Chapter Twenty rewrote the New Shore Program from a single all-or-nothing vote into a string of experiments that could afford to be wrong. But however honest the experiments, they must eventually settle back into choices: one channel scheme is adopted, one scheduling arrangement is generalized. A question invisible before the vote thereby moves to the foreground — the alternative paths that lost in the experiments: where are they now, in what state do they exist, and who pays for them? Chapter Nine criticized how alternative paths contract under the name of efficiency; this chapter treats the other half of the matter: once the contraction has happened or is about to happen, what does retention mean, what retention can be afforded, and at which scale. This question cannot be answered with "the more retained, the better." Retaining alternative paths occupies capacity, hands, knowledge, and maintenance, and each of these occupations has concrete bearers; under destabilized conditions, the occupation of resources is itself transferred from elsewhere. The direction this chapter argues is therefore this: alternative paths are not retained everywhere at every scale, but configured in tiers according to two variables — failure correlation and recovery time. Some alternatives must remain alive at the local scale, some need only be callable at the regional scale, some need only preserve the knowledge and capability to rebuild; the criterion has never been the number of paths, but the independence of failure modes and the coverage of recovery time.
The Retention Value of Unchosen Paths
Low-loss experiments purchase information, and part of that information is which path is better. But if the ledger has no column for the destination of rejected paths, the experiment is only half complete: it improves the choice while defaulting on the disposal. And the default option for disposal has never been neutral mothballing but atrophy — investment stops, drills stop, the proficient drift away, entrances fall into disuse. The disposal of rejected paths needs to be written on the same page as the choice itself: retirement, mothballing, reduced-frequency maintenance, or transfer to other uses — what each means, and who is affected.
That a path lost in one round of experiments is a statement about its relative performance under the conditions tested, not a death sentence. Chapter Twenty showed that results cannot be extrapolated away from their conditions; the same principle holds in reverse — when conditions move, the rejected may again become optimal. Changes in conditions may increase the value of retaining certain alternatives, or may render old and new paths useless together. Whether retention is possible still requires comparing maintenance costs, the possibility of future applicability, and other uses; one cannot infer, from "the environment is destabilized" alone, that the more backups the better.
Chapter Nine stood at the contraction end, analyzing how multiple paths share conditions and fall together; this chapter stands at the recovery end, asking what to retain and where, once contraction has been judged excessive, or when excess needs to be prevented. The recovery end has its own economics: retention is not free, and every item of retention competes with other uses for the same resources. The question is thereby rewritten from "whether to retain alternatives" to "at which scale, in what form, and paid for by whom to retain" — a rewriting that runs through the whole chapter.
The Two Determining Variables of Alternative Paths
The table below separates failure conditions from tolerable waiting time. It is this chapter's comparative framework, not a configuration standard for port engineering; actual capacity and switching times require separate measurement.
| Condition when the primary path fails | Backup state | Gaps still to verify |
|---|---|---|
| Shared power supply, personnel, or authorization | However many path names there are, they may still be unavailable simultaneously | Whether the support conditions actually differ |
| The function can barely tolerate waiting | A runnable alternative already exists locally | Who maintains it, how much load it can absorb |
| Some switching time can be tolerated | Regional mutual backup, resources callable | Transport, authorization, and common-failure capacity |
| Rebuilding can be awaited | Knowledge, skills, and rebuilding conditions retained | Whether rebuilding from the documentation is actually possible, and who covers the waiting interval |
The four rows are not a four-grade score. Each critical function should be judged separately, and may require more than one arrangement.
Chapter Nine's core finding was this: dispersed ownership, dispersed maps, and diverse information do not automatically constitute alternatives; what matters is common dependency and common failure. This directly yields the first variable of retention configuration: if two paths are unavailable together under some failure condition, the second cannot respond to that interruption; it may still share the load in other situations. Common dependencies, failure conditions, and available capacity should therefore be identified item by item; neither the number of paths nor the so-called "number of independent failure modes" can be taken directly as a total score for reliability.
The second variable is recovery time: after a function is interrupted, within how long must it be restored. If the tolerable interruption time suffices to cover procurement, manufacturing, training, and rebuilding, retaining a rebuilding capability may be one option; if it does not, then a takeover arrangement that becomes available faster is needed. There is no universal threshold of "documents only if measured in days, presence required if measured in hours"; the actual arrangement also depends on capacity, transport, authorization, and risk. Recovery time is determined not by the path itself but by the function — the verification, care, error-correction entry points, and basic supply of Chapter Nineteen fall precisely at the end where recovery time is least compressible, a fact treated separately later.
The two variables combine into a configuration principle: alternatives are tiered by failure correlation and recovery time, rather than retaining everything everywhere. Replicating all facilities at every location would occupy enormous resources and still might not evade common failure. If maintenance responsibility is devolved without funding and authority being provided at the same time, the tiers with thin resources may be unable to sustain the burden. Tiered configuration acknowledges that the form, cost structure, and bearers of retention differ across the three scales; the following three sections take them up in turn.
Local, Regional, and Global Alternatives
Alternatives at the local scale must exist in use. Chapter Eight showed that backup roles need time and authorization to remain available, and that different backups have different maintenance regimes. Some facilities need to be run periodically; some materials suit mothballing, inspection, and rotation; personnel backups need skills and authorization. Not all backups can be required to carry daily traffic; the mode of preservation, activation time, and capacity should be verified against failure conditions.
The minimum usage has costs, and the bearers of those costs must enter the ledger tradition running since Chapter Eighteen: who pays for this low-traffic channel, who takes the extra shifts in the rotation, whose territory is occupied by low-frequency use. The occupation entailed in maintaining alternatives often falls on small bearers, while the benefit appears only on the day of failure. This time lag is political: the daily costs are visible, the backup benefits invisible, so cutting backups always looks like cleaning up waste — precisely the soil in which the hollowing-out mechanism of the next section thrives.
The minimum usage must also withstand the test of everyday scheduling. Alternatives compete with the primary path not for the same column of the budget table but for the same hands, the same stretch of berth, the same share of attention: when peak season arrives, is the substitute channel yielded to the main line's overtime vessels; when hands run short, is the substitute shift the first to be borrowed away. Each yielding to "the immediate first" is individually reasonable; cumulatively it is a chronic concession of the alternative. The record of these yieldings must therefore enter the ledger — not to forbid yielding, but so that how much was yielded, who decided, and when it was returned remain auditable.
Alternative paths are not only facilities but also the people who know how to make them run. Knowledge at the local scale attaches to concrete carriers: the craftsman familiar with the old technique, the veteran who knows the temper of the valves, the duty chief who can take over dispatch during a blackout. Retaining alternatives on these carriers means retaining people. This cannot be reduced to "redundant hands" — Chapter Eight already distinguished role redundancy from treating people as parts; what must be added here is the sequence: knowledge-type alternatives corrode before facility-type ones; the equipment is still there, those who can repair it leave first, and by the time the facility needs an overhaul, the two have already failed together.
Small systems cannot afford complete self-replication; Chapter Eight pointed out that transparent fragility is also a form of protection, and here is its positive use: a small community's alternative strategy is not to back up a copy of itself, but to know where its single points are, to disclose them, and to connect them to the channels of regional mutual aid. Making fragility public is not shameful bookkeeping but a way of letting the next scale up know where to catch the fall; the small system that feigns self-sufficiency is precisely the one least rescuable at failure, because no one knew in advance what needed rescuing.
The Regional Scale: Mutual Backup Rather Than Replication
The rational form at the regional scale is mutual backup rather than replication at every site: several localities each retain available margin on a different facet, agreeing to serve as one another's alternatives upon failure. The reality of mutual backup depends on the structure of conditions — whether the parties' margins genuinely complement one another, or whether, as in Chapter Nine, they share the same transport line, the same supplier, the same weather; whether the rules of invocation are written down in advance, or left to the goodwill of the moment of failure. Mutual aid decided by goodwill when the moment arrives will be crushed by each party's own failure pressure.
Regional alternatives have switching lag: people must move, materials must be transported, authority must be handed over. The lag determines that regional backup is effective only for functions whose recovery time tolerates lag, which brings the recovery-time variable on stage once more. Capacity likewise needs calibration: mutual backup configured for "only one party fails" may not cover common failure; whether it suffices depends on actual demand, capacity, and other support. Chapter Nine's common-failure analysis is transcribed at the regional scale into a question of capacity — the moment mutual backup is most needed is precisely the moment when everyone is too busy saving itself — so mutual-backup capacity must be calibrated against common-failure scenarios, not against the average of isolated failures.
Mutual backup is itself a path, with its own modes of failure: agreements wear down over the years, members who have long given unilaterally withdraw, a dominant member reshapes the mutual-aid network into its own dependency structure. To what extent the mutual-backup accounts must balance, who may withdraw when they do not, how far in advance withdrawal must be declared — these rules are not execution details but preconditions for whether mutual backup can be honored under destabilization. A mutual-backup agreement that has never been exercised jointly has exactly the same epistemic standing as an experimental promise that has never been rolled back.
The Global Scale: Capability and Knowledge Rather Than Facilities
The form of retention at the global scale is not keeping a facility copy of every path somewhere in inventory — that is neither possible nor necessary. What the global scale retains is the capability to rebuild: knowing how to reconstruct a path that has been abandoned, including technique, drawings, training methods, and organizational experience. A rebuilding capability occupies resources of knowledge and teaching, not parallel facilities. Compared with maintaining parallel facilities, this may reduce the occupation of equipment, yet it still requires continuously preserving skills, validating documentation, and maintaining supply conditions. Its cost and rebuilding time cannot be determined by the label "global" alone; only when the verified rebuilding time is shorter than the tolerable interruption time is it fit to bear the corresponding backup duty.
The carriers of a rebuilding capability are documents, curricula, teachers, and periodic small-scale rebuilds. Its corrosion is the most hidden: the documents remain but no one can act on them; the courses remain but teach long-failed versions; the drills remain but perform theatrical success — Chapter Eight said that tests must produce corrections rather than performances, and the variant here is: an actual rebuild is an important test, while document review, component testing, and simulation can also furnish evidence of differing scope. It must be stated to which layer the verification extends; partial results cannot be taken as proof that full rebuilding has been established. A rebuilding capability with no record of rebuilding must have the strength of its claim discounted accordingly.
The greatest temptation at the global scale is standardization: unification may lower some coordination costs, and may also reduce the diversity of implementations; whether it weakens alternatives depends on whether the paths thereby acquire more common dependencies. This must be conceded up front — standardization and economies of scale have real returns, not illusions; a critique of standardization cannot slide into a romantic opposition to all standards. The correct location of the tension is in failure modes: the real cost of standardization is rising failure correlation — when everyone uses the same standard, everyone shares the same error. Retaining, at critical points, the right to deviate from the standard is therefore more precise than opposing standards in general; the right of deviation equally requires justification and is not a license for caprice.
There is a further corollary at the global scale that must be faced directly: if the rebuilding capability is monopolized by a single institution, retention degenerates into a bargaining chip. The party who holds "how to rebuild" in fact holds the entrance to everyone else's survival on the day of failure; it can exert influence through the priority order of rebuilding and draw the line between insiders and outsiders through the range within which knowledge is dispensed — this requires no conspiracy, only the fact of monopoly itself. The countermeasure is isomorphic to Chapter Nineteen's treatment of alternative bearers: the teaching, copies, and rebuilding-drill entry points of rebuilding knowledge must not be held by a single bearer; the publicness of the knowledge itself must be configured in verifiable form.
Scale Linkage and the Alienation of Retention
Tiering is not three boxes drawn on a diagram; it runs in practice on channels, reports, joint meetings, and joint drills, all of which have costs. Part of the benefit of linkage work appears as interruptions avoided and is hard to attribute separately; invocation times, error rates, and drill results can still furnish material. Under tight budgets this work may be cut, or may receive priority protection on account of higher risk. Judging the consequences of cuts requires retaining the grounds of the decision and its subsequent changes; it cannot be presupposed that all costs appear only at failure. The linkage budget should therefore be treated as part of the retention configuration, not as administrative expenditure that can be sacrificed at any time.
When a local failure escalates into a regional event depends on the linkage channels: whether the local level reports faithfully, whether the region has the authority and capacity to take over. The incentive to conceal failure is always present — admitting single-point failure happens politically before it happens in fact. If escalation conditions are not written down in advance, the region's backup is detained by the local level's face; what is written down should include which observations trigger reporting, to whom the report goes, and who bears the consequences of concealment.
Calling backup down from the next scale up is not a logistics event but a power event: who decides the invocation, for whom it is invoked, who commands during it. Chapter Nine's single point of decision authority here reappears between scales — every tier may quietly rewrite "invocable" into "at my discretion". The rules, ceilings, and time limits of invocation must be written down in ordinary times; this is isomorphic to Chapter Eight's requirement that backup authority carry its own end condition: an invocation coming in must have a term, and command must be returned as the situation subsides.
For tiered configuration to work, the precondition is that knowledge of failure correlation and knowledge of recovery time flow between the tiers. If the upper tier does not grasp the lower tier's true single points, and the lower tier does not know the scope of the upper tier's safety net, tiering degenerates into each tier talking to itself. The information channel is itself a path requiring maintenance; its characteristic form of failure is usually not interruption but each tier holding an outdated map, each assuming some other tier has already covered a gap — the gap lives on untroubled in the crevice between two tiers.
How Retention in the Name of Redundancy Becomes Protection
Alternative paths may also invoke the name of redundancy to escape being tested. To distinguish necessary retention from the protection of entrenched positions, we must return to this chapter's two questions: which failure is it aimed at, and how much usable capability can it deliver within how long?
The mechanism is not complicated: inefficient paths, institutions, and supply lines that should have exited under performance review persist instead under the names of "strategic reserve" and "security guarantee". The criterion is here smuggled away — one no longer asks "is it failure-independent of the current path and reachable within the required recovery time", but only "does it exist". Existence itself becomes the reason for exemption from all testing. This is fully isomorphic to the justifying function of criticality claims in Chapter Nineteen: a survival category is used as a pass exempting its holder from review.
The beneficiaries are the path's current bearers: posts, contracts, and positions prolonged by the two words "backup". The cost bearers are of two layers: the budgets and consumers paying for the maintenance, and the genuine backups that get squeezed out — resources occupied by false backups, while alternatives genuinely independent in failure go unmaintained. Identifying this requires no accusation of motive; the bearers can entirely sincerely believe themselves to be backups. The evidentiary threshold is structural: backup records, the argument for failure independence, periodic verification under conditions of use — Chapter Eight's review checklist, Chapter Nine's verification requirements, and Chapter Nineteen's falsifiable tests apply here in combination.
This corollary has a boundary; not every retention of an inefficient path is protectionism. The shape of the counterexample is clear: an old line that is indeed outdated but failure-independent once caught the whole when the dominant line failed through a common mode — in retrospect, its "inefficiency" was precisely its value. The boundary is therefore drawn here: the criterion is failure correlation and recovery time, not the ranking by efficiency. Cutting every failure-independent alternative in the name of efficiency and retaining every inefficient path in the name of backup are the two halves of the same error: neither looks at failure correlation, only at whichever single indicator it prefers.
It follows that a retirement mechanism is a necessary component of any regime of retention: an alternative path must be capable of being judged no longer needed and retired with dignity. Chapter Eight said that maintenance must be able to accept the conclusion "no longer needed"; here the procedural half is added — the judge of retirement must not be a beneficiary of the alternative, and the retirement decision must be appealable and must leave a record. Without review and retirement mechanisms, backups that no longer apply become harder to exit; appeal and record-keeping do not automatically guarantee correct judgment either — the applicable failure conditions, capacity, and cost basis must also be made public.
Nominal Retention and Effective Failure
The chapter's second stern corollary is quieter: alternative paths retained in name while hollowed out in fact. The list of forms is not long: the backup facilities are there, the maintenance budget shrinks year by year; the backup staffing is there, vacancies go unfilled for years; the backup authority is on paper, the activation procedure must complete approvals that could never be completed on the day of failure; the backup documents are there, their content long out of step with the live version. Each item, taken alone, is a reasonable economy; taken together, they amount to an alternative system that exists only in documents.
The mechanism of hollowing-out is isomorphic to the deniability of supply cutoff in Chapter Nineteen: no one orders the backup abolished; training is simply canceled, drills downgraded to tabletop exercises, the budget temporarily diverted, and once the proficient retire, their posts are optimized away. Such gradual changes sometimes correspond to no unified abolition decision at all, which makes the tracing of responsibility harder. The countermeasure is likewise bookkeeping: every substantive downgrade of backup status — capacity, hands, drill frequency, validity of authorization — should have an auditable decision-maker, rationale, and conditions for restoration, so that the decline in capacity and its causes are easier to discover and to question.
The most ironic degradation is when the record of nominal retention blocks genuine alternatives in return. The audit reads "alternative paths retained", and on that basis investment in new alternatives is refused — the record of the old existence becomes the reason for the new nonexistence. The test criterion returns to Chapter Nine: backups must be verified under conditions of use. A backup not verified under applicable conditions retains uncertainty as to its availability; this does not mean it has already failed. Verification can combine inspection, analysis, simulation, and controlled testing; the choice among them must weigh evidence strength together with the interruption the test may itself cause.
Credible retention requires a verification plan proportionate to the risk. A real switchover can provide important evidence, and can also endanger critical services in operation; it cannot be set up as a context-blind obligation. The Jiawan Harbor comparison framework requires recording what the verification covered, what it did not, who judges the residual risk, and who bears the cost of testing. When a real switchover is impossible, the alternative evidence and its limits should be stated, rather than ruling "never actually switched" directly as "already failed". Verification cycles and loading of actual facilities must be determined by applicable standards and professional assessment.
Testing Alternatives and Critical Functions
Chapter Twenty's epistemology here takes on its recovery-end meaning: every low-loss experiment, whether it succeeds or fails, is producing knowledge of alternative paths — how each path fails under which conditions, how long recovery takes, who takes over at switchover. The sequence of experiments is thus the main production line for alternative knowledge. Using experimental results only for selection wastes half their output: the behavioral data of failed paths are precisely the raw material for the recovery manual of some future day of failure, and should be preserved in the experimental records in retrievable form.
Alternative paths need to undergo real testing, allowing overruns, failures, and unknown dependencies to surface. Testing is likewise risky: boundaries, stop conditions, rollback resources, and responsibilities should be checked in advance, and who bears the losses should be stated. Limiting scale does not guarantee capping losses, and switching back to the original path does not necessarily undo consequences already incurred; when estimates are exceeded, expansion must still be halted, recorded, and remedied. This shares the same constraints as Chapter Twenty's bounded experiments.
Retention is not the preservation of specimens. Conditions move, dominant paths change, and so do the failure modes the alternatives must answer: an old backup technique may happen to share the very vulnerability of a new generation of dominant path. Alternative paths therefore need generational turnover — each generation must be re-argued against the current failure correlation and recovery time, not inherit the previous generation's position. "We have always kept it" is, within tiered configuration, not a reason but the name of inertia; navigating this generation with the previous generation's failure map differs little from having no map at all.
The Distribution of Alternatives for Critical Functions
The verification, care, error-correction entry points, and basic supply of Chapter Nineteen fall, by the recovery-time variable, naturally into the innermost tier of the retention configuration: their recovery time is the least compressible, and the alternatives must be present rather than rebuildable. But the four take different forms across the three scales — the alternatives for care and basic supply lie mainly at the local and regional scales, because their failure lands directly on bodies; independent channels of verification can be arranged across scales; and the error-correction entry — the function that lets everyone keep asking "is this really critical, who certifies it, and how is it corrected when wrong" — must be present at every scale, so that when something goes wrong at this tier there are still people able to raise and pursue the question; a blocked channel is one risk signal, but not the common origin of all failures.
Retaining alternatives for critical functions does not exempt those alternatives themselves from inspection. Chapter Nineteen said that retention does not mean exemption from review; alternative paths, as "retained goods", are precisely the most liable to persist for long periods with unexamined internal arrangements: in the alternative care arrangements, who is cared for and who is bypassed; whether the bearers on the alternative supply line are once again those who have borne the burden repeatedly throughout history. The ledger for backups shares the same structure as the ledger for the primary path: current costs and maintenance costs side by side, itemized by subject, cumulated over history, with revisions on record.
Convergence: Transitional Guardrails for Tiered Retention
This chapter's conclusion can be gathered into one sentence: the correct unit of account for retaining alternative paths is not the number of paths but the independence of failure modes and the coverage of recovery time — on this basis, keep live use at the local scale, mutual backup at the regional scale, and rebuilding at the global scale, with each of the three tiers paying its own costs, keeping its own records, and undergoing its own tests.
The transitional guardrails are therefore these: the disposal of rejected paths enters the ledger on the same page as the choice, with retirement having a judge, an appeal, and a record; the retention configuration is argued in tiers by failure correlation and recovery time, and the arguing documents disclose common dependencies and failure modes rather than merely listing items; local alternatives adopt modes of operation, mothballing, and maintenance proportionate to their objects, with the bearers of their costs visible in the ledger; regional mutual backup has its capacity calibrated against common-failure scenarios, its invocation rules and ceilings written down in ordinary times, and command returned as the situation subsides; the global rebuilding capability is verified tier by tier, with the scope covered by actual rebuilds stated; backups choose testing cycles, loading, and methods according to risk and object, with switchover losses allocated by rules — beneficiary, bearer, ceiling — kept on the same page; substantive downgrades of backup status enter the ledger with a record, so that hollowing-out cannot happen by way of not deciding; critical functions are arranged in tiers by the four categories, with the error-correction entry present at every scale.
Tiered retention does not promise that failure will not occur, nor that any switchover will succeed — backups will malfunction, mutual backup will prove insufficient, rebuilding will come too late. What it promises is isomorphic to Chapter Twenty's low losses: when the dominant path fails, whether an alternative is usable depends not on resolve at the moment of crisis, but on whether availability was redeemed beforehand under real load, and on whether failure correlation and recovery time were actually computed rather than waved away with the word "existence". The returns of standardization are real, and the right of deviation is retained only at critical points; the returns of efficiency are equally real, and retirement and retention obey the same criterion. The full meaning of retaining alternative paths is thereby not "keeping a few more roads", but ensuring that each time failure arrives, there still exists a path verified by use, redeemed by record, and consented to by its bearers — it may be narrow, it may be expensive, but it is there.