some things become more trustworthy when less is visible.
when we want to trust a process, we often ask to see inside it. show us the records. show us the inputs. show us who checked them. if an outcome matters, we tend to think seeing more will help us trust it more.
transparency and accountability have become tightly linked.
but there are systems where visibility can weaken the very thing it is meant to protect.
take a secret ballot. we need to know that the votes were counted correctly, not how each person voted. exposing individual votes can make people easier to pressure, while a verifiable tally lets us check the outcome without seeing the choices beneath it.
the same tension appears in markets where participants cannot reveal their positions without changing one another's behavior, or institutions that could establish something together but cannot simply pool their records. different forms of coordination, each shaped by what participants can safely reveal.
none of these examples calls for less accountability. they ask us to separate what must be visible from what must be verified.
as computation produces more of the outcomes we share — votes, prices, rankings, models, allocations — that distinction gives us more room to ask what a system actually needs to know, rather than simply what it is capable of knowing.
once trust no longer has to depend on total visibility, we can start building shared systems around a different question: not how much they can see, but how little they actually need to.