
When a dispute never reaches the investigation queue
A dispute team can meet every deadline it measures and still miss a valid notice. The blind spot may sit before the investigation queue, where an intake rule decides whether a case exists for the people and dashboards downstream. A clean resolution metric says little about a notice that never entered its denominator.
Disclosure: This article was drafted using generative AI.
The design question I care about is where to put the boundary between receiving a notice and asking for more information. An extra form may help an investigator understand a dispute. Treating completion of that form as the condition for routing an already valid notice is a different decision. It can turn a request for detail into an exit from the process.
The missing route
In a synthetic workflow we built at Veriprajna, a consumer submits a valid billing-error notice through a message channel. The system asks for a secondary form. On one modeled route, the consumer does not complete it, a timeout closes the case as incomplete, and investigation never starts. The closure occurs on model day six. That timing matters because it shows the defect is not a late investigation. The notice has lost its route to one.
The model is an illustrative reconstruction inspired by the form-routing failure described in the CFPB's Apple order, not a customer case or a replica of Apple's actual system. Its checker explores the reachable states, including the branch where the form is missing. The ordinary baseline follows the anticipated route and reports a compliant result. Both outputs can be internally consistent: one answers whether the expected path completed its steps; the other asks whether any permitted path can strand a valid notice.

The trace is useful because it gives a reviewer a sequence to challenge: notice received, secondary form requested, timeout, closure. The reviewer can ask whether the first event really satisfies the relevant notice conditions, whether the timeout really permits closure, and which team would see the record after that. A red status without the path would make those questions harder to settle.
What should the form be allowed to control?
There are at least two plausible designs. The first makes the secondary form an intake gate: no completed form, no investigation. That may keep an investigation queue limited to records with a preferred set of fields. It also makes the queue a poor measure of all qualifying notices if people can provide a valid notice through another channel.
The second separates recognition of a potentially valid notice from collection of additional detail. A qualifying notice is routed into an investigation state; the team can still request the form, track missing information, and apply the actual rule for what follows. The cost is operational. Someone must own incomplete records, preserve the original receipt time, and decide how to handle genuinely insufficient notices. A state label alone cannot make those judgments.
My design preference is to make that boundary explicit. The intake system should record the notice and the basis for its classification before an optional information request can remove it from the investigation route. If the governing rule allows a different outcome for a particular kind of notice, model that condition and its evidence. Do not let a generic timeout silently decide it.
Our remediated synthetic model makes the narrower change: the missing-form route continues to investigation. Its four configured properties hold across the reachable states of that supplied model. That result supports the routing change within the model. It does not establish that the new workflow covers every applicable obligation or reflects a real operation.

The harder part comes after a green result
A checker can be exhaustive about its model and still be wrong about the world the model represents. If the real intake system has an unmodeled channel, a different timeout, or a handoff that can silently fail, a green verdict over the draft says nothing about that missing route. The relevant proof obligation for an operations team is therefore two-part: inspect what the model permits, then establish that its states and transitions correspond to the process people and systems actually follow.
The same discipline applies to clocks. This demonstration simplifies regulatory timing rules and uses a fixed calendar conversion for business days that omits holidays and exceptions. A result about its encoded deadline cannot stand in for an applicability decision or a legal opinion. For a real workflow, compliance specialists would need to determine which notice conditions and deadlines apply, while operators and engineers would need to reconcile the model with intake records, closure reasons, and system handoffs.
The most valuable output of the exercise is a question with a concrete route attached: can a notice that qualifies for investigation be closed because an additional form was not returned? If the answer depends on facts or a rule exception, those conditions belong in the workflow and in the review. If it does not, the routing boundary needs to change. That is a more useful decision than accepting a clean dashboard at face value.
And if you would rather see the route than read my description, here is the founder demo running end to end.
The full demo breakdown shows the modeled branch, counterexample, and remediated route. The judgment remains with the team that can verify the real notice, rule, and process behind them.


