All posts
compensationreliabilitysupportincident response

A compensation record should preserve the uncertainty it closed

Reversing a side effect is safer when the case still explains what could not be proved about the original delivery

Compensation can make a customer whole while making the incident record less honest.

The refund is issued.

The replacement message is sent.

The duplicated reservation is cancelled.

The operator closes the case because the visible harm has been reversed.

What disappears is the reason compensation was necessary in the first place. The original delivery remained uncertain, the team could not prove which side effect completed, and a deliberate corrective action was chosen to bound the customer's risk.

If the record keeps only the correction, the next person sees a tidy outcome with no reliable account of the uncertainty underneath it.

We think a compensation record should preserve the uncertainty it closed.

The corrective action is not a verdict about the original attempt

A compensation answers a practical question: what action reduces harm now?

It does not always answer the historical question: what exactly happened before the evidence ran out?

Suppose a delivery timed out after crossing a remote boundary. Local retries stopped. Lookup returned no final status before its useful window closed. The team may choose a refund or reversal because leaving the customer exposed is worse than accepting the cost of compensation.

That decision can be sound even if the original side effect is never conclusively classified.

The case should not rewrite unknown as failed merely because failure makes the corrective action easier to explain. It should keep the two statements separate:

  • original outcome: unresolved after the final evidence window
  • corrective action: completed to bound customer impact

That separation protects the truth without weakening the response.

Closing customer harm and closing technical uncertainty are different events

Support often needs to tell a customer that the practical issue is resolved. That answer should not depend on pretending the delivery system learned more than it did.

The case can say that the replacement arrived or the refund completed. It can also say that the first attempt could not be proved either way. Those facts do not conflict.

Keeping both matters when the customer returns later. If a delayed original side effect appears after compensation, the team can recognise it as a known residual risk instead of treating it as a new mystery. The case already explains why the corrective action happened and what uncertainty remained open at that moment.

This also prevents a misleading success metric. If compensation automatically changes the original delivery to failed, incident review may conclude that the transport failure rate was higher than it was. If it changes the original delivery to resolved, review may miss how often the system needed a costly human action because evidence was insufficient.

Neither label is accurate enough on its own.

The record needs four durable facts

A useful compensation entry can stay compact. It should preserve:

  1. the last honest state of the original delivery,
  2. the evidence boundary that prevented a stronger conclusion,
  3. the corrective action chosen and its own outcome, and
  4. the residual risk the next operator should still recognise.

The residual risk may be that a late receipt can still arrive, that the original provider can still complete asynchronously, or that a second reconciliation pass is needed after a defined window.

Naming that risk does not mean the customer case must remain visibly open forever. It means the operational record stays ready for the next fact instead of declaring certainty early.

A later fact should update the case, not erase the earlier decision

Sometimes the missing receipt arrives after compensation. Sometimes a provider lookup eventually confirms that the original attempt completed. Sometimes no stronger fact ever appears.

If new evidence arrives, the case should append it to the timeline and reassess the residual risk. It should not make the compensation look mistaken simply because the team knows more now.

The operator made a decision from the evidence available at the time. A good record preserves that decision context. Later review can then ask the right question: was compensation reasonable under the known uncertainty, not whether it would have been necessary with evidence that arrived hours later.

That distinction makes postmortems fairer and system improvements more precise.

If compensation repeatedly occurs because one provider's lookup window closes too early, the product team has found an evidence-retention problem. If it occurs because the case hides a durable receipt, the product has a retrieval problem. If operators compensate while a reliable lookup remains available, the workflow may have a decision-support problem.

One generic resolved state cannot reveal those differences.

Resolution should remain honest after the money or message moves

At Stack Dispatch, we care about the case file that survives after the urgent action. Compensation is important, but it should not wash uncertainty out of the record.

A compensation record should preserve the uncertainty it closed because customer resolution and delivery certainty are separate outcomes. Keep the last honest original state, the evidence boundary, the corrective action, and the remaining risk visible together.

The case can be operationally complete without pretending the past became clearer than it was.

0 comments

Join the conversation

Get the next dispatch

New writing on software architecture, AI systems, and shipping production software, sent by email. Unsubscribe anytime.