After an incident
The incident file — which number, which edition, and was the use covered.
Three questions are asked at once after an incident on a machine: which skill set was it running, which edition, and did a licence cover that use. The register answers all three from records it already keeps.
The answers are evidence about the machine and about the licence. A record is never supplied to assess the person, to an insurer or to anyone else.
A reading of records the register already keeps, for one machine over one span.
Not a new record. An incident file is records the register already holds, read together for one machine over one span: the machine manifest for that unit, the licence against each number it names, and the usage receipt for each use. Side by side they answer three questions, and the file stops where those answers stop.
Why the reading has a name. The receipt exists so that a use can be read back from both ends; the manifest exists so that a unit's configuration has a provenance of its own. An incident is the moment somebody has to read both at once, under pressure, about a day that has gone. Naming the reading makes it ordinary: the questions are settled in advance, so is the record each is answered from, and nothing is assembled out of recollection.
What it adds to the register. Nothing. No event is written to a number because an incident happened, no new field appears on a Card, and the register is never told that anything went wrong.
Three questions, and where each answer is read from.
| The question | Where the answer is read | What the answer is |
|---|---|---|
| Which skill set was the machine running? | The machine manifest for that unit, over that span. | The number, with the name beside it and never instead of it. |
| Which edition of it? | The same manifest, and the receipt written for each use. | The edition the licence pinned, sealed, and its seal can be checked. |
| Was that use covered? | The cover answer the register gave before the use, read off the licence on file. | Covers, or does not cover. |
The third answer is reached for first, and it is the narrowest. Its words are covers and does not cover — the register's words rather than anybody's judgement: they say whether a use stands inside the paper a licensee itself signed. What is asked and what is never answered is at the answer before a use.
Read in order, they describe a configuration and a permission. There is no fourth question the register can take: what the machine did, why, and who should have done what are not facts it holds, and an answer given anyway would be read as a finding.
Six parts, and every one of them written before the day it is wanted.
| The record | What it carries into the file |
|---|---|
| The unit | The machine, as the OEM or the fleet owner identifies it. The register holds no identifier of its own. |
| The editions loaded | Each Machine-track number and the edition the unit runs, over the span the file covers — the machine manifest. |
| The licence | The paper each number runs under: its kind, term, field of use and territory, and the conditions carried onto it from the Card. |
| The cover answers | What the register answered before each use: covers, or does not cover, with the day. |
| The receipts | The usage receipt each use writes, read from both ends on Meter. |
| The seal | The edition is sealed when it is frozen, and its seal can be checked years after, because nothing is stored as a verdict. |
Every one is written at the moment the work is cleared to start, and none afterwards. That is why the file can be relied on: a record made after the fact is a description of it, and a record made before it is evidence.
What the file does not gather is as fixed as what it does: no reading taken off the machine, no record of the work, no moment-by-moment account, and no entry for the person in the seat. The register holds what was loaded, what was permitted and what was counted.
The file says what ran and what was permitted. It says nothing about who was in the seat.
Evidence about the machine and about the licence — and the register has no facts of its own about anything else.
Evidence about the machine and the licence, and nothing about the person.
A record is never supplied to assess the person, to an insurer or to anyone else. The refusal is structural rather than promissory. A file names a number, an edition, a licence, a cover answer and an hour; none of those is a measurement of anybody, and no outcome is recorded against a person's number. A request for a record of how somebody worked is refused because there is nothing of that kind to supply, which is a stronger answer than a policy.
A licence permits a use; it never requires one. The machine's own safety logic refuses whenever it refuses. A cover answer says that a use stands inside the paper. It never says the use is safe, that the ground is right, or that the work should go ahead. The decision to run belongs to the operator and to the machine, and no answer this register gives may be read into a safety case. On the Machine track the older rule is the same rule: a release proposes, a person authorizes, and safety has veto.
What the register does not do with a file. It does not investigate, does not apportion fault, does not decide what happened, and makes no finding about the machine, the work or anybody near it. Where what an entry covers is put in question, the challenge is recorded as a challenge; who is right is decided where such questions are decided. The register records; it does not decide.
What a file is not. It is not a record of what a machine did, because the register never receives one. It is not a report, and nobody at the register writes one. It is not produced to a party with no entitlement to the rows: an entitlement to read is what an agreement gives, not what an event creates.
The parties to the rows, and nobody else by default.
Who reads what, and on what footing. A usage receipt is read from both ends by the two parties on it: the licensee that ran the use, and the Source whose entry it ran against. A machine manifest is read by the party that holds the machine and the party that licensed what is on it. Entitlement comes from an agreement rather than from an event — a fleet owner reads its own machines, a licensee its own licence, a Source their own entry — and nobody acquires a right to somebody else's rows by asking at the right moment.
How a third party gets one. Through the parties, or through the place where such questions are decided, never through a side door at the register. A party may produce its own records to whoever it chooses or is required to, and the register neither supplies them on its behalf nor stops it. Where an entry is carried closed, a reader who cannot see it cannot be told that it is there.
The same records, read by the fleet, by counsel and by the person in the seat.
For the OEM or the fleet owner. Three answers, each read from the register's own record and each carrying the day it was written: which number, which edition, and whether the licence covered that use. They are answers a second party can check rather than a statement somebody prepared, and they come from the records that answer an ordinary working week.
For counsel. A signed row is evidence of what was permitted and what was counted, and of nothing else; a cover answer is evidence of what the register read back off a licence on a day. What such a row must carry to be useful in a dispute is a question with counsel. What the register warrants is its own acts: the count, what it computes, the stop, and the accuracy of the record it reads back.
For the person in the seat. The file cannot be turned on them. Their name stands on their own Card as an address, and what the register holds beside it is a number, an edition and a count — not a grade, not a result, not an account of how a day went.
What is counted, and how both ends read the same row, is on Meter.
It sets out the unit on each track, the fields a signed row carries, and what each end of that row can read.
