← research
Verified retrospective28 March 2026Checked 11 October 20265 min read

RedBlue Had to Work When the AI Layer Did Not

A March build retrospective on recursive asset discovery, deterministic reporting, and why optional intelligence should never become a platform dependency.

RedBlueEASMResilience
A deterministic RedBlue workflow continuing while an optional AI route is unavailable
A deterministic RedBlue workflow continuing while an optional AI route is unavailable. Editorial illustration.

The first architecture test was not whether RedBlue could reason well. It was whether the platform still produced useful evidence when the reasoning service disappeared.

March was when RedBlue stopped looking like a collection of scanners and started behaving like a system. That transition exposed a design mistake I wanted to avoid early: making an optional AI service responsible for the basic truth of a scan.

Question

Could RedBlue discover related assets, preserve scanner output, and produce a readable report without ARBI or another model-assisted layer being available?

Method

I reconstructed the month from three dated commits. I inspected the change that added recursive asset discovery, the later fallback-report path, and the work that added stuck-scan detection alongside brand discovery. Their hashes and timestamps are preserved in a sanitised evidence record.

I evaluated the boundary between deterministic work and advisory work. Discovery, scope checks, scanner execution, evidence storage, and report assembly belong on the deterministic side. Prioritisation and narrative assistance can be useful, but failure there should be visible and recoverable.

Evidence

The recursive discovery change allowed a scan to retain relationships found through IPs, domains, CNAMEs, and certificate names. That made the asset graph more useful, but it also increased the need for scope control. A discovered name is evidence to review, not automatic permission to test it.

The fallback-report commit added report generation when ARBI was unavailable. That is a small feature with a large architectural consequence: the evidence path no longer depended on successful model output.

The brand-discovery work paired another source of candidate assets with stuck-scan detection. I read those together. Expanding discovery without monitoring execution health would make the platform look busy while work silently stalled.

Finding

RedBlue became more credible when AI stopped being the centre of the workflow. The durable sequence is simpler: collect authorised evidence, validate it, retain provenance, calculate deterministic state, then invite an advisory layer to help explain or prioritise it.

If the advisory layer fails, the result may be less polished, but it should not become less true. That remains one of my main design rules for the project.

Limitations

Commit history proves that these code paths were introduced. It does not prove production availability, complete scanner coverage, or the accuracy of every discovered relationship at that time. The repository is private, so readers can inspect the published commit metadata but not independently review the underlying diff.

Recursive discovery can also cross ownership boundaries quickly. Nothing in this retrospective turns a public DNS or certificate relationship into authorisation. Exact scope and explicit approval remain prerequisites for direct testing.