Cross-Boundary Hazard Ledger¶
A standing register — instantiates Migration-Resistant Hazard Control
A standing double-entry record that follows the hazard across every boundary, so a reduction booked in one place must reconcile against system totals or stand exposed as a mere transfer.
Cross-Boundary Hazard Ledger is the persistent accounting artifact of the archetype: a running, double-entry record of where hazard sits and where it moves, kept across all the boundaries the control spans. Its defining discipline is conservation — a decrease booked at one site has to reconcile against the system total, and if the total does not move, the ledger shows the reduction for what it is: hazard transferred to another column, not removed. Where a review reframes and a monitor watches, the ledger simply keeps the books, and it enforces one rule that makes the books trustworthy: every column must be measured the same way, so a "reduction" cannot be conjured by grading the destination on a looser ruler than the source.
Example¶
A prime contractor on a large construction program reports its recordable-injury rate falling year over year, and points to it as proof its safety program works. Kept honestly, a cross-boundary hazard ledger records injuries across the prime and every subcontractor tier, with a measurement symmetry rule forcing identical injury definitions and reporting thresholds at each tier. The books tell a different story: the prime's rate fell because the most dangerous scopes were pushed down to subs, whose rates rose by more. The ledger posts each such shift as a transfer path — a line linking the prime's decrease to the subcontractor's increase — and its residual-risk register shows total program injuries roughly flat. The improvement was not risk removed; it was risk shifted down the tier where it is counted less well.
How it works¶
- Keep a residual-risk register per site. Each actor, phase, or location holds a standing balance of residual hazard, updated as controls and conditions change.
- Post transfers as linked entries. When hazard falls in one column and rises in another, record the pair as an explicit transfer path rather than two unrelated movements, so displacement is a line item, not a coincidence.
- Enforce measurement symmetry. A single rule fixes definitions, thresholds, and instruments across every column, so a reduction can never come from a weaker measurement at the destination.
- Reconcile to the total. A real reduction has to show up in the system sum; anything that nets to zero is flagged as a transfer, not a win.
Tuning parameters¶
- Ledger granularity — per-site, per-actor, or per-phase columns. Finer granularity exposes more transfers but multiplies the bookkeeping and the noise.
- Measurement-symmetry strictness — how identical destination and source metrics must be before an entry is trusted; the dial that decides whether the books can be gamed by definition.
- Reconciliation cadence — continuous posting versus a periodic close; how fast a transfer becomes visible against how much churn you tolerate.
- Gross vs. residual basis — whether columns hold raw hazard or hazard net of local controls; changes what "moved" means.
- Transfer-attribution rule — how confidently a rise in column B may be attributed to a fall in column A before the two are linked as a transfer.
When it helps, and when it misleads¶
Its strength is arithmetic: it makes transfers visible as subtraction and addition, so a claimed reduction that the books do not support is hard to sustain. It is the standing evidence the reviews and incident boards draw on, and its measurement-symmetry rule is the specific defense against a local metric being optimized while the system worsens.[1]
Its weaknesses live at the destination. The ledger needs symmetric, timely data from exactly the columns where measurement is usually weakest — the subcontractor, the downstream region, the informal channel — and cross-boundary attribution is noisy, so it can both invent transfers that are coincidence and miss transfers buried in lag. Its classic misuse is to run backwards: choose the boundary set or the close date that happens to net to a win, or define the destination's metric loosely so nothing ever reconciles against you. The discipline is independent destination data and a symmetry rule set before the numbers are in, not tuned afterward to protect the headline.
How it implements the components¶
Cross-Boundary Hazard Ledger realizes the record-keeping and reconciliation side of the archetype:
residual_risk_register— the standing, per-column balance of residual hazard that the whole ledger is built on.transfer_path— each linked entry recording a reduction at one site against a rise at another, so displacement is booked rather than lost.measurement_symmetry_rule— the rule forcing identical measurement across columns, without which the books can be balanced by cheating the destination's ruler.
It does not decide where the boundaries are drawn (that's Boundary Expansion Review), watch the destinations in real time (that's Migration Sentinel Network), or assign who owns a harm that reappears (that's Cross-Jurisdiction Incident Review). The ledger records; others frame, watch, and act.
Related¶
- Instantiates: Migration-Resistant Hazard Control — it is the conserved-quantity bookkeeping that keeps every claimed reduction honest.
- Consumes: Boundary Expansion Review — which defines the boundaries the ledger reconciles across.
- Sibling mechanisms: Boundary Expansion Review · Cross-Jurisdiction Incident Review · Intervention Displacement Stress Test · Migration Sentinel Network · Pressure-Absorption Redesign Workshop · Source-Reduction or Safe-Dissipation Plan · Whole-System Impact Map · System-Wide Net-Risk Dashboard · Before–After–Elsewhere Evaluation · Adaptive Circumvention Red Team · Causal Loop Diagram · Agent-Based Experiment or Simulation · Fault Tree Analysis · Mass Balance · Hazard Analysis
References¶
[1] Goodhart's law — once a measure becomes a target it stops being a good measure. A local injury-rate or incident count optimized in isolation invites exactly the boundary-shifting the ledger's system-total reconciliation is built to expose. ↩