Post-change verification
After every successful write through SZ-MCP, the zone, WLAN, AP group, AP,
switch group or switch it touched is watched for 15 minutes and judged. This
covers a call, an undo and a MOP step. If something got worse, the verdict is
degraded and Claude suggests the undo. Nothing is ever undone
automatically, and the check makes no controller calls.
What is watched after a change?
Section titled “What is watched after a change?”The object the write’s path names, if the inventory knows it.
| The write’s path names | Watched |
|---|---|
A WLAN (/rkszones/{zone}/wlans/{id}) | The WLAN’s zone |
| An AP group in a zone | The AP group |
| A zone | The zone |
| A switch group | The switch group |
| An AP’s or switch’s MAC address, anywhere in the path | That AP or switch |
A write whose path names nothing in the inventory is not verified. Writes close together on the same scope share one watch: a write within 10 minutes of a watch starting joins it and extends it, so a MOP run is usually a single watch.
Which signals count as worse?
Section titled “Which signals count as worse?”Fewer clients, a lost AP or switch, lost ports, or a new alert problem. Each signal compares its average over the 15 minutes before the change with its average from 3 minutes after the change to the end of the watch. The first 3 minutes are skipped while devices rejoin and clients reassociate.
| Signal | Counted as worse when |
|---|---|
| Clients | They fall by 40% or more, from at least 5 |
| APs online | Any AP is lost |
| Switches online | Any switch is lost |
| Ports up | 2 or more ports are lost |
| Alert problems | A new HARD problem appears in scope that was not there before |
Where a weekly baseline exists, a finding also says what is usual for that time, so you can tell a change’s effect from a quiet hour.
What do the verdicts mean?
Section titled “What do the verdicts mean?”| Verdict | Meaning |
|---|---|
watching | The 15 minutes are not over yet |
ok | Something was measured, and nothing got worse |
degraded | A signal fell or a new problem appeared. Claude shows the summary and suggests history.undo per write, newest first, or mop.rollback for a MOP run |
no_data | Nothing could be measured |
degraded means something got worse after the change, not that the change
caused it. Claude is told never to undo on its own: you decide.
How do I check a change’s verdict?
Section titled “How do I check a change’s verdict?”Ask Claude. A write’s result carries verification: { watching, dueAt, see },
and these functions read verdicts later. Every role can use them:
| Function | Default | What it returns |
|---|---|---|
history.verification({ writeId }) or ({ id }) | — | One watch: its status, scope, findings, new problems and suggestion |
history.verifications({ status, entity, sinceMinutes, limit }) | Last 24 hours, 50 results | Watches newest first. entity also finds a watch on what holds the entity, so an AP finds a change to its zone |
mop.status({ runId }) | — | The run’s worst verdict over all its writes |
Verifications are kept 30 days. A change and its verdict also appear in alert notifications, the alert context pack and post-mortems.
Why was my write not verified?
Section titled “Why was my write not verified?”| Reason | What you see |
|---|---|
| The write failed, named nothing in the inventory, or is over 30 days old | ”Write N has no verification: it failed, named nothing in the inventory, or is older than 30 days.” |
| 50 changes were already being watched | ”50 changes are already being watched; this one is not verified.” |
| Metric polling is off | The watch ends no_data: “No metrics reported for the watched entities before and after the change (is polling or the stream on?).” |