Assurance · Soft Data · Pre-Incident Sensing

The Institutional Failure Radar: Failure Changes Shape Before It Changes the Numbers

📖 This article has an expanded ebook edition — read the full ebook.

Formal systems record the declared state. Soft exhaust records the felt state. Failure changes shape — chatter, silence, compression, timing — before it changes the numbers.

By Scott Farrell, LeverageAI  ·  A field guide for risk, assurance and safety leaders

The short version

Consider two approvals that are identical in the structured system. Required checks completed. Authorised approver. Risk status: green. Outcome: approved. The formal pipeline treats them as equivalent. The soft exhaust does not.

Approval A assembled evidence over several days. Engineering, safety and operations participated. Objections were recorded and answered. Alternatives were considered. Final approval landed during normal working hours. Language became more confident as evidence accumulated.

Approval B was a thirty-message thread circling one disputed number. Two engineers wrote "probably" and "should be acceptable." The field team was never in the room. One objection was never answered. Status moved from amber to green without new evidence. Approval fired just before shift handover. The final report scrubbed the qualifiers that were live in the discussion.

Both are green. Only one looks healthy.

That gap — between the colour on the dashboard and the shape of the deliberation that produced it — is the sensing problem this article is about. Failure often exists first as a deformation in attention, language, participation and timing, long before it appears as an incident, a lagging KPI, or a risk-register entry. The question for assurance leaders is no longer only "is the control green?" It is: how did it become green?

Declared state vs felt state

Formal systems are excellent at the declared state: status codes, completed checklists, authorised roles, reported metrics. They were designed for that. What they systematically under-sample is the felt state — where people are uncertain, where attention is accumulating, where nobody wants ownership, where dissent is being compressed, where a supposedly routine decision is consuming abnormal cognitive energy, and where a consequential decision is consuming suspiciously little.1

A dashboard may say the control is green. The exhaust may show that twenty people are arguing around it, nobody can explain the number, three objections remain unresolved, and the approval was finally clicked at 5:47 pm on Friday. That is not a process-mining event. It is a shape.

BI for Soft Data already established the substrate: structured systems record outcomes while emails, meetings and documents hold the causal layer — reasoning, objections, trade-offs, relationship texture.2 The radar does not replace that compile step. It asks a further question of the same exhaust: what is the organisation's behaviour around facts and decisions? How much discussion? Who participated? Were objections answered or merely stopped? When did certainty arrive relative to evidence? That layer is organisational behavioural telemetry — and it is not the same thing as measuring whether someone accepted an AI recommendation. It is the attention-shape of the institution itself.

Seven shapes failure takes before it has a number

None of these is proof. Each is a prior that says: something here deserves inspection.

  1. Excess chatterA routine control suddenly produces several times its normal traffic. Possible friction: unclear procedure, contradictory evidence, ambiguous ownership, a decision that does not fit the governance model. The chatter is not the answer. It is the nomination.
  2. Suspicious silenceA high-consequence decision with no visible challenge, no cross-functional discussion, no alternatives, no recorded uncertainty. It may be genuinely straightforward — or dissent may have become socially unsafe, approval ritualised, or the people closest to the work locked out of the channel. Psychological-safety research has long shown that fear suppresses reporting while risk accumulates underneath.3
  3. Consensus compressionDiscussion contains uncertainty; the formal artefact becomes clean and unanimous. Qualifiers vanish. Risks raised in email disappear from the final report. An amber conversation produces a green summary. Classic groupthink dynamics — avoiding critical evaluation of the favoured path — leave a semantic fingerprint: where did uncertainty disappear without being resolved?4
  4. Approval-friction anomaliesMismatch between decision consequence and decision friction: low-risk with enormous chatter; high-risk with almost none; long uncertainty then sudden approval; late-shift clicks; status changes without new evidence; many reviewers with identical language.
  5. Chatter displacementIntense attention on the wrong variable — threshold 4.8 versus 5.0 — with silence about whether the threshold measures the relevant risk. Governance displacement dressed as rigour.
  6. Normalised exceptions"Temporary workaround," "just this once," "usual exception," "approved subject to later confirmation." Each event resolves green on the dashboard. Soft data shows the exception has become the operating model — governance converted into folklore.
  7. Missing voicesField operations absent; control owner also produces the assurance evidence; every reviewer from one reporting line; contractors discussing privately but missing from the formal meeting; dissent collapsing after a particular executive enters the thread. The absence of an expected voice can be more revealing than another approval.

Chatter is a prior, never a verdict

Work on The Author's Attention found that repeated mention is a fossil of real attention — what people return to, argue about and discuss carries information static structure cannot see. It also found the critical limitation: people talk disproportionately about what is broken.5 Therefore high chatter is not high risk, low chatter is not safety, sentiment is not truth, disagreement is not dysfunction, and consensus is not correctness.

The signal must perturb, not command.

A useful radar combines weak signals: volume relative to baseline, change in volume, participant diversity, hierarchy distribution, unresolved-question count, reopening, timing relative to deadlines and shifts, qualifier density, evidence-to-assertion ratio, disagreement between discussion and final report, presence or absence of expected roles, independence of evidence sources. No single signal decides. Together they nominate a case for human investigation — the same spirit as a just culture that treats safety information as something to be encouraged, not weaponised.6

Worked composite — nomination, not verdict

A control family shows: volume 4× baseline for this decision class; participation missing the field role that normally appears; two unresolved objections still open at approval; qualifier density high in the thread, near-zero in the final pack; approval timestamp in the last hour of the shift, immediately before a reporting deadline.

The radar does not mark the control red. It produces a nomination: this pathway shows abnormal compression of unresolved uncertainty under deadline pressure. A human disposition decides whether to investigate, accept with monitoring, or clear with a recorded rationale.

The strongest instrument: formal importance vs lived attention

The Author's Attention framework also supplies a design that generalises cleanly. It compares what structure says is important with what behaviour says mattered — and treats the disagreement as more informative than either ranking alone.5 Applied organisationally:

Formal importanceExhaust attentionInterpretation
HighHighRecognised consequential issue — healthy engagement if the shape is healthy
HighLowRitualised control, invisible risk, or mature stable process — inspect which
LowHighEmerging issue, broken workflow, or unofficial dependency with no dashboard identity
LowLowProbably peripheral

The off-diagonal cells are where the radar should look. High governance importance with low chatter may be maturity — or a control nobody substantively thinks about anymore. Low formal importance with high chatter is how soft data finds issues dashboards cannot: not by replacing the dashboard, but by finding where formal structure and lived attention disagree.

When a measure becomes a target, it ceases to be a good measure — Goodhart's law in the governance register.7 Green status as a target compresses the felt-state signal out of the formal record. The radar restores a sensing layer that is hard to game without changing the deliberation itself.

From behavioural signal to shape-of-failure prediction

This is where organisational sensing connects to Shape-of-Failure Prediction — the idea that useful prediction is a falsifiable sequence of how failure will develop, not an unauditable prophecy about an outcome date.8 The radar does not need to say "asset X fails on Tuesday." It might say:

"This decision currently resembles a recurring institutional failure shape: prolonged technical uncertainty, repeated attention to one disputed metric, narrowing participation, unresolved objections disappearing from the final artefact, and approval immediately before a programme deadline."

That is specific, falsifiable, reviewable, based on receipts — and useful before the physical or financial failure. It predicts institutional preconditions, not the engineering event. Continuous review of exhaust at machine scale is exactly the Version-3 class of AI value: patterns no human team can read exhaustively on a standing basis.9 The deeper formulation is cognitive metabolism: where attention flows, pools and disappears; where uncertainty is metabolised into evidence versus merely compressed into status; where disagreement improves the decision versus where social pressure erases it.

Use organisational exhaust to identify the shape of failure before the organisation has a formal category, metric or dashboard for it.

Stay low on the Surveillance Gradient

This architecture can very easily become employee surveillance. The boundary must be architectural, not aspirational.

The primary object of analysis is the decision, the process, the control, the project, the organisational interface — not individual productivity, loyalty, personal sentiment scores, or employee "riskiness." Default outputs look like: this approval pathway shows an abnormal compression of unresolved uncertainty. They never look like: Engineer Smith is negative and delaying the project.

That maps to the Surveillance Gradient from the Workforce AI Compact: Level 1 aggregate quality assurance; Level 2 team productivity analytics; Level 3 individual behavioural monitoring; Level 4 algorithmic management. The Institutional Failure Radar is designed to live at Level 1. Aggregate first. Preserve semantic access controls. Reveal source material only through authorised investigation. Use behavioural signals to generate questions, not accusations. Climb the gradient and you recreate the governance problem you claimed to solve.

Prohibited uses (non-negotiable): individual performance scoring from chatter; loyalty or "attitude" metrics; personal risk rankings; automated status changes from soft signals alone; feeding HR disciplinary workflows from radar nominations without a separate, human, due-process investigation.

How this sits beside the rest of the stack

The radar is one sensing plane, not the whole assurance architecture.

Institutional Linter reads the codified organisation — policies, procedures, reports as a dependency graph — for contradictions, dead controls and correlated checkers.10 The radar reads behaviour around those controls. Different defects, complementary planes.

Elastic Assurance is the routing and disclosure plane: compute broadly, disclose narrowly, Soft Attestation Packages, without automatically moving the formal traffic light.11 The radar nominates; Elastic Assurance is where findings go next.

Not capacity accounting. When green is maintained by human heroics and reserve margin, that is a separate reading — a companion piece in this series (Green by Heroics), not this sensor.

Monday morning

You do not need a transformation programme. Pick one decision pathway that is formally green and consequential. Compile its soft exhaust for a bounded window. Score it against the seven shapes. Run the formal-importance × lived-attention matrix. Build one composite nomination with receipts. Route it to a human disposition — investigate, monitor, or clear with rationale. Keep the object of analysis as the pathway, not the people on it.

Commission one radar pass

Failure changes shape before it changes the numbers. The organisations that will see trouble forming are the ones that instrument felt state without turning assurance into panopticon.

If you'd like to scope a first pass over a single control family, start a conversation: scott@leverageai.com.au.

References

  1. Scott Farrell, LeverageAI. "BI Tells You Where, the Wiki Tells You Why." — structured systems locate; soft/causal layers explain. leverageai.com.au/wp-content/media/articles/106-bi-where-wiki-why.html
  2. Scott Farrell, LeverageAI. "Your Organization Has Source Code (And You Can Finally Read It)" (BI for Soft Data compile step). — exhaust as source code; as-designed vs as-operated; the read that became affordable. leverageai.com.au/wp-content/media/articles/86-your-organization-has-source-code.html
  3. Amy C. Edmondson. "Psychological Safety and Learning Behavior in Work Teams." Administrative Science Quarterly. — fear suppresses error reporting while risk accumulates; silence is not safety. web.mit.edu/.../Edmondson Psychological safety.pdf
  4. NYU Steinhardt. "Groupthink as System." — groupthink as avoidance of critical evaluation of favoured ideas; defective decisions fail to consider alternatives. wp.nyu.edu/steinhardt-appsych_opus/groupthink/
  5. Scott Farrell, LeverageAI. "The Author's Attention: Ranking Files by How Often You Talked About Them." — attention-as-fossil; perturb don't command; disagreement is its own instrument. leverageai.com.au/wp-content/media/articles/89-the-authors-attention.html
  6. SKYbrary Aviation Safety. "Just Culture." — atmosphere of trust that encourages safety-related information; supports questions-not-accusations design. skybrary.aero/articles/just-culture
  7. "Goodhart's law." — when a measure becomes a target, it ceases to be a good measure. en.wikipedia.org/wiki/Goodhart's_law
  8. Scott Farrell, LeverageAI. "Frameworks Are Second-Hand Time Travel." — frameworks as transferable shape knowledge; parent cluster for shape-of-failure prediction. leverageai.com.au/wp-content/media/articles/131-frameworks-second-hand-time-travel.html
  9. Scott Farrell, LeverageAI. "Maximising AI Cognition and AI Value Creation." — Version-3 continuous sensing; committee-think dynamics. leverageai.com.au/wp-content/media/articles/27-maximising-ai-cognition.html
  10. Scott Farrell, LeverageAI. "The Institutional Linter: Static Analysis for Your Organisation." — codified-org lint plane complementary to behavioural radar. leverageai.com.au/wp-content/media/articles/137-institutional-linter.html
  11. Scott Farrell, LeverageAI. "Elastic Assurance: Compute Broadly, Disclose Narrowly." — routing/disclosure plane for findings. leverageai.com.au/wp-content/media/articles/136-elastic-assurance.html
  12. ANZSOG. "Committee Decision Processes." — committees often optimise for acceptable consensus rather than best answer. anzsog.edu.au/.../10.21307_eb-2018-002.pdf