Skip to content
SZ-MCP
Get Support

Post-change verification

After every successful write through SZ-MCP, the zone, WLAN, AP group, AP, switch group or switch it touched is watched for 15 minutes and judged. This covers a call, an undo and a MOP step. If something got worse, the verdict is degraded and Claude suggests the undo. Nothing is ever undone automatically, and the check makes no controller calls.

The object the write’s path names, if the inventory knows it.

The write’s path namesWatched
A WLAN (/rkszones/{zone}/wlans/{id})The WLAN’s zone
An AP group in a zoneThe AP group
A zoneThe zone
A switch groupThe switch group
An AP’s or switch’s MAC address, anywhere in the pathThat AP or switch

A write whose path names nothing in the inventory is not verified. Writes close together on the same scope share one watch: a write within 10 minutes of a watch starting joins it and extends it, so a MOP run is usually a single watch.

Fewer clients, a lost AP or switch, lost ports, or a new alert problem. Each signal compares its average over the 15 minutes before the change with its average from 3 minutes after the change to the end of the watch. The first 3 minutes are skipped while devices rejoin and clients reassociate.

SignalCounted as worse when
ClientsThey fall by 40% or more, from at least 5
APs onlineAny AP is lost
Switches onlineAny switch is lost
Ports up2 or more ports are lost
Alert problemsA new HARD problem appears in scope that was not there before

Where a weekly baseline exists, a finding also says what is usual for that time, so you can tell a change’s effect from a quiet hour.

VerdictMeaning
watchingThe 15 minutes are not over yet
okSomething was measured, and nothing got worse
degradedA signal fell or a new problem appeared. Claude shows the summary and suggests history.undo per write, newest first, or mop.rollback for a MOP run
no_dataNothing could be measured

degraded means something got worse after the change, not that the change caused it. Claude is told never to undo on its own: you decide.

Ask Claude. A write’s result carries verification: { watching, dueAt, see }, and these functions read verdicts later. Every role can use them:

FunctionDefaultWhat it returns
history.verification({ writeId }) or ({ id })—One watch: its status, scope, findings, new problems and suggestion
history.verifications({ status, entity, sinceMinutes, limit })Last 24 hours, 50 resultsWatches newest first. entity also finds a watch on what holds the entity, so an AP finds a change to its zone
mop.status({ runId })—The run’s worst verdict over all its writes

Verifications are kept 30 days. A change and its verdict also appear in alert notifications, the alert context pack and post-mortems.

ReasonWhat you see
The write failed, named nothing in the inventory, or is over 30 days old”Write N has no verification: it failed, named nothing in the inventory, or is older than 30 days.”
50 changes were already being watched”50 changes are already being watched; this one is not verified.”
Metric polling is offThe watch ends no_data: “No metrics reported for the watched entities before and after the change (is polling or the stream on?).”