826 lines
51 KiB
Markdown
826 lines
51 KiB
Markdown
# lorin/resilience-engineering · GitHub
|
||
|
||
- **期号**: SRE Weekly Issue #170(2019-04-28)
|
||
- **作者**: @lorin (GitHub)
|
||
- **链接**: https://github.com/lorin/resilience-engineering/blob/master/README.md
|
||
|
||
## 简介
|
||
|
||
An absolute treasure trove of links to many articles and papers on resilience engineering. Beyond just links, there are short profiles of 30+ important thinkers in the field. I’m going to be busy for awhile.
|
||
|
||
## 正文
|
||
|
||
Alias: [http://resiliencepapers.club](http://resiliencepapers.club) (thanks to [John Allspaw](https://twitter.com/allspaw)).
|
||
|
||
This doc contains notes about people active in resilience engineering, as well as some influential researchers who are no longer with us, organized alphabetically. It also includes people and papers from related fields, such as cognitive systems engineering and naturalistic decision-making.
|
||
|
||
If you're not sure what to read first, check out [Resilience engineering: Where do I start?](https://github.com/lorin/resilience-engineering/blob/master/intro.md)
|
||
|
||
A [BH](https://safety177496371.wordpress.com/) link indicates Ben Hutchinson's [Safety & Performance Research Summaries](https://safety177496371.wordpress.com/) blog.
|
||
Ben writes summaries of safety papers, posting them to his blog as well as LinkedIOn.
|
||
|
||
A [TWRR](http://resilienceroundup.com) link indicates Thai Wood's [Resilience Roundup](http://resilienceroundup.com). Thai publishes a newsletter that
|
||
summarizes resilience engineering papers.
|
||
|
||
[resilienceinsoftware.org](https://resilienceinsoftware.org) is the Resilience in Software Foundation, a community of software people who are interested in resilience engineering.
|
||
|
||
For a collection of talks, check out the [Resilience Engineering, Cognitive Systems
|
||
Engineering, and Human Factors Concepts in Software
|
||
Contexts](https://www.youtube.com/playlist?list=PLb1aZTnPf3-OMChMkrr6WsokRI6LOnuem)
|
||
YouTube playlist maintained by John Allspaw.
|
||
|
||
You might also be interested in my [notes on David Woods's Resilience Engineering short course](https://github.com/lorin/res-eng-short-course-notes).
|
||
|
||
The papers linked here are also in the [zotero res-eng group](https://www.zotero.org/groups/2335189/res-eng/items).
|
||
|
||
For each person, I list concepts that they reference in their writings, along with some publications. The publications lists aren't comprehensive: they're ones I've read or have added to my to-read list.
|
||
|
||
- [The adaptive universe](https://github.com#the-adaptive-universe) (David Woods)
|
||
- [Dynamic safety model](https://github.com#dynamic-safety-model) (Jens Rasmussen)
|
||
- [Safety-II](https://github.com#safety-i-vs-safety-ii) (Erik Hollnagel)
|
||
- [Graceful extensibility](https://github.com#graceful-extensibility) (David Woods)
|
||
- [ETTO: Efficiency-tradeoff principle](https://github.com#etto-principle) (Erik Hollnagel)
|
||
- [Drift into failure](https://github.com#drift-into-failure) (Sidney Dekker)
|
||
- Robust yet fragile (John C. Doyle)
|
||
- [STAMP: Systems-Theoretic Accident Model & Process](https://github.com#stamp) (Nancy Leveson)
|
||
- Polycentric governance (Elinor Ostrom)
|
||
|
||
Note: there are now [multiple contributors](https://github.com/lorin/resilience-engineering/graphs/contributors) to this repository.
|
||
|
||
[Alexander](https://www.linkedin.com/in/colette-alexander-4168267/) is a Director of Engineering and researcher who previously held roles with IBM, Spotify, Cognite, and HashiCorp. She hosts the podcast This is Fine with co-host Clint Byrum.
|
||
She completed a Masters thesis at Lund titled [Risky Business: Quantitative Risk Assessments as Enabling Devices in Cybersecurity](https://lup.lub.lu.se/luur/download?func=downloadFile&recordOId=9148570&fileOId=9148571).
|
||
|
||
Allspaw is the former CTO of Etsy. He applies concepts from resilience engineering to the tech industry.
|
||
He is one of the founders [Adaptive Capacity Labs](http://www.adaptivecapacitylabs.com/), a resilience engineering consultancy.
|
||
|
||
Allspaw tweets as [@allspaw](https://twitter.com/allspaw).
|
||
|
||
- [Resilience Engineering: The What and How](https://devopsdays.org/events/2019-washington-dc/program/john-allspaw/)
|
||
- [Incidents as we Imagine Them Versus How They Actually Are](https://www.youtube.com/watch?v=8DtzmV1jiyQ)
|
||
- [How your systems keep running day after day](https://www.youtube.com/watch?v=xA5U85LSk0M)
|
||
- [Problem detection (papers we love)](https://www.youtube.com/watch?v=NxctiGRI2y8) (presentation of[Problem detection](https://www.researchgate.net/publication/220579480_Problem_detection) paper)
|
||
- [Common Ground and Coordination in Joint Activity (papers we love)](https://paperswelove.org/2016/video/john-allspaw-common-ground/) (presentation of[Common Ground and Coordination in Joint Activity](http://jeffreymbradshaw.net/publications/Common_Ground_Single.pdf) paper)
|
||
- [Amplifying sources of resilience](https://www.infoq.com/presentations/resilience-thinking-paradigm/) (presentation about applying Resilience Engineering thinking & paradigms to the world of software engineering)
|
||
- [Incidents: What Is Often Missed & What Can Be Done About That](https://www.adaptivecapacitylabs.com/blog/2020/03/30/incidents-what-is-often-missed-what-can-be-done-about-that/#fvp_10,1s)
|
||
- [Incident Analysis: How *Learning* is Different Than *Fixing*](https://www.adaptivecapacitylabs.com/blog/2020/05/06/how-learning-is-different-than-fixing/)
|
||
|
||
Bainbridge is a psychology researcher. She has a website at [http://www.complexcognition.co.uk/](http://www.complexcognition.co.uk/)
|
||
|
||
Bainbridge is famous for her 1983 [Ironies of automation](https://www.sciencedirect.com/science/article/abs/pii/0005109883900468) paper, which continues to
|
||
be frequently cited.
|
||
|
||
- automation
|
||
- design errors
|
||
- human factors/ ergonomics
|
||
- cognitive modelling
|
||
- cognitive architecture
|
||
- mental workload
|
||
- situation awareness
|
||
- cognitive error
|
||
- skill and training
|
||
- interface design
|
||
|
||
[Baker](https://www.thehopmentor.com/) is a practitioner who provides
|
||
training services in human and organizational performance (HOP) and learning
|
||
teams.
|
||
|
||
Baker tweets as [@thehopmentor](https://twitter.com/thehopmentor).
|
||
|
||
- Human and organizational performance (HOP)
|
||
- Learning teams
|
||
- Industrial empathy
|
||
|
||
- [A bit about HOP](https://docs.wixstatic.com/ugd/1a0149_21bcf20f158540098d3d7987ffbf3f58.pdf) (editorial)
|
||
- [A short introduction to human and organizational performance (hop) and learning teams](http://www.safetydifferently.com/a-short-introduction-to-human-and-organizational-performance-hop-and-learning-teams/) (blog post)
|
||
|
||
- [Resiliency Trade Space Study: The Interaction of Degraded C2 Link and Detect and Avoid Autonomy on Unmanned Aircraft](https://www.researchgate.net/publication/330222613_Resiliency_Trade_Space_Study_The_Interaction_of_Degraded_C2_Link_and_Detect_and_Avoid_Autonomy_on_Unmanned_Aircraft)
|
||
- [Developing Systemic Contributors and Adaptations Diagramming (SCAD): systemic insights, multiple pragmatic implementations](https://journals.sagepub.com/doi/10.1177/1071181322661334)
|
||
|
||
[Bergström](http://www.jbsafety.se/p/about-me.html) is a safety research and
|
||
consultant. He runs the [Master Program of Human Factors and Systems
|
||
Safety](http://www.humanfactors.lth.se/msc-programme/) at Lund University.
|
||
|
||
Bergström tweets as [@bergstrom_johan](https://twitter.com/bergstrom_johan).
|
||
|
||
- Analytical traps in accident investigation
|
||
- Counterfactual reasoning
|
||
- Normative language
|
||
- Mechanistic reasoning
|
||
- Generic competencies
|
||
|
||
- [Resilience engineering: Current status of the research and future challenges](https://www.sciencedirect.com/science/article/pii/S0925753516306130)
|
||
- [Rule- and role retreat: An empirical study of procedures and resilience](https://www.researchgate.net/publication/50917226_Rule-_and_role_retreat_An_empirical_study_of_procedures_and_resilience)
|
||
- [Team Coordination in Escalating Situations: An Empirical Study Using Mid-Fidelity Simulation](https://portal.research.lu.se/ws/files/1376441/3014838.pdf)
|
||
|
||
- [Three analytical traps in accident investigation](https://www.youtube.com/watch?v=TqaFT-0cY7U)
|
||
- [Two Views on Human Error](https://www.youtube.com/watch?v=rHeukoWWtQ8)
|
||
- [What, Where and When is Risk in System Design?](https://www.youtube.com/watch?v=BtJIumyCrtE&feature=youtu.be) (Velocity 2013)
|
||
|
||
- [Basic patterns in how adaptive systems fail](https://www.researchgate.net/publication/284324002_Basic_patterns_in_how_adaptive_systems_fail) ([TWRR](https://resilienceroundup.com/issues/34/) )
|
||
- [A practitioner’s experiences operationalizing Resilience Engineering](https://www.sciencedirect.com/science/article/abs/pii/S0951832015000812)
|
||
- [Noticing Brittleness, Designing for Resilience](https://www.taylorfrancis.com/chapters/edit/10.1201/9781315605708-18/noticing-brittleness-designing-resilience-elizabeth-lay-matthieu-branlat)
|
||
|
||
- [Beyond surge: Coping with mass burn casualty in the closest hospital to the Formosa Fun Coast Dust Explosion](https://doi.org/10.1016/j.burns.2018.12.003)
|
||
- [Coping With a Mass Casualty: Insights into a Hospital’s Emergency Response and Adaptations After the Formosa Fun Coast Dust Explosion](https://www.researchgate.net/publication/335366770_Coping_With_a_Mass_Casualty_Insights_into_a_Hospital's_Emergency_Response_and_Adaptations_After_the_Formosa_Fun_Coast_Dust_Explosion) ([TWRR](https://resilienceroundup.com/issues/76/) )
|
||
|
||
Conklin's books are on my reading list, but I haven't read anything by him
|
||
yet. I have listened to his great [Preaccident investigation
|
||
podcast](https://preaccidentpodcast.podbean.com/).
|
||
|
||
Conklin tweets as [@preaccident](https://twitter.com/preaccident).
|
||
|
||
- [Pre-accident investigations: an introduction to organizational safety](https://www.amazon.com/Pre-Accident-Investigations-Todd-Conklin/dp/1409447820)
|
||
- [Pre-accident investigations: better questions - an applied approach to
|
||
operational learning](https://www.amazon.com/gp/product/1472486137)
|
||
- [Do Safety Differently](https://www.amazon.com/Do-Safety-Differently-Sidney-Dekker/dp/B09RM3Z17V)
|
||
|
||
Quanta - [Risk and Safety Conf 2019](https://www.youtube.com/watch?v=5WTbeFj2kJY&feature=youtu.be)
|
||
|
||
[Cook](<https://en.wikipedia.org/wiki/Richard_Cook_(safety_researcher)>) was an anasthesiologist who studies failures in complex systems. He is one of the founders [Adaptive Capacity Labs](http://www.adaptivecapacitylabs.com/), a resilience engineering consultancy.
|
||
He tweeted as [@ri_cook](https://twitter.com/ri_cook).
|
||
|
||
- how complex systems fail
|
||
- degraded mode
|
||
- sharp end (c.f. Reason's blunt end)
|
||
- Going solid
|
||
- Cycle of error
|
||
- "new look"
|
||
- first vs second stories
|
||
|
||
- [How Complex Systems Fail](https://www.youtube.com/watch?v=2S0k12uZR14) (Velocity 2012)
|
||
- [Resilience in Complex Adaptive Systems: Operating at the Edge of Failure](https://www.youtube.com/watch?v=PGLYEDpNu60&feature=youtu.be) (Velocity 2013)
|
||
- [Lectures on the study of cognitive work](https://www.youtube.com/playlist?list=PLb1aZTnPf3-OEU1by77zZQQYckvXUGmNY) (Graduate student lecture-discussions at The Royal Institute of Technology, Huddinge, SWEDEN in 2012 )
|
||
- [Panel discussion: Safety Culture, Lean, and DevOps](https://www.youtube.com/watch?v=gtxtb9z_4FY&feature=youtu.be) (DOES 2017)
|
||
- [Working at the center of the Cyclone](https://www.youtube.com/watch?v=3ZP98stDUf0&feature=youtu.be) (DOES 2018)
|
||
- [A Few Observations on the Marvelous Resilience of Bone & Resilience Engineering](https://www.youtube.com/watch?v=8LbePBiOvZ4) (REdeploy 2019)
|
||
|
||
Le Coze is research director at INERIS (National Institute for the Industrial Environment and Risks) in France. He frequently writes on historical views of safety.
|
||
|
||
Le Coze tweets as [@JcLeCoze](https://twitter.com/JcLeCoze).
|
||
|
||
Dekker is a human factors and safety researcher with a background in aviation.
|
||
His books aimed at a lay audience (Drift Into Failure, Just Culture, The Field Guide to 'Human Error' investigations)
|
||
have been enormously influential. He was a founder of the MSc programme in Human Factors & Systems Safety at Lund University.
|
||
His PhD advisor is [David Woods](https://github.com#david-woods).
|
||
|
||
Dekker tweets as [@sidneydekkercom](https://twitter.com/sidneydekkercom).
|
||
|
||
Dekker developed the theory of *drift*, characterized by five concepts:
|
||
|
||
1. Scarcity and competition
|
||
2. Decrementalism, or small steps
|
||
3. Sensitive dependence on initial conditions
|
||
4. Unruly technology
|
||
5. Contribution of the protective structure
|
||
|
||
Dekker examines how cultural norms defining justice can be re-oriented to minimize the negative impact and maximize learning when things go wrong.
|
||
|
||
1. Retributive justice as society's traditional idea of justice: distributing punishment to those responsible based on severity of the violation
|
||
2. Restorative justice as an improvement for both victims and practicioners: distributing obligations of rebuilding trust to those responsible based on who is hurt and what they need
|
||
3. First, second, and third victims: an incident's negative impact is felt by more than just the obvious victims
|
||
4. Learning theory: people break rules when they have learned there are no negative consequences, and there are actually positive consequences - in other words, they break rules to get things done to meet production pressure
|
||
5. Reporting culture: contributing to reports of adverse events is meant to help the organization understand what went wrong and how to prevent recurrence, but accurate reporting requires appropriate and proportionate accountability actions
|
||
6. Complex systems: normal behavior of practicioners and professionals in the context of a complex system can appear abnormal or deviant in hindsight, particularly in the eyes of non-expert juries and reviewers
|
||
7. The nature of practicioners: professionals want to do good work, and therefore want to be held accountable for their mistakes; they generally want to help similarly-situated professionals avoid the same mistake.
|
||
|
||
- There is a difference between the organization's prescribed processes for completing work and how work is actually completed. (work as imagined vs work as done)
|
||
- The difference between work as imagined and work as done is the result of the expertise that exists in your workers from contact with real-life pressures, heuristics, and unexpected conditions.
|
||
- Old View: People are the problem to control with process
|
||
- They did something wrong
|
||
- They need more rules and enforcement
|
||
- They need to try harder
|
||
- We need to get rid of "bad apples"
|
||
- Focus on the "sharp end" of the organization - the people closest to the work
|
||
- New View: Work is done adaptively in an uncertain world
|
||
- Things go wrong all the time
|
||
- Workers often detect and correct these problems
|
||
- Local adaptations are a source of organizational expertise
|
||
- "What conditions existed that made the selected course of action seem correct to the people involved?"
|
||
- Traditional safety interventions have diminishing yields with increasing overhead. Accumulated compliance burden and "safety clutter" makes it harder to get work done *and* to do so safely.
|
||
- Safety Clutter is accountable to safety bureaucracy and compliance rather than the safety of the workers or the process
|
||
- Safety Clutter is produced by the "blunt end" of the organization without local expertise of what is practicable or practical in-situ
|
||
- Safety Clutter represents a broader "deprofessionalization" - a removal of trust and confidence in professionals to do their job well, removing their pride, autonomy, and achievement.
|
||
- Paradoxically, Safety Clutter can result from government deregulation - organizations need to self-impose risk controls in the absence of external guidelines.
|
||
- Sadly for organizations with Safety Clutter, more internal rules do not equal better legal protection.
|
||
- When a process is relatively safe or stable, measurements of bad outcomes lack statistical significance to understand trends or tie trends to interventions.
|
||
- Fundamental Regulator Paradox: regulating a system so well that there are no useful measurements left to understand how the system is performing
|
||
- Zero Paradox: A study of construction contractors showed more fatal accidents in firms with "goal zero" safety policies than in those without. Non-fatal accidents were similar.
|
||
- Risk Secrecy: "goal zero" commitments result in injury underreporting and hiding of incidents which prevents learning, particularly when tied to financial incentives for leadership.
|
||
- There are patterns (capacities) that help things go well
|
||
- *Diversity of opinion* - possibility to voice dissent
|
||
- *Keeping the discussion on risk alive* even when things go well
|
||
- *Deference to expertise* that already exists in people at the sharp end
|
||
- *Psychological safety* / "stop" ability
|
||
- *Low barriers* to interaction between organizational groups
|
||
- *Sharp end improvements* to existing systems based on local expertise
|
||
- *Pride in work* - process and results
|
||
- Rapid problem-solving can prevent effective problem-understanding
|
||
- Leadership buy-in and practice of New View safety is imperative to its success. It's also difficult to foster.
|
||
- Worker buy-in is rapid and fits their existing mental model
|
||
- Leadership must abandon the mental model that has governed their past work and decision-making - difficult for anyone.
|
||
- Peer discussions are especially helpful for leadership
|
||
- Highlighting how local adaptations helped things go well also helps
|
||
|
||
- Drift into failure
|
||
- Safety differently
|
||
- New view vs old view of human performance & error
|
||
- Just culture
|
||
- complexity
|
||
- broken part
|
||
- Newton-Descartes
|
||
- diversity
|
||
- systems theory
|
||
- unruly technology
|
||
- decrementalism
|
||
- generic competencies
|
||
- work as imagined vs work as done
|
||
|
||
Devita is a software engineering manager and researcher in software resilience engineering. She has previously held roles at Microsoft, Netflix, and Google. Her master thesis [To Deploy, or Not to Deploy, That is the Question A qualitative study of the decision-making experiences of engineers deploying software changes in production](https://lup.lub.lu.se/student-papers/search/publication/9149521) focused on software deployments and decision making.
|
||
|
||
[Doyle](http://www.cds.caltech.edu/~doyle/wiki/index.php?title=Main_Page) is a
|
||
control systems researcher. He is seeking to identify the universal laws that capture the
|
||
behavior of resilient systems, and is concerned with the architecture of such
|
||
systems.
|
||
|
||
- Robust yet fragile
|
||
- layered architectures
|
||
- constraints that deconstrain
|
||
- protocol-based architectures
|
||
- emergent constraints
|
||
- Universal laws and architectures
|
||
- conservation laws
|
||
- universal architectures
|
||
- Highly optimized tolerance
|
||
- Doyle's catch
|
||
|
||
*Doyle's catch* is a term introduced by David Woods, but attributed to John Doyle. Here's how
|
||
[Woods quotes Doyle](https://www.researchgate.net/publication/303832480_The_Risks_of_Autonomy_Doyles_Catch):
|
||
|
||
Computer-based simulation and rapid prototyping tools are now broadly available and powerful enough that it is relatively easy to demonstrate almost anything, provided that conditions are made sufficiently idealized. However, the real world is typically far from idealized, and thus a system must have enough robustness in order to close the gap between demonstration and the real thing.
|
||
|
||
|
||
[Edwards](http://hopcoach.net/) is a practitioner who provides
|
||
training services in human and organizational performance (HOP).
|
||
|
||
Edwards tweets as [@thehopcoach](https://twitter.com/thehopcoach).
|
||
|
||
Ericsson introduced the idea of *deliberate practice* as a mechanism for
|
||
achieving high level of expertise.
|
||
|
||
Ericsson isn't directly associated with the field of resilience engineering. However, Gary Klein's work is informed by his, and I have a particular interest in how people improve in expertise, so I'm including him here.
|
||
|
||
- Expertise
|
||
- Deliberate practice
|
||
- Protocol analysis
|
||
|
||
[Feltovich](https://www.ihmc.us/groups/pfeltovich/) is a retired Senior Research Scientist at the Florida Institute for Human & Machine Cognition (IHMC),
|
||
who has done extensive reserach in human expertise.
|
||
|
||
Finkel is a Colonel in the Israeli Defense Force (IDF) and the Director of the IDF's Ground Forces Concept Development and Doctrine Department
|
||
|
||
[Grayson](https://www.linkedin.com/in/marisa-grayson/) is a cognitive systems engineer at Mile Two, LLC.
|
||
|
||
- [Approaching Overload: Diagnosis and Response to Anomalies in Complex and Automated Production Software Systems](https://www.researchgate.net/publication/333091997_Approaching_Overload_Diagnosis_and_Response_to_Anomalies_in_Complex_and_Automated_Production_Software_Systems)
|
||
- [Cognitive Work of Hypothesis Exploration During Anomaly Response](https://queue.acm.org/detail.cfm?id=3380778)
|
||
|
||
[Herrera](https://www.ntnu.edu/employees/ivonne.a.herrera) is an associate professor in
|
||
the department of industrial economics and technology management at NTNU and a
|
||
senior research scientist at SINTEF. Her areas of expertise include safety management and
|
||
resilience engineering in avionics and air traffic management.
|
||
|
||
- [Organisational accidents and resilient organisations: six perspectives](https://www.sintef.no/globalassets/upload/teknologi_og_samfunn/sikkerhet-og-palitelighet/rapporter/sintef-a17034-organisational-accidents-and-resilience-organisations-six-perspectives.-revision-2.pdf) (SINTEF A17034 report)
|
||
|
||
See also: [list of publications](https://wo.cristin.no/as/WebObjects/cristin.woa/wa/fres?sort=ar&pnr=30556&action=sok)
|
||
|
||
[Hicks](https://www.drcathicks.com/) is a psychological scientist and researcher who creates open science to drive change for people doing technical work. She holds a PhD in Quantitative Experimental Psychology from UC San Diego and is the founder and principal scientist of Catharsis Consulting, a scientific consultancy that helps organizations transform with human-centered evidence strategies.
|
||
|
||
- [The Psychology of Software Teams](https://www.routledge.com/The-Psychology-of-Software-Teams/Hicks/p/book/9781032963389)
|
||
- [Developer Thriving: four sociocognitive factors that create resilient productivity on software teams](https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=10491133)
|
||
- [The New Developer: AI Skill Threat, Identity Change & Developer Thriving in the Transition to AI-Assisted Software Development](https://osf.io/preprints/psyarxiv/2gej5)
|
||
- [Google Scholar](https://scholar.google.com/citations?user=MotKyQcAAAAJ&hl=en)
|
||
|
||
[Hoffman](https://www.ihmc.us/groups/rhoffman/) is a senior research scientist at Florida Institute for Human & Machine Cognition (IHMC),
|
||
who has done extensive reserach in human expertise.
|
||
|
||
1. "Autonomy" is unidimensional.
|
||
2. The conceptualization of "levels of autonomy" is a useful scientific grounding for the development of autonomous system roadmaps.
|
||
3. Autonomy is a widget.
|
||
4. Autonomous systems are autonomous.
|
||
5. Once achieved, full autonomy obviates the need for human-machine collaboration.
|
||
6. As machines acquire more autonomy, they will work as simple sibstitutes (or multipliers) of human capability
|
||
7. "Full autonomy" is not only possible, but is always desireable.
|
||
|
||
Hollnagel proposed that there is always a fundamental tradeoff between
|
||
efficiency and thoroughness, which he called the *ETTO principle*.
|
||
|
||
Safety-I: avoiding things that go wrong
|
||
|
||
- looking at what goes wrong
|
||
- bimodal view of work and activities (acceptable vs unacceptable)
|
||
- find-and-fix approach
|
||
- prevent transition from 'normal' to 'abnormal'
|
||
- causality credo: believe that adverse outcomes happen because something goes wrong (they have causes that can be found and treated)
|
||
- it either works or it doesn't
|
||
- systems are decomposable
|
||
- functioning is bimodal
|
||
|
||
Safety-II: performance variability rather than bimodality
|
||
|
||
- the system’s ability to succeed under varying conditions, so that the number of intended and acceptable outcomes (in other words, everyday activities) is as high as possible
|
||
- performance is always variable
|
||
- performance variation is ubiquitous
|
||
- things that go right
|
||
- focus on frequent events
|
||
- remain sensitive to possibility of failure
|
||
- be thorough as well as efficient
|
||
|
||
Hollnagel proposed the Functional Resonance Analysis Method (FRAM) for modeling complex socio-technical systems.
|
||
|
||
- respond
|
||
- monitor
|
||
- learn
|
||
- anticipate
|
||
|
||
- ETTO (efficiency thoroughness tradeoff) principle
|
||
- FRAM (functional resonance analysis method)
|
||
- Safety-I and Safety-II
|
||
- things that go wrong vs things that go right
|
||
- causality credo
|
||
- performance variability
|
||
- bimodality
|
||
- emergence
|
||
- work-as-imagined vs. work-as-done
|
||
- joint cognitive systems
|
||
- systems of the first, second, third, fourth kind
|
||
|
||
[Johannesen](https://www.linkedin.com/in/leilajohannesen/) is currently a UX researcher and community advocate at IBM.
|
||
Her PhD dissertation work examined how humans cooperate, including studies of anesthesiologists.
|
||
|
||
- common ground
|
||
|
||
- [Grounding explanations in evolving, diagnostic situations](https://pdfs.semanticscholar.org/1bed/356b5aa67c701f5bad6d943768622095f418.pdf)
|
||
- [Maintaining common ground: an analysis of cooperative communication in the operating room](https://www.abdn.ac.uk/iprc/documents/Communication%20Book%20Chapter.pdf)
|
||
- [Behind Human Error](https://www.amazon.com/Behind-Human-Error-David-Woods/dp/0754678342)
|
||
|
||
Klein studies how experts are able to quickly make effective decisions in high-tempo situations.
|
||
|
||
Klein tweets as [@KleInsight](https://twitter.com/KleInsight).
|
||
|
||
- naturalistic decision making (NDM)
|
||
- intuitive expertise
|
||
- cognitive task analysis
|
||
- common ground
|
||
- problem detection
|
||
- automation as a "team player"
|
||
|
||
Elizabeth Lay is a resilience engineering practitioner. She is currently a director of safety and human performance at Lewis Tree Service.
|
||
|
||
- [Noticing Brittleness, Designing for Resilience](https://www.taylorfrancis.com/chapters/edit/10.1201/9781315605708-18/noticing-brittleness-designing-resilience-elizabeth-lay-matthieu-branlat)
|
||
- [A practitioner’s experiences operationalizing Resilience Engineering](https://www.sciencedirect.com/science/article/abs/pii/S0951832015000812)
|
||
|
||
Nancy Leveson is a computer science researcher with a focus in software safety.
|
||
|
||
Leveson developed the accident causality model known as STAMP: the Systems-Theoretic Accident Model and Process.
|
||
|
||
See [STAMP](https://github.com/lorin/resilience-engineering/blob/master/STAMP.md) for some more detailed notes of mine.
|
||
|
||
- Software safety
|
||
- STAMP (systems-theoretic accident model and processes)
|
||
- STPA (system-theoretic process analysis) hazard analysis technique
|
||
- CAST (causal analysis based on STAMP) accident analysis technique
|
||
- Systems thinking
|
||
- hazard
|
||
- interactive complexity
|
||
- system accident
|
||
- dysfunctional interactions
|
||
- safety constraints
|
||
- control structure
|
||
- dead time
|
||
- time constants
|
||
- feedback delays
|
||
|
||
[Long](https://www.linkedin.com/in/beth-adele-long/) is a software engineer, product manager, and Principal at software incident analysis company Adaptive Capacity Labs. She previously held roles at New Relic, Jeli, and who co-authored the paper [Building and revising adaptive capacity sharing for technical incident response: A case of resilience engineering](https://www-sciencedirect-com.proxy.lib.ohio-state.edu/science/article/pii/S0003687020301903) with Dr. Richard Cook.
|
||
|
||
[Macrae](https://www.nottingham.ac.uk/business/people/lizcjm.html) is a social psychology
|
||
researcher who has done safety research in multiple domains, including aviation
|
||
and healthcare. He helped set up the new healthcare investigation agency in
|
||
England. He is currently a professor of organizational behavior and psychology
|
||
at the Notthingham University Business School.
|
||
|
||
Macrae tweets at [@CarlMacrae](https://twitter.com/CarlMacrae).
|
||
|
||
- risk resilience
|
||
|
||
[Maguire](https://www.linkedin.com/in/lauramaguire/) is a cognitive systems
|
||
engineer and ressearcher with a PhD from Ohio State University. Maguire has done safety work in multiple domains, including forestry, healthcare, oil & gas, wildland firefighting, mountain safety, and software services. She formerly led research & development at [jeli.io](https://github.com/lorin/resilience-engineering/blob/master/jeli.io), is the a Director of the [Resilience & Proactive Safety Initiative([https://u.osu.edu/csel/resilienceproactivesafetyinitiative/](https://u.osu.edu/csel/resilienceproactivesafetyinitiative/)) at The Ohio State University's Cognitive Systems Engineering Lab and is the founder of [Trace Cognitive Engineering](https://www.tracecognitive.com/) and [Cognition In The Wild](https://github.com/lorin/resilience-engineering/blob/master/cognitioninthewild.com) translating theory into practice for software and other industries. She also supervises Masters thesis projects for the College of Engineering at Lund University for the Human Factors & Systems Safety program. She was a founding member of the [SNAFUCatchers Consortium](https://www.snafucatchers.com/) conducting focused cognitive systems and resilience engineering research on software companies.
|
||
|
||
Maguire (rarely) tweets as [@LauraMDMaguire](https://twitter.com/lauramdmaguire).
|
||
|
||
- [Joint Cognitive Systems: Ideas With Impact for Designing Safer, More Resilient Automated Systems](https://ieeexplore.ieee.org/document/10493156/)
|
||
- [Cognitive Skills in Software Engineering: Operating Complex, Adaptive Systems at Speed and Scale](https://ieeexplore.ieee.org/document/10339148)
|
||
- [Automation doesn't work the way we think it does](https://ieeexplore.ieee.org/document/10372510)
|
||
- [Realizing the Benefits of Human Machine Teaming for Safe Software Operations](https://dl.acm.org/doi/abs/10.1109/MS.2024.3480768) (with Laura Nolan)
|
||
- [Navigating tradeoffs in software failures](https://www.computer.org/csdl/magazine/so/2025/03/10953345/25ICFoAidsk) (with Fred Hebert)
|
||
- [Managing the Hidden Costs of Coordination](https://queue.acm.org/detail.cfm?id=3380779)
|
||
- [Controlling the Costs of Coordination in Large-scale Distributed Software Systems](http://rave.ohiolink.edu/etdc/view?acc_num=osu1593661547087969) (PhD dissertation)
|
||
- [Howie: The Post-Incident Guide](https://www.jeli.io/howie-the-post-incident-guide/)
|
||
- [STELLA: Report from the SNAFUcatchers Workshop on Coping With Complexity](https://snafucatchers.github.io/)
|
||
- Pre-prints of many of her paywalled publications are available on [Researchgate](https://www.researchgate.net/profile/Laura-Maguire-2)
|
||
|
||
Nash is a researcher and founder of [The Void] ([https://www.thevoid.community/](https://www.thevoid.community/)), a community-contributed collection of software-related incident reports, aimed at making the internet a safer and more resilient place.
|
||
|
||
[Nemeth](https://www.linkedin.com/in/christopher-nemeth-6651204) is a principal scientist at Applied Resesarch Associates, Inc.
|
||
|
||
- [Replacing Hindsight With Insight: Toward Better Understanding of Diagnostic Failures](http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.458.7283&rep=rep1&type=pdf)
|
||
- [Resilience is not control: healthcare, crisis management, and ICT](https://www.researchgate.net/profile/Robert-Wears/publication/225108705_Resilience_is_Not_Control_Healthcare_Crisis_Management_and_ICT/links/00b49532b2c7f3ed62000000/Resilience-is-Not-Control-Healthcare-Crisis-Management-and-ICT.pdf)
|
||
- [Taking Things in One’s Stride: Cognitive Features of Two Resilient Performances](https://www.taylorfrancis.com/chapters/edit/10.1201/9781315605685-19/taking-things-one-stride-cognitive-features-two-resilient-performances-richard-cook-christopher-nemeth)
|
||
- [Minding the Gaps: Creating Resilience in Health Care](https://europepmc.org/article/NBK/nbk43670)
|
||
|
||
[Nolan](https://www.linkedin.com/in/lauralifts/details/experience/) is a Principal Software Engineer and researcher who previously held roles at Google, Slack, Stanza. Her forthcoming masters thesis from Lund university studied expert troubleshooting during outages in production software environments.
|
||
|
||
She currently works at Reddit.
|
||
|
||
- [Realizing the Benefits of Human Machine Teaming for Safe Software Operations](https://dl.acm.org/doi/abs/10.1109/MS.2024.3480768) (with Laura Maguire)
|
||
|
||
[Nyssen](http://www.lecit.ulg.ac.be/equipe/anne-sophie-nyssen/) is a psychology professor at the University of Liège,
|
||
who does research on human error in complex systems, in particular in medicine.
|
||
|
||
A list of publications can be found on her website linked above.
|
||
|
||
[Ostrom](http://www.elinorostrom.com/) was a Nobel-prize winning economics and
|
||
political science researcher.
|
||
|
||
- [Coping with tragedies of the commons](https://www.annualreviews.org/doi/abs/10.1146/annurev.polisci.2.1.493)
|
||
- [Governing the Commons: The Evolution of Institutions for Collective Action](https://www.amazon.com/Governing-Commons-Evolution-Institutions-Collective/dp/1107569788)
|
||
|
||
- tragedy of the commons
|
||
- polycentric governance
|
||
- social-ecological system framework
|
||
|
||
Pariès is the president of [Dédale](http://www.dedale.net/dedale_en/), a safety and human factors consultancy.
|
||
|
||
[Patterson](https://hrs.osu.edu/faculty-and-staff/faculty-directory/patterson-emily)
|
||
is a researcher who applies human factors engineering to improve patient safety
|
||
in healthcare.
|
||
|
||
Perrow is a sociologist who studied the Three Mile Island disaster. "Normal Accidents" is cited by numerous other influential systems engineering publications such as [Vaughan's](https://github.com#diane-vaughan) "The Challenger Launch Decision".
|
||
|
||
- Complex systems: A system of tightly-coupled components with common mode connections that is prone to unintended feedback loops, complex controls, low observability, and poorly-understood mechanisms. They are not always high-risk, and thus their failure is not always catastrophic.
|
||
- Normal accidents: Complex systems with many components exhibit unexpected interactions in the face of inevitable component failures. When these components are tightly-coupled, failed parts cannot be isolated from other parts, resulting in unpredictable system failures. Crucially, adding more safety devices and automated system controls often makes these coupling problems worse.
|
||
- Common-mode: The failure of one component that serves multiple purposes results in multiple associated failures, often with high interactivity and low linearity - both ingredients for unexpected behavior that is difficult to control.
|
||
- Production pressures and safety: Organizations adopt processes and devices to improve safety and efficiency, but production pressure often defeats any safety gained from the additions: the safety devices allow or encourage more risky behavior. As an unfortunate side-effect, the system is now also more complex.
|
||
|
||
Perry is a medical researcher who studies emergency medicine.
|
||
|
||
- Underground adaptations
|
||
- Articulated functions vs. important functions
|
||
- Unintended effects
|
||
- Apparent success vs real success
|
||
- Exceptions
|
||
- Dynamic environments
|
||
|
||
Jens Rasmussen was an enormously influential researcher in human factors and safety systems. In particular, you can see his influence in the work of Sidney Dekker, Nancy Leveson, David Woods.
|
||
|
||
Rasmussen proposed three models of human performance.
|
||
|
||
**Skill-based** behavior doesn't require conscious attention. The prototypical example is riding a bicycle.
|
||
|
||
**Rule-based** behavior is based on a set of rules that we have internalized in
|
||
advance. We select which rule to use based on experience, and then carry it
|
||
out. An example would be: if threads are blocked, restart the server. You can think of rule-based behavior as a memorized runbook.
|
||
|
||
**Knowledge-based** behavior comes into play when facing an unfamiliar
|
||
situation. The person generates a set of plans based on their understanding of
|
||
the environment, and then selects which one to use. The challenging incidents
|
||
are the ones that require knowledge-based behavior to resolve.
|
||
|
||
He also proposed three types of information that humans process as they perform work.
|
||
|
||
**Signals**. Example: weather vane
|
||
|
||
**Signs**. Example: stop sign
|
||
|
||
**Symbols**. Example: written language
|
||
|
||
Rasmussen proposed a model of how operators reason about the behavior of a
|
||
system they are supervising called the *abstraction hierarchy*.
|
||
The levels in the hierarchy are
|
||
|
||
1. functional purpose
|
||
2. abstract functions
|
||
3. general functions
|
||
4. physical funcitons
|
||
5. physical form
|
||
|
||
The hierarchy forms a means-ends relationship: proper function is described top-down (ends), and problems are explained bottom-up (means)
|
||
|
||
Rasmussen proposed a state-based model of a socio-technical system as a system that moves within a region of a state space. The region is surrounded by different boundaries:
|
||
|
||
- economic failure
|
||
- unacceptable work load
|
||
- functionality acceptable performance
|
||
|
||

|
||
|
||
|
||
Source: [Risk management in a dynamic society: a modelling problem](<https://doi.org/10.1016/S0925-7535(97)00052-0>)
|
||
|
||
Incentives push the system towards the boundary of acceptable performance: accidents happen when the boundary is exceeded.
|
||
|
||
The AcciMaps approach is a technique for reasoning about the causes of an accident, using a diagram.
|
||
|
||
Rasmussen proposed a multi-layer view of socio-technical systems:
|
||
|
||

|
||
|
||
|
||
Source: [Risk management in a dynamic society: a modelling problem](<https://doi.org/10.1016/S0925-7535(97)00052-0>)
|
||
|
||
- Dynamic safety model
|
||
- Migration toward accidents
|
||
- Risk management framework
|
||
- Boundaries:
|
||
- boundary of functionally acceptable performance
|
||
- boundary to economic failure
|
||
- boundary to unacceptable work load
|
||
- Cognitive systems engineering
|
||
- Skill-rule-knowledge (SKR) model
|
||
- AcciMaps
|
||
- Means-ends hierarchy
|
||
- Ecological interface design
|
||
- Systems approach
|
||
- Control-theoretic
|
||
- decisions, acts, and errors
|
||
- hazard source
|
||
- anatomy of accidents
|
||
- energy
|
||
- systems thinking
|
||
- trial and error experiments
|
||
- defence in depth (fallacy)
|
||
- Role of managers
|
||
- Information
|
||
- Competency
|
||
- Awareness
|
||
- Commitment
|
||
- Going solid
|
||
- observability
|
||
|
||
(These are written but others about Rasmussen's work)
|
||
|
||
- [Recurring themes in the legacy of Jens Rasmussen](https://www.sciencedirect.com/science/article/abs/pii/S0003687016302150?via%3Dihub) - special issue of Applied Ergonomics
|
||
- [Reflecting on Jens Rasmussen’s legacy. A strong program for a hard problem](https://doi.org/10.1016/j.ssci.2014.03.015) ([my notes](https://github.com/lorin/booknotes/blob/master/papers/Reflecting-on-Jens-Rasmussens-Legacy.md) )
|
||
- [Reflecting on Jens Rasmussen's legacy (2) behind and beyond, a ‘constructivist turn’](https://doi.org/10.1016/j.apergo.2015.07.013)
|
||
- [Musings on Models and the Genius of Jens Rasmussen](https://www.sciencedirect.com/science/article/abs/pii/S0003687015301009?via%3Dihub)
|
||
|
||
Rayo is the Director of the Cognitive Systems Engineering Laboratory at the Ohio State University.
|
||
|
||
- SCAD (Systematic Contributors Analysis and Diagram)
|
||
|
||
- [Developing Systemic Contributors and Adaptations Diagramming (SCAD): systemic insights, multiple pragmatic implementations](https://journals.sagepub.com/doi/10.1177/1071181322661334)
|
||
- [Multiple Systemic Contributors versus Root Cause: Learning from a NASA Near Miss](https://www.researchgate.net/publication/308194080_Multiple_Systemic_Contributors_versus_Root_Cause_Learning_from_a_NASA_Near_Miss)
|
||
- [The Silicon Valley Way: Move fast and break…aviation safety?](https://thebulletin.org/2025/05/the-silicon-valley-way-move-fast-and-breakaviation-safety/)
|
||
|
||
Reason is a psychology researcher who did work on understanding and categorizing human error.
|
||
|
||
Reason developed an accident causation model that is sometimes known as the *swiss cheese* model of accidents.
|
||
In this model, Reason introduced the terms "sharp end" and "blunt end".
|
||
|
||
Reason developed a model of the types of errors that humans make:
|
||
|
||
- slips
|
||
- lapses
|
||
- mistakes
|
||
|
||
- Blunt end
|
||
- Human error
|
||
- Slips, lapses and mistakes
|
||
- Swiss cheese model
|
||
|
||
[Reed](https://jpaulreed.com/) is a Senior Applied Resilience engineer at Netflix and runs [REdeploy](https://re-deploy.io), a conference focused on Resilience Engineering in the software development and operations industry.
|
||
|
||
Reed tweets as [@jpaulreed](https://twitter.com/jpaulreed).
|
||
|
||
- [Maps, Context, and Tribal Knowledge: On the Structure and Use of Post-Incident Analysis Artifacts in Software Development and Operations]([https://lup.lub.lu.se/student-papers/search/publication/8966930j](https://lup.lub.lu.se/student-papers/search/publication/8966930j)
|
||
- [Beyond the "Fix-it" Treadmill](https://queue.acm.org/detail.cfm?id=3380780d)
|
||
|
||
- [Blame "Aware"](https://jpaulreed.com/blame-aware) (versus "Blameless") Culture
|
||
- Postmortem Artifact *Archetypes*
|
||
|
||
[Roth](http://www.rothsite.com/resume.html) is a cognitive psychologist who
|
||
serves as the principal scientist at [Roth Cognitive Engineering](http://www.rothsite.com/), a small
|
||
company that conducts research and application in the areas of human factors
|
||
and applied cognitive psychology (cognitive engineering)
|
||
|
||
[Sarter](https://ioe.engin.umich.edu/people/nadine-sarter/) is a researcher in industrial and operations engineering.
|
||
She is the director of the Center for Ergonomics at the University of Michigan.
|
||
|
||
- cognitive ergonomics
|
||
- organization safety
|
||
- human-automation/robot interaction
|
||
- human error / error management
|
||
- attention / interruption management
|
||
- design of decision support systems
|
||
|
||
Scott is an anthropologist who also does research in political science. While
|
||
Scott is not a member of a resilience engineering community, his book *Seeing
|
||
like a state* has long been a staple of the cognitive systems engineering and
|
||
resilience engineering communities.
|
||
|
||
- authoritarian high-modernism
|
||
- legibility
|
||
- mētis
|
||
|
||
Shorrock is a chartered psychologist and a chartered ergonomist and human
|
||
factors specialist. He is the editor-in-chief of EUROCONTROL
|
||
[HindSight](https://www.skybrary.aero/index.php/HindSight_-_EUROCONTROL)
|
||
magazine. He runs the excellent [Humanistic Systems](https://humanisticsystems.com/) blog.
|
||
|
||
Shorrock tweets as [@StevenShorrock](https://twitter.com/StevenShorrock).
|
||
|
||
- [Systems Thinking for Safety: Ten Principles A White Paper Moving towards Safety-II](https://skybrary.aero/sites/default/files/bookshelf/2882.pdf)
|
||
- [Human Factors and Ergonomics in Practice: Improving System Performance and Human Well-Being in the Real World](https://www.crcpress.com/Human-Factors-and-Ergonomics-in-Practice-Improving-System-Performance-and/Shorrock-Williams/p/book/9781472439253) (book)
|
||
- [State of science: evolving perspectives on ‘human error’](https://doi.org/10.1080/00140139.2021.1953615)
|
||
|
||
[Life After Human Error](https://www.youtube.com/watch?v=STU3Or6ZU60) (Velocity Europe 2014 keynote)
|
||
|
||
Vaughan is a sociology researcher who did a famous study of the NASA Challenger accident, concluding that it was the result of organizational failure rather than a technical failure. Specifically, production pressure overrode the rigorous scientific safety culture in place at NASA.
|
||
|
||
- Structural Secrecy: Organizational structure, processes, and information exchange patterns can systematically undermine the ability to "see the whole picture" and conceal risky decisions.
|
||
- Social Construction of Risk: Out of the necessity to balance risk with the associated reward, any group of people will develop efficient heuristics to solve the problems they face. The understanding of risk that faces one subgroup may not match that of another subgroup or of the whole group. The ability of an individual to change a social construction of risk, formed over years with good intentions and often with evidence, is limited. (Though the evidence is usually accurate, the conclusion might not be, leading to an inadvertent scientific paradigm.)
|
||
- Normalization of Deviance: During operation of a complex system, inadvertent deviations from system design may occur and not result in a system failure. Because the intial construction of risk is usually conservative, the deviation is seen as showing that the system and its redundancies "worked", leading to a new accepted safe operating envelope.
|
||
- Signals of potential danger: Information gained through the operation of a system that may indicate the system does not work as designed. Most risk constructions are based on a comprehensive understanding of the operation of the system, so information to the contrary is a sign that the system could leave the safe operation envelope in unexpected ways - a danger.
|
||
- Weak signals, mixed signals, missed signals: signals of potential danger that have been interpreted as non-threats or acceptable risk because at the time they didn't represent a clear and present danger sufficient to overcome the Social Construction of Risk. Often, post-hoc, these are seen as causes due to cherry-picking - such signals were ignored before with no negative consequences.
|
||
- Competition for Scarce Resources: An ongoing need to justify investment to customers leads to Efficiency-Thoroughness Tradeoffs (ETTOs). In NASA's case, justifying the cost of the Space Shuttle program to taxpayers and their congressional representatives meant pressure to quickly develop payload delivery capability at the lowest cost possible.
|
||
- Belief in Redundancy: Constructing risk from a signal of potential danger such that a redundant subsystem becomes part of the normal operating strategy for a primary subsystem. In NASA's case, signals that the primary O-ring assembly did not operate as expected formed an acceptable risk because a secondary O-ring would contain a failure. Redundancy was eliminated from the design in this construction of risk - the secondary system now became part of the primary system, eliminating system redundancy.
|
||
|
||
[Turner](https://www.tandfonline.com/doi/pdf/10.1080/10245289508523441) was a sociologist who greatly influenced the field of organization studies.
|
||
|
||
[Wears](https://en.wikipedia.org/wiki/Robert_Wears) was a medical researcher who also had a PhD in industrial safety.
|
||
|
||
- Underground adaptations
|
||
- Articulated functions vs. important functions
|
||
- Unintended effects
|
||
- Apparent success vs real success
|
||
- Exceptions
|
||
- Dynamic environments
|
||
- Systems of care are intrinsically hazardous
|
||
|
||
[Woods](https://u.osu.edu/csel/member-directory/david-woods/) has a research background in cognitive systems engineering and did work
|
||
researching NASA accidents. He is one of the founders [Adaptive Capacity
|
||
Labs](http://www.adaptivecapacitylabs.com/), a resilience engineering
|
||
consultancy.
|
||
|
||
Woods tweets as [@ddwoods2](https://twitter.com/ddwoods2).
|
||
|
||
Woods has contributed an enormous number of concepts.
|
||
|
||
Woods uses *the adaptive universe* as a lens for understanding the behavior of
|
||
all different kinds of systems.
|
||
|
||
All systems exist in a dynamic environment, and must adapt to change.
|
||
|
||
A successful system will need to adapt by virtue of its success.
|
||
|
||
Systems can be viewed as units of adaptive behavior (UAB) that interact. UABs exist at different scales (e.g., cell, organ, individual, group, organization).
|
||
|
||
All systems have competence envelopes, which are constrained by boundaries.
|
||
|
||
The resilience of a system is determined by how it behaves when it comes near to a boundary.
|
||
|
||
See [Resilience Engineering Short Course](https://www.youtube.com/playlist?list=PLvlZBj1NU_ikTy1ot30EbEbYMAoBf9eAt) for more details.
|
||
|
||
- Trigger
|
||
- Units of adaptive behavior
|
||
- Goals and goal conflicts
|
||
- Pressure points
|
||
- Subcycles
|
||
|
||
From [The theory of graceful extensibility: basic rules that govern adaptive systems](https://www.researchgate.net/publication/327427067_The_Theory_of_Graceful_Extensibility_Basic_rules_that_govern_adaptive_systems):
|
||
|
||
(Longer wording)
|
||
|
||
1. Adaptive capacity is finite
|
||
2. Events will produce demands that challenge boundaries on the adaptive capacity of any UAB
|
||
3. Adaptive capacities are regulated to manage the risk of saturating CfM
|
||
4. No UAB can have sufficient ability to regulate CfM to manage the risk of saturation alone
|
||
5. Some UABs monitor and regulate the CfM of other UABs in response to changes in the risk of saturation
|
||
6. Adaptive capacity is the potential for adjusting patterns of action to handle future situations, events, opportunities and disruptions
|
||
7. Performance of a UAB as it approaches saturation is different from the performance of that UAB when it operates far from saturation
|
||
8. All UABs are local
|
||
9. There are bounds on the perspective any UAB, but these limits are overcome by shifts and contrasts over multiple perspectives.
|
||
10. Reflective systems risk mis-calibration
|
||
|
||
(Shorter wording)
|
||
|
||
1. Boundaries are universal
|
||
2. Surprise occurs, continuously
|
||
3. Risk of saturation is monitored and regulated
|
||
4. Synchronization across multiple units of adaptive behavior in a network is necessary
|
||
5. Risk of saturation can be shared
|
||
6. Pressure changes what is sacrificed when
|
||
7. Pressure for optimality undermines graceful extensibility
|
||
8. All adaptive units are local
|
||
9. Perspective contrast overcomes bounds
|
||
10. Mis-calibration is the norm
|
||
|
||
For more details, see [summary of graceful extensibility theorems](https://github.com/lorin/resilience-engineering/blob/master/graceful-extensibility.md).
|
||
|
||
(tbd)
|
||
|
||
Many of these are mentioned in Woods's [short course](https://www.youtube.com/playlist?list=PLvlZBj1NU_ikTy1ot30EbEbYMAoBf9eAt).
|
||
|
||
- adaptive capacity
|
||
- adaptive universe
|
||
- unit of adaptive behavior (UAB), adaptive unit
|
||
- continuous adaptation
|
||
- graceful extensibility
|
||
- sustained adaptability
|
||
- Tangled, layered networks (TLN)
|
||
- competence envelope
|
||
- adaptive cycles/histories
|
||
- precarious present (unease)
|
||
- resilient future
|
||
- tradeoffs, five fundamental
|
||
- efflorescence: the degree that changes in one area tend to recruit or open up beneficial changes in many other aspects of the network - which opens new opportunities across the network ...
|
||
- reverberation
|
||
- adaptive stalls
|
||
- borderlands
|
||
- anticipate
|
||
- synchronize
|
||
- proactive learning
|
||
- initiative
|
||
- reciprocity
|
||
- SNAFUs
|
||
- robustness
|
||
- surprise
|
||
- dynamic fault management
|
||
- software systems as "team players"
|
||
- multi-scale
|
||
- brittleness
|
||
- how adaptive systems fail (see: [How do systems manage their adaptive capacity to successfully handle disruptions? A resilience engineering perspective](https://www.researchgate.net/publication/286581322_How_do_systems_manage_their_adaptive_capacity_to_successfully_handle_disruptions_A_resilience_engineering_perspective) )
|
||
- decompensation
|
||
- working at cross-purposes
|
||
- getting stuck in outdated behaviors
|
||
- proactive learning vs getting stuck
|
||
- oversimplification
|
||
- fixation
|
||
- fluency law, veil of fluency
|
||
- capacity for manoeuvre (CfM)
|
||
- crunches
|
||
- turnaround test
|
||
- sharp end, blunt end
|
||
- adaptive landscapes
|
||
- law of stretched systems: Every system is continuously stretched to operate at capacity.
|
||
- cascades
|
||
- adapt how to adapt
|
||
- unit working hard to stay in control
|
||
- you can monitor how hard you're working to stay in control (monitor risk of saturation)
|
||
- reality trumps algorithms
|
||
- stand down
|
||
- time matters
|
||
- Properties of resilient organizations
|
||
- Tangible experience with surprise
|
||
- uneasy about the precarious present
|
||
- push initiative down
|
||
- reciprocity
|
||
- align goals across multiple units
|
||
- goal conflicts, goal interactions (follow them!)
|
||
- to understand system, must study it under load
|
||
- adaptive races are unstable
|
||
- adaptive traps
|
||
- roles, nesting of
|
||
- hidden interdependencies
|
||
- net adaptive value
|
||
- matching tempos
|
||
- tilt toward florescence
|
||
- linear simplification
|
||
- common ground
|
||
- problem detection
|
||
- joint cognitive systems
|
||
- automation as a "team player"
|
||
- "new look"
|
||
- sacrifice judgment
|
||
- task tailoring
|
||
- substitution myth
|
||
- observability
|
||
- directability
|
||
- directed attention
|
||
- inter-predictability
|
||
- error of the third kind: solving the wrong problem
|
||
- buffering capacity
|
||
- context gap
|
||
- Norbert's contrast
|
||
- anomaly response
|
||
- automation surprises
|
||
- disturbance management
|
||
- Doyle's catch
|
||
- Cooperative advocacy
|
||
|
||
- [Cognitive Systems Engineering Laboratory's (CSEL) Resilience Engineering 101 Series](https://resiliencefoundations.github.io/video-1-introduction-pt-1-it's-all-about-viability.html)
|
||
- [Resilience Engineering: An Introductory Short Course](https://www.youtube.com/playlist?list=PLvlZBj1NU_ikTy1ot30EbEbYMAoBf9eAt)
|
||
|
||
Wreathall is an expert in human performance in safety. He works at the
|
||
[WreathWood Group](http://www.wreathall.com/), a risk and safety studies
|
||
consultancy.
|
||
Wreathall tweets as [@wreathall](https://twitter.com/wreathall).
|