RedHub AIRedHub AI
Tool Gate · How it works

How the gate works

How the Validation-Failure Backstop gate works

This tool grades an escalation path's odds of failing closed instead of proceeding unanswered. It scores 6 weighted controls into a 0–100 number — then a gate that can only make the verdict worse.

The 6 weighted controls

01A named ownerwt 18
02Reachable inside the window the action needswt 18
03What happens when nobody answersgate - times out openwt 16
04The reviewer gets enough to decidewt 18
05Overrides are recordedwt 15
06Rejections teach somethingwt 15
FAILS CLOSED
score 75+
FAILS SOFT
score 45+
FAILS OPEN
below floor
Fail-open timeout gate · worsen-only

When nobody has defined what happens if the reviewer does not answer in time, the path is forced to FAILS OPEN regardless of its score on the other five controls - an escalation that proceeds unanswered is not a control, it is a delay with a due date.

84/100
FAILS OPEN

Why: This path (a refund over threshold) scores 84/100 across the six controls - that reads FAILS CLOSED. But its timeout behavior is undefined (mark 0): nobody decided what happens when the reviewer does not answer in time. The gate forces FAILS OPEN regardless of the score - an unanswered request that proceeds on its own is a delay, not a control. Two more paths in the same portfolio also read FAILS OPEN, so the portfolio verdict is NO BACKSTOP.

Fix firstDefine what happens when nobody answers on this path first - right now an unanswered approval just proceeds. A named owner and a logged override do not help if the timeout itself fails open.

A high score didn’t save it. The score is context; the gate is the answer — and it names the one thing to fix first. Grades the escalation paths you describe against six controls, offline. Not a security audit or a guarantee no request will fail open.