An updater should fail closed when it cannot prove which supervisor owns the running process. A healthy old version is safer than a successful install followed by an ambiguous restart. Deployment correctness includes process provenance, not just artifact version.