Dependencies are not impacts.
Knowing that a function depends on something tells you where to look. It does not tell you what happened.
A useful model, used wrongly
Dependency models are among the most valuable things a resilience team can build. They become harmful the moment a tool converts a modelled relationship into an asserted outcome and shows a function as affected because something upstream was mentioned in a signal.
Why the shortcut is tempting
Asserted impact makes a demo look decisive and a report look complete. It also produces confident statements that no evidence supports, which is exactly what a post-event review will find.
Keeping the distinction
Possible exposure and confirmed impact should be different states in the data, not different words in a description. Moving between them should require evidence or a recorded human verification, and the transition should be visible in the record.
See SKALV with your own operational scenario.
Bring a real scenario — the sources you follow, the functions you cannot lose — and we will show where SKALV fits and where it does not.