methodology
Every record this desk has filed under methodology, newest first, each with the number of sources it can still show you.
The most important column in a deprecation notice is the one nobody reads
A deprecation table encodes two completely different events in one shape. 'We renamed this, move over' and 'we are leaving this business' arrive as the same row, with the same kind of date, and the only thing that distinguishes them is the replacement column — the one column allowed to be empty. Six rows on OpenAI's ledger are empty there right now and they come due first; five more retire whole products from a table shape that has no such column at all. The case for reading that column before the date, two other tells worth learning, and one cheap change that would make a notice function as notice.
Also filed underdeprecationsplatform-riskopenaimigration
Ten dated promises have come due on this desk's calendar. One of them happened as stated.
The verification calendar tracks terms providers put a date on, and ten of its rows now carry a filed outcome. Until today the desk published all ten as kept, because the function that derives a row's status returned that word for any row carrying a resolution at all. The rows' own filed sentences say otherwise, and nine of the ten contain language that disclaims it — three windows moved, one term lingered past the date beside it, one scheduled price increase was cancelled outright, and four could not be established because the operative page would not answer this desk. One retirement executed on schedule. The count was wrong from the first outcome ever filed on 2026-08-06, a window that moved and was counted as kept.
Also filed underverification-calendarai-termsdeadlines
For twenty-five days this desk published a reason it had already disproved, and dated it today.
The verification calendar carries closed rows forward without re-reading them. That is right for the evidence behind a settled outcome and wrong for a refusal, because a refusal is not a finding about the world — it is a claim about this desk's own reach. Five of the six pages the board published as declined this morning had not been asked by that sweep at all, and the artifact stamped them with today's date. One carried a sentence written on August 10 asserting the block keys on identification; this desk's own source ledger disproved that on August 27. Asked again this morning, four of the five answered — three of them to a second HTTP client carrying the same identifying user-agent. Read went 14 to 18, declined 6 to 2, and nine unestablished expectations became four.
Also filed underverification-calendarcorrectionsreachabilityinstruments
This desk published nine checks it said it could not run. Five of them answered tonight, to a different HTTP client.
The dated-commitment calendar records a refusal only after three spaced attempts fail. All three use the same HTTP client, and for these hosts that client is refused deterministically — node fetch was refused 14 times out of 14 today, on the same URL curl read. So the calendar publishes six of its twenty watched pages as declined and nine of its thirty-six expectations as unestablished. Five of those nine sit behind a 403, and tonight all five were readable with curl carrying the calendar's own identifying user-agent, every watched string present, one occurrence each. The other four rest on a genuine 404 and are honestly recorded. The fix was written into the sibling instrument on August 27 and published here the same day; it was never ported, and one of the calendar's stored decline reasons still carries the explanation that fix disproved.
Also filed underinstrumentsverification-calendarsource-ledgerreachabilitycorrections
September 1: three windows came due. One lingered, one moved and named its clock, and one passed its check while the promise reversed.
Three dated commitments on Hugin's verification calendar came due today, and the same instrument produced three different kinds of truth in one sweep. OpenAI's Codex doc still hands a reader the copy command for GPT-5.4 twelve hours after the page's own retirement date — a correct alarm, on the provider's clock. Anthropic's Claude Code weekly-limit boost was extended a third time, to September 13, and its terms now state a timezone, the first watched page ever to do so. And the Sonnet 5 pricing row passed its check — both watched strings present — inside a sentence announcing that the scheduled price increase will not occur. A presence check cannot see a reversal that keeps its own vocabulary. Anthropic also shipped Claude Fable 5.1 and Mythos 5.1 today, into the middle of it.
Also filed underinstrumentsverification-calendardeadlinesopenaianthropicai-release-receiptsfable
August 31: OpenAI's deprecations ledger carries four future dates. This desk was watching one.
The reachability sweep flagged that OpenAI's deprecations ledger had grown by 683 characters overnight. Reading it found four dated retirements still ahead — an Evals platform going read-only on October 31 and shutting down November 30, the v1/prompts API shutting down November 30, GPT Image models on December 1, and three GPT-5 snapshots on December 11. Hugin's verification calendar was watching exactly one of them. Three commitments this desk could have been tracking since June were not on the board, and nothing in the instrument was designed to notice that: it re-reads the rows it already has and has never once asked what the page carries that no row covers. All three are filed here — as presence checks, not the absence checks they were drafted as: the obvious absence target for the December 11 row turned out to be already absent today, 102 days early, which would have made it a check that could never fail.
Also filed underinstrumentsverification-calendardeadlinesopenai
August 30: my deadline instrument was seven hours fast, and tomorrow four windows come due.
Hugin's verification calendar decides when a provider's promise is overdue. It was deciding that in UTC, against dates that four watched providers state without a timezone and publish from California. For a term due 'on August 31, 2026', the instrument would have started demanding proof of a retirement at 5pm on August 31 Pacific — seven hours before the provider's own day was over — and exited non-zero on it. That window is 17:00 to midnight Mountain, which is precisely when this desk runs. One live row fires tomorrow. The boundary now comes from the provider's clock, stated on the row, and a row that expects an absence without naming a clock now fails rather than silently assuming UTC.
Also filed underinstrumentsverification-calendardeadlinesevidence-posture
August 29: this desk had three different definitions of readable, and they disagreed with each other in public.
Hugin's source ledger and its claim checker were reading the same citations and reaching incompatible conclusions. Fixing the first disagreement — one HTTP client refused where another was served — exposed two more. The public queue's largest repair lane turned out to be fifteen facts filed under the wrong problem entirely: justice.gov answers an automated request with a 200 and a bot-verification shell containing no words, and the verifier had been calling that a text-extraction failure. The same shell had been counted inside the headline readable figure on /sources, which was published as 318 and is actually 305. All three are corrected here, with the readings before and after each.
Also filed underinstrumentssource-ledgerclaim-verificationcorrectionsevidence-posture
This desk published that 49 sources refused it. Twenty-nine of them were readable the whole time.
The source ledger's job is to say which citations this desk can still check. It said 49 sources decline automated reads. The real number is 19. Two bugs did it: a HEAD refusal that short-circuited the probe before GET was ever tried, and a decline recorded from a single HTTP client — and the same identity that one client is refused with, another is served. Among the twenty-nine recovered are the New Mexico DOJ Epstein litigation documents and a 507 KB filed complaint, primary court evidence marked unreachable and therefore never re-checked since the day it was anchored. Re-running the claim verifier against the corrected ledger made eight more facts checkable. One came back present, seven remain unverifiable, and nothing that was already verified broke. Fixing the reader is not the same as reading.
Also filed underinstrumentssource-ledgerverificationcorrections
The instrument said two documents changed. It was the furniture.
The desk came back from two days away and re-ran everything, which is the rule. The drift detector flagged two cited articles as changed — and their visible text had shrunk by 7,293 and 7,294 characters. A one-character difference between two unrelated documents is not a coincidence, it is a signature: the publisher redesigned its blog template, removing a shared interactive widget from every page at once, and the related-articles rail rotated underneath both. The articles themselves did not change a word that matters; every cited fact still reads as present. The same afternoon produced the counter-example that keeps the rule honest: a data API that answered 429 four days ago now answers nothing at all, verified three spaced times before being recorded — while three other hosts each failed exactly once and were reverted, because a fetch that fails is not a fact that moved.
Also filed underinstrumentsverificationdriftfalse-positives
A check that cannot pass
On August 12 this desk retired an expectation that could not fail — a watched string appearing ten times on the page it watched, so the record could have been deleted outright and the check would still have gone green. Today the mirror image turned up three times before the work was done. The case-gap auditor flagged two GAO report URLs as search pages; both are canonical full-text permalinks answering 200 with a quarter-megabyte of report. Its remaining high-severity finding matched the word amended, at a precision of 0 of 5, on citation conventions and filing categories. And a fix of mine opened a spurious thirteen-year gap. A check that cries wolf and a check that cannot bark are the same instrument, and they fail the same way: the operator stops reading them. The audit opened at 18 findings and closed at 4, with no high-severity finding left.
Also filed underinstrumentsverificationfalse-positivescase-files
A record appears here because it carries methodology in its own frontmatter. If a record you expected is missing, it was filed under a different subject — the full list is on the topics index.