Leverage AI
LeverageAI · Assurance & Soft Data

The Institutional Failure Radar

Failure Changes Shape Before It Changes the Numbers

Formal systems record the declared state. Soft exhaust records the felt state. Continuously sensing the shape of attention — chatter, silence, compression, timing — detects institutional failure preconditions before any dashboard number moves.

A field guide for risk, assurance and safety leaders who need to see how green was made.

You will leave able to:

By Scott Farrell · LeverageAI

01
Part I — Declared vs Felt

Both Are Green. Only One Looks Healthy

Two approvals can be identical in the structured system and opposite in institutional health. Failure often exists first as a deformation in attention — long before any dashboard number moves.

Consider two approvals that are identical in the formal record.

Formal record Approval A Approval B
Required checks completedYesYes
Authorised approverYesYes
Risk statusGreenGreen
Approval outcomeApprovedApproved

The formal pipeline treats them as equivalent. The soft exhaust does not.

Approval A assembled evidence over several days. Relevant engineering, safety and operational staff participated. Objections were recorded and answered. Alternatives were considered. Final approval occurred during normal working hours. Language became more confident as evidence accumulated.

Approval B was a thirty-message thread circling one disputed number. Two engineers wrote “probably” and “should be acceptable.” The field team was never in the room. One objection was never answered. Status moved from amber to green without new evidence. Approval fired just before shift handover. The final report scrubbed the qualifiers that were live in the discussion.

Both are green. Only one looks healthy.

Declared state is not felt state

Formal systems are excellent at the organisation’s declared state: status codes, completed checklists, authorised roles, reported metrics. They were designed for that. What they systematically under-sample is the felt state — where people are uncertain, where attention is accumulating, where nobody wants ownership, where dissent is being compressed, where a supposedly routine decision is consuming abnormal cognitive energy, and where a consequential decision is consuming suspiciously little.

Most people think · Actually true

Most people think a green control means the work is healthy. Actually green means the declared process completed — which says nothing about how certainty was manufactured, who was missing, or what objections vanished on the way to the artefact.

A dashboard may say the control is green. The exhaust may show that twenty people are arguing around it, nobody can explain the number, three objections remain unresolved, and the approval was finally clicked at 5:47 pm on Friday. That is not a process-mining event. It is a shape.

When a measure becomes a target, it ceases to be a good measure.1 Green status under managerial pressure is exactly that kind of target. The organisation learns to produce the colour. The deliberation that produced the colour disappears from the formal record. Post-incident, everyone remembers that “something felt off.” Pre-incident, nothing in the dashboard had permission to say so.

The thesis

This book is about restoring that permission — carefully.

Failure changes shape before it changes the numbers. Continuously sensing the shape of attention — chatter, silence, compression, timing, participation — on organisational soft exhaust detects institutional failure preconditions before any dashboard number moves.

The product name is blunt on purpose. An Institutional Failure Radar continuously analyses organisational exhaust — not to monitor employees, but to detect abnormal shapes of attention, uncertainty, silence, consensus, timing and decision compression around consequential work. It asks how green was made. It does not replace operational metrics. It does not score people.

The reader’s question

If you lead risk, assurance, safety or compliance in a regulated, long-lived, safety-critical organisation, you already live with a familiar discomfort: work that is formally green and generates no incidents can still feel wrong. Programme packs arrive all green. Near-misses later reveal that field knowledge never reached the decision channel, or that an exception had become folklore, or that Friday-night approvals had become a habit. You do not lack dashboards. You lack a sensing layer for the felt state of decisions.

By the end of this book you will be able to:

  • Name seven failure shapes that appear in soft exhaust before they appear as incidents
  • Instrument declared-versus-felt divergence with a formal-importance × lived-attention matrix
  • Combine weak signals into nominations for human review — priors, never verdicts
  • Govern the system so it analyses decisions and controls, never individual productivity or “riskiness”

What this is not

Three adjacent disciplines sit beside this radar and must not be collapsed into it.

Not the Institutional Linter. Static analysis of the codified organisation — policies, procedures, reports as a dependency graph — is a complementary plane. The linter finds structural defects in how the organisation is written and linked. The radar finds deformations in how people attend and decide around those controls.

Not Elastic Assurance. Once a finding exists, routing it, disclosing it narrowly, and packaging soft attestations without automatically moving the formal traffic light is a separate architecture. The radar nominates. Elastic Assurance is where findings go next.

Not capacity accounting. When green is maintained by human heroics and thin reserve margin, that is a different reading of the exhaust — a companion argument in this series (Green by Heroics), not this sensor.

We start where the sensing layer itself must be named. Before you can hunt failure shapes, you need a clear account of what organisational behavioural telemetry is — and what it is not.

02
Part I — Declared vs Felt

Organisational Behavioural Telemetry

Soft exhaust does not only contain facts. It contains the organisation’s behaviour around facts and decisions — and that behaviour is now continuously readable.

Open a week of real work and ignore the structured fields for a moment. What remains is the felt state:

  • where people are uncertain
  • where attention is accumulating
  • where nobody wants ownership
  • where dissent is being compressed
  • where a supposedly routine decision is consuming abnormal cognitive energy
  • where a consequential decision is consuming suspiciously little energy

That is a fundamentally different sensing layer from the one your dashboards already own. Dashboards observe the organisation’s outputs. Soft data can observe its behaviour around the decisions that produce those outputs. We call that layer organisational behavioural telemetry.

The compile is not the radar

BI for Soft Data already established the substrate. Structured systems record outcomes. Emails, meetings and documents hold the causal layer: reasoning, objections, trade-offs, relationship texture — the layer where the why lives. Related work on natural-key joins shows how soft corpora become provenance-bearing rather than merely “similar.”

That compile is necessary. It is not sufficient for this book’s purpose. Once the exhaust is readable, you can ask a second family of questions — not only “what was decided?” but “what did the organisation do around the decision?”

What behavioural telemetry compiles

  • How much discussion occurred — and how that volume changed over time
  • Who participated, and who was absent relative to the roles this decision class usually needs
  • Whether objections were answered or merely stopped
  • How often a decision was reopened
  • How language moved from uncertain to certain
  • How long deliberation took, and when approval occurred
  • Whether the evidence changed before the status changed
  • Whether independent groups actually formed independent views
The dashboard sees the green light. The exhaust sees how it became green.

An institutional nervous system

Think of the soft-data layer as the organisation’s nervous system. Nerves do not replace blood chemistry. They carry a different class of signal: where pressure is building, where sensation has gone numb, where a limb is compensating for another. Organisational behavioural telemetry does the same for decisions and controls. It does not certify that a transformer is healthy or that a balance sheet balances. It certifies something your formal pipeline was never designed to certify: whether the path to green looks like healthy deliberation or like compression under pressure.

That distinction matters for a critical-infrastructure operator as much as for a bank’s control function. The formal pipeline will always be required. The missing layer is continuous sensing of cognitive friction, silence and participation shape — the felt state that sits underneath the declared state.

Disambiguation — do not import the wrong “telemetry”

In adjacent AI-operations writing, “behavioural telemetry” sometimes means whether users accept, edit, reject or ignore an AI recommendation. That is useful for model drift. It is not this book’s subject.

Term In this book Not this
Organisational behavioural telemetryAttention-shape on organisational exhaustAI output accept / edit / ignore rates
Soft exhaustThreads, meetings, reports, chat, decision packsSCADA tags or ERP status alone
Sensor outputNomination for human reviewAutomatic traffic-light change

What the formal pipeline will never show you

Process mining and conformance checking answer whether activity followed a documented sequence. They are excellent at that. They are structurally uninterested in whether the sequence still deserves to exist, whether the people who executed it believed the evidence, or whether the final artefact still contains the uncertainty that was alive in the discussion. Those questions live in language, participation and timing — soft exhaust properties, not event-log fields.

That is why organisational behavioural telemetry is not “BI, but for email volume.” Volume is one weak signal among many. The compile that matters is multi-dimensional: who, when, how certain, what disappeared between thread and pack, which expected voice never arrived. Once those dimensions are joinable, the seven shapes in the next chapter become detectable rather than anecdotal.

Why this layer is newly affordable

None of these questions is philosophically new. Seasoned assurance leaders have always asked them in sampling exercises and incident reviews. What was missing was the economics of standing review. Continuously reading the soft estate of a large organisation — every consequential pathway, every week — was simply not a job a human institution could staff. Machine-scale reading changes the unit price of that attention. Continuous strategic sensing of patterns no team can exhaustively read is exactly the class of AI value that only becomes real when cognition is cheap enough to run in the background.

Affordable reading is not the same as wise use. The next chapter gives the vocabulary the radar needs: seven shapes institutional failure takes in soft exhaust before it has a number, a risk category, or a dashboard tile.

03
Part I — Declared vs Felt

Seven Shapes of Institutional Failure

Failure leaves a recognisable attention-shape long before it has a formal category. These seven shapes are the radar’s taxonomy — priors that nominate inspection, never verdicts that accuse.

The origin of this whole line of work is simple: when you review soft data and organisational exhaust — work reports, email chatter, items that never enter the formal pipeline — you can see the shape of a problem. Too much chatter around a number. Not enough. A green light executed too easily, too quickly, or at the end of a shift. Indecision and groupthink still greenlit. Shapes of organisational failure that are inherently not on dashboards.

Rule of use

Each shape produces a question for human review. None produces an automatic red light, a person-score, or a disciplinary trigger. Chatter is a prior. Silence is a prior. Compression is a prior. Humans dispose.

1. Excess chatter

A supposedly routine control suddenly produces several times its normal email or Teams traffic. That does not prove failure. It indicates abnormal cognitive friction.

Possible interpretations: the procedure is unclear; the evidence is contradictory; staff no longer trust the underlying number; responsibility is ambiguous; the decision does not fit the existing governance model; the formal process is concealing a difficult judgement. The chatter is not the answer. It is a prior saying: something here deserves inspection.

Vignette

A weekly checklist that usually generates a handful of clarifying messages suddenly produces a multi-day thread about one field no one can source. The formal status remains on track. The exhaust is already screaming friction.

2. Suspicious silence

Silence may be equally important. A high-consequence decision is approved with no visible challenge, no cross-functional discussion, no contribution from the people closest to the work, no alternatives, no recorded uncertainty, no follow-up questions.

That may mean the case was genuinely straightforward. It might also mean dissent has become socially unsafe; approval is ritualised; everyone assumes somebody else checked; the process is so normalised that nobody sees its risk; or the people who know the most are outside the decision channel.

The useful comparison is not “how many messages were sent?” It is: how much deliberation would a decision of this type, novelty and consequence normally produce?

Psychological-safety research has long shown the asymmetry: under cultures of fear, staff report fewer errors while risk accumulates underneath.2 Suspicious silence is therefore a safety signal about the decision channel, not a productivity metric about the people in it.

Vignette

A major interface change is approved with a three-line email and no field signature. Last year, comparable changes produced multi-day technical threads. The novelty and consequence have not fallen. The deliberation has.

3. Consensus compression

The discussion contains uncertainty and disagreement, but the formal artefact suddenly becomes clean and unanimous. Signals include: ten different interpretations becoming one unsupported sentence; risks raised in email disappearing from the final report; qualifiers such as “subject to,” “assuming” and “not yet confirmed” vanishing; minority objections recorded as “stakeholders consulted”; an amber discussion producing a green summary.

This is not ordinary “groupthink detection” as a personality critique. It is comparing the semantic shape of the deliberation with the semantic shape of the decision artefact.

Where did uncertainty disappear without being resolved?

Group-decision research describes defective decisions as those that avoid critical evaluation of favoured ideas and fail to consider more favourable alternatives.3 Committees under time pressure often optimise for an answer stakeholders will accept rather than the best available answer.4 Compression leaves a fingerprint in the exhaust even when the formal pack looks immaculate.

Vignette

The thread is full of “not yet confirmed” and “subject to site conditions.” The board pack contains none of those words. The residual risk section reads as if the week of argument never happened.

4. Approval-friction anomalies

Compare decision consequence with decision friction.

Pattern Possible signal
Low-risk decision, enormous chatterBroken process, unclear ownership, dead constraint
High-risk decision, almost no chatterRitual approval or absent challenge
Long uncertainty, sudden approvalDeadline pressure or consensus collapse
Approval late in shiftFatigue, handover pressure, queue clearing
Status changes without new evidenceAdministrative green rather than evidentiary green
Repeated re-approvalUnstable assumptions or weak initial decision
Many reviewers, identical languageCorrelated assurance rather than independent assurance

None is proof. Together they form a failure signature.

Vignette

A low-risk template approval thrashes for a week because nobody owns the exception path. The same week, a high-risk temporary deviation sails through in twenty minutes with identical language from three reviewers who all read the same one-page briefing.

5. Chatter displacement

People may be discussing the wrong thing intensely: enormous discussion about whether a threshold is 4.8 or 5.0; almost none about whether the threshold measures the relevant risk. Repeated debate about report formatting; no challenge to where the underlying evidence came from. Detailed conversation about compliance wording; silence about whether the control can prevent anything.

That is governance displacement: the organisation applies intense attention inside an inherited frame while leaving the frame itself unexamined. It is particularly dangerous because the activity looks like rigour.

Vignette

Thirty messages argue about fonts and section order in a residual-risk annex. Zero messages ask whether the source system for the annex’s numbers has been revalidated since the last restructure.

6. Normalised exceptions

The exhaust repeatedly contains phrases such as: “temporary workaround,” “just this once,” “pending the permanent fix,” “usual exception,” “we normally handle this manually,” “approved subject to later confirmation,” “we’ve always done it this way.”

A dashboard may record each event as successfully resolved. The soft-data layer sees that an exception has become the operating model. The failure shape is not an individual breach. It is the gradual conversion of governance into folklore.

Vignette

A “temporary” bypass has been renewed monthly for eighteen months. Every month the formal record is green. The exhaust’s phrase fossils show no living plan for the permanent fix — only the ritual of re-approving the temporary.

7. Missing voices

Participation itself is evidence. Was anyone from field operations involved? Did the control owner also produce the assurance evidence? Was the person most exposed to the consequence represented? Did every reviewer come from the same reporting line? Were contractors discussing concerns privately but absent from the formal meeting? Did senior management dominate the conversation before technical views stabilised? Did dissent fall sharply after a particular executive entered the thread?

The absence of an expected voice can be more revealing than the presence of another approval.

Vignette

Contractors voice concerns in a side channel the formal system never sees. The meeting minutes record “contractor input noted — no objections.” The missing voice is not a person to score. It is a channel failure.

Taxonomy, not accusation

These seven shapes are the radar’s shared language. Chapter 4 puts them to work on the flagship demonstration: reconstructing how green was made, end to end, with nomination cards that carry receipts rather than verdicts.

04
Part II — The Radar Demonstrated

How Green Was Made

The flagship demonstration: two greens and one unofficial high-chatter workflow, reconstructed as radar nominations with receipts — not as red lights.

Chapter 1 introduced Approval A and Approval B as a contrast. This chapter develops them as if the Institutional Failure Radar had run overnight over a bounded window of soft exhaust. The point is not theatre. The point is to show the output form the doctrine requires: a nomination about a pathway, with multi-signal receipts, for a human to dispose.

The dashboard sees the green light. The exhaust sees how it became green.

Worked case 1 — Deadline compression pathway

Start from the formal record of Approval B. Everything required is present. The colour is green. Now open the exhaust and reconstruct the week in shape language (illustrative narrative — the radar reports patterns and receipts, not invented statistics).

Timeline of a shape assembling

Early thread: technical uncertainty is explicit. Qualifying language appears — “probably,” “should be acceptable,” “subject to confirmation.”

Mid-thread: attention narrows to one disputed number. Traffic rises well above the baseline for this decision class. The field role that normally appears on comparable decisions is never invited.

Objection: one substantive challenge is raised. Subsequent messages do not answer it. The objection simply stops appearing.

Status move: amber becomes green. No new evidence artefact is attached to the status change. The administrative colour moves first.

Approval moment: the click lands in the last hour of the shift, immediately before a reporting deadline.

Final artefact: the decision pack is clean. The qualifiers that filled the thread are gone. Minority concerns are summarised as consultation completed.

Mapped to the taxonomy (Ch3), this is not one shape. It is a composite signature: local excess chatter around a disputed metric; consensus compression between thread and pack; approval-friction anomaly on timing and status-without-evidence; missing voices (field role); a touch of chatter displacement (the number absorbing attention that should have stayed on the underlying risk).

The nomination card — what the radar actually emits

Nomination — not a verdict

Object: Decision pathway / control family (not a person)

Claim: This approval pathway shows an abnormal compression of unresolved uncertainty under deadline pressure.

Receipts (illustrative classes):

  • Volume elevated versus baseline for this decision class
  • Expected field role absent from participation set
  • Unresolved objection still open at approval time
  • Qualifier density high in discussion, near-zero in final pack
  • Approval timestamp class: late-shift / pre-deadline
  • Status transition without linked new evidence

Disposition options for humans: investigate · monitor next N instances · clear with recorded rationale

Explicit non-claims: does not mark the formal control red; does not rank individuals; does not assert that an incident will occur.

That last line is load-bearing. The radar’s success metric is better questions earlier, not more red lights. If the system starts auto-moving formal status from soft signals, it has left the doctrine and entered a different product — one that will be gamed, resisted and eventually corrupted.

Worked case 2 — The unofficial dependency

The second flagship example is the other key case the brief requires: a workflow of low formal importance with abnormally high chatter.

There is no risk-register row. There is no dashboard tile. The process does not appear in the monthly control report. And yet the soft exhaust shows sustained, elevated traffic: repeated handoffs, the same unofficial step mentioned across teams, workarounds that never graduate into procedure, a standing set of “who do I actually ask?” messages.

The formal system has no place to put this. The radar does. In the language of Chapter 6’s matrix, this is the low-formal / high-attention cell: an emerging issue, broken workflow, or unofficial dependency with no dashboard identity.

Nomination — unofficial citizenship

Object: Workflow cluster (joined on natural keys across threads and teams)

Claim: Lived attention without formal citizenship — recommend ownership and risk-identity review.

Receipts: sustained elevated traffic vs peer workflows; repeated workaround language; cross-team mention of the same unofficial handoff; absence of formal owner in governance maps.

Disposition: assign temporary owner · promote to formal control · retire the workaround · or document why the chatter is healthy noise.

This is how soft data finds what dashboards cannot: not by replacing the dashboard, but by noticing where formal structure and lived attention disagree. Approval B is the high-formal pathway that looks clean while its deliberation shape is unhealthy. The unofficial dependency is the low-formal pathway that the dashboard cannot even see.

What “healthy green” looks like in exhaust

For completeness, reconstruct Approval A as a negative control — the shape that should not nominate.

Evidence assembled over several days. Engineering, safety and operations present. Objections recorded and answered (not merely stopped). Alternatives considered. Approval in normal hours. Language becoming more confident as evidence accumulates. Final artefact retains appropriate residual-risk language rather than scrubbing uncertainty into false unanimity.

The formal record is still green. The exhaust agrees that the green was earned. A radar that only knows how to alarm is as useless as a dashboard that only knows how to soothe. The doctrine needs both: nominate the deformed path; leave the healthy path alone.

From vignette to method

These cases already imply a multi-signal recipe. Chapter 5 makes that recipe explicit: the composite weak-signal panel, the worked nomination that combines volume, participation, timing and qualifier density, and the discipline that keeps every signal a prior rather than a command.

05
Part II — The Radar Demonstrated

Weak Signals, Strong Nominations

No single soft signal should decide anything. Twelve weak signals combine into a prior that nominates a case for human investigation.

Work on The Author’s Attention found that repeated mention is a fossil of real attention — what people return to, argue about and discuss carries information static structure cannot see. It also found the critical limitation: people talk disproportionately about what is broken.

Therefore:

  • high chatter does not equal high risk
  • low chatter does not equal safety
  • sentiment does not equal truth
  • disagreement does not equal dysfunction
  • consensus does not equal correctness
Chatter should be a prior, never a verdict. The signal must perturb, not command.

The composite panel

A useful system combines multiple weak signals. None decides. Together they nominate.

Twelve weak signals

  1. Volume relative to baseline (for this decision class, not org-wide noise)
  2. Change in volume (trajectory, not only level)
  3. Participant diversity
  4. Hierarchy distribution (who is speaking — and when)
  5. Unresolved-question count
  6. Repeated reopening of the same decision
  7. Timing relative to deadlines and shifts
  8. Qualifier density (“probably,” “subject to,” “not yet confirmed”)
  9. Evidence-to-assertion ratio
  10. Disagreement between discussion and final report
  11. Presence or absence of expected roles
  12. Independence of evidence sources

Baselines matter. A control family that always generates dense technical debate should not be nominated merely for being talkative. A high-consequence pathway that is usually quiet and suddenly goes silent-to-the-point-of-ritual is a different story. Compare like with like: decision class, novelty band, consequence band.

Worked composite — volume, participation, timing, qualifiers

Return to the deadline-compression pathway (Ch4). The radar does not emit twelve separate alarms. It emits one nomination built from concurrent weak signals:

Composite example

Volume vs baseline: elevated for this decision class over the window.

Participation: expected field role absent; reviewers clustered in one reporting line.

Unresolved questions: at least one substantive objection without subsequent answer.

Qualifier density: high in the thread; near-zero in the final pack (discussion-vs-artefact disagreement).

Timing: approval in the last hour of shift, immediately before a reporting deadline.

Evidence-to-assertion: status moved without a new evidence artefact.

Nomination: abnormal compression of unresolved uncertainty under deadline pressure.

Human disposition: investigate (open a review), monitor (watch the next instances of this pathway), or clear (record why this shape is acceptable here).

Notice what is missing from that card: names ranked by message volume; sentiment scores; a machine-moved traffic light; a claim that an asset will fail on a date. Those omissions are the product.

Why “just culture” is design, not tone

Aviation’s just-culture tradition defines an atmosphere of trust in which people are encouraged — even rewarded — for providing essential safety-related information, rather than punished for surfacing it.5 Soft-exhaust sensing without that design intent becomes a snitch engine. Soft-exhaust sensing with it becomes a way to ask better questions about pathways while protecting the people who generate the signal by doing their jobs out loud.

Practical implications:

  • Aggregate first. Default views are pathway-level and control-family-level.
  • Access control on receipts. Source material opens only through authorised investigation.
  • Questions, not accusations. Output language is about compression, silence, displacement — not about loyalty or attitude.
  • Human disposition always. The system nominates; people decide.

Anti-patterns

Sentiment as risk. Personal mood is not institutional precondition.

Single-threshold auto-red. One volume spike is not a verdict.

Employee leaderboards. Ranking people by chatter volume inverts the sensor into surveillance.

Consensus-as-quality. Unanimous language can be compression, not health.

Ignoring baselines. Without decision-class baselines, everything looks anomalous or nothing does.

Decision-class baselines are not optional

Two errors destroy composite sensing. The first is treating the whole organisation as one baseline — so noisy domains always look “high risk” and quiet domains always look “safe.” The second is treating every pathway as unique, so nothing is ever anomalous. The discipline is intermediate: baseline by decision class, novelty band and consequence band. A low-risk template approval and a high-consequence interface change are different animals. Compare each to its own peers.

Trajectory matters as much as level. A pathway at 1.2× baseline and rising for three cycles may be more interesting than a pathway at 3× baseline that has been 3× for years because that is how the work is done. The composite panel’s second signal — change in volume — exists for that reason.

The next instrument

Composites answer “what shape is assembling on this pathway?” The most valuable organisational instrument may still be a different comparison: not signal versus signal inside the exhaust, but formal importance versus lived attention. Chapter 6 makes that disagreement matrix definitive.

06
Part II — The Radar Demonstrated

The Disagreement Instrument

Disagreement between formal importance and lived attention is diagnostically more valuable than either ranking alone. The off-diagonal cells are where the radar should hunt.

The Author’s Attention framework compares what structure says is important with what behaviour says mattered — and treats the disagreement as its own instrument. Structural prominence is not importance. Mention frequency is a behavioural fossil. Neither ranking alone is enough; the mismatch is the hunt.

That design generalises cleanly from a code corpus to organisational exhaust.

The matrix

Formal importance Exhaust attention Interpretation
HighHighRecognised consequential issue — engagement is present; still inspect shape of that engagement
HighLowRitualised control, invisible risk, or mature stable process — discriminate which
LowHighEmerging issue, broken workflow, or unofficial dependency with no dashboard identity
LowLowProbably peripheral

The on-diagonal cells are comparatively calm. High/high means the organisation already treats the issue as consequential — though Chapter 3’s shapes still apply if the attention is compressed or displaced. Low/low is usually noise. The off-diagonals are where formal structure and lived attention disagree — and where BI for Soft Data finds issues dashboards cannot, not by replacing the dashboard, but by hunting that disagreement.

High formal importance, low chatter

Two very different stories produce the same cell.

Mature process. The control is well understood. Novelty is low. Experts are available. Near-miss culture is open. Silence is informed, not hollow. People could explain the control if asked; they simply do not need to re-litigate it weekly.

Ritualised control. The control still carries formal weight — risk-register criticality, regulatory linkage, board visibility — but nobody substantively thinks about it anymore. Approvals are administrative. When challenged, owners cannot reconstruct why the control exists or whether it still binds a live failure mode. Silence is hollow.

Discriminating questions

  • Can the owner explain the failure mode this control is for without reading the procedure?
  • Has the enabling constraint changed while the control stayed still?
  • Is silence matched by open near-miss reporting, or by empty incident history that looks too clean?
  • Do comparable high-importance controls show healthy technical deliberation — making this silence an outlier?

The Institutional Linter’s plane (codified contradictions, dead constraints) often meets this cell from the other side. The radar’s contribution is the behavioural half: is the silence informed or empty?

Low formal importance, high chatter

This is the unofficial-dependency cell from Chapter 4. Sustained attention without formal citizenship. Possible emerging risk, broken workflow, or a standing workaround that has not earned a dashboard tile. The organisation is already paying cognitive cost; it has not yet given the issue a name, an owner, or a control identity.

Radar question set for this cell:

  • What natural-key join keeps this chatter cluster together?
  • Who is the de facto owner — and who is the missing formal owner?
  • Is the chatter producing learning (healthy) or perpetual rework (broken)?
  • Should this be promoted into the risk register, fixed as a process defect, or left alone with a recorded rationale?

How the inputs are built

Formal importance is declared: risk-register criticality, safety-case linkage, regulatory obligation weight, financial materiality, board visibility. It is not inferred from chatter. That is the point of the disagreement.

Lived attention is not raw message count. It is the composite panel from Chapter 5 — volume versus baseline, participation, timing, qualifier density, discussion-versus-artefact divergence, expected roles — rolled into an attention estimate for a pathway. Volume alone would reintroduce every bias Author’s Attention already warned against.

Output is a cell classification plus a nomination, not a single organisational risk score. Scores invite Goodhart. Classifications invite investigation.

Green as target

When a measure becomes a target, it ceases to be a good measure.1 Green status under managerial pressure is exactly that kind of target. The formal importance axis remains, but the felt-state signal is trained out of the formal record. The matrix restores a sensing plane that is hard to game without changing the deliberation itself — which is the point of sensing deliberation in the first place.

The disagreement is its own instrument.

Knowing where to look is not yet knowing what kind of prediction this is. Chapter 7 frames the deeper formulation: cognitive metabolism, and shape-of-failure prediction operationalised inside the organisation.

07
Part III — Pre-Incident Sensing & Governance

Cognitive Metabolism & Shape-of-Failure Prediction

Dashboards observe outputs. The radar observes cognitive metabolism — where attention flows, pools, disappears, and is compressed into status. Useful prediction here is a falsifiable shape of institutional preconditions, not an event date.

Use organisational exhaust to identify the shape of failure before the organisation has a formal category, metric or dashboard for it.

Cognitive metabolism

The dashboard observes the organisation’s outputs. BI for Soft Data, used as a behavioural sensor, can observe its cognitive metabolism:

  • where attention flows
  • where it pools
  • where it disappears
  • where uncertainty is metabolised into evidence
  • where uncertainty is merely compressed into status
  • where disagreement improves the decision
  • where social pressure erases disagreement
  • where a process feels difficult before anybody can articulate why

That formulation is strategically important because it names a sensing target that is not “more KPIs.” Metabolism is about conversion: does the organisation convert uncertainty into evidence, or into colour? Does it convert dissent into better decisions, or into silence? Those conversions leave exhaust shapes long before they leave incident tickets.

This is also why the economics work now. Continuous sensing of patterns no human team can read exhaustively is a Version-3 class of AI value — previously infeasible as a standing practice, now a compute cost rather than a headcount fantasy.

Shape-of-failure prediction — parent and operational child

At strategy level, Shape-of-Failure Prediction argues that the valuable thing a serious reasoning engine does on a fragile strategy is not predict outcomes but predict the falsifiable shape of failure — what failure will look like, in what sequence — so the prediction can be checked against reality later. Frameworks themselves are a form of second-hand time travel: portable shape knowledge transferred across contexts.

This book operationalises that parent inside the organisation, on behavioural exhaust. The radar does not need to say:

“Transformer X will fail on Tuesday.”

It might say:

“This decision currently resembles a recurring organisational failure shape: prolonged technical uncertainty, repeated attention to one disputed metric, narrowing participation, unresolved objections disappearing from the final artefact, and approval immediately before a programme deadline.”

That statement is specific, falsifiable, reviewable, based on receipts, and useful before a physical or financial failure. It predicts the institutional preconditions of failure, not necessarily the engineering event itself. If the next three instances of the pathway show answered objections, restored field participation and daytime approvals with evidence attached, the nomination was productive even if “nothing broke.” The radar’s job was never prophecy. It was earlier, better inspection.

A pattern language for critical operators

For a transmission network operator or similar regulated, safety-critical estate, the shapes tend to recur in recognisable families. Present them as a watch-list — not as accusations of any named organisation:

  • deadline-driven closure overwhelming engineering caution
  • field knowledge failing to reach project governance
  • repeated temporary controls becoming permanent
  • multiple assurance bodies relying on the same source narrative
  • project status remaining green while soft-data friction accelerates
  • risks being linguistically softened as they travel upwards
  • regulatory compliance demonstrated through artefacts that operations quietly route around

Each maps onto the Chapter 3 taxonomy and the Chapter 5 composite panel. “Linguistically softened as they travel upwards” is consensus compression plus hierarchy distribution. “Temporary controls becoming permanent” is normalised exceptions. “Field knowledge failing to reach governance” is missing voices. The vocabulary is portable; the receipts are local.

Public post-incident reports as shape primers

When public post-incident literature describes silenced dissent, missing frontline voice, deadline compression, or exceptions that had become normal, reread those passages as radar shapes. Do it without inventing frequencies or retrofitting a claim that “the radar would have prevented that event.” The honest claim is narrower and stronger: these preconditions produce nominations earlier than lagging metrics, and earlier nomination is what just-culture, high-reliability practice has always wanted — better questions while the system is still formally green.

Committee dynamics, without scorning committees

Time pressure and social dynamics cause groups to optimise for acceptable consensus, narrow alternatives prematurely and suppress challenging information.4 Groupthink research describes defective decisions as failures to critically evaluate favoured paths.3

The radar does not “fix people of groupthink.” It surfaces compression signatures — discussion-versus-artefact divergence, sudden certainty, missing alternatives — for human review. That is the difference between behavioural science as insult and behavioural telemetry as instrument.

Power without panopticon

By this point the doctrine is dangerous in the useful sense: it can see more than dashboards see. The last chapter is the governance boundary that keeps that power from becoming the problem it was built to find — the Surveillance Gradient, the prohibited uses, and the Monday-morning first pass.

08
Part III — Pre-Incident Sensing & Governance

Stay Low on the Surveillance Gradient

The same exhaust that enables pre-incident sensing can become panopticon. Architecture must force the radar to analyse decisions and controls — never score people — and stay at Level 1 of the Surveillance Gradient.

Default good output

“This approval pathway shows an abnormal compression of unresolved uncertainty.”

Default bad output

“Engineer Smith is negative and delaying the project.”

If your design cannot enforce that distinction, do not build the radar. You will recreate the governance problem you claimed to solve.

The Surveillance Gradient

The Workforce AI Compact classifies workplace monitoring on a four-level gradient. Organisations slide from Level 1 to Level 4 incrementally; each step seems reasonable in isolation. Governance gates must sit at each transition.

Level Category Governance
1Aggregate / sample quality assurance on decisions & controlsStandard practice — radar home
2Team productivity analyticsRequires transparency
3Individual behavioural monitoringRequires governance approval
4Algorithmic management (AI-directed work)Requires full Compact + ongoing review

The Institutional Failure Radar is designed to live at Level 1. It analyses decisions, processes, controls, projects and organisational interfaces. It does not score individual productivity, loyalty, personal sentiment, or employee “riskiness.”

Prohibited uses

Non-negotiable

  • Individual productivity scoring from chatter volume or tone
  • Loyalty or “attitude” metrics derived from exhaust
  • Personal sentiment as a risk score
  • Employee “riskiness” rankings
  • Hidden performance management via radar nominations
  • Automatically changing formal traffic lights from soft signals alone
  • Feeding disciplinary workflows without a separate, human, due-process investigation
Signals generate questions, not accusations.

That rule aligns with just-culture practice: safety information is something the system encourages, not weaponises.5 Aggregate first. Preserve semantic access controls. Reveal source material only through authorised investigation.

Why Level 1 is a product constraint

It is tempting to treat the Surveillance Gradient as a policy memo: “we promise not to score people.” Policy memos rot. Product constraints do not. Level 1 means the default schema has no employee risk field; the default UI has no person-rank view; the default export is pathway-level; opening message-level receipts requires a separate authorisation step with an investigation purpose. If those constraints are missing, the gradient will be climbed by a well-intentioned manager who only wanted “a little more detail.”

The same constraint protects the signal. Once people believe exhaust is used to rank them, they stop writing the uncertainty that makes the radar useful. You will get cleaner formal packs and emptier soft data — consensus compression as an adaptive response to surveillance. Stay at Level 1 or lose the sensor.

Monday morning — commission one radar pass

You do not need a transformation programme.

  1. Pick one consequential, formally green decision pathway or control family.
  2. Bound a time window and compile its soft exhaust (BI for Soft Data substrate).
  3. Score the window against the seven shapes (Ch3).
  4. Place the pathway on the formal-importance × lived-attention matrix (Ch6).
  5. Build one composite nomination with receipts (Ch5).
  6. Human disposition: investigate, monitor, or clear with recorded rationale.
  7. Do not rank individuals. Do not move formal status automatically.
  8. If the nomination is load-bearing, route it through a narrow disclosure path — compute broadly, disclose narrowly — rather than flooding the formal traffic light.

Where this sits in the stack

Institutional Linter — static analysis of the codified organisation; complementary plane to behavioural radar.

Elastic Assurance — routing, disclosure, Soft Attestation Packages; where findings go after nomination.

Green by Heroics — capacity, human reserve margin, green maintained by strain. Adjacent, not this sensor. Name it; do not absorb it.

Later companions in this series (governance barbell, intent compiler, cognition scarcity audit) — name in prose when relevant; they are not yet the radar’s job.

Close

Formal systems will keep recording the declared state. They should. The organisations that will see trouble forming are the ones that also instrument the felt state — chatter, silence, compression, timing, participation — without climbing the Surveillance Gradient.

Failure changes shape before it changes the numbers. The Institutional Failure Radar is the discipline of reading that shape continuously, nominating with receipts, and leaving judgement where it belongs: with accountable humans reviewing decisions and controls, not with a system scoring the people who produce the exhaust by doing their work out loud.

Commission one radar pass

Pick a single control family. Compile its exhaust. Name the shapes. Build one nomination. Keep the object of analysis as the pathway.

If you’d like to scope a first pass: scott@leverageai.com.au

REF
Sources & Evidence

References & Sources

The evidence base behind every claim — primary research, industry analysis, and technical specifications

Research Methodology

This ebook draws on primary research from standards bodies, independent research firms, enterprise technology vendors, and consulting firms. Statistics cited throughout have been cross-referenced against primary sources.

Frameworks and interpretive analysis developed by Scott Farrell / LeverageAI are listed separately below — these represent the practitioner lens through which external research is interpreted, and are not cited inline to avoid self-promotional appearance.

Primary Research & Standards Bodies

Wikipedia — Goodhart's law [1]

When a measure becomes a target, it ceases to be a good measure — green status as target compresses felt-state signal

https://en.wikipedia.org/wiki/Goodhart%27s_law

Amy C. Edmondson — Psychological Safety and Learning Behavior in Work Teams [2]

Fear suppresses error reporting while risk accumulates; silence is not safety

https://web.mit.edu/curhan/www/docs/Articles/15341_Readings/Group_Performance/Edmondson%20Psychological%20safety.pdf

NYU Steinhardt — Groupthink as System [3]

Groupthink as avoidance of critical evaluation of favoured ideas; defective decisions fail to consider alternatives

https://wp.nyu.edu/steinhardt-appsych_opus/groupthink/

ANZSOG — Committee Decision Processes [4]

Committees often optimise for acceptable consensus rather than best answer

https://anzsog.edu.au/app/uploads/2022/06/10.21307_eb-2018-002.pdf

SKYbrary Aviation Safety — Just Culture [5]

Atmosphere of trust that encourages safety-related information; supports questions-not-accusations

https://skybrary.aero/articles/just-culture

LeverageAI / Scott Farrell — Practitioner Frameworks

The interpretive frameworks, architectural patterns, and practitioner analysis in this ebook were developed through enterprise AI transformation consulting. The articles below are the underlying thinking behind those frameworks. They are listed here for transparency and further exploration — not cited inline, as this is the author's own analytical voice.

Scott Farrell, LeverageAI — The Institutional Linter: Static Analysis for Your Organisation

Codified-org lint plane complementary to behavioural radar

https://leverageai.com.au/wp-content/media/articles/137-institutional-linter.html

Scott Farrell, LeverageAI — Elastic Assurance: Compute Broadly, Disclose Narrowly

Routing and disclosure plane for findings; Soft Attestation Packages

https://leverageai.com.au/wp-content/media/articles/136-elastic-assurance.html

Scott Farrell, LeverageAI — Your Organization Has Source Code (And You Can Finally Read It)

BI for Soft Data compile step: exhaust as source code; as-designed vs as-operated

https://leverageai.com.au/wp-content/media/articles/86-your-organization-has-source-code.html

Scott Farrell, LeverageAI — The Soft Join: SQL Discipline for Soft Data

Natural-key joins for soft data; provenance not resemblance

https://leverageai.com.au/wp-content/media/articles/88-the-soft-join.html

Scott Farrell, LeverageAI — BI Tells You Where, the Wiki Tells You Why

Structured systems locate; soft/causal layers explain

https://leverageai.com.au/wp-content/media/articles/106-bi-where-wiki-why.html

Scott Farrell, LeverageAI — Maximising AI Cognition and AI Value Creation

Version-3 continuous sensing; patterns no human reads exhaustively

https://leverageai.com.au/wp-content/media/articles/27-maximising-ai-cognition.html

Scott Farrell, LeverageAI — The Author's Attention: Ranking Files by How Often You Talked About Them

Attention-as-fossil; perturb don't command; disagreement instrument

https://leverageai.com.au/wp-content/media/articles/89-the-authors-attention.html

Scott Farrell, LeverageAI — Frameworks Are Second-Hand Time Travel

Frameworks as transferable shape knowledge; shape-of-failure parent cluster

https://leverageai.com.au/wp-content/media/articles/131-frameworks-second-hand-time-travel.html

About This Reference List

Compiled July 2026. All URLs verified at time of compilation. Regulatory documents and standards specifications are subject to revision — check primary sources for the most current versions.

Some links to academic papers and vendor research may require free registration. Government and standards body publications are freely accessible.