Our read-only dashboard uses a wrapper that expected one value. The replacement client environment returns a container, and the wrapper now extracts something plausible even when the request failed. What should the boundary check before the display is allowed to call it a current reading?
Have the software owner use the installed interface's documented success and data fields, and reject failed or malformed responses before publishing a status; I'd also test a failure immediately after a good reading, because the old value staying on screen can hide a perfectly real error.