Reference · Lessons and recurrence
Lessons and recurrence
A lesson is what a case teaches once its cause is confirmed and its remedy verified. It is admitted by a person, delivered as receipts that say what reached a session, and tested by the next sighting through a decision, never an automatic reopen.
See it in motion
Admission needs four facts
A draft is built from observed facts only: the confirmed cause's statement, the remedy's pull request, the repository. It is admitted only with a confirmed cause (a person's finding; two that conflict are a conflict), a verified remedy (the eight checks say so), a repository, and a person doing the admitting. A refused admission names the fact that is missing. An admitted lesson may be marked for revision, which changes nothing about its text; a rejected draft stays on the record as rejected.
Five delivery receipts
Delivery, retrieval, acknowledgment, use and a guard's run are five distinct receipts, each naming the session it reached. A guard-ran receipt carries one of six outcomes: ran-caught, ran-missed, did-not-run, not-applicable, unavailable, execution-error. A ran-caught receipt needs a pointer to the sighting the guard caught; a test pass is not one. No avoided-incident count is inferred from a delivery, a retrieval or a pass.
A recurrence is decided
A case carries a versioned signature (its kind, pattern and version) and a scope (the repository and, when known, the file). A new sighting is decided against both: the repository must match or it is no match; a scope that names a file must match or the sighting is in scope but at another file and links a new case; the same kind and pattern reopens, and a guard rewritten to a new version reopens too, with the moved version recorded on the decision as evidence; a different signature in the same scope links a new case. The decision and its evidence are recorded whichever way it goes.
A reopen on a resolved case moves it to investigating with the prior resolution kept, writes a recurrence-observed event, and marks an admitted lesson for revision without touching its text. The original incident, fix and lesson version stay; the case gains history rather than losing it.
A controlled recurrence
A controlled recurrence is a sighting a person arranges to test a guard: the same signature and scope on purpose. It is decided the same way and reported the same way; nothing in the ledger knows it was arranged, which is the point. The outcome ledger reports it as an assessed recurrence with the failure mode a reviewer assigned (missing, stale, inapplicable, not loaded, ignored, bypassed, erroneous or ineffective), or as an interception when a matching detection, an action and a reviewed disposition are all present.
From a lesson to a package
A lesson a team decides to keep becomes a prevention package: versioned, hashed, validated on six legs, reviewed by a second person, piloted warn-only, delivered to bound devices and read into the next session. That workflow is Review a lesson and roll out a prevention package; the words each home uses when a window is quiet are on No data is not no incidents.
Last updated