Precondition for Unsafe Act¶
Name the immediate situational, personal, and team conditions — fatigue, distraction, a steep authority gradient — that raise the probability of frontline operator error, a distinct HFACS layer between upstream supervision and the unsafe act itself.
Core Idea¶
A precondition for unsafe act is the HFACS layer that sits between the organisational and supervisory layers above it and the unsafe act immediately below it, naming the immediate situational, personal, and team conditions that substantially elevate the probability of frontline operator error at the moment of action. The structural commitment is that operator reliability is not a fixed property of skill and intent but a function of the state the operator and team are in immediately before acting: HFACS partitions the layer into conditions of the operator — adverse mental states (fatigue, complacency, task saturation, distraction), adverse physiological states (hypoxia, illness, medication effect), and physical or mental limitations (reduced vision, working-memory ceiling) — and personnel factors — crew-resource-management failures (communication breakdown, unhelpful authority gradient, failure to cross-check) and personal readiness failures (training-currency gaps, insufficient rest). The analytical force of naming the layer is the decoupling of operator state from operator action: a fatigued surgeon operating safely and a rested surgeon committing an error are both within the layer's descriptive range, because the precondition is the probabilistic elevation of error risk, not the determination of a specific outcome. Naming the layer also makes the causal trace explicit — preconditions are produced by the unsafe-supervision decisions and organisational-influence choices upstream, not by the operator — and it licenses countermeasures targeted at this layer specifically: fatigue-risk-management systems, sterile-cockpit rules, structured handover protocols, and CRM curricula each act at the precondition layer without requiring re-engineering of the organisational layer above or retraining of the unsafe act below. Shappell and Wiegmann developed HFACS from Reason's Swiss-cheese model for naval aviation mishap analysis; it has since been applied in medicine (HFACS-medical), nuclear operations, and finance operations with the layer structure intact.
Structural Signature¶
Sig role-phrases:
- the operator-and-team — the frontline agent(s) whose immediate state, not skill or intent alone, sets reliability at the moment of action
- the five-slot typology — the HFACS bins any finding lands in: adverse mental state, adverse physiological state, physical/mental limitation, CRM failure, personal readiness
- the two sub-layers — condition of operators (the individual's internal state) and personnel factors (team and individual-readiness factors)
- the probability-shift reading — a precondition records an elevated likelihood of error, not the error itself; a fatigued surgeon who operates safely and a rested one who errs both sit in range
- the immediacy — present at the moment of action, the test that separates a precondition from a latent condition emplaced months earlier (even when both involve, say, staffing)
- the upstream-causal trace — preconditions are produced by the unsafe-supervision and organisational-influence layers above, not by the operator
- the layer-attribution cut — the framework's reason for existing: was the breakdown a condition the operator was in, the act taken, or an arrangement laid down upstream — three things "human error" fuses into one
- the slot-indexed countermeasure — the fix is keyed to the slot (fatigue-risk management for adverse physiological; sterile-cockpit rules for distraction; structured handovers/CRM for personnel factors), and a fix aimed at the act below or organisation above will not move this slope
What It Is Not¶
- Not the unsafe act itself. A precondition is the state the operator and team are in immediately before acting, not the action taken — they are adjacent layers, and the framework's whole leverage is decoupling operator state from operator action. The act sits one layer below; collapsing the two loses the distinction the layer exists to draw.
- Not a determinant of the error. A precondition records an elevated probability of error, not the error: a fatigued surgeon who operates safely and a rested one who errs both sit coherently inside the layer's range. When harm does occur, the preconditions enabled it (raised its odds), not directly caused it — reading the slot as a verdict on the operator mistakes a likelihood shift for a cause.
- Not a latent condition. The immediacy test separates them: a precondition is present at the moment of action, whereas a latent condition was emplaced months earlier, far from the harm in time and organisational distance. The test sorts the two even when both involve, say, staffing — fatigue in the room now is a precondition; the staffing policy that produced it is the latency upstream.
- Not unsafe supervision. Supervision is the layer above that, together with organisational influences, produces the precondition; it concerns supervisor-level decisions, not operator-level state. The originating scheduling or pairing decision lives in the supervision layer; the fatigue or unfamiliar-crew state it creates lives here.
- Not a finding that blames the operator. Operator state is held apart from operator action precisely so the breakdown is read as a condition rather than a culpable choice, and preconditions are traced upstream to the supervision and organisation that manufactured them — not attributed to the person who happened to be acting. The layer is part of the move away from "human error" verdicts, not an instance of one.
- Not context-dependence in the general sense. It is the HFACS specialization of that pattern for operator error in safety-managed systems — a five-slot typology with slot-indexed countermeasures — not the substrate-independent fact that effects depend on surrounding context. Strip the typology and what remains is the general parent applied to action under risk; the predictive slot-to-remedy content is exactly what the home apparatus adds.
Scope of Application¶
The precondition layer lives across the accident-investigation subfields of safety and human-factors practice; its reach is within that domain — the substrate-class of safety-managed sociotechnical systems with frontline operators under high consequence — and beyond it the bare proposition "the actor's surrounding state shifts error probability" loses the slot-indexed diagnostics and reverts to its parents context_dependence, cognitive_load, attention, and state. The five-slot HFACS typology applies unchanged across the canonical applications below.
- Aviation safety — HFACS's birthplace (Shappell and Wiegmann): the precondition layer classifies fatigue, unfamiliar crew pairing, new-to-type status, and authority-gradient findings in mishap investigation.
- Healthcare and patient safety — HFACS-medical for adverse-event investigation, where surgeon fatigue, team unfamiliarity, distracting environment, and hierarchical pressure are the operative preconditions.
- Nuclear and process safety — incident analysis classifying the operator conditions (fatigue, distraction, limitation) immediately preceding the active failure.
- Financial operations — the less-canonical adaptation for operator-error analysis in trading and middle-office work (fatigue, distraction, poor handoff at the moment of action).
Clarity¶
Naming this layer gives the investigator a place to put findings that otherwise have nowhere to go. A long shift, an unfamiliar team pairing, a steep authority gradient, a distracting environment — without the layer these read as colour around the "real" cause, the operator's action, and tend to be folded into a blame verdict or dropped entirely. Calling them preconditions makes them a distinct, classifiable stratum between the supervision that produced them and the act they enabled, with defined slots (adverse mental state, adverse physiological state, physical or mental limitation, CRM failure, personal readiness) into which any specific finding lands. The breakdown becomes legible as a probability shift in operator reliability rather than as a near-miss explanation for what the operator did.
That stratification sharpens the layer-attribution question the framework lives to make answerable: was this a condition the operator was in, the act the operator took, or an arrangement the organisation laid down months earlier — three things an undifferentiated "human error" finding collapses into one. Pinning the breakdown to the precondition layer tells the practitioner that the corrective belongs there too — fatigue-risk management, sterile-cockpit rules, structured handovers, CRM curricula — and, equally, that a fix aimed at the act below (retrain the operator) or the organisation above (re-engineer staffing) will not move a slope whose driver is immediate operator-and-team state. The sharper question is no longer "did the operator err?" but "what state were the operator and team in that raised the odds of an error here, and is our countermeasure aimed at that state or at the wrong layer?"
Manages Complexity¶
The sprawl this layer tames is the effectively unbounded list of things that can be "going on" with an operator and team at the moment of action. Anything might be relevant — how long the surgeon has been awake, whether the resident is new to the service, how the scrub tech came to be in the room, the lighting, the noise, the steepness of the authority gradient, a head cold, a missed meal, an unfamiliar crew pairing — and across thousands of incident reports this open list never repeats in the same configuration, so an investigator working without structure faces a fresh, idiosyncratic situational description each time and no way to compare one case's circumstances with another's. The concept compresses this by mapping that open space onto a small, fixed, validated typology: two sub-layers — condition of operators and personnel factors — resolving into five slots: adverse mental state, adverse physiological state, physical or mental limitation, CRM failure, and personal readiness. Any specific finding, however particular, lands in one of these slots. The sprawling "what was going on" collapses to a five-way classification, and because the slots are stable across investigations, individually irreproducible situational details become comparable tokens that support cross-incident pattern mining — the same fatigue slot filled in a thousand reports is now a countable, trendable quantity rather than a thousand separate stories.
What the analyst tracks per finding is therefore just two things: which HFACS layer it belongs to, and within this layer, which of the five slots it fills. And the typology's defining commitment fixes how each finding is read: a precondition is a probability shift in operator reliability, not a determinant of the act. So a fatigued surgeon who operates safely and a rested surgeon who errs both sit coherently inside the layer's descriptive range — the layer records the elevated odds, not the realised outcome — and the analyst reads off the contribution of operator-and-team state as a likelihood adjustment rather than as a near-miss explanation of what was done. This decoupling is what keeps the slot a condition and not a verdict on the operator, and it is read directly off the typology rather than re-litigated for each case.
The branch structure the concept supplies is a layer cut followed by a slot cut, and each cut decides where the corrective belongs. The layer cut answers the attribution question the framework exists to make answerable: was the breakdown a condition the operator was in (this layer), the act the operator took (the layer below), or an arrangement the organisation laid down upstream (the layers above) — three things an undifferentiated "human error" finding fuses into one. Placing the finding at the precondition layer tells the practitioner that the fix belongs at this layer too, and equally that a remedy aimed at the act below (retrain the operator) or the organisation above (re-engineer staffing) cannot move a slope whose driver is immediate operator-and-team state. The slot cut then selects the specific countermeasure, because the established interventions are slot-indexed: fatigue-risk-management systems and rest regulation for adverse physiological state, sterile-cockpit rules for distraction-class adverse mental states, structured handover protocols and CRM curricula for personnel-factor slots. The analyst reads the intervention off the slot rather than improvising one per incident. So in place of an idiosyncratic, unbounded situational narrative, the investigator holds a five-slot typology, two coordinates per finding, and one fixed reading (probability shift, not cause) — and reads off which layer owns the breakdown, which countermeasure the slot calls for, and whether a proposed fix is aimed at the right layer at all. A high-dimensional, case-unique description of "operator state" becomes a small bounded classification with a definite branch structure and slot-indexed remedies.
Abstract Reasoning¶
The first characteristic move is diagnostic with a probabilistic, not deterministic, reading. From a finding about operator-and-team state — nineteen hours awake, a resident new to the service, a scrub tech pulled mid-case — infer an elevated probability of error, and crucially do not infer the error itself. The layer's defining commitment makes the inference shape unusual: a precondition is a likelihood shift, so a fatigued surgeon who operates safely and a rested one who errs are both within range, and the analyst reasons FROM "these conditions obtained immediately before action" TO "the odds of an unsafe act were raised here," never FROM "an error occurred" TO "fatigue caused it." This is what keeps the slot a condition and not a verdict: when a retained-object event does occur, the preconditions are read as having enabled it (raised its probability) rather than as having directly caused it.
The second move is interventionist with a slot-indexed remedy. Because the established countermeasures are keyed to the five HFACS slots, classifying a finding selects the fix: the analyst reasons FROM "this finding fills the adverse-physiological-state slot (fatigue)" TO "fatigue-risk-management and rest regulation are the indicated countermeasures," FROM "this is a distraction-class adverse mental state" TO "sterile-cockpit / sterile-field rules during critical phases," and FROM "this is a personnel-factor slot (unfamiliar pairing, communication breakdown)" TO "structured handover protocols and CRM curricula." Each is a prediction that acting at the precondition layer lowers the error-probability slope without re-engineering the organisation above or retraining the operator below — and the layer makes the matching negative prediction explicit: a remedy aimed at the act (discipline the operator) or the organisation (restructure staffing) will not move a slope whose driver is immediate operator-and-team state.
The third move is boundary-drawing, and the framework lives to make one specific boundary decidable: the layer-attribution cut. Faced with a contributing factor, the analyst asks whether it is a condition the operator was in (this layer), the act the operator took (the layer below), or an arrangement the organisation laid down upstream — three things an undifferentiated "human error" finding fuses into one, and the cut tells the practitioner which layer owns the breakdown and therefore where the corrective belongs. A second boundary is immediacy: a precondition is a condition present at the moment of action, which distinguishes it from a latent condition emplaced months earlier far from the harm — temporal proximity is the test that sorts a precondition from the latent stratum even when both involve, say, staffing. The concept also supports an upstream-causal-trace inference and an order-of-events reading: preconditions are produced by the unsafe-supervision and organisational-influence layers above, not by the operator, so the analyst can trace from a fatigue precondition back to the scheduling decision and the case-volume target that manufactured it, and can predict that leaving those upstream layers intact will keep regenerating the same precondition. Finally the boundary marks the limit of the layer's home range: within safety-managed sociotechnical systems the five-slot typology carries the predictive force, while outside it the bare statement "the actor's surrounding state shifts error probability" loses the slot-indexed diagnostics and dissolves into more general notions of context and operator state.
Knowledge Transfer¶
Within safety and human-factors practice the precondition layer transfers as mechanism, completing the HFACS quartet alongside organisational influence, unsafe supervision, and the unsafe act, and its transfer among the canonical four substrates is documented and direct. HFACS originated in naval aviation (Shappell and Wiegmann) and was adapted as HFACS-medical for adverse-event investigation, into nuclear incident analysis, and (less canonically) into trading and middle-office operator-error work, with the layer structure intact throughout. Across all four the same five-slot typology applies unchanged — adverse mental state, adverse physiological state, physical/mental limitation, CRM failure, personal readiness — and so do the layer's distinctive analytic commitments: the probability-shift-not-cause reading (a fatigued surgeon who operates safely and a rested one who errs both sit inside the layer's range, because it records elevated odds, not a realised outcome), the immediacy test that separates a precondition present at the moment of action from a latent condition emplaced months earlier (the test that sorts the two even when both involve staffing), the upstream-causal trace back to the supervision and organisational decisions that produced the precondition, and above all the slot-indexed countermeasures — fatigue-risk-management and rest regulation for the adverse-physiological slot, sterile-cockpit/sterile-field rules for distraction-class adverse mental states, structured handover protocols and CRM curricula for the personnel-factor slots. These carry without modification because, by the framework's own account, the four "domains" are not independent substrates running one mechanic but four applications of one framework to a single substrate-class: safety-managed sociotechnical systems with frontline operators under high consequence.
Beyond that substrate-class the honest report is clean (B). The general pattern the layer instantiates — the contextual state of the actor and team shifts the probability of error — is genuinely recognisable everywhere, but it is not the precondition layer that travels; it is the catalog parents the layer specialises: context_dependence (the substrate-independent fact that a thing's effect depends on its surrounding context, here applied to action under risk) together with cognitive_load, attention, and state in their general senses, which supply the specific factors the typology bins rather than the typology itself. Any cross-domain lesson about how operator-and-team state raises error odds should be carried by those parents. What stays home-bound is the precondition layer's own cargo: the five-slot HFACS typology calibrated to operator error in safety-managed systems, the layered Swiss-cheese scheme that fixes the layer-attribution cut (condition-the-operator-was-in versus act-taken versus arrangement-laid-down-upstream), the immediacy boundary against latent conditions, and the slot-indexed intervention vocabulary — none of which has diagnostic force outside a managed-safety practice with frontline operators. Strip the typology and what remains is context_dependence plus state applied to action under risk; the predictive, slot-to-countermeasure content is exactly what the home apparatus adds and exactly what does not generalize. So: full mechanistic portability across the safety-managed sociotechnical substrate-class (the four canonical applications), with the substrate-independent core owned by context_dependence / cognitive_load / attention / state, and no distinctive cross-substrate transfer of the layer-as-named. (This entry is the structural sibling of active_failure, latent_condition, and organizational_influence_failure: latent conditions pre-position the holes, preconditions raise the probability that the operator's action aligns with them, and the active failure completes the path.) See Structural Core vs. Domain Accent.
Examples¶
Canonical¶
Consider how HFACS reads the 1977 Tenerife runway collision, the deadliest accident in aviation history: in dense fog at Los Rodeos, a KLM 747 began its takeoff roll and struck a Pan Am 747 still taxiing on the runway, killing 583. The unsafe act was starting the roll without takeoff clearance. But the precondition layer names the operator-and-team conditions that raised the odds of exactly that act: fog that eliminated visual confirmation (a physical limitation), schedule and duty-time pressure weighing on the captain (an adverse mental state), and — decisively — a steep authority gradient, with the KLM flight engineer and first officer voicing doubt about clearance yet not forcefully halting a senior, revered chief training pilot (a crew-resource-management personnel factor). None of these determined the collision; each raised its probability.
Mapped back: The KLM cockpit crew is the operator-and-team whose immediate state, not skill, set reliability. Fog, time pressure, and the unchallenged authority gradient fill three cells of the five-slot typology (physical limitation, adverse mental state, CRM personnel factor). That none of them "caused" the crash but each lifted its odds is the probability-shift reading, and separating these conditions from the takeoff-without-clearance act is the layer-attribution cut.
Applied / In Practice¶
Patient-safety practice imported the precondition framing directly, via HFACS-medical and the operating-room "sterile cockpit." The clearest slot-indexed countermeasure is the WHO Surgical Safety Checklist, which mandates a team briefing before incision — confirming identities, roles, allergies, and anticipated problems — precisely to flatten the authority gradient and repair the communication breakdowns that are personnel-factor preconditions. In a landmark eight-hospital study, Haynes and colleagues (2009, NEJM) found that introducing the checklist was associated with a drop in major inpatient complications from 11% to 7% and in inpatient death from 1.5% to 0.8%. The intervention did not retrain surgeons or restructure hospitals; it acted at the precondition layer, on the immediate team state before the critical act — exactly where the framework says a fix aimed at that slot, rather than at the act below or the organisation above, will move the error-probability slope.
Mapped back: The surgical team is the operator-and-team; poor communication and steep hierarchy are personnel-factor cells of the five-slot typology. The pre-incision briefing is the slot-indexed countermeasure (structured handover / CRM for the personnel-factor slots). That the checklist works without retraining operators or re-engineering the hospital confirms the layer-attribution cut — the corrective belongs at the precondition layer, and the measured complication drop is the predicted downward shift in the error-probability slope.
Structural Tensions¶
T1: Probability-shift reading versus actionable attribution (the honesty that also frustrates). The layer's defining commitment is that a precondition raises error odds without determining the act — a fatigued surgeon who operates safely and a rested one who errs both sit in range. This is analytically honest and it protects the operator from a blame verdict. But an investigator, a regulator, or a bereaved family often needs a causal statement, not a likelihood adjustment, and "the fatigue raised the probability" can read as evasion where "the fatigue caused it" would satisfy. The very refusal to convert a condition into a cause — the discipline that keeps the slot a condition and not a verdict — is what makes the finding hard to act on when accountability, compensation, or a legal standard demands a determinate cause. Diagnostic: Does this forum need a calibrated odds-shift, or a determinate cause the probability-shift reading will refuse to supply?
T2: Fixed five-slot typology versus residual novelty (the bins that enable comparison also flatten). The typology's power is that any idiosyncratic situational detail lands in one of five slots, turning a thousand unique stories into countable, trendable tokens for cross-incident pattern mining. But comparability is bought by discarding what did not fit the bin. A precondition that is genuinely two-slot in character — fatigue entangled with a distraction that only fatigue made dangerous — is recorded as one token or split into two, and the interaction that was the real story disappears into the classification. The same forced binning that makes fatigue countable across a thousand reports can homogenize a novel operator-and-team state into the nearest available slot, so trend mining sees a familiar pattern where something new was actually happening. Diagnostic: Does this finding sit cleanly in one slot, or is the typology absorbing an interaction or a genuinely new condition into a bin that loses it?
T3: Layer autonomy versus causal continuity (the clean cut that also severs the chain). The layer-attribution cut is the framework's reason to exist: was the breakdown a condition, an act, or an upstream arrangement — three things "human error" fuses into one. Separating the layers is what tells the practitioner where the corrective belongs. Yet the strata are not really independent; the layer itself insists preconditions are produced by the supervision and organisation above and enable the act below. Treat the precondition layer as the place to fix, and you may install a sterile-cockpit rule that suppresses the visible fatigue while the scheduling policy that manufactures it keeps regenerating the condition. The cut that localizes the remedy can also amputate the causal chain, licensing a fix at the enabling layer while the generating layer runs on. Diagnostic: Is the precondition layer where this breakdown should be fixed, or only where it is most visible while its upstream generator survives?
T4: Slot-indexed countermeasure versus over-mechanization (the ready remedy that skips diagnosis). Because countermeasures are keyed to slots — fatigue-risk management for the physiological slot, sterile-cockpit for distraction, CRM for personnel factors — classifying a finding selects the fix, sparing the analyst from improvising one per incident. That is a real economy, and it is also a temptation to let the slot do the thinking. Once a finding is dropped into the adverse-physiological slot, the indicated rest regulation follows automatically even if the fatigue in this case was a symptom of an illness the physiological slot does not name, or a workload the CRM remedy will not touch. The catalog of slot-to-remedy mappings can turn diagnosis into lookup, deploying a validated countermeasure at the right layer for the wrong reason. Diagnostic: Is the slot-indexed remedy addressing what actually raised the odds here, or being applied reflexively because the finding fell into its slot?
T5: Immediacy boundary versus continuous latency (the temporal test that draws a line through a gradient). The immediacy test separates a precondition present at the moment of action from a latent condition emplaced months earlier — the test that sorts the two even when both involve staffing. Crisp and useful, but time is continuous, and the distance from "the fatigue in the room now" to "the scheduling policy that produced it" is a gradient, not a gap. A chronic understaffing that has left the operator persistently under-rested for a year is neither cleanly immediate nor cleanly latent; the boundary forces a placement that shapes which layer owns the fix. Draw the line early and a slow-building condition is misfiled as a momentary state; draw it late and a genuine precondition is exiled upstream where the slot-indexed remedy will not reach it. Diagnostic: Is this condition genuinely present-at-the-moment, or a latency that has crept close enough to the act to be mistaken for one?
T6: Autonomy versus reduction (its own HFACS layer or the safety instance of its parents). "Precondition for unsafe act" is a validated, named HFACS layer with proprietary equipment — the five-slot typology, the immediacy test, the layer-attribution cut, the slot-indexed intervention vocabulary — and that equipment carries as mechanism across the canonical safety substrates (aviation, medicine, nuclear, finance ops), because those are four applications of one framework to a single substrate-class, not four independent substrates. But strip the typology and what remains is context_dependence (an effect depends on surrounding context) plus cognitive_load, attention, and state supplying the specific factors the slots bin. Any cross-domain lesson about how an actor's state raises error odds is carried by those parents, not by the named layer, which has no diagnostic force outside a managed-safety practice. The tension is between a standalone HFACS layer that repays its own study inside safety work and the recognition that its substrate-independent cargo already belongs to context-dependence and state. Diagnostic: Resolve toward the parents when asking what carries outside safety-managed systems; toward the precondition layer when diagnosing operator-and-team state before a high-consequence act.
Structural–Framed Character¶
Precondition for unsafe act sits on the framed side of the spectrum — best read as framed-leaning: a practice-constituted analytical layer of a specific accident-investigation framework, though one built over a real, observer-independent fact about operator error. Three criteria point framed. Its evaluative weight is present but unusual: the layer is a classification within a safety-improvement enterprise, yet its defining commitment is explicitly not to blame — it reads a slot as a probability-shifting condition, not a culpable act, and is part of the move away from "human error" verdicts. So it carries the normative pull of a safety practice while deliberately withholding the operator-blame verdict. It is human-practice-bound: the layer exists only within a safety-managed sociotechnical system with frontline operators, an investigative apparatus that classifies and remediates — remove that practice and there is no "precondition layer," only the bare fact that fatigue raises error odds. Its institutional origin is pronounced: the five-slot typology, the immediacy test, the layer-attribution cut, and the Swiss-cheese scheme are HFACS furniture (Shappell and Wiegmann, from Reason), and vocab_travels fails beyond safety-managed systems. The structural-pulling marks are that the underlying phenomenon is real and observer-independent (an operator's state genuinely shifts error probability whether or not it is classified) and that import_vs_recognize runs to genuine parents: the general pattern recurs and is carried by catalog primes, recognized rather than borrowed.
The portable structural skeleton is context_dependence — the substrate-independent fact that an effect depends on surrounding context, here that an actor-and-team's immediate state shifts the probability of error — with cognitive_load, attention, and state supplying the specific factors the five slots bin. That skeleton (plus its factor-primes) is exactly what the layer specializes, not what makes "precondition for unsafe act" travel: the cross-domain reach belongs to context-dependence and state, while the five-slot HFACS typology, the immediacy boundary, the layer-attribution cut, and the slot-indexed countermeasures are the safety-practice accent that stays home. Its character: a practice-constituted, HFACS-institutional accident-investigation layer built over a real state-shifts-error-probability fact, structural only in the context-dependence-plus-state parents it specializes, its five-slot typology and layer machinery having no diagnostic force outside a managed-safety practice — framed-leaning, not a prime.
Structural Core vs. Domain Accent¶
This section decides why "precondition for unsafe act" is a domain-specific abstraction and not a prime — marking where the portable context-dependence skeleton ends and the HFACS accident-investigation machinery begins.
What is skeletal (could lift toward a cross-domain prime). Strip the safety-investigation framework and a thin relational structure survives: the immediate surrounding state of an actor and its team shifts the probability of error at the moment of action — reliability is a function of the state one is in, not a fixed property of skill or intent. The portable pieces are abstract — an actor whose output depends on context, a set of state factors that raise or lower error odds, and a probabilistic (not deterministic) coupling between state and outcome. This is context_dependence (the substrate-independent fact that an effect depends on its surrounding context, here applied to action under risk), with cognitive_load, attention, and state supplying the specific factors the typology bins. The skeleton is genuinely substrate-portable — that an actor's state shifts error odds is recognizable everywhere — which is why the entry names those parents as what actually carries any cross-domain lesson. That portable core is what the precondition layer specializes, not what makes it a precondition for unsafe act.
What is domain-bound. Almost everything that makes the construct this layer is HFACS accident-investigation furniture and none of it survives extraction: the five-slot typology (adverse mental state, adverse physiological state, physical/mental limitation, CRM failure, personal readiness) with its two sub-layers; the immediacy test that separates a precondition from a latent condition emplaced months earlier; the layer-attribution cut within the Swiss-cheese scheme (condition-the-operator-was-in versus act-taken versus arrangement-laid-down-upstream); the upstream-causal trace to supervision and organisational influence; and above all the slot-indexed countermeasure vocabulary (fatigue-risk management, sterile-cockpit rules, structured handovers, CRM curricula). These are the worked apparatus, the diagnostics, and the empirical cases (Tenerife, the WHO surgical checklist) the practice uses. The decisive test: strip the typology and what remains is context_dependence plus state applied to action under risk — the predictive, slot-to-countermeasure content that gives the layer diagnostic force is exactly what the HFACS apparatus adds, and it has no such force outside a managed-safety practice with frontline operators.
Why this does not clear the prime bar. A prime is a relational structure whose vocabulary travels and whose cross-domain transfer is recognition of the same mechanism, not analogy. The precondition layer's transfer is bimodal. Within safety and human-factors practice it travels as full mechanism — the five-slot typology, the probability-shift reading, the immediacy test, the upstream trace, and the slot-indexed countermeasures carry unchanged across aviation, medicine (HFACS-medical), nuclear, and finance operations, because those are four applications of one framework to a single substrate-class (safety-managed sociotechnical systems with frontline operators under high consequence), not four independent substrates: genuine recognition of one layer. Beyond that substrate-class the layer-as-named does not travel: the bare proposition "the actor's surrounding state shifts error probability" is recognizable everywhere, but it is the parents that recur, not the HFACS layer with its typology and slot-remedies. And when the bare structural lesson is needed cross-domain — an actor-and-team state raising error odds — it is already carried, in more general form, by context_dependence (with cognitive_load, attention, state). The cross-domain reach belongs to those parents; "precondition for unsafe act," as named, carries the five-slot typology, immediacy boundary, layer-attribution cut, and slot-indexed remedies that stay home in managed-safety practice.
Relationships to Other Abstractions¶
Current abstraction Precondition for Unsafe Act Domain-specific
Parents (2) — more general patterns this builds on
-
Precondition for Unsafe Act presupposes Swiss Cheese Model (Layered Defense with Aligning Holes) Prime
The HFACS precondition stratum presupposes the Swiss-cheese layered model that distinguishes an operator's immediate state from the active act below and latent organizational holes above.Immediate fatigue, distraction, limitation, crew state, and readiness become this named stratum only inside a layered accident-causation analysis. The Swiss-cheese model supplies the path, defensive layers, latent/active split, and anti-blame trajectory; HFACS refines it with the precondition slots.
-
Precondition for Unsafe Act is a decomposition of Context Prime
A precondition for unsafe act is context specialized to the immediate operator-and-team surround that changes what a fixed capability or action does by shifting the probability of error at the sharp end.The focal foreground is the operator's skill or contemplated act; the surround is fatigue, physiological state, physical limitation, distraction, crew coordination, and readiness; and performance is jointly determined by the pair. The HFACS child adds a five-slot taxonomy, immediacy test, upstream trace, and slot-indexed safety remedies to the live prime's fixed-foreground, variable-surround relation.
Children (1) — more specific cases that build on this
-
Human Factors Analysis and Classification System Domain-specific is part of Precondition for Unsafe Act
Preconditions for unsafe acts are the third constituent stratum of HFACS.Remove the precondition stratum and HFACS can no longer separate the operator's immediate probability-shifting state from the act itself. parent_in_child
Hierarchy paths (26) — routes to 10 parentless roots
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Conjunctive Path Activation → Causality → Dependency
- Precondition for Unsafe Act → Context
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Self Checking
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Self Checking
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Reserve → Mobilization → Latent Realizable Capacity
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Optimization
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Heavy-Tailed Distributions
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Reserve → Mobilization → Latent Realizable Capacity
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Optimization
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Recurrence
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Reserve → Economy Of Force → Allocation → Scarcity → Constraint
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Heavy-Tailed Distributions
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Reserve → Mobilization → Latent Realizable Capacity
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Recurrence
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Reserve → Economy Of Force → Allocation → Scarcity → Constraint
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Reserve → Mobilization → Latent Realizable Capacity
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Spatial Indexing → Search and Retrieval → Trade-offs → Constraint
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Reserve → Economy Of Force → Allocation → Scarcity → Constraint
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Spatial Indexing → Search and Retrieval → Problem Space → Representation → Abstraction
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Spatial Indexing → Search and Retrieval → Trade-offs → Constraint
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Reserve → Economy Of Force → Allocation → Scarcity → Constraint
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Spatial Indexing → Search and Retrieval → Problem Space → State and State Transition → Phase Space
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Spatial Indexing → Search and Retrieval → Problem Space → Representation → Abstraction
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Spatial Indexing → Search and Retrieval → Problem Space → Problem Representation → Representation → Abstraction
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Spatial Indexing → Search and Retrieval → Problem Space → State and State Transition → Phase Space
- Precondition for Unsafe Act → Swiss Cheese Model (Layered Defense with Aligning Holes) → Defense In Depth → Redundancy → Two-Store Architecture → Caching → Locality Of Reference → Spatial Indexing → Search and Retrieval → Problem Space → Problem Representation → Representation → Abstraction
Not to Be Confused With¶
-
Unsafe act / active failure. The action itself — the error or violation the operator commits at the sharp end (starting the takeoff roll without clearance). The precondition is the state that raised the odds of that act, sitting one HFACS layer above it. The framework's whole leverage is decoupling state from action. Adjacent-layer, cause-side. Tell: is the referent the operator's action (unsafe act), or the immediate condition that made the action more likely (precondition)?
-
Latent condition. A dormant weakness emplaced months earlier and far from the harm in time and organisational distance (a scheduling policy, a flawed procedure) that lies waiting. The precondition is present at the moment of action; the immediacy test sorts them even when both involve, say, staffing (fatigue-in-the-room now vs the policy that produced it). Same causal family, different temporal position. Tell: is the condition present at the moment of action (precondition), or laid down long before and lying dormant (latent condition)?
-
Unsafe supervision / organisational influence (the upper HFACS layers). The supervisory decisions (crew pairing, scheduling) and organisational choices (resource allocation, culture) above that produce the precondition. They concern supervisor- and organisation-level decisions, not operator-level state; the fatigue precondition is manufactured by the scheduling decision that lives in the supervision layer. Upstream-cause vs the condition it creates. Tell: is the referent a supervisor/management decision that generated the situation (unsafe supervision/organisational influence), or the operator-and-team state it produced (precondition)?
-
Swiss cheese model / HFACS (the parent framework). Reason's layered-defenses model and the HFACS taxonomy built on it, of which "precondition for unsafe act" is one layer. The framework is the whole four-layer scheme (organisational influence, unsafe supervision, preconditions, unsafe acts); the precondition is a single stratum within it. Part-versus-whole. Tell: is the referent the entire layered accident-causation framework (Swiss cheese/HFACS), or the specific operator-state layer inside it (precondition)?
-
"Human error" (the fused verdict). The undifferentiated, often blame-laden attribution that lumps together the operator's state, the operator's act, and the upstream arrangement into one cause. The precondition layer exists precisely to disaggregate this — to name the operator's condition as distinct from the act and the upstream arrangement, and to trace it upstream rather than blame the person. Contrast case (the thing it decomposes). Tell: is the account collapsing everything into operator fault (human error), or separating the probability-shifting condition from the act and locating its upstream generator (precondition)?
-
Context dependence + cognitive load / attention / state (parent primes). The substrate-neutral core the layer specializes — an actor-and-team's immediate state shifting the probability of error. These carry any cross-domain lesson about state-shifts-error-odds; "precondition for unsafe act" is their HFACS specialization with the five-slot typology and slot-indexed remedies. Treated more fully in the Knowledge Transfer and Structural Core vs. Domain Accent sections. Tell: strip the HFACS typology and immediacy/layer machinery and what remains — an actor's surrounding state raising error probability — is the parent, not the precondition layer.
Neighborhood in Abstraction Space¶
Precondition for Unsafe Act sits in a crowded region of the domain-specific corpus (34th percentile for distinctiveness): several abstractions share nearly its structure, so a description that fits it tends to fit its neighbors too.
Family — Unclustered & Miscellaneous (309 abstractions)
Nearest neighbors
- Active Failure — 0.86
- Automation Bias — 0.86
- Latent Condition — 0.85
- Operator-Vigilance Dependency — 0.85
- Deep Engagement — 0.84
Computed from structural-signature embeddings · 2026-07-12