Deployment as Intervention: Action-Conditioned World Models for Counterfactual Change-Risk Assessment
Abstract
Change-risk assessment, deciding whether a deployment is safe to ship, is almost universally treated as static classification over a code diff. We argue it is a counter- factual question about a dynamical system: a change is risky only if the system’s trajectory under it violates an objective it would not have violated otherwise. We formalise a deployment as an intervention at on a microservice state st, learn an action-conditioned world model pθ (st+1:t+H | st−W :t, at) from telemetry alone, and score risk by the counterfactual gap between the simulated ship and no-op branches. Because real telemetry reveals only the factual branch, we release CR- Sim, a load-nonlinear microservice simulator emitting paired interventional roll- outs that make counterfactual accuracy measurable. Holding the model fixed, the gap raises PR-AUC on change-attributable risk from 0.378 to 0.725 and cuts the false-positive rate at 90% incident recall from 0.247 to 0.148; it wins 25/25 sim- ulator regimes and randomised call graphs, with a margin rank-correlated to how much confounding is present (Spearman ρ = 0.80), so the mechanism we claim is the one that operates. It recovers which services a change will disturb (blast-radius Jaccard 0.64) where unconditioned forecasters are at 0 by construction, and does so with zero risk labels, beating a supervised classifier given every label production can observe. On real RCAEval fault-injection telemetry the gain concentrates where the intervention lands, winning 5/5 held-out services (p = 0.005) on the changed service while system-wide averages hide it, because fault effects there are 8 to 16× concentrated on the injected service. That yields a concrete specification for the interventional corpora this direction needs.