By checking the destination rather than the status. A successful deploy, a green test suite, and a migration file in a repository are all reports about a process, not evidence about the result, and each one can be true while the thing you wanted did not happen. So our standard is to read the live object: the row that was written, the asset the page actually served, the schema the database actually holds. We also prove a check by deliberately breaking something and confirming the check fails, because a checker reporting zero problems may simply have examined nothing.