A server room floor before an open rack, dust across everything except one worn clean patch where somebody knelt repeatedly.

Specimen VII

The Goodwill

Threat rating
Endemic
Domain
Change scheduling

First contact

A platform cutover scheduled two weeks before the largest sale season that customer had. The date of the sale season had been known for a year. The collision was raised more than once, by people whose job it was to raise it, and the answer each time was the same: “It will be fine.”

It was fine.

Behaviour

It prevents outages. Nobody goes looking for a thing that keeps the platform up. A change lands beside the one window where failure would be most expensive, the platform holds, and the holding is produced by a small number of people fixing production by hand at two in the morning for several weeks. None of that effort has a record. There was no incident, so nothing was logged. The budget held, so nothing was escalated. The project closes green and the schedule is retrospectively correct.

What it leaves behind is worse than an outage would have been. The next cutover is planned the same way and defended with evidence, because last time it was fine. Each survival raises the confidence and lowers the margin, and the only resource being consumed is one nothing in the organisation meters. The first reliable signal that it has run out is people resigning.

Signs of infestation

Put the change calendar beside the business calendar — peak trading, year-end, enrolment, reporting deadlines — and find every go-live that lands inside one. Then find who owns reconciling those two calendars. Where the answer is nobody, that is the condition rather than an oversight.

Then test the successes, because the failures are already known. For each change that landed near a peak and reported green, look at what the estate was doing in the fortnight after go-live: deployments by hour, Activity Log write operations by hour, privileged activations at night, commits at weekends. A change that genuinely went well is quiet afterwards. Where the nights are busy, the green status was manufactured, and you are looking at the invoice.

Containment

Rescheduling one change fixes one change. The condition only shifts when the save becomes visible, so record what a go-live cost in hours outside the plan and publish it beside the go-live’s status. A project that closed green on six weeks of nights was subsidised, by people who were never asked and cannot be repaid.

Recovered note

It did not break. The only reason it did not break is that the IT team spent many nights fixing it in production. Nobody who approved the date was there for any of them.