There is a script here that reads every document in the project and checks the numbers in them against the actual files on disk. Page counts, prices, how big the app is. It exists because four documents were once found quietly contradicting each other, and nobody noticed for weeks.
It reported nine out of nine. Green. Grand.
The file it was checking was empty. Zero bytes. A script had opened it to write a correction, truncated it on the way in, then fell over before writing anything. The controlling document of the whole project was a blank page and the checker said it was fine.
It said it was fine because every check it ran was looking for a wrong number, and a blank page has no numbers in it. It was flawless against a typo and blind to a deletion. Which is the wrong way round. A wrong number sends you off in the wrong direction for an afternoon. An empty file loses the argument entirely.
The fix took two minutes — check the document still has a heading. The part that took longer was the sitting-there afterwards, going through the other checks and asking which of them had ever actually failed. A few of them never had. I had been reading green as evidence, and green is not evidence. It is just green.
So now nothing is trusted here until it has been broken on purpose and watched to go red. Every gate, once, deliberately. It is a slow, slightly stupid ritual and it has caught three things since.