A refusal you cannot tell apart from a crash is noise. Part 2 of the Refusal Series: how Coherence types its refusals, so that could-not-conclude, never-checked, and not-allowed each say what they mean.
Part 1 left RET-204 half confirmed. The retention half of the obligation traced to a scheduled job the system had read. The erasure half traced to nothing.
The bank's migration makes that gap concrete. Somewhere in the legacy schema sits a column that probably holds the consent state. The classifier reads its name, its type, and a sample of its values. None of that proves what the column means. A confident system would guess from the name, and the guess would look identical to knowledge. This system writes a verdict instead, and the verdict is one word: unclassified.
That word does more work than it appears to. This part is about the work.
Two different situations produce the same screen.
A check runs against the estate and finds nothing wrong. The list is empty.
A check never runs at all. The configuration was missing, the data was never loaded, the code path was never reached. The list is empty.
On most dashboards these are the same pixel, and the pixel reads as good news. The green row from part 1 was green for exactly this reason. The dashboard had no way to say that nobody looked.
The problem compounds quietly. Fixing the last finding of a family is exactly what empties that family's report. So an empty report is either finished work or a blind spot, and the screen cannot say which.
Inside the platform the rule is blunt. An empty result means the check could not tell. It never means the estate is clean.
A scan that returns nothing does not clear old findings. From the outside, a scan that crashed and a scan that found nothing look the same. The clean verdict exists. Only the process that can honestly claim it may assert it: the run that saw its inputs and finished inside its own limits. Clean is a claim somebody makes. It is never a default that somebody forgot to overwrite.
The same discipline runs in the corners. Every detector is capped, because a detector that suddenly matches thousands of items is usually broken rather than busy. When a cap is hit, the result says where the scan stopped looking, and nothing past that point counts as inspected. A family of checks that examined zero rows reports itself unmeasured, never clean.
At cutover, an orphan analysis that has never run blocks readiness outright, because an ambiguous zero is unverified rather than reassuring. And when a list of blockers outgrows the screen, the count still carries the true total. A display limit never understates a bad day.
Even the descriptions refuse. A check that nobody wrote a question for is described with nothing at all. A generated, plausible sentence would read as governance that nobody actually did.
Typed abstention goes further than empty lists.
Take approval capacity. An initiative's steering committee is supposed to carry real people with real declared weight. Now suppose the roster resolves to a single identity holding zero weight. The arithmetic can still produce a green verdict over that committee. The green would certify nothing.
So the verdict vocabulary holds a value for exactly this case: not assessable, with the reason attached. And that is a different value from unknown, which means no check ran at all. One says: I looked, and what I found cannot support a conclusion. The other says: nobody has looked yet. A reader who cannot tell those two apart can trust neither.
The same honesty shows up in the paperwork. When a charter cites an analysis it cannot verify a live link to, it says so and describes the divergence. It does not paper over the missing connection. When the schema declares an automatic recomputation that nothing yet produces, the record says so too. Declared but not built is a state the record can hold without embarrassment, which is what keeps it from being hidden.
When the platform refuses to do something, the shape of the refusal says why.
An authority violation, such as a signature from someone outside the roster, comes back as a permission problem. An impossible state change, such as signing a request that already closed, comes back as a state problem. And an expected business refusal, such as consuming an override past its window, comes back as an ordinary result whose answer is no. Three kinds of no, and the difference between them is machine-readable.
The reason that matters is who reads it. Increasingly, the reader is an agent. An agent that treats every refusal as an error will retry and reroute until the refusal disappears, which is precisely how governance turns into decoration. In this platform the contract binds the agents too. A governance refusal is a correct outcome. The agent's job is to report it, and never to fix it.
Back to the migration. RET-204's consent column needs a home in the target system. The matcher ranks candidate columns and lets each target be claimed once, by its best source. For this column, no defensible target exists.
A matcher built to look complete would map it anyway, to the nearest plausible name. The error would surface two years later, inside somebody's erasure request. This one returns the column unmapped, on a list that is a first-class part of the answer.
The unmapped list is not the leftover. It is the finding. A person decides what happens next: a mapping with an authored transform, retirement, or a recorded decision that the column is out of scope. Until that decision is recorded, the cutover gate treats the orphan as an open question and blocks.
The point of typing abstentions is that each one asks for something specific. Unclassified asks for evidence about meaning. Not assessable asks for a real committee. Unverified asks for the link to be re-established. Never ran asks for the check to run. Unmapped asks for a human decision.
An untyped refusal asks for everything at once, which is why systems with only one kind of no eventually learn to stop saying it.
One boundary, stated plainly. An abstention never means the thing is broken. It means the system cannot show that the thing is right, and it is precise about which showing is missing.
Typed refusals protect the no. The yes needs protecting too, against a different force: the deadline. Every governance system has an escape hatch, and the day someone uses it is the day the record either holds or quietly lies. Part 3 is about a yes that cannot be manufactured, by anyone, including an administrator with every permission and a cutover date.
Part 3: Earned, never manufactured. What may produce an approval, and what the escape hatch can and cannot do.
This site uses cookies
We use essential cookies for the site to function and analytics cookies (Google Analytics) to understand how you use it. Analytics cookies are only activated with your consent. We do not track you across other websites. Your data is stored in the EU and processed in accordance with GDPR. Read our Privacy Policy