Infinite Graph
Journal

JOURNAL

Read access and write authority are being treated as the same AI feature

Read access and write authority are being treated as the same AI feature. They shouldn’t be.

As AI becomes more deeply integrated into personal knowledge systems, note-taking applications, and research environments, the debate is often framed around access: How much of my information should an AI be allowed to see? This is an important question, but it is not the only one. A second, structurally different question follows immediately afterward:

What should the AI be allowed to change?

The distinction matters because allowing an AI system to inspect a knowledge base is fundamentally different from granting it authority over the state of that knowledge base.

An AI that searches notes, retrieves related concepts, identifies possible duplicates, or suggests relationships is performing a form of inference. It observes an existing informational environment and generates interpretations about that environment. Those interpretations may be useful, incorrect, incomplete, or probabilistic, but the underlying knowledge remains unchanged.

The moment the system merges two existing notes, deletes a node, rewrites a claim, renames an entity, or permanently confirms a relationship, however, the nature of the operation changes.

The AI is no longer merely interpreting state.

It is mutating state.

This distinction is familiar in other areas of computing. A database user may have permission to execute SELECT queries without being permitted to run UPDATE or DELETE. An analyst may inspect a production system without possessing deployment privileges. A recommendation engine may propose an action without being authorized to execute it.

These distinctions exist because information access and operational authority create different classes of risk.

Yet AI knowledge tools often blur them.

Consider a personal knowledge graph containing several years of notes. The system may infer that two nodes refer to the same concept. Perhaps one is titled “Distributed Cognition,” while another is titled “Cognition Across Systems.” Their embeddings are similar, they share several references, and an LLM concludes that they are probably duplicates.

As an inference, this is valuable.

The AI can surface the connection:

These two concepts appear closely related. Would you like to review them?

But automatically merging them is a different operation entirely.

The two nodes may in fact represent different conceptual distinctions that matter to the user. One may refer specifically to a theoretical framework in cognitive science, while the other may be a broader personal category developed across several projects. Semantic similarity provides evidence for consolidation, but it does not necessarily establish authority to consolidate.

The same logic applies to relationships.

Suppose an AI examining a graph infers that Concept A causes Outcome B. The source material may actually support the weaker statement that A is associated with B. If the system merely proposes the causal relationship, the error remains provisional. If the system writes that edge directly into the graph, however, an uncertain inference becomes part of the persistent knowledge state.

That transformation is easy to underestimate.

Before the write operation, the proposition was:

“The AI thinks this relationship may exist.”

After the write operation, it becomes:

“The knowledge base says this relationship exists.”

Those are not equivalent epistemic states.

This is why a well-designed AI knowledge system needs more than a generic promise that there is a “human in the loop.” The phrase sounds reassuring, but it says remarkably little about where human authority actually enters the process.

A user may technically remain “in the loop” while an AI performs dozens of automatic modifications that the user never meaningfully reviews. Conversely, a system can provide strong human authority without requiring the user to manually perform every organizational task.

The more useful question is architectural:

At which state transitions does inference become action?

A robust authority model might make those transitions explicit:

observe → propose → preview → commit

In the observe stage, the AI receives read access to the relevant portion of the knowledge base. It may search, retrieve, compare, classify, or analyze information, but it does not alter the persistent state.

In the propose stage, the system converts its inference into a candidate action. It may suggest merging nodes, creating a relationship, reorganizing a cluster, renaming a concept, or identifying information that appears obsolete.

Importantly, a proposal is not yet knowledge.

It is an interpretation of knowledge.

The preview stage then makes the consequences of the proposed change visible. Rather than presenting the user with an abstract confirmation dialog — “Accept changes?” — the system should show what will actually happen: which nodes will be merged, which edges will be added or removed, which properties will change, and what information may become inaccessible through the previous structure.

Only after this inspection does the system reach commit: the point at which the proposed transformation becomes part of the canonical knowledge state.

This architecture produces a useful separation between AI capability and AI authority.

A system can be highly capable without being highly autonomous.

It may detect sophisticated patterns, reorganize large conceptual spaces, or generate complex graph transformations while still requiring explicit authorization before those transformations become permanent. In other words, restricting write authority does not require making the AI less intelligent. It requires distinguishing what the AI can infer from what it is allowed to decide.

This distinction becomes increasingly important as personal knowledge systems move from passive storage toward active maintenance.

The earliest generations of PKM software largely placed the burden of organization on the user. Users created folders, tags, backlinks, categories, and hierarchies manually. AI changes this relationship because organization itself can now be computationally generated.

An AI system can notice that two projects have converged around the same concept. It can detect that five notes are variants of the same argument. It can suggest that a new paper contradicts a claim stored two years earlier. It can identify disconnected clusters, redundant concepts, missing links, or inconsistent terminology.

These capabilities are valuable precisely because they reduce the cognitive cost of maintaining a large knowledge base.

But the more powerful the inference becomes, the more important the authority model becomes as well.

A weak AI assistant that occasionally suggests a tag poses relatively little structural risk. A powerful system capable of restructuring thousands of interconnected knowledge objects can introduce significant consequences through a single mistaken operation.

The problem is therefore not whether AI should be permitted to organize knowledge.

It is whether organizational intelligence should automatically imply organizational authority.

There is no reason that it must.

In fact, one of the most productive design principles for AI-assisted knowledge systems may be to maximize the intelligence of proposals while minimizing the irreversibility of decisions.

This leads to another important requirement: reversibility.

Even explicit user approval does not guarantee correctness. Users may approve a merge without understanding its full consequences. They may discover weeks later that two concepts should have remained separate. An AI may make a plausible restructuring proposal whose flaw becomes apparent only after new information enters the graph.

A mature authority model should therefore distinguish commitment from irreversibility.

Every meaningful structural mutation should ideally have provenance: who initiated it, whether it originated from an AI suggestion or direct user action, what the graph looked like beforehand, and how the change can be reversed.

Under this model, an AI does not simply “edit your knowledge.” It proposes a transformation whose history remains inspectable.

This is a more meaningful form of control than a single permission toggle labeled Allow AI access.

Access is multidimensional.

An AI might have permission to read all notes but modify none. It might create new candidate nodes without altering existing ones. It might add provisional relationships but require confirmation before making them canonical. It might automatically perform low-risk transformations while requiring approval for destructive operations such as merges or deletions.

In other words, AI permissions for knowledge systems may need to resemble a genuine capability model rather than a binary choice between “AI enabled” and “AI disabled.”

This perspective also clarifies a useful design philosophy for systems such as Infinite Graph. The principle that AI should assist while users retain decision authority is not merely a branding preference or a conservative stance toward automation. It can be justified architecturally.

The AI occupies the inference layer.

The user retains authority over canonical state.

That division allows the system to exploit what language models do well — detecting patterns, generating hypotheses, identifying possible relationships, and proposing transformations — without pretending that probabilistic inference and authoritative knowledge are the same thing.

The result is not necessarily less automation.

It is better-scoped automation.

Some actions may eventually become safe enough to commit automatically. Others may be governed by confidence thresholds, reversible transactions, or user-defined policies. A mature system could gradually delegate authority while preserving clear boundaries around what the AI is permitted to mutate.

The important point is that these boundaries should exist by design rather than by convention.

As AI becomes more deeply embedded in personal knowledge management, the central trust question may therefore change. Users will not only ask whether an AI can understand their notes.

They will ask whether they can understand what the AI is doing to them.

A trustworthy knowledge system should be able to answer that question at every significant state transition: what the AI observed, what it inferred, what it proposes to change, what the resulting structure will look like, and how that change can be reversed.

The distinction ultimately seems simple:

Reading is epistemic access. Writing is operational authority.

Treating them as a single permission obscures one of the most consequential design decisions in AI-assisted knowledge management.

The future of PKM may therefore depend less on deciding whether AI should organize our knowledge and more on specifying exactly when an AI suggestion is allowed to become part of what we consider true, connected, and canonical.

And that leaves a deliberately simple question:

Would you let an AI reorganize your notes automatically if every change were reversible?