Skip to content

Just Culture Postmortem

Retrospective review — instantiates Scapegoat Displacement Interruption

A blameless failure review that draws the line between honest error, at-risk behavior, and recklessness, so a system failure is not pinned on one operator.

Just Culture Postmortem is the organisational failure review built to not scapegoat the operator at the sharp end. Its governing distinction, borrowed from safety-critical industries, is that behavior comes in kinds: honest human error, at-risk behavior where the drift from the rule went unseen, and genuine recklessness — and only the last is culpable in the ordinary sense. A postmortem applies that culpability line to a specific failure, reading the causes and the surrounding system precisely so the honest operator who made a foreseeable mistake in a badly designed situation is protected, learned from, and reintegrated, while the system that set the trap is actually fixed. Its defining move is the retrospective culpability judgement plus the systemic repair: it is triggered by one incident, it protects one person from carrying the whole thing, and it closes not with a punishment but with a change.

Example

An airline experiences a serious runway-incursion near-miss: a crew lines up on a taxiway they believe is the runway during a nighttime departure. The reflex — and the old aviation habit — would be to discipline the captain. Instead the airline runs a just culture postmortem. It reconstructs the causes and reads the system around the crew: confusing taxiway lighting at that airport, a chart revision that had changed the layout weeks earlier, a fatiguing scheduling pattern, and an ambiguous ground-control instruction. It then applies the culpability line: was this recklessness, at-risk behavior, or the kind of honest error a competent, conscientious crew could make in exactly that trap? The review concludes the latter — a foreseeable error in a poorly designed environment — and the outcome is not a firing but a set of fixes: lighting escalated to the airport, the chart-change alerting improved, the schedule pattern flagged, and the crew reintegrated and debriefed as a source of learning rather than a cause of shame. The failure is answered by changing the system, not by sacrificing the people in it.

How it works

  • Reconstruct the failure and its causes, reading the surrounding system — design, procedure, resources, incentives — as part of the explanation rather than as background.
  • Apply the culpability line. Classify the behavior as honest error, at-risk drift, or reckless conduct — the substitution test asks whether another competent person in the same situation could have done the same, which distinguishes a system trap from a personal failing.
  • Protect and reintegrate the honest actor. Where the behavior was error or unseen drift, the operator is a source of learning to be reintegrated, not a culprit to be sacrificed.
  • Repair the system. Close with the concrete changes — to design, procedure, staffing, incentives — that remove the trap, so the same failure is less likely regardless of who is next in the seat.

Tuning parameters

  • Culpability threshold — where the line between at-risk behavior and recklessness is drawn. A lenient line maximises learning and disclosure but can under-respond to genuine recklessness; a harsh line chills the reporting the review depends on.
  • Blamelessness scope — how fully individual identity is held out of the review. Fuller blamelessness improves candor but can frustrate a legitimate need for individual accountability in the rare reckless case.
  • System-depth — how far into design, staffing, and incentive the causal read goes. Deeper reads find better fixes but lengthen the review and can blur into a general audit.
  • Repair bindingness — whether the identified fixes are commitments with owners or recommendations. Binding repair closes the loop; advisory repair is faster but often ignored.

When it helps, and when it misleads

Its strength is that it converts the highest-pressure scapegoating setup — a visible operator at the scene of a failure — into learning and a system fix, while still preserving a real line for genuine recklessness. It is the operational embodiment of just culture,[n1] the safety-science stance that a fair, learning-oriented response to error is a precondition for the honest reporting that makes systems safer.

Its failure mode is blamelessness stretched into blanket immunity: if the culpability line is never applied, a genuinely reckless act is laundered as "a system problem," which is its own injustice to those harmed. The opposite misuse is a "just culture" postmortem run for show while the outcome — disciplining the operator — was decided in advance. The discipline is that the culpability line must be applied honestly and symmetrically, the substitution test must be a real test rather than a rubber stamp for exoneration, and the systemic repair must be binding, so the review answers the failure with change rather than with either a sacrifice or an amnesty.

How it implements the components

  • causal_responsibility_map — the postmortem reads the event's contributions to apply the culpability line, distinguishing the operator's action from authority, enabling conditions, and constraint.
  • structural_context_scan — it examines the surrounding system — design, procedure, staffing, incentives — as part of the explanation, so the trap around the operator is visible.
  • repair_and_reintegration_path — it closes with binding system fixes and the reintegration of the honest actor as a source of learning.

It reviews the failure and drives repair but does not run the session with an impartial outside facilitator (independent_facilitator_role — that's Causal Responsibility Mapping Workshop) or give omitted outside stakeholders a voice (cross_group_voice_channel — that's Structural Harm Scan). Its nearest twins are those two: unlike the workshop it does not exist to produce the map but to judge culpability and fix the system, and unlike the standalone structural scan it is triggered by one specific incident and centered on protecting one operator.

Editorial Notes

Form Classification

Form family: Assessment, Review & Assurance

Rationale: Just Culture Postmortem operates as a bounded evaluation of existing evidence or work that produces a finding or disposition because it a blameless failure review that draws the line between honest error, at-risk behavior, and recklessness, so a system failure is not pinned on one operator

Independent corroboration: The frozen evidence defines Just Culture Postmortem as 'A blameless failure review that draws the line between honest error, at-risk behavior, and recklessness, so a system failure is not pinned on one operator', so its operative form is Assessment, Review & Assurance.

Review outcome: Independent reviewer agreement; high confidence.

Origin Attribution

Primary origin: Aviation & Aeronautics

Origin pattern: Cross-disciplinary synthesis

Present-day reach: Multi-domain

Rationale: Aviation safety and accident-investigation practice developed just-culture postmortems that distinguish system traps from culpable conduct.

Related originating lineages:

Review resolution: Both independent reviews place the primary lineage in aviation_aeronautics. The queued differences (alternate_origin_disagreement) concern secondary metadata rather than primary provenance. The final retains medicine_healthcare, systems_cybernetics, organizational_management only where a reviewer supplied a formative-lineage rationale; downstream application by itself is not treated as origin. origin_mode=cross_disciplinary_synthesis records the relationship among origin traditions, while domain_reach=multi_domain records application breadth separately. encyclopedia_synthesis=false reflects whether either reviewer identified a corpus-specific synthesis, and confidence=high preserves the more cautious evidence assessment.

Review outcome: Reconciled after independent review; high confidence.

Notes

[n1] Just culture (developed in safety science by figures including James Reason and Sidney Dekker) is an organisational stance that responds to failure by distinguishing honest error and at-risk behavior from recklessness, protecting the former to sustain the honest reporting that makes systems safer. The "substitution test" — would another competent person in the same situation have done the same? — operationalises the line.