Safety-Gain Offset Dashboard¶
Monitoring dashboard — instantiates Compensation-Aware Safeguard Design
Nets technical failure reduction against behavioral offset, displaced exposure, and bystander harm so a safeguard's real gain is read as a total, not a local win.
Safety-Gain Offset Dashboard puts the whole safety ledger on one surface and computes a net, not a headline. It takes the technical failure reduction the safeguard was built for and subtracts the behavioral offset, the risk that migrated to another channel, and the harm that landed on people who never chose the exposure — so the number a team celebrates is total harm after adaptation, not the one failure mode that improved. Its defining move is refusing the local win: it treats displaced and bystander harm as first-class terms in the sum rather than footnotes, which is precisely the archetype's insistence that the success metric include net harm, not device-level success.
Example¶
An enterprise rolls out phishing-resistant multi-factor authentication to 12,000 employees and, a month in, the security team wants to know whether it actually made the company safer. The dashboard shows why the answer is not obvious. The top line is real: credential-phishing account takeovers are down sharply — the technical reduction. But three offset panels sit beside it. Behavioral offset, fed from the behavior monitor: password reuse across internal tools is up, because staff feel "the login is handled now." Substitution: attacker activity has migrated from phishing to help-desk social engineering, calling in to request MFA resets — the risk crossed a channel boundary rather than vanishing. Bystander: a rising count of shared-device and shared-credential incidents where a lapse exposes teammates who made no such choice.
The dashboard nets the four terms with uncertainty bands and reports that the true safety gain is roughly half the headline once the reset channel and shared-credential harm are counted. That single netted figure — not the takeover-reduction chart the vendor would show — is what the org uses to decide the rollout is not finished: the help-desk reset path needs hardening before MFA can be called a win.
How it works¶
- Assemble the ledger. Pull technical failure reduction, behavioral offset (from the monitor), channel substitution, and bystander harm onto one view.
- Compute the net, headline the net. Net safety gain = technical reduction − behavioral offset − displaced exposure − new systemic risk, carried with uncertainty bands so the primary win never stands alone.
- Track risk across boundaries. The substitution panel follows risk as it crosses channels, populations, or time horizons — from the protected failure mode to a softer one nearby.
- Sentinel the innocent. A dedicated alert fires when harm concentrates on parties who did not choose the exposure, so displacement onto bystanders cannot hide inside an aggregate.
Tuning parameters¶
- Offset weighting — how heavily displaced and bystander harm count against the primary reduction. Heavier weighting resists local-win bias but leans on the terms hardest to quantify.
- Netting horizon — a snapshot versus a trailing window. A longer window catches slow substitution and habituation but is slower to reflect a genuine fix.
- Channel coverage — how many substitution channels the map watches. More coverage catches migration but multiplies instrumentation and the chance of double-counting.
- Bystander threshold — how much third-party harm trips the sentinel. Sensitive thresholds surface displacement early but raise noise.
- Confidence display — a single net number versus a banded estimate. Showing the band resists false precision on terms that are genuinely uncertain.
When it helps, and when it misleads¶
Its strength is that it forces the success metric to include displaced exposure and net harm, directly defeating the archetype's signature symptom — celebrating adoption while exposure quietly grows.
Its honest limit is that a dashboard is only as truthful as its softest terms, and displaced and bystander harm are exactly the terms that resist measurement — so it can look comprehensive while under-counting the offsets that matter most. And once a net-safety number becomes the goal, teams optimize the number: drop an inconvenient substitution channel, and the net looks positive by construction.[n1] The classic misuse is a clean, reassuring net produced by an incomplete channel list. The guarding discipline is to carry uncertainty bands, keep the substitution map's channel list open and adversarially reviewed, and treat a suspiciously tidy net as a measurement gap rather than a triumph.
How it implements the components¶
net_safety_gain_audit— its core computation: technical reduction minus behavioral offset minus displaced exposure, reported as the headline instead of the local win.exposure_substitution_map— it tracks risk migrating across channels, populations, and horizons so a failure mode that merely moved is not scored as one that vanished.bystander_harm_sentinel— it alerts when harm concentrates on parties who did not choose the exposure, keeping displacement onto third parties out of the aggregate's shadow.
It captures no pre-safeguard baseline or raw behavioral drift feed — those are the Before / After Behavior Monitor's — and it installs no counter-incentive, which the Shared Downside or Deductible Rule provides. It aggregates and judges; it neither measures the raw behavior nor intervenes.
Related¶
- Instantiates: Compensation-Aware Safeguard Design — it is the net-harm scoreboard the archetype demands in place of a device-level success metric.
- Consumes: Before / After Behavior Monitor — supplies the behavioral-offset term the net calculation subtracts.
- Sibling mechanisms: Risk Compensation Premortem · Before / After Behavior Monitor · Shared Downside or Deductible Rule · Use-Conditioned Protection Policy · Exposure Cap or Rate Limiter · Adaptive Safeguard Recalibration Gate · Post-Safeguard Incentive Audit
Editorial Notes¶
Form Classification¶
Form family: Monitoring, Sensing & Alerting
Rationale: Safety-Gain Offset Dashboard operates as ongoing observation, sensing, or alerting that detects and surfaces state without itself executing the response because it nets technical failure reduction against behavioral offset, displaced exposure, and bystander harm so a safeguard's real gain is read as a total, not a local win.
Independent corroboration: The frozen evidence defines Safety-Gain Offset Dashboard as 'Nets technical failure reduction against behavioral offset, displaced exposure, and bystander harm so a safeguard's real gain is read as a total, not a local win', so its operative form is Monitoring, Sensing & Alerting.
Nearest alternative: Analysis, Modeling & Optimization — Safety-Gain Offset Dashboard includes features of an analytical, modeling, inference, comparison, or optimization procedure that derives insight or a solution, but its defining operation is ongoing observation, sensing, or alerting that detects and surfaces state without itself executing the response.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Behavioral Economics
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Multi-domain
Rationale: Netting technical protection against induced risk-taking, displaced exposure, and bystander harm operationalizes risk compensation. Peltzman's primary economic analysis shows safety regulation can change behavior and offset engineering gains, while engineering and public policy supply failure and externality measures.
Related originating lineages:
- Data Science & Analytics — Data science, analytics, and operational monitoring supplies a parallel or contributing lineage for the mechanism's defining operation: nets technical failure reduction against behavioral offset, displaced exposure, and bystander harm so a safeguard's real gain is read as a total, not a local win.
- Economics & Finance — economics_finance contributes marginal returns, demand, allocation, and stress testing to the mechanism's formative or independently convergent form; that contribution does not displace the primary behavioral_economics lineage.
- Engineering & Design — Safety-Gain Offset Dashboard's terminology and operating form—nets technical failure reduction against behavioral offset, displaced exposure, and bystander harm so a safeguard's real gain is read as a total, not a local win—are rooted most directly in engineering design, reliability, and systems-safety practice.
- Psychology — Experimental, clinical, and behavioral psychology supplies a parallel or contributing lineage for the mechanism's defining operation: nets technical failure reduction against behavioral offset, displaced exposure, and bystander harm so a safeguard's real gain is read as a total, not a local win.
- Public Administration & Policy — Distributional review independently captures displaced and bystander exposure.
- Systems Thinking & Cybernetics — Systems thinking, feedback control, and cybernetics supplies a parallel or contributing lineage for the mechanism's defining operation: nets technical failure reduction against behavioral offset, displaced exposure, and bystander harm so a safeguard's real gain is read as a total, not a local win.
Review resolution: The blind reviewers disagreed on primary lineage (behavioral_economics versus engineering_design); authoritative or primary research supports behavioral_economics as the best historical origin. Netting technical protection against induced risk-taking, displaced exposure, and bystander harm operationalizes risk compensation. Peltzman's primary economic analysis shows safety regulation can change behavior and offset engineering gains, while engineering and public policy supply failure and externality measures. The cited Peltzman, The Effects of Automobile Safety Regulation directly supports the defining operation used in that choice. All independently supported contributing domains are retained without an arbitrary cap, while domain_reach=multi_domain records later applicability separately from provenance.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
Notes¶
[n1] Goodhart's law — "when a measure becomes a target, it ceases to be a good measure." A net-safety dashboard optimized for its own headline can be gamed by quietly dropping the offset terms that would drag the number down. ↩