Guide · Evidence model
Evidence and attribution
Phigon does not treat every signal as proof. It keeps claims from different sources independent, then shows how much those sources can responsibly support.
The four states
Supported
The required coverage is present and available sources agree. The activity can be used as supported operational context.
Limited
Some useful evidence exists, but an expected source or coverage window is missing. The observation may still help, but it supports a narrower claim.
Conflicting
Independent sources disagree. Phigon keeps the conflict visible instead of choosing whichever source produces the neatest answer.
Missing
There is not enough evidence to attribute the activity. The correct result is unknown.
Coverage changes meaning
Imagine that an OS signal shows a process while the agent-native integration is unavailable. The OS record may support process presence, but it may not support a confident claim about the agent’s internal lifecycle.
The same event can therefore become less certain when coverage disappears—even if the remaining record has not changed.
Conflicts are useful information
A conflict can reveal stale clocks, PID reuse, delayed delivery, a broken integration, or an incorrect assumption in the model. Hiding it removes the clue an operator needs most.
Stable process identity
PIDs are reused. Phigon displays them because they are familiar, but uses a stable process key for process-lifetime identity.
Never join events solely because the PID matches.
Review checklist
- What source made the claim?
- Was that source healthy at the time?
- Was expected coverage present?
- Did another source agree or conflict?
- Does the record refer to the same stable process lifetime?
- Would the conclusion change if one source disappeared?
When evidence is insufficient, leave attribution unresolved.