Methods · releases & currentness
A release is a named, immutable thing
Deployment is not activation
Code may ship with a model WITHHELD, a surface gated, or evidence STATUS UNAVAILABLE — and production keeps those conditions distinct. Withheld means a governed value exists but publication is not authorized; unavailable means SIGNAL cannot verify a publishable value. Neither permits a stale number under a current-sounding label. One release can therefore contain a withheld model and an unavailable status surface without treating either state as a deployment failure or silently promoting it.
Four different clocks — never collapsed
A newly built page can honestly present an older publication of an older model over an even older dataset. That is why product truth keeps four separate freshness clocks, and why collapsing them is how status pages lie:
- Source-data clock — the dataThrough boundary of the underlying dataset, as the producer states it. A dataset can end last September while its artifact was published this morning.
- Model/release clock — the producer's named model or release identity and its generation time when one is exposed. A release hash is an identity, not a timestamp; absent timing remains not measured.
- Publication/deployment clock — when the governed release was activated or deployed for readers. A deployment identifier alone does not supply this clock; when the producer does not expose it, SIGNAL says not measured.
- Page/build clock — when the producer page or artifact, and separately this SIGNAL page, were built. A new page build does not refresh source data, a model, or its publication.
SIGNAL additionally retains a capture-attempt clock for each fetch and an observation clock for each distinct normalized state. Those are audit provenance, not child-product freshness clocks.
- SOURCE-DATA CLOCK
- Data through The producer-stated boundary of the underlying dataset. It can end last September while its artifact was published this morning.
- MODEL / RELEASE CLOCK
- Release identity The producer’s named model or release and its generation time when exposed. A hash is an identity, not a timestamp.
- PUBLICATION / DEPLOYMENT CLOCK
- Activated for readers When the governed release was actually deployed. When the producer does not expose it, SIGNAL says not measured.
- PAGE / BUILD CLOCK
- Built When the producer page — and separately this SIGNAL page — was built. A new build refreshes none of the other three.
Current is earned, stale is admitted
Freshness policies are explicit — for example, offseason boards age after 5 days and go stale after 8, measured from the newest meaningful input, never from generation time. When a board fails the check, the served verdict says stale with the failed check named. The day the trust-recovery gate was adopted, all four boards evaluated to stale — and that reading was recorded as correct, not as a regression.
Rollback preserves history
Every deployment leaves an immutable hash. Rolling back promotes a prior known-good deployment — a new publication event pointing at old bytes — and the release notes record both directions. Nothing is deleted, nothing is rewritten, and the rollback target for the current release is always written down before anyone needs it. This site follows the same rule; see the release ledger.