KymiraCertified BI

Failure catalogue · The verification is theater · 34 of 51

OBSERVED FAILURE MODE

Detection without disclosure.

The screen catches a suspect value and the check table counts the flag. The certified page beside it shows the figure at face value, with no marker, no share of the headline, and no what if. A flag that stops before the render is a detection the reader never receives. The build has contradicted itself and shipped anyway.

What we saw

In our own audits a plausibility screen raised a flag on a value feeding a headline. The check table counted the flag. The certified page beside it showed the figure clean, with no marker on the tile, no share of the headline, and no what if. Every rollup containing the row showed it clean too, and so did the export. Detection happened at every step except the one the reader sees. Someone comparing the check table with the page would have found the contradiction; nobody compares.

Why it passes a glance

Detection and disclosure are different code paths, and usually only the first is tested. The check table is evidence that the system works, which makes the page beside it more convincing rather than less. A marker that never renders leaves no gap, because a missing glyph looks exactly like a value with nothing to declare.

What addresses it

The honest-dataviz skill defines the third figure state: a value that ties to its anchor but rests materially on a flagged row wears the flag glyph at every point of display, tile, bar, and label, with the flagged share in the caption. Principle 11, reconciliation proves arithmetic not plausibility, requires the full path, stakes, what if, and the glyph at every render, aggregates included.

Check your own file in two minutes

  1. Take a flag the checks recorded and search every rendered surface for its marker: tile, chart, table, rollup, and export.
  2. Confirm the flagged share of each headline the row feeds is printed beside the figure.
  3. Confirm a labelled what if figure exists for each open ruling branch.
  4. Treat any figure the check table doubts and the page shows clean as a failed build.

What this does not catch

The disclosure path makes a raised flag unavoidable. It says nothing about a value the screen never flagged, and a flag with no stakes attached is a disclaimer rather than a doubt. Marking a figure is not the same as correcting it, and the correction needs its own ruling.

Quick answers

Why is undisclosed detection worse than no detection?
Because the system reports a safety it did not provide. A check table that counts a flag the page denies is a manifest contradicting its page, and a reader who trusts the check table trusts a figure the build already doubted.
Where does a flag have to appear?
At every render of the affected figure, aggregates included. The marker travels to every rollup, region, month, and total containing the row, and into the CSV, the spreadsheet, and the board pack.
What does a flagged figure need beside the marker?
Its share of each headline it feeds, and a labelled what if value computed under each open branch. A named doubt without its cost is a disclaimer, not a doubt.

Nearby failures

The screen calibrated by its own targetThe verification is theaterThe manifest that contradicts its pageThe wrapper betrays the numbersThe 100x slip that ties perfectlyThe number is plausible, and wrong

Last updated 2026-09-02 · Dylan, founder · one of 51 observed failure modes, every one seen in a real build or in our own audits, none invented.

Get the free skill → The doctrine All 51 failure modes