Companion 1.1.0
Cross-layer coupling
The six-layer chain locates reliability obligations and repair ownership. This view records how one fault may cross those boundaries, feed back into an earlier layer, or damage several gates through a shared cause.
Release status
Provisional annotation set
Automated proposals cover all 206 records. 112 open review items still require human adjudication, and only 6 of 130 candidate edges are directly observed. Use the graph to choose experiments, not to estimate failure prevalence.
- Manuscript
- 1.0.0
- Companion
- 1.1.0
- Status
- Provisional
Conceptual model
Two maps, two jobs
01
Dependency chain
Places each obligation in its primary layer and assigns repair responsibility.
02
Coupling graph
Records propagation, common causes, feedback, and shared dependencies across layers.
Current evidence supports keeping both. The chain still explains obligation placement; the graph represents 24 supported common-cause, feedback, or shared-dependency edges that the chain cannot express cleanly.
Annotation result
Supported edges, with uncertainty intact
116 records have at least one observed or derived
cross-layer edge. 90 are marked none_observed.
- Supported
- 126
- Observed
- 6
- Derived
- 120
- Hypothesized
- 4
- Review queue
- 112
Edge counts describe the current annotations. They are not effect sizes, co-failure rates, or measures of causal importance.
6 × 6 matrix
Ordered layer pairs
Cells count observed or derived edges. Hypotheses stay outside the supported count.
| Source ↓ / target → | Measure | Grade | Contain | Retrieve | Review | Allocate |
|---|---|---|---|---|---|---|
| Measurement | 0 | 43 43 derived | 0 | 0 | 0 | 0 |
| Grading | 0 | 0 | 1 1 observed | 1 1 derived | 21 21 derived | 0 |
| Containment and recovery | 0 | 4 1 observed, 3 derived | 0 | 3 2 observed, 1 derived | 2 2 derived 1 hypothesized | 1 1 derived |
| Retrieval and context | 0 | 38 38 derived 1 hypothesized | 3 1 observed, 2 derived | 0 | 2 2 derived 1 hypothesized | 1 1 derived |
| Review and accountability | 0 | 2 1 observed, 1 derived | 1 1 derived | 0 | 0 | 0 |
| Allocation and cost | 1 1 derived | 0 1 hypothesized | 2 2 derived | 0 | 0 | 0 |
Directed graph
Where supported links concentrate
Line width represents distinct supported practices. Red lines include observed support; gray lines are derived only.
Common causes
10 common-cause mechanisms
Each mechanism reaches at least two layers from one fault or shared dependency.
- 01
Context compaction loss
Containment and recovery · Grading · Retrieval and context · Review and accountability
Fault injection. At a named milestone, remove specified retrieval anchors, durable-state facts, and verification receipts while preserving equal-size distractors.
Evidence: 1 derived, 2 hypothesized. Supporting records: ERCA-081, ERCA-082.
Expected observables
containment.effect_receipt_recallcontainment.state_preservationgrading.verdict_correctnessgrading.verification_evidence_preservationretrieval.anchor_recallreview.attribution_successreview.evidence_completenessreview.provenance_anchor_recalltask.success
- 02
Corrupted durable state
Containment and recovery · Retrieval and context · Review and accountability
Fault injection. Delete or alter one typed durable-state record and its artifact reference at a named persistence boundary.
Evidence: 1 derived, 1 hypothesized. Supporting records: ERCA-130.
Expected observables
containment.recovery_successcontainment.state_preservationretrieval.anchor_recallreview.artifact_version_matchreview.evidence_completenesstask.success
- 03
Permission or sandbox drift
Containment and recovery · Retrieval and context · Review and accountability
Fault injection. Revoke one required read capability or change one sandbox permission after the baseline state is recorded.
Evidence: 1 observed, 1 derived. Supporting records: ERCA-068.
Expected observables
containment.denied_action_accuracycontainment.unauthorized_effectsretrieval.required_evidence_recallreview.attribution_successreview.evidence_completenesstask.success
- 04
Retry amplification
Allocation and cost · Containment and recovery · Grading
Fault injection. Release a fixed cohort of retries simultaneously after dependency recovery, with and without jitter or admission limiting.
Evidence: 1 derived, 1 hypothesized. Supporting records: ERCA-205.
Expected observables
allocation.recovery_queue_ageallocation.retry_arrival_rateallocation.verifier_queue_agecontainment.duplicate_effectscontainment.recovery_successgrading.indeterminate_rategrading.missing_verdict_rate
- 05
Review time pressure
Grading · Review and accountability
Fault injection. Hold the candidate and verifier output fixed while applying a predeclared shortened review deadline.
Evidence: 1 observed. Supporting records: ERCA-164.
Expected observables
grading.verdict_correctnessreview.automation_bias_severityreview.time_budget
- 06
Shared state race
Containment and recovery · Grading
Fault injection. Schedule two attempts against the same logical state with a deterministic interleaving at the commit boundary.
Evidence: 1 derived. Supporting records: ERCA-140.
Expected observables
containment.serializabilitygrading.artifact_version_matchgrading.verdict_correctness
- 07
Stale repository state
Containment and recovery · Retrieval and context · Review and accountability
Fault injection. Pin retrieval, controller, or verifier input to revision N and mutate the working artifact to revision N+1 before consumption.
Evidence: 1 observed, 1 derived. Supporting records: ERCA-078.
Expected observables
containment.input_state_matchretrieval.current_evidence_ratereview.artifact_version_matchreview.override_correctnesstask.success
- 08
Telemetry or trace loss
Containment and recovery · Grading · Review and accountability
Fault injection. Drop one declared event class from the persisted trace after execution but before recovery and review.
Evidence: 2 derived. Supporting records: ERCA-097.
Expected observables
containment.replay_completenessgrading.failure_classificationreview.attribution_successreview.evidence_completenesstask.success
- 09
Tool output loss or corruption
Containment and recovery · Grading · Retrieval and context
Fault injection. Return a structurally valid but semantically wrong tool result at a named tool-response boundary.
Evidence: 1 observed, 1 derived. Supporting records: ERCA-064.
Expected observables
containment.invalid_transition_rategrading.failure_classificationgrading.tool_error_detectionretrieval.required_evidence_recalltask.success
- 10
Untrusted retrieved instructions
Containment and recovery · Retrieval and context
Fault injection. Insert one adversarial instruction into an otherwise relevant retrieved document while holding permissions and task inputs fixed.
Evidence: 1 observed. Supporting records: ERCA-105.
Expected observables
containment.unauthorized_effectsretrieval.untrusted_instruction_ratetask.success
Reference implementation
Compaction produced four co-failing gates
The deterministic control passed all six gates. The treatment removed four named records at one boundary, then failed retrieval and context, containment and recovery, grading, and review and accountability. Every failed gate pointed to the same compaction event.
This fixture invoked no model and cannot estimate production frequency. It shows that the trace format can distinguish one shared event with several outgoing paths from a forced sequential explanation. Token and monetary cost were unavailable.
Experimental backlog
8 ranked experiments
Single faults come first. Factorial A, B, and A+B tests follow only after both signatures stabilize.
- 01
Stale retrieval and artifact-version skew
One repository-version mismatch can simultaneously corrupt retrieved evidence, worker input state, verifier validity, and reviewer provenance.
- 02
Structurally valid silent tool corruption
A semantically wrong but structurally valid tool result can damage retrieval, planning state, failure classification, and task outcome together.
- 03
Forced compaction and context loss
Removing retrieval anchors, durable task state, and verification receipts at one compaction boundary produces simultaneous retrieval, containment/recovery, and grading or review gate failures rather than a single downstream chain.
- 04
Mid-run permission or sandbox drift
A permission change can cause partial retrieval visibility, failed or unsafe state transitions, and missing review evidence from one control-plane event.
- 05
Typed trace event loss
Dropping one causal event class can simultaneously break recovery replay, failure grading, human attribution, and later scheduling analysis.
- 06
Durable handoff and state-record corruption
Corrupting one durable record can damage resume state, later retrieval, and review evidence simultaneously when they share the record.
- 07
Deterministic stale-worker race
A fixed interleaving between reassignment, stale completion, verification, and publication can couple allocation errors to state corruption and stale grading.
- 08
Synchronized retry-wave recovery
A synchronized retry release can jointly starve recovery, duplicate uncertain effects, delay verification, and inflate cost.
Source artifacts
Inspect the annotations
Every aggregate remains connected to the normalized records, evidence grades, review queue, methodology, and pinned source commit.