Both Are Green. Only One Looks Healthy
Two approvals can be identical in the structured system and opposite in institutional health. Failure often exists first as a deformation in attention — long before any dashboard number moves.
Consider two approvals that are identical in the formal record.
| Formal record | Approval A | Approval B |
|---|---|---|
| Required checks completed | Yes | Yes |
| Authorised approver | Yes | Yes |
| Risk status | Green | Green |
| Approval outcome | Approved | Approved |
The formal pipeline treats them as equivalent. The soft exhaust does not.
Approval A assembled evidence over several days. Relevant engineering, safety and operational staff participated. Objections were recorded and answered. Alternatives were considered. Final approval occurred during normal working hours. Language became more confident as evidence accumulated.
Approval B was a thirty-message thread circling one disputed number. Two engineers wrote “probably” and “should be acceptable.” The field team was never in the room. One objection was never answered. Status moved from amber to green without new evidence. Approval fired just before shift handover. The final report scrubbed the qualifiers that were live in the discussion.
Both are green. Only one looks healthy.
Declared state is not felt state
Formal systems are excellent at the organisation’s declared state: status codes, completed checklists, authorised roles, reported metrics. They were designed for that. What they systematically under-sample is the felt state — where people are uncertain, where attention is accumulating, where nobody wants ownership, where dissent is being compressed, where a supposedly routine decision is consuming abnormal cognitive energy, and where a consequential decision is consuming suspiciously little.
Most people think · Actually true
Most people think a green control means the work is healthy. Actually green means the declared process completed — which says nothing about how certainty was manufactured, who was missing, or what objections vanished on the way to the artefact.
A dashboard may say the control is green. The exhaust may show that twenty people are arguing around it, nobody can explain the number, three objections remain unresolved, and the approval was finally clicked at 5:47 pm on Friday. That is not a process-mining event. It is a shape.
When a measure becomes a target, it ceases to be a good measure.1 Green status under managerial pressure is exactly that kind of target. The organisation learns to produce the colour. The deliberation that produced the colour disappears from the formal record. Post-incident, everyone remembers that “something felt off.” Pre-incident, nothing in the dashboard had permission to say so.
The thesis
This book is about restoring that permission — carefully.
Failure changes shape before it changes the numbers. Continuously sensing the shape of attention — chatter, silence, compression, timing, participation — on organisational soft exhaust detects institutional failure preconditions before any dashboard number moves.
The product name is blunt on purpose. An Institutional Failure Radar continuously analyses organisational exhaust — not to monitor employees, but to detect abnormal shapes of attention, uncertainty, silence, consensus, timing and decision compression around consequential work. It asks how green was made. It does not replace operational metrics. It does not score people.
The reader’s question
If you lead risk, assurance, safety or compliance in a regulated, long-lived, safety-critical organisation, you already live with a familiar discomfort: work that is formally green and generates no incidents can still feel wrong. Programme packs arrive all green. Near-misses later reveal that field knowledge never reached the decision channel, or that an exception had become folklore, or that Friday-night approvals had become a habit. You do not lack dashboards. You lack a sensing layer for the felt state of decisions.
By the end of this book you will be able to:
- Name seven failure shapes that appear in soft exhaust before they appear as incidents
- Instrument declared-versus-felt divergence with a formal-importance × lived-attention matrix
- Combine weak signals into nominations for human review — priors, never verdicts
- Govern the system so it analyses decisions and controls, never individual productivity or “riskiness”
What this is not
Three adjacent disciplines sit beside this radar and must not be collapsed into it.
Not the Institutional Linter. Static analysis of the codified organisation — policies, procedures, reports as a dependency graph — is a complementary plane. The linter finds structural defects in how the organisation is written and linked. The radar finds deformations in how people attend and decide around those controls.
Not Elastic Assurance. Once a finding exists, routing it, disclosing it narrowly, and packaging soft attestations without automatically moving the formal traffic light is a separate architecture. The radar nominates. Elastic Assurance is where findings go next.
Not capacity accounting. When green is maintained by human heroics and thin reserve margin, that is a different reading of the exhaust — a companion argument in this series (Green by Heroics), not this sensor.
We start where the sensing layer itself must be named. Before you can hunt failure shapes, you need a clear account of what organisational behavioural telemetry is — and what it is not.
Organisational Behavioural Telemetry
Soft exhaust does not only contain facts. It contains the organisation’s behaviour around facts and decisions — and that behaviour is now continuously readable.
Open a week of real work and ignore the structured fields for a moment. What remains is the felt state:
- where people are uncertain
- where attention is accumulating
- where nobody wants ownership
- where dissent is being compressed
- where a supposedly routine decision is consuming abnormal cognitive energy
- where a consequential decision is consuming suspiciously little energy
That is a fundamentally different sensing layer from the one your dashboards already own. Dashboards observe the organisation’s outputs. Soft data can observe its behaviour around the decisions that produce those outputs. We call that layer organisational behavioural telemetry.
The compile is not the radar
BI for Soft Data already established the substrate. Structured systems record outcomes. Emails, meetings and documents hold the causal layer: reasoning, objections, trade-offs, relationship texture — the layer where the why lives. Related work on natural-key joins shows how soft corpora become provenance-bearing rather than merely “similar.”
That compile is necessary. It is not sufficient for this book’s purpose. Once the exhaust is readable, you can ask a second family of questions — not only “what was decided?” but “what did the organisation do around the decision?”
What behavioural telemetry compiles
- How much discussion occurred — and how that volume changed over time
- Who participated, and who was absent relative to the roles this decision class usually needs
- Whether objections were answered or merely stopped
- How often a decision was reopened
- How language moved from uncertain to certain
- How long deliberation took, and when approval occurred
- Whether the evidence changed before the status changed
- Whether independent groups actually formed independent views
The dashboard sees the green light. The exhaust sees how it became green.
An institutional nervous system
Think of the soft-data layer as the organisation’s nervous system. Nerves do not replace blood chemistry. They carry a different class of signal: where pressure is building, where sensation has gone numb, where a limb is compensating for another. Organisational behavioural telemetry does the same for decisions and controls. It does not certify that a transformer is healthy or that a balance sheet balances. It certifies something your formal pipeline was never designed to certify: whether the path to green looks like healthy deliberation or like compression under pressure.
That distinction matters for a critical-infrastructure operator as much as for a bank’s control function. The formal pipeline will always be required. The missing layer is continuous sensing of cognitive friction, silence and participation shape — the felt state that sits underneath the declared state.
Disambiguation — do not import the wrong “telemetry”
In adjacent AI-operations writing, “behavioural telemetry” sometimes means whether users accept, edit, reject or ignore an AI recommendation. That is useful for model drift. It is not this book’s subject.
| Term | In this book | Not this |
|---|---|---|
| Organisational behavioural telemetry | Attention-shape on organisational exhaust | AI output accept / edit / ignore rates |
| Soft exhaust | Threads, meetings, reports, chat, decision packs | SCADA tags or ERP status alone |
| Sensor output | Nomination for human review | Automatic traffic-light change |
What the formal pipeline will never show you
Process mining and conformance checking answer whether activity followed a documented sequence. They are excellent at that. They are structurally uninterested in whether the sequence still deserves to exist, whether the people who executed it believed the evidence, or whether the final artefact still contains the uncertainty that was alive in the discussion. Those questions live in language, participation and timing — soft exhaust properties, not event-log fields.
That is why organisational behavioural telemetry is not “BI, but for email volume.” Volume is one weak signal among many. The compile that matters is multi-dimensional: who, when, how certain, what disappeared between thread and pack, which expected voice never arrived. Once those dimensions are joinable, the seven shapes in the next chapter become detectable rather than anecdotal.
Why this layer is newly affordable
None of these questions is philosophically new. Seasoned assurance leaders have always asked them in sampling exercises and incident reviews. What was missing was the economics of standing review. Continuously reading the soft estate of a large organisation — every consequential pathway, every week — was simply not a job a human institution could staff. Machine-scale reading changes the unit price of that attention. Continuous strategic sensing of patterns no team can exhaustively read is exactly the class of AI value that only becomes real when cognition is cheap enough to run in the background.
Affordable reading is not the same as wise use. The next chapter gives the vocabulary the radar needs: seven shapes institutional failure takes in soft exhaust before it has a number, a risk category, or a dashboard tile.
Seven Shapes of Institutional Failure
Failure leaves a recognisable attention-shape long before it has a formal category. These seven shapes are the radar’s taxonomy — priors that nominate inspection, never verdicts that accuse.
The origin of this whole line of work is simple: when you review soft data and organisational exhaust — work reports, email chatter, items that never enter the formal pipeline — you can see the shape of a problem. Too much chatter around a number. Not enough. A green light executed too easily, too quickly, or at the end of a shift. Indecision and groupthink still greenlit. Shapes of organisational failure that are inherently not on dashboards.
Rule of use
Each shape produces a question for human review. None produces an automatic red light, a person-score, or a disciplinary trigger. Chatter is a prior. Silence is a prior. Compression is a prior. Humans dispose.
1. Excess chatter
A supposedly routine control suddenly produces several times its normal email or Teams traffic. That does not prove failure. It indicates abnormal cognitive friction.
Possible interpretations: the procedure is unclear; the evidence is contradictory; staff no longer trust the underlying number; responsibility is ambiguous; the decision does not fit the existing governance model; the formal process is concealing a difficult judgement. The chatter is not the answer. It is a prior saying: something here deserves inspection.
Vignette
A weekly checklist that usually generates a handful of clarifying messages suddenly produces a multi-day thread about one field no one can source. The formal status remains on track. The exhaust is already screaming friction.
2. Suspicious silence
Silence may be equally important. A high-consequence decision is approved with no visible challenge, no cross-functional discussion, no contribution from the people closest to the work, no alternatives, no recorded uncertainty, no follow-up questions.
That may mean the case was genuinely straightforward. It might also mean dissent has become socially unsafe; approval is ritualised; everyone assumes somebody else checked; the process is so normalised that nobody sees its risk; or the people who know the most are outside the decision channel.
The useful comparison is not “how many messages were sent?” It is: how much deliberation would a decision of this type, novelty and consequence normally produce?
Psychological-safety research has long shown the asymmetry: under cultures of fear, staff report fewer errors while risk accumulates underneath.2 Suspicious silence is therefore a safety signal about the decision channel, not a productivity metric about the people in it.
Vignette
A major interface change is approved with a three-line email and no field signature. Last year, comparable changes produced multi-day technical threads. The novelty and consequence have not fallen. The deliberation has.
3. Consensus compression
The discussion contains uncertainty and disagreement, but the formal artefact suddenly becomes clean and unanimous. Signals include: ten different interpretations becoming one unsupported sentence; risks raised in email disappearing from the final report; qualifiers such as “subject to,” “assuming” and “not yet confirmed” vanishing; minority objections recorded as “stakeholders consulted”; an amber discussion producing a green summary.
This is not ordinary “groupthink detection” as a personality critique. It is comparing the semantic shape of the deliberation with the semantic shape of the decision artefact.
Where did uncertainty disappear without being resolved?
Group-decision research describes defective decisions as those that avoid critical evaluation of favoured ideas and fail to consider more favourable alternatives.3 Committees under time pressure often optimise for an answer stakeholders will accept rather than the best available answer.4 Compression leaves a fingerprint in the exhaust even when the formal pack looks immaculate.
Vignette
The thread is full of “not yet confirmed” and “subject to site conditions.” The board pack contains none of those words. The residual risk section reads as if the week of argument never happened.
4. Approval-friction anomalies
Compare decision consequence with decision friction.
| Pattern | Possible signal |
|---|---|
| Low-risk decision, enormous chatter | Broken process, unclear ownership, dead constraint |
| High-risk decision, almost no chatter | Ritual approval or absent challenge |
| Long uncertainty, sudden approval | Deadline pressure or consensus collapse |
| Approval late in shift | Fatigue, handover pressure, queue clearing |
| Status changes without new evidence | Administrative green rather than evidentiary green |
| Repeated re-approval | Unstable assumptions or weak initial decision |
| Many reviewers, identical language | Correlated assurance rather than independent assurance |
None is proof. Together they form a failure signature.
Vignette
A low-risk template approval thrashes for a week because nobody owns the exception path. The same week, a high-risk temporary deviation sails through in twenty minutes with identical language from three reviewers who all read the same one-page briefing.
5. Chatter displacement
People may be discussing the wrong thing intensely: enormous discussion about whether a threshold is 4.8 or 5.0; almost none about whether the threshold measures the relevant risk. Repeated debate about report formatting; no challenge to where the underlying evidence came from. Detailed conversation about compliance wording; silence about whether the control can prevent anything.
That is governance displacement: the organisation applies intense attention inside an inherited frame while leaving the frame itself unexamined. It is particularly dangerous because the activity looks like rigour.
Vignette
Thirty messages argue about fonts and section order in a residual-risk annex. Zero messages ask whether the source system for the annex’s numbers has been revalidated since the last restructure.
6. Normalised exceptions
The exhaust repeatedly contains phrases such as: “temporary workaround,” “just this once,” “pending the permanent fix,” “usual exception,” “we normally handle this manually,” “approved subject to later confirmation,” “we’ve always done it this way.”
A dashboard may record each event as successfully resolved. The soft-data layer sees that an exception has become the operating model. The failure shape is not an individual breach. It is the gradual conversion of governance into folklore.
Vignette
A “temporary” bypass has been renewed monthly for eighteen months. Every month the formal record is green. The exhaust’s phrase fossils show no living plan for the permanent fix — only the ritual of re-approving the temporary.
7. Missing voices
Participation itself is evidence. Was anyone from field operations involved? Did the control owner also produce the assurance evidence? Was the person most exposed to the consequence represented? Did every reviewer come from the same reporting line? Were contractors discussing concerns privately but absent from the formal meeting? Did senior management dominate the conversation before technical views stabilised? Did dissent fall sharply after a particular executive entered the thread?
The absence of an expected voice can be more revealing than the presence of another approval.
Vignette
Contractors voice concerns in a side channel the formal system never sees. The meeting minutes record “contractor input noted — no objections.” The missing voice is not a person to score. It is a channel failure.
Taxonomy, not accusation
These seven shapes are the radar’s shared language. Chapter 4 puts them to work on the flagship demonstration: reconstructing how green was made, end to end, with nomination cards that carry receipts rather than verdicts.
How Green Was Made
The flagship demonstration: two greens and one unofficial high-chatter workflow, reconstructed as radar nominations with receipts — not as red lights.
Chapter 1 introduced Approval A and Approval B as a contrast. This chapter develops them as if the Institutional Failure Radar had run overnight over a bounded window of soft exhaust. The point is not theatre. The point is to show the output form the doctrine requires: a nomination about a pathway, with multi-signal receipts, for a human to dispose.
The dashboard sees the green light. The exhaust sees how it became green.
Worked case 1 — Deadline compression pathway
Start from the formal record of Approval B. Everything required is present. The colour is green. Now open the exhaust and reconstruct the week in shape language (illustrative narrative — the radar reports patterns and receipts, not invented statistics).
Timeline of a shape assembling
Early thread: technical uncertainty is explicit. Qualifying language appears — “probably,” “should be acceptable,” “subject to confirmation.”
Mid-thread: attention narrows to one disputed number. Traffic rises well above the baseline for this decision class. The field role that normally appears on comparable decisions is never invited.
Objection: one substantive challenge is raised. Subsequent messages do not answer it. The objection simply stops appearing.
Status move: amber becomes green. No new evidence artefact is attached to the status change. The administrative colour moves first.
Approval moment: the click lands in the last hour of the shift, immediately before a reporting deadline.
Final artefact: the decision pack is clean. The qualifiers that filled the thread are gone. Minority concerns are summarised as consultation completed.
Mapped to the taxonomy (Ch3), this is not one shape. It is a composite signature: local excess chatter around a disputed metric; consensus compression between thread and pack; approval-friction anomaly on timing and status-without-evidence; missing voices (field role); a touch of chatter displacement (the number absorbing attention that should have stayed on the underlying risk).
The nomination card — what the radar actually emits
Nomination — not a verdict
Object: Decision pathway / control family (not a person)
Claim: This approval pathway shows an abnormal compression of unresolved uncertainty under deadline pressure.
Receipts (illustrative classes):
- Volume elevated versus baseline for this decision class
- Expected field role absent from participation set
- Unresolved objection still open at approval time
- Qualifier density high in discussion, near-zero in final pack
- Approval timestamp class: late-shift / pre-deadline
- Status transition without linked new evidence
Disposition options for humans: investigate · monitor next N instances · clear with recorded rationale
Explicit non-claims: does not mark the formal control red; does not rank individuals; does not assert that an incident will occur.
That last line is load-bearing. The radar’s success metric is better questions earlier, not more red lights. If the system starts auto-moving formal status from soft signals, it has left the doctrine and entered a different product — one that will be gamed, resisted and eventually corrupted.
Worked case 2 — The unofficial dependency
The second flagship example is the other key case the brief requires: a workflow of low formal importance with abnormally high chatter.
There is no risk-register row. There is no dashboard tile. The process does not appear in the monthly control report. And yet the soft exhaust shows sustained, elevated traffic: repeated handoffs, the same unofficial step mentioned across teams, workarounds that never graduate into procedure, a standing set of “who do I actually ask?” messages.
The formal system has no place to put this. The radar does. In the language of Chapter 6’s matrix, this is the low-formal / high-attention cell: an emerging issue, broken workflow, or unofficial dependency with no dashboard identity.
Nomination — unofficial citizenship
Object: Workflow cluster (joined on natural keys across threads and teams)
Claim: Lived attention without formal citizenship — recommend ownership and risk-identity review.
Receipts: sustained elevated traffic vs peer workflows; repeated workaround language; cross-team mention of the same unofficial handoff; absence of formal owner in governance maps.
Disposition: assign temporary owner · promote to formal control · retire the workaround · or document why the chatter is healthy noise.
This is how soft data finds what dashboards cannot: not by replacing the dashboard, but by noticing where formal structure and lived attention disagree. Approval B is the high-formal pathway that looks clean while its deliberation shape is unhealthy. The unofficial dependency is the low-formal pathway that the dashboard cannot even see.
What “healthy green” looks like in exhaust
For completeness, reconstruct Approval A as a negative control — the shape that should not nominate.
Evidence assembled over several days. Engineering, safety and operations present. Objections recorded and answered (not merely stopped). Alternatives considered. Approval in normal hours. Language becoming more confident as evidence accumulates. Final artefact retains appropriate residual-risk language rather than scrubbing uncertainty into false unanimity.
The formal record is still green. The exhaust agrees that the green was earned. A radar that only knows how to alarm is as useless as a dashboard that only knows how to soothe. The doctrine needs both: nominate the deformed path; leave the healthy path alone.
From vignette to method
These cases already imply a multi-signal recipe. Chapter 5 makes that recipe explicit: the composite weak-signal panel, the worked nomination that combines volume, participation, timing and qualifier density, and the discipline that keeps every signal a prior rather than a command.
Weak Signals, Strong Nominations
No single soft signal should decide anything. Twelve weak signals combine into a prior that nominates a case for human investigation.
Work on The Author’s Attention found that repeated mention is a fossil of real attention — what people return to, argue about and discuss carries information static structure cannot see. It also found the critical limitation: people talk disproportionately about what is broken.
Therefore:
- high chatter does not equal high risk
- low chatter does not equal safety
- sentiment does not equal truth
- disagreement does not equal dysfunction
- consensus does not equal correctness
Chatter should be a prior, never a verdict. The signal must perturb, not command.
The composite panel
A useful system combines multiple weak signals. None decides. Together they nominate.
Twelve weak signals
- Volume relative to baseline (for this decision class, not org-wide noise)
- Change in volume (trajectory, not only level)
- Participant diversity
- Hierarchy distribution (who is speaking — and when)
- Unresolved-question count
- Repeated reopening of the same decision
- Timing relative to deadlines and shifts
- Qualifier density (“probably,” “subject to,” “not yet confirmed”)
- Evidence-to-assertion ratio
- Disagreement between discussion and final report
- Presence or absence of expected roles
- Independence of evidence sources
Baselines matter. A control family that always generates dense technical debate should not be nominated merely for being talkative. A high-consequence pathway that is usually quiet and suddenly goes silent-to-the-point-of-ritual is a different story. Compare like with like: decision class, novelty band, consequence band.
Worked composite — volume, participation, timing, qualifiers
Return to the deadline-compression pathway (Ch4). The radar does not emit twelve separate alarms. It emits one nomination built from concurrent weak signals:
Composite example
Volume vs baseline: elevated for this decision class over the window.
Participation: expected field role absent; reviewers clustered in one reporting line.
Unresolved questions: at least one substantive objection without subsequent answer.
Qualifier density: high in the thread; near-zero in the final pack (discussion-vs-artefact disagreement).
Timing: approval in the last hour of shift, immediately before a reporting deadline.
Evidence-to-assertion: status moved without a new evidence artefact.
Nomination: abnormal compression of unresolved uncertainty under deadline pressure.
Human disposition: investigate (open a review), monitor (watch the next instances of this pathway), or clear (record why this shape is acceptable here).
Notice what is missing from that card: names ranked by message volume; sentiment scores; a machine-moved traffic light; a claim that an asset will fail on a date. Those omissions are the product.
Why “just culture” is design, not tone
Aviation’s just-culture tradition defines an atmosphere of trust in which people are encouraged — even rewarded — for providing essential safety-related information, rather than punished for surfacing it.5 Soft-exhaust sensing without that design intent becomes a snitch engine. Soft-exhaust sensing with it becomes a way to ask better questions about pathways while protecting the people who generate the signal by doing their jobs out loud.
Practical implications:
- Aggregate first. Default views are pathway-level and control-family-level.
- Access control on receipts. Source material opens only through authorised investigation.
- Questions, not accusations. Output language is about compression, silence, displacement — not about loyalty or attitude.
- Human disposition always. The system nominates; people decide.
Anti-patterns
Sentiment as risk. Personal mood is not institutional precondition.
Single-threshold auto-red. One volume spike is not a verdict.
Employee leaderboards. Ranking people by chatter volume inverts the sensor into surveillance.
Consensus-as-quality. Unanimous language can be compression, not health.
Ignoring baselines. Without decision-class baselines, everything looks anomalous or nothing does.
Decision-class baselines are not optional
Two errors destroy composite sensing. The first is treating the whole organisation as one baseline — so noisy domains always look “high risk” and quiet domains always look “safe.” The second is treating every pathway as unique, so nothing is ever anomalous. The discipline is intermediate: baseline by decision class, novelty band and consequence band. A low-risk template approval and a high-consequence interface change are different animals. Compare each to its own peers.
Trajectory matters as much as level. A pathway at 1.2× baseline and rising for three cycles may be more interesting than a pathway at 3× baseline that has been 3× for years because that is how the work is done. The composite panel’s second signal — change in volume — exists for that reason.
The next instrument
Composites answer “what shape is assembling on this pathway?” The most valuable organisational instrument may still be a different comparison: not signal versus signal inside the exhaust, but formal importance versus lived attention. Chapter 6 makes that disagreement matrix definitive.
The Disagreement Instrument
Disagreement between formal importance and lived attention is diagnostically more valuable than either ranking alone. The off-diagonal cells are where the radar should hunt.
The Author’s Attention framework compares what structure says is important with what behaviour says mattered — and treats the disagreement as its own instrument. Structural prominence is not importance. Mention frequency is a behavioural fossil. Neither ranking alone is enough; the mismatch is the hunt.
That design generalises cleanly from a code corpus to organisational exhaust.
The matrix
| Formal importance | Exhaust attention | Interpretation |
|---|---|---|
| High | High | Recognised consequential issue — engagement is present; still inspect shape of that engagement |
| High | Low | Ritualised control, invisible risk, or mature stable process — discriminate which |
| Low | High | Emerging issue, broken workflow, or unofficial dependency with no dashboard identity |
| Low | Low | Probably peripheral |
The on-diagonal cells are comparatively calm. High/high means the organisation already treats the issue as consequential — though Chapter 3’s shapes still apply if the attention is compressed or displaced. Low/low is usually noise. The off-diagonals are where formal structure and lived attention disagree — and where BI for Soft Data finds issues dashboards cannot, not by replacing the dashboard, but by hunting that disagreement.
High formal importance, low chatter
Two very different stories produce the same cell.
Mature process. The control is well understood. Novelty is low. Experts are available. Near-miss culture is open. Silence is informed, not hollow. People could explain the control if asked; they simply do not need to re-litigate it weekly.
Ritualised control. The control still carries formal weight — risk-register criticality, regulatory linkage, board visibility — but nobody substantively thinks about it anymore. Approvals are administrative. When challenged, owners cannot reconstruct why the control exists or whether it still binds a live failure mode. Silence is hollow.
Discriminating questions
- Can the owner explain the failure mode this control is for without reading the procedure?
- Has the enabling constraint changed while the control stayed still?
- Is silence matched by open near-miss reporting, or by empty incident history that looks too clean?
- Do comparable high-importance controls show healthy technical deliberation — making this silence an outlier?
The Institutional Linter’s plane (codified contradictions, dead constraints) often meets this cell from the other side. The radar’s contribution is the behavioural half: is the silence informed or empty?
Low formal importance, high chatter
This is the unofficial-dependency cell from Chapter 4. Sustained attention without formal citizenship. Possible emerging risk, broken workflow, or a standing workaround that has not earned a dashboard tile. The organisation is already paying cognitive cost; it has not yet given the issue a name, an owner, or a control identity.
Radar question set for this cell:
- What natural-key join keeps this chatter cluster together?
- Who is the de facto owner — and who is the missing formal owner?
- Is the chatter producing learning (healthy) or perpetual rework (broken)?
- Should this be promoted into the risk register, fixed as a process defect, or left alone with a recorded rationale?
How the inputs are built
Formal importance is declared: risk-register criticality, safety-case linkage, regulatory obligation weight, financial materiality, board visibility. It is not inferred from chatter. That is the point of the disagreement.
Lived attention is not raw message count. It is the composite panel from Chapter 5 — volume versus baseline, participation, timing, qualifier density, discussion-versus-artefact divergence, expected roles — rolled into an attention estimate for a pathway. Volume alone would reintroduce every bias Author’s Attention already warned against.
Output is a cell classification plus a nomination, not a single organisational risk score. Scores invite Goodhart. Classifications invite investigation.
Green as target
When a measure becomes a target, it ceases to be a good measure.1 Green status under managerial pressure is exactly that kind of target. The formal importance axis remains, but the felt-state signal is trained out of the formal record. The matrix restores a sensing plane that is hard to game without changing the deliberation itself — which is the point of sensing deliberation in the first place.
The disagreement is its own instrument.
Knowing where to look is not yet knowing what kind of prediction this is. Chapter 7 frames the deeper formulation: cognitive metabolism, and shape-of-failure prediction operationalised inside the organisation.
Cognitive Metabolism & Shape-of-Failure Prediction
Dashboards observe outputs. The radar observes cognitive metabolism — where attention flows, pools, disappears, and is compressed into status. Useful prediction here is a falsifiable shape of institutional preconditions, not an event date.
Use organisational exhaust to identify the shape of failure before the organisation has a formal category, metric or dashboard for it.
Cognitive metabolism
The dashboard observes the organisation’s outputs. BI for Soft Data, used as a behavioural sensor, can observe its cognitive metabolism:
- where attention flows
- where it pools
- where it disappears
- where uncertainty is metabolised into evidence
- where uncertainty is merely compressed into status
- where disagreement improves the decision
- where social pressure erases disagreement
- where a process feels difficult before anybody can articulate why
That formulation is strategically important because it names a sensing target that is not “more KPIs.” Metabolism is about conversion: does the organisation convert uncertainty into evidence, or into colour? Does it convert dissent into better decisions, or into silence? Those conversions leave exhaust shapes long before they leave incident tickets.
This is also why the economics work now. Continuous sensing of patterns no human team can read exhaustively is a Version-3 class of AI value — previously infeasible as a standing practice, now a compute cost rather than a headcount fantasy.
Shape-of-failure prediction — parent and operational child
At strategy level, Shape-of-Failure Prediction argues that the valuable thing a serious reasoning engine does on a fragile strategy is not predict outcomes but predict the falsifiable shape of failure — what failure will look like, in what sequence — so the prediction can be checked against reality later. Frameworks themselves are a form of second-hand time travel: portable shape knowledge transferred across contexts.
This book operationalises that parent inside the organisation, on behavioural exhaust. The radar does not need to say:
“Transformer X will fail on Tuesday.”
It might say:
“This decision currently resembles a recurring organisational failure shape: prolonged technical uncertainty, repeated attention to one disputed metric, narrowing participation, unresolved objections disappearing from the final artefact, and approval immediately before a programme deadline.”
That statement is specific, falsifiable, reviewable, based on receipts, and useful before a physical or financial failure. It predicts the institutional preconditions of failure, not necessarily the engineering event itself. If the next three instances of the pathway show answered objections, restored field participation and daytime approvals with evidence attached, the nomination was productive even if “nothing broke.” The radar’s job was never prophecy. It was earlier, better inspection.
A pattern language for critical operators
For a transmission network operator or similar regulated, safety-critical estate, the shapes tend to recur in recognisable families. Present them as a watch-list — not as accusations of any named organisation:
- deadline-driven closure overwhelming engineering caution
- field knowledge failing to reach project governance
- repeated temporary controls becoming permanent
- multiple assurance bodies relying on the same source narrative
- project status remaining green while soft-data friction accelerates
- risks being linguistically softened as they travel upwards
- regulatory compliance demonstrated through artefacts that operations quietly route around
Each maps onto the Chapter 3 taxonomy and the Chapter 5 composite panel. “Linguistically softened as they travel upwards” is consensus compression plus hierarchy distribution. “Temporary controls becoming permanent” is normalised exceptions. “Field knowledge failing to reach governance” is missing voices. The vocabulary is portable; the receipts are local.
Public post-incident reports as shape primers
When public post-incident literature describes silenced dissent, missing frontline voice, deadline compression, or exceptions that had become normal, reread those passages as radar shapes. Do it without inventing frequencies or retrofitting a claim that “the radar would have prevented that event.” The honest claim is narrower and stronger: these preconditions produce nominations earlier than lagging metrics, and earlier nomination is what just-culture, high-reliability practice has always wanted — better questions while the system is still formally green.
Committee dynamics, without scorning committees
Time pressure and social dynamics cause groups to optimise for acceptable consensus, narrow alternatives prematurely and suppress challenging information.4 Groupthink research describes defective decisions as failures to critically evaluate favoured paths.3
The radar does not “fix people of groupthink.” It surfaces compression signatures — discussion-versus-artefact divergence, sudden certainty, missing alternatives — for human review. That is the difference between behavioural science as insult and behavioural telemetry as instrument.
Power without panopticon
By this point the doctrine is dangerous in the useful sense: it can see more than dashboards see. The last chapter is the governance boundary that keeps that power from becoming the problem it was built to find — the Surveillance Gradient, the prohibited uses, and the Monday-morning first pass.
Stay Low on the Surveillance Gradient
The same exhaust that enables pre-incident sensing can become panopticon. Architecture must force the radar to analyse decisions and controls — never score people — and stay at Level 1 of the Surveillance Gradient.
Default good output
“This approval pathway shows an abnormal compression of unresolved uncertainty.”
Default bad output
“Engineer Smith is negative and delaying the project.”
If your design cannot enforce that distinction, do not build the radar. You will recreate the governance problem you claimed to solve.
The Surveillance Gradient
The Workforce AI Compact classifies workplace monitoring on a four-level gradient. Organisations slide from Level 1 to Level 4 incrementally; each step seems reasonable in isolation. Governance gates must sit at each transition.
| Level | Category | Governance |
|---|---|---|
| 1 | Aggregate / sample quality assurance on decisions & controls | Standard practice — radar home |
| 2 | Team productivity analytics | Requires transparency |
| 3 | Individual behavioural monitoring | Requires governance approval |
| 4 | Algorithmic management (AI-directed work) | Requires full Compact + ongoing review |
The Institutional Failure Radar is designed to live at Level 1. It analyses decisions, processes, controls, projects and organisational interfaces. It does not score individual productivity, loyalty, personal sentiment, or employee “riskiness.”
Prohibited uses
Non-negotiable
- Individual productivity scoring from chatter volume or tone
- Loyalty or “attitude” metrics derived from exhaust
- Personal sentiment as a risk score
- Employee “riskiness” rankings
- Hidden performance management via radar nominations
- Automatically changing formal traffic lights from soft signals alone
- Feeding disciplinary workflows without a separate, human, due-process investigation
Signals generate questions, not accusations.
That rule aligns with just-culture practice: safety information is something the system encourages, not weaponises.5 Aggregate first. Preserve semantic access controls. Reveal source material only through authorised investigation.
Why Level 1 is a product constraint
It is tempting to treat the Surveillance Gradient as a policy memo: “we promise not to score people.” Policy memos rot. Product constraints do not. Level 1 means the default schema has no employee risk field; the default UI has no person-rank view; the default export is pathway-level; opening message-level receipts requires a separate authorisation step with an investigation purpose. If those constraints are missing, the gradient will be climbed by a well-intentioned manager who only wanted “a little more detail.”
The same constraint protects the signal. Once people believe exhaust is used to rank them, they stop writing the uncertainty that makes the radar useful. You will get cleaner formal packs and emptier soft data — consensus compression as an adaptive response to surveillance. Stay at Level 1 or lose the sensor.
Monday morning — commission one radar pass
You do not need a transformation programme.
- Pick one consequential, formally green decision pathway or control family.
- Bound a time window and compile its soft exhaust (BI for Soft Data substrate).
- Score the window against the seven shapes (Ch3).
- Place the pathway on the formal-importance × lived-attention matrix (Ch6).
- Build one composite nomination with receipts (Ch5).
- Human disposition: investigate, monitor, or clear with recorded rationale.
- Do not rank individuals. Do not move formal status automatically.
- If the nomination is load-bearing, route it through a narrow disclosure path — compute broadly, disclose narrowly — rather than flooding the formal traffic light.
Where this sits in the stack
Institutional Linter — static analysis of the codified organisation; complementary plane to behavioural radar.
Elastic Assurance — routing, disclosure, Soft Attestation Packages; where findings go after nomination.
Green by Heroics — capacity, human reserve margin, green maintained by strain. Adjacent, not this sensor. Name it; do not absorb it.
Later companions in this series (governance barbell, intent compiler, cognition scarcity audit) — name in prose when relevant; they are not yet the radar’s job.
Close
Formal systems will keep recording the declared state. They should. The organisations that will see trouble forming are the ones that also instrument the felt state — chatter, silence, compression, timing, participation — without climbing the Surveillance Gradient.
Failure changes shape before it changes the numbers. The Institutional Failure Radar is the discipline of reading that shape continuously, nominating with receipts, and leaving judgement where it belongs: with accountable humans reviewing decisions and controls, not with a system scoring the people who produce the exhaust by doing their work out loud.
Commission one radar pass
Pick a single control family. Compile its exhaust. Name the shapes. Build one nomination. Keep the object of analysis as the pathway.
If you’d like to scope a first pass: scott@leverageai.com.au
References & Sources
The evidence base behind every claim — primary research, industry analysis, and technical specifications
Research Methodology
This ebook draws on primary research from standards bodies, independent research firms, enterprise technology vendors, and consulting firms. Statistics cited throughout have been cross-referenced against primary sources.
Frameworks and interpretive analysis developed by Scott Farrell / LeverageAI are listed separately below — these represent the practitioner lens through which external research is interpreted, and are not cited inline to avoid self-promotional appearance.
Primary Research & Standards Bodies
Wikipedia — Goodhart's law [1]
When a measure becomes a target, it ceases to be a good measure — green status as target compresses felt-state signal
https://en.wikipedia.org/wiki/Goodhart%27s_law
Amy C. Edmondson — Psychological Safety and Learning Behavior in Work Teams [2]
Fear suppresses error reporting while risk accumulates; silence is not safety
https://web.mit.edu/curhan/www/docs/Articles/15341_Readings/Group_Performance/Edmondson%20Psychological%20safety.pdf
NYU Steinhardt — Groupthink as System [3]
Groupthink as avoidance of critical evaluation of favoured ideas; defective decisions fail to consider alternatives
https://wp.nyu.edu/steinhardt-appsych_opus/groupthink/
ANZSOG — Committee Decision Processes [4]
Committees often optimise for acceptable consensus rather than best answer
https://anzsog.edu.au/app/uploads/2022/06/10.21307_eb-2018-002.pdf
SKYbrary Aviation Safety — Just Culture [5]
Atmosphere of trust that encourages safety-related information; supports questions-not-accusations
https://skybrary.aero/articles/just-culture
LeverageAI / Scott Farrell — Practitioner Frameworks
The interpretive frameworks, architectural patterns, and practitioner analysis in this ebook were developed through enterprise AI transformation consulting. The articles below are the underlying thinking behind those frameworks. They are listed here for transparency and further exploration — not cited inline, as this is the author's own analytical voice.
Scott Farrell, LeverageAI — The Institutional Linter: Static Analysis for Your Organisation
Codified-org lint plane complementary to behavioural radar
https://leverageai.com.au/wp-content/media/articles/137-institutional-linter.html
Scott Farrell, LeverageAI — Elastic Assurance: Compute Broadly, Disclose Narrowly
Routing and disclosure plane for findings; Soft Attestation Packages
https://leverageai.com.au/wp-content/media/articles/136-elastic-assurance.html
Scott Farrell, LeverageAI — Your Organization Has Source Code (And You Can Finally Read It)
BI for Soft Data compile step: exhaust as source code; as-designed vs as-operated
https://leverageai.com.au/wp-content/media/articles/86-your-organization-has-source-code.html
Scott Farrell, LeverageAI — The Soft Join: SQL Discipline for Soft Data
Natural-key joins for soft data; provenance not resemblance
https://leverageai.com.au/wp-content/media/articles/88-the-soft-join.html
Scott Farrell, LeverageAI — BI Tells You Where, the Wiki Tells You Why
Structured systems locate; soft/causal layers explain
https://leverageai.com.au/wp-content/media/articles/106-bi-where-wiki-why.html
Scott Farrell, LeverageAI — Maximising AI Cognition and AI Value Creation
Version-3 continuous sensing; patterns no human reads exhaustively
https://leverageai.com.au/wp-content/media/articles/27-maximising-ai-cognition.html
Scott Farrell, LeverageAI — The Author's Attention: Ranking Files by How Often You Talked About Them
Attention-as-fossil; perturb don't command; disagreement instrument
https://leverageai.com.au/wp-content/media/articles/89-the-authors-attention.html
Scott Farrell, LeverageAI — Frameworks Are Second-Hand Time Travel
Frameworks as transferable shape knowledge; shape-of-failure parent cluster
https://leverageai.com.au/wp-content/media/articles/131-frameworks-second-hand-time-travel.html
About This Reference List
Compiled July 2026. All URLs verified at time of compilation. Regulatory documents and standards specifications are subject to revision — check primary sources for the most current versions.
Some links to academic papers and vendor research may require free registration. Government and standards body publications are freely accessible.