Accommodation Failure and Recovery Rehearsal¶
Test or assessment — instantiates Human-Capacity Accommodation Design
Simulates tool, staff, channel, power, network, schedule, or handoff failure and tests backup and repair.
An accommodation that works only while everything else works is a trap: the day the tool crashes or the specialist is out is exactly the day access disappears. Accommodation Failure and Recovery Rehearsal stress-tests the delivery before dependence becomes critical. It deliberately injects a failure — the assistive device dies, the interpreter no-shows, the network drops, the trained staffer is on leave, a handoff is missed — and then watches whether the backup engages, whether state and preferences survive, whether the user is notified accessibly, and whether repair happens inside the promised window. Its one defining idea is simulated failure under controlled conditions: it does not wait for breakdown to be observed, it stages one on purpose to see if the recovery machinery is real. It does not measure whether the normal path is equivalent, nor track outcomes as they drift over months — it pulls a plug today and checks that access survives.
Example¶
A hospital relies on two channels to give Deaf patients equal access in clinical encounters: an on-site sign-language interpreter roster and a video-remote-interpreting (VRI) tablet as backup. On paper, redundancy. The rehearsal tests it. During a mock pre-op consult, the team stages the plausible worst case — the rostered interpreter is pulled to an emergency and the VRI tablet's wireless drops in a shielded room. What surfaces is ugly: the fallback "backup" turns out to require the same specialist scheduling desk that is now closed after hours; the tablet's cellular failover was never provisioned; and the only remaining option is a family member interpreting, which the accommodation was specifically meant to avoid. Repair of the network dead zone has no owner and no target. The rehearsal's output is not a grade of the interpreting quality but a punch list against the plan: provision cellular failover, name an after-hours recovery owner, and set a maximum-outage target — the operational gaps that only a staged double failure could reveal.
How it works¶
The defining move is injecting failure and watching the recovery, not the normal run:
- Enumerate credible failure modes. Tool, staff, channel, power, network, schedule, and handoff — and, crucially, combinations, since single-point drills miss the real outages.
- Inject under control. Stage the failure in a rehearsal, not production, so consequences are observed without harming a real user.
- Test the backup's independence. Confirm the fallback does not secretly depend on the same unavailable resource as the failed path.
- Check state, notification, and repair. Verify preferences and progress survive, the user is warned accessibly, and repair fires inside the promised window with a named owner.
- Produce a plan punch list. Output owners, targets, and provisioning gaps — the operational holes that must close before dependence is safe.
Tuning parameters¶
- Failure-mode coverage — single points versus combined failures; combinations reveal hidden shared dependencies but are harder to stage.
- Injection realism — tabletop walk-through versus live staged outage; live injection finds real gaps but risks disruption.
- Recovery-window target — how fast backup must engage and repair complete; tighter targets raise resilience but cost standby capacity.
- Backup independence depth — how far you trace a fallback's dependencies; deeper tracing catches shared single points but takes investigation.
When it helps, and when it misleads¶
Its strength is exposing the fake backup — the fallback that shares a hidden dependency with the primary, the "spare" nobody provisioned, the recovery step with no owner — while the cost of finding out is a rehearsal rather than a stranded person.
Its failure mode is rehearsing only tidy single-component failures and declaring resilience, when real outages arrive in correlated clusters (tool failure plus the one person who knows the workaround being unavailable). This is the discipline of chaos engineering — deliberately injecting failures, including compound ones, to learn where a system actually breaks rather than where you assume it will.[1] The classic misuse is a paper continuity plan never exercised, which reads as coverage until the day it is needed. The guarding discipline is to rehearse plausible combinations, trace every backup to independent resources, and re-run after any change to the primary system.
How it implements the components¶
This mechanism fills the operational-resilience side of the delivery plan and nothing else:
accommodation_implementation_support_and_ownership_plan— it hardens the plan's backup, repair, ownership, and service-target provisions by exercising them against injected failure, and returns the gaps to close before dependence is safe.
It does not build capacity or demand profiles or the mismatch ledger (representative_human_capacity_and_variability_profile, task_environment_and_interface_demand_map, mismatch_barrier_workaround_and_risk_ledger), frame the essentials (essential_outcome_user_and_context_frame), generate options (accommodation_option_and_equivalent_path_set), or grade an option's normal-conditions equivalence (safety_dignity_privacy_and_burden_gate). Its nearest twin is the Longitudinal Fit, Equity, and Burden Audit: that one *observes real use over time to detect drift (in_context_fit_breakdown_and_revision_monitor), whereas this one stages a failure today, before any real dependence, to test the recovery machinery.*
Related¶
- Instantiates: Human-Capacity Accommodation Design — hardens the delivery plan's backup and repair before dependence becomes critical.
- Consumes: Multimodal Equivalence and Assistive-Compatibility Test — the equivalence-passed accommodation whose failure and recovery it rehearses.
- Sibling mechanisms: Person–Task–Environment Mismatch Analysis · Essential-Function and Method-Separation Review · Participatory Accommodation-Option Workshop · Multimodal Equivalence and Assistive-Compatibility Test · Longitudinal Fit, Equity, and Burden Audit
Editorial Notes¶
Form Classification¶
Form family: Experiment, Test & Rehearsal
Rationale: The mechanism simulates tool, staff, channel, power, network, schedule, or handoff failure and tests backup and repair, so its operative form is an evidence-generating test, experiment, or rehearsal.
Independent corroboration: The frozen evidence defines Accommodation Failure and Recovery Rehearsal as 'Simulates tool, staff, channel, power, network, schedule, or handoff failure and tests backup and repair', so its operative form is Experiment, Test & Rehearsal.
Nearest alternative: Assessment, Review & Assurance — It deliberately generates evidence through exposure, perturbation, or practice rather than only evaluating evidence already in hand.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Disaster Management & Risk Reduction
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Multi-domain
Rationale: Deliberately staging single and compound failures to verify independent fallback, notification, ownership, and time-bounded recovery is a continuity and emergency-preparedness practice.
Related originating lineages:
- Computer Science & Software Engineering — Deliberate fault injection and compound-failure testing borrow directly from chaos engineering and resilient systems practice.
- Engineering & Design — Fault injection, redundancy independence, and recovery-time objectives contribute the resilience-testing method.
- Human-Computer Interaction — Assistive tools, alternative channels, and preservation of user preferences make the rehearsal specifically about accessible service continuity.
- Medicine & Healthcare — Clinical interpreting and patient-access continuity make accommodation failure a safety-critical healthcare concern.
- Public Administration & Policy — Standing accommodations and service-delivery obligations supply the governance context for recovery ownership.
Review resolution: Deliberately exercising continuity plans, backup capabilities, and recovery gaps is a mature disaster-management and continuity discipline. Engineering and computing contribute failure injection, while HCI, medicine, and public administration make the recovery test accommodation-specific; the page synthesizes those lineages.
Attribution caveat: The mechanism is an Encyclopedia synthesis applying disaster-recovery rehearsal to accessibility accommodations.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
References¶
[1] Basiri, A., Behnam, N., de Rooij, R., Hochstein, L., Kosewski, L., Reynolds, J., & Rosenthal, C. "Chaos Engineering". IEEE Software 33(3), 35–41 (2016). Defines chaos engineering as deliberately injecting realistic failure conditions and observing actual system behavior to uncover weaknesses that assumptions and specifications miss. registry ↩