# W13 Worked Case — Frozen Panel, Four Incidents, One Append-Only Ledger

## Case status

This is a synthetic, offline, deterministic monitoring exercise. LAB-L06 supplies the frozen panel. The W13 system cards, release entry, outage, authorization expiry, projected costs, thresholds, decisions, and ledger events are authored for instruction. No live platform, account, API, browser automation, payment, or personal data is involved. The case tests whether another analyst can reproduce a monitoring decision, not whether the decision rule is universally correct.

PAPER-29, PAPER-38, PAPER-12, PAPER-23, and PLAT-04 remain bounded reference routes. None establishes the case facts or authorizes hidden-backend inference. A same-time alias difference does not identify a hidden backend change.

## 1. Frozen plan

Plan `MON-W13-001`, version `1.0`, freezes:

- one event for each query–surface–time-block–repetition cell;
- LAB-L06’s 20 queries, SYN-A/SYN-B surfaces, B-01/B-02/B-03 blocks, and three repetitions;
- mention as the incident demonstration metric, while citation, entailment, absorption, and referral remain distinct;
- complete-response denominators for outcome rates and explicit noncomplete rows;
- scheduled outcome looks only after each complete block;
- continuous monitoring of authorization, privacy, policy, evidence preservation, rate limits, and budget;
- no outcome-success stopping claim;
- incident precedence `STOP_AND_ROLLBACK > PAUSE > REBASELINE > CONTINUE`;
- account-free, network-free snapshot mode as the only approved collection state.

The plan is frozen before incident interpretation. An unplanned look or changed threshold would be appended as a deviation.

## 2. System cards and the alias boundary

| Field | `SYS-A-ALIAS` | `SYS-B-EXPLICIT` |
|---|---|---|
| LAB-L06 surface | SYN-A | SYN-B |
| Route type | Authored dynamic-alias example | Authored explicit-configuration example |
| Public label | `SYN-ALIAS` | `SYN-EXPLICIT-2026-06-A` |
| Account | None; supplied snapshot | None; supplied snapshot |
| Session | Not applicable to frozen CSV | Not applicable to frozen CSV |
| Locale | `en-EX` teaching value | `en-EX` teaching value |
| Collection mode | Offline instructor snapshot | Offline instructor snapshot |
| Hidden backend | Unknown / nonexistent as a real platform claim | Unknown / nonexistent as a real platform claim |
| Authorization | Course-owned fixture only | Course-owned fixture only |

This mapping teaches the record structure. It is not a claim that SYN-A and SYN-B are real products or versions.

In B-02, the analyzer reports SYN-A mention 25/59 = 0.423729 and SYN-B mention 31/60 = 0.516667. Their same-block difference is 0.092938. The only valid interpretation is a descriptive difference between two authored surface labels under the frozen panel. It cannot identify routing, model, index, cache, retrieval, or policy causes.

## 3. Deterministic LAB-L06 reproduction

Run from `course-labs/L06_repeated_measurement`:

```bash
python3 scripts/analyze_panel.py \
  --panel data/panel.csv \
  --output /tmp/geo-l06 \
  --minimum-queries 20
```

Expected terminal line: `L06 PASS: 360 events, 20 queries, 2 surfaces, 3 blocks`.

The output directory must contain exactly:

- `tidy_panel.csv`
- `metric_estimates.csv`
- `time_drift.csv`
- `query_mix_sensitivity.csv`
- `missingness.csv`
- `data_dictionary.json`
- `validity_boundary.json`
- `run_manifest.json`

The validity record reports 360 events, 354 complete events, six noncomplete events, 20 queries, two surfaces, three repetitions, and three blocks. It warns that repeated events for one query are dependent and Wilson intervals are descriptive only.

## 4. Panel audit and descriptive rates

The designed panel equality is `20 × 2 × 3 × 3 = 360`. Every key is unique. Six rows have response status `missing`; none is silently deleted or converted to a negative outcome.

| Surface | Block | Mention numerator | Complete denominator | Rate | Missing/designed |
|---|---|---:|---:|---:|---:|
| SYN-A | B-01 | 28 | 58 | 0.482759 | 2/60 |
| SYN-A | B-02 | 25 | 59 | 0.423729 | 1/60 |
| SYN-A | B-03 | 24 | 60 | 0.400000 | 0/60 |
| SYN-B | B-01 | 31 | 58 | 0.534483 | 2/60 |
| SYN-B | B-02 | 31 | 60 | 0.516667 | 0/60 |
| SYN-B | B-03 | 29 | 59 | 0.491525 | 1/60 |

SYN-A first-to-last mention difference is −0.082759. SYN-B is −0.042958. These are synthetic descriptive drift values. They do not establish a release effect, platform mechanism, or causal intervention.

## 5. Frozen action rules

Evaluate hard gates first. Authorization expiry, privacy exposure, prohibited collection, evidence-preservation failure, policy conflict, or approved-cost-cap breach triggers `STOP_AND_ROLLBACK` when containment is specified. A persistent rate-limit conflict also stops.

If hard gates pass, a recoverable outage, noncomplete proportion above 0.10 in the incident batch, rate-limit warning, or unknown configuration requiring diagnosis triggers `PAUSE`. If no pause applies but a known configuration or protocol identity changes, trigger `REBASELINE`. If hard gates pass, no pause applies, no comparability boundary changes, and noncomplete proportion is at or below 0.05, trigger `CONTINUE`. Values between 0.05 and 0.10 require an authored quality review; none appears in this fixture.

Rollback target `SNAPSHOT-APPROVED-001` is the course-owned offline snapshot mode. Verification requires the frozen panel SHA-256 and successful LAB-L06 reproduction.

## 6. Incident one — continue

`INC-01` occurs at the scheduled B-01 look. Across both surfaces, four of 120 designed events are noncomplete:

`4 / 120 = 0.033333`.

This is at or below the 0.05 continue threshold. Authorization, privacy, policy, evidence preservation, and budget gates pass. The deterministic decision is `CONTINUE`.

Continue does not mean that mention improved, that uncertainty is small, or that a live panel is stable. It means the frozen authorized procedure permits the next planned block. The four noncomplete rows remain in the panel.

## 7. Incident two — rebaseline

`INC-02` occurs before B-02. A supplied release card states that the authored explicit configuration record changes from `SYN-EXPLICIT-2026-06-A` to `SYN-EXPLICIT-2026-06-B`. The dynamic alias card still has `backend_state: unknown`. No hard gate fails, and no outage requires pause.

The deterministic decision is `REBASELINE` at the B-02 boundary. B-01 remains regime `REG-01`; B-02 and later approved observations enter `REG-02`. Do not pool the regimes without an explicit bridge analysis.

This decision follows the changed configuration identity, not the B-02 outcome. The 0.092938 alias/explicit mention difference remains descriptive. The case cannot say that a backend mapping changed or caused the difference.

## 8. Incident three — pause

`INC-03` injects a simulated outage into a 20-cell B-03 mini-batch. Six cells receive the authored state `unavailable`:

`6 / 20 = 0.300000`.

This exceeds the 0.10 pause threshold. Authorization and privacy remain valid, and no cost cap has yet failed. The deterministic decision is `PAUSE`. Preserve realized order, first attempts, and the outage evidence. Assign an owner and expiry. Resume only through a new ledger event after the collection regime, rate state, and retry authorization are confirmed.

The injected mini-batch does not alter `panel.csv` or its LAB-L06 outputs. It exercises the decision rule on a supplied incident card.

## 9. Incident four — stop and rollback

`INC-04` occurs before a simulated restart. The supplied authorization expired, and the projected restart cost is 12 units while the approved remaining budget is eight units. Either condition is sufficient to stop. Together they produce `STOP_AND_ROLLBACK`.

No live request occurs. Rows collected outside authorization are not admitted. The rollback restores `SNAPSHOT-APPROVED-001`, verifies the panel hash and analyzer pass, and appends a completion event. It does not delete the outage or hard-gate incident.

## 10. Append-only ledger reproduction

The fixture contains eight events:

| Sequence | Event | Type | Parent | Decision |
|---:|---|---|---|---|
| 1 | `EV-001` | plan frozen | none | `NONE` |
| 2 | `EV-002` | B-01 scheduled look / INC-01 | `EV-001` | `CONTINUE` |
| 3 | `EV-003` | release and configuration change / INC-02 | `EV-001` | `REBASELINE` |
| 4 | `EV-004` | B-02 scheduled look | `EV-003` | `CONTINUE_WITHIN_REGIME` |
| 5 | `EV-005` | outage / INC-03 | `EV-004` | `PAUSE` |
| 6 | `EV-006` | authorization and budget hard gate / INC-04 | `EV-005` | `STOP_AND_ROLLBACK` |
| 7 | `EV-007` | rollback verification | `EV-006` | `ROLLBACK_COMPLETE` |
| 8 | `EV-008` | evidence-preserving closure | `EV-007` | `CLOSED` |

Each event has a contiguous sequence, unique ID, monotonic recorded time, valid parent, system-card or plan pointer, evidence pointer, reason code, previous hash, and row hash. The first previous hash is 64 zeroes. Later rows use the previous row hash. Canonical compact JSON with sorted keys is hashed with SHA-256. A correction would append a ninth row rather than modify history.

The hash chain makes mutation detectable under this file process. It does not prove the factual accuracy of an event or the security of external storage.

## 11. Planned looks and change-point interpretation

The plan permits outcome looks after complete B-01, B-02, and B-03 only. Hard-gate monitoring remains continuous. The release/configuration event is a known operational change point and justifies rebaseline. It does not establish an outcome cause.

The authored alert also flags an absolute block-to-block primary-rate shift of at least 0.10 or an incident-batch noncomplete proportion above 0.10. An alert opens investigation; it does not announce a model update. A three-block fixture cannot validate detector sensitivity, false alarms, or production tuning.

No unplanned outcome look appears in the frozen ledger. If one did, it would become a deviation and reduce later confirmatory language.

## 12. Reading boundaries

PAPER-29 supports repeated-observation questions in its own Swiss-German, four-vertical, January–March 2026 setting. Its finite run/window findings and exclusions do not define universal monitoring thresholds or isolate token sampling.

PAPER-38 is a single-author vendor preprint using unreleased commercial data, varying cohorts, provider policies, vendor metrics, and proposed future protocols. It is not an independently reproduced causal intervention study.

PAPER-12 uses a locked arXiv v2 fixed candidate slate and named model calls. It does not establish live retrieval into the slate, future-version stability, or business outcomes. PAPER-23 uses locked arXiv v2/KDD 2026 in a reconstructed pipeline, conditional target selection, and study-specific components. It does not disclose a proprietary engine or establish production causal effects.

PLAT-04 is a bounded official public-preview interface case. Its citations, cited-page, sampled grounding-query, and trend labels on specified Microsoft surfaces do not indicate rank, authority, placement, cross-engine share, or business outcome.

## 13. Bounded conclusion and self-check

The frozen LAB-L06 panel reproduces 360 events, 354 complete events, six noncomplete events, and descriptive metric/drift outputs. Under the authored W13 rules, INC-01 yields `CONTINUE`, INC-02 yields `REBASELINE`, INC-03 yields `PAUSE`, and INC-04 yields `STOP_AND_ROLLBACK`. The eight-event ledger and final hash are reproducible.

This case does not evaluate a live platform, a real product release, production detector quality, hidden backend state, causal treatment effect, user behavior, or business outcome.

Self-check:

- Are system state, time, session, account, locale, order, failure, and release fields recorded?
- Are unknown backend fields still unknown?
- Are outcome looks planned and separated from continuous hard-gate checks?
- Are decisions derived from frozen thresholds and precedence?
- Are deviations and incidents appended rather than rewritten?
- Is the rollback target approved, exact, and verified?
- Can another analyst reproduce all four decisions and the hash chain without network access?

If any answer is no, the monitoring conclusion is not ready.
