P. Tolkachev
05Platforms & infrastructureAugust 20258 min

Platform versus institution

What changes when the infrastructure of shared life becomes private.

The words "platform" and "institution" are easy to confuse. Both are something large that shared life rests on, something you reach for without thinking, as if it were self-evident. But look at how each is built from the inside and the difference turns out to be enormous. And more depends on it than it seems at first.

An institution is obligated, a platform provides

An institution, a school, a court, a postal service, a university, carries obligations. It exists for a particular purpose, it has norms, and it can be held to account: there is a procedure and, in the end, a door you can knock on. A platform is built the other way. It provides the possibility of connection and takes its cut. It owes nothing; it optimises. When a platform says "we only connect people", it sheds institutional responsibility and keeps infrastructural power.

What it means to become private

When the infrastructure of shared life, of communication, commerce, work, knowledge, passes to platforms, it becomes private in two senses at once. In ownership that is obvious. But the logic changes too. The rules are now set by a product decision rather than a public procedure. They can be changed with an update, without explanation and without debate. What used to be a matter of norm and dispute becomes a matter of configuration.

Over the past twenty years huge areas of shared life have quietly moved into environments where there is neither a citizen nor a procedure. There is a user and an interface.

The flag someone forgot to turn off

Here is a concrete case. For several years I built out Unleash where I work, a feature-flag platform, the machinery that lets you switch on new product behaviour for a fraction of users without shipping a release to everyone. A wonderfully handy thing. One day, going through old flags before a migration, I came across one: enabled for five percent of users and forgotten for about a year. Someone had set it up for an experiment, the experiment was never finished, and the person, it seems, had left the company long ago. Five percent at the scale of a bank is tens of thousands of people who spent a whole year living in a slightly different version of the product. No ill intent, no record of who decided this or why. Just a checkbox with no one left to uncheck it.

Tens of thousands of people lived in a different version of the product for a year, and no one was left who could say: I decided this.

In an institution a decision like that would leave a trace: an order and a signature. Here the trace was a line in a config and, if you were lucky, a commit in the history. After that we set a rule: every flag has an owner and a lifespan, and when the lifespan runs out the flag goes to review. A small bureaucracy we put on ourselves, because we had felt something simple. Without it the environment becomes irresponsible in the literal sense of the word: there is no one in it to answer.

Efficiency as an argument

A platform almost always beats an institution on convenience. Faster, cheaper, and it asks almost nothing of you by way of learning. The advantage is genuine, and that is exactly why the shift feels natural and barely needs defending. An institution is slow partly because it is accountable: procedure and appeal, the very brakes a platform proudly removes.

It would be easy to object that I idealise institutions. The post loses parcels, a court drags on for years, university bureaucracy can strangle any living thing. People go to a platform out of despair, because the institution failed them first, and I have chosen the app over the queue at the window a hundred times myself. All true. But a bad institution has a broken accountability mechanism, and a broken thing can still be fixed: there is somewhere to complain, there is a norm against which you can see that it works badly. A platform has no such mechanism by design. There is nowhere to bring a grievance, because no one promised anything in the first place.

So the question is not which is better in general. The question is what we give up along with the slowness, and whether we notice that we gave anything up at all.

The engineer's view

Here engineering and theory meet in the most literal way. Whoever builds platform tooling, and I build it every day, makes decisions of institutional scale in the guise of product ones. Who has access to the switch in production and who does not. What lands in the log and what vanishes without a trace. Which behaviour the interface quietly encourages and which it buries so deep that people stop using it. How long a flag lives before someone asks what it is even for. In review all of this looks like routine: "wire up an audit", "hide the button behind a flag". In substance it is the constitution of an environment, written in passing, in pull-request comments.

Once we argued about who should get the right to flip flags in production. Giving it to product managers is convenient: they own the features anyway, no need to summon an engineer for every little thing. But it means a person can change the product for hundreds of thousands of people with one click, without review, without a second pair of eyes. In the end we made critical switches require a second person's confirmation. A small separation of powers, dreamed up on a forty-minute call. None of us thought at that moment that we were doing constitutional law, though that is more or less what we were doing.

I am not calling for a return to institutions, and I am not proposing that we reject platforms. That is impossible, and unnecessary, and, if I am honest, I love what I do too much to want it seriously. The speed is real, the convenience is real, and I create it myself every sprint. I am calling for designing with the scale in mind. If a platform takes on the function of an institution, it is worth at least asking whether it takes on its responsibility too, and if not, who is left carrying it. In a product framing that question is almost never voiced. I do not always ask it myself, and when I do it comes late, usually while I am going through yet another forgotten flag. But asking it, it seems, is still part of my job. It just is not written in any ticket.

Back to writing© Peter Tolkachev · MMXXVI