Failure catalogue · The verification is theater · 33 of 51
OBSERVED FAILURE MODE
The screen calibrated by its own target.
A plausibility screen compares each value against a ceiling derived from the same column it is screening. One extreme value raises the ceiling that would have caught it. A threshold a slip can move is a threshold that slip passes. The screen runs, reports clean, and certifies the value it was built to find.
What we saw
In our own audits, an outlier ceiling was derived from the data being screened. A 100x slip lifted the basis it was measured against, cleared the threshold it had just raised, and the screen reported nothing. Every other check was green, so the page carried a certified figure resting on the value the screen existed to catch. The screen was not skipped and did not error. It ran, produced a verdict, and the verdict was clean because the reference was contaminated by the candidate.
Why it passes a glance
A completed screen on the page reads as stronger evidence than no screen at all. Circularity is invisible in output: a clean verdict from a contaminated basis looks exactly like a clean verdict from a sound one, and a total that ties to the cent supports the headline either way, because the slip multiplies through every sum consistently.
What addresses it
The trust-the-upload skill runs the plausibility screen in both directions as a fixed step of the landing pass, before anything is promoted. Principle 11, reconciliation proves arithmetic not plausibility, forbids a basis derived from the candidate value and names three that are not: a configured tier list, a stated outside prior, and a leave one out read that excludes the value being screened.
Check your own file in two minutes
- Ask what the screen compares each value against, and whether that reference includes the value itself.
- Recompute the group's typical value with the suspect row excluded, then compare again.
- Screen the quantity columns as well as the price and amount columns.
- Where a group is too small for a leave one out read, mark that group unscreened by name rather than passing it.
What this does not catch
A non circular basis catches a slip that is extreme against its group. It does not catch an error that is plausible for its group, and a group with too few other rows cannot be screened at all. An unscreened column is stated as unscreened, and no figure resting on one is described as certified.
Quick answers
- What is a leave one out basis?
- The group's typical value computed with the candidate row excluded. A single slipped row cannot move a median it is not part of, which makes the comparison non circular without needing any configuration.
- Why screen quantity columns?
- Because a fat fingered quantity certifies exactly as cleanly as a fat fingered price. Seats, units, and counts multiply through every sum consistently, so reconciliation stays green while the headline is wrong.
- Is refusing to screen a safe outcome?
- No. An unscreened column is unscreened however principled the refusal was. The page names which columns and groups went unscreened, and a screen that refuses everywhere never renders like one that ran and found nothing.
Nearby failures
Last updated 2026-09-02 · Dylan, founder · one of 51 observed failure modes, every one seen in a real build or in our own audits, none invented.