Worked case · Reference condition · 12 figures

Decision replay

Make decisions replayable

Figure 01 / 12

Determine the eligible population first

Determine the eligible population first — Decision replay. Count; records. Exact values are in the figure data below.
Count; records

Of 6,800 source records, 6,732 are within the stated synthetic scope and 68 are outside it. Eligibility here is an explicit teaching input, not a legal conclusion. Production classification must use the actual entity, product, activity, jurisdiction, and facts.

Figure data and text version
Scope stateRecords
Within stated scope6,732
Outside stated scope68

Historical replay should reproduce what the system knew and which policy was eligible to run. It must not execute the financial effect a second time.

The reference case starts with the stated population and a functioning evidence path. The owner is decision platform.

All amounts, rates, capacity limits, and outcomes in this case are synthetic. The three conditions are separate assumptions for comparison. A better result in the response condition is not measured proof that the proposed control causes that improvement. The figures expose the calculation and its limits; a real deployment needs its own evidence.

Read the result

The case identifies 6,732 eligible records from a source population of 6,800. The required workflow completes for 6,530, but 98 completed records miss the illustrative internal target. Another 202 remain incomplete. Communication evidence covers 6,465 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

Model inputs and calculated values

Inputs below are the case-specific values. Each figure states the condition-specific assumptions and units used in its calculation. Calculated values are rounded for display.

InputValue
population6,800
eligibility0.99
Calculated valueResult
population6,800
eligible6,732
excluded68
complete6,530
incomplete202
late98
ontime6,432
notices6,465
undelivered65
pending82
reviewed120
Figure 02 / 12

A control can miss eligible records

A control can miss eligible records — Decision replay. Count at a fixed observation cutoff. Exact values are in the figure data below.
Count at a fixed observation cutoff

The required workflow completes for 6,530 of the 6,732 eligible records. The 202 remainder needs an owned exception path. Reporting completion as a percentage of all source records would answer a different question and could hide the actual coverage gap.

Figure data and text version
MeasureRecords
Eligible records6,732
Workflow completed6,530
Workflow incomplete202
Figure 03 / 12

Completion and timeliness are distinct outcomes

Completion and timeliness are distinct outcomes — Decision replay. Count; exclusive states within eligible population. Exact values are in the figure data below.
Count; exclusive states within eligible population

The illustration applies an internal target, not a statutory deadline. Of 6,530 completed records, 98 miss that target and 6,432 meet it. The 202 open records are a third state; do not automatically classify them as timely merely because their final outcome is unknown.

Figure data and text version
OutcomeEligible records
Complete within target6,432
Complete after target98
Still incomplete202
Figure 04 / 12

An obligation record connects authority to behavior

An obligation record connects authority to behavior — Decision replay. Control contract. Exact values are in the figure data below.
Control contract

This case implements make decisions replayable. The record separates scope, trigger, required action, ownership, and retained proof. Exact legal duties belong to the applicable source and interpretation; the timing and counts in this worked example are synthetic.

Figure data and text version
ElementIllustrative value
Control subjectDecision replay
ScopeThe eligible population defined above
TriggerA replay calls the live payment adapter and creates another instruction.
Required behaviormake decisions replayable
Ownerdecision platform
EvidenceVersioned event, action, and communication records
Figure 05 / 12

Different clocks start from different facts

Different clocks start from different facts — Decision replay. Internal teaching timeline; not a legal deadline schedule. Exact values are in the figure data below.
Internal teaching timeline; not a legal deadline schedule

These relative times are illustrative service targets. They deliberately distinguish customer contact, receipt by the institution, classification, investigation, and communication. A routing delay must not silently replace the original receipt time when that fact matters.

Figure data and text version
EventIllustrative timeRecord
Customer reportT0Original channel and words
Institution receiptT0 + 5 minutesRetained receipt timestamp
ClassificationT0 + 20 minutesApplicable process and owner
Internal review targetT0 + 1 dayInternal target only
Outcome communicationAt decisionContent, destination, and delivery state
Figure 06 / 12

Evidence fields fail independently

Evidence fields fail independently — Decision replay. Count; overlapping field-level checks. Exact values are in the figure data below.
Count; overlapping field-level checks

Each row is one evidence requirement over the eligible population. The same record can fail several checks, so the absent counts across rows must not be added as though they were distinct customers. Completeness does not itself prove that a field is accurate.

Figure data and text version
Evidence fieldPresentAbsent
scope6,66567
trigger6,69834
action6,597135
notice6,66567
evidence6,564168
Figure 07 / 12

A generated notice is not a delivered notice

A generated notice is not a delivered notice — Decision replay. Count; generated equals delivered plus unresolved. Exact values are in the figure data below.
Count; generated equals delivered plus unresolved

6,530 completed records generate a modeled notice event. 6,465 have a delivered state and 65 do not. The system must distinguish generation, dispatch, delivery evidence, and any required follow-up under the actual process.

Figure data and text version
Communication stateNotices
Generated6,530
Delivered state recorded6,465
Delivery unresolved65
Figure 08 / 12

Authority differs by operation

Authority differs by operation — Decision replay. Illustrative permission matrix. Exact values are in the figure data below.
Illustrative permission matrix

The access matrix is a proposed teaching separation of duties. Read, propose, approve, and administer are distinct capabilities. The final policy must match the organization’s actual roles and obligations, with controlled emergency access and an audit trail.

Figure data and text version
RoleRead evidencePropose actionApprove release
decision platformScopedYesNo
Independent approverScopedNoYes
SupportLimitedRequest onlyNo
System administratorOperational logsNoNo
Figure 09 / 12

Exceptions need capacity and a closing state

Exceptions need capacity and a closing state — Decision replay. Records per observation window. Exact values are in the figure data below.
Records per observation window

The control has 202 incomplete records. The available exception capacity covers 120, leaving 82 pending. A pending state requires an owner and a next action; changing a status label without resolving the required behavior does not close the gap.

Figure data and text version
Queue itemRecordsMeaning
Exceptions opened202Eligible workflow incomplete
Capacity applied120Records handled in this window
Pending exceptions82Still require an owned response
Figure 10 / 12

A rate includes its denominator

A rate includes its denominator — Decision replay. Percent; named populations. Exact values are in the figure data below.
Percent; named populations

These rates deliberately use different populations. Overall throughput, eligible coverage, completed-record timeliness, and delivery evidence are not interchangeable. Each needs the same cohort, cutoff, and definition every time it is compared.

Figure data and text version
MetricNumeratorDenominatorPercent
Eligible coverage6,5306,73297
On-time among completed6,4326,53098.5
On-time among eligible6,4326,73295.54
Delivered among generated6,4656,53099
Figure 11 / 12

A change needs an evidence trail

A change needs an evidence trail — Decision replay. Control-change lifecycle. Exact values are in the figure data below.
Control-change lifecycle

The trigger is A replay calls the live payment adapter and creates another instruction.. A controlled change connects the revised requirement or interpretation to implementation, replay, customer impact, and approval. The old version remains relevant to decisions already made under it.

Figure data and text version
StageRetained proof
InterpretScope, source, effective date, and owner
ImplementVersioned logic, data contract, and message template
VerifyBoundary cases and affected-population comparison
ReleaseApproval, start time, and rollback condition
CorrectAffected records and customer outcome where required
Figure 12 / 12

Correction follows the affected population

Correction follows the affected population — Decision replay. Illustrative correction responsibilities. Exact values are in the figure data below.
Illustrative correction responsibilities

A remediation map links the defect to affected records, financial consequences, communication, and closure evidence. It should retain exclusions and unresolved cases. A change that prevents future failures does not by itself correct earlier customer outcomes.

Figure data and text version
FromToRelationship
Decision replayAffected populationReproducible query
Affected populationFinancial reviewAmount and balance impact
Affected populationCustomer messageRequired communication
Financial reviewClosure evidenceVerified adjustment
Customer messageClosure evidenceDelivery and follow-up

Connect the result to the system

Separate pure decision evaluation from effect execution and pin the original inputs and versions.

Check the population, evidence, permitted action, and actual effect together. A balanced calculation can still use the wrong population; a successful response can still leave an unknown financial outcome. The case’s numerical result applies only to its stated assumptions.

Sources and further reading

The chapter sources support the concepts and scope. They do not prescribe the synthetic model rates.

  1. PostgreSQL: transaction isolation
  2. Stripe: idempotent requests (provider example)
  3. Google SRE: handling overload