What the Ring Was For
Three lessons back, the answer to an unavailable reviewer was a ring: an ordered rotation, entered at the requested name, walked exactly once, every hop logged with the reason the previous one was skipped. It was a good answer to the problem it solved — an empty chair must not be recorded as a review — and it held as the default for five weeks.
Then the rounds got sharded. A full cold sweep had grown past what one reviewer's window could hold, so the sweep was split into per-track shards run as one round — and each shard entered the ring wherever it could. The round's report named the reviewer that was requested. The reviewers that actually ran were several, rotated invisibly, behind the report's back. The ruling came down in one line: a reviewer swap the operator never sees is a bug.
Named, and Nothing Else
The replacement is a refusal, and it is worth stating as one. Every shard runs on the named reviewer — the one the operator asked for — and nothing else. If that reviewer is unavailable, the shard fails, with the reason on the record, while the other shards continue. Partial coverage with the holes showing beats full coverage with a hidden swap, because the author can judge a hole and cannot judge a lie. The property review exists for is the boundary: it is crossed by the reviewer you named, or the record says it was not crossed.
A swap still happens — limits and outages are exactly why it must — but it is a visible decision, made one of two ways. The operator re-runs the round naming a different reviewer, and only the failed shards re-run. Or the operator opted in up front with an explicit fallback chain, walked in a written order, each hop logged with the displayed tail that killed the last. What never happens is the silent middle: a default that rotates.
Nothing Already Reviewed Is Lost
The rebuild's other half is durability, born of a second observation from the same season: a review process is a long process, and a long process can die at hour three, abnormally, through nobody's fault. So each shard's parsed result — the findings block, the verdict, which reviewer actually ran, the elapsed time — persists the moment the shard finishes, and a re-run of the same round resumes: finished shards are reused, keyed to the request's hash so a changed request re-runs, and failed shards retry on the same named reviewer.
One failure mode was promoted to a rule here, and it is the one that sounds strangest: a shard that exits cleanly with no findings block is a failed shard, not an empty success. The case that forced it: one reviewer's harness politely auto-cancelled every tool prompt it was sent, narrated for a while, and exited zero. Clean exit, no review. "No findings" can never again mean "nothing found" — only "something finished" — until the findings are actually there.