Scenarios
Proven in the shadows
Rewritten billing aggregation — output must match to the cent before touching a real invoice. Outcome: proven · 2.1M comparisons. 5 of 5 held · 0 mismatches escaped
one control point a woven topology
“a one-line bugfix” ●shipped · 41 min“a CLI release to every laptop” ↶re-pinned in 51 s · then shipped“a mobile feature stuck behind store review” ●shipped · one binary“a rewrite that claims it’s 10× faster” ●proven · 2.1M comparisons“a risky change to a feature most orgs ignore” ●verdict · 5 h“a new skill for your agent fleet” ●fleet-wide · 0 broken sessions“a feature that spans API and UI” ●shipped · 3 days“one contract across three services” ●zero drift · one 40-min hold“a feature built on another feature” ●2 ships · 1 graph“the change that looked safe” ↶reversed · 43 s
billing-shadow-rewrite
PROMOTED · 11× FASTERProven in the shadows
Rewritten billing aggregation — output must match to the cent before touching a real invoice.
The plan — drafted before anyone saw it
Strategy Shadow the new path first; promote only on parity proof
Control points Shadow control point — mirror traffic, diff results, discard
Gates row-level parity ≥ 99.99% · p95 runtime · memory per shard
Guardrails parity drift · cost per query
Rollback any mismatch on a money path → stay on the old query
Ramp — planned outline, actual fill
shadow
10%
50%
100%
The run — from the decision log
T+0m read: rewrites billing aggregation — output must match to the centheld
T+1h chose: shadow control point: new query mirrors traffic, results diffed, discardedheld
T+2d watched: row-level parity, p95 runtime, memory per shard — 2.1M comparisonsheld
T+4d gate: parity 100.00% · 11× faster — promotion approvedheld
T+5d done: promoted with the old path kept warm for 48 h as fallbackheld
5 of 5 held · 0 mismatches escaped
learnedshadow-diff topology is now the default for money-path rewrites.