Reconstruction
Evidence is scattered across traces, OpenTelemetry, identity systems, ERP records, SaaS logs, policy engines, business events and external services — and a great deal of important business state is never instrumented at all. So the problem is not collecting more logs. It is recovering a trustworthy picture of operational reality from the evidence that exists, plus the ontology, historical state, and causal constraints.
Observability answers what did we see. Reconstruction answers given this evidence, what is the most likely state — and which parts are observed, which inferred, and which still uncertain.
Reconstruction is inference under uncertainty, and in security it is adversarially hard: a missing edge is often missing precisely because an attacker or a misconfiguration made it invisible. Every element of the state carries its origin, and that origin propagates to every finding computed from it.