Failure catalogue · The verification is theater · 42 of 51
OBSERVED FAILURE MODE
The honest refusal that catches nothing.
A plausibility screen calibrated from the data it screens is circular, because the slip becomes its own ceiling. Closing that circle without naming a workable substitute produces screens that decline to calibrate at all, report themselves uncalibrated, and let a hundredfold quantity slip certify exactly as cleanly as before. A refusal to screen is still an unscreened column.
What we saw
In our own audits, three builds were told not to calibrate a screen from the data it screens. All three stopped calibrating. Each reported itself uncalibrated, plainly and in writing, and each certified a hundredfold quantity slip as cleanly as the builds before them. Nothing was hidden and nothing was caught. The reader saw a page saying the screen had not run and a headline carrying the inflated figure, and no rule connected the two, because the wording had already been satisfied.
Why it passes a glance
A build that declines to calibrate looks like a build obeying the rule, and its own report says so. Declining reads as caution rather than as a gap, so nobody grades it against the harm. Meanwhile the certified page renders the same as a page whose screen ran and found nothing, so the distinction that decides whether a figure is trustworthy never reaches the reader.
What addresses it
The trust-the-upload skill puts the plausibility screen, both directions, into the fixed landing pass every file walks before anything is certified. Doctrine principle 11, Reconciliation proves arithmetic, not plausibility, names the always-available basis: compare each value against its group's distribution computed with that value excluded, since a slip cannot move a median it is not part of, and no figure resting on an unscreened column may be called certified.
Check your own file in two minutes
- Name the screen's basis out loud: a configured tier list, a stated outside prior, or a leave-one-out read.
- Confirm a group too small for a leave-one-out read is reported by name rather than as a whole unscreened column.
- Multiply one quantity by a hundred in a copy of the input and confirm the flag reaches every headline that row feeds.
What this does not catch
A leave-one-out screen catches values standing apart from their own group. It cannot catch an error applied consistently across a whole group, or one landing inside the normal range. It raises candidates for a person to rule on, and it never decides on their behalf.
Quick answers
- Is reporting a column unscreened good enough?
- It beats a false green and it is worse than a screen. The page must name which columns and groups went unscreened, and no figure resting on one may be described as certified while the gap is open.
- What is a leave-one-out basis?
- Each value is compared against its group's distribution computed with that value excluded. A slipped row cannot move a median it is not part of, so the basis is non-circular by construction and needs no configuration to work.
- What if a group is too small to screen?
- With fewer than four other rows the screen reports uncalibrated for that group by name, not for the whole column. A screen that refuses everywhere and one that ran and found nothing must never render the same.
Nearby failures
Last updated 2026-09-02 · Dylan, founder · one of 51 observed failure modes, every one seen in a real build or in our own audits, none invented.