hc0.io § Operating Standard

Section 5

Reliability and composition

How qualified parts are allowed to be combined, and why the count of parts is governed as strictly as their quality.

Documenthc0.io §5
Revision2.0
StatusIn force
ScopeSystem composition
Clauses9
Issued2026
5.1

Reliability compounds multiplicatively

The reliability of a procedure is the product of the reliabilities of the components it depends on. It is not their average and it is not the reliability of the weakest one. Every component added multiplies what came before.

5.2

Consequence for design

Twenty components at ninety percent each compose to roughly twelve percent. The same twenty at ninety-nine percent each compose to roughly eighty-two percent. Component count and per-component quality are therefore the same lever pulled from two ends, and count is usually the cheaper end.

5.3

Component budget

Every procedure states the number of components it depends on, counting each system, credential, schedule, and handoff between agents. The count is part of the register. Adding a component requires removing one, or a recorded justification carrying the new composed reliability.

5.4

Single path preferred

Where two paths reach the same result, one is chosen and the other is deleted. A fallback path is a component: it is counted, qualified under Section 4, and exercised on a schedule. A fallback that is never exercised is recorded as a failure mode, not as redundancy.

5.5

Failure halts rather than propagates

Components are arranged so that a failure stops the procedure instead of passing a partial result forward. A stop is cheap and legible. A partial result travels, gets built on, and is discovered late.

5.6

Maintenance or delete

Every component carries a named owner and a review interval. A component that misses its review is removed from the live path, not left running quietly. An unmaintained component in a live path is a defect whether or not it has yet failed.

5.7

Measurement

Reliability is measured on completed runs against the success condition in the register. The absence of complaints is not a measurement. A procedure with no measurement is recorded as unmeasured, and an unmeasured procedure does not hold Level 3.

5.8

Replication gate

A procedure is replicated to a second product, client, or system only after it has held its stated reliability across a full review interval on the first. Replication proceeds one target at a time. Two first replications running at once is not permitted, because neither can then be read.

5.9

Reduction before addition

When a procedure misses its reliability target, components are removed before components are added. Monitoring, alerting, and retries are components too, and they are not a remedy for a part that should not be in the path at all.

This is the last section of the standard. The register it refers to is maintained separately and is not published.

Revision notices

A note when a clause in this standard changes or a new one is added. Sent on revision, not on a schedule.

No spam. Used only to send the notes.

← Previous · Section 4, Procedure qualification Contents · Section 1, Cover →