Until Further Notice¶
The printout lies on the table between us with one line marked in red. 31,400 euros, approved by N. Prentice, March 27, 14:52.
The N stands for Naomi. It is my line, and every number on it is correct.
Merrick asks whether I was authorized to do that. I say yes. He asks whether I can prove it.
March 13, Six Months Earlier¶
Ballard is out. He doesn't say what it is and I don't ask. On the phone he sounds like a man who has been told something and has not finished thinking about it yet.
In the afternoon HR calls. Could I cover for him. A few weeks, they say, possibly longer.
I have been in purchasing here for eleven years. The volume doesn't frighten me; the part of the job I have never done is the part Ballard keeps for himself, which is sitting across from suppliers who have known him for two decades and telling them no. I say yes anyway, because the alternative is that nobody signs anything for weeks, and nobody can tell me how many.
Two days later the memo is in my in-tray, countersigned by Ballard and by the managing director. Deputy Head of Purchasing. Approval limit 50,000 euros. Effective March 13 until further notice.
The last three words don't bother me. Nobody knows when he is coming back, so there is no date anyone could honestly write down. I put the memo in the drawer where I keep things I will not need again.
On Monday I log in and my profile says 50,000 instead of 10,000. Everything works exactly as it is supposed to.
March 27, 14:52¶
Thurlow's price commitment expires at the end of the month. From April, eighteen percent more on steel bar stock. It is in writing and it is not a negotiating position; I call and it is still not a negotiating position.
We need the material in May regardless. So the question is only whether we buy it now at the old price or in five weeks at the new one.
I run it twice. Pulling the second-quarter demand forward costs us storage space and about three weeks of tied-up capital, and it saves 4,900 euros. I call Pike in the warehouse and ask whether he can take four pallets earlier than planned. He can, grudgingly, which is how Pike does everything.
The order comes to 31,400 euros.
Before I approve it I look at my limit, because that is what you do. 50,000. There is no prompt, no second pair of eyes, no note in the margin. Why would there be. At 14:52 I approve PO-4471 and move on to the next line item.
It is the kind of decision Ballard would have made in ten seconds and I have taken forty minutes over it. I am mildly pleased with myself for the rest of the afternoon, and then I forget about it entirely for six months.
April¶
Ballard is back, earlier than expected and thinner. He goes straight into a supplier meeting on his second day, which everyone including me agrees is stupid.
My profile says 10,000 again. I see the number and think nothing at all.
May¶
Reorganization in purchasing: four areas become three, two people move, one team leader position disappears. My role is still called PUR-2. It has a new limit, 7,500 euros.
For two days I am annoyed, because I now need Ballard's signature for parts that cost less than a decent office chair. Then I get used to it, the way you get used to a door that sticks.
Nothing has been deleted. The field simply holds a different number now.
September¶
Internal audit runs an automated check across the year: every order compared against the approval limit of the person who approved it. Six thousand line items. Eleven exceptions.
Ten of them are transposition errors, cleared in an afternoon by putting two numbers next to each other.
The eleventh needs a date.
Merrick is polite about it. He puts the printout on the table with one line in red and asks whether I was authorized. I say yes. He asks whether I can prove it, and I say of course, and that is the last easy sentence of the month.
It takes me five days to understand that I cannot.
What the Systems Remembered¶
The approval log. It is complete, unbroken, tamper-evident and retained for seven years. It says: Prentice, approval, PO-4471, March 27, 14:52:16. It says nothing about what my limit was at 14:52. It records what I did. It does not record what I was permitted to do.
The role assignment. Doyle from IT shows me the table on his screen. There is one row for me and a column called valid_from, and it says May 4. I ask where the March row is. He says there is one row per person; it gets changed, not added to. He says it the way you would explain that water is wet, and he is not being unhelpful, he is being accurate.
I ask about the roles table itself, the one that holds the limit for PUR-2. Same answer. The field holds 7,500. What it held in March is not stored anywhere, because nobody ever needed it to be.
The transaction log. Doyle gets there before I do. It exists, it is exactly what I am looking for, and it is retained for eight days, because its purpose is recovery, not history.
The personnel file. The memo is there, scanned as a PDF. Effective March 13 until further notice. There is no end date, because in March nobody could name one. Which means that on paper I am still deputy head of purchasing today, in September, with a limit of 50,000 euros. This does not help me. It makes the file look sloppy, and a sloppy file is not the thing you want to put in front of internal audit.
The Document That Was New Every Time¶
The order document. This is the one that costs me a night's sleep, because for about two hours I think I have it.
Every purchase order can be printed as a PDF, and the footer of that PDF carries the name and the function of the person who approved it. If the document from March 27 says Deputy Head of Purchasing, the question is settled.
I open PO-4471 and print it and the footer says: N. Prentice, PUR-2.
Doyle explains it without being asked, because he can see my face. The document is not stored. It is generated when you ask for it, from the data as it stands at that moment. The order from March is real and unchanged; the sheet of paper describing it is new every time, and it describes March using September.
The backups. Daily, overwritten after ninety days, with quarterly snapshots kept indefinitely. So there are exactly two snapshots that bracket March 27. The one from December 31, in which I have a limit of 10,000 and no deputy role at all. And the one from March 30, in which I am deputy head of purchasing with 50,000.
Somewhere between those two points my row changed. The March 30 snapshot is three days after the order.
Merrick says what it proves, and he says it without any edge, which somehow makes it worse: it proves March 30.
The One System That Never Deleted Anything¶
The mail archive. It is journaled, it has never overwritten anything, and it goes back eight years. It has Thurlow's letter with the price and the deadline. It has a thread from mid-March in which the managing director's assistant asks me to take over the Thurlow negotiation while Ballard is out.
Nobody writes approval limits in emails.
So the one system in this building that has never destroyed anything holds the reason, and the reason is not what I am being asked about.
Ballard confirms all of it. He ordered the delegation himself, he remembers the conversation, he remembers signing. So there are now two people who remember the same thing correctly and in detail, and it is worth nothing, because it is testimony.
Joanne in finance tells me to stop, that nobody thinks I did anything wrong, that these things go into reports all the time and are never read again. She means it kindly and she is probably right about the reading.
The trouble is what the finding is attached to. It is not attached to a role assignment table with one row per person. It is attached to my name, in a document with my employee number on it, and the sentence next to it will say that the matter could not be resolved. I would like it to say something else.
The Sheet of A4¶
For the second meeting I bring a sheet of A4 with a timeline on it, written by hand, dates down the left margin. March 13, the phone call. March 15, the memo. March 16, the login with the new limit. March 24, Thurlow's letter. March 27, the order. April, Ballard's return. May, the reorganization. I built it from my calendar, the memo, the mail archive and the order itself, and it took me most of a Sunday.
Merrick reads it properly, all the way down, which I appreciate. He says it is helpful.
Then he says: it is your account of events.
I tell him about the price commitment, about the eighteen percent, about the 4,900 euros. He listens and he does not write it down, and he is right not to, because the check compares two numbers and there is no field anywhere in it for why a person decided something.
At the end he asks whether this has happened before.
I tell him that to answer that, someone would have to do for six thousand orders what the two of us have just failed to do for one.
The report says: not conclusively determinable. Recommendation to revise the authorization concept, with a note on the documentation of temporary delegations. It is not an accusation. It is also not an exoneration. It will sit in the file, and the next auditor will read it before they meet me.
Merrick is friendly when he leaves. That is the part that stays.
October¶
Since then I have kept a folder. On the first working day of every month I take a screenshot of my own profile, with the limit and the date visible, and save it as a PNG with the date in the filename. It takes eleven seconds.
Doyle would tell me it is redundant. He would be right, in the sense that every number in it is already in the system somewhere. It is also not evidence.
It is just the only thing I could think of.
Nobody Cut a Corner¶
Nobody in this story cut a corner.
There is an approval log, and it is a good one. There is a validity date on the role assignment. There are backups with a sensible retention policy. There is a signed memo in the personnel file. Every number was correct at the moment it was written, and every change was made by the right person for the right reason.
The information did not disappear through a failure. It disappeared through normal operation.
One question before you go: was Naomi Prentice authorized, at 14:52 on March 27, to approve 31,400 euros?
You didn't have to think about it.
You Were the Event Store¶
You have known almost from the beginning. You know the date it started, you know the number, you know who signed. You know something that never entered the audit at all, which is why she placed the order. And if you scrolled back up to be certain before you answered – that was the entire exercise.
Note that you had less data than the company did. No ERP, no approval log, no snapshots, no personnel file. What you had was a sequence of sentences in the past tense, in the order in which things happened, and not one of them overwrote the one before it. You did not hold a state. You held a sequence, and you computed the answer at the moment the question arrived, rather than months earlier.
That is the whole difference.
UPDATE Is a Small Deletion¶
State is already the answer to a question somebody asked long ago: what is this person allowed to do today? For that question, UPDATE is the correct operation, and one row per person is the correct design. It is also, at the same time, a small deletion. It removes the answers to every question nobody has asked yet.
That is the uncomfortable part. Dropping a row at least looks like destruction, which is why soft delete feels like the responsible alternative and mostly is not. Overwriting a field does not look like anything at all. It looks like Tuesday. The same instinct that turns a lifecycle into a single row you keep editing is what left Doyle with nothing to show Merrick, and neither Doyle nor the person who designed that table did anything wrong.
Nor would a separate audit log have saved her. Hers was excellent, and it still answered the wrong question: it recorded actions faithfully and said nothing about the state those actions were taken against. We took that argument apart in You Don't Need an Audit Log. Merrick's five days are what it looks like from the inside.
The most complete record in that building is a human being. Naomi's memory is ordered, it is only ever appended to, and it knows intent. It has exactly one property that makes it useless: it does not count as proof. Every field that takes investigation seriously has learned this the expensive way – aviation does not ask the crew what the aircraft was doing, it reads the recorder.
The second most complete record is the mail archive, which nobody ever designed to be a system of record and which behaves like one anyway, for an entirely unglamorous reason. Nothing in it is ever changed in place.
There Are Other Ways to Lose Information¶
What was missing in this story was state at a point in the past. That is one way to lose information, and it is the one that ends up in audit reports. There are others, quieter ones, and this is the first post in a new series about them.
The companies and the people in these stories are invented. The failure modes are not. Every one of them comes from a system doing exactly what it was built to do, which is what makes them so hard to see coming.
If Naomi's five days sound familiar, the remedy is less dramatic than the problem. EventSourcingDB stores what happened instead of what is true right now, and reading a stream up to a chosen point in the past is an ordinary read, not an excavation. That means September's question – what applied at 14:52 on March 27 – is answered from the same data as everything else, without anyone in March having to anticipate that it would ever be asked. Our guide on patterns for temporal queries shows what that looks like in practice.
And if you have a story of your own, a question your systems could not answer in hindsight no matter how carefully they were built, we'd like to read it. Write to us at hello@thenativeweb.io. Some of them may well end up here, suitably disguised.