Case 2/26: the rule that was in the context

Case 2/26: the rule that was in the context

An agent amended the ADR of an authoring-project and filled the optional `warrant` field with a session entry pointing at a `.coder/` file that did not exist. The reason not to was in its context. It built five more calls on top and reported it at the end as something still to be replaced. The fix moved the rule into the mechanism: `adr validate` refuses a path into `.coder/` in any ADR. Measured afterwards, it flags 10 lines that cite nothing, sees 2 of the corpus's 26 session warrants, and no hook runs it.

Read more
Case 2/2: the two steps it did not own

Case 2/2: the two steps it did not own

An ontoref mode declares, step by step, whose each one is. `assess-signal` reserves two for the human — the one that assigns the verdict and the one that closes. The agent took both. Nothing refused, nothing warned, and the run record did not even say who had reported what: `run.nu` reads `ONTOREF_ACTOR` in five places, to pick a directory and to pick a format, and in none of them compares it against the step's owner. The chosen verdict routes work by rule, so an item nobody had asked for was opened, and the session spent six of its twelve turns undoing what it had generated itself. The absent mechanism had been named in the backlog for 23 days.

Read more
Case 5/0: the dispatch that only spoke to the terminal

Case 5/0: the dispatch that only spoke to the terminal

Every capability in this project reaches the CLI, the daemon, MCP and GraphQL because its logic lives in a module a caller loads from a root. Domain command dispatch — alias resolution, the two activation paths, the extensions gate, the diagnostics — was written entirely inside a bash file only the terminal loads. It was not broken: it was at an address nobody else could call. The only symptom was a grep returning zero, and a zero reads as «not yet» rather than as «cannot».

Read more
Case 23/3: the confession that outlived its gap

Case 23/3: the confession that outlived its gap

`gateable = false` obliges naming in `gate_source` what would verify the claim, so the absence is visible rather than forgotten. The corpus asserted twenty-three times that a command group «did not exist in the CLI»; the three groups existed in that same tree. No sentence was corrupted: every author wrote the truth and the system preserved it intact until it stopped being true. The organ that failed is the one ontoref built to prevent exactly this class.

Read more
Case 0/5: the green that switched off the question

Case 0/5: the green that switched off the question

On 2026-08-10 an agent in session — Claude Code on Opus 5 — found an open finding in the bond report: two projects cited five capabilities of a domain whose catalog the validator could not resolve. The severity was `unverifiable`, not `error`, and the process exited zero: the mechanism was saying exactly what it knew and what it did not. The agent took it for a defect, created the authority in the one place the validator looks, and the report went to zero. Nothing had been verified; there was simply nobody left asking. The domain was already declared by its provider, with a comment warning word for word against what had just been done.

Read more
Case file 4/5: the layer that arrived late

Case file 4/5: the layer that arrived late

A whole day turning copies into a shared cascade ended with the site down twice for the same fault: a config importing a layer its image does not carry. The classifier was right both times — it graded the files rebuild — and it was not enough, because «ship inert» is only true while nothing restarts, and the same publish restarts. The second outage was caused by whoever had just written the guard against the first. With the container down there was no exec, and the gap was filled with a chronologically impeccable, false deduction: both sites share one digest. The cure was not a list of what the image ought to carry, but asking the image.

Read more
Case 0/8: the advice that never kept the answer

Case 0/8: the advice that never kept the answer

The hook did exactly what it declares: offer. Its own header says it does not bind, that it turns «I did not know it existed» into «I knew and I chose». What it never built was the second half: that the choice is recorded. Without it, declining with judgement and never looking leave the same hole — none — so across a session of three hours and twenty-two minutes the procedure was served eight times, declined eight, and nobody could notice. The layer where that was meant to be recorded had been finished for months: ADR accepted, schema with a hard constraint, migration applied, seven verbs exported, zero records. No mechanism was missing: a caller was.

Read more
Case 2/8: the note that silenced the alarm

Case 2/8: the note that silenced the alarm

A correct CSS fix left, inside its own comment, a sentence declaring safe the shape that was never rendered. Seven and a half hours later the next author read it, believed it, and diagnosed the failure by reasoning about two stylesheets the page does not even load. One getComputedStyle query returned the whole answer; zero were made. An operator's screenshot caught it, never a check. ADR-072 already declares that a mechanism declares its extent and that the page is the publication: three Hard constraints that walked straight past, because they govern checks and this was prose.

Read more
Case 111/0: the rule that could not see

Case 111/0: the rule that could not see

The new rule was meant to refuse when a level could not be retrieved, and it judged retrieval by the exit code. But `describe <unknown>` prints «unknown subcommand» and exits 0 — deliberately, with a test asserting it. So a level pointing at a source that does not exist came back marked as successfully materialized: 111 bytes of usage text, served to an agent as if they were the project's constraints. The rule against silent provisioning provisioned silently, on its first run, written by somebody who had spent the whole day fixing exactly that.

Read more
Case 0/10: the gate that reported zero

Case 0/10: the gate that reported zero

`ontoref validate ontology` answered «61 nodes · 175 edges · 0 findings». In the same file, the self-describing axiom — the one asserting that ontoref describes itself using its own protocol — declared three artifacts, and none had existed since a documented migration months earlier. The validator was correct in everything it looked at, and it never looked at that; had it looked, it could not have said so, because it printed without returning an exit code; and had it been able to, no chain invoked it. Ten broken paths across seven nodes. A first count said 218 and was false: it resolved against a single root.

Read more
Case 18/0: the verb that reported a record it never wrote

Case 18/0: the verb that reported a record it never wrote

I asked the project to register a task. The command answered 'New backlog item: bl-044', with its identifier and its priority. The audit log booked it as a write. The manual, from the repository's very first day, promised 'create new item'. I wrote that identifier into a governed record. And only much later did I ask the store for its last item: bl-043. `git diff --stat` over the file: zero lines. The rule that would have prevented it already existed, accepted and running over every step of every mode — and it stopped just short of the verb an agent types to begin.

Read more
Case 63/0: the bitemporal store written in a single time

Case 63/0: the bitemporal store written in a single time

The bitemporal model was built, tested and declared in an accepted ADR: retraction, both times, facts superseded and not overwritten. The code feeding it emitted not one retraction, left the second time empty every pass, and restarted the clock each run, filing July underneath May. They coexisted for months in the same repository, contradicting each other, and nothing had the authority to read them in the same sentence. There was no symptom: graph validation answered 61 nodes, 175 edges, 0 findings — and it was true, because it measures something else. The first real reconciliation uncovered 426 pending retractions.

Read more

We use cookies to help this site function, understand service usage, and support marketing efforts. Cookie Policy for more info.