{
  "schema": "vedokrok.public-item.v1",
  "release_id": "MHC-RPUB-20260920-75ad787a",
  "url": "/knowledge/treat-surprise-as-evidence-that-the-model-is-incomplete",
  "id": "MHC-D-RESEARCH-1282",
  "version": "0.1.0",
  "title": "Treat surprise as evidence that the model is incomplete",
  "summary": "Surprise is not automatically danger, but it is evidence that your map of the situation missed something.",
  "kind": "principle",
  "body": "When a meaningful surprise appears, avoid forcing it immediately into the nearest familiar explanation. Pause consequential action if the unknown invalidates safety assumptions, preserve the cue, and ask what model, dependency or condition was missing. Then decide whether to update the procedure, monitoring, training or operating boundary. Resilient systems need a way to notice and respond when the prediction fails.",
  "limits": [
    "Do not overreact to every novelty. Escalate based on consequence, uncertainty and whether the unexpected state undermines assumptions the current action depends on."
  ],
  "topics": [
    "union-drift-alerts-change-control"
  ],
  "intents": [],
  "source_ids": [
    "RS-51C347036C655252"
  ],
  "evidence": [
    {
      "claim": "NASA's 2025 organizational-resilience work explicitly treats early cues that something unexpected is happening and the response to surprise as important themes in resilient operations.",
      "source_id": "RS-51C347036C655252",
      "role": "supports",
      "note": "The report identifies organizational themes; it does not validate a single universal surprise-response procedure.",
      "locator": "Appendix B themes 3 and 9"
    }
  ],
  "use_when": [
    "Reality produces an unexpected state, anomaly or combination that the current procedure did not anticipate."
  ],
  "avoid_when": [
    "Do not overreact to every novelty. Escalate based on consequence, uncertainty and whether the unexpected state undermines assumptions the current action depends on."
  ],
  "example": "A process that normally fails loudly starts returning successful status with missing output. The surprise is not 'just another bug'; it reveals that the current success signal is incomplete.",
  "check": "The review identifies the assumption exposed by the surprise and either updates the model/control or records why no change is needed.",
  "sources": [
    {
      "id": "RS-51C347036C655252",
      "title": "Best Practices for Organizational Resilience in the International Space Station (ISS) Program",
      "url": "https://ntrs.nasa.gov/citations/20250005960"
    }
  ],
  "relations": [
    {
      "from": "MHC-D-RESEARCH-1282",
      "to": "MHC-D-RESEARCH-0490",
      "type": "useful_with",
      "url": "/knowledge/stop-the-process-when-the-unexpected-state-invalidates-the-safety-assumptions"
    }
  ],
  "collections": [
    {
      "id": "RC-63301F6643A9DBC3",
      "title": "Detect safety drift before the exception becomes normal",
      "url": "/collections/detect-safety-drift-before-the-exception-becomes-normal"
    }
  ]
}
