Part 1 · Operator’s Guide
Trust but Verify
Evidence for completion and distinct state vocabularies.
Public teaching edition · 1 October 2026
Trust but verify
Trust lets someone perform an authorized step. Verification earns a completion claim. The result must be checked in the destination, not merely reported by the builder.
Choose the required QA level before work. Record who checked, what revision they opened, when, and the finding. A scheduled checker is useful for evidence that can expire, but the schedule itself proves no run occurred.
When proof is missing, name the missing evidence and return the task to its owner. Set a recheck time. Escalate repeated misses to the accountable function and then the appropriate human decision owner. Use agreed deadlines rather than inventing a universal service promise.
Keep these vocabularies separate:
- Packet state: OPEN, CLAIMED, QA, DONE, PARKED
- Capability maturity: Available, Delivered, Installed, Enabled, Tested, Scheduled, Observed
- Scheduled-run observation: Scheduled, Attempted, Observed success, Observed failure, Missing run
A packet marked DONE cannot prove a tool is installed everywhere. A capability marked Scheduled cannot prove its next run succeeded.
What done means
| Claim | Useful evidence | Insufficient on its own |
|---|---|---|
| Sent | The sent record in the intended thread with the correct recipient | A draft or a send-button click |
| Posted | The comment read back in its destination thread | A success response from the write call |
| Published | The current live page showing the intended revision | The editor's update banner |
| Merged | The expected commit on the intended branch | A local commit |
| Fixed | The previously failing behavior exercised successfully | Code that looks right |
| Delivered a file | The intended recipient can open the correct file at its destination | A successful local export |
| Scheduled job ran | A dated receipt from that firing | The schedule definition |
Use: Verified: <what you opened> — <what you saw> — <when>.
If evidence is missing, use: Verified: NO — <missing check> — <owner and next action>.
A sent record proves submission through that route; it does not by itself prove that a person read the message. Test recipient access when relevant, without exposing private evidence to an unauthorized audience.