Safety-I and Safety-II by Erik Hollnagel
Safety has traditionally been defined as a condition where the number of adverse outcomes was as low as possible (Safety-I). From a Safety-I perspective, the purpose of safety management is to make sure that the number of accidents and incidents is kept as low as possible, or as low as is reasonably practicable. This means that safety management must start from the manifestations of the absence of safety and that - paradoxically - safety is measured by counting the number of cases where it fails rather than by the number of cases where it succeeds. This unavoidably leads to a reactive approach based on responding to what goes wrong or what is identified as a risk - as something that could go wrong. Focusing on what goes right, rather than on what goes wrong, changes the definition of safety from ’avoiding that something goes wrong’ to ’ensuring that everything goes right’. More precisely, Safety-II is the ability to succeed under varying conditions, so that the number of intended and acceptable outcomes is as high as possible. From a Safety-II perspective, the purpose of safety management is to ensure that as much as possible goes right, in the sense that everyday work achieves its objectives. This means that safety is managed by what it achieves (successes, things that go right), and that likewise it is measured by counting the number of cases where things go right. In order to do this, safety management cannot only be reactive, it must also be proactive. But it must be proactive with regard to how actions succeed, to everyday acceptable performance, rather than with regard to how they can fail, as traditional risk analysis does. This book analyses and explains the principles behind both approaches and uses this to consider the past and future of safety management practices. The analysis makes use of common examples and cases from domains such as aviation, nuclear power production, process management and health care. The final chapters explain the theoret
#SafetyII #SafetyManagement #RiskManagement #productivityhacks #personaldevelopment #successstrategies #businessinsights #leadershipskills #leadership #ambitiousprofessionals #businesstips #self help #scaling business #businesstactics #professionaldevelopment #startupgrowth #entrepreneurship #businessmindset #growthstrategies
So, you know, when a system just completely fails, like whether that's a massive hospital network going down or a corporate supply chain bottleneck, or I mean, honestly, just your own weekly schedule totally falling apart. Oh absolutely. It happens to all of us. Right. And our very first instinct is usually to hunt down the exact broken rule, right? Like we want to find that one specific broken gear so we can build a new, much stricter rule to replace it. We desperately want that satisfying click of just pointing and saying there it is, there is the problem.
Yeah, we really crave that clear cause and effect. Exactly. But what if that relentless pursuit of perfect, unbroken rules is actually the exact thing making your system so incredibly fragile in the first place? Well, I mean, it's a deeply uncomfortable thought, you know, but it really goes straight to the heart of the rail we're exploring today on this deep dive. Like, why do these catastrophic mishaps still occur in environments where we think we have absolutely everything perfectly under control?
And to navigate that, we are diving into the work of Eric Hornigal today. And just to be clear for you listening, we aren't just talking about like industrial factory floors here or, you know, preventing chemical spills. We're looking at a completely different way to understand success, failure, and how to actually build resilience into whatever you manage every day, right? Because to really get there, to understand Hallmiggles framework, we have to recognize that the traditional way we've all been taught to approach errors is built on this massive, almost invisible assumption.
OK, so let's unpack this, because before we can build anything resilient, we have to flip that default setting, right? Exactly. We have to flip it entirely. Hallmiggle calls this traditional default setting safety one. Right. Safety one. And from what I'm looking at in the source material, safety one basically assumes that success is simply the absence of failure. That's the core of. It like if the machine isn't jammed, it's working perfectly. So your only job as a manager is to just aggressively hunt down errors, evaluate accidents, and enforce these incredibly rigid protocols?
Exactly. It's an entirely deficit based mindset. You know you manage A-Team by tightly controlling the environment. You define safety or even just operational success by the absence of negatives. It's like I was thinking about this. It's like playing an endless, exhausting game of whack a mole. Oh, that's a great way to put it. Yeah, like you just stand there with your mallet waiting for a mistake to OU so you can smash it down with a new compliance man, Yes. You're completely reactive. But then safety, too, feels more like taking a step back and figuring out how the arcade machine is wired in the first place.
That is a much more accurate way to look at it, because safety, too, entirely reverses the philosophy. Instead of obsessing over what goes wrong, it demands that you deeply understand what goes right. OK. So focusing on the wins instead of just the losses. Right, because it recognizes that in complex real world environments, things are always fluctuating, resources are tight, timeline shift, people get sick. Oh. For sure. So true reliability isn't about avoiding the unexpected, it's really about a system's ability to constantly adjust to those changing conditions.
OK, let's ground this with a hospital example from the sources, because I think that makes it super clear. Good idea. Let's look at the medical field. Under Safety One, reducing medical errors means enforcing strict, unwavering adherence to checklists. You know, step A, step B, Step C. Never deviate. Right, strict protocol. And I mean, my immediate instinct is, well, good. I want my surgeon washing their hands exactly the same way every single time. Like aren't strict protocols in a hospital there for a very good reason?
Yes, and what's fascinating here is that safety too doesn't abandoned that checklist. It doesn't just say you know protocols are bad, do whatever you want. OK, Hugh, that's a relief. Right, But it recognizes A fundamental truth, which is that protocols are static, but reality is incredibly dynamic. Yeah, that makes sense. A safety one hospital treats the protocol is the ultimate goal, but a safety 2 hospital treats the protocol as a baseline, and then they intensely study how their staff actually applies it in the messy reality of a busy shift.
So what does that actually look like when things go sideways, like, say, an unexpected power outage hits the ER? Well, under peer safety one staff are basically only trained to execute a sunny day script. A sunny day script I like. That yeah, you know, when everything is perfect. So when the power drops and those digital monitors go dark, the script just vanishes. And then panic sets in. Exactly. Panic sets in because the rigid rules they rely on are suddenly totally impossible to follow. Wow, right, because they have no backup framework.
But a Safety 2 hospital has already spent time examining the small, everyday workarounds their nurses and doctors use, like when equipment is slow or when a room is unexpectedly overbooked. They've already studied the messy reality. Right. They don't just tolerate those adaptations, they actively train for them. Which completely shifts the conversation from theoretical safety to actual real time adaptability. Yes, exactly. Like if safety 1 is just crossing your fingers and hoping your protocols survive the pressure, safety 2 is actively engineering the resilience before the pressure even hits.
Right. And let's look at another example like the restaurant industry. Anyone who has managed to kitchen knows it is just a master class in dynamic reality. Oh, absolutely. Total payoff most of the time. Right, so a safety one manager writes A stringent rulebook. Every ticket has to be routed this way, every dish plated exactly that way. But the danger there isn't just that, like an oven might break on a busy Friday night. No, it's bigger than that. The real psychological trap is that the safety one mindset forces the manager to try and execute a rigid protocol on broken equipment.
Yes, and the system snaps because they literally can't follow the rules anymore. But they have no framework for doing anything else. Precisely. But a Safety 2 strategy establishes a flexible environment. Let's say an unannounced health inspector walks in during the massive lunch rush. A nightmare scenario for any kitchen. Exactly. Now a rigidly trained rule bound staff might totally panic. They might drop the ball on customer orders or even try to, you know, hide things because they're fragile. Routine is interrupted.
But a resilience trained Staffs handles the inspector calmly. They modify their workflow on the fly without letting the entire dining room collapse. OK, I need to pause you there though, because I am struggling a little bit with the line between adaptability and just pure chaos. That's a fairpoint. Because if I am managing that restaurant or literally any team, and I tell my staff, they have the flexibility to bend the rules during a rush. You're worried about quality control? Yeah, How do I ensure they don't compromise core safety like, I don't know, smurving undercooked chicken?
Where is the guardrail? That is the pivotal question. Safety, too isn't about giving permission to just wing it. Right winging it is a recipe for disaster. This is about what the source calls resilience in action, and the mechanics of it really come down to training for the boundaries, not just the center. What do you mean by training for the boundaries? It means instead of just making staff memorize the ideal recipe, you run simulation drills. You red team your own lunch rush. OK, so you actively try to break your own system.
Exactly. You ask? The kitchen. OK, the primary grill is down. We have 40 tickets. How do we triage the menu while maintaining strict food safety standards? Oh, I see. You're explicitly teaching them the principles behind the rule book. The internal temperature of the chicken is non negotiable. Right. You can't bend that. Rule, but how they utilize the remaining equipment to get it to that temperature that can be flexible. You equip them with the capability to cope with the unforeseen event while keeping the core standard totally intact.
OK, I love that. But if our ultimate goal is that kind of dynamic adaptability, then the data we rely on has to completely change. It really does. Like we can't just investigate the night the oven caught fire. We have to deeply analyze the 300 nights where the dinner service was completely flawless. And this is exactly where we hit a massive human bias. Evolutionarily, we are wired to ignore smooth sailing. The smooth flight is safe, so our brains basically conserve cognitive energy by completely ignoring it.
Here's where it gets really interesting though, because we only ever notice the Wi-Fi when it goes down, right? 100% you. Never, ever walk into the office on a random Tuesday and say wow, the router is functioning. Florida State today. Let's pull a whole team together to investigate. Why no, never. But if we connect this to the bigger picture by only focusing on what goes wrong, we create a massive operational blind spot. Yeah, we literally blind ourselves to the mechanisms of our own success. The source gives a great example of a production line supervisor, a pure safety.
One supervisor acts like a detective, but only a crime scenes. Right, they only show up when there's a body. Exactly. They analyze every single machine malfunction, generate massive report and then just add a new rule. But the Safety 2 supervisor? The Safety 2 supervisor realizes that the machine functions perfectly 99% of the time, so they study that 99% with just as much intensity. Right, but what are they actually looking for? Because staring at a working machine sounds like, you know, watching paint dry.
It sounds boring, but they are looking for the invisible human adjustments. Invisible adjustments, yeah. They might notice that an experienced operator slightly adjusts the material feed rate based on, say, the humidity in the factory that day, and that adjustment isn't in the manual anywhere, but it is actually the exact reason the machine isn't jamming. But under safety one, that operator might literally be written up for deviating from the written manual. Exactly. They'd be punished, but under Safety 2, that operator's insight is studied, codified and shared with the whole floor.
That airport example from the sources really underscores this too. It's so counterintuitive because our brains are completely wired to only notice the one delayed. Flight naturally, yes. But if you manage a crowded airport under Safety 1, you spend your entire life in meetings examining the snowstorms, the mechanical failures, the late catering trucks. Right, which only teaches you the architecture of failure. You basically just learn how not to be delayed, right? But Safety 2 says wait a minute.
Thousands of planes depart exactly on schedule every single week. So what's going? On let's look at the buffer times the dispatchers instinctively use when they know a certain runway is busy. Let's look at the communication shortcuts the baggage handlers have developed. Shortcuts that probably aren't officially documented anywhere. Exactly, but they safely shave 3 minutes off every turn around. So instead of just playing defense all the time and putting out fires, yeah, you're learning what actually makes the structure fireproof.
Yes. Understanding both the achievements and the failures makes a system far more durable. But if we're suddenly asking A-Team to study these everyday successes, and we're explicitly looking at those undocumented workarounds, we are completely changing the role of the employee. We really are. We're no longer treating human behavior. Is this like terrifying liability? It is a total 180° turn in management philosophy. Because in the safety one mindset, human behavior is almost exclusively viewed as the ultimate root cause of errors.
Think about it. The phrase human error is the most common conclusion to almost any incident investigation. Oh totally. It's the ultimate scapegoat. The assumption is that humans are messy. We get tired, we cut corners, and therefore we constantly need to be reined in by tighter systems and much closer supervision. OK, I have to play the skeptic again here because I just know someone listening is nodding along with Safety One right now. I'm sure they are. Because humans are tired. We do forget things.
We aren't perfect algorithmic problem solver. If I just decide to blindly trust my tired employees common sense, aren't I just opening the door to a massive uncontrollable amount of variability? It's a very fair fear to have, but Safety 2 points out that while humans are variable, rigid rules are brittle. Brittle. I like that word for. It when a situation falls outside the pre programmed parameters, a computer just crashes. A rule book is completely useless. Safety 2 views human variability not as a bug, but it's the essential feature.
Our intuition, our ability to instantly synthesize context, That is what actually maintains order when complexity scales up. OK, think about a tech support call center safety. One demands every single agent read off a strictly approved script to eliminate that human variability. Right. And what happens when a client calls in with a bizarre cascading software problem that the scriptwriters never anticipated? The agent is totally paralyzed. Yes, they literally aren't allowed to solve the problem. The client gets furious and the system fails.
But a safety too approach gives that agent a framework of intent rather than a rigid script of actions. Exactly. You trust their technical ingenuity? So when that bizarre call comes in, they aren't trapped by some dialogue tree. They can quickly adapt, test a creative solution and actually help the client. And addressing your skepticism from earlier about opening the door to more errors, what the data actually shows is that recognizing employees as the ultimate asset profoundly changes workplace culture.
Really in a measurable way. Yes, when you stop treating people like broken cogs that need constant supervision, they feel encouraged to rise to challenges. Team morale improves, client satisfaction goes up, and overall performance increases. People who are trusted to use their brains tend to actually use their brains far more effectively. Precisely. So what does this all mean for the person listening right now? We've redefined the purpose of rules. We've shifted the focus from failure to success and completely flipped our view of human nature.
It's a lot to take in. It is. This isn't just a tiny tweak to a morning routine. It's an entire paradigm shift in how we manage anything. This raises an important question, though, because moving from Safety one to Safety 2 requires A profound change in organizational culture. It means transitioning from a posture of policing to a posture of continuous learning. But how do you actually do that? You know, on a random Tuesday? If a listener wants to implement this today, what are the tangible day-to-day mechanisms?
Well, the source mentions a manufacturing facility that successfully made this shift. Right. They went from just reacting to equipment malfunctions to a proactive learning based culture. But how? It comes down to fundamentally changing your feedback loops instead of just holding post mortems when things go drastically wrong, you institute what went right debriefs. What went right? Debriefs. Yeah, you actively asked the floor staff, Hey, we hit our production goals today despite the massive supply chain delay.
What did you guys do to make that happen? Oh, so you're actively trying to make their invisible adaptations visible to the whole company? Exactly. And you reward people for finding proactive solutions rather than just punishing them when something inevitably breaks. You train your managers to ask entirely different questions. Like what? Instead of investigating an issue by asking who didn't follow the procedure, you ask what was it about the reality of today's shift that made the procedure difficult to follow?
Wow, that completely changes the tone of the conversation. It does. It creates A dynamic culture of flexibility. You empower the staff to identify potential problems in advance, which makes the entire operation infinitely more efficient during unforeseen setbacks. Safety One trains you to be a great mechanic when the engine fails. Safety 2 trains you to be an architect of an engine that rarely needs a mechanic in the first place. That is a phenomenal way to look at it. Eric Hallnagel's framework really forces us to completely rethink what it means to be in control.
It really challenges our baseline assumptions. Designing safer, more effective systems, whether that's in a kitchen, a hospital or honestly, just managing your own e-mail inbox, requires blending the reactive with the proactive. Exactly. It means making the leak, from obsessing over preventing things from going wrong, to actively ensuring they have the capacity to go right. So. Take a hard look at your own environment this week. Where is your energy actually going? Are you spending all your time and resources trying to meticulously rein in errors and police behavior playing?
Whack a mole. Right. Or are you studying your daily accomplishments, asking your team why things work today, and intentionally building that adaptability? It brings us right back to the beginning. We love the comfort of a rigid rule because we want the illusion of perfect mechanical precision. But I really want you to Mull over this final thought as you go about your day. If our systems are built entirely on the assumption that humans will inevitably fail, are we inadvertently training ourselves to stop thinking critically and just passively wait for the inevitable failure to happen?
What if your biggest vulnerabilities aren't actually coming from broken rules, but from rules that are being followed far too perfectly in exactly the wrong situations? It's a question that completely changes how you look at the world. It really does. Thanks for joining us on this deep dive.
Podbean