ishchenko.co

Method

Two of the things I spend most of my time on have almost nothing in common. One is payments, and the AI system I built and run to work my own sales pipeline. The other is a large, multi-contributor canon project — a fictional world built by many hands over a long stretch of time, with its own internal rules about what counts as true inside it. Different materials, different people, different reasons to exist. Both ended up organized around the same rule: nothing enters the permanent record without something behind it that another person could check. Not as a value statement. As a gate at the point of entry, enforced by something mechanical, that fails loudly when it isn't met.

I didn't set out to apply one idea in two places. I noticed it afterwards, which is the main reason I trust it.

Worked example one: the sales system

Payments teaches this early and without much sympathy. A number without a source isn't information — it's a liability with good posture. Settlement files don't care how confident anyone sounded on the call. Either the transaction reconciles against something, or you have a discrepancy with your name on it.

So when I built the system that runs my pipeline, I built it the way a payments person builds anything that touches a ledger. Before a fact becomes durable — a stage change, a company detail, a next step, a figure attached to a deal — it has to point at where it came from. An email. A line in a transcript. A document someone sent. If the source exists, the record gets written and the source travels with it. If it doesn't, the system doesn't improvise a plausible value and it doesn't quietly skip the field. It writes down that it couldn't confirm, marks it unverified, and puts it in front of me.

That second half matters more than the first. A checker that only ever reports success is indistinguishable from a checker that isn't running. So the system has to distinguish between two very different sentences that look identical in a summary: I looked and found nothing, and I stopped partway. One is a finding. The other is a gap wearing a finding's clothes. Anything that can't tell those apart will eventually hand you a green light that's really a burnt-out bulb.

The same logic governs what leaves. Everything the system produces lands in drafts. It writes, chases, and documents; it doesn't send, and it doesn't decide. My signature is the last gate, every time — which sounds like a brake and works like one, in the sense that brakes are what let you drive quickly.

What that discipline bought, in practice: the record stopped depending on me remembering it. Quiet deals surface while they're still just a task instead of after they've already cost something, and deal context exists outside my head, in a form a colleague can pick up cold — which stopped being theoretical the first time one actually had to. See the full writeup →

Worked example two: a large, multi-contributor canon project

The second project shares no vocabulary with the first. No revenue to reconcile, no processors, no pipeline. It's a fictional universe with many contributors, built to be added to over years.

Its failure mode is contradiction. Two people write two things, both good, and the two cannot both be true. That's survivable on the day it happens and expensive a year later, once other work has been built on top of both. By then the question isn't which version is better; it's how much has to be unwound to make the world hold together again. A world that contradicts itself stops being a world and becomes a pile of drafts.

The rule that emerged there, arrived at by people solving a storytelling problem rather than a data problem, is the same rule in a different accent: a hard line between what is canon and what is speculation. Something becomes part of the permanent record when it can be traced to an established, agreed source inside the project. Until then it's marked provisional, visibly, so anyone building on it knows what they're standing on. Names and terms get registered so two contributors don't unknowingly claim the same one in different corners. There's a defined way to settle a conflict when one surfaces, so it gets resolved once rather than re-litigated in every conversation it touches.

And the enforcement isn't a person remembering to care. It's a check that runs whether or not anyone is paying attention — with the same requirement I'd put on any checker: it has to be provably able to fail. If it can't reject a case that ought to be rejected, its approval means nothing.

Nobody involved was thinking about payments. Nobody was thinking about CRMs. They were thinking about how to keep a story coherent across many hands, and they converged on evidence-before-permanence anyway.

That's what I find genuinely interesting. Two domains that share no tooling, no incentives, and no vocabulary, arriving independently at the same primitive. Which suggests the primitive isn't really about payments or about fiction. It's about scale and time — about any system where more than one person contributes, and the record outlives everyone's memory of how it got there.

There's a corollary to this I didn't expect going in. Once a record is actually trustworthy — sourced, checkable, worth relying on — it stops being a byproduct of the work and starts being an asset in its own right. Two years of my own client conversations sat in an archive the whole time this was true of them; nobody had reason to disagree, because nobody could afford to check. The gate is what made the archive worth anything. Everyone I compete with can buy the same tooling. Nobody else has that archive, or the two years it took to accumulate.

Trust in a system like that rarely collapses because someone lied. It erodes because unsourced things get treated as settled, quietly, one at a time, until nobody can tell which parts were checked. The fix isn't more diligence, because diligence is exactly the resource that runs out on a bad week. The fix is a gate that doesn't care what kind of week you're having, and that is capable of embarrassing you.

I hold this site to the same standard, which is why it's built so that a post without a source field fails the build rather than getting a stern note in a style guide. It's a small thing. It's also the only version of the rule that survives contact with a deadline.