The alert fired at 6:46 AM. By 8:03 AM I was still staring at a blank brief that had refused to render, and the cron that generated it had already exited zero an hour earlier like nothing was wrong.
The briefing mechanism is new: one standing agent watching the AI and dev-tool space and writing me a morning summary. It has a gate on it. If I’m away from the desk, the display step shouldn’t fire. That gate is correct. A briefing that pushes itself onto a screen nobody’s sitting at is just noise, and worse, if it’s wrong about something it can’t be corrected before it’s seen. So the design was: generate the content, check presence, only render if I’m actually there.
The gate did exactly what it was built to do. I was away. It refused. The problem is what “refused” meant downstream. The away-mode check wasn’t a soft skip, it was a hard stop in the same cron step that would have written the brief anywhere retrievable. No display path meant no persistence path either. When I sat down at 8:03, there was no blank card waiting for me to load, there was nothing. The morning’s brief had been generated, evaluated, and discarded, and I couldn’t tell that from looking. It just looked like the job hadn’t run.
First thing I checked was whether the cron had failed. It hadn’t. Exit code 0, log line present, timestamp right on schedule. That sent me down the wrong path for a while: a clean exit code reads as “worked,” so I went looking for a display bug instead of a generation bug, stale cache, a race with the window agent, a stylesheet not loading. None of that panned out because none of that was true. The actual sequence, once I traced it, was generate content, check presence, presence check fails, log “correctly refused, user away,” exit. The refusal was logged as a success state, which is accurate from the gate’s point of view and useless from mine. I spent close to an hour treating a silent no-op as a rendering bug before I went back and read what the gate itself had written to the log, not the cron’s exit status.
Once I saw “correctly refused” sitting in the log next to “away from the desk,” the defect was obvious. The gate had one output, present or absent, and no third state for “generated but not yet delivered.” Binary gates do this. They’re easy to reason about until the thing they’re guarding has a cost to producing that shouldn’t be thrown away just because the delivery condition failed.
The fix wasn’t to loosen the gate. I didn’t want the brief popping up on a monitor I’m not in front of, and I didn’t want to weaken the away-check to be more permissive, because the whole point of the gate is that it’s supposed to say no under those conditions. What changed is what “no” does. Now the away-mode branch doesn’t just log and exit, it publishes the generated content to a link and writes that link into the day’s log entry instead of nothing. Presence still gates the live, in-place display. Absence no longer gates existence. The content gets written and addressable either way, it’s just that only one of the two paths puts it in front of my eyes automatically.
That’s a small code change, one branch in a cron script that used to be a dead end and is now a fork: display inline if present, publish and link if not. But it fixes a class of failure, not just this one instance. Any gate in our ops repo that’s structured as “check condition, then either proceed or silently stop” has the same shape of risk, work done and then dropped on the floor because the only two states were “shown” and “nothing happened.” The fix generalizes to “shown” and “recorded, retrievable, just not pushed.”
We verified both paths live that same afternoon: once with the desk-presence check passing and the brief rendering in place, once with it forced to the away branch and confirming the link resolved to the same content, timestamped and legible, sitting in the log where I could find it instead of implied by a gap. Two verifications, not one, because the whole point of the fix was that the failure mode had been invisible the first time and I wasn’t going to trust “looks right now” without checking the branch that had actually broken.