The incident
A worker returns a corrupted result.
What decision changed, which boundary was crossed, and can useful work recover?
Recorded incident
Device first
Keep the incident inspectable.
Roles
This page
01 · Controlled fault
Software-injected byte fault. No physical failure observed.
Integrity check
Teaching fixture: unsafe fallback
def authorize(authorized, worker_healthy):
if not worker_healthy:
return True # fails OPEN
return authorized02 · Semgrep
Semgrep finds the fallback. The fix keeps good work.
Before fix
After pinned fix
Recovery matrix
AI advice has no authority to apply a patch.
03 · Custody
Each step has an address. Your browser recomputes the proof.
Incident MMR, recomputed now from recorded leaves
expected
computed …
computed …
Integrity preserves the record; it does not prove that every claim is true.
04 · ClickHouse Cloud
Same incident. Replayed. Read back exactly.
Checkpoints sent
Readback
Readback query
measured once
05 · Akash GPU (separate branch)
Deployed on Akash. Advice in .
Model advice (untrusted · not applied)
06 · Separate custody branch
All leaves verify, including the close.
GPU MMR, recomputed now · not part of the incident MMR
expected
computed …
computed …
Close request
Not claimed
Live vs replay
Public site: recorded replay. magicPRO: live OS polling.
This page makes no sponsor requests. It replays recorded receipts and recomputes their commitments in your browser.
Lower troubleshooting and inference costs are goals we still need to measure.
Privacy and rights
From error to recovery, easier to inspect.
Credentials and proprietary internals stay private. Earlier failures stay in the record.
Original explanatory content © 2026 Biobitworks, CC BY-NC-ND 4.0. Third-party rights retained. Software license not established.
sources: