In May 1924, Walter Shewhart sent his supervisor at Western Electric a memo that George Edwards, the man who received it, later described as only about a page in length, a third of it taken up by a simple diagram: a measured quantity plotted over time, wandering between two statistical limits. It was the first control chart, and the argument compressed into it was that the factory had been asking its quality question at the wrong altitude. Not “is this part good.” Is the process behaving.

Inspection convicts one part at a time. A failed part tells you a failure happened, and nothing about which world you’re in: a stable process that produced one unlucky part, or a process that shifted an hour ago and is producing failures in volume. Shewhart’s limits split those worlds. Inside them, leave the process alone, because adjustments made in reaction to individual bad parts add variation instead of removing it. Outside them, some assignable cause changed the process, and the job is to go find it. The part stops being the object you reason about and becomes a reading on the thing you do.

Deming spent the following decades pushing that logic to its blunt conclusion and put it third on his list of fourteen: cease dependence on inspection to achieve quality. Checking finished goods arrives too late and samples too little. Build the quality into the process instead.

Pharmaceutical regulation wrote all of this down. FDA’s process validation guidance starts from the same premise, quality “cannot be adequately assured merely by in-process and finished-product inspection or testing,” and aims all three of its stages at the process: design it, qualify it by demonstrating it can manufacture reproducibly, then verify for the rest of its life that it remains in a state of control. A batch gets released on the strength of that standing argument plus its own in-process checks. No shop re-earns the argument from scratch per batch. The volume would make that impossible, and the validated process makes it unnecessary.

Which answers a question I left hanging last month, about where assurance goes when agents drive change volume past anything a per-change process can absorb. Seen from Shewhart’s side of the century, change control is easy to classify. It is 100% inspection. Every unit coming off the line gets a person’s attention, a posture manufacturing already abandoned wherever it was tried, for exactly the reason now bearing down on software: the line got faster than the inspectors.

So the unit of account moves to the process, because it has nowhere else to go. The pipeline producing the changes gets qualified the way a line does, its gates and its evidence demonstrated on representative work before the output touches anything validated. After that, continued verification, monitoring the output stream the way stage three monitors routine production, with a confirmed escape handled as a deviation, a fact about the process to investigate rather than merely a bug to patch. An inspector would need none of this grammar explained. It’s how they already read a factory floor.

The entry fee is the part I keep catching on. Qualification means something only if you can name the defect and measure its rate. A tablet batch has critical quality attributes with numbers on them, assay, dissolution, impurities, each with limits a lab can test. That gives “state of control” its content. A stream of agent-written diffs has no equivalent yet. Escaped defects surface months later, a guard pipeline’s rejection rate measures the guards as much as the code, and whatever review finds depends on who reviewed. Shewhart’s memo fit on a page because the hard part fit in one picture: a quantity worth charting and limits worth trusting. For a process that manufactures changes, that page hasn’t been written, and I don’t know what goes on the axis.