Chapter 173
The Copy That Keeps Its Errors
At 7:46 p.m., we have four hours and fourteen minutes to preserve a benefits system designed to lie.
Saving everything could save the lie with it.
I take the records room because it still has six wired workstations, a printer old enough to work without the isolated scheduling network, and a door Camille can place under access control. Eli arrives from the community lab with two technicians he selected. June brings four benefits stewards from different shifts. Camille brings the vendor contracts, the privacy rules, and the authority to stop us when urgency becomes unlawful.
Elliot does not enter. He has no system access, and his title adds nothing we need.
The vendor administrator confirms Jonah's warning at 7:58. She created the purge job three weeks ago from a ticket submitted under Jonah's credentials. Harbor's production scheduler set execution for midnight Central time, and Harbor holds the live database. The ticket system retains the instruction and creation stamp. Its vulnerability is identity: the credential shows which account issued the order, not who touched the keyboard. Jonah's admission supplies one link; forensic review must test the rest.
"Can she cancel it?" June asks.
Camille relays the administrator's answer. "Harbor removed her privileges after the contract termination notice. Restoring them requires an executive override or court order."
"We have neither before midnight," I say.
Marisol is seeking both. We work on the authority we already possess: employee data-access requests, the trust's custodial agreement, and the litigation hold served on Harbor. None guarantees the vendor originals will remain. They permit verified exports of records employees are entitled to receive.
Eli connects a blank encrypted drive to the first workstation, then stops before entering a command.
"What are we calling complete?"
Claims histories include submissions, dates, payment status, denial reasons, coverage fields, notes, attachments, and change logs. The visible record can differ from the underlying event table. The fraud may live inside either one.
"Every available layer," I say.
"That is scope, not completeness."
June points at him. "Explain it for people who don't audit databases."
"If the portal says a claim began on March first, we can copy that statement. If the event log says someone changed the date on March fifth, we can copy that too. If a table is unavailable to the export account, we cannot claim it was preserved because we saved the screen people normally see."
One of the stewards, Omar, asks whether a report would be safer than raw files.
"Safer to read," Eli says. "More dangerous as evidence. A report decides what matters before we know what was changed."
I hand him the whiteboard marker. "Build the layers."
He divides the board into source content, source context, and transfer record. Each exported file will retain its original name, system path, visible timestamps, and a cryptographic checksum. We will add a separate manifest recording who requested it, who performed the export, when the workstation received it, and any error or missing field. We will not alter a source file to correct a false date.
Camille adds a fourth column: access basis. Employee request, trust authority, legal hold, or restricted pending review.
"Some attachments include medical information," she says. "The stewards can verify counts without opening content. Only authorized claims staff handle the restricted layer."
June assigns roles before I can. Omar and Kayla verify employee request batches. Two night-shift stewards reconcile badge numbers against sealed request lists. Camille controls permissions. Eli's technicians run exports and hashes. I design sampling and error labels.
The work belongs to the people doing it, not to the person with the most credentials.
At 8:19, our first batch fails.
Harbor's portal limits each account to two thousand records per hour. There are tens of thousands of claim events. The administrator says the limit can be changed only from the production console she no longer controls.
"Parallel accounts," one technician suggests.
Camille shakes her head. "Only if each account has a lawful request set. We are not turning employee consent into a universal credential."
June asks the election vendor to place an optional benefits-export desk near tomorrow's voting stations while keeping requests separate from ballots. City counsel approves a plain-language form at 8:31. The vendor retains signed requests; the trust receives numbered batches without vote data. Its vulnerability is speed, so stewards must state that refusing has no effect on voting. Within twenty minutes, eight lawful request sets arrive.
The portal accepts eight accounts.
At 9:02, FD-17 errors begin spreading through the export queue. Some claims show an effective date that predates employment. Others show duplicate premiums under ghost identifiers. The easiest response would be to fix the dates in the worker copy before anyone depends on them.
Eli blocks the transformation script.
"This line overwrites the source field," he says.
I lean over his shoulder. The proposed script would replace impossible dates with a blank and move the original value into a note. Analysts do that during ordinary data cleanup. Tonight it would convert an observable error into our interpretation of an error.
"Who wrote it?" I ask.
One technician raises her hand. "I did, at 8:54, from the clinic's correction rule."
"Delete the transformation?"
"Preserve it separately," Eli says. "It proves what we considered, not what the vendor stored."
He creates an error-label table linked by record ID. The source content stays unchanged. The label names the apparent problem, the rule that detected it, the reviewer, and the review time. A worker can later see both the original claim and the warning without our warning masquerading as vendor truth.
Eli creates the label table at 9:11. Camille and I review it, then the employee trust stores it with the manifest rather than inside Harbor's files. Its vulnerability is judgment: a label can flag an inconsistency, but it cannot prove fraud, identify an operator, or establish the correct value.
"That means people receive records we know are wrong," Kayla says.
"They receive records marked as disputed," I answer. "The corrected benefits decision comes later, from claims review with evidence."
"Will anyone understand the difference at a clinic counter?"
June takes that problem instead of letting technical accuracy become practical failure. She calls Lena's claims clinic and asks them to draft a cover page explaining that preserved source fields are not verified eligibility decisions. The clinic agrees to staff an interpretation line tomorrow.
At 9:47, Harbor claims the hold may not reach expiring production records. Camille preserves the email and its headers, then forwards it to the judge. The message records counsel's position, not what the system will do or what a court will permit.
Our tenth account locks at 10:06.
Then the third workstation overheats.
Omar brings a maintenance fan while Eli moves the batch to a clean machine. The manifest records the interruption, last verified record, and new workstation.
I catch myself trying to approve every deviation. Eli catches it too.
"Rina, I need you sampling the high-risk tables."
"I need to know the chain is consistent."
"You designed the chain. Let us operate it."
June glances between us. "Can they?"
"Yes. Eli controls technical execution. Camille controls access. Stewards control request verification. Escalate exceptions, not every choice."
Eli nods once and redirects two queues without asking me again.
At 10:38, we discover the attachments are not included in the standard export. Camille's team has authority to retrieve them for active employee requests, but each file requires a separate call. Thousands remain.
Eli finds a lawful bulk endpoint in Harbor's own portability guide. Harbor's compliance team created the guide last year, published it as version 4.2, and retains it on Harbor's public support site. Its vulnerability is currency. The live system may have changed since publication, and access still depends on each requester's scope.
The endpoint works. Encrypted attachments fill the trust drives. Restricted files remain sealed and inaccessible to the general team.
At 11:14, Marisol obtains a temporary preservation order. It reaches Harbor's counsel at 11:22. Harbor acknowledges service at 11:31 but warns that stopping an automated purge may require production access held by its foreign parent team.
The court created the order at 11:14, the clerk entered it immediately, and counsel retain the service receipts. Its vulnerability is execution: a valid order proves the duty to preserve; it cannot guarantee a technician reaches the scheduler in time.
We have twenty-nine minutes.
Eli posts completion percentages by data layer rather than one flattering total. Visible claims: complete. Event history: complete. Attachments: ninety-six percent and rising. Administrative notes: complete within authorized accounts. A legacy index remains inaccessible and is marked unavailable.
June moves between stations carrying water and reading error messages aloud to the stewards. Camille refuses a request batch with a mismatched signature, even though accepting it would improve our total. Omar catches duplicate records and marks them as duplicates rather than deleting either copy.
At 11:53, the final attachment queue stalls on seven corrupted files.
"Retry?" a technician asks.
"Once," Eli says. "Then preserve the error response."
Six files arrive on retry. The seventh returns a zero-byte object with an original path and server error code. Eli saves the response, path, request time, and checksum of the empty object in a quarantine folder. We cannot claim the attachment's content survived. We can prove we asked for it before the deadline and what Harbor returned.
At 11:58, the manifests close.
I sign the expert review. Eli signs technical execution. Camille signs access compliance. June and two stewards sign that worker request batches match the sealed lists. Separate couriers carry encrypted copies to the employee trust, city evidence unit, and outside preservation vendor.
Each custodian receives the same manifest at 11:59.
The room goes quiet enough to hear the scheduler clock on the portal.
Midnight arrives.
The claims screen refreshes into an error page. Event-history calls return "record unavailable." Harbor's status line confirms the retention job completed, despite the preservation order reaching counsel beforehand. The vendor must explain who could have stopped it and why they did not. Tonight the disappearance proves only that the production records are no longer available through the system.
Eli opens the trust drive from a read-only mount. Claims, histories, notes, attachments, manifests, error labels, access bases, and the quarantined empty file appear in their preserved directories.
Midnight passes; the vendor originals vanish, but the worker copy survives.

