sm. Simon Mullis

Positions

Where I've got to. Revised when the ground moves rather than when the calendar does.

The essays on this site carry dates for a reason. Each one is a snapshot of what I thought in a particular month, and I would rather leave them that way than quietly edit them into being right later.

This page is the other half of that arrangement. It holds what I currently think, assembled out of those pieces and rewritten whenever something changes my mind. It is not a summary of the writing. It is a set of positions I am prepared to defend today, each one pointing back at the piece that earned it, and it is wrong in places I cannot yet see.

The claim underneath the others

Everyone working with these models has arrived at the same conclusion: context is what makes the difference. Give a model enough of what you have and what you are actually trying to do and it performs. Starve it and it guesses fluently. The more careful version of that view adds a second requirement, that the context be shared, so two people asking the same question of the same system get equivalent answers instead of two private ones.

Both are right. Neither is new.

The same was always true between people. We never had to say it out loud, because shared context was never good and nobody noticed. It was continuously and invisibly repaired.

Every organisation I have worked in ran on a shared understanding that was ambiguous, incomplete and quietly contradictory. It held together because people patch it constantly and for free. Someone unsure asks the person next to them. Someone hedges until the next standup. Someone reads a room and infers the thing nobody said. Thousands of small negotiations a day, none of them written down, all of them mending the model before anyone notices it was torn.

I now think most of the failures I have spent a career on are cases of that repair being absent, too slow, or mistaken for an insult.

This is the position the rest of the page hangs from. It is also the newest one, so treat it accordingly.

Severity and blast radius are different questions

“Is this insecure?” and “what breaks if I fix it?” are answered by different instruments, and we have spent thirty years building only the first.

A correct finding can still take down the thing it was meant to protect, because the confidence attached to the finding gets spent as though it were confidence about the fix. Those are not the same confidence. Until the second instrument exists, and is trusted the way the first one is, every remediation is a bet with a stake you cannot see.

Earned in Right Finding, Wrong Fix.

Controls belong in the path itself, not in a gate across it

If safety has to be applied by each person, it gets applied unevenly and resented. If it is inherited by standing on the path, it is applied everywhere and noticed nowhere. The aim is not a faster checkpoint. It is a road built so that the checkpoint has nothing left to find.

The corollary matters more than the principle. The golden path has to be the lowest-friction way to do what people actually need. A safe path that is slower than the unsafe one is a signal, not a control.

Earned in Compliance as an Inherited Property.

The failure mode is agreement, not confusion

When two minds share a word and unpack it differently, the dangerous outcome is not that they disagree. It is that they agree, proceed, and find the gap much later and much further downstream.

Confusion announces itself. False agreement does not. Which is why I have stopped treating “we’re aligned” as evidence of anything.

Earned in Darmok, Brown M&Ms, and the Bandwidth of Meaning.

Trust is the dial that sets how much you check

Trust is less a feeling about a source than a setting: it governs how much compression you will accept without verifying.

Turn it up and you allow more meaning per word and check less. Turn it down and you demand things spelled out. A source earns the dial by marking the edge of what it knows, saying plainly when it does not know, and saying where it would start looking. That last part is most of it. Certainty you cannot separate from guessing is worth very little, because the “I don’t know” is what makes the “I do know” worth acting on.

This one runs through all three essays without being the subject of any of them. It is the thread I am currently pulling.

What I am least sure about

Each of these threatens one of the positions above, and I would rather say so than let the page read as settled.

The claim underneath the others is the weakest thing here. It is weeks old, I have not tried hard to break it, and its likely failure is being too accommodating: a frame that explains everything and therefore predicts nothing. Ask me what it rules out and I do not have a confident answer yet.

The trust dial has a hole in the middle of it. I can describe how an automated system loses the right to be trusted once it learns from inputs nobody controls. I cannot describe the repair. A source earns the dial back by marking the edge of what it knows, and I do not know what that move looks like for a machine that cannot reliably tell when it is guessing.

And the page as a whole rests on something I should be suspicious of: that these really are one failure seen at four scales, rather than four separate things I have pattern-matched into a family because the resemblance is satisfying. The test I use elsewhere is whether a connection does work or merely feels profound. This one has done some work. Not yet enough to be safe.

Where this goes

The same failure shows up at scales I have not written about yet. Between two people in an organisation, where a request for review arrives as a verdict on the person. Across a whole company, where a mission statement is meant to decompress the same way in every head and mostly does not. Between a person and a machine, where the repair that held all of it together is simply absent.

Those are the next pieces. When they exist this page will change, and the version you are reading will have been wrong in ways I will try to say out loud rather than quietly correct.