The Decision You Can No Longer Defend
Someone is going to ask you why you did that.
Not today. In about eighteen months, in a meeting you didn’t expect to be in, in front of people who weren’t there the first time. The question will be perfectly reasonable, and it will be asked in a tone that suggests the answer is obvious.
Eighteen months ago you stood down the investment. The capability was peripheral — everyone said so, the assessment said so, and the money was needed somewhere it would do more good. You made the call on the evidence in front of you. It was the right call on that evidence.
The capability is not peripheral now. It is on the critical path of something that matters, and the assessment in front of you today says exactly that. In a calm, confident voice. With no indication that it has ever said anything else.
So you go looking for the version that justified you. It isn’t there. Not missing, not deleted, not lost in a migration — it was updated. Somebody did the responsible thing and brought the record in line with reality, and in doing so removed the only evidence that reality used to be different.
You made a defensible decision. You can no longer demonstrate that it was defensible.
And the organisation comes off worse than you do, because it is about to learn the wrong lesson. It will conclude that someone was careless. The actual lesson — that the assessment moved, and nobody noticed it moving, and no decision was ever revisited when it did — is the one nobody can see, because the evidence for it was tidied away one field at a time.
Keeping It Current Is How You Lose It
Every model we build asks one question. What is true? Then it stores the answer.
When the answer changes we replace it, and we call that maintenance. Data quality. Keeping the record accurate. It sounds so obviously correct that it takes an effort to notice it is a choice, and a strange one: we are running systems whose defining behaviour is to destroy their own past.
First, a word about true — because it is about to do more work than it should, and it is not quite the word we mean.
Nothing in this argument requires a claim to be accurate, verified or exact. It does not require it to be right. When this piece calls something true, it means only that it is the best account anybody currently has: made by someone who was in a position to know, bounded to the part they can actually speak for, and good enough that a reasonable person would act on it.
That is credibility, and credibility is not precision.
A field filled to four decimal places by somebody who was guessing is precise and worthless. “I can’t tell you what it costs, but I can tell you it’s the part that breaks first” is imprecise and immediately useful.
Read true that way for the rest of this piece — the best we know, trusted enough to decide from — and notice that it has to be a lower bar than accuracy. Set the bar at accuracy and almost nothing clears it, which is exactly how a model ends up empty.
There is a better question, then, and it has the useful property that the first one can be recovered from it.
What has been claimed, about what, by whom, and when?
Answer it and you can always derive what is true now — take the claims, apply precedence, read off the result. But it does not work in reverse. From the current answer you cannot recover when it arrived, what it replaced, or whether it has been quietly reversed twice since spring.
Overwriting is lossy in exactly one direction. It is the direction we have been going for forty years.
A record that is always current can never tell you when it wasn’t.
A Claim Is an Event With a Date On It
The Myth of the Single Source of Truth argued that the authoritative view should be composed on demand from layers, rather than negotiated into a single stored row.
Follow that one step further than it went.
If there is no single row, then “update the record” is not a coherent operation. There is nothing to overwrite. There are layers, each saying what it has an opinion about, and every one of those claims already carries a date — the moment somebody made it. The date is not metadata bolted onto the side. It is part of what the claim is.
Which means the answer you get today is the composition evaluated at today. That is all “current” has ever meant. Ask the same question with a different date and you get a different answer, assembled the same way, equally real, equally authoritative for its moment. And not one field of it. Every claim in the model carries a date, so the entire composition evaluates at that date — you are not retrieving an old value, you are standing in the model as it stood.
History stops being a feature you add to the model. It becomes the model. What we have been calling the current state turns out to be a query — one among many, with no special status except that it happens to be the one we ask most often.
Nothing has to be discarded for this to work, because nothing was ever being replaced. It was only ever being added to.
What You Can Ask a Model That Remembers
Three questions become available. None of them can be answered by a system that keeps itself tidy, and none of them is idle — behind each one is somebody with a decision in front of them and a date by which it has to be made.
When did this become true? Not whether it is true — when it started being true.
The person asking is deciding whether to act at all. A cost that has been climbing steadily for two years and a cost that jumped last week are the same number today and two completely different problems, needing two completely different responses. One is a trend you have been ignoring; the other is an event you have just discovered. A model that only holds today’s answer flattens both into a single confident present tense and leaves you to guess which you are looking at — usually wrongly, and usually in the direction that requires less work.
What did we believe when we committed? This is the one that would have saved the meeting we opened with.
The decision here isn’t about the past at all. It is whether to trust the same process again. A commitment can only be judged fairly against the evidence available when it was made — and if that evidence no longer exists in the form it had at the time, every past decision gets judged by present knowledge. Competent people look reckless. Lucky people look wise. And the organisation, quite rationally, stops making bold calls, because the record has quietly made boldness indefensible after the fact.
Where did intent and delivery part company? The gap between the service you designed and the service you are running is not a number. It is a shape over time.
The decision this feeds is where to spend next. A gap that opened in one month usually has a cause sitting right next to it in the timeline — a reorganisation, a supplier change, a budget round. A gap that widened slowly over two years is a design problem, and no amount of remediation will close it. Same gap today, different money entirely. A snapshot tells you the size and hides the shape, which means it can tell you that something is wrong but never what to do about it.
That is the pattern in all three. The model is not being asked to be a record. It is being asked to be something you can commit on the strength of — and a claim you cannot date is a claim you cannot weigh.
Credible Is Not the Same as Correct
We set the terms earlier: credible, not accurate. It is worth following that to the place it actually leads, because most people accept the definition and then flinch at the consequence.
A claim can be credible — properly sourced, honestly bounded, made by exactly the right person — and still turn out to be wrong.
That is not a flaw in the idea. It is the point.
Whole fields have moved forward on theories the world eventually refused to match. The theory was never worthless — it was the best available claim, held honestly, and the fact that it could be seen to fail is precisely what produced the next one. Progress did not come from being right first time. It came from being wrong in a way that was visible, dated and attributable.
A model that overwrites cannot do this. When the wrong claim is replaced by the right one, the organisation gains a corrected field and loses the entire lesson. There is no record that anybody believed otherwise, no record of how long they believed it, and no way to ask the only question that would have been useful: what were we reasoning from, and why did it look right at the time?
Being visibly wrong is worth more than being quietly corrected.
An organisation that cannot see itself having been wrong cannot calibrate anything. It cannot tell you which of its sources have earned confidence and which have merely never been checked. Every claim arrives wearing the same face.
Nobody Has to Be Right the First Time
So far the cost of forgetting has been the organisation’s. There is a personal one too, and it is the reason the model ends up thin in the first place.
Contribution Without Consensus argued that people stop contributing what they know because contributing exposes them — put your name to something and wait to be quietly overruled by someone with more seniority and less proximity.
Time is what finally removes that risk.
If nothing is discarded, a correction is not a deletion. Someone else’s later claim does not replace yours; it sits beside it, both dated, both attributed. If theirs wins on precedence, yours is still on the record saying exactly what you said, on the day you said it, with the reasoning intact.
Which means the worst outcome of contributing is that you were right about your patch at the time and something changed afterwards. That is not a professional risk. That is just what happens to true things.
The Timeline Doesn’t Stop at Today
Everything so far has looked backwards. It doesn’t have to.
If a claim is an event with a date on it, then a claim about a date that has not arrived yet is exactly the same kind of object. A contract that lapses in March. A supplier exiting in June. A capability being stood down at year end, a team being restructured, a licence that will not be renewed. Each of these is known now and true later — a claim with a future validity date, sitting in the model alongside everything else.

So ask the model the same question, dated March.
Not a forecast, and not a guess. The same composition, evaluated at a date that hasn’t happened yet, returning what the service will look like given what has already been decided. The commitments you cannot currently see are the ones nobody has connected to the thing they will land on.
That is the difference between reacting to a change and seeing it coming — and it is not sophistication or analytics or a maturity level. It is whether the claims in your model carry a date.
Why We Don’t Do This
It is not storage. Storage has been effectively free for two decades, and anyone who has priced it knows the “we can’t keep all that” storage argument is a reflex rather than a calculation.
There is a better objection, and it has actually been earned.
Most organisations have already tried keeping everything once, and it went badly. The archive nobody could navigate. The warehouse that quietly became someone’s second job. The shared drive holding fourteen versions of the same document with no way to tell which one anybody acted on. The lesson taken from that wasn’t we stored too much so much as stored information rots — it ages, it detaches from whatever it described, and every additional pile is one more thing to govern, secure and eventually explain to somebody. Collecting more starts to look like pouring fuel on a fire you are already fighting.
That objection is right about what it saw. It is wrong about what caused it.
Those things rotted because they were kept somewhere else. A copy lifted out of the system that gave it meaning is an orphan the moment it lands: no owner, no relationship to the thing it describes, no way to tell whether it still applies. It has to be managed separately precisely because it is separate. That is what turns volume into fuel.
A claim that was simply never removed is in no such position. It is still attached to the part of the service it speaks about and the person who made it, still bounded by what they said they knew, still sitting in the same structure as everything else. Nothing needs curating, because nothing was ever extracted.
You are not building an archive alongside the model. You are declining to delete from it.
Which is worth being exact about, because the two get confused constantly. Hoarding is copying data out and hoping it proves useful later. This is the opposite: nothing moves, nothing is duplicated, and the past is reachable by the same query that reaches the present.
So it isn’t cost, and it isn’t sprawl. The real reason is less comfortable than either.
A model that remembers is a model that can be checked. Checked against the world, which most organisations would accept. But also checked about itself — how often it has been wrong, how long it stayed wrong, which sources keep needing correction, and which decisions were made in the window while it was wrong.
That is a genuinely exposing thing to build, and the discomfort is real rather than irrational. It is also the entire value. A model whose reliability cannot be examined is not a safer model. It is one whose unreliability is simply unmeasured, being used to make commitments anyway.
Every organisation that has ever said “we need a single, accurate view” has been asking for a model that can be examined about itself, while believing it asked for one that is simply accurate about the world.
The Challenge
Pick a decision your organisation made about eighteen months ago. A real one, with money or people attached.
Now try to reconstruct what made it credible at the time — not the minutes, not the paper that went to the committee, but the state of the world the paper was drawing on. What the assessments said that week. What was believed about the dependencies, the cost, the criticality.
You will find one of two things. Either you cannot reconstruct it at all, or you can only reconstruct it from someone’s personal archive — a saved deck, an exported spreadsheet, an email thread that survived because one person happens not to delete things.
Which means you can no longer show the decision was credible when it was made. Only that it was made.
Then notice what that means about the decision you are going to make this quarter.
What did your organisation believe on the day it decided?
If this landed, I’d love to hear it — comment, follow, or share it with whoever has been asked to justify a decision using evidence that no longer exists.