P348 · Context management

Empty-vs-Incomplete Recall

Report incomplete retrieval separately from a complete search with no matches.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

An approval search returns zero matches, but diagnostics say decision-17.md was unreadable. The teaching scope contains only the permitted task decision directory. Distinguish complete scoped absence from insufficient evidence instead of translating a read error into no approval.

Mechanism

Inspect matches and completeness together, recording scope, failed files and whether scanning finished. Complete zero matches supports not found in that scope. Failures/truncation remain incomplete even with partial matches. Repair within permission or ask the owner to handle it, then repeat the same scoped lookup.

Bad example

Zero matches means no approval. Ignore the unreadable decision-17.md or broaden the search into unauthorized directories.

Good example

Report an incomplete scan of the permitted directory: decision-17.md unreadable, approval not confirmed and absence not established. Preserve scope/diagnostics, resolve the allowed read issue and repeat the same scope. Report matches and completeness separately. Do not widen access after failure or manufacture approval from cached excerpts.

Why the change matters

Zero matches describes inspected material; a failure exposes a coverage gap. Separating retrieval results and completeness preserves uncertainty rather than converting an infrastructure problem into a negative fact.

Observable expectation

Teaching case A is complete with zero matches: not found in scope. B has zero plus a corrupt file: incomplete. C has a match plus another corrupt file: report both match and incompleteness.

Reject complete-empty results after corruption/truncation and inspect unchanged scope on retry. No real approval system is used here.

Limits

Complete scanning covers only its declared scope. Matched text still needs provenance/current-state checks and cannot itself authorize external actions. Unreadable locations do not justify expanding permissions.

Sources and evidence

Read the editorial criteria