Skip to content

Assumption-Failure Tabletop

Tabletop exercise — instantiates Surprise Preparedness

Exercises response when several normal operating assumptions fail simultaneously.

The Assumption-Failure Tabletop gathers the people who would actually respond and walks them through a scenario in which several normal operating assumptions fail at once — not one channel, not one system, but a bundle: the primary works, the backup is independent, the lead is reachable, the vendor answers. Its distinguishing idea is that surprises rarely arrive as a single clean fault; they arrive as combinations that defeat primary and fallback together, and the exercise exists to find where those assumptions are secretly coupled. It is collaborative rehearsal, not adversarial attack: the room's job is to preserve the service floor under compound stress and to reach for responses that are reversible and bounded rather than to improvise blind.

Example

A commercial bank runs an Assumption-Failure Tabletop on its payments operations. The scenario removes four assumptions together: the main payments switch degrades, the "independent" backup switch is also impaired, the operations lead is mid-flight and unreachable, and the card-network vendor hotline is saturated. Conflicting evidence is injected on purpose — two dashboards disagree about whether settlement is flowing. The responders must decide what the floor actually is (payroll and benefit payments before discretionary transfers) and what reversible move buys time: cap outbound transfers at a low, clearly reversible ceiling and queue the rest, rather than an irreversible full stop that would strand every payment.

Talking it through, they discover the trap the exercise was built to expose: the backup switch authenticates through the same identity provider as the primary — a shared dependency that would fail both together. That is a correlated failure no single-fault drill would have surfaced. They score the run on floor preservation, decision latency, and whether every improvised move was genuinely reversible and bounded. The fixes follow: an identity-independent authentication path, and a pre-authorized, reversible transfer cap that no longer has to be invented in the moment.

How it works

  • Fail a bundle, not an event. Remove several jointly-relied-on assumptions at once, chosen because they might be coupled — the point is to find shared fate.
  • Inject conflicting evidence. Make the picture ambiguous, so the room must act before the situation is cleanly named.
  • Use the real responders. The people who would actually decide work the problem, not a facilitator reciting a plan.
  • Require safe-to-fail moves. Every proposed action must state its purpose, maximum scope, stop trigger, and rollback — "try something" is not allowed.
  • Score outcomes, not recitation. Grade floor preservation, latency, and the reversibility of choices, not whether anyone remembered the binder.

Tuning parameters

  • Assumption coupling — how many assumptions fail and how tightly they interact. Tightly coupled bundles reveal correlated failure; loosely related ones teach little.
  • Evidence ambiguity — how conflicting and incomplete the injected picture is. More ambiguity tests judgment; too much becomes an unfair puzzle.
  • Room composition — real decision-makers versus proxies. Real principals surface authority gaps; proxies are easier to schedule but less honest.
  • Reversibility bar — how strictly proposed actions must be bounded and undoable. A strict bar trains safe improvisation; a loose one rewards recklessness.
  • Scoring stance — outcome-based versus narrative. Outcome scoring resists theater; narrative scoring is comfortable and misleading.

When it helps, and when it misleads

Its strength is exposing the common-mode failure — the shared dependency that quietly links a primary and its supposed backup — while training people to respond with bounded, reversible moves instead of freezing or flailing.[n1] It rehearses the exact conditions the archetype warns about: multiple assumptions failing together, faster than escalation can keep up.

Its signature failure is tabletop theater: a scripted walk-through that confirms the expected plan and calls the confirmation readiness. A related trap is removing assumptions that do not actually interact, so there is no correlation to find and the exercise only flatters the design. And a room allowed to "just try something" mistakes unmanaged experimentation for adaptive capacity. The guarding discipline is to remove genuinely coupled assumptions, keep the evidence ambiguous, require every move to be safe-to-fail, and score whether the floor survived — not whether the story ended well.

How it implements the components

  • correlated_dependency_map — by failing several assumptions at once, the exercise reveals which fallbacks share a hidden dependency and would collapse together, mapping the couplings a single-fault test never touches.
  • safe_to_fail_action_set — it forces every response into the safe-to-fail mold (purpose, scope, stop, rollback), rehearsing bounded improvisation under model failure.

It fails a bundle of assumptions rather than isolating one channel — testing a single channel's independence is independent_state_observation, and running the recurring connectivity drill is readiness_exercise_cadence, both the Alternate Communication Drill's. The tabletop stresses floors and authority but authors neither: minimum_viable_continuity belongs to the Minimum-Service Runbook and bounded_emergency_authority to the Emergency Authority Charter.

Editorial Notes

Form Classification

Form family: Experiment, Test & Rehearsal

Rationale: Exercises response when several normal operating assumptions fail simultaneously, making its operative form a deliberate probe, variation, simulation, or practiced execution used to generate evidence or readiness.

Independent corroboration: The frozen evidence defines Assumption-Failure Tabletop as 'Exercises response when several normal operating assumptions fail simultaneously', so its operative form is Experiment, Test & Rehearsal.

Review outcome: Independent reviewer agreement; high confidence.

Origin Attribution

Primary origin: Military & Strategic Studies

Origin pattern: Convergent development

Present-day reach: Multi-domain

Rationale: Tabletop exercises descend from military staff exercises that rehearse decisions under simulated compound contingencies.

Related originating lineages:

Review resolution: Both reviewers trace tabletops to military staff exercises. Emergency management, reliability engineering, and intelligence red-teaming independently shaped compound-failure rehearsal, so all three are retained as material alternates without treating broad use as separate origins.

Review outcome: Reconciled after independent review; high confidence.

Notes

The Assumption-Failure Tabletop and the Red-Team Disruption Challenge (a neighbor under Wild-Card Contingency Mapping) both fail several assumptions at once, but the tabletop is a collaborative rehearsal scored on preserving the floor, whereas the red team is rewarded for defeating the plan — the difference is stance, and it is why the two find different weaknesses.

[n1] Common-mode failure — a single underlying cause (shared power, identity, vendor, or workforce) that disables multiple components thought to be independent. It is the reliability-engineering name for exactly the coupling this exercise hunts: the reason a primary and its "backup" fail together.