A control is a piece of evidence that a check actually happened: the output of a run, kept.
The rule is that it must be captured from the run — never written afterwards to describe what the run would have produced.
Why this needs to be a rule
Four artifacts once sat in an evidence base here as controls. Their bytes had not come from the run they described. Two of the four differed from the backup copies, two matched — so nothing about the set announced itself as wrong.
No automated check caught it, and none could have. A fabricated artifact passes every test that asks whether a file is present and well-formed, because it is both.
How it was cured
Not by deletion. All four files carry a header naming what they are, why they are not evidence, and where the real evidence base is. The originals are preserved byte-for-byte elsewhere, because overwriting them would destroy the proof that the fabrication occurred.
What it means for this site
Every recording published here is the output of an actual fetch. The terminal captures on the project pages are rendered from real tool output, not mocked. Where an image would have to depict something that does not exist, it is drawn as a labelled diagram instead of a screenshot.
That distinction is small and it is the whole thing: a diagram explains, a recording attests. Dressing the first as the second is the failure this rule exists to prevent.