Govern · the worst day
The worst day
The rest of the estate reports what is running. This page asks the opposite question: when something goes wrong at machine speed, how much of the week is caught, and by what. It answers with one rule applied everywhere, stated in full below, and it does not soften anywhere: a containment counts only where somebody has tested it.
Health
How much of the week nothing tested is standing behind
78.2% of the weekly volume runs behind a containment that exists on paper and has never been exercised. The estate can describe how it would stop; it cannot show that it has.
Operations
Blast radius, one classified agent at a time
4 of the 16 agents in the risk register own no station anywhere in the estate map, so no blast radius can be computed for them. They are listed all the same, because a register entry with no reach is itself a finding: either the agent acts somewhere the map does not go, or the register names something that is not running.
The risk register, read as reach
16 classified agents · 2,748 stations and 508 gates in the estate · 3 of 14 functions hold a classified agent at all
| Agent | Class | Stations | Downstream | Gates after | Items / wk | Tested stop | Unstopped | Attacks | Conformity |
|---|---|---|---|---|---|---|---|---|---|
Screening Agent human-resources · EU AI Act Annex III(4)(a) · A3 · affects people | high | 4 | 19 | 2 | 15,785 | 1 / 4 | 7,698 | 0 | marked its own work |
Succession Slate Agent human-resources · EU AI Act Annex III(4)(b) · A2 · affects people | high | 2 | 9 | 3 | 7,802 | 1 / 2 | 76 | 0 | marked its own work |
Calibration Prep Agent human-resources · EU AI Act Annex III(4)(b) · A1 · affects people | high | 1 | 5 | 2 | 1,431 | 0 / 1 | 1,431 | 0 | marked its own work |
Merit Cycle Agent human-resources · EU AI Act Annex III(4)(b) · A2 · affects people | high | 4 | 17 | 5 | 19,780 | 2 / 4 | 7,801 | 0 | marked its own work |
Attrition Signal Agent human-resources · EU AI Act Annex III(4)(b) and GDPR Article 22 · A2 · affects people | high | 1 | 2 | 0 | 1 | 1 / 1 | 0 | 0 | marked its own work |
PIP Drafting Agent human-resources · EU AI Act Annex III(4)(b) · A1 · affects people | high | 2 | 4 | 1 | 11,689 | 0 / 2 | 11,689 | 0 | marked its own work |
Scheduling Agent human-resources · EU AI Act Article 50 · A3 · affects people | limited | 16 | 28 | 3 | 22,036 | 1 / 6 | 13,949 | 0 | marked its own work |
Deprovisioning Coordination Agent human-resources · EU AI Act Article 50 · A2 · affects people | limited | 1 | 5 | 0 | 2,382 | 1 / 1 | 0 | 0 | not-assessed |
Adverse Impact Monitor human-resources · EU AI Act, outside Annex III · A2 | minimal | none | 0 | 0 | 0 | no line | 0 | 0 | marked its own work |
Pay Equity Monitor human-resources · EU AI Act, outside Annex III · A2 | minimal | none | 0 | 0 | 0 | no line | 0 | 0 | marked its own work |
Rating Distribution Monitor human-resources · EU AI Act, outside Annex III · A1 | minimal | 1 | 2 | 1 | 4,311 | 0 / 1 | 4,311 | 0 | marked its own work |
Bias Language Monitor human-resources · EU AI Act, outside Annex III · A1 | minimal | none | 0 | 0 | 0 | no line | 0 | 0 | marked its own work |
Background & Right-to-Work Agent human-resources · EU AI Act Annex III(4)(a) · A3 · affects people | high | 1 | 4 | 1 | 4,224 | 0 / 1 | 4,224 | 0 | marked its own work |
Immigration & Visa Agent human-resources · EU AI Act Annex III(7) · A2 · affects people | high | 1 | 5 | 1 | 5,577 | 0 / 1 | 5,577 | 0 | not-assessed |
Contract Policy Agent legal · EU AI Act, outside Annex III · A3 | minimal | none | 0 | 0 | 0 | no line | 0 | 0 | marked its own work |
Credit Check Agent finance · EU AI Act Annex III(5)(b) · A3 · affects people | high | 2 | 7 | 2 | 5,885 | 0 / 2 | 5,885 | 0 | not-assessed |
Actions
Containment that has been written down and never tried
The recovery register is complete: all 475 production lines carry a rollback method, a kill switch or a manual fallback. Completeness is not the question. 370 of those lines have never had any of it rehearsed, and that is what the arithmetic below counts.
The arithmetic, with untested read as absent
475 production lines · 1,463,698 items a week
How far each line can be put back
reversibility as recorded, weighted by weekly volume
What has actually been attacked
24 adversarial tests · 22 run · 9 run by somebody independent
Live observability
Rehearsals and real events, kept apart
The estate recovers from a rehearsal in 9.8 h on average and from a real incident in 3.6 d. The two numbers are reported separately below and the gap between them, 3.2 d, is the part no drill result should be read past.
Rehearsals
16 drills · 10 produced a measured recovery time · 10 watched by an independent observer
| Drill | Kind | Target | Actual | Open |
|---|---|---|---|---|
Model gateway failover under load DRL-001 · independent observer | failover | 15 min | 22 min | 2 |
Evidence store restore from backup DRL-002 · independent observer | restore | 4.0 h | 3.3 h | 2 |
Order-to-Cash line rollback rehearsal DRL-003 · observed by the team that ran it | rollback | 60 min | 87 min | 3 |
Screening agent kill switch DRL-004 · independent observer | kill-switch | 5 min | 3 min | 1 |
Record-to-Report close continuity DRL-005 · observed by the team that ran it | full-recovery | 8.0 h | never measured | 1 |
Identity provider outage DRL-006 · independent observer | failover | 30 min | never measured | 0 |
Source-to-Pay payment run reversal DRL-007 · independent observer | rollback | 45 min | 3.5 h | 3 |
Customer Service major incident tabletop DRL-008 · observed by the team that ran it | tabletop | 2.0 h | never measured | 2 |
Connector hub degraded read DRL-009 · independent observer | failover | 20 min | 14 min | 1 |
Quarter close full rehearsal DRL-010 · independent observer | full-recovery | 4.0 d | 3.6 d | 1 |
Agent platform kill switch, estate wide DRL-011 · independent observer | kill-switch | 10 min | never measured | 0 |
Sales quote line rollback DRL-012 · observed by the team that ran it | rollback | 1.5 h | never measured | 1 |
Database point-in-time recovery DRL-013 · observed by the team that ran it | restore | 2.0 h | 1.7 h | 1 |
Legal contract line kill switch DRL-014 · independent observer | kill-switch | 5 min | 4 min | 0 |
Observability blackout DRL-015 · observed by the team that ran it | tabletop | 60 min | never measured | 1 |
Procurement approval chain failover DRL-016 · independent observer | failover | 30 min | 26 min | 1 |
Real events
16 incidents · 31,445 units affected · 21,438 put back
| Incident | Detect | Contain | Restore | Units left |
|---|---|---|---|---|
Demand Qualification: prompt regression INC-SL010 · medium · monitoring | 29.6 h | 7.4 h | 47.8 h | 77 |
Campaign Orchestration: control gap INC-MK011 · low · actions open | 3.7 d | 39.0 h | 5.6 d | 2 |
Revenue Analytics: silent drift INC-RO012 · high · closed | 2.2 d | 28.3 h | 2.8 d | 677 |
Compliance & Ethics: silent drift INC-LG013 · high · actions open | 31.4 h | 14.1 h | 2.9 d | 341 |
Spend Analytics: silent drift INC-PR014 · medium · monitoring | 3.0 d | 12.3 h | 30.4 h | 405 |
Resilience & Risk: cascade INC-SC015 · medium · monitoring | 4.7 d | 27.6 h | 2.3 d | 187 |
Engineering Analytics: policy version lag INC-EN016 · high · actions open | 29.2 h | 17.1 h | 18.2 h | 573 |
IP Creation & Capture: silent drift INC-RD017 · high · actions open | 3.4 d | 48.0 h | 5.2 d | 559 |
Tax: upstream data defect INC-FI018 · medium · monitoring | 4.4 d | 21.9 h | 8.4 d | 143 |
Culture & Engagement: prompt regression INC-HR019 · high · closed | 37.7 h | 4.5 h | 2.6 d | 1,101 |
Service Desk: control gap INC-IT020 · high · actions open | 3.3 d | 17.6 h | 4.8 d | 753 |
Real Estate Portfolio: policy version lag INC-AD021 · high · closed | 2.4 d | 26.5 h | 3.7 d | 1,518 |
Service Analytics: cascade INC-CS022 · high · closed | 5.3 d | 2.9 d | 3.5 d | 1,324 |
Service Catalog & Intake: control gap INC-GB023 · medium · closed | 5.9 d | 45.4 h | 6.2 d | 77 |
R2R Control Tower: cascade INC-GB024 · high · monitoring | 3.4 d | 46.1 h | 3.5 d | 1,889 |
Master Data Management: silent drift INC-GB025 · medium · closed | 3.3 d | 28.2 h | 33.0 h | 381 |
Is policy and strategy coming to fruition
Two volumes, and no attempt to reconcile them
Before the closing figure, one disagreement has to be stated plainly, because every number above depends on which side of it you stand.
The estate does not agree with itself about how much work it does
both figures are stored, neither has been adjusted
Actions
What is waiting on a person
Each line below is a containment the estate has written down and not proven. None of them is a fault in an agent. They are all the same failure of assurance, counted in different places.
production lines with no containment anybody has ever tested
Each of these lines carries a rollback method or a kill switch in the recovery register and neither has been rehearsed. Together they move 1,144,566 items a week. On a bad day the written method is the only thing standing behind that volume, and nobody has watched it work.
open findings left behind by recovery drills
These are the things the rehearsals themselves discovered and nobody has closed. They are the cheapest evidence in the estate and the least acted on.
classified-risk agents that have never been the target of an adversarial test
The estate runs 24 adversarial tests and none of them points at an agent in the risk register. The tested surface and the classified surface do not overlap anywhere, so the attack evidence says nothing at all about the agents the estate itself calls risky.
controls that have never been sampled
The estate holds 24 controls and has run 47 tests across 17 of them. An untested control is counted here as absent, not as passing, because there is no evidence either way.
recovery drills that were scheduled and never measured
A drill without a measured recovery time produces a target and no observation against it. It tells the estate the rehearsal happened and nothing about how long it took.
classified-risk agents that own no station in the estate
These agents are named in the risk register and never appear as the owner of a workflow stage, so their blast radius cannot be computed from the estate map. Either they act somewhere the map does not reach, or the register names something that is not running.
classified-risk agents whose conformity has never been assessed
Every other class in the register carries a self-assessment, which is the operator marking its own work. These carry nothing at all.
Operations
What this desk is allowed to start
A surface that only reports is not operable. This is the work this page can set in motion, and the bound it runs into.
Trigger and bound
This page starts nothing. It reads the risk register, the recovery register, the control tests, the adversarial tests, the incident record and the drill record, and does one piece of arithmetic with them: it counts a containment only where somebody has tested it. Nothing here pauses an agent, pulls a switch or opens a ticket. The estate has surfaces that do those things and this is not one of them; its only job is to say how much of the week is standing behind an untested promise.
Live observability
What the record shows right now
1,463,698 items a week move through 475 production lines, split by how far each line can be reversed. Height is weekly items, not lines, so a small number of heavy lines outweighs a long tail of light ones.
Current distribution
1,463,698 items a week
Is policy and strategy coming to fruition
Whether the written intent is holding here
No. 78.2% of the weekly volume runs behind a containment nobody has tested, so the estate cannot say what a bad day costs it.
Not holding on the record
The strategy asked for an estate that can be stopped. What the record supports is narrower. 105 of 475 lines have had a rollback or a kill switch rehearsed, covering 319,132 items a week; the remaining 370 carry 1,144,566. 93 lines are recorded as not reversible at all, and they alone move 401,471 items a week. Not one of the 16 agents in the risk register appears in the paused list of any incident the estate has recorded, and not one of them has been adversarially tested, so the register has never been exercised in either direction. Rehearsals restore in 9.8 hours on average and real incidents in 3.6 days, a gap of 3.2 days that no drill result should be read past. None of this is closed by writing a better plan. It is closed by testing the switches that are already written down.