Certify-then-reject loop
When an automated gate records a pass and a human accountable for the artifact rejects it on inspection, the loop has a name. The recorded counts are final. The converted cost stays on the cost page and updates as this release closes.
Recorded counts, updating in place.
Last updated
Subject: an enterprise SaaS company with a digital media publishing operation. This page tracks one in-progress software release on that estate. Final rows stay final. Open rows — executive hours and the release tally — update on this page as that release closes.
- Loops
- 5
- Reopens
- 4
- Pull requests
- 6
- Automated suite
- 29/29 green
- Routes rejected on inspection
- 8
- Executive hours
- Open — updates as this release closes
- Release tally
- Open — updates as this release closes
Recorded count.
Recorded count.
Recorded count.
Recorded count.
Recorded count.
Estimate until this release closes.
Estimate until this release closes.
What is a certify-then-reject loop?
Canonical home: /answers/certify-then-reject-loop
The gate measured a different property than the human judged.
A repeat count above one is diagnostic. In this case the certification method asserted that frames differed and that a reduced-motion park applied. The accountable human judged whether the live artifact stayed inside its designed bounds on every route those frames were sampled from. Those are different properties. The suite recorded 29/29 green. Inspection rejected 8 routes. 5 loops and 4 reopens established the mismatch as a repeating pattern.
The subject is an enterprise SaaS company with a digital media publishing operation. The same two timestamps — automated pass, human reject — are the whole detection method.
The loop is already in ordinary history.
Both events — the automated pass and the human rejection — are already recorded in version control, pipeline output, and issue-tracker history. A platform lead names the loop from those two timestamps. A buyer and an operator can point at the same pattern without reading the application.
What the loop teaches, in operating terms.
01
A repeat count above one is diagnostic.
One reject after a pass can be a miss. A second loop establishes that the certification method is measuring something other than the property the human is judging.
02
The gate and the human must judge the same property.
A green suite certifies the assertions it encodes. An accountable human certifies the live artifact against the property they own. Align those properties, or the pass will keep arriving ahead of the reject.
03
Ordinary history already holds both events.
Automated pass and human rejection leave timestamps in version control, pipelines, and the issue tracker. Detection reads those two timestamps.
04
Suite-green certifies suite properties.
Pixel difference, parked motion, and assertion count are real properties. They remain a different measurement than bounds, containment, or the live route a human inspects.
05
Put the intended property in terms the gate can inspect.
A gate can only certify a property it can inspect. Write the intended property in those inspectable terms. A specification written in rendered behavior — the same surface a human sees — is a specification a gate can carry. A specification written only as a symptom report will oscillate.
06
Independent inspection is part of the control.
Independent inspection of the live artifact closes the loop. A second pair of eyes judges the same property the accountable human owns, and that is the control that ends the repeat.
Name the property before the gate certifies it.
Day-one deliverables stay with the estate. The map is the first control against a certify-then-reject loop: it names what a human will judge so the gate can assert the same property.
Visual Topology
The board view of how people, systems, and policies actually connect — so the property a human judges is named before a gate is asked to certify it.
Executable Schema
Typed routes engineers can run against. The map becomes an assertion the pipeline can carry, in the same terms inspection will use.
Compute & Token Economics
Recovered spend sized before inference scales, so the cost of a loop is visible in the same units finance already watches.
Client-owned rails
The blueprint and the custom MCP rails stay with the estate. Manta Graph™ is the map; the client keeps the artifact.
Name the loop. Then stop it.
This is the operator page for the term. It answers how a certify-then-reject loop is detected and how you stop it. When a search arrives as "CI green but production broken" or "the agent said it fixed it," this is the named home. The cost page answers what a certified failure costs once the loop is in motion. Both pages name the same pattern so a briefing lands on one definition and one economics narrative.
Economics twin: Cost of a certified failure. Same case, CFO intent.
A modular controller over the stack you already run.
GW Slate™ holds identity, policy, runtime, and receipts so the property a human judges is the property the gate can assert. Human-at-the-control stays on every irreversible step. Actuality Receipts™ make provenance, authority, logic, and outcome auditable. The Diagnostic Sprint maps one estate and stands up one live micro-controller — $7,500 standard / $10,000 regulated, 100% creditable toward the GW Slate™ build.
Questions
01What is a certify-then-reject loop?
A certify-then-reject loop is a repeating failure pattern in which an automated gate records a passing result on an artifact, and a human with accountability for that artifact then rejects it on inspection. A repeat count above one is diagnostic: it establishes that the certification method is measuring something other than the property the human is judging. The loop is detectable without reading application code, because both events — the automated pass and the human rejection — are already recorded in ordinary version control, pipeline and issue-tracker history.
02Why does a green suite still ship an artifact a human rejects?
A repeat count above one is diagnostic. In this case the certification method asserted that frames differed and that a reduced-motion park applied. The accountable human judged whether the live artifact stayed inside its designed bounds on every route those frames were sampled from. Those are different properties. The suite recorded 29/29 green. Inspection rejected 8 routes. 5 loops and 4 reopens established the mismatch as a repeating pattern.
03How do you detect a certify-then-reject loop without reading application code?
Both events — the automated pass and the human rejection — are already recorded in version control, pipeline output, and issue-tracker history. A platform lead names the loop from those two timestamps. A buyer and an operator can point at the same pattern without reading the application.
04What does Manta Graph™ return on day one against this loop?
Visual Topology for the board, Executable Schema for engineers, and Compute & Token Economics for finance — plus a blueprint and custom MCP rails the client owns. The map names the property a human judges before a gate is asked to certify it.
05How does GW Slate™ keep the loop from compounding?
GW Slate™ holds identity, policy, runtime, and receipts so the property a human judges is the property the gate can assert. Human-at-the-control stays on every irreversible step. Actuality Receipts™ make provenance, authority, logic, and outcome auditable. The Diagnostic Sprint maps one estate and stands up one live micro-controller — $7,500 standard / $10,000 regulated, 100% creditable toward the GW Slate™ build.
Map the property. Then certify it.
Book the Diagnostic Sprint. Manta Graph™ names what a human judges. GW Slate™ holds the gate to that same property.
