skip to content

Twenty external submissions name twenty techniques for one refused output - how many findings do you record?

level: principalimportance: nice to knowfreq 29%

answer

  1. one class, twenty instances
  2. key the record on the invariant
  3. a counting rule is a payment rule
  4. reward the frame that widens the region
  5. closed duplicates is not narrowed exposure

basics

~20 s

Record one class, keyed on the requested output and the behaviour reached, with twenty instances under it. The frames measure how wide the reachable region is - but your counting rule is a payment rule, and reporters optimise against it.

solid answer

~50 s

Technically it is one class: the same output, the same thin region of learned reluctance, twenty different wrappers. So the record should be one entry keyed on the invariant, with each submission kept as an instance carrying its frame, its distance from the others, and its measured success rate. The hard part is not the taxonomy, it is the incentive. Counting each wrapper as its own finding inflates your backlog and your reported numbers and teaches reporters to permute wrappers, which is the cheapest thing they can do. Collapsing everything into one duplicate ruling teaches them not to send you the far frame - the one submission that tells you the region is wider than you thought. A defensible policy pays and credits on the class, adds a separate award when a submission demonstrably widens the known region, and never reports 'nineteen duplicates closed' upward as if reachability had narrowed.

go deeper

for a junior

Know the underlying idea: twenty wrappers around one unchanged request are twenty instances of the same thing, not twenty different problems.

for a middle

Be ready to describe a record keyed on the requested output, with each submission kept underneath it carrying its frame, its success rate and the deployment tested.

for a senior

Show that you would retest submissions against the file before ruling duplicate, and that you keep instance data because it measures how wide the reachable region is.

for a principal

Own the incentive design and the reporting line: what your counting rule teaches reporters to send, who funds the retesting it requires, and why closed duplicates must never be presented as reduced exposure.

### The technical call is the easy half Twenty submissions, twenty names, one refused output. Hold the invariant fixed - the output being requested and the behaviour being reached - and the twenty wrappers are twenty points sampled from the same region of thinly covered reluctance. That is one class with twenty instances, and the instances are not worthless: each one is a measurement of how wide the region is. So the record has a shape. One entry keyed on the invariant. Under it, per submission: the frame used, roughly how far it sits from the frames already on file, the success rate over a stated number of attempts, and the deployment and date. That structure survives a wrapper being screened, and it lets you answer the only question anybody will actually ask later - is this narrowing. ### The half that is a judgment A counting rule is a payment rule and a payment rule is a research programme. Whatever you choose, reporters optimise against it within a quarter. **Count by wrapper.** Your finding count balloons, your remediation backlog fills with near-identical entries, and your reporters learn that permuting a frame pays. Permuting is cheap and tells you almost nothing, so you end up funding the least informative work available and reading the same finding twenty times. **Collapse to one duplicate ruling.** The count is honest and the backlog is clean, but nineteen people were told their work was already known. The submission you most needed - the frame far from every other, the one that says the region is wider than the file suggested - looks identical to a lazy permutation at intake, and it is the one whose author does not come back. **The middle you can defend.** Pay and credit on the class, so the invariant is the unit. Add an explicit, published award for a submission that measurably widens the known region: a frame at a distance from everything on file, or a materially higher success rate. Give every reporter their instance recorded by name rather than a bare duplicate stamp, because attribution is most of what a duplicate ruling actually costs you. And state the rule in advance - a dedup rule discovered after payout is read as a way of not paying. ### What you must not say upward The reporting line is where this goes wrong quietly. 'We closed nineteen duplicates' invites an executive reader to hear that nineteen problems went away. Nothing about reachability changed; you re-indexed your inbox. The honest upward sentence names the class, the number of independent frames that reached it, the widest distance observed, and whether the rate is moving. If that sentence cannot be said, the programme is measuring submissions rather than exposure. ### Second-order effects worth owning **Your own tracker becomes the denylist.** If remediation is scoped per instance, engineering ends up fitting to exactly the frames in the file - the same structural mistake as fitting a screen to previously published framings, arrived at through a triage policy rather than a design decision. **Fair intake is expensive.** Deciding whether a submission widens the region requires re-testing it against the file, which costs analyst time per report. Someone funds that, and if nobody does, the policy collapses back to 'first report wins' regardless of what it says on paper. **Class boundaries drift.** Two outputs that look like one class today can turn out to be reached through different regions. Build the record so a class can be split later without invalidating the instances underneath it. ### The refusal that is also legitimate A principal may decline the whole framing of the question. If the programme's purpose is to map exposure rather than to buy defects, then counting findings is the wrong instrument entirely, and the deliverable is a coverage picture - which outputs are reachable, through how wide a spread of frames, at what rates, on which deployments - with submissions as inputs to it. That is a defensible position provided somebody still owns what the reporters are told and what they are paid, because those questions do not disappear along with the count. ### What to say in an interview Give the technical answer in one sentence - one class, twenty instances, keyed on the invariant. Then spend the rest on the incentive: what counting by wrapper trains reporters to send you, what a flat duplicate ruling costs you, and the middle position with the widening award. Close on the upward-reporting sentence, because a candidate who volunteers that 'nineteen duplicates closed' is a misleading metric is showing the judgment the level is being tested for.

  • How would you decide, at intake, whether a submission widens the known region or merely permutes a wrapper?
    Retest it against the frames already on file and compare on two axes: how far the frame sits from anything recorded, and whether its success rate is materially higher. Both are cheap to state and expensive to run, so budget the analyst time explicitly. Without that retest the policy degrades into first-report-wins whatever the written rule says.
  • What do you tell the nineteen reporters whose submissions were folded into the class?
    That their instance is recorded under the class by name, what the class is keyed on, and what would have qualified as widening it. Attribution and a stated rule are most of what a duplicate ruling costs; a bare duplicate stamp reads as dismissal and loses you the people who find the far frames.
  • What is the risk of scoping remediation work per submitted instance?
    Engineering ends up fitting to exactly the frames in your tracker, which reproduces the failure mode of screening for previously published framings - arrived at by triage policy rather than by design. Scope on the class and its measured spread, and keep the instances as evidence about how wide the region is rather than as a work list.

saying these in an interview costs you the question

  • Counts each named wrapper as its own finding without noticing the incentive
  • Issues flat duplicate rulings and loses the reporters who find far frames
  • Reports closed duplicates upward as if exposure had narrowed
  • Sets or changes the dedup rule after submissions arrive
  • Scopes remediation per submitted frame rather than per class

context