IVAN FERLAND / INCIDENT ROOM / SYNTHETIC

A denied write. Two boundaries.

A complete synthetic investigation. Technical and operational views share the same facts.

← Home
Synthetic incident record

This record uses fictional hosts and events. It represents neither a customer incident nor an inspection of your device.

DEMO-CONSOLE-02

Owned storage recovery, export boundary intact

A synthetic write probe is denied in the Axiom-owned data root. A bounded recovery succeeds there, while an arbitrary export destination remains denied.

Initial business impact

The fictional diagnostic console cannot save its own synthetic run record. The replay contains no customer or clinical data, and no system-wide permissions are changed.

Synthetic scenario diagram
  1. Fictional request
  2. Scope check
    • Axiom-owned storage
      Eligible scope
    • External destination denied
      POLICY_DENIED

The destinations are separate branches: owned storage can be eligible; the external destination remains denied.

Ivan Ferland · Synthetic record — no customer incident

Owned storage recovery, export boundary intact

DEMO-CONSOLE-02

Impact and final state

The fictional diagnostic console cannot save its own synthetic run record. The replay contains no customer or clinical data, and no system-wide permissions are changed.

A synthetic write probe is denied in the Axiom-owned data root. A bounded recovery succeeds there, while an arbitrary export destination remains denied.

Decision and permission boundary

In the synthetic record, the operator confirms the owned data root and selects the scoped storage-recovery operation. Only that owned root is eligible. The external destination is rejected again instead of expanding the allowlist.

The documented executable recovery allowlist is restricted to Axiom-owned storage and runtime. An arbitrary export path is outside that boundary and must stay denied. This public experience changes narrative state only; it does not read paths or modify permissions.

Validation and handover

A new fictional write probe succeeds within the owned data root and the synthetic run record is readable. The outside export destination still receives POLICY_DENIED. Both checks are required: recovery must not weaken the boundary.

The original write denial is observed; its historical cause is unknown. The record cannot distinguish inherited ACL drift, a prior setup mismatch or another local condition. The arbitrary export denial is expected policy behaviour, not evidence of a fault.

Stop conditions

Stop if ownership or the canonical data root cannot be confirmed, if the destination escapes the allowlist or if the bounded recovery fails. Preserve the denial; do not request broad permissions or retry arbitrary export paths.

Complete record and evidence

Fictional timeline

  1. Owned write denied

    A synthetic write test reports ACCESS_DENIED in the declared owned data root.

  2. Export request rejected

    A bundled request for an arbitrary destination receives POLICY_DENIED.

  3. Scoped recovery recorded

    The fictional operator selects Axiom-owned storage recovery after checking ownership.

  4. Positive and negative checks

    Owned write succeeds; outside export remains denied. Historical cause stays unknown.

Evidence

ROOT-E1 · Owned-root write: ACCESS_DENIED

The fixture records a denied write attempt inside the declared Axiom-owned root.

Interpretation: Directly supports the observed inability to save the console’s own run.

Limit: The denial alone does not identify the historical ACL or account change that caused it.

ROOT-E2 · Arbitrary export: POLICY_DENIED

The bundled external-destination request falls outside the owned-root allowlist and is rejected.

Interpretation: Supports correct enforcement of the export boundary.

Limit: This is not a failed repair or proof of an operating-system permission problem.

ROOT-E3 · Owned recovery recorded

The fictional record confirms ownership and a recovery operation confined to the approved data root.

Interpretation: Shows the intended allowlist decision without expanding system privileges.

Limit: This is a synthetic replay, not a runtime audit of the private product.

ROOT-E4 · Owned write and read succeed

The post-action fixture successfully saves and reads its synthetic run record.

Interpretation: Supports recovery of this bounded storage operation.

Limit: Does not retrospectively prove the original permission failure’s cause.

ROOT-E5 · Outside export remains denied

The same bundled external-destination request still returns POLICY_DENIED.

Interpretation: Confirms that this synthetic recovery preserves the export boundary.

Limit: No arbitrary path can be entered or executed in this public page.

Competing hypotheses

Owned storage is not writable

Observed condition supported

The denied probe directly supports this observed condition, but not its origin.

Historical ACL drift caused the denial

Unconfirmed

The record has no before-change ACL evidence. Recovery is not proof of a particular historical cause.

All export destinations need broader access

Not supported by this record

The external request is intentionally denied by policy. Broadening access would violate the product boundary.

Chosen action

In the synthetic record, the operator confirms the owned data root and selects the scoped storage-recovery operation. Only that owned root is eligible. The external destination is rejected again instead of expanding the allowlist.

Permission boundary

The documented executable recovery allowlist is restricted to Axiom-owned storage and runtime. An arbitrary export path is outside that boundary and must stay denied. This public experience changes narrative state only; it does not read paths or modify permissions.

Stop and escalation conditions

Stop if ownership or the canonical data root cannot be confirmed, if the destination escapes the allowlist or if the bounded recovery fails. Preserve the denial; do not request broad permissions or retry arbitrary export paths.

Validation and open questions

A new fictional write probe succeeds within the owned data root and the synthetic run record is readable. The outside export destination still receives POLICY_DENIED. Both checks are required: recovery must not weaken the boundary.

The original write denial is observed; its historical cause is unknown. The record cannot distinguish inherited ACL drift, a prior setup mismatch or another local condition. The arbitrary export denial is expected policy behaviour, not evidence of a fault.

Open the interactive replay →