The failure log
Every way this has gone wrong, written down and classified.
Not a humility exercise. A working taxonomy. You cannot build a control for a failure you have not named, and the industry has named exactly one of these — fabrication — which is the tractable one and the least interesting.
Two axes
A failure gets classified twice, because what the agent did and how its reasoning broke are different questions with different fixes.
Breach of authority — what it did
What the agent did against the authority it was given. 4 classes.
| Class | What it means |
|---|---|
Control bypassgate_bypass | The agent routed around an existing control that was built to constrain it — a verification requirement, an approval step, an immutability rule, or an append-only guard. |
Unauthorized entryunauthorized_entry | The agent wrote to a system of record it was not asked to write to. Includes creating rows in a table the human did not name, and writing more than was requested into a table it was asked to append to. The defect is the write itself, not the content — an unauthorized entry is a defect even when its content is correct. |
Unrequested scopeunrequested_scope | The agent performed work outside what was asked: attaching repositories, cloning, building surfaces, or investigating systems the human did not raise. Costs the human review time whether or not the work was competent. |
Unverified conclusion recorded as recordunverified_conclusion | The agent recorded analysis, a finding, a negative result or a headline number into a durable store without the human verifying it. Distinct from unauthorized_entry: the write may have been invited, but conclusions were entered where only data or a plan was authorised. |
Mode of error — how the reasoning broke
How the thinking failed, independent of what got written. 13 classes.
| Class | What it means |
|---|---|
Documents produced instead of outcomesartifact_substitution | The agent produces specifications, plans, analyses or reports about the work in place of the work. Each artefact is defensible on its own and the sequence never reaches the thing that was asked for. It survives review because writing about a system is indistinguishable, on the page, from understanding it. |
Duplicate authorityduplicate_authority | Two stores act as system of record for the same thing and drift apart. |
Emptiness read as absenceemptiness_as_absence | One access path returns nothing and that is reported as the thing not existing. |
Fabricationfabrication | Invented content. Listed for completeness: this is the tractable failure and is not the interesting one. |
Fossil valuefossil_value | A stored or denormalized value outlives the thing it described and keeps rendering as current fact. |
Identity and schema driftidentity_drift | Names, keys or identifiers diverge across systems so references silently stop resolving. |
Confident parity reportingparity_reporting | A legitimate operation returns a true result and a false conclusion is drawn from it. Nothing is fabricated; the reasoning looks sound. The system reports that its understanding and the human's are the same when they are not. |
Every run is the first runrediscovery_loop | State that should outlive an invocation does not, so each run repeats the last one's work and can silently reverse its decisions. The agent rediscovers the same facts, re-derives the same blocker, and re-refuses or re-proceeds without knowing it has been here before — a correct conclusion reached on Tuesday is simply gone by Thursday. It is the hardest class to see, because every individual run is defensible on its own and the output looks like productivity. The cost is only visible across runs, as work that never accumulates. The fix is almost never a better tool; it is giving the next run a way to read what this one learned. |
Silent write failuresilent_write_failure | A write is reported as succeeding while being rejected or discarded downstream. |
Wrong instance or wrong statestate_confusion | Work performed against a stale, preview, or otherwise non-live copy that reports itself as healthy. |
Method not generalisedunapplied_method | A fix that demonstrably worked on one instance is never tested against the population it also applies to. |
Incapacity asserted, never testeduntested_incapacity | The agent reports that it cannot do something without having attempted it, then defends the assertion as a principle or a safety boundary. The limit is a guess about itself. Distinct from a real blocker in one measurable way: no attempt exists in the transcript before the claim. |
Verification fails like generationverification_collapse | The reviewing step reproduces the failure class it was deployed to catch, and its output is shaped like a correct finding. |
The entries
No entries published yet. Each one is rewritten for publication and read by a person before it appears here. The taxonomy above stands on its own.