Systems, Decisions and Robust Design

A reading-and-practice path through cybernetics, systems dynamics and failure studies for seeing behaviour as the output of structure and designing so that being wrong is survivable.

Established#systems#feedback#robustness#cybernetics#design

Systems thinking begins with a reversal. Instead of asking who or what is to blame for a behaviour, ask what structure would produce this behaviour no matter who occupied the seats. The second half of the discipline asks how to build things so that when your understanding turns out to be wrong, the damage is limited and the error can be seen.

Core vocabulary

Meadows's Thinking in Systems gives the plainest introduction. A stock is an accumulation (water in a bathtub, money in an account, unread messages). A flow changes a stock (inflow, outflow). A feedback loop carries information about a stock back to the flows. A balancing loop pushes toward a target, as a thermostat does; a reinforcing loop amplifies, as compound interest or a bank run does. Delays between action and result are the hidden cause of many oscillations: anyone who has adjusted a shower with slow hot water has overcorrected twice. Boundaries are choices about what to include, and a wrong boundary hides the real cause. Meadows's essay on leverage points argues that the most powerful places to intervene are usually goals and the rules of the system, not the numerical parameters people tend to adjust. Established as a framework; the exact ranking of leverage points is Provisional, being a practitioner's synthesis rather than a tested result.

The founders

  • Wiener (Cybernetics, 1948) treated control and communication in animals and machines as one subject: a system steers by comparing its state to a goal and correcting error.
  • Ashby (An Introduction to Cybernetics, 1956) stated the law of requisite variety: a regulator can handle disturbances only if it has at least as many possible responses as the disturbances have distinct effects. Demonstrated within its formal setting; applying it loosely to organizations is analogy, useful but not proven.
  • Simon (The Sciences of the Artificial) argued that designed things sit between an inner environment and an outer one, and that real agents "satisfice," accepting a good-enough option because search is costly (the 1955 paper develops the idea; Simon coined the word "satisficing" in 1956).
  • Bertalanffy (General System Theory) proposed that similar organizational principles recur across biology, engineering and society. How far that unity goes is Aporetic.

Beyond "root cause"

The phrase "root cause" is sometimes right and often misleading. Many real failures involve several individually acceptable conditions interacting. Redundant components can share a hidden dependency, such as one power source, one shared configuration or one vendor, so the backup fails with the primary. Incentives distort metrics: when a measure becomes a target, people optimize the measure, a pattern often called Goodhart's law (a saying, not a theorem). Fact and analogy need separating here: the bathtub model is a fact about accounting identities, while calling an organization "a feedback system" is a lens.

Why systems fail

Doerner's The Logic of Failure reports experiments in which people managing simulated towns and villages failed in repeatable ways: they ignored side effects, acted on one variable at a time without watching delays, and gave up on goals prematurely. Perrow's Normal Accidents (1984) argued that systems that are both tightly coupled (little slack between steps) and interactively complex (opaque, with unexpected interactions) will eventually produce accidents that no operator could easily foresee. Established as an influential framework drawn from case studies; later work (Leveson's systems-theoretic approach) disputes some of its claims. Vaughan's study of the 1986 Challenger launch decision shows how a group can slowly accept deviation as normal. For financial panics, Kindleberger's history shows a recurring pattern of rising credit, a shock, and a rush to liquidity.

Coordination and institutions

Schelling's Micromotives and Macrobehavior shows how mild individual preferences can aggregate into sharp collective patterns that nobody intended. Hayek's 1945 essay argues that the knowledge needed for an economy is dispersed among individuals, and prices carry it; Adam Smith's "invisible hand" (Wealth of Nations, Book IV, ch. 2) makes a related point about unintended order. Ostrom's Governing the Commons documents communities that managed shared resources through locally evolved rules, challenging the claim that only privatization or central control works. On networks, Granovetter (1973) found that weak ties carry novel information between clusters, and Watts and Strogatz (1998) showed that a few long-range links shorten paths in a network. The mathematics of nodes and edges is introduced in Discrete Mathematics and Graphs: Counting, Relations and Networks, and the dynamics of feedback and queues in Systems Thinking: Feedback, Queues, Information and Dynamics.

Diagnosis and design

Diagnosis reasons backward from an outcome to causes: "why did this happen?" Design reasons forward from requirements and failure modes: "what structure will keep producing the desired result despite variation and faults?" The skills overlap but are different habits. Practice for the first is in Evidence-Based Troubleshooting: Separating Explanations. The second begins by asking, for each component, "what happens when this fails or lies?" A related lesson from Stale Information and Dependable Reports is that any stored copy of the world, such as a cache or a dashboard, can be out of date and must be designed accordingly.

How much more information is worth

Bounded rationality means you will never have all the facts. The useful question is whether more information could change the decision at a cost worth paying. Three factors set the answer: reversibility (an undoable change needs less certainty), stakes, and cost of delay. Reasoning under such limits is the subject of Judgment Under Uncertainty: Probability, Causation and Forecasting.

Robust design

When you know your model may be wrong, prefer choices that work acceptably across several possible worlds:

  • Redundancy with independent failure modes.
  • Staged rollout, so a faulty change reaches few users first.
  • Backups that are actually restored in tests.
  • Rollback plans prepared before the change.
  • Segmentation, so a failure or intrusion cannot spread everywhere.
  • Graceful degradation, so the system loses features before it loses everything.

These are engineering tools and also epistemic tools, since each one admits that the designer might be mistaken. After any action, verify: did the symptom actually go away, did anything else change, does the improvement persist? An improvement that coincides with your change is not yet proof that the change caused it.

What keeps a system open to correction

Every healthy system has a way to detect error and act on it. The closing question for this page is the one worth carrying into every institution you join or build: what keeps this system from closing itself to correction? Candidates include honest measurement, protected dissent, blameless review of failures, and leaders who value the correction process over the appearance of being right. The same attitude appears in Peirce's fallibilism, taken up in Principles Ledger and Question Arcs, and in the wider questions of Technology, AI and Human Judgment.

Try this

  1. One diagram, three cases. Draw a causal-loop diagram (stocks, flows, reinforcing and balancing loops, delays) for a financial panic, a technical outage and a public tragedy of your choice. Mark where information was delayed, where coupling was tight and where incentives pointed the wrong way. Compare the three diagrams for shared structure.
  2. Blameless postmortem. Take a recent failure from your own life or work. Write what happened, what made the action seem reasonable at the time, and which structural change would make it less likely, without naming a culprit.
  3. Failure inventory. List five components of something you depend on and write what happens when each one fails silently.

Further reading

  • Meadows, Thinking in Systems: A Primer (2008).
  • Perrow, Normal Accidents (1984).
  • Doerner, The Logic of Failure (1996).
  • Simon, The Sciences of the Artificial (3rd ed., 1996).
  • Ostrom, Governing the Commons (1990).
  • Leveson, Engineering a Safer World (2011).
  • Sterman, Business Dynamics (2000), for the simulation methods.

Sources

  • Meadows, Donella H. Thinking in Systems: A Primer (Chelsea Green, 2008); 'Leverage Points: Places to Intervene in a System' (Sustainability Institute, 1999).
  • Ashby, W. Ross. An Introduction to Cybernetics (Chapman and Hall, 1956), chapter 11 on requisite variety.
  • Wiener, Norbert. Cybernetics: Or Control and Communication in the Animal and the Machine (1948).
  • Simon, Herbert A. The Sciences of the Artificial (MIT Press, 1969); 'A Behavioral Model of Rational Choice,' Quarterly Journal of Economics 69 (1955).
  • von Bertalanffy, Ludwig. General System Theory (George Braziller, 1968).
  • Doerner, Dietrich. The Logic of Failure (Metropolitan Books, 1996; German original 1989).
  • Perrow, Charles. Normal Accidents: Living with High-Risk Technologies (Basic Books, 1984).
  • Kindleberger, Charles P. Manias, Panics, and Crashes (1978).
  • Schelling, Thomas C. Micromotives and Macrobehavior (Norton, 1978).
  • Ostrom, Elinor. Governing the Commons (Cambridge University Press, 1990).
  • Hayek, Friedrich A. 'The Use of Knowledge in Society.' American Economic Review 35 (1945).
  • Smith, Adam. An Inquiry into the Nature and Causes of the Wealth of Nations (1776), Book IV, chapter 2.
  • Granovetter, Mark. 'The Strength of Weak Ties.' American Journal of Sociology 78 (1973).
  • Watts, Duncan J., and Steven H. Strogatz. 'Collective dynamics of small-world networks.' Nature 393 (1998).
  • Leveson, Nancy G. Engineering a Safer World (MIT Press, 2011).
  • Sterman, John D. Business Dynamics: Systems Thinking and Modeling for a Complex World (Irwin/McGraw-Hill, 2000).
  • Vaughan, Diane. The Challenger Launch Decision (University of Chicago Press, 1996).