Manish Karney

Field notes / 2018 · Family Link · The autonomy transition

The account belongs to the teenager

Parents wanted to supervise teens who already had real digital lives. But that account was the teen’s — which made consent, and the exit, the whole engineering problem.

Live question

When a parent wants to supervise an account that already belongs to a teenager, who is allowed to say yes — and who is allowed to leave?

5 min read
AutonomyConsentSafety

The unmet ask is simple to state and hard to honor: parents want to supervise teenagers who already have Google accounts. Not new accounts created for a child — live identities with years of mail, contacts, purchases, sessions on a dozen devices, third-party apps they’ve granted access to. Everything in the original product assumed a parent creating an account from nothing. Here the account exists, it is in active use, and it does not belong to the parent. It belongs to the teen.

That single fact reorganizes the design. If the account belonged to the parent, supervision would be configuration. Because it belongs to the teen, supervision is a transfer of administrative power over someone’s digital life from that person to another, and the only thing that makes such a transfer legitimate is real consent from the person losing the autonomy. So I will not let a parent unilaterally place an existing account under supervision. The flow is initiated by the parent and finished by the teen, and ‘finished’ means the teen re-enters their own password, presence and identity and a deliberate act, after being shown plainly what a parent will and won’t be able to see and do.

The harder half is the exit. If a supervised teen can silently switch supervision off, the whole thing is theater and no parent should trust it. If a teen can never leave, we have built coercion and handed it a logo. Both of those are real failures, and they pull in opposite directions, and I have to choose a single behavior that sits between them.

If exit is silent, supervision is theater. If exit is impossible, supervision is coercion. The escape hatch has to be real and never quiet.

What I landed on: the teen can always unlink, from the on-device app and from every new sign-in screen, so it can never be hidden from them — but leaving is not free of consequence. The parent is notified. There’s a short, cancellable countdown. Then previously supervised devices lock until a parent unlocks them. The lock signals that trust was renegotiated, so the family has to talk. When a parent ends supervision, it costs the teen nothing. The asymmetry is the point: leaving is always available, never invisible.

Then there’s the case that haunts the whole design. What if supervision was set up on an account without the owner’s knowledge — someone who has the teen’s password, in a home that is not safe. A consent flow can be abused as easily as it can be honored. So the ‘about supervision’ surface has to anticipate that exact person: tell them plainly that someone else may have their password, that they should change it now, and exactly how to unlink. I cannot design only for the cooperative family. The same tool that gives an anxious parent peace of mind can, in the wrong house, become an instrument of control, and the product has to leave a door open for the person it might otherwise trap.

What I still can’t resolve is whether the lock-on-exit is a fair deterrent or a small cruelty in the homes that need the escape hatch most. I’ve weighted it toward the parent’s awareness because a supervision tool nobody trusts is useless. But I am not certain that’s right, and I notice I keep the question open on purpose.