Concepts
Definitions for the concepts and vocabulary used across March.
| Term | Meaning in March |
|---|---|
| Event | Source material that may indicate a meaningful change, such as a merged PR or submitted MCP event. It is not yet the normalized organizational change. |
| Source | The system or context March learns from. A change source supplies an event; a context source supplies the company material March checks. |
| Change | March's normalized statement of what changed: a subject, property, prior state when known, and new state, grounded in evidence. |
| Investigation | The asynchronous workflow that loads an event, checks configured context, records evidence, and produces a decision. |
| Evidence | A finding March used, paired with provenance such as a source label, URL, or locator. |
| Consequence | A downstream artifact or area that may now be wrong or require work because of a change. The product presents consequences as recommendations or required updates. |
| Recommendation | The user-facing description of a consequence: what is affected, what it currently says/does, what should be true instead, and why. |
| Outcome / decision | The investigation result: propose_action, no_action, or escalate. |
| Trace | The structured user-visible account of what March understood, checked, found, and concluded. |
| Deduplication | Reusing an existing investigation instead of starting duplicate work. MCP joins only live (pending/running) investigations by source + external_id, or a content hash when no external ID is supplied. GitHub first matches non-failed rows, including completed ones: manual starts use a PR, while webhooks use a PR plus merge commit SHA. Source external IDs are stored and compared case-insensitively. |
An investigation's lifecycle status (pending, running, completed, or
failed) answers whether the run finished. Its decision answers what March
concluded. These are related but different fields.