Work-Performance Configuration and Recovery Testing
About this pattern
This is a generated FPF pattern page projected from the published FPF source. It is canonical FPF content for this ID; it is not a FPF Reference product feature page.
How to use this pattern
Read the ID, status, type, and normativity first. Use the content for exact wording, the relations for adjacent concepts, and citations to keep active work grounded without pasting the whole specification.
Type: Architectural (A) Status: Stable Normativity: Normative unless marked informative
Plain name. Test whether the exact performer, support, and continuation-state configuration for Work can continue or recover when something important changes.
Primary reader. A practitioner preparing or performing human, automated, biological, organizational, computational, or mixed Work whose result may depend on several Systems, tools, records, resources, and environmental conditions.
Use this when. Use this pattern when a result succeeds in one configuration but may fail after interruption, handoff, delay, support loss, replacement, or changed conditions, and the decision needs to know which exact relation to repair or test. Begin through exactly one lawful branch:
Relations
Content
Problem frame
Use this when. Use this pattern when a result succeeds in one configuration but may fail after interruption, handoff, delay, support loss, replacement, or changed conditions, and the decision needs to know which exact relation to repair or test. Begin through exactly one lawful branch:
- Actual-Work branch: start from one exact dated
U.Workoccurrence already admitted underA.15.1. Name actual performers, assignments, and attribution only where their direct rules pass. - Present-WorkPlan branch: start from one exact present
U.WorkPlanunderA.15.2. Intended performers and intended performance remain declaration-local plan content; they are not an existing futureU.Work, obtaining assignment, or actual attribution.
Start with an ordinary branch-exact sentence:
Actual Work: For this admitted Work occurrence, these Systems performed it under the direct attribution rules; these other Systems or values supported it; this is where the state needed to continue lives; this dependency failed under this probe; repair this relation or stop.
Present WorkPlan: For this present WorkPlan, these Systems are named only as intended performers in its declaration-local content; these other Systems or values support the proposed configuration; this is where the state needed for intended performance would be recovered; this dependency is unsupported by the current plan or probe claim; repair the plan relation or stop.
First useful result. Return a short branch-specific account naming the exact Work or WorkPlan focus, required result and receiving decision, actual or intended performers, supports, continuation-critical state, probe and observation, the direct relation result or exact blocker, and the next repair or stop.
What changes in practice. Instead of saying that a person, tool, team, organism, service, or machine must “pay attention”, “remember”, or become one “extended performer”, the practitioner names the exact relation whose loss changes continuation or recovery and challenges that relation under one representative condition. The next move becomes a bounded configuration repair, direct domain test, plan change, or stop.
Cheap non-use. Do not use this pattern merely because Work uses a tool, a person takes notes, software has state, a bacterium responds to its environment, or several Systems participate. Stop when current results from directly governed domain Work already identify the actual configuration, continuation state, representative recovery evidence, and limits needed by the decision, with the applicable Method and evidence boundary explicit. If A.15.5 has established an ordinary full kit and no interruption, handoff, support loss, or configuration ambiguity can change entry, stop there. If the configuration is adequate and only the next action during current Work is open, use A.15.7.
Not this pattern when. Use A.1 or B.2 when the current question is whether a proposed whole is a System or must be reidentified; A.2.2 for capability of one admitted holder; A.15.1 for Work occurrence identity or resumption segmentation; A.15.2 for the WorkPlan; A.15.5 for ordinary entry readiness; A.15.7 for next-action selection; A.22 for one selected Structure; C.30 for architecture; the direct representation pattern for a representation; A.10 for evidence reliance; or the applicable domain Method when only its test, threshold, algorithm, safety rule, or intervention is missing.
Problem
Performance often depends on relations among actual or intended performers, supporting Systems, physical resources, representations, records, services, models, environmental conditions, and state needed for continuation. A perfect run can hide that one dependency is stale, inaccessible, inconsistent, unavailable to a successor, or supported only by the current session.
Umbrella words conceal different objects. “Attention” may mean sensing, selection, monitoring, search, checking, or a holder capability. “Memory” may mean internal state, a record, model state, retrieval, cultural continuation, or a relied-on claim. “Work state” may mix world state, epistemes, carriers, and cues. Treating these words as fields on one composite performer hides the relation that must change and can incorrectly assign System identity, Work, capability, authority, or evidence.
The missing practical move is neither a theory of mind nor a universal resilience procedure. It is to recover the exact Work-dependent configuration, expose the minimum state needed to continue, challenge the weakest decision-changing dependency, and return the observation to its direct owner.
Forces
Solution
Choose one branch, keep every System and value separately identified, recover only relations that can change the named result or decision, and run the weakest representative probe that can expose an unsupported dependency. Return the branch-specific result to direct owners. Do not first decide whether cognition, mind, or agency is “extended”.
Keep the governed object and non-kinds explicit
This pattern introduces no root U.ExtendedPerformer, U.WorkSystem, U.WorkState, U.Attention, U.Memory, or joint-cognition kind. It does not admit an arrangement as a System, performer, Agent, Structure, ArchitectureRelation, or capability holder merely because its constituents are coupled or jointly useful.
In the actual branch, the governed world-side focus is one exact admitted U.Work occurrence. In the prospective branch, it is one exact present U.WorkPlan; proposed performance stays declaration-local content of that episteme. Supporting Systems and values may be inside or outside a selected containing-System boundary. Their contribution, dependency, access, update, control, or other relations must be directly declared and supported when the result relies on them.
An arrangement remains ordinary prose unless another use needs an exact U.Structure admitted under A.22. An architecture claim enters only through C.30. A configuration account can designate several independently governed Systems and values without making them one whole or using a plural EntityOfConcern.
Follow the seven-step configuration-and-recovery sequence
- Choose the lawful branch and name its focus, required result, and receiving decision. For an actual case identify one exact dated
U.Workoccurrence underA.15.1. For a prospective case identify one exact presentU.WorkPlanunderA.15.2and the declaration-local intended-performance content used by the configuration claim. UseA.15.5only when entry readiness is current. Do not call intended performance a future Work entity. - Keep performers, intended performers, supports, and values separate. In the actual branch identify the admitted Systems that performed the Work, with assignments and attribution only where their direct predicates pass. In the prospective branch name intended performers only inside the exact WorkPlan's claim content. In either branch identify supporting and external interacting Systems, physical resources, representations, records, models, tools, services, and environmental conditions without forcing them into one whole.
- Recover concrete contributions and dependencies. Translate words such as attention, memory, computation, and checking into exact sensing, selection, monitoring, operation, record, state, evaluation, communication, access, update, control, or other direct relations. For actual Work, retain only relations whose obtaining, loss, or change can alter continuation, result, or recovery of that occurrence. For a WorkPlan, retain only relations whose obtaining, loss, or change can alter the current plan, proposed configuration, or intended-performance content. For every attempted relation claim, name the exact participants and receiving use. When a current predicate definition, applicability condition, occurrence rule, or other governor can state or test it, apply that governor and preserve its result: use
factually unsupportedonly when the available case basis is sufficient and the positive test fails,missing-informationwhen a needed fact is unavailable, and an inapplicable or negative result only under the governor's own rule. Returnmissing-governoronly when no current rule can state or test the attempted claim for those participants and that use. Name capability and authority only when their direct claims are current. - Expose the minimum continuation state. For each value needed after interruption, handoff, support loss, or delay, state what it concerns, where it resides, who or what may update and use it, how currentness or consistency is determined, and which return condition makes it usable. Keep world state, claims, carriers, and cues distinct.
- Select the weakest decision-changing condition. Choose one representative interruption, handoff, degraded support, changed performer, changed tool or environment, or delayed-continuation condition. Apply it to the named Work occurrence in the actual branch. In the prospective branch, formulate it as a condition of the current WorkPlan, proposed configuration, or intended-performance content. If executing the probe creates actual test Work or a later performance, admit that occurrence separately under
A.15.1; otherwise keep the condition in the plan or probe claim. Do not demand a ritual battery. - Run the direct domain probe and observe recovery. Select an applicable human-factors, biological, software, robotics, operations, rehearsal, safety, or other domain
U.Methodonly to define or constrain the probe, mechanism, thresholds, safety rules, and evidence rules. When the probe is executed, recover each actual performer through A.13 and admit its dated probe Work separately underA.15.1; state that the Work enacts the Method. Add A.2.1 and F.6 only when this probe account expressly consumes precise assignment-bound attribution through the same obtaining A.13 assignment. A missing or failed attribution leaves the probe Work intact. When the probe remains prospective, keep it as a condition in the WorkPlan or probe claim. Observe result recovery, time or burden where material, wrong continuation, missing or stale state, unsupported dependency, protected-condition loss, and fallback or stop. This pattern supplies no universal cue, timeout, checkpoint algorithm, intervention, or safety threshold. - Return one branch-specific account to direct owners. State which exact Work occurrence or present WorkPlan is the focus, what configuration is supported for which occurrence or intended-performance content and window, what failed or remains unknown, and the next relation or configuration repair or stop. Return System identity to
A.1orB.2, Structure toA.22, architecture toC.30, capability toA.2.2, actual Work and resumption identity toA.15.1, plan content and plan change toA.15.2, representations to their direct owners, evidence toA.10, and a receiving choice toC.11orA.15.7.
Return the first result in plain language
Use this compact form and omit rows the receiving decision does not need:
Focus: exact actual
U.Workoccurrence … / exact presentU.WorkPlan… and its declaration-local intended-performance designator …Required result and receiving decision: …
Actual performers for the Work / intended performers in the plan, plus supports: …
State needed to continue and where it is recovered: …
Probe and observation: …
Direct relation result or exact blocker, and next repair or stop: …
For a small reversible use, this ordinary prose is enough. The result describes support for one configuration and window; it does not certify every configuration, create a whole, or make the repair decision.
Persist only the account another use needs
When another use must retain, compare, audit, or rely on the result, identify one or more C.2.1 account epistemes explicitly.
- An actual-branch account selects the exact
U.Workoccurrence as its one truthful EntityOfConcern. - A prospective-branch account selects the exact present
U.WorkPlanas its one truthful EntityOfConcern. Its ClaimGraph may designate the declaration-local intended-performance content but does not turn that designator into an entity. - The ClaimGraph may also designate independently governed actual or intended performers, supports, state bearers, exact relation claims, and the direct governor's result. It may record the ordinary A.6.RCD blocker
factually unsupported,missing-information, ormissing-governoronly under that pattern's three-way split; these phrases are not new kinds or relation values. Probe observations, uncertainty, and the repair or stop remain separate claim content. - The effective
U.ReferenceSchemealways supplies the designation and interpretation rules needed by those claims and adds only the measurement, comparison, or evaluation rules actually used. Any actual measurement, comparison, or evaluation occurrence remains under its direct pattern. - If one focus cannot truthfully carry the combined claims, keep claims local or use several epistemes. Do not invent a plural focus.
The account is not the world-side configuration, performed Work, WorkPlan, carrier, evidence, or merely possible future performance.
Separate recognition from assurance
- Recognition: one actual or credible failure under interruption, transfer, support loss, or stale intermediate state is enough to open
A.15.8. One ordinary sentence can name the first weak relation and probe. - Assurance: safety-, release-, compliance-, irreversible-, or high-impact use adds the applicable direct test, evidence, assurance, authority, and stop rules. A successful probe does not establish universal readiness or waive those rules.
Precision restoration
Recover the exact object or relation before relying on the umbrella word.
Bias check. Human-centered cognitive vocabulary and anthropomorphic AI vocabulary are easy to recognize and therefore easy to overgeneralize. Begin with the exact Work or WorkPlan and direct relations. A bacterium, computation, machine, person, or team enters by the same FPF branch and relation rules; none requires mental, stakeholder, or ethical vocabulary unless the receiving question independently does.
Worked cases
Literature qualification across a researcher, services, and files
Situation. LiteratureQualificationWork-2026-08-27-AM is one admitted actual Work occurrence. Researcher-17 is first recovered as an actual performer through A.13, and A.15.1 admits the Work independently. This recovery account also compares accountability under one named assignment, so it separately establishes the exact A.2.1 occurrence and F.6 attribution; failure of that later relation would lower only the accountability attribution, not erase the Work. A search service, language-model service, repository, pinned papers, claim sheet, and unresolved-question note support the Work; none becomes a performer or constituent of a new whole merely by appearing in the configuration. A reviewer may continue later.
Probe. The fresh-session and reviewer-handoff probe removes the original model session and asks the reviewer to recover the bounded question, exact source editions, accepted and rejected claim reasons, open uncertainty, and next probe.
Observation and result. The reviewer can recover the papers but cannot distinguish why one claim was rejected because the claim sheet lacks a decision reason and one citation lacks an edition pin. The result focuses on the exact Work occurrence, identifies the missing source and record relations, and returns two repairs to their representation and source owners. The unsupported claim stops. No “extended researcher”, composite System, or researcher capability is inferred.
What changed. Repair the source pin and decision record before continuing; do not ask the person or model to “remember better”.
Non-human distributed computation after worker loss
Situation. SettlementComputationWork-2026-08-27-Run42 is one admitted long-running computation Work occurrence. Its separately grounded performer Systems exchange messages and use an object store, configuration values, intermediate results, completed-effect records, and provenance records. Another worker must continue without duplicating an irreversible settlement effect.
Probe. RecoveryTestController-Run42 : U.System first has the A.13 core for the probe action; A.15.1 then independently admits WorkerLossRecoveryProbeWork-Run42-P1 : U.Work in the bounded representative environment. The recovery comparison expressly uses which controller assignment covered the probe, so the account separately establishes that A.2.1 occurrence and F.6 attribution through the same A.13 assignment. That probe Work enacts the selected computing U.Method: it removes one worker after a message has been emitted but before its local completion record is available, then attempts recovery from the selected state mechanism. If the F.6 link failed, the probe Work would remain and only its assignment-bound attribution would be unresolved.
Observation and result. Process state is recoverable, but channel state and the completed-effect provenance relation are not mutually consistent. The branch-specific account names those state bearers and update/use relations and returns the missing idempotency or provenance condition. A Chandy-Lamport snapshot, event sourcing, transaction protocol, or another computing Method may be selected as the reusable way for the repair. If the repair is carried out, an admitted System performs the dated repair Work and that Work may enact the selected Method; this pattern selects neither.
What changed. Add or repair the exact checkpoint, provenance, or idempotency condition. No human attention, memory faculty, or cognitive ontology enters.
Equipped performer in a present WorkPlan
Situation. ConcertPerformancePlan-2026-09-12 is one exact present U.WorkPlan. Its declaration-local content names a musician and a robotic prosthesis controller as intended performers for a proposed performance after device replacement. It also names an instrument, cue source, power support, control link, and allowed latency. None of this content is a future Work occurrence or obtaining assignment.
Probe. The current plan proposes a rehearsal under changed latency and a degraded visual-cue condition. Its material, timing, control, threshold, and stop rules are taken from the applicable music-performance, robotics, human-factors, and safety Methods. If the rehearsal occurs, first recover each actual performer through A.13 and admit the actual Work independently under A.15.1. Add F.6 only if the receiving rehearsal account also consumes precise assignment-bound attribution; missing or failed F.6 leaves the rehearsal Work intact.
Observation and result. Current evidence does not support recovery after cue loss within the required timing window. The WorkPlan-focused account names the intended performers, support and control relations, return condition, uncertainty, and the planned probe. It returns a plan repair: restore a redundant cue/control relation or narrow the supported configuration. Capability claims for the musician, device, or any independently admitted whole stay separate.
What changed. Repair the proposed sensing, control, cue, or recovery relation before declaring entry readiness; do not infer one timeless capability holder.
Conformance and practical checks
A use conforms to this pattern only when it passes the checks that its claimed result needs:
- A cold reader can obtain the first result without deciding whether cognition or mind is extended.
- The selected focus is exactly one admitted actual
U.Workoccurrence or one exact presentU.WorkPlan; intended performance remains declaration-local plan content. - Actual performers, intended performers, supports, values, and environmental conditions remain distinct. Every attempted relation claim names exact participants and the receiving use, applies a current direct governor when one exists, and preserves its
factually unsupported,missing-information, inapplicable, negative, or other direct result;missing-governoris used only when no rule can state or test that claim. - No arrangement becomes a System, performer, Agent, capability holder, Structure, architecture, or evidence merely by inclusion or wording.
- Continuation-critical state names its concern, bearer or carrier, update and use relations, currentness or consistency condition, and return condition when each matters.
- The probe is the weakest representative condition that can change the receiving decision; its mechanism, thresholds, safety rules, and evidence rules come from an applicable direct domain Method. For any dated probe Work, recover the exact actual performer through A.13 and let A.15.1 independently admit the occurrence; add F.6 only for an expressly consumed precise assignment-bound attribution, whose failure leaves the Work intact.
- Actual test or later performance Work is admitted separately under
A.15.1; a proposed condition remains a plan or probe claim. - The result names one unsupported dependency and next repair or stop, or states that the selected probe found none within its declared window.
- A relied-on account has one truthful C.2.1 focus and effective ReferenceScheme; incompatible focuses split instead of forming a plural EntityOfConcern.
- Recognition and assurance remain separate; high-consequence use opens direct evidence, assurance, authority, and domain-stop rules.
Recognition check. Ask a reader to produce the compact result from one case in ordinary language. If the reader first needs a theory of attention, a new performer whole, a capability diagnosis, or a full architecture model, repair the entry and boundary.
Assurance check. For consequential use, identify the exact direct test, evidence, criterion, authority, protected condition, applicability window, and stop. If any is absent, retain the configuration observation but do not upgrade it to readiness, safety, release, or permission.
Anti-patterns
- Composite by coupling. Treating person, device, service, records, and environment as one performer because they jointly matter.
- Future Work from a plan. Giving intended performance, intended performers, or proposed relations actual Work identity or obtaining attribution.
- Umbrella slots. Adding universal attention, memory, cue, or Work-state fields instead of recovering exact objects and relations.
- Carrier equals state. Treating a note, trace, checkpoint, model context, or file as identical to the world state or claim it carries.
- Perfect-run readiness. Generalizing one successful live configuration to interruption, handoff, support loss, or changed conditions.
- Probe as assurance. Treating success under one probe as universal capability, safety, permission, release, or certification.
- FPF as domain algorithm. Inventing a universal timeout, checkpoint, cue, redundancy, practice, or recovery procedure in this pattern.
- Configuration as architecture by default. Naming a support list a Structure or ArchitectureRelation without the direct admission and selection rules.
Consequences and trade-offs
SoTA-echoing source effects
Use source traditions for the action they change and keep their scope limits. The links and publication/status labels below were checked 2026-08-27. Correct a citation or publication-status label in its row without reopening the action when the used distinction and limit are unchanged. Reopen only the affected row and action when a source change alters the inventory, boundary, probe, observation, or decision supported by this pattern.
Relations
- Builds on:
A.1andA.13for admitted Systems and exact actual-performer cores;A.15.1for independent actual-Work admission;A.2.1andF.6only for an expressly consumed precise assignment-bound attribution;A.15.2for present WorkPlans and declaration-local intended-performance content;A.6.RELand direct relation patterns for obtaining relations;A.6.RCDfor the exactmissing-governor,factually unsupported, andmissing-informationsplit; and C.2.1 when a result must persist as an account episteme. - Coordinates with:
A.15.5for work-entry readiness;A.15.7for next-action selection after a configuration blocker is repaired;A.2.2,E.23.CAE, andE.23.CDIfor holder capability, the wider access/expression differential, and capability development;A.22andC.30for selected Structure and architecture;C.27.TAfor temporal/currentness claims;C.2.P.DRand direct representation patterns for carriers and representations;A.10for evidence reliance;A.15.4for appearance-based reliance repair;C.11for receiving decisions; direct domain patterns and Methods for probe mechanisms, thresholds, and safety rules; and direct subject patterns for authority and evidence. AnA.15.8observation may support anE.23.CAEconfiguration disposition, while the exact Work/WorkPlan relation test remains here. - Informs: domain patterns for equipped or joint performance, human capability development, organizational coordination, operations and service recovery, human factors, robotics, software and distributed systems, and biological Work when they retain their own quantities, mechanisms, evidence, and stops.
Didactic quick card
Which branch? Actual dated Work, or a present WorkPlan with intended performance only as plan content. Who performs? Only Systems with the direct actual attribution, or intended performers named only by the plan. What supports? Separately identified Systems and values through exact relations. What must survive? The minimum state, its carrier, update/use, currentness, and return condition. What do we test? Use an applicable direct domain Method to define one decision-changing loss, handoff, delay, or reconfiguration; when the probe occurs, an admitted System performs the dated probe Work. What comes back? The direct relation result or exact blocker and the next repair or stop—not a new performer whole.
A.15.8:End
Last Updated: 2026-09-03 — this section last modified in upstream FPF commit 59c45532 (github.com/ailev/FPF)