The reconciliation report is the easiest document in a migration to write, which is exactly what is wrong with it. Part 5 of the Proof Series: four signals, one divergence number, and a proof derived from the map rather than written about it.
Part 4 closed with Danubia's map fully decided. Eighty-three columns confirmed, one absence decided, every entry an object with a name behind it. Then the integrator runs the trial load, because the loading is their work and never ours, and the question changes shape. The decisions are recorded. Were they right?
In most projects, the answer arrives as a document called the reconciliation report, and somebody writes it. That verb is the problem. A written report says what its author concluded, and its author works for the project, under the deadline, with the go-live date in the room. The report can be diligent and honest. Nothing about its production guarantees it, and an auditor two years later has only the author's word.
Our reconciliation is not a document, and nobody writes it.
It is derived from the confirmed field map. The map already states exactly what should happen to every value, in the closed grammar from part 3. It names which columns copy, which cast, and which translate through which confirmed pairs. That statement is machine-readable, so the platform can read both sides and check the outcome against it, column by column, with no narrative in between.
Confirming the map was confirming the reconciliation. They are one object read twice: once as the plan, once as the standard the result is held to. Nobody can author agreement into the proof, because nobody authors the proof at all. The map drives it, and the map was decided in daylight, pair by pair, back when nobody knew which answer would be convenient.
The check reads four signals, and each carries its own failure story.
Row counts come first. Every supplier that left the legacy table arrived somewhere, and none arrived twice. Control totals follow: the balances sum to the same figure on both sides, to the penny, because off by a rounding rule is off.
The third signal is the null rate. A column whose empty fraction rises in flight lost values silently, and a risen null rate is the classic signature of a failed decode. Key cardinality closes the set: the same number of distinct suppliers on both sides, so nothing collapsed two of them into one.
The four reduce to a single divergence number between zero and one. Zero is a perfect tie-out. Anything else is a distance from perfect, and the components that produced it stay readable underneath.
One number is a deliberate act of restraint. The alternative is the reconciliation dashboard: forty tiles, each individually green or amber, collectively unreadable. An auditor in front of forty tiles samples them. An auditor in front of one derived figure reads it, and then reads the component that moved it. The number exists so that reading is possible.
At Danubia the trial load comes back and the tie-out does its job.
Row counts match. The supplier balances tie to the penny. And the null rate on the status column climbs from almost nothing to four percent, so the divergence is not zero. The shape deserves a long look, because it is the shape of most late migration failures. Every figure that belongs on a status slide reads clean, and the figure underneath does not.
The trail leads back through the map. One of the eleven legacy status codes was rare, and part 3 recorded what the profiler did about it. The code never entered the sample, so it got no proposed pair rather than an invented one. The load found no translation for it and wrote nothing. Four percent of suppliers carried the rare code, and their status went missing in flight.
The repair is one decision, made where the map lives. A person reads the rare code, confirms its pair, and the map now covers eleven of eleven. The next trial load ties out at zero. Note what the incident never was: nobody hunted through load scripts, and nobody argued with a report. The proof pointed at the missing decision, and the missing decision was made.
Now the paragraph we would rather write ourselves than have a reader discover. There is a second way a decode can fail, and it is worse than the first.
A lookup that meets an unmapped value can also pass it through unchanged. Today our own transform runtime does exactly that, and it counts the operation as successfully applied. A record that crosses this way keeps its legacy code in a target field that expects the new domain.
Walk the four signals past it. Row counts match, and totals tie. The null rate does not move, because the value is present, and cardinality holds. All four read clean while a class of records quietly failed to translate.
Our own design ruling already names this behavior and abolishes it. An unmapped live value must surface as a blocking coverage finding, never as a silent passthrough. As we write this, the code has not caught up with the ruling. Until it does, the honest statement of our tie-out is bounded. Divergence proves what its four signals can see, and an incomplete crosswalk is not yet one of them. The fix makes the crosswalk's coverage part of what blocks, which is where this series says every gap belongs: decided, or blocking.
A vendor writing its own reconciliation report would not include this section. That is the argument for proofs nobody writes, applied to ourselves.
Stand back and count what Danubia holds. A map decided by people, and a proof derived from that map. A divergence of zero on the last trial load. One known bound on what zero means, stated in the open.
Nobody negotiated with that number. Nobody could. It was not a judgment, so it had no author to pressure, and the go-live date in the room had no one to lean on. That is what derivation buys. The proof inherits the honesty of the map rather than the mood of the project.
But the number is honest today, about today's load, under today's map. Migrations regress. Extracts get corrected, maps get amended, and a figure that was true in the trial can be false by cutover. The next part opens on the question every stored green checkmark fails. What keeps a proof true after the night it was computed?
Part 6: A seal that breaks itself. Certification as a live derivation, the two refusals inside it, and why the regression reaches the auditor before it reaches the project.
This site uses cookies
We use essential cookies for the site to function and analytics cookies (Google Analytics) to understand how you use it. Analytics cookies are only activated with your consent. We do not track you across other websites. Your data is stored in the EU and processed in accordance with GDPR. Read our Privacy Policy