01The failure nobody sees
A catalog read from a database doesn't stay still. Someone renames a column, rewrites the descriptions, or a supplier changes an ingredient list, and the next time the data is read, a safety value can be missing from dozens of records. Nobody removed it. Nothing errored. The records simply stop carrying it.
On a safety field that is the worst kind of change: a dish that was correctly left out of a dairy-free answer is now served as if it were safe. The point of failing closed is lost one quiet re-import at a time.
02Compare with what was released
A release is a snapshot that never changes, so it is the right thing to compare against. A sync reads the source table again, matches rows to records by the identity column, re-tags only the records whose text changed, and removes records whose rows are gone. Then, before anything is published, it compares the result with the last release.
03Two signals worth an alert
- A value's share moved. On a safety field, a value carried by 5 percentage points fewer records is critical, and 10 points more is a warning. On an ordinary field, a move of 10 points either way is a warning.
- More records unknown on a safety field: a rise of 5 points is a warning, 10 is critical. Unknown is never served as safe, so this is the agent's answers quietly shrinking.
Small datasets swing on a handful of records, so nothing is compared when either side has fewer than 30.
04What happens then
A sync that finds drift waits for a person, and the workspace's owners are emailed with the alerts. Each alert stays until someone acknowledges it.
Publishing automatically is off by default. An owner can turn it on per dataset, and even then a sync publishes only when nothing drifted, still behind the accuracy gate.