204: Instruments That Cannot Fail
Key question: How do we know our checks are checking?
This Chapter's ACIs
| ACI | Name | Takeaway |
|---|---|---|
| ACI-038 | Controls That Can Fail | A check nobody has seen fail is no evidence that it ran. Prove each guard both ways, with a refuse arm that asserts its reason. |
| ACI-039 | An Instrument Must Say What It Did Not Look At | A gate can pass, fail or decline to answer. Print what was examined, and make an empty population refuse. |
| ACI-040 | Silent Success | When output matches the run that was meant, no error path catches the failure. Sweep the source by defect class, and derive residuals. |
| ACI-041 | The Fence | Pair each rule with a fence that asks the system what exists and reds on anything new and unguarded. Establish absence the same way. |
| ACI-042 | A Verdict Names Its Tree | Quote a verdict with its ref, its uncommitted count and its artefact, and publish the command beside it. |
| ACI-043 | Landed Is Not Working | The hop to the user can change the artefact or never run. Verify the delivered thing, and never close on a failed bar. |