Essay · building · August 2026

The Grammar of the Second Surface

The Companion ended on a promise: the copyable mark is a compromise, to be retired the day something better exists. This is the something better — a typed grammar for keeping a conversation and an application in common ground — and its first increment is in production.

Two surfaces, one live object

The pattern this site keeps arriving at — chat on one side, an instrument surface on the other — has a hard problem at its seam. The conversation reasons and speaks. The surface shows, stages, and authorizes. But they are operating the same live object: the same correspondence, the same shared pages, the same order. Keep the two surfaces strangers and the user becomes the integration layer, re-describing to each side what the other just did. Merge them and you get the failure half this site warns against: the website grows a chat box, the chat grows buttons, and two half-products end up pretending to be each other.

The rule I hold is that the website never becomes a second chatbot. It stays an instrument — but an instrument that can receive and emit accountable acts. What was missing was a vocabulary for those acts: what the exchanges between a conversation and an application mean, independent of whatever transport happens to carry them. So I wrote one — a conversation-linked application grammar.

A WIDGET IN THE CHATTHE CHATyou“book the flight?”the assistantthe airline appin an iframe…the thread scrolls onsqueezed into the message streamTHE WEBSITE BESIDE ITYOUR CHATyouyour assistantreasons · authorsthe service's sitethe pagethe live objectshows · authorizesorient · pointreferences backcommitview moves freely; commitment is authorized on the site
The grammar's geometry: the refused widget on the left; on the right, two surfaces on one live object — orient and point flow to the site, references flow back, and the one gate sits exactly where the commit lane crosses the site's edge.

Write the conversations first

Method matters here, because it is the same method as everything else in the practice. The grammar did not start as a schema. It started as twelve concrete interaction sequences, written the way a conversation analyst writes transcripts — and deliberately including the breakdowns: the ambiguous selection, the denied approval, the stale view, the timeout, the resumption after a week away. Only then was the smallest grammar extracted that covers all twelve. Turn-taking, adjacency pairs, and repair — the apparatus I have used on transcripts since 1995 — turn out to be engineering primitives, not just reading instruments.

Seven families of acts

Every exchange the two surfaces need falls into seven families: Orient (present, open, focus, refine), Point (select, cite, attach, bind), Reveal (retrieve additional authorized evidence), Propose (stage, revise, discard), Commit (review, approve, execute, receipt), Repair (clarify, refresh, reconcile, retry), and Manage attention (notify, resume, close, expire). The governing rule: every cross-surface act either establishes common ground, changes reversible state, requests a commitment, reports an authoritative effect, or repairs a breakdown — and its type must say which. An act that won't say what kind of thing it is doesn't get to cross.

The accountable pair

The basic unit is borrowed straight from conversation analysis: the adjacency pair, engineered. A present expects a presented; a stage expects a staged; a human approval expects a committed — and each pair carries named repair branches: ambiguous, stale, denied, failed with nothing applied, failed with effect unknown. “Failed” must distinguish no effect, partial effect, and unknown effect, because those demand three different repairs.

The clause I care most about: a timeout is a missing second pair part, never an invitation to assume success. The assistant may say “sent” only after the authoritative receipt. Thirty-one years ago I watched a user read a frozen progress bar as progress — a system asserting a state it had not reached. The accountable pair is that observation made law: silence is not an answer, and no answer is not a yes.

A timeout is a missing second pair part — never an invitation to assume success.

View, proposal, commitment

State crosses the seam in three classes, at three speeds. View state moves fluidly — showing you something never needs permission. Proposal state is durable enough to inspect and revise, and reversible by design. Commitment state changes an authoritative record — a send, a purchase, a deletion — behind a deliberately visible boundary, and approval binds to a version of the thing approved, never to the drift of a transcript. Between the surfaces sits a small interaction ledger — active view, focus, selection, the active proposal and its version, the pending commitment, the last confirmed effect — so that neither side ever needs the other's whole state.

Two consequences do a lot of quiet work. First, selection is a communicative act: clicking three messages can mean “these are the ones I mean,” “use these as evidence,” or “this is my answer to your question,” and the grammar keeps merely-visual selection distinct from selection offered as conversational context. When the conversation says these, the reference resolves in a fixed order — explicit stable reference, then current selection, then focused object, then active view, then plain language, then a clarifying question — so deixis degrades gracefully instead of guessing silently. Second, events declare delivery classes — silent context, notify, interrupt, reply required — so “bidirectional” cannot degenerate into a website making the chatbot chatter.

Three rules from production

The grammar was derived on paper the same week Mail·Sum shipped chat-authored compose and site-authorized sending — an accidental conformance test. Production handed back three amendments, each now law across the family.

World reports. The grammar ends at committed, but the world answers back — attributed, unverifiable, sometimes days later. A bounce notice is not a revision of the receipt; it is a third epistemic class beside the product's facts and the product's receipts: recorded as reported, never as truth. The send row stays “submitted” forever; the world's answer stands beside it, not over it. The live case that earned the rule: a mail provider answered a send with a diagnostic that none of our fixtures predicted. A system that had hard-coded the expected answer would have recorded the wrong reason, confidently.

The material under discussion is not a participant. Selection-as-communication needs a rule about who may perform pointing acts: members and their gestures — never the content being discussed. A message body never gets a turn, so nothing inside it can select, point, or bind; the instrument refuses any act whose binding was not established by a member. That sentence is prompt-injection defense stated grammatically: the most a hostile document can ever do is be read.

Events carry references, never content. Whatever the instrument tells the host lands in a model's context, which makes every event an injection surface. So events carry IDs, versions, and counts; the host retrieves content only through authorized reads it initiates. The conversation learns that something was selected; it goes and looks for itself to learn what.

It shipped

Increment one is in production in Mail·Sum. A pairing code shown on the Companion, pasted once into chat, binds that conversation to that window — one instrument at a time, moved between devices by a deliberate tap. Orientation intents travel from chat to window; the window reports what it is showing back as references. The first live run: “Show my Mail·Sum correspondence with @wes on my Companion” — the handle resolved against the owner's own roster, the window turned in under a second, over ordinary MCP. And none of it needs a desktop app: a browser tab of chat, the Companion beside it, an ordinary protocol between them. The grammar assumes the web, because that is where the users are.

The same evening taught three lessons worth the whole day. A host answered and then asked whether it should orient the window — fixed in the tool contract: act, don't offer; view state never needs permission. A host tried to point at a person by email address — the validator refused it, correctly, and the fix was teaching the intent the grammar's currency, the @handle. And a host routed a generic “my correspondence” question to a different mail product entirely — the lesson that routing is member-side: no server can reach a conversation that never calls it, so the member names the product. That is what the marks are for.

The transport, incidentally, has just agreed with the shape. The July 2026 revision of MCP removes protocol-level sessions; a server that needs continuity now mints a handle the model passes back as an ordinary argument. Continuity belongs to the product, not to the connection — which is where this grammar had already put it (Don't Make the Tool Semantic).

The industry is arriving at the door

The pattern is no longer private. In July, OpenAI's CEO demonstrated — from one spoken sentence — ChatGPT planning a group trip and generating a full-stack website where nine friends could weigh options and vote: the conversation plane conjuring an instrument plane out of nothing. Read as grammar, it is the first pair part of the first sequence, with no second pair part anywhere: nothing returns. No selection, no focus, no acknowledgement, no version. The agent knows the page only because it wrote the page — deixis by authorship — which works exactly as far as objects with no authority boundary, and a disposable trip page is pure view state. It stops where the ambition points next: an approval must bind to a version of something real, and you cannot regenerate the thing that holds the state (the commerce essay takes that seam up in full).

The same month, ChatGPT's Chrome extension began carrying a highlighted passage into its side panel as a visible selection — a member's gesture becoming conversational context. That is a real Point act, and a real step; but the binding is the host's, with no application-minted reference, version, acknowledgement, or receipt behind it. And the agent desktops now ship per-chat browser panes the agent can open and drive. The shell is ahead of the contract. Each of these is a host learning half the grammar — and the missing halves, acknowledgement, versions, receipts, repair, are precisely the application's half to supply. That seam is what this grammar fills, from the application side, for any host.

The website never becomes a second chatbot. It stays an instrument — one that can now listen.

The constitution of the second surface

Why a grammar and not a feature list? Because this seam is about to be everywhere. Every serious service is going to face the same fork: put a chat box on the website, or teach the website to hold a typed conversation with whatever chat the user already keeps. Everything this site argues about the forum — named speakers, visible acts, commitments that execute where they can be honored (the rules) — reappears at this seam in miniature. The forum is that discipline among many participants; the grammar is the same discipline between the two surfaces of a single product. They are also this site's two standing bets — independent, and to my mind equally consequential: the forum answers who speaks; the grammar answers where the software lives. And both come from the same place: treating interaction as a sequence of accountable turns, which is what I have been doing with transcripts since a PDA study in 1995. The categories held. They were never just for reading.

Essay — building. The conversation-linked application grammar, shipped first in Mail·Sum. ← All essays