Reference · One incident across the six homes
One incident across the six homes
A labeled synthetic walkthrough. Every name, number and receipt below is invented to show the shape of the workflow; none entered a production incident total, and no screenshot here is a production screenshot. The evidence-backed version of this page, recorded from a real authorized case, waits on the production credential and is named as such in the ledger.
1. Today: the queue names one next action
Acme's team opens Today. The five figures read: 3 open cases by class, 1 fix waiting at the gate, 0 cases past their SLA, 4 source families observed, build spend at 12 percent of the cap. Security reads no source, because no security source is connected; that is not a clean scan. The predicted next action is the oldest critical case: Checkout returns 500 after the release, a production case opened from a Sentry issue and a manual report that landed on the same case through the deduplication key.
2. The case: understand the change
The case opens in place, seven sections in one order. Evidence shows the Sentry issue with the source's health at the sighting (ok) and the manual report with its reporter. Attribution walks from the deployment to the commit to the changed file to the session that produced it, each edge with its confidence and its gap: the session reference the source supplied is reported context until the trace confirms it, and here it does. The session's prompt text is read locally on the developer's machine on demand; it never crossed. Security says not a security case with the versioned rule that decided it.
3. Verify the remedy
A person records a hypothesis, then confirms the cause: the generated client retried without a bounded deadline. The proposed remedy is a pull request. The exact-scope approval binds to the action, the files, the brief, the target and the policy version; the desktop app verified the digest before the approval landed. The eight checks are recorded one by one: builds, tests, regression, the guard replayed against the introducing commit and blocking it, the pull request's own checks, the reproduction, the deployment, and a two-day observation window with no matching sighting. Cost carries one measured charge from the remediation loop and one estimate a person entered with its rate and hours, shown apart and never added.
4. The lesson and the package
With a confirmed cause, a verified remedy, a repository and a person, the lesson is admitted. The team writes version 1 of a prevention package, sets the criteria first (40 reviewed legitimate executions, no more than 5 percent false positives, 5 held-out cases), and runs the six legs. The guard leg times out once, which the ledger keeps as an infrastructure error and not a failure; a rerun passes. A second person, neither the owner nor the drafter, approves; the approval binds to the hash. The package pilots warn-only on one repository, then publishes.
5. Delivery: the next session
Two bound laptops pull the delta after their cursors. Each stages version 1 by a temporary file and a rename, rebuilds the manifest, writes the curated block into the repository's instruction files, and acknowledges delivered and installed by exact hash. One laptop is offline for a day; it keeps its last manifest, shows it as stale, and reconciles on its next pull. The next session on each laptop starts with the package in context and leaves a retrieval receipt.
6. The outcome, in its denominators
A week on, the case's Outcome row reads: delivered to 2 of 2 targeted devices, installed on 2; executed in 3 of 5 eligible sessions; no matching recurrence observed during this covered window; no detections. Effectiveness reads no-recurrence-observed across 3 of 5 sessions, with the two sessions the guard did not run in named as the gap, not as protection.
The missing link
The observed-use receipt. The retrieval receipt says the package was in context; whether the assistant followed it is a receipt the assistant's hooks write, and in this walkthrough none did. The ledger says retrieved, not observed used, and the case does not claim the session used the lesson. A walkthrough that filled that link in would be the kind this program refuses; the honest reading is that use is unverified until a hook records it.
The workflow step by step: the incident case, verified recovery, review a lesson and roll out a prevention package, no data is not no incidents.
Last updated