Three parts in, this series finally answers the question it opened with: not whether to explore, not how safely, but exactly when the case for building the fix stops being patience and starts being negligence. Reframe that decision as what it actually is, a bounded premium paid once for the right to survive an open-ended, heavy-tailed cost, and this series' already-locked numbers say something sharper than "eventually": at this series' base discount rate, every tail weight this series has priced already clears that threshold, though the lightest tail's margin turns out to depend on the discount rate in a way the heavier tails' margins do not.
A perpetual probe is a mathematical necessity that terrifies change management. This post builds the boundary a reviewer approves once, a discrete-time stochastic control barrier function, then does what this series always does to its apparatus: names the gap. Bounding the probability of an excursion says nothing about the blast radius. Under a heavy tail, a probability bound alone can certify a system as safe while its worst case runs four orders of magnitude past what a reviewer thought they signed off on.
Part 1 proved the cost of not exploring. The standard organizational response, scheduling a two-week canary test for the failure you already suspect, is just a second simulator built to agree with you, and under a heavy tail, bounded experiments systematically under-sample the cliff. Feldbaum's 1960 dual control theory supplies the actual fix: a control action engineered to regulate the system and keep testing its own estimates at the same time, permanently, with no scheduled point where it gets to stop, already running at internet scale inside TCP BBR since 2016.
An offline simulator validates cleanly against history, then a correlated-retry burst shatters production. You cannot log a regime that hasn't happened yet. This post proves the modeling tax is a structural trap, not a data-pipeline bug, and Lai and Robbins' 1985 regret floor prices exactly what that comfortable congruence costs: a bill that does not vanish just because you refuse to pay it.
Five posts have priced, over and over, what it costs to guess wrong about a distribution that won't hold still: borrowing five of the Constraint Sequence Framework's six named components along the way, without ever turning the sixth, Meta-Constraint Awareness, on the machinery doing the pricing. This post runs that test on its own series: a real, three-times-computed numerator with a fourth entry named but never priced, a denominator no post has ever measured, and a Return on Investment whose sign comes out genuinely undetermined, not favorably assumed. The formula's own algebra still yields a real bound on how cheap that machinery has to be, and formal metareasoning research, cited directly, explains why the missing stopping criterion isn't an oversight: it's the same unsolvable regress that research already proved exists and resolved by capping it, not computing it. Then it points the same unpriced test at the next post's own proposal (centralizing the machinery itself) before that proposal gets to claim an advantage nobody has costed either.
Post 3 cited a paper this series can't quietly set aside: threshold-based eviction, proven dynamically unstable under saturated demand, a worst-case limit cycle that costs up to half of throughput. This post takes on the population Blood Oath was built to exclude from that result (tasks that can actually be evicted) and asks the two questions Post 3 left open: is a single eviction worth its cost, and is running that rule as a policy, at scale, safe from the instability Post 3 only watched from the outside. It also checks a third: would a fleet-wide coordinator make a better call than the local rule this post proves optimal on its own terms: and the answer splits in two, one physical reason coordination can't help the ranking decision itself, and one real, unpriced reason it still might help pace evictions across nodes sharing the same fabric.
No algorithm can save a Blood Oath workload: Post 1 proved that formally. What's left is physical, not algorithmic: a redline that watches real headroom and its derivative instead of trusting a number, an honest accounting of when autoscaling actually helps, and a buffer sized by the same critical-fractile logic that opened the series. None of it adapts on its own; that only starts once MAPE-K's own most commonly skipped phase, Knowledge, actually closes the loop the other four were never built to close by themselves.
Detection is the easy part — acting without making things worse is harder. This article works through the MAPE-K autonomic loop adapted for edge conditions: stability conditions, confidence-gated action thresholds, dependency-ordered recovery to prevent cascades, and a self-throttling law that keeps the loop from consuming the very resources it's trying to protect.