Reliability Principle·7 min read

Status is observed, not declared

Why my command center refuses to trust its own status fields, and treats the gap between claimed and true state as the real signal.

By Andrew J. Pyle

Every system I have been burned by had a green light on it at the time. The deploy said succeeded. The row said done. And the thing the system was supposed to accomplish had quietly not happened.

So I made one rule load-bearing: the system is not allowed to trust a field that says something is finished. It has to go look. Status is something you measure, not something a column declares.

01DONE IS A CLAIM

The lie of the status column

Every system I have been burned by had a green light on it at the time. The deploy said succeeded. The row said status is done. The dashboard was all checkmarks. And the actual thing the system was supposed to accomplish had quietly not happened.

A status column is a convenience. Some code did a thing and, on its way out, wrote down that it did the thing. The write and the reality are two separate events, and only one of them is guaranteed.

Done is a claim, not a fact. The gap between what a field says and what is actually true is the real signal.

02RECONCILE, DO NOT TRUST

Go look

The rule I made load-bearing: the system is not allowed to trust a field that says something is finished. It has to go look.

The clearest example is indexing. Is this content actually in the search index? There is an easy wrong answer, a column somewhere that says indexed is true, and a real answer that only exists if you reconcile against the live funnel. The system reports the reconciled number, never the flag.

03COUNT, DO NOT READ A FLAG

Probe the world, everywhere

Once you refuse declared status, you cannot stop, because the label-versus-reality gap is everywhere. Take something as basic as how many sites are live. The lazy version reads a status is live flag off each project. The honest version probes the world and counts what is actually serving.

Every important number on the system is measured, not read from a column a past process hoped was still true.

04WHY I TAKE THIS PERSONALLY

The demotion was a green light lying

This is not abstract for me. The most expensive lesson I have written up, a self-inflicted search demotion that dragged a whole site down, was at its root a green light that lied. The monitoring said fine while the thing it monitored was already broken.

That is why observed-not-declared is a rule and not a preference. A status field will tell you what a past process intended. Only a probe tells you what is true now.

05NEXT STEPS

Stop trusting the label

  1. Pick the one status field you rely on most and ask how it is written versus how you would verify it.
  2. Replace the read of that field with a probe that reconciles against reality.
  3. Treat the gap between claimed and true as an alert, not an accident.
  4. Make important numbers measured, never read from a column.

Have something you need built or fixed?

I build production Django / Next.js platforms and human-supervised AI-agent systems. Solo, senior, and fast. Tell me what you are building.

Start a project