Skip to content

Close-Call Review Protocol

Review procedure — instantiates Counterfactual Proximity Signal Calibration

Investigates a specific almost-event as evidence — surfacing what nearly went wrong — while leaving the actual no-harm outcome recorded exactly as it happened.

A Close-Call Review Protocol is a structured retrospective run on one almost-event. It treats the incident as evidence to be investigated — what nearly happened, why it stopped short, what latent condition made it possible — and it produces a bounded set of follow-up actions. Its defining commitment is the double-ledger: the factual outcome (no harm occurred) stays on the books unchanged, and the review is explicitly barred from converting the near-miss into a completed loss, a blame record, or a harm statistic. It is a procedure for learning from an almost, not for rewriting it. What separates it from a general incident inquiry is that its subject is precisely the case where nothing bad actually happened, and its discipline is keeping that fact intact.

Example

On a hospital ward a nurse draws up a syringe of a concentrated electrolyte, and a second nurse, performing the required independent check at the bedside, catches that the concentration is ten times the intended dose before anything is administered. No patient was harmed. Under a bare outcome record this is a non-event. The Close-Call Review Protocol convenes instead: it fixes the factual anchor (medication not administered, patient unharmed, caught at the bedside check), then investigates the almost — the look-alike vials stocked side by side, the interruption that broke the first nurse's concentration, the fact that the independent check was the last and only barrier standing. The review's output is bounded to what a near-miss may legitimately trigger: separate the vials, add a pharmacy-level flag, retrain on interruption management. It does not enter a "medication error" on the patient's chart, because none reached the patient. The lesson is captured; the record stays honest.

How it works

The protocol runs a fixed sequence with two rails. It anchors the fact first — writing down the observed outcome, timing, and the barrier that actually stopped the event — before anyone reconstructs the counterfactual, so the near-miss can never be back-filled into a harm. It then investigates causes and defenses, and finally scopes the response inside a learning boundary: the review may recommend inquiry, retraining, redesign, or retest, but may not manufacture credit, blame, or a completed-outcome statistic. Where the reconstruction needs a judgment about whether the bad alternative was genuinely reachable, the protocol defers that call to a Counterfactual Plausibility Filter rather than adjudicating reachability itself.

Tuning parameters

  • Convening threshold — how close a call must be to trigger a full review versus a lightweight log entry. Set low and reviews multiply and fatigue reviewers; set high and instructive near-misses slip through as "no harm, no review."
  • Response ceiling — the strongest action a review may recommend on near-miss evidence alone. Raising it lets one dramatic close call force big changes; lowering it protects against overreaction but may under-respond to a real latent hazard.
  • Fact/counterfactual firewall — how strictly the actual-outcome record is quarantined from the reconstruction. Stricter firewalling protects the record but slows the discussion.
  • Membership — whether the review includes the people involved, independent reviewers, or both, trading candor against distance.

When it helps, and when it misleads

Its strength is turning free, no-cost warnings into fixes before a real failure arrives — the near-miss is the cheapest evidence a system ever gets. It pairs naturally with a layered-defenses view of accidents, where a close call reveals that most barriers were already breached and only the last one held.[n1] Its failure mode is hindsight storytelling: a review that reconstructs a lurid "what could have happened" and then treats that invented scenario as if it were the fact, over-driving the response. The guarding discipline is the firewall — keep the factual anchor untouched, cap the response inside the learning boundary, and send any dispute about whether the bad path was truly reachable to the plausibility filter rather than settling it by vividness in the room.

How it implements the components

  • factual_outcome_anchor — the protocol's first and non-negotiable step: record what actually occurred (and what stopped it) before any alternative is reconstructed, and keep that record unaltered.
  • learning_update_boundary — it defines and enforces the ceiling on what the near-miss may change: inquiry, retraining, redesign, retest — never a completed harm, credit, or blame entry.

It does NOT implement calibration_feedback_loop — testing whether close-call signals actually predicted later outcomes across many cases is Proximity Signal Backtest's job, not this per-incident review's. It also leaves proximity_metric_or_ordering to Near-Miss Distance Scorecard.

Editorial Notes

Form Classification

Form family: Assessment, Review & Assurance

Rationale: Investigates a specific almost-event as evidence — surfacing what nearly went wrong — while leaving the actual no-harm outcome recorded exactly as it happened, making its operative form a bounded evaluation of existing evidence or work that produces a finding or disposition.

Independent corroboration: The frozen evidence defines Close-Call Review Protocol as 'Investigates a specific almost-event as evidence — surfacing what nearly went wrong — while leaving the actual no-harm outcome recorded exactly as it happened', so its operative form is Assessment, Review & Assurance.

Review outcome: Independent reviewer agreement; high confidence.

Origin Attribution

Primary origin: Engineering & Design

Origin pattern: Convergent development

Present-day reach: Multi-domain

Rationale: Industrial safety and reliability engineering established close-call investigation as a root-cause learning procedure that distinguishes an event with no injury from a completed harm and produces preventive actions without blame.

Related originating lineages:

  • Aviation & Aeronautics — Aviation institutionalized confidential, non-punitive reporting of incidents and potential safety deficiencies through ASRS.
  • Medicine & Healthcare — Patient-safety practice independently standardized investigation of no-harm events and close calls while preserving the no-harm factual classification.

Review resolution: OSHA explicitly defines and investigates workplace close calls as no-injury events whose root causes should produce corrective action without blame. FAA and AHRQ document independent aviation and healthcare systems for confidential reporting and review of potential or no-harm events. The general safety-engineering procedure is therefore primary, with aviation and medicine retained as independently institutionalized convergent lineages.

Attribution caveat: Aviation is a particularly mature and influential reporting lineage, but official occupational-safety guidance documents the broader incident-investigation form most closely matching the mechanism; healthcare independently converged on the same no-harm learning discipline.

Review outcome: Researched adjudication after independent review; high confidence.

Sources consulted:

Notes

[n1] James Reason's Swiss cheese model of accident causation pictures defenses as layers of cheese whose holes must line up for harm to pass; a near-miss is the case where they nearly did, which is exactly why investigating one exposes latent conditions before an accident makes them visible.