Lesson 1 · from Chapter 1
Maintenance began as a discipline for machines that wear out. This lesson is about what happens when the thing that wears out is a capability rather than a bearing — and why a system can be running perfectly while the work it produces has quietly stopped being right.
Step one
Read each one. Mark it read, or have it read to you. The test at the bottom draws from these five and nowhere else.
Idea one
The founding observation of maintenance is that a machine left alone gets worse. Nobody has to break it. Heat, vibration, contamination and time do the work, and the only question is whether you find the drift before it finds you.
Chapter 1 makes the same claim about a capability. A workflow, a prompt, a model, a standard, a team's skill at reviewing output — each of these degrades without anyone touching it, because everything around it moves. The documents change. The people change. The model is updated beneath you. The standard that was right in March describes a world that no longer exists.
The first of the six rules follows from this: maintain the behaviour, not the infrastructure. The servers can be at full uptime, the code unchanged, the dashboards green, and the capability still gone.
Idea two
An assistant waits to be asked and hands something back for a person to use. An agent holds a goal, chooses its own steps, and acts on the world in the gaps between your instructions.
The line between them is not intelligence and it is not blast radius. It is initiative. The moment a system takes a step without being asked again for that specific step, it has crossed over.
This matters because almost every control most teams rely on was written for an assistant. "Review the output before you use it" assumes there is a moment before use, and a person standing in it. Remove the person and the sentence still sounds like a control while doing nothing at all.
Idea three
Availability answers one question: did it respond. Integrity answers a different one: was the response fit to act on. A system can score perfectly on the first while failing continuously on the second, and most monitoring is built to watch only the first.
On a factory floor the difference is obvious, because a machine that runs all shift and makes scrap leaves a pile of scrap. In cognitive work the scrap is invisible. Wrong work looks exactly like right work until somebody checks, and the checking is the part that gets dropped when the volume rises.
So the useful measures are not requests served and latency. They are actions taken, and actions later reversed or corrected — the count of times the work was wrong enough that somebody had to undo it.
Idea four
The third rule is that autonomy is graduated, never assumed. An agent is granted a rung, and the grant only means something if there is a boundary the agent cannot cross.
A boundary only holds if a machine can evaluate it in the moment, with no interpretation. "Escalate anything unusual" is not a boundary; it is a request for judgement, delivered to something that will supply its own. "No refund over $200, anything above goes to a named approver" is a boundary, because it can be checked without a meeting.
The second rule is the same idea aimed at documents: standards must be executable. A forty-page policy states an intention. A check that runs, refuses and logs is what actually holds. Until the standard exists in a form the system evaluates at run time, it is a description of what you hoped would happen.
Idea five
The fifth rule is maintain the interfaces, not the components. Two agents can each pass every test they were given and still fail as a pair, because each was tested against its own idea of the contract between them. The failure lives in the seam, and the seam belongs to nobody.
The fourth rule is preserve lineage. Six weeks after a bad decision the model has been updated, the prompt revised and the data refreshed. Re-running the input tells you what today's system does. Only a retained record of which model, which prompt, which data and which limits were in force at that moment lets you reconstruct why.
And the sixth: human attention is a protected operating resource. The reviewer is not outside the system, they are a component of it. An overloaded reviewer is a failed control, and load is something you can design, measure and exceed.
Step two
Autonomy is graduated, never assumed — so it has rungs. Move the slider and read what a system on that rung may do, what it must keep, what actually stops it, what the human is for, and what fails when a capability is placed on that rung for the wrong reason.
Try this. Pick a task somebody on your team already hands to an AI system. Put it on the rung it is actually on today, not the rung it was approved for.
Then ask the only question that matters on rungs six, seven and eight: what stops it? If the answer is a sentence rather than a mechanism, the rung is aspirational.
Step three
Ten situations, two per idea, drawn at random. Two right in a row on an idea marks it solid. A wrong answer tells you why that particular choice fails, and sends you back to the one idea it was testing.
You can say what decays, what makes something an agent rather than an assistant, why uptime is not integrity, what makes a boundary real, and where a chained system fails. That is chapter 1.
This lesson teaches chapter 1. The book runs to twenty chapters and sets out Cognitive Capability Maintenance in full — the framework this class is built on. Written and donated to the Foundation by GSU's founder, Dr. Gene A Constant.
Read on Kindle The whole class
The class is free and always will be. As an Amazon Associate, Global Sovereign University earns from qualifying purchases; every cent funds tuition-free education.
Global Sovereign University: Different by Design. Better by Mission.