Skip to content

Safety, Risk & Systems

9 domain-specific abstractions whose origin domain is Safety, Risk & Systems.

  • Active Failure — The frontline operator's act at the sharp end that completes a hazard path by aligning with holes latent conditions had pre-positioned in a system's layered defenses — the proximate, visible half of Reason's Swiss cheese model.
  • Black Elephant — A high-impact hazard that is widely known and clearly foreseeable yet collectively ignored until it materialises as a disaster narrated as a surprise — foreseeable-but-unowned, failing at the incentive layer, not the knowledge layer.
  • Grey Swan — A high-impact event whose category is foreseeable and reasoned about in advance but whose specific timing, magnitude, and form are unpredictable — the intermediate cell that calls for scenario planning and stress testing, not antifragility or actuarial insurance.
  • HAZOP Guideword Miss — The structural failure in which a HAZOP's finite guideword-times-parameter-times-node grid never generates the deviation that later causes an incident, because the hazard fell outside the schema's coverage boundary and was never identified, safeguarded, or risk-assessed.
  • Latent Condition — Name the dormant, pre-staged weakness in a system's defence layers — laid down by upstream decisions far from the sharp end — that produces no harm until an operational circumstance aligns it with an active failure to complete a path to an accident.
  • Latent-Path Activation — Explain harm that arrives while every factor is individually in-range as a previously inert causal path going live only when a rare conjunction of gating states closes every edge along it at once.
  • Operator-Vigilance Dependency — Name the safety configuration in which a human operator's unaided sustained attention is the final live barrier against a severe hazard, under exactly the monotony and rarity that the vigilance literature says will degrade that attention — worsened, not helped, by more upstream automation.
  • Organizational Influence Failure — The accident-causation configuration in which upper-level resource, culture, and process decisions systematically stage the downstream conditions under which frontline operators produce unsafe acts — the apex of the HFACS four-level hierarchy, reclassifying the visible failure as the expression of an upstream choice rather than its cause.
  • Precondition for Unsafe Act — Name the immediate situational, personal, and team conditions — fatigue, distraction, a steep authority gradient — that raise the probability of frontline operator error, a distinct HFACS layer between upstream supervision and the unsafe act itself.