Case study: a fleet sweep with a real denominator

← Operations Web Function

Case study: a fleet sweep with a real denominator

Candidate redacted meta example — not yet Task Library accepted · Operations Web Function 0.1.0.

Download the complete plugin · Source SHA-256: 3789529ccc0a77bcc7124db70c6735721f7f1f8adbe659361f48307ade6a63c6

On August 13, 2026, a credential-free sweep selected 220 domains from a validated private roster plus one external control and checked all 221. The run wrote an immutable private receipt with the roster and guard hashes, plus the sanitized aggregate in this package.

The lesson is not the number of green sites. The lesson is that checked / declared is part of the verdict. A monitor can accurately report every site it saw while silently missing properties its roster never loaded. Roster source, age, declared count, parsed count, deduplication, and residual categories therefore belong in the same receipt as availability.

This bounded guard classified 197 OK, 0 infected, 2 suspect, 2 down, and 20 unreachable. Those labels did not authorize remediation. Suspect and unreachable observations required another vantage or authenticated follow-up, and the receipt explicitly did not claim that files, users, plugins, databases, or scheduled tasks were clean.

What changed in the reusable SOP:

  • denominator and source freshness are mandatory;
  • every category partition has a residual assertion;
  • control probes run before fleet verdicts;
  • public and authenticated internal checks produce separate evidence;
  • the action ledger projects immutable receipts rather than replacing them.

Evidence: examples/receipts/fleet-aggregate-2026-08-13.json.


This page is generated from examples/case-studies/01-fleet-denominator.md. Do not hand-edit the public copy.

Scroll to Top