Part 5 of 7 · 6 min

A decision a person made is never quietly lost

Nobody needs to fake a verdict to lose one. A routine re-run will do. Part 5 of the Refusal Series: the rule that human judgment survives every automatic process that touches its neighborhood.

Part 4 closed on the quieter attack. An override cannot fake a verdict, but a verdict can still be lost. A well-meaning process only has to write over it.

Picture RET-204 a year after cutover. During the migration, the matcher proposed a target for the consent column, and a reviewer rejected it. Wrong lifecycle, wrong meaning, and a reason recorded with the click. The decision cost the reviewer twenty minutes of careful reading.

Then the estate moves on. Sources get re-read. Mappings get re-derived on a newer model. Every one of those processes writes into the same neighborhood where that rejection lives.

What a re-run wants to do

A re-run is thorough rather than malicious. Its job is to regenerate its output from current inputs, and the rejected suggestion is still in its inputs. The natural implementation writes the suggestion back, with its status reset to fresh. Nothing in that story looks like a deletion. The rejection is resurrected over.

Ask what the record shows afterward. The pair sits in the review queue again, dressed as a new question. The reviewer's twenty minutes are gone, and nothing announces the loss. Multiply that by every re-run and every rejected pair, and review becomes a treadmill. People notice treadmills, and then they stop reviewing.

The guard at the only writer

Part 3 argued for properties over rules. Put the guard inside the one function that writes the fact, and every caller inherits it. This part applies that argument to memory.

Every mapping enters the record through a single writer, and inside that writer sits an unconditional stop. A pair a person rejected can never be written back to suggested. No caller is exempt, and no re-run is fresh enough. The regeneration can propose whatever it likes. At the write itself, the rejected pair is filtered out. The run's own record states the outcome plainly: persistence refused, because a person already decided.

Note the type of that refusal, because part 2 defined it. Nothing broke. The refusal is a correct result, recorded as one, and the re-run completes around it.

The rule above the guard

The guard covers one writer. Above it sits a rule we hold every pipeline to, and our own design records name it as the highest-severity failure the platform could commit. Never write an authoritative delete over a table that contains human decisions.

A process may demote its own machine-made rows, advise, or re-surface a settled question for a person to confirm. It may not erase what a person decided as a side effect of refreshing itself. Deletion of judgment is reserved for judgment.

Replacement, ratified

Re-derivation is where the temptation is strongest, so it gets the strictest shape.

Two generated versions of the same transformation map cannot be merged line by line. Each is internally coherent, and a splice of the two is coherent nowhere. So the platform never merges them. A re-derivation replaces its predecessor whole, and the predecessor is archived and stays diffable.

Whether the replacement lands is a decision, not a default. The two versions are compared first, cheaply. When the new derivation barely diverges from the old, it ratifies automatically, and the record says it did. When divergence is high, the replacement stops at a human gate. The person sees the differences, and the rationale is captured beside the choice.

And the decisions attached to the old version ride across. A disposition someone recorded against the previous derivation either re-binds to the new one or surfaces for re-confirmation. The standard we hold that migration to is blunt: zero decisions silently wiped.

Reading the source again

The same posture governs discovery. When the platform re-reads a source it read before, the ontology that curation already settled is the trusted baseline. That is the stance we hold the discovery pipeline to. New material that overlaps settled ground does not rewrite it. The overlap is flagged and queued for a person, and merging or replacing takes a deliberate operator action. Re-reading never outranks what review already decided.

The write that outlives its own machinery

One more guard completes the set, and it points the other way. The guards above protect a decision from later processes. This one protects it from its own consequences.

When a person changes an operative fact, the write commits first. Everything downstream runs after that commit: signature refresh, impact recalculation, notifications, audit rows. Each downstream step is guarded on its own. Any of them can fail, and all of them can fail together, and the person's write stands. A cascade failure degrades the machinery around a decision. It never rolls the decision back.

There is a corollary, and we would rather state it than have you find it. A change can commit while some of its downstream effects lag behind. The response lists which effects ran, so a reader can tell a landed change from a fully propagated one. That list is the honest witness, and part 2 explained why we prefer an honest gap to a smooth surface.

What the twenty minutes bought

Return to the reviewer's rejection. A year of scheduled re-runs and two full re-derivations passed through its neighborhood. The pair is still rejected, and the reason is still attached. No queue silently re-filled, and nobody re-answered a question that was already answered.

This is the quietest member of the refusal family, because its refusals happen inside machinery, at moments when no person is watching. It is also the one that decides whether people keep participating. Judgment that stays kept is judgment people keep giving.

The decisions survive. Now look underneath them. Every decision in this series rested on a number: a completion fraction, a signer count, a divergence measure. A figure can flatter, and a flattering figure corrupts every decision made on top of it. Part 6 is about numbers that decline to do that.

Part 6: The number that declines to flatter. Unblended figures, announced bounds, and why a small number you can defend beats a large one you cannot.

Model your first domain today.

You send five documents, we model them, and the first cut comes back in days.

This site uses cookies

We use essential cookies for the site to function and analytics cookies (Google Analytics) to understand how you use it. Analytics cookies are only activated with your consent. We do not track you across other websites. Your data is stored in the EU and processed in accordance with GDPR. Read our Privacy Policy