FIELD NOTE / LINKEDIN
A green canary can contain no relevant customer.
The complete written thought and the evidence behind it. The video edition will follow its public release.
The written argument is here.
This approved LinkedIn edition is on the journal now. Its video player and original platform link will appear after each public release is verified.
A green canary can contain no relevant customer.
Video caption
A green canary can contain no relevant customer.
Count relevant requests, not just traffic.
The gate should refuse a false green.
My rule: A quiet chart cannot authorize expansion.
#EricFieldNotes
Full written post / accessibility read
A rollout can report no regressions because the only affected account type never entered the canary. For example, a new approval path applies only to regulated exporters, while the sampled traffic is ordinary accounts. Aggregate health is useful, but it is not evidence for that specific product promise.
Before promotion, name the source decision, affected account class, operation, exact image digest and minimum relevant observations. Compare canary and control for that class. Configure the analysis so zero qualifying events is inconclusive; an aggregate error rate cannot certify a path nobody exercised.
In a disposable rollout, suppress qualifying requests while leaving ordinary traffic healthy. The cohort-specific analysis should pause as UNVERIFIED. Then send safe synthetic requests through the protected path and inspect the customer-visible state. Record cohort count, metric window and artifact digest with the verdict.
My rule: require a source-linked acceptance check and enough relevant canary observations before widening a consequential release. Do this because zero observed regressions over zero affected users tells you nothing about the change that mattered; an owner must resolve or explicitly override the gap.
#EricFieldNotes
Four-beat scene transcript
1. A green canary can contain no relevant customer.
A rollout can report no regressions because the only affected account type never entered the canary. For example, a new approval path applies only to regulated exporters, while the sampled traffic is ordinary accounts. Aggregate health is useful, but it is not evidence for that specific product promise.
Visual: Zero errors may mean zero exposure.
2. Declare the exposure denominator.
Before promotion, name the source decision, affected account class, operation, exact image digest and minimum relevant observations. Compare canary and control for that class. Configure the analysis so zero qualifying events is inconclusive; an aggregate error rate cannot certify a path nobody exercised.
Visual: Count relevant requests, not just traffic.
3. Remove exposure on purpose.
In a disposable rollout, suppress qualifying requests while leaving ordinary traffic healthy. The cohort-specific analysis should pause as UNVERIFIED. Then send safe synthetic requests through the protected path and inspect the customer-visible state. Record cohort count, metric window and artifact digest with the verdict.
Visual: The gate should refuse a false green.
4. No relevant exposure, no verdict.
My rule: require a source-linked acceptance check and enough relevant canary observations before widening a consequential release. Do this because zero observed regressions over zero affected users tells you nothing about the change that mattered; an owner must resolve or explicitly override the gap.
Visual: A quiet chart cannot authorize expansion.
Research and claim limits
The examples identified as illustrative or simulated are design probes, not reported incidents. Vendor specifications do not establish workload performance.