risks.sgit.ai / the grounding ladder / absence

Not knowing is a fact

Absence of evidence is a first-class node. A measure can be a documented zero — “zero tested-restore records found” is as much a measurement as any positive count. An unevidenced fact is recorded as unevidenced rather than left blank, which is what makes it countable, queryable and assignable to someone.

“not knowing a fact is also a fact. Lack of evidence is also evidence, because then we say we do not know, and somebody needs to investigate until we do.”

The difference between a blank and a zero

In a spreadsheet register, three completely different situations look identical: the field is empty.

SituationIn a spreadsheetIn this model
Somebody looked, and found nothingempty cellA Measure returning zero, producing Evidence: “zero records found, checked on this date, by this method”
Nobody has looked yetempty cellA Fact marked unevidenced, which spawns its own risk and can be assigned
Somebody looked and never wrote it downempty cellIndistinguishable from the row above — and that is itself the finding

The first is a strong result. We checked, and there are no records of a tested restore in twelve months is a defensible, dated, attributable statement about the world. Collapsing it into the same blank as “nobody has looked” throws away the most expensive information in the register.

Gaps spawn their own risks

An unevidenced fact is not a hole in the register; it is a node with edges. And one of the edges goes upward, because not knowing has a business consequence of its own:

“the full extent of the impact has not been captured, which means the risk is not yet correctly classified or correctly accepted.”

That sentence is a risk statement, and it can be rated, owned and given an interval like any other. It usually gets a short one — the one-hour rung exists precisely for this: I cannot decide on what I have; someone must get me more data. An unevidenced fact and the one-hour interval are two halves of the same mechanism.

It also produces the cleanest instance of the meta-risk family: a risk that has been accepted on the basis of an unevidenced fact is an acceptance of something that may not be true, and that is a governance failure independent of whether the underlying fact turns out to be correct.

The question node, and why unanswered ones are the output

Late in the corpus, absence gets its own node type. A Question is a first-class node with an answers edge that may or may not exist yet — and the striking claim is about which ones matter:

Unanswered question nodes are the most productive output of the whole exercise.

In the Article 26(5) worked example, the graph carries nine questions, five of them unanswered, and the source document says of them: “those five are the actual output of the exercise.” Not the risks, not the ratings — the five things nobody could answer. That inverts what a risk assessment is normally judged by, and it is the honest inversion: an assessment that produced no unanswered questions almost certainly did not look hard enough.

The related quality gate is a question is not a risk: if a sentence cannot sensibly carry a named acceptor and an interval, it is a question rather than a risk and belongs in a different node type. “Nobody accepts ‘whose call is it at three in the morning' for six months.”

Rendered: ghosted means unanswered

The Risk Graph Explorer makes this visible rather than argued, using a three-colour convention across every view it draws:

amber — exposure green — assurance ghosted — unanswered

Ghosting-for-unanswered is this concept rendered. Nothing else in the estate makes an absence visible on the picture — and once it is visible, an executive looking at a graph that is half ghosted has learned something no summary would have told them. The vault is live and browsable with no account and no network access: permissions: {}. Open it →

Absence as the widest confidence band

Confidence is a first-class property of every node, and it is a band rather than a point — widest where the data is thin. “We don't know” is simply the widest band there is, which is what connects this page to the evidence economy: a band too wide for comfort is the trigger that converts unease into a purchase order for better evidence. A band spanning trivial to catastrophic cannot be accepted responsibly by anyone, at any interval. Confidence bands →

Provenance

Concept
C17 — Not knowing is a fact (absence of evidence as first-class)
Source
team/humans/dinis_cruz/briefs/06/26/risk-register-and-five-whys/v0.33.35__arch-brief__…facts-only-no-deny-cascade-cia-blast-radius.md
Repository
SGraph-AI__App__Send @ v0.33.35, never published — the version tag is the address
First written
26 June 2026; questions as nodes, 2 August 2026
Maturity
well-developed — and demonstrated as fact F7 in the Article 26(5) example
Licence
CC BY 4.0 at source and here

For an agent

C17 — not knowing is a fact. Absence of evidence is a first-class node, never a blank. Distinguish three states a spreadsheet collapses into one empty cell: (a) somebody looked and found nothing — that is a Measure returning zero, producing dated, attributable Evidence (“zero tested-restore records found”), and it is a strong result; (b) nobody has looked — that is a Fact marked unevidenced, which is countable, queryable and assignable; (c) somebody looked and did not record it — indistinguishable from (b), which is itself a finding. An unevidenced fact spawns its own risk: “the full extent of the impact has not been captured, which means the risk is not yet correctly classified or correctly accepted” — usually accepted at the one-hour rung, which exists for exactly this. A Question is its own node type, and unanswered questions are the most productive output of the exercise (in the Article 26(5) graph, five unanswered of nine: “those five are the actual output”). Rendered convention: amber = exposure, green = assurance, ghosted = unanswered. Not implemented in code, though the ghosting convention runs live in the Risk Graph Explorer vault.