Witness scorecard
Hours under v3/ are recorded by several machines at once
(the witnesses), and the merge keeps the union of what they heard. This is cut 1 of the
scorecard that measures each of them: not whether the archive is complete, which the
coverage audit answers, but how much each machine contributed to what
is here, and which of them the fleet could stand to lose.
Status. Countersigned 2026-09-04. Publication latency (one measure of eleven) is HELD: the publish cadence is under a live certification of 24 consecutive hours and no instrument is borrowed from a lane mid-certification; the latency row lands when it completes. Retirement is the operator's ruling; everything below recommends.
Instrument. Census witness-census-cut1.json,
sha256[:16] c7510d22113927b6 (verified at assembly, 2026-09-04T22:04Z), built
by a 13-arm census over 422 merged manifests. Values below are from that
census unless marked otherwise. Host details (provider, region, cost) live in a private
appendix and are not published, for the same reason the
machines table gives no provider: it would tell somebody
where to aim.
Observation floors
Vintage has two halves: when we looked, and how far back the instrument could see.
- Corpus: 422 generated hours at census time. Rows era = 287 hours,
floor
2026-08-23T21(the birth of the per-witness accounting field); the 135 pre-field hours read NO-CLASS: a could-not-look, never a zero. - Winner-attribution era (won-share): floor
2026-08-29T02(the birth of the winner-attribution field); 162 hours for the standing fleet, 57 hours fora, whose era ended first. h's 17 captured-never-merged hours (08-23T12 → 08-24T04) are excluded from availability: captured-never-merged is a fact about the merge, not about the witness. They are queued to merge after the certification window.
Per-witness measures
"Enrolled" is the registry span; "first accounted" is the first hour with rows in a merged manifest. The two meanings of "from" are both shown. Availability is hours with rows > 0 divided by hours enrolled in the rows era; presence is not contribution, so it counts rows, never a merely-present key.
| measure | a | b | c | e | h |
|---|---|---|---|---|---|
| enrolled (registry from → to) | (pre-registry) → 08-31T10 (RETIRED) | (pre-registry) → open | 08-18T06 → open | 08-27T05 → open | 08-23T12 → open |
| first accounted hour | 08-23T21 | 08-23T21 | 08-23T21 | 08-27T05 | 08-24T05 |
| enrolled hours in rows era | 182 | 287 | 287 | 207 | 287 (279 after the merge-fact exclusion) |
| hours with rows | 182 | 182 | 280 | 207 | 279 |
| availability | 1.000 | 0.634 | 0.976 | 1.000 | 1.000 (see note) |
| zero hours / episodes | 0 / 0 | 105 / 4 | 7 / 1 | 0 / 0 | 0 / 0 |
| volume vs peer median (median · p5) | 1.000 · 0.920 | 1.000 · 0.729 | 1.000 · 0.754 | 0.999 · 0.804 | 1.000 · 0.376 |
| unique contribution (BOUND, upper, product-hours) | ≤201.4M (1274) | ≤293.2M (2009) | ≤746.7M (2009) | ≤83.8M (1449) | ≤231.0M (1953) |
| won-share (own era; ORDER not quality) | .0024 (57h) | .0013 (162h) | .0166 (162h) | .9578 (162h) | .0234 (162h) |
| discord product-hours (>20% off peer median; flag not verdict) | 173 | 278 | 252 | 88 | 537 |
| publication latency (median · p95) | HELD | HELD | HELD | HELD | HELD |
h availability, the merge-fact exclusion. The census reports
h at 0.9721 = 279/287, keeping its 8 in-era captured-never-merged hours
(08-23T21 → 08-24T04) in the denominator. Those 8 are exactly the rows-era portion of
the 17 h-backfill hours, and the spec (§2.2/§3) rules captured-never-merged a merge fact,
not a witness fact: excluded from availability. Applying the spec's own rule (the census
computed the raw ratio; the scorecard applies the exclusion) removes the 8 from numerator
and denominator both: 279/279 = 1.000. The divergence from the census's
0.9721 is this exclusion and nothing else.
Won-share standing warning. Won-share is a property of REGISTRY ORDER:
e wins .9578 of output rows because ties break to the highest registry rank,
not because e's rows are better. A retire list read off winner share would
retire healthy witnesses.
Unique contribution is a BOUND in cut 1 (at most
rows_merged − max(other rows_by_domain)); the exact merge-side figure is
built and held until the certification window closes. No recommendation below rests on it.
Zero-episode causes, named where the record has one
- b (105 zero hours, 4 episodes): 08-23/22 → 08-24/00 (3h) and 08-29/03 → 08-31/12 (58h), where the record names a redis AOF crash-loop / OOM loop; 08-31/14 → 09-01/12 (23h) and 09-01/14 → 09-02/10 (21h), no named cause on this record; the incident register owns them.
- c: 09-02/00 → /06 (7h), no named cause on this record.
Per-witness notes
- a: era SHORT (182 h) and CLOSED (retired 08-31T10, an end-date in the registry). Within its era: availability 1.000, the only witness with volume p5 ≥ 0.9 (0.920), zero zero-hours. Its era-scoped record is the strongest in the fleet.
- b: availability 0.634 sits 0.366 below the fleet median (1.000), driven by 105 zero hours in 4 episodes; volume p5 0.729 when present; discord 278.
- c: 0.976 availability, one 7-hour episode; the largest unique-contribution bound (≤746.7M), which cut 2 can turn into a number.
- e: availability 1.000 over 207 h, zero zero-hours, lowest discord (88); volume p5 0.804, below the 0.9 best-performer bar. Won-share .9578 is the order artefact above, not evidence.
- h: availability 1.000 after the merge-fact exclusion (279/279, note above); volume p5 0.376 and discord 537. h's low-volume tail is the fleet's widest, flagged for cut 2 with latency beside it.
Recommendations (DRAFT; the operator rules)
Best performer: no ACTIVE witness currently passes the bar (highest availability AND volume p5 ≥ 0.9 AND p95 latency inside the line, latency HELD besides). The only witness that passed availability and volume is a, which is retired: its era-scoped record (1.000 availability, p5 0.920, 0 zeros) is the source of the search spec for new witnesses. e is the closest active witness (1.000 availability, 0 zeros, lowest discord) and fails only the volume bar (p5 0.804). The cut-1 recommendation derives the search spec from a's and e's shared characteristics; in public form: same provider class and region family, kernel held, redis bound in compose, scoped key. Never the private values on a public surface.
Retire candidate: b (DRAFT). Availability 0.634 is more than 20 points below the fleet median (1.000 − 0.634 = 0.366); 105 zero hours across 4 episodes, two with named causes. The second criterion (unique contribution near zero) cannot be settled in cut 1: the measure is a bound, and b's bound (≤293.2M) is an upper limit, not an estimate. The third (cost) awaits the private appendix. So b is named on the fully-instrumented measures, with the two unsettled criteria stated beside it, and the verdict is the operator's. A retirement is an end-date in the registry, never a deletion.
No other witness meets the retire predicate: with the fleet median at 1.000, a, e and h sit AT it and c is 2.4 points below, nowhere near the 20-point bar. Only b clears it.
Bounds, and what cut 2 adds
The pre-field era reads NO-CLASS (135 h); a's era is short and closed; the latency row lands after the cadence certification completes (the count itself is its instrument); unique contribution becomes exact when the held merge-side change lands post-certification; h's 17 hours merge in the same window. Each of those turns a stated bound into a number, which is the whole difference between cut 1 and cut 2.