freedom of action in another’s hands. Second, we trust our own interpretation of what their previous behavior reveals. We believe we have seen more than temporary compliance, convenient virtue, or self-interest that has not yet encountered the right temptation.

The second judgment can never be proved exhaustively. Trustworthiness is partly counterfactual. We want to know what someone will do when supervision disappears, when values conflict, when their judgment is challenged, or when honoring a commitment becomes expensive. No finite history contains every such situation.

This uncertainty does not require cynicism. It means that trust should be resilient but revisable. A trustworthy person can make mistakes, and a mature relation can survive them. Yet trustworthiness must remain capable of being falsified. If every harmful action can be redescribed as the expression of a deeper benevolence, then the claim of good values has become insulated from evidence. At that point, trust has turned into faith in an inaccessible essence.

Thompson’s remark offers a better conclusion. To trust the people who wrote the software is not to rely on their declarations of goodness or on an intuition about their character. It is to rely on practices that make hidden choices visible, permit inconvenient evidence to travel, constrain the use of asymmetric knowledge, and leave someone answerable when the visible source and actual behavior diverge.

The deepest responsibility of those who shape a shared world is therefore not to persuade others that they are trustworthy. It is to create conditions under which trustworthiness remains a reasonable inference.

People will offer more than compliance when truth remains usable, vulnerability remains survivable, and responsibility is not arranged so that one side receives the benefit of initiative while the other bears all the risk. They will continue through difficulty when they believe that stated values will not disappear at the first moment they become costly. And when those values fail, they may trust again if the failure is allowed to change more than the words used to explain it.

We trust trustworthiness not because it promises a world without mistakes, but because it allows a world that inevitably contains mistakes to remain capable of truth, correction, and renewed cooperation.

Perhaps it is more important to trust the people who wrote the software because, in the end, they also wrote the conditions under which the truth about the software could be spoken.

Selected References and Further Reading

Foundations of Trust and Trustworthiness

  • Thompson, Ken. “Reflections on Trusting Trust.” Communications of the ACM 27, no. 8 (1984): 761–763. The starting point for the essay’s visible-source and hidden-foundation problem.
  • Baier, Annette. “Trust and Antitrust.” Ethics 96, no. 2 (1986): 231–260. A foundational philosophical account of trust, vulnerability, goodwill, and the moral risks of misplaced trust.
  • Jones, Karen. “Trustworthiness.” Ethics 123, no. 1 (2012): 61–85. Develops the idea that trustworthiness is domain-specific and requires responsiveness to another person’s reliance.
  • Mayer, Roger C., James H. Davis, and F. David Schoorman. “An Integrative Model of Organizational Trust.” Academy of Management Review 20, no. 3 (1995): 709–734. Introduces the influential distinction among ability, benevolence, and integrity.

Trust, Candor, and Control

  • Edmondson, Amy C. “Psychological Safety and Learning Behavior in Work Teams.” Administrative Science Quarterly 44, no. 2 (1999): 350–383. Examines the conditions under which people take interpersonal risks necessary for learning and error reporting.
  • Falk, Armin, and Michael Kosfeld. “The Hidden Costs of Control.” American Economic Review 96, no. 5 (2006): 1611–1630. Demonstrates experimentally how explicit control can crowd out voluntary effort.
  • Power, Michael. The Audit Society: Rituals of Verification. Oxford University Press, 1997. Explores how demands for accountability produce expanding systems of formal inspection and auditable performance.

Trust Violation and Repair

  • Slovic, Paul. “Perceived Risk, Trust, and Democracy.” Risk Analysis 13, no. 6 (1993): 675–682. Develops the asymmetry principle explaining why trust is generally easier to destroy than to build.
  • Kim, Peter H., Donald L. Ferrin, Cecily D. Cooper, and Kurt T. Dirks. “Removing the Shadow of Suspicion: The Effects of Apology versus Denial for Repairing Competence- versus Integrity-Based Trust Violations.” Journal of Applied Psychology 89, no. 1 (2004): 104–118. Distinguishes competence-based from integrity-based violations and studies how each responds to apology or denial.
  • Schweitzer, Maurice E., John C. Hershey, and Eric T. Bradlow. “Promises and Lies: Restoring Violated Trust.” Organizational Behavior and Human Decision Processes 101, no. 1 (2006): 1–19. Shows why deception causes more persistent damage than untrustworthy behavior without deception.
  • Bottom, William P., Kevin Gibson, Steven E. Daniels, and J. Keith Murnighan. “When Talk Is Not Cheap: Substantive Penance and Expressions of Intent in Rebuilding Cooperation.” Organization Science 13, no. 5 (2002): 497–513. Examines the role of substantive amends, apology, and costly action in rebuilding cooperation.

“也许,更重要的是去信任那些编写软件的人。”

—— Ken Thompson,Reflections on Trusting Trust

人们记住 Ken Thompson 1984 年的那场演讲,通常是因为其中那个令人不安的演示:仅仅检查源代码,并不能证明一个软件系统值得信任。编译器可以向程序中注入源代码里根本不存在的行为;甚至在编译一份干净的自身源码时,它仍能把这种行为复制到新的编译器中。眼前的代码讲述着一个故事,解释它的机制却可以在暗中产生另一个结果。验证链条走到某处,终究会抵达一个无法用自身工具验证的基础。Thompson 的结论不只是代码很危险,而是技术上的信任最终仍然取决于我们如何判断创造代码的人,以及代码由何种实践孕育而来。

这个论证还可以有一种更宽广、也更有希望的理解。验证无法为自己提供终极基础,并不意味着合作从此不可能。它意味着,任何足够复杂的系统里都会有一个位置,形式保证到此让位于可信。我们能够建造超出完整证明范围的事物,是因为我们已经学会——虽然并不完美,却也并非毫无根据——辨认这样一些人:当成文规则不再给出答案时,他们的判断依然靠得住。

每一项共同事业,都有某种类似于“可见源代码”的东西:公开的原则、承诺、流程,以及关于决策应当如何作出的说明。它们之下还藏着不那么可见的一层:当这些原则彼此冲突时,真正决定结果的价值排序。诚实可能与声誉冲突,自主可能与控制冲突,长期的关切可能与眼前的体面冲突,公平也可能与私人忠诚冲突。当冲突尚未出现,可见的源码与隐藏的机制会产出同样的结果。只有当坚守价值开始需要付出代价时,我们才知道一直以来究竟是什么在负责解释。

人们很少只把自己托付给那些可见的文字。他们也把自己托付给一种信念:相信局面变得困难时,那些文字仍会得到怎样的解释。他们作出贡献,不只是因为规则要求如此,也因为他们相信,自己的判断、坦率和承担责任的意愿不会反过来成为伤害自己的工具。他们信任的并不是完美,而是承诺之下那套机制的品格。

无法命令而来的东西

人的许多努力可以被明确规定。任务可以分配,最低标准可以设定,截止日期可以强制执行,是否合规也可以观察。然而,一些最有价值的贡献,往往出现在任何人来得及提出要求之前:尽早说出一个让人不舒服的事实,在错误暴露之前主动承认,跨越正式职责的边界向他人伸出援手,为一个仍不确定的未来承担风险,或者关心整件事业,而不只是关心日后可以追责到自己的那一小块。

这些贡献都伴随着脆弱。过早发言的人可能判断错了;承认不确定的人可能显得不够专业;挑战主流叙事的人可能从此与他指出的问题捆绑在一起;承担职责之外责任的人,也可能在没有相应权力的情况下继承全部后果。单靠要求人们勇敢,无法稳定地得到这些行动。只有当周围的条件使人际风险变得可以承受时,这些选择才是理性的。

Annette Baier 把脆弱置于信任问题的中心。信任另一个人,并不只是预测他会怎么做,而是接受这样一种暴露:你无法完全控制他将如何使用手中的权力或裁量空间。这个区别很重要,因为可靠的行为可以由监控、激励、恐惧甚至巧合制造出来。信任真正关心的是,当这些机制都走到尽头,另一个人会如何使用剩余的自由。

Amy Edmondson 后来把心理安全感描述为一种共同信念:人们相信身处的环境允许自己承担人际风险。她的田野研究将这种信念与学习行为联系起来,包括寻求帮助、讨论错误、请求反馈和挑战假设。重点并不是让人永远感到舒服,而是让人能够为了把事情做好,去做那些在社交上令人不适的事,而不必合理地预期自己会因此受到羞辱或报复。

这也解释了为什么信任能够产生一种不能被简单归入“士气”的生产力。当人们相信真相即使令人不便也仍然有用,他们就会在问题变得无法否认之前暴露信息。当人们相信诚实的错误会被分析而不是被武器化,他们就愿意让别人从中学习。当人们相信责任不会变成风险的单向转移,他们就更愿意运用判断,作出超出事后最低限度自保范围的贡献。

控制可以守住行为的下限,却未必能产生这种自愿的盈余。在一项委托—代理实验中,Armin Falk 和 Michael Kosfeld 发现,施加控制往往会降低自愿绩效,因为许多参与者把限制理解成不信任的信号。控制的总体效果因此并非单调:它阻止了一部分机会主义行为,同时也挤走了一部分原本会被自愿付出的努力。

这并不意味着控制本身是错的。有些风险本就应该受到约束,有些权力应当彼此分离,有些决定也必须经过独立审查。重要的区别在于:一种控制是为了限制错误造成的损害,另一种则试图彻底取代人的判断。前者通过约束后果,让信任变得合理;后者却可能逐渐教会人们,最安全的贡献就是一字不差地执行看得见的指令,除此之外什么也不要做。

所以,塑造一项共同事业的人无法直接命令别人付出额外的关切。他们所能做的,只是创造一个让这种付出仍然显得明智的世界。

善意与可信的结构

假设一个行动者的价值观确实是正面的。他不追求支配,不谋求私利,也不希望别人受苦;他真诚地想保护有价值的事物、减少伤害,并让世界在自己离开时比到来时更好。那么,即使某个具体决定后来被证明是错的,这种底层取向是否仍能使他值得信任?

我们有充分理由回答“是”,但这个答案必须附带条件。

Roger Mayer、James Davis 与 F. David Schoorman 提出的一个经典模型,把感知到的可信分为三个基础:能力、善意与正直。这个区分很重要,因为三者完全可能彼此分离。一个人也许非常关心他人,却缺少特定领域所需的能力;也许能力很强,却用它来压低别人的利益;也可能兼具能力与善意,却在坚持原则开始需要个人付出时放弃自己宣称的价值。

所以,好的价值观无法保证正确的行动。一个人的行为还取决于他如何理解世界、掌握了哪些信息、有没有能力看清问题,以及如何解决价值之间的冲突。善意与错误的模型结合,可能变成家长主义;正直与僵化结合,可能变成教条;对崇高目的的确信,一旦阻止证据改变既定路线,同样可能变得危险。

但反过来,因为价值观无法保证结果正确,就断言它们毫无意义,也同样是错的。价值最重要的时刻,恰恰出现在规范不再完备的地方。规则可以规定熟悉情形下应当怎么做,却无法预见每一种新的冲突,也无法在两个正当承诺彼此碰撞时告诉行动者究竟该保护什么。到了这个边界,价值观提供了连续性:它影响一个人会注意到什么,愿意把哪些代价施加给别人,以及当权宜之计建议忽略他人的脆弱时,那份脆弱是否仍然在道德上可见。

Karen Jones 对这一点给出了特别有用的解释。她认为,可信不是一种在所有情境中都同等存在的普遍属性,而是一种三元关系:一个行动者,在某个特定领域里,对另一个人而言是可信的。能力是必要条件,但还不够;行动者还必须能够回应这样一个事实:另一个人正在依赖自己。这份依赖本身,必须成为其思考过程中一个有分量的行动理由。

这并不意味着他人的依赖必须永远压倒一切竞争性的考虑。为了避免严重伤害,承诺有时不得不被打破;如果满足一个请求会违反另一项义务,它也可能必须被拒绝。可信不要求不加判断地服从。它要求的是:他人的依赖不能从权衡中消失;当它不得不被推翻时,解释、问责与修复的义务也随之产生。

因此,一个底层价值观良好的行动者,即使犯错,仍然可能值得信任。我们可以继续相信他的基本取向,同时降低对他在某个领域判断力的依赖。我们可以相信他追求的是一个好结果,同时得出结论:他缺少安全实现它所需的能力、信息或谦逊。信任不必坍缩成绝对相信与彻底拒绝之间的二选一。

对良好价值观最深的检验,或许并不是从不犯错,而是错误变得无可否认之后会发生什么。行动者是否允许原有判断被修正?是否能在不借意图开脱的情况下承认伤害?受影响的人能否收回授权,或施加新的约束?纠正是否真的改变了未来的行为,还是只被吸收到一套叙事里,让最初的决定继续处于根本不可挑战的位置?

可信的人并不是永远不需要纠正的人,而是纠正能够抵达的人。

价值观在代价出现时显形

当遵循一种价值恰好很方便时,口头宣称的价值最不能说明问题。真相有利于自己时,几乎谁都可以赞美诚实;异议不会改变任何事情时,谁都可以支持不同声音;别人独立判断后恰好得出了自己想要的结论时,谁都可以拥护自主。这些行为也许是真诚的,但尚不足以区分原则与便利。

真正有诊断意义的时刻,是不同承诺发生冲突的时候。一个难以接受的真相威胁到声望,一项承诺变得昂贵,一个独立判断挑战了权力更大者的偏好,一份长期责任与眼前的成功指标发生矛盾。正是在这些时刻,人们才看见公开价值之下真正的排序。

当所有价值都指向同一个方向时,一个人的选择说明不了他的价值。只有价值彼此冲突时,仍然被他保护下来的东西,才会揭示答案。

这也解释了为什么一个决定有时比多年平常的表现更具证据分量。它所揭示的也许不只是某个人在某一次做错了,而是过去那些良好行为背后的生成机制,并不是别人原先相信的那个机制。曾经的开放,可能被重新理解为只有在无关紧要时才被容忍的开放;曾经的自主,可能变成只有在产出获准结果时才被授予的自主;对坦率的赞美,也可能开始像一种提取信息的手段,而不再是对采取相应行动的承诺。

Paul Slovic 描述过信任形成与瓦解之间的不对称。正面事件通常分散而难以计数,负面事件却具体、可见,并且会被赋予极高的权重。信任可以通过无数次平静无事的互动缓慢积累,却在一次清晰可指认的失败之后急剧下降。

但有些发现并不只是抵消过去的证据,它们会改变过去证据的含义。Ursula K. Le Guin 笔下的 Omelas 为这种变化提供了一个精确的文学形式。那个受苦的孩子,并不是繁荣城市旁边多出来的一条负面事实。一旦人们明白繁荣以什么为条件,城里的音乐、美丽与幸福就再也无法用原来的方式理解。这个发现会一路向后改写过去。

信任也会通过同样的机制崩塌。一个有害决定固然会造成伤害,但欺骗更具腐蚀性,因为它攻击的是我们用来推断可信与否的证据渠道。一旦发现信息曾被有意控制,过去的陈述就变得更难解释。问题不再只是某一个说法是否为假,而是此前哪些真话经过策略性挑选,哪些沉默是刻意为之,以及看似透明的表现本身是否也只是表演的一部分。

关于信任修复的研究体现了这个差别。Peter Kim、Donald Ferrin、Cecily Cooper 和 Kurt Dirks 发现,由能力问题与正直问题造成的失信,需要不同的回应。承认能力上的失败可能有所帮助,因为它指出了一个可以纠正的局限。正直方面的失信则更难处理,因为承认它,似乎恰好证实了这样一种品质缺陷:而我们原本还需要依赖这种品质,才能重新建立未来的信任。

Maurice Schweitzer、John Hershey 和 Eric Bradlow 发现,不可靠行为造成的信任损害,可以在此后持续可信的行为中逐渐恢复;但如果此前伴随着欺骗,伤害就会更持久。承诺可以加快最初的恢复,可一旦发生过欺骗,承诺的作用就会减弱,因为新承诺的可信度仍依赖于那条已经受损的沟通渠道。

所以,发现恶意或不诚信时,人们的反应看起来可能远大于眼前事件本身。这未必是情绪失控。这个发现也许迫使人重新修正那套理解整个关系的模型。

背叛有时并不只是一个坏的数据点。

它是关于过去那些数据如何生成的一种全新解释。

不信任如何变成双向的

一旦人们不再确定,令人不便的真话会受到怎样的对待,他们的行为就会改变。他们更晚开口,披露更少,寻求书面保护,回避边界模糊的责任,并投入更多精力确保自己的行动日后能够自证。这些反应可能只是自我保护而非敌意,但从另一个位置看,却会像投入下降、主动性减弱,或不愿合作。

观察到这种退缩的人,可能转而加强监督。他们索要更多证据,压缩裁量空间,让决定经过更多审批,并把更多工作翻译成可以被检查的形式。从他们的角度看,这似乎很有必要,因为人们的确不再主动付出,也确实更谨慎地保护自己。

新的控制随即印证了最初的怀疑。人们据此认定,自己的判断不被信任,承担责任只会增加暴露却不会带来相应权力,而最安全的做法就是只待在形式上可以证明的范围之内。自愿贡献进一步下降,又为加强控制提供了新的证据。

到了这里,双方都可以把对方当下的行为当作不信任对方的理由。

Falk 和 Kosfeld 的研究解释了这个循环中的一种机制:控制不仅会被理解成限制,也会被理解成控制者如何看待被控制者的信息。因此,它改变的不只是行动边界,还有行动动机。

Michael Power 对“审计社会”的分析,则描述了一种更广泛的趋势:问责需求会催生越来越形式化的检查体系。这些体系最初也许只是对不确定性的理性回应,最终却可能把注意力引向能够被审计的东西,而不是实质上真正有价值的东西。验证本身成了系统中可见的产品,判断、坦率和非正式的责任感反而越来越难以辨认。

走到这一步,信任的失败就不再只是人际问题,而变成了环境。人们不必记得最初发生了什么,也会继续复制它的后果。为回应那次事件而产生的流程、防御习惯与预期,会持续制造符合低信任状态的行为。即便后来者完全不了解那段历史,也会学会这个均衡。

表面仍然可以井然有序。规定动作照常完成,报告持续产出,也更少有人未经允许就承担风险。消失的未必是一般意义上的努力,而是努力中依赖这样一种信念的部分:相信整项事业值得得到超出命令之外的关心。

修复之所以困难,是因为此时的每一方,都可能正在理性回应一个由对方参与塑造的世界。

为什么修复不能从更好的话术开始

当信任因误解或能力不足而受损时,解释和道歉可以澄清发生过什么,并提供证据说明失败已经被理解。但当失信涉及正直或欺骗时,语言会遇到一个更深的问题:说话者正在使用一条已经损坏的渠道,来证明这条渠道如今可靠了。

这并不让道歉变得毫无意义,却改变了道歉必须与什么相伴。William Bottom、Kevin Gibson、Steven Daniels 和 Keith Murnighan 发现,与单纯解释相比,实质性的补偿更能重建合作。他们所说的“实质性悔罪”抓住了基本要求:只有当回应昂贵到足以提供廉价语言无法提供的信息时,修复才会变得可信。

这里的代价不必是惩罚性的。它可以是放弃单方面的裁量权,把过去封闭的决定交给独立审查,补偿真正承担后果的人,分担过去被转嫁给他人的风险,或者建立一条让不受欢迎的信息得以传递的路径,使它不再依赖可能被牵涉其中者的许可。

只有当被揭示的真相改变了未来处理真相的条件,修复才算真正开始。

这也解释了为什么有些失败实际上无法修复。能够恢复信任的行动,可能恰好要求责任方放弃他们最不愿放弃的东西:对事件叙事的控制,决定“是否已经做得足够”的权力,或者一边承诺不同结果、一边保留原有激励结构的能力。只要一套结构仍然奖励对原则的违反,重新宣告原则就无法修复它。

正面的价值观在这里仍然重要,但并不是出于天真或感伤。它们不能证明有害行为其实暗中合理,却可以给行动者一个理由,让他继续面对那些威胁自我认知的后果。一个真正关心他人的人,能够承认善意没有带来良好的关系,伤害即便并非有意也依然真实,也能够接受:若想重新成为可信的人,自己也许必须暂时只获得更少的信任。

因此,信任可以在失败之后继续存在,而不必变成无条件的信任。它可以区分动机与判断,在降低授权的同时仍然相信善意,也可以随着新行为提供证据而逐步重新开放。但有一件事,它无法无限承受:以良好目的为由,声称行动者可以免于纠正。

好的价值观只有在包含这样一种意愿时,才可能带来修复:愿意发现自己对“何为善”的理解原来并不完整。

信任「可信」

信任可信,包含两个判断。第一,我们把自己的一部分福祉、工作、知识,或行动自由交到另一个人手里。第二,我们相信自己对其过往行为的解释。我们相信自己看到的不只是暂时的服从、恰好方便的美德,或尚未遇到合适诱惑的自利。

第二个判断永远无法得到穷尽的证明。可信在一定程度上是反事实的:我们想知道,没有监督时一个人会怎么做,价值冲突时会怎么做,判断受到挑战时会怎么做,以及信守承诺开始变得昂贵时会怎么做。任何有限的历史,都不可能包含所有这些情形。

这种不确定并不要求我们走向犬儒。它意味着,信任应当坚韧,却也必须可以修正。可信的人会犯错,成熟的关系也能经受错误。但可信必须始终保留被证伪的可能。如果每一种有害行为都能被重新描述成某种更深善意的表达,那么对良好价值观的主张就已经与证据隔绝。走到这一步,信任便成了对某种无法抵达的本质的信仰。

Thompson 的那句话提供了一个更好的结论。信任编写软件的人,并不意味着依赖他们对自身善意的宣告,也不意味着依赖一种关于其品格的直觉。它意味着依赖这样一些实践:让隐藏的选择变得可见,让令人不便的证据得以流动,约束不对称知识的使用,并在可见源码与实际行为发生偏离时,让某个人必须对此负责。

所以,塑造一个共同世界的人所承担的最深责任,不是说服别人相信自己可信,而是创造让“可信”始终可以被合理推断的条件。

当真相仍然有用,脆弱仍然可以承受,责任也没有被安排成一方享受主动性的收益、另一方承担全部风险时,人们就会付出超出合规要求的东西。当他们相信公开宣称的价值不会在第一次变得昂贵时立刻消失,他们就会在困难中继续下去。而当这些价值真的失败,如果失败改变的不只是解释失败的措辞,他们也许还会重新信任。

我们信任可信,并不是因为它承诺一个没有错误的世界,而是因为它能让这个注定包含错误的世界,继续保有真相、纠正与重新合作的能力。

也许,更重要的是去信任那些编写软件的人。因为归根结底,他们编写的不只有软件,也包括那个让软件真相得以被说出的环境。

参考资料与延伸阅读

信任与可信的基础

  • Thompson, Ken. “Reflections on Trusting Trust.” Communications of the ACM 27, no. 8 (1984): 761–763。本文关于可见源码与隐藏基础问题的起点。
  • Baier, Annette. “Trust and Antitrust.” Ethics 96, no. 2 (1986): 231–260。关于信任、脆弱、善意,以及错误信任所带来的道德风险的奠基性哲学论述。
  • Jones, Karen. “Trustworthiness.” Ethics 123, no. 1 (2012): 61–85。提出可信具有特定领域,并要求行动者回应另一个人对自己的依赖。
  • Mayer, Roger C., James H. Davis, and F. David Schoorman. “An Integrative Model of Organizational Trust.” Academy of Management Review 20, no. 3 (1995): 709–734。提出能力、善意与正直这一影响深远的三分框架。

信任、坦率与控制

  • Edmondson, Amy C. “Psychological Safety and Learning Behavior in Work Teams.” Administrative Science Quarterly 44, no. 2 (1999): 350–383。研究人们承担学习与报告错误所必需的人际风险,需要怎样的环境条件。
  • Falk, Armin, and Michael Kosfeld. “The Hidden Costs of Control.” American Economic Review 96, no. 5 (2006): 1611–1630。通过实验展示明确控制如何挤出自愿付出的努力。
  • Power, Michael. The Audit Society: Rituals of Verification. Oxford University Press, 1997。讨论问责需求如何催生不断扩张的正式检查与可审计绩效体系。

信任破裂与修复

  • Slovic, Paul. “Perceived Risk, Trust, and Democracy.” Risk Analysis 13, no. 6 (1993): 675–682。提出信任通常易毁难建的不对称原理。
  • Kim, Peter H., Donald L. Ferrin, Cecily D. Cooper, and Kurt T. Dirks. “Removing the Shadow of Suspicion: The Effects of Apology versus Denial for Repairing Competence- versus Integrity-Based Trust Violations.” Journal of Applied Psychology 89, no. 1 (2004): 104–118。区分能力型与正直型失信,并研究道歉或否认对两者的不同作用。
  • Schweitzer, Maurice E., John C. Hershey, and Eric T. Bradlow. “Promises and Lies: Restoring Violated Trust.” Organizational Behavior and Human Decision Processes 101, no. 1 (2006): 1–19。说明与单纯的不可靠行为相比,欺骗为什么会造成更持久的伤害。
  • Bottom, William P., Kevin Gibson, Steven E. Daniels, and J. Keith Murnighan. “When Talk Is Not Cheap: Substantive Penance and Expressions of Intent in Rebuilding Cooperation.” Organization Science 13, no. 5 (2002): 497–513。考察实质性补偿、道歉与高成本行动在重建合作中的作用。
#随笔# #信任# #软件工程#
  • Author:作者: Changkun Ou
  • Link:链接: https://changkun.de/blog/posts/trusting-trustworthiness/
  • All articles in this blog are licensed under本博客所有文章均采用 CC BY-NC-ND 4.0 unless stating additionally.许可协议,除非另有声明。
Developing Taste Through Accumulated Experience

Have thoughts on this?有想法?

I'd love to hear from you — questions, corrections, disagreements, or anything else.欢迎来信交流——问题、勘误、不同看法,或任何想说的。

hi@changkun.de
© 2008 - 2026 Changkun Ou. All rights reserved.保留所有权利。 | PV/UV: /
0%