SHIPQ · DHF CONTROLLED RECOVERY

The hardest case begins after a write has already changed the remote document.

A Google Docs canary write produced a side effect and then failed its structure assertion. DHF had to contain the mutation, restore a trusted state, obtain fresh authority, and prove the final result.

Selected case: partial write → fail closed → native rollback → independent readback → new manifest → fresh authorization → controlled completion.
5allowlisted documents
4changed H1 sections
3written documents
2 / 0no-write documents / unrolled writes

Why this case was selected

Alternatives were narrower

Lifecycle routing, worktree governance, fixtures, status publication, and cloud analytics each exercised only part of the framework.

This case crossed every boundary

It combined scoped authorization, live revision state, an external side effect, a failed postcondition, rollback, independent verification, and reauthorization.

Four state worlds had to agree

Business objective

Synchronize Git-tracked content into existing Google Docs while protecting document IDs, tab topology, unmapped sections, and permissions.

Observed incident

The canary content existed, but inherited an H1 style. The writer returned readback_structure_mismatch: the remote state changed without satisfying the contract.

Scope

Five exact documents, one mapped tab, changed sections only; no create, copy, delete, share, permission, or topology changes.

Authority

Approval bound a live owner message to the manifest digest and target revision. Restored facts could not silently renew permission.

DHF changed lanes when the facts changed

The route moved from execution to freeze, restore, and revalidation. Only new evidence and new authority could return it to execution.

01–06

Recover → Govern → Specify → Authorize → Execute → Validate

Recover the current state, classify risk, bind the manifest, confirm the exact action, execute in stages, and read back each stage.

07–12

Rollback → Fact check → Fix → Re-gate → Reauthorize → Handoff

Restore natively, verify independently, make the minimum local repair, generate fresh evidence, obtain fresh authority, and record the terminal state.

SAFE controlled every state change

S · Specification

Five allowlisted documents, changed sections only, and explicit content, structure, style, and tab completion criteria.

A · Authorization

Live scoped confirmation bound to digest and revision; a retry required new authority.

F · Facts

Source commit, pre/post revisions, permanent failure receipt, receipt v3, and staged fresh readback.

E · Error recovery

Mismatch classification, no blind retry, native restore, independent verification, and explicit handoff.

RECOVER: seven stages after a failed or uncertain effect

R1Recognize

Recognize the partial or uncertain outcome.

E1End

End further mutation.

CCapture

Capture the failed receipt and scope.

OObtain

Obtain the last trusted state.

VVerify

Verify restoration independently.

E2Escalate

Escalate for fresh authority.

R2Resume

Resume only from proven state.

Boundary: RECOVER restores facts and continuity. It does not grant a connector retry, publication, production write, or destructive action.

Failure cannot jump directly back to execution

MISMATCH ─X→ RETRY

An error is a reason to stop, not authority to repeat a side effect.

RESTORED ─X→ EXECUTE

Restoration closes the old incident; it does not grant a new write.

OLD DIGEST ─X→ WRITE

A changed HEAD, manifest, digest, or revision invalidates old confirmation.

SUCCEEDED → FULL READBACK

API success alone is insufficient; completion requires readback and a terminal record.

SAFE controls became TRUST value

Trust and quality

Mismatch, restored, and succeeded remained distinct claims.

Risk control

The canary stopped the defect before it reached the remaining documents.

Productivity and continuity

Only changed sections were written, no-change documents stayed untouched, and the recovery path was known.

Traceability

Manifest, revisions, receipts, and authorization formed an auditable chain.

Evidence and claim boundary

  • Final scope: 5 allowlisted documents, 4 changed H1 sections, 3 written documents, 2 no-write documents, and 0 unrolled writes.
  • The failed readback_structure_mismatch receipt remained evidence after native restoration.
  • Independent readback verified content and styles before a new HEAD, manifest, digest, revision, and owner authorization permitted another canary.
Evidence boundary: this historical case does not prove current connector authority or authorize a new remote write. Current scope, revision, and permission must be checked again.