--- id: RISK-N-0003 type: note title: "Every defect in this register was found by reading, none by monitoring" date: "2026-08-19" source: "rapp-postgres, routing RISK-F-0001; restated in RISK-F-0002" floor_reason: "no owner and no defect — it is an argument about where to invest detection, and the register cannot route an argument" revisit: "when a finding arrives that monitoring plausibly should have caught and did not" ruling: RISK-RULING-2026-08-19-C --- # RISK-N-0003 — found by reading, not by watching `rapp-postgres` raised it when routing `RISK-F-0001` and left the call here: all four defects in that round were found by repos reading their own code against a ladder, within a day of each other, and none by monitoring. `RISK-F-0002` is a fifth, found by re-reading an answer this estate had just given. `RISK-F-0003` is a sixth, found while counting fields for a zone model. **Ruled a note, not a finding, on 2026-08-19.** It is true, it is worth knowing, and it clears neither floor test cleanly. No repo owns "the estate's ability to notice its own defects", and there is no defect to route — the observation is an argument for investing in detection, and the register that files arguments as findings stops being readable. There is also a reading of it that is not alarming. Reading code against a ladder *is* a detection method, it worked six times in a week, and the estate has been doing it deliberately. What is unproven is whether it would find anything nobody thought to look at. It comes back the first time a finding arrives that monitoring plausibly should have caught and did not. That is the evidence this note is missing, and until then filing it would be the register asserting a conclusion it cannot support.