51 of 55. That is how many of the “already cleared” verdicts an adversarial audit refuted after I fanned a backlog review out to sub-sessions and got back 45 tidy files, each one confident.
Forty-five files that looked finished
A ticket migration had dumped 644 untouched comments into 45 “Story” buckets under one epic, 54 open items in all (45 Stories plus 9 real tickets). The job was to work out which comments described work that had shipped, died, or been superseded, so a human only had to decide about the survivors.
That is a fan-out shape. The Stories are independent, each is a bounded corpus, and a sub-session per Story can read git, read the live product, and write a verdict file. I dispatched them and got 45 files under a verdicts/ directory. Every file sorted its comments into SHIPPED, DEAD, SUPERSEDED, or still open. They read like finished work.
I started acting on them. Cleared items were collapsed out of my way, and the plan was to retire Stories on the strength of the files.
What the audit found
I ran a separate adversarial pass whose only job was to refute the cleared verdicts. Of 55 it checked, 51 fell over. The failure was systematic, and it had three causes I could name afterward.
“No commits on the ticket” was read as “never fixed.” Tournament work in this codebase landed under weekly catchall tickets that never referenced the ticket that originated the request. A sub-session that greps for the ticket key finds nothing and concludes the work was abandoned. Another session that greps for the symptom finds it shipped. Each one is confident, and they disagree.
Story titles were a prior session’s guesses, and the workers inherited them. One Story was titled “never-built.” When I looked at it myself, the Dashboard had been built in February 2024 and shelved a day later. A worker told the frame is “never built” will go looking for confirmation of that frame. It found it.
The seed material was itself wrong. The migration’s own summary comment listed three “source-verified findings.” Two of the three were false. Every worker treated that comment as ground truth, so the error was copied 45 times instead of caught once.
There was a fourth surprise in the same pass. I had believed two tickets carried unmerged code, and it was four. Any retirement built on the SHIPPED/DEAD calls would have closed live work. The retire script now refuses those four by key, and I told the next session not to work around it.
What the wrong turn cost
The 45 files were unusable for the one thing I built them for. In the handoff to the next session I had to write, in capitals, that they were good for fragment and merge arithmetic (which comment is a duplicate of which) and that every SHIPPED, DEAD, or SUPERSEDED call inside them was UNRESOLVED. I generated a confident-looking artifact, then had to spend more time teaching the next session to distrust it.
The replacement was slower and worked. Pick one coherent Story. Do the clearing pass myself: date each item against known reworks, check the live product, check git by symptom. Show decisions first with cleared items collapsed at the bottom so they can be audited instead of read. One Story went from 22 comments to 6 decisions to one message from me, resulting in one carved-out ticket and a retirement. Three Stories retired that way, each walked item by item.
The same fan-out, working
Around the same time, I used four parallel reviewers on a teammate’s site-templates ticket before release, and it held up. The difference is what came after. Once the reviewers reported, a separate agent was tasked to adversarially verify the proposed fixes, and it found a real hole in one of them.
The fix turned on createBackup: 1 for the bulk-apply path. That made the bulk path the first caller ever to run Backup_WebsiteTemplate concurrently. Its ID lookup was only ever safe for one request at a time:
var newTemplateRow = SQL.top({ select: "MAX(layouttemplateID) AS maxID" , from: "app." + sport + "layouttemplate" , where: "username = '" + CleanSQL(username) + "'" // username ONLY});if(newTemplateRow && newTemplateRow.maxID) { this.Add_WebsiteTemplate_Files(newTemplateRow.maxID, ...);}Bulk apply posts N requests in parallel, all inserting backup rows under the same username, then each reads the global max. One request can pick up another’s ID, and that ID becomes the folder name. Site A’s files land in site B’s backup, and some backups get no files at all. The backup was the safety net for a path that deletes customer logos with no other copy.
The evidence that this was real came from the code itself. The sibling lookup in Apply_WebsiteTemplate had already been hardened, with a comment saying it is scoped to the page so concurrent bulk requests cannot cross-assign each other’s inserted IDs. The backup path never got the same treatment, because before this change it was single-request only. The verifier also flagged its own limit: it had read the race, not executed it. That caveat is why I trusted it more than the 45 files that had none.
What separates the two runs
Both used parallel agents, and both produced confident output. The reviewer fan-out found a cache-poisoning bug and several file-handling bugs, and I trust it. The comment-triage fan-out produced 45 files I now trust for arithmetic only.
Three things differed.
- The review’s input was a diff. The triage input was 644 comments plus a summary someone had already framed. Workers cannot outrun a wrong frame they were handed.
- The review’s claims were checkable in one file. A race condition is a line of code. “This was never fixed” is a negative, and proving a negative needs a search strategy the worker may not have had.
- The review had a skeptic wired in. Someone was assigned to break the claims before they reached me. The triage run put nobody between the workers and me, and I was the skeptic by default, which is how I paid for the whole run and could retire nothing from it.
My rule now: any verdict of the form “this is done, dead, or superseded” gets audited against the symptom, not the ticket key, before it moves anything. Workers can gather and merge. The word “cleared” has to be earned by something whose only job is to disagree with it.