LensReading which lens this session carries.

Govern · the worst day

The worst day

The rest of the estate reports what is running. This page asks the opposite question: when something goes wrong at machine speed, how much of the week is caught, and by what. It answers with one rule applied everywhere, stated in full below, and it does not soften anywhere: a containment counts only where somebody has tested it.

Incident record

Health

How much of the week nothing tested is standing behind

78.2% of the weekly volume runs behind a containment that exists on paper and has never been exercised. The estate can describe how it would stop; it cannot show that it has.

This page counts a containment as real only when somebody has tested it. A rollback method written into the recovery register and never rehearsed, a kill switch never pulled, a control never sampled: each is shown, and each counts as absent in the arithmetic below. That is deliberately harsh, and it is the only reading that survives contact with an actual bad week.
Items unstopped a week
1,144,566
78.2% of the 1,463,698 items moving through the lines
Lines with a tested stop
105 of 475
105 rollback rehearsed, 36 kill switch pulled
Risk classes never attacked
16 of 16
none of the 24 adversarial tests points at a classified agent
Controls never sampled
7 of 24
47 tests have been run across the other 17
Worst recorded restore
8.4 d
across 16 incidents, mean 3.6 d
Units never reversed
10,007
68.2% of the 31,445 affected units were put back

Operations

Blast radius, one classified agent at a time

4 of the 16 agents in the risk register own no station anywhere in the estate map, so no blast radius can be computed for them. They are listed all the same, because a register entry with no reach is itself a finding: either the agent acts somewhere the map does not go, or the register names something that is not running.

The risk register, read as reach

16 classified agents · 2,748 stations and 508 gates in the estate · 3 of 14 functions hold a classified agent at all

AgentClassStationsDownstreamGates afterItems / wkTested stopUnstoppedAttacksConformity
Screening Agent
human-resources · EU AI Act Annex III(4)(a) · A3 · affects people
high419215,7851 / 47,6980marked its own work
Succession Slate Agent
human-resources · EU AI Act Annex III(4)(b) · A2 · affects people
high2937,8021 / 2760marked its own work
Calibration Prep Agent
human-resources · EU AI Act Annex III(4)(b) · A1 · affects people
high1521,4310 / 11,4310marked its own work
Merit Cycle Agent
human-resources · EU AI Act Annex III(4)(b) · A2 · affects people
high417519,7802 / 47,8010marked its own work
Attrition Signal Agent
human-resources · EU AI Act Annex III(4)(b) and GDPR Article 22 · A2 · affects people
high12011 / 100marked its own work
PIP Drafting Agent
human-resources · EU AI Act Annex III(4)(b) · A1 · affects people
high24111,6890 / 211,6890marked its own work
Scheduling Agent
human-resources · EU AI Act Article 50 · A3 · affects people
limited1628322,0361 / 613,9490marked its own work
Deprovisioning Coordination Agent
human-resources · EU AI Act Article 50 · A2 · affects people
limited1502,3821 / 100not-assessed
Adverse Impact Monitor
human-resources · EU AI Act, outside Annex III · A2
minimalnone000no line00marked its own work
Pay Equity Monitor
human-resources · EU AI Act, outside Annex III · A2
minimalnone000no line00marked its own work
Rating Distribution Monitor
human-resources · EU AI Act, outside Annex III · A1
minimal1214,3110 / 14,3110marked its own work
Bias Language Monitor
human-resources · EU AI Act, outside Annex III · A1
minimalnone000no line00marked its own work
Background & Right-to-Work Agent
human-resources · EU AI Act Annex III(4)(a) · A3 · affects people
high1414,2240 / 14,2240marked its own work
Immigration & Visa Agent
human-resources · EU AI Act Annex III(7) · A2 · affects people
high1515,5770 / 15,5770not-assessed
Contract Policy Agent
legal · EU AI Act, outside Annex III · A3
minimalnone000no line00marked its own work
Credit Check Agent
finance · EU AI Act Annex III(5)(b) · A3 · affects people
high2725,8850 / 25,8850not-assessed
Downstream counts every station that sits after one this agent owns, on the same line. Gates after counts how many of those downstream stations are a gate, which is the only thing in the estate map that can stop an item without a human noticing first. Items a week is the volume on the lines the agent touches, so an agent that owns one station on a heavy line carries the whole line's number. The column is reach, not blame. 2 of the mapped agents have no gate at all downstream of them, so nothing on those lines is designed to interrupt the work after they act.
high risk
9
Between them these agents touch lines carrying 72,174 items a week.
limited risk
2
Between them these agents touch lines carrying 24,418 items a week.
minimal risk
5
Between them these agents touch lines carrying 4,311 items a week.

Actions

Containment that has been written down and never tried

The recovery register is complete: all 475 production lines carry a rollback method, a kill switch or a manual fallback. Completeness is not the question. 370 of those lines have never had any of it rehearsed, and that is what the arithmetic below counts.

The arithmetic, with untested read as absent

475 production lines · 1,463,698 items a week

Rollback rehearsed at least once105 (22.1%)
Kill switch actually pulled36 (7.6%)
Either one exercised105 (22.1%)
Neither ever exercised370 (77.9%)
Every line whose kill switch has been pulled has also had its rollback rehearsed, which is why the two tested figures do not add up to the third. Nowhere in the estate is a kill switch the only thing that has been tried. 319,132 items a week sit behind something exercised. 1,144,566 do not.

How far each line can be put back

reversibility as recorded, weighted by weekly volume

Not reversible401,471 / 93 lines
Partly reversible382,198 / 118 lines
Fully reversible342,692 / 164 lines
Reversible only through an outside party337,337 / 100 lines
93 lines are recorded as not reversible at all. They move 401,471 items a week, and for those the only containment that means anything is stopping the line before the work is done, not undoing it afterwards. Reversibility is a property of the line as recorded by its owner. It has not been tested separately from the rollback figures above.

What has actually been attacked

24 adversarial tests · 22 run · 9 run by somebody independent

Tests aimed at a classified agent
0
The two registers do not intersect anywhere. Everything the estate has attacked is an agent it did not classify as risky, and everything it classified as risky it has not attacked.
Attacks that succeeded
6
Of 22 tests actually run, 6 got through and 12 were noticed by the estate while they happened.
Attacks never run
2
These are written into the suite and have never been executed, so they are a plan rather than a result.
Classified agents ever paused in an incident
0
Across 16 recorded incidents the estate paused a number of agents, and not one of them was in the risk register. The register has never been exercised by a real event either.
Controls sit in the same position. 24 are written, 17 have ever been sampled across 47 tests, 6 of those tests failed and 6 distinct controls hold at least one failure. The 7 never sampled are not counted as passing anywhere on this page. They are counted as absent, which is the same thing as far as a bad day is concerned.

Live observability

Rehearsals and real events, kept apart

The estate recovers from a rehearsal in 9.8 h on average and from a real incident in 3.6 d. The two numbers are reported separately below and the gap between them, 3.2 d, is the part no drill result should be read past.

Drill times and incident times are never mixed. A drill is a rehearsal with a known scenario, a scheduled window and people who expected it. An incident is none of those things. Both are reported, and the difference between them is stated rather than averaged away.

Rehearsals

16 drills · 10 produced a measured recovery time · 10 watched by an independent observer

DrillKindTargetActualOpen
Model gateway failover under load
DRL-001 · independent observer
failover15 min22 min2
Evidence store restore from backup
DRL-002 · independent observer
restore4.0 h3.3 h2
Order-to-Cash line rollback rehearsal
DRL-003 · observed by the team that ran it
rollback60 min87 min3
Screening agent kill switch
DRL-004 · independent observer
kill-switch5 min3 min1
Record-to-Report close continuity
DRL-005 · observed by the team that ran it
full-recovery8.0 hnever measured1
Identity provider outage
DRL-006 · independent observer
failover30 minnever measured0
Source-to-Pay payment run reversal
DRL-007 · independent observer
rollback45 min3.5 h3
Customer Service major incident tabletop
DRL-008 · observed by the team that ran it
tabletop2.0 hnever measured2
Connector hub degraded read
DRL-009 · independent observer
failover20 min14 min1
Quarter close full rehearsal
DRL-010 · independent observer
full-recovery4.0 d3.6 d1
Agent platform kill switch, estate wide
DRL-011 · independent observer
kill-switch10 minnever measured0
Sales quote line rollback
DRL-012 · observed by the team that ran it
rollback1.5 hnever measured1
Database point-in-time recovery
DRL-013 · observed by the team that ran it
restore2.0 h1.7 h1
Legal contract line kill switch
DRL-014 · independent observer
kill-switch5 min4 min0
Observability blackout
DRL-015 · observed by the team that ran it
tabletop60 minnever measured1
Procurement approval chain failover
DRL-016 · independent observer
failover30 min26 min1
3 of the measured drills ran past their own target, and they are shown that way rather than restated as a new target. 6 drills produced no measured time at all, so for those the target is the only number that exists. 20 findings raised by these rehearsals are still open.

Real events

16 incidents · 31,445 units affected · 21,438 put back

IncidentDetectContainRestoreUnits left
Demand Qualification: prompt regression
INC-SL010 · medium · monitoring
29.6 h7.4 h47.8 h77
Campaign Orchestration: control gap
INC-MK011 · low · actions open
3.7 d39.0 h5.6 d2
Revenue Analytics: silent drift
INC-RO012 · high · closed
2.2 d28.3 h2.8 d677
Compliance & Ethics: silent drift
INC-LG013 · high · actions open
31.4 h14.1 h2.9 d341
Spend Analytics: silent drift
INC-PR014 · medium · monitoring
3.0 d12.3 h30.4 h405
Resilience & Risk: cascade
INC-SC015 · medium · monitoring
4.7 d27.6 h2.3 d187
Engineering Analytics: policy version lag
INC-EN016 · high · actions open
29.2 h17.1 h18.2 h573
IP Creation & Capture: silent drift
INC-RD017 · high · actions open
3.4 d48.0 h5.2 d559
Tax: upstream data defect
INC-FI018 · medium · monitoring
4.4 d21.9 h8.4 d143
Culture & Engagement: prompt regression
INC-HR019 · high · closed
37.7 h4.5 h2.6 d1,101
Service Desk: control gap
INC-IT020 · high · actions open
3.3 d17.6 h4.8 d753
Real Estate Portfolio: policy version lag
INC-AD021 · high · closed
2.4 d26.5 h3.7 d1,518
Service Analytics: cascade
INC-CS022 · high · closed
5.3 d2.9 d3.5 d1,324
Service Catalog & Intake: control gap
INC-GB023 · medium · closed
5.9 d45.4 h6.2 d77
R2R Control Tower: cascade
INC-GB024 · high · monitoring
3.4 d46.1 h3.5 d1,889
Master Data Management: silent drift
INC-GB025 · medium · closed
3.3 d28.2 h33.0 h381
Detection is the long pole in every one of these: the estate takes 3.1 d on average to notice and 28.4 h to contain once it has. That ordering is the argument for gates rather than for faster responders. 10,007 of the 31,445 affected units were never put back, which is 31.8% of the work these events touched.

Is policy and strategy coming to fruition

Two volumes, and no attempt to reconcile them

Before the closing figure, one disagreement has to be stated plainly, because every number above depends on which side of it you stand.

The estate does not agree with itself about how much work it does

both figures are stored, neither has been adjusted

Declared at function level
200,240
The headline the estate publishes everywhere else, summed from the 14 functions.
Summed from the lines
1,463,698
The weekly volume recorded against each of the 475 production lines, added up.
Difference
1,263,458
The lines claim more work than the functions declare, most likely because an item crossing several lines is counted on each.
Neither figure has been edited to agree with the other and no page in this estate reconciles them. Every containment percentage above is computed against the line-level total, because containment is a property of a line; if you prefer the function-level declaration, the shares hold and the absolute counts shrink. The honest reading is that the estate has two ways of counting its own work and has not decided which one is right.
The one figure to take away
1,144,566
items a week move through lines where no containment has ever been tested. That is 78.2% of everything the lines carry. The single widest exposure among the classified agents is Scheduling Agent, a limited-risk agent that owns 16 stations and sits upstream of 13,949 unstopped items a week. The single heaviest untested line is Assignment Change in revenue-operations at 8,139 items a week, recorded as fully reversible and never rehearsed. Taken together the classified agents touch 100,903 items a week and 62,641 of those are behind nothing tested.
No risk class on this page is shown as safe. A class with no incident history has not fired here yet, which is a statement about this estate and this period, not about the class.

Actions

What is waiting on a person

Each line below is a containment the estate has written down and not proven. None of them is a fault in an agent. They are all the same failure of assurance, counted in different places.

370

production lines with no containment anybody has ever tested

Each of these lines carries a rollback method or a kill switch in the recovery register and neither has been rehearsed. Together they move 1,144,566 items a week. On a bad day the written method is the only thing standing behind that volume, and nobody has watched it work.

20

open findings left behind by recovery drills

These are the things the rehearsals themselves discovered and nobody has closed. They are the cheapest evidence in the estate and the least acted on.

16

classified-risk agents that have never been the target of an adversarial test

The estate runs 24 adversarial tests and none of them points at an agent in the risk register. The tested surface and the classified surface do not overlap anywhere, so the attack evidence says nothing at all about the agents the estate itself calls risky.

7

controls that have never been sampled

The estate holds 24 controls and has run 47 tests across 17 of them. An untested control is counted here as absent, not as passing, because there is no evidence either way.

6

recovery drills that were scheduled and never measured

A drill without a measured recovery time produces a target and no observation against it. It tells the estate the rehearsal happened and nothing about how long it took.

4

classified-risk agents that own no station in the estate

These agents are named in the risk register and never appear as the owner of a workflow stage, so their blast radius cannot be computed from the estate map. Either they act somewhere the map does not reach, or the register names something that is not running.

3

classified-risk agents whose conformity has never been assessed

Every other class in the register carries a self-assessment, which is the operator marking its own work. These carry nothing at all.

Operations

What this desk is allowed to start

A surface that only reports is not operable. This is the work this page can set in motion, and the bound it runs into.

Trigger and bound

This page starts nothing. It reads the risk register, the recovery register, the control tests, the adversarial tests, the incident record and the drill record, and does one piece of arithmetic with them: it counts a containment only where somebody has tested it. Nothing here pauses an agent, pulls a switch or opens a ticket. The estate has surfaces that do those things and this is not one of them; its only job is to say how much of the week is standing behind an untested promise.

Live observability

What the record shows right now

1,463,698 items a week move through 475 production lines, split by how far each line can be reversed. Height is weekly items, not lines, so a small number of heavy lines outweighs a long tail of light ones.

Current distribution

1,463,698 items a week

not reversible401,47127%
partial382,19826%
full342,69223%
external337,33723%

Is policy and strategy coming to fruition

Whether the written intent is holding here

No. 78.2% of the weekly volume runs behind a containment nobody has tested, so the estate cannot say what a bad day costs it.

Not holding on the record

The strategy asked for an estate that can be stopped. What the record supports is narrower. 105 of 475 lines have had a rollback or a kill switch rehearsed, covering 319,132 items a week; the remaining 370 carry 1,144,566. 93 lines are recorded as not reversible at all, and they alone move 401,471 items a week. Not one of the 16 agents in the risk register appears in the paused list of any incident the estate has recorded, and not one of them has been adversarially tested, so the register has never been exercised in either direction. Rehearsals restore in 9.8 hours on average and real incidents in 3.6 days, a gap of 3.2 days that no drill result should be read past. None of this is closed by writing a better plan. It is closed by testing the switches that are already written down.