The gap between observability and incident management.
When I started in IT Operations, Incident Management was just incidents and Observability wasn't a word yet. Between monitoring and an incident, we had alerts in an inbox. Twenty years later, both are industries, and between them we still have alerts in an inbox. The work in that stretch, reading signals, deciding what matters, investigating, escalating, or letting go, is some of the most consequential in IT. It has no name.
In an industry built on traceability, production alerts pass through the least traceable part of the operational lifecycle. Between an alert firing and an incident being declared there is no custody at all, and the loss has weight: when something slips through, you cannot tell whether the alert that mattered was one of three that hour or one of three hundred. The incidents are the survivors. The operation is the sifting, and the sifting lives nowhere.
Named, the space becomes a discipline: Signal Operations. Upstream, observability hands it a stream of signals. Downstream, incident management takes declared incidents with their story attached. And for the operation itself it keeps the record, inputs, decisions, investigations, and outcomes, where the next shift can stand on them. Named work can be measured, staffed, handed over, and improved. Unnamed work can only be survived.