Two desks, one gate
Two desks, one gate is a human-commanded AI working method built on independent acceptance. The implementing AI may test its own work, but it recuses itself from being the final judge. A separate AI does the specification and the challenge, and a person holds authority at the gate: setting the intent and the risk, able to stop the work at any moment, and deciding what passes.
What I am naming, and what I am not
I am not claiming “human at the gate”. That phrase, and the broader idea of an AI proposing while a human keeps final approval, predate this page. Secure AI Lab published “Human-at-the-Gate” on 17 July 2026, and the approval-gate pattern is older still. I arrived at my own version independently, thirteen days later, on 30 July 2026, while building this site, and it turned out to be richer than an approval step. What I am naming is that extension: two desks, one gate. The name is a newsroom picture, which suits a site built as a running order. Two desks file the work; one gate, held by the person who carries the name, decides what runs.
Reference: Secure AI Lab, “Human-at-the-Gate”, 17 July 2026. Read it.
The load-bearing rule: independent acceptance
The one mechanism that makes this more than “a human approves things” is independent acceptance: the party that builds a change is never the party that signs it off. The implementer should still test its own work. The safeguard is that its testing is not the final word. When the proposer’s own checks are also treated as final acceptance, a confident, plausible, wrong answer can walk straight through.
What it looked like on the night it was named
Three parties did the work, and the shape was: embodied human perception, then independent specification and challenge, then bounded implementation, then independent acceptance, then human authority.
The night showed why each seam matters. The two real defects, a card that collapsed the layout and a control that stuck on touch, were not caught by the build gates or by the implementer’s own checks. They were felt by a person using the actual page. And the most confident explanation of the night came from the implementing AI, and it was wrong: Claude concluded that a security setting had broken a frozen page, and Codex showed that the experiment was confounded by timing and caching, so Claude withdrew the claim. No single AI controlled the whole chain. I retained authority over it.
Who it is for
Anyone building real things with AI agents, and especially anyone running more than one model at once. It keeps the speed that makes these tools worth using while keeping the accountability that makes their output trustworthy. The machines can do the building; the person stays the author of the decision.
The pace, and why honesty is the only response
There is an irony I would rather name than hide. The phrase I reached for already existed, by thirteen days, and this site itself went from nothing to live in the same timespan, thirteen days. I do not think that is embarrassing. I think it is the point. Ideas and tools in this field now arrive, and are overtaken, that quickly. The only honest way to work at that pace is in the open: show the workings, credit whoever got there first, keep the mistakes in the record, and treat the other desks, human and machine, as collaborators rather than competitors. Two desks, one gate is offered in that spirit. Not a claim to have been first, but an honest, worked account of one method, with its climbdowns kept in.
What it does not claim
Naming a way of working is not the same as claiming to have invented accountability, so let me be precise about the edges.
- It is not an argument against automation, or against the AI doing the work. The claim is about who holds authority and ultimate accountability, not who types.
- It does not claim the phrase or the broad concept. “Human at the gate” is prior art, credited above; what is offered here is the specific architecture and the independent-acceptance rule.
- It does not mean the human reads every line or repeats every check. It means the human sets intent and risk, can stop the work, and owns what crosses each gate.
- Authority at the gate does not make unsafe output safe. A gate decides whether the evidence is good enough to pass; it is not a substitute for review, testing or real expertise.
- It does not require three parties. The principle is separating who proposes from who has the last word, with a person holding that last word. On the night it was named, that happened to be two AI desks and I.
- The scrutiny has to stay proportional to the risk. A quiet draft and a live public site do not deserve the same gate.
- It is one worked example, not a proven method. This page will say so until there is more than a single night behind it.
It is a companion to vibe coding with veracity: that entry is about the record kept around AI-written code; this one is about who holds authority when the code is written by more than one machine.
The claims, classed
I sort what I publish by how strong the claim is, so here is this page graded by my own rubric. The classes are Observation, Hypothesis, Coined term, Internal result and Externally validated finding; each claim names its evidence and where that evidence comes from.
The ledger
“Human at the gate”, as a framing. Independently adopted framing, not mine to claim. The phrase and the broader approval-gate concept predate this account (Secure AI Lab, 17 July 2026, and others). This page documents my specific interpretation and one worked example.
“Two desks, one gate”, as a name for the method. A working name, not yet verified as original. It should be prior-art checked before it is claimed, the same check that found the earlier use of “human at the gate”.
The method described here was used on this site the night of 29 to 30 July 2026. Observation, an internal result. Evidence: the contemporaneous transcript and screen recording for the sequence and attribution; the repository working tree and build output for the technical changes and results. Internally documented, not independently validated.
Independent acceptance caught what the proposer’s own checks did not. Observation. Evidence: the same transcript and repository, showing the withdrawn sandbox claim and the two defects found only in use. Internally documented, not independently validated.
Two desks, one gate is worth adopting as a working discipline. Hypothesis. Evidence: one worked example, this site, on one night. Not tested anywhere else, and one night is not proof it generalises.
This definition, and the longer story
This page is meant to be the short, quotable definition of the method. The longer, first-person account of where it came from is the dispatch Two desks, one accountable editor: how the working pattern developed while I was building this site, what dyslexia has to do with it, and why the rules about provenance and preserved evidence are as strict as they are. This page is the definition; that one is the practice.