Part XIX — Practicums and the Capstone
Chapter 112. QC and Incident Practicum: Finding the Problem Is Only the Beginning#
In this chapter
The QC role turns observation into evidence, severity, root cause, routing and regression. The incident lead stops the spread after an error escapes, restores service and repairs the system's controls. The practicum uses an E004 release candidate with 18 deliberately planted problems.
112.1 The boundary and five-layer blind checking#
The boundary.
QC can block a release, create issues, demand evidence and verify closure. It cannot overreach into changing the story or approving rights exceptions. The incident lead coordinates technical, creative, legal and operations, preserves a factual timeline, and does not start by looking for someone to blame.
Inputs are the release candidate, contracts, state, rights and specifications. Outputs are findings, issues, regressions, a release decision and an incident report.
Five-layer blind checking.
The story layer has a character knowing a secret too early. The continuity layer has a mirrored watch on the left wrist and a wrong folder holder. The audiovisual layer has lip sync, music masking dialogue and a bad subtitle break. The technical layer has loudness, black frames and a wrong frame rate. The rights layer has an expired music cue and an unapproved font.
The QC lead checks independently first and only then reads the automated report, so the tools do not decide where their attention goes.
How to write an issue.
Each contains a timecode, the observation, the expectation, the evidence, severity, responsibility layer, a suggested route and the regression scope. "It doesn't feel premium" does not qualify. Several shots sharing one identity root cause are aggregated.
Blocker status is determined by fact, rights, safety and conspicuous identity errors — not by how hard something is to fix.
112.2 Root cause routing, regression sets, and release decisions#
Routing to root cause.
A wrong amount in a subtitle goes first to the fact registry and the graphic source, not to editing a character in the finished file. A wrong holder goes to state, take acceptance and edit selection. Expired music goes to rights dependencies and the release gate.
Fix at the earliest wrong layer, so a local patch does not leave the other derivatives broken.
Regression sets.
Fixing a subtitle means checking every language and every creative asset. Replacing a take means checking action interfaces, music, lip sync, duration and graphics. Replacing music means checking cues, the mix, rights and all platform packages. The QC lead generates a minimum sufficient regression from the dependency graph.
Reviewing only the changed point, or indiscriminately re-reviewing the whole episode, are both unsophisticated strategies.
Release decisions.
Blockers must be zero. Majors are fixed or waived by someone with the authority, while rights and key facts can never be waived. A release candidate is immutable, so any fix produces a new one.
The QC lead submits an approval, a rejection or a conditional decision, citing the evidence.
112.3 An injected incident, the retrospective, and acceptance#
Injecting the incident.
After "release," the facilitator reports that the old subtitle version was uploaded to the test platform. The QC lead stops distribution, preserves the platform receipt, confirms the impact, switches back to the correct version, notifies the responsible parties and builds a timeline. Deleting evidence first is prohibited.
Then they investigate why the manifest check did not catch it — rather than simply blaming whoever uploaded.
The retrospective.
The report separates facts, impact, detection, response, recovery, root cause, escape controls and improvements. Every improvement has an owner, a deadline, a test and a rollback. "Improve communication" is not an effective improvement.
The retrospective asks why an interface permitted the error; it does not shame an individual in public.
Acceptance and deliverables.
Detection coverage 20 percent; issue evidence 15 percent; severity 10 percent; root cause and routing 15 percent; regression 15 percent; release decision 10 percent; incident response 15 percent. Missing a rights blocker fails the whole deliverable outright.
- Automated and human results are stored independently.
- Every problem has observable evidence.
- Fixes return to the earliest responsible layer.
- Changing a release candidate produces a new version.
- Incident improvements carry regression tests.
Deliverables: qc_findings.jsonl, issues.csv, regression_sets.yaml, release_decision.json,
incident_timeline.csv, postmortem.md and remediation_tests/.
112.4 The incident timeline, communication, and the retrospective#
A simulated incident timeline.
10:02 published to the test platform. 10:11 operations notices the subtitle amount reads 430 million instead of 480 million. 10:13 traffic stopped. 10:16 platform receipt and the bad file preserved. 10:20 confirmed that only the English burned-in version is affected. 10:27 rolled back to the previous release candidate. 10:41 the correct version passes preview. 11:05 restored at low volume.
The QC lead's first instinct is to replace the remote file directly, and the facilitator requires the evidence to be frozen first. The root cause is not a translator's typo: the English graphic export bypassed the fact registry, and the release check only compared filenames rather than running OCR against the manifest. The fix binds graphic fields to facts in every language, adds OCR before release, verifies the remote hash, and adds this error to the regression set.
A separate identity drift on the small mole was missed by the automated evaluator and caught by a human. The QC lead does not immediately lower the threshold; they check and find the evaluator returned a pass at low confidence under backlight. The protocol changes so low confidence goes to review, and the evaluator shadow-runs for a week before it is allowed to block again.
Incident communication.
Tell the client the known facts, the scope of impact, the current safe state, when the next update will come and what interim measures are in place — without speculating about fault. Internal technical detail and external notification are layered, but the fact that a wrong version was briefly visible is not concealed.
The facilitator's note: QC's value is not measured by the number of findings, but by the escape rate of critical errors, routing accuracy and closure evidence. Incident response is valued by stopping the spread while protecting the facts of the investigation.
The live retrospective.
The facilitator shows five issues and asks the QC lead to re-judge severity. They include a visually obvious background flaw that does not affect the story, a tiny piece of text that changes a contract amount, a drifting mole, expired music and an 80-millisecond lip sync offset. The QC lead must explain by audience, commercial, rights and release consequence — not sort by ease of repair.
The second question presents twelve findings from one root cause and asks for aggregation, the earliest fix layer and a regression design. The third simulates a client demanding release with a blocker open, and the QC lead should state their own authority, the available routes and the items that can never be waived — rather than letting it through because the client insisted.
The incident retrospective requires stating facts and assumptions separately under uncertainty, choosing the scope of the stop, preserving evidence, and then recovering. The facilitator supplies misleading clues, and the QC lead must not write an early guess into the report as the root cause. The final evidence includes detection time, response time, remote state, who was affected, the fix commit, the regression and the notifications. An issue without closure evidence is still open.
A reviewer reopens one closed issue at random and re-runs its regression from the original evidence. If the closure depended on a reviewer's memory, an unavailable temporary file, or someone saying it looked fine, it does not count as fixed.
The re-check is written into that issue's closure history with the person, the time, the input versions and evidence checksums — not into a separate report detached from the problem.
A note on sources#
This is a rehearsal design rather than any studio's QC manual. What transfers is checking blind before reading the tools, writing findings as observable evidence, fixing at the earliest responsible layer, and treating an incident as a control failure rather than a personal one.