Error-Reporting System¶
Capture system — instantiates Psychological Safety Enablement
A standing system that defines what counts as a reportable error, hazard, or near miss, gives it a durable intake path, and tracks whether reporting is actually rising.
Error-Reporting System is the persistent operational machinery for capturing the small, uncomfortable facts that precede accidents — errors made, hazards spotted, near misses that "almost" happened. Its defining property is that it is a standing system, not a one-time invitation: it names in advance the class of events people should file, provides a durable path for filing them, and instruments the reporting rate itself as a managed number that leadership watches. Where a single anonymous tip is an event, this is infrastructure — the difference between "you can raise a concern if you want" and "here is the form, here is what belongs on it, and here is the dashboard that tells us whether you are using it." It cares intensely about volume and coverage of reporting and comparatively little about the identity attached to any single report.
Example¶
A regional airline wants to catch the conditions that cause runway incursions before one causes a collision. It stands up a voluntary safety-reporting program: any pilot, controller, or ramp worker can file a short report whenever something almost went wrong — a clearance that was ambiguous, a checklist item nearly skipped, a taxiway sign obscured by glare at dusk. The program publishes exactly what counts as reportable (near misses and hazards, not just accidents that already caused damage), routes every filing to a small analysis desk, and — critically — puts the monthly count of near-miss reports on the operations review alongside on-time performance. In the first quarter reports rise sharply. Read naively that looks like the airline got more dangerous; read correctly it means the hazards that were always there finally became visible. The safety desk now sees, weeks in advance, that dusk glare on one taxiway is generating a cluster of near-incursions — a pattern no accident report would ever have surfaced, because the accident had not happened yet.
How it works¶
- Define the reportable event. The system states, concretely, that errors, hazards, and near misses are all in scope — not only outcomes that already caused harm. This is what turns a vague "speak up" into a filed, categorizable behavior.
- Provide a durable intake. A short, always-available form or line with a low filing cost, structured enough to be analyzable but light enough that a tired operator will actually use it at end of shift.
- Instrument the reporting rate. The count and coverage of reports become a first-class metric — tracked over time and across roles, so a drop in reporting reads as a warning (people have stopped filing), not as success.
- Route to analysis, not to a drawer. Every report reaches an owner who aggregates it into patterns. (What that owner then does with a pattern — the change it drives — is the Learning Review's job, not this system's.)
Tuning parameters¶
- Reportability threshold — how minor an event must be before it is worth filing. A low threshold catches faint signals but raises noise and triage load; a high one keeps the queue clean but misses the weak precursors that matter most.
- Filing friction — the seconds and fields a report costs. Lower friction lifts volume (the whole game early on) but yields thinner reports; higher friction yields richer data but suppresses the marginal filer.
- Voluntary vs. mandatory scope — which events must be reported versus which are encouraged. Mandates guarantee coverage of defined hazards but corrode the voluntary candor that surfaces the undefined ones.
- Rate-metric interpretation — whether a rising report count is read as deterioration or as improving observability. This dial is a stance, and setting it wrong (punishing units for reporting more) quietly kills the system.
- Feedback latency — how quickly a filer sees that a report landed somewhere. Long latency teaches futility and depresses the very rate the system is trying to lift.
When it helps, and when it misleads¶
Its strength is foresight through volume: by lowering the bar to "almost happened" and treating the reporting rate as the health metric, it converts a population of small, individually-trivial observations into an early-warning surface. Aviation's decades-long confidential near-miss reporting practice is the canonical demonstration that a well-run capture system makes latent hazards visible long before they mature into accidents.[1]
Its central failure mode is the one the parent archetype calls the reporting black hole — a system that collects reports but never visibly acts, which trains everyone that filing is pointless and drives the rate to zero. A subtler misuse is weaponizing the rate metric: when a manager is judged by low report counts, the rational response is to suppress reporting, and the dashboard turns from an observability instrument into an incentive to hide. The system also cannot, by itself, keep filers safe — a named report is only as safe as the surrounding protection, which is why coverage collapses without a credible retaliation safeguard behind it. The guarding discipline is to treat the rate as a diagnostic to be raised, not a defect to be minimized, close the loop fast enough that filers see their reports move, and never let the metric become a target a manager can game.
How it implements the components¶
speak_up_behavior— the system's scoping definition (errors, hazards, near misses are reportable) is the concrete specification of the protected behavior, so "speak up" stops being a slogan and becomes a fileable act.reporting_channel— the durable, low-friction intake form/line is the usable path the archetype calls for, engineered for repeated operational use rather than one-off disclosure.participation_monitor— tracking report count and coverage across roles over time is the participation monitor: it tells you whether the target behavior is actually increasing and where it is not.
It does not implement anonymity_option or confidential_escalation_path — those belong to Anonymous Reporting, its nearest twin; this system captures and counts reports whether or not identity is stripped, and relies on that sibling when the reportable act needs to be de-identified. Converting a surfaced pattern into an acted-on change is the Learning Review's visible_use_of_raised_concerns, not this system's.
Related¶
- Instantiates: Psychological Safety Enablement — the standing capture-and-metrics layer for operational errors, hazards, and near misses.
- Consumes: Anonymous Reporting — supplies the anonymity layer when a reportable event is too exposing to file under one's own name.
- Sibling mechanisms: Anonymous Reporting · Learning Review · Retaliation Protection Process · Blameless Postmortem · Leader Vulnerability Modeling · Pre-Meeting Silent Input · Team Agreement · Dissent Round
Editorial Notes¶
Form Classification¶
Form family: Organization, Role & Governance
Rationale: The mechanism maintains a standing reporting service with defined scope, durable low-cost intake, reporting-rate instrumentation, and accountable owners who route reports into analysis.
Nearest alternative: Record, Log & Register — Reports create durable records, but the broader operative form is the continuing institutional service and ownership arrangement that makes filing and follow-through possible.
Review outcome: Adjudicated after independent review; medium confidence.
Origin Attribution¶
Primary origin: Aviation & Aeronautics
Origin pattern: Convergent development
Present-day reach: Multi-domain
Rationale: Aviation safety established durable, voluntary, confidential, non-punitive systems for reporting hazards, errors, unsafe situations, and near misses and feeding them into systemic improvement.
Related originating lineages:
- Engineering & Design — Safety engineering supplied hazard taxonomies, causal analysis, and corrective-action tracking.
- Medicine & Healthcare — Patient safety independently developed adverse-event and near-miss reporting for organizational learning.
Review resolution: NASA documents ASRS as operating since 1976 with the exact confidential, non-punitive, near-miss reporting pattern; AHRQ confirms its later independent healthcare convergence.
Attribution caveat: Aviation and healthcare have strong convergent reporting-system lineages.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
References¶
[1] NASA's Aviation Safety Reporting System (ASRS), operating since 1976, is a long-running voluntary, confidential program that collects error and near-miss reports from aviation personnel — the archetypal example of an error-reporting system whose value comes from broad, low-friction capture of events that never became accidents. withdrawn registry ↩