All notes

2026-08-06

An unrecorded action did not happen

pipera writes every action down with its evidence and its approver, because an unrecorded action cannot be audited, disputed or refunded.

Most operations treat the log as a by-product. The work happens, and somewhere behind it a system writes lines that nobody reads until something breaks. pipera runs the opposite order. The record is not the residue of an action. It is the condition under which the action counts as having been taken at all. Inside this operation, an action that left no record is treated as an action that never occurred, and nothing downstream argues otherwise.

Held as a hard rule rather than a good habit, that changes how the operation is built. A capability that cannot produce a record of what it did is not permitted to act. An action taken outside the log is not handled as a fast exception, it is handled as an incident. This is stricter than it sounds, because the tempting exceptions are always the small ones: a quick manual fix, a setting changed directly inside an account, something done at speed because the alternative was to wait. Those are precisely the actions that later cannot be explained.

A record carries four things and is not a record without all four. What was done, stated as the action itself rather than the intent behind it. When it was done, at the resolution of the action rather than the day. What evidence it rested on, meaning the specific observation that was read before the action rather than a general rationale composed after it. And who approved it, for every action in a class that requires approval, which includes every action that spends money and every action that cannot be reversed. That last rule does not loosen as autonomy rises.

The decision log is open to the client. That is a different arrangement from reporting to the client, and the difference is the entire point. A summary is an editorial act. Somebody decides which decisions were interesting enough to mention, and that somebody is the party being judged. An open log removes the step. The client reads the same rows the operation reads, in the order they were written, including the rows nobody would have chosen to feature. The portal shows all of it and runs none of it, which is the same arrangement as everywhere else in the model: full visibility, no execution rights.

It would be easy to present this as a courtesy to the client. It is not primarily that. The discipline exists because two other parts of the model stop working without it.

The first is autonomy. A capability earns autonomy in steps, and promotion is supposed to rest on evidence: hundreds of successful executions and a clean record before a capability moves up a rung. Demotion runs the other way and is not gradual, since a single incident drops it immediately. Both decisions are arithmetic performed on a list of actions. Without a record per action there is no list, and without a list, autonomy becomes an opinion held by whoever is currently most confident. Some classes of action never reach the top rung at all, refunds among them, and that ceiling only means something if every refund can be shown to have passed through a person.

The second is money. Deliverables are written into the contract item by item, and a deliverable that does not happen has its fee returned. That commitment is only as strong as the operation's ability to settle the factual question underneath it, which is whether the thing happened. An operation running on summaries cannot settle that argument, it can only win it by assertion, because it owns the account of events. An operation running on an open log has already handed the client the material to argue against it. The refund clause becomes decidable rather than negotiable.

Here is what the record does not do. It proves an action was taken and it preserves the reasoning that produced it. It does not prove the action was correct. A wrong decision that was properly logged is still a wrong decision, and the log will describe it accurately, in detail, with its evidence attached. Completeness of the record and quality of the judgement are separate properties, and an operation that confuses them starts producing beautifully documented mistakes.

So the log narrows the argument rather than ending it. What still requires judgement is everything above the row. Whether the evidence read was the right evidence to read. Whether a threshold sat in a sensible place, given that the threshold, not the action, is usually where the real decision was made. Whether an action that was permitted was also wise. Whether a sequence of individually defensible actions is accumulating into a direction the business does not actually want, which is the failure nobody catches from a single row, because every row inside it looks fine on its own. Those readings are made by people, over the record, and the record is the input rather than the answer.

The practical consequence for a company is smaller than it sounds and more useful than it sounds. Disagreements stop being about what happened. They start at the point where they are worth having, which is whether what happened was the right thing to do.

If that is the argument you want to be able to have with a supplier, ask on the call to be walked through a single day of the log before anything else is discussed.