Decisionless monitoring: the reports nobody acts on
A monitoring system that reports everything is indistinguishable from one that reports nothing: both train the reader to stop reading. The interesting question is not "how accurate are our alerts" but "what decision does this report change?"
Decisionless is not the same as wrong
When a team deletes most of its reports, the removed ones are usually not false - they are decisionless. Nothing anyone would do differently depended on them. That is a different and much more fixable property than accuracy: a false report can be argued about, a decisionless one can simply be moved to a dashboard.
The test is one sentence long: if this arrives and I do nothing, what have I lost? If the answer is "nothing", it is not an alert.
The two error types must be measured apart
| Error | Cost in trading | Cost on call |
|---|---|---|
| Missed event (false negative) | Direct, sometimes terminal | Depends entirely on the event |
| Useless page (false positive) | Annoying, cheap | Expensive - it trains people to ignore the channel the real event will use |
Same system, opposite optimisation. Averaging the two into a single "precision" number hides which one you are trading away, which is why an alerting setup can look well-tuned while being useless in both directions at once.
The metric that actually describes protection
Not alert volume. Not detection latency. The number that corresponds to the thing you were buying is:
After a real breach, how long until the behaviour actually changes?
Time-to-detect is an engineering metric that is easy to instrument. Time-to-effect requires staging a real breach and timing the outcome - which is exactly why it is usually missing, and exactly why adding alerts feels like progress while protection does not move. If you only measure the first, you will look well-instrumented right up until the review.
Three questions to ask of any report
- What decision does this change? None -> dashboard, not an inbox.
- If it is wrong in each direction, what does each cost? If you cannot answer separately, you cannot tune it.
- Is it on the path that can act? A signal that no component consults is a log line with a notification attached.
The pattern behind all of this is the same one that turns risk guards into decoration: something that looks like protection, occupies the attention that protection would need, and does not sit on the path where the decision is actually made.
Related notes
- Your daily loss limit resets when MetaTrader restarts. Here is the fix.
- Memory plus an expiry policy: what a restarted guard is allowed to assume
- Detection is not resolution: the gap that makes guards decorative
- What a kill switch should actually do (and the four ways they fail)
- Silent failures in trading automation: the three that cost the most
- Which day is it? Broker time, host time, and the trading-day boundary
Get the guard
Free MT5 daily-loss guard, source included: https://xuks124.github.io/vigildesk/free.html
Risk disclosure
Algorithmic trading carries both technical and market risk. No tool eliminates the possibility of loss. Nothing on this page is investment advice, and no performance is implied or promised.