Kymira · 40 terms
GLOSSARY
The vocabulary of a certified number.
Forty terms the Kymira doctrine uses when it talks about numbers: anchors, rails, gates, forks, and the several ways a report can look proved without being proved. Each entry names the failure it exists because of, links to the principle that closes it, and states what the term does not cover.
Why does each term name a failure?
Because every one of these words exists to describe something that went wrong on a page somebody acted on. A term with no failure behind it is a preference, and preferences do not belong in a method.
The 40 terms
| Term | What it means |
|---|---|
| BLOCKED report | The page a build writes when it stops. It carries every check verdict earned before the stop, the named reason for stopping, and no certified figure. A stack trace is not a deliverable: a refusal that leaves a log line and an empty folder discards the verdicts the file had already earned. |
| Borrowed evidence | Two or more checks citing the same fire test log as proof, so one captured red run stands in for several guards and proves none of them. Every check needs its own evidence file naming that exact check. Shared proof is how a gate that looks fully evidenced ends up covering a single rule. |
| Both rails from one blueprint | The failure where a two rail check builds both rails from the same field list, the same parse, or the same helper, so it compares values to themselves. Agreement is then guaranteed and proves nothing. Independence has to go all the way down, and shared logic is disclosed and counted as a single read. |
| Calendar fork | The retail and finance calendar choice, 4-5-4 against 4-4-5 against thirteen periods, which is almost always silent in the data and shifts every comparison that crosses it. The calendar is a recorded ruling, carried by the period label itself, not a convention each report is left to infer. |
| Certified deliverable | A rendered, self contained HTML page plus its machine artifacts: the data, the checks log, and the manifest, each sibling linked from the page. The definition sits beside every number and the check results are visible on its face. Markdown alone is a draft, because a buyer forwards a page, not a repository. |
| Certified vs certified-looking | The distinction the whole method exists to draw. A certified-looking page has a checks panel, green marks, and a confident layout. A certified page can name the input that would have turned each of those marks red. Everything else, the panel, the marks, the layout, is available to anybody. |
| Circular check | A check whose verdict is derived from the thing it is meant to test: a total computed from the rows it checks, a screen calibrated on the value it screens, a verdict read from the configuration that produced the build. A check that consults its own input is a mirror, not a gate. |
| Claim vs system of record | A platform's own number is an assertion by an interested party on its own window and model; a system of record figure comes from the store, the ledger, or the ERP and ties to an anchor. The two sit side by side and never sum, because adding claims to measurements invents revenue nobody made. |
| Control total | The figure a file publishes about its own contents: the grand total on a ledger export, the record count in a report footer, the deposit amount on a settlement statement. A control total is evidence, never a row to sum, and a pipeline that adds it to the detail it summarizes doubles the answer. |
| Definition drift | What happens when the same formula or reference table is copied into several scripts and updated in only some of them. The stale copy keeps reporting correctly from the wrong facts, which is exactly why it survives review. One stored definition is executed directly, or re-derived by a check that fails naming the key. |
| Doctrine gate | The mechanical gate shipped with the packs and run over a finished deliverable folder before anything is certified. It enforces what a script can prove: file hygiene, leaked local paths, prose figures against machine output, byte verified hashes, and fire test evidence for every rendered PASS. A green gate is necessary and never sufficient. |
| Dual rail | Computing a published value twice by two routes that share as little logic as possible: once by where it sits in the file, once by the label beside it. Both must agree within a tolerance written down in advance. Disagreement is a refusal to publish, never a warning to dismiss. |
| Fail closed | A failed check blocks the update instead of degrading it. The last known good version stays live and marked, a person is told, and no partial figure slips out under the old heading. Failing closed is an artifact, not an exit code: the build still writes a page carrying every verdict earned before the stop. |
| Filename lie | A file named by the system that produced it rather than by what it holds. A file called weekly_sales.csv may contain last week, another account, or both. Never compare a filename derived value against itself, which is a test that passes every time and proves nothing about the contents. |
| Fire test | A test that feeds a guard known bad input through the deployed production path and watches it turn that exact check row red. A check nobody has watched fail is a comment with a runtime cost. Passing on good input proves the guard runs; only a captured red run proves it can stop anything. |
| Fire-test theater | A test that re-implements the guard's comparison inline instead of calling the deployed guard. It stays green forever while the real guard is broken, and the suite reports a passing test named after the check. The evidence has to come from the production code path, not from a second copy of the rule. |
| Flag stakes | What a flag must carry to count as one: the flagged row's share of every headline it feeds, at every level that contains it. A named doubt without its cost is a disclaimer, not a doubt, and a reader who cannot see what a suspect row is worth will either ignore it or discount everything. |
| Grain | What one row of a file actually represents: an order, a line item, a day, a store week. Grain is the question to answer before any sum, because an export that repeats the order total on every line item will inflate revenue by the average number of lines per order. |
| Honesty strip | One line above the content that leads with what was proved: what ties, what was computed but unverified, what went unscreened, and as of when. A page that shows only its passes is reporting a safety it never provided. The strip is where a hurried reader meets the limits first. |
| Join coverage | The share of rows that found a match when a table was joined to a reference. It is published as a number with a configured threshold. An unpublished coverage figure is how a join that dropped a third of the rows still reports a confident average of whatever happened to survive it. |
| Leave-one-out basis | Screening a value against its own group's distribution computed with that value excluded. A single slipped row cannot move a median it is not part of, so the basis is non circular by construction and needs no configuration. It is the always available answer to a screen that would otherwise refuse to run. |
| Painted row | A check row whose verdict text is fixed in the template while the scan's real findings are computed and discarded. It renders green beside gates that can actually fail, indistinguishable to any reader. A row that no input can change is deleted, not rendered, or demoted to INFO, which claims no guarantee. |
| Period from contents | Establishing which period a file covers from the rows and the pre-header metadata inside it, not from its name or its download date. The contents decide the period. Where a file carries no internal evidence of what it is, that absence is stated on the page rather than assumed away. |
| Plausibility screen | A pass over every value column, prices and rates and amounts and equally the quantity, seat, and unit columns, comparing each value against its group's typical value in both directions. A total that ties to the cent can still be a hundred times wrong, because a slipped value multiplies through every sum consistently. |
| PROPOSED ruling | The status a fork ruling takes when nobody can be asked: an unattended or scheduled run records the fork, both readings with their numbers, and the provisional reading it chose, then publishes behind a visible flag. A ruling converts to active only when a named human ratifies it with their own timestamp. |
| Provenance record | The trail from a published figure back to the archived source bytes: the raw file as received, the script that transformed it, the check log, and the manifest that hashes them. A first transformation done by hand and never preserved makes every number downstream unreproducible, however carefully it was computed. |
| Reconciliation anchor | A total the source file states about itself, a printed grand total, a totals row, a stated base, that every computed figure must tie back to. The anchor is the only check a vendor cannot argue with, because it compares your arithmetic against the file's own claim rather than against your second attempt at the same sum. |
| Refuse, don't guess | The rule that ambiguity is an error to raise, not a heuristic to apply. A label that appears zero times or twice, a date that parses two valid ways, a missing expected column: each stops the build and names what was ambiguous. Guessing past ambiguity is how wrong numbers get published. |
| Relabel, never revalue | The line between cleaning data and authoring it. You may change what a row is called: normalize a name, unify a date format, classify it, join it to a reference, drop a proven duplicate. You may never change what a row says. After cleaning, the anchor must still tie, because relabelling cannot move a sum. |
| Ruling | A recorded answer to a metric fork: durable, attributed to a named person, reviewable, and reversible. It is asked in business language with the consequence stated, then stored once and applied everywhere. A ruling turns a definition argument into a fact the pipeline can enforce instead of a meeting that happens every quarter. |
| Staging swap | Assembling every artifact of a build in a staging directory and moving it into the delivered folder only after the final gate passes. A failed run then leaves the previous pack byte for byte intact, rather than overwriting a certified deliverable file by file and leaving a half updated ruin in its place. |
| Stale and correct | The state a certified system prefers when a check fails: last week's numbers, visibly labelled as last week's, with a newer cut under review. Stale and correct beats fresh and wrong, because a reader can discount an old figure and has no defence at all against a current one that is untrue. |
| Subtotal row | A row inside the data that summarizes other rows in the same file, emitted by accounting and report writers between groups. It looks like a record and behaves like a total. Summing a file without removing its subtotal rows counts the same money twice, and the inflated sum still looks entirely ordinary. |
| The fork | A point where one metric name covers several defensible definitions in live use: four denominators for sell-through, three revenues from a single storefront admin, lift as a multiple or as a percentage. Every branch of a fork reconciles perfectly against its own source, which is why arithmetic never catches the wrong one. |
| The trap | The specific way a named export shape produces a wrong number when handled the obvious way: a total repeated on every line, a summary row inside the data, a locale that rewrites decimals on save. The trap is a property of the file format, not of the analyst, and it repeats for every customer who pulls that export. |
| Title lie | A cell in a file's pre-header that looks like identity evidence but asserts nothing: an unfilled template name, a saved report title, a label the vendor never updates. A title lie is identical across two different exports from the same system, so accepting it lets every file prove its own identity. |
| Tolerance creep | Widening the allowed difference between two reads until they stop disagreeing. The tolerance exists to absorb rounding, not the error you just found. A count gets no tolerance at all: a default of one silently absorbs exactly the dropped or duplicated row the check was built to catch. |
| UNCALIBRATED | The verdict a plausibility screen returns for a group too small to read without the row under test, fewer than four other rows. It is reported per group, never for the whole column. No figure resting on an unscreened column may be described as certified, and a screen that refuses everywhere never renders like one that ran. |
| Unproven, computed, certified | The three states a figure can be in on a page. Computed means code produced it. Certified means it also ties to an anchor and survived a fire tested gate. Unproven means the file stated no total to tie to, and the page says so beside the number rather than hiding the gap. |
| What-if branch | A labelled figure computed by code under each open reading of a flagged value, one branch per hypothesis, the full cross product when several rulings are open at once. A conditional figure computed and labelled as conditional is disclosure, not revaluing, and it answers the reader's real question on the page. |
Not for
Not a general business intelligence glossary. Nothing here defines ARR or explains what a KPI is. Every term is one the doctrine needs in order to say precisely what was proved about a number and what was not.
Last updated 2026-09-02 · Dylan, founder · the principles behind these terms are published in full in the doctrine, and the failures they are named after are in the failure catalogue.