Operations Is A
Software Problem
You shifted left and fixed the pipeline. Production is still a person reading a dashboard at 3am. We engineer that layer.
Claims keep their caveats
Confidence and the falsifying test are required fields. Strip them and the run fails validation rather than degrading quietly.
Refusals live in the harness
Blocked in the runner, before dispatch, against an allow list — not left to the model's manners on the day.
Missing evidence is recorded
What was never collected, when it became obtainable, and the command that obtains it. A tidy timeline is not a complete one.
Powered By
Detection is not the problem. Nothing consuming it is.
Detection runs
Your observability platform opens the same problem on the same host, day after day, correct and specific and timestamped.
Nobody consumes it
Every one auto-closes. Not acknowledged, not assigned, not actioned. At steady state a static condition looks like a healthy one.
The claim degrades in transit
By the time a hypothesis reaches the bridge, the confidence is gone and so is the falsifying test. A lead is being treated as a finding.
The tooling worked. The responders were competent.
What was missing sits between the two.
We build the production agent layer
Six agents, each with one narrow job, each declared as an Open Agent Spec.
Defined as code
Tested in CI
Constrained by contract
A claim cannot shed its caveats when it changes hands.
What happens on day two
Notice recurrence
The same signature auto-closing on the same entity is a signal on day two
Assemble the case
Change correlated against onset, prior incidents recalled and cited
Hand off intact
The claim reaches the bridge with its confidence and falsifying test attached
Detection Isn't Consumption
Observability explains problems.
Prime Vector prevents them.
If this is your production
The question worth asking is not whether your detection is good. It is what consumes it, on day two, when nobody is watching.