Fail-Prevention vs Fair-Safe

Fail-Prevention vs Fair-Safe

This is a short story about two very different approaches to designing the first generation of commercial jet aircraft.

The British de Havilland Comet was the world’s first commercial jet airliner. Its four engines were buried inside the wing roots, close to the fuselage. It was an elegant aerodynamic solution: embedding the engines reduced drag and produced a remarkably clean aircraft. But it also meant placing four powerful, high-speed machines inside one of the aircraft’s primary structures. The Comet designers were aware of engine-failure safety risks and even incorporated armour around the engine cells, but the installation inevitably made containment more complex.

Boeing took a different path with the 707. Its engines were mounted externally in pods beneath the wings on pylons. That physical separation meant an engine and its associated systems could be treated more independently from the aircraft itself. Boeing’s later documentation describes the 707 as being certified on a fail-safe basis: the aircraft was required to be capable of continued safe flight and landing even after the separation of a single engine.

The difference can be framed as two engineering questions.

The Comet asks:

“How do we prevent the engine from failing catastrophically?”

Boeing asks:

“What happens to the aircraft when an engine does fail catastrophically?”

That second question interests us.

It assumes that however well something is designed, maintained and operated, failure remains a real possibility.

So instead of making the entire system depend upon preventing failure, you also design the system to contain the consequences of failure.

We think about workplace behaviour in much the same way.

Instead of asking:

How do we prevent people behaving badly?

We ask:

How does the team remain safe and functional when someone inevitably does?

That is a stronger systems question because it assumes human fallibility rather than designing around its absence.

Psychological safety is often framed more like the fail-prevention approach: create conditions in which people feel safe, trust one another, speak openly and behave respectfully.

All desirable.

But the system is still vulnerable to the inevitable interruption, rudeness, belittling, ignored objection, angry response or abuse of authority.

Spatz starts from a different assumption:

Someone will eventually behave objectionably. What happens next?

A verbal caution is the first containment mechanism.

If that fails, SpatzChat app provides progressive escalation through a Formal Caution, Formal Objection and if the interaction still cannot recover, Formal Stop and the Team & AI Review provides another layer of protection. HR remains outside the process as the final escalation if the micro-conflict cannot be resolved.

This fits closely with our recent thinking:

We don’t create the culture. Reduce the behaviour that degrades It.

We are not trying to engineer a workplace in which behavioural failure never occurs.

We are trying to engineer one in which ordinary behavioural failure does not become catastrophic failure.

Our thinking is simple:

Don’t design a team that cannot fail.
Design a team that can safely fail.

And perhaps the most important distinction is this:

Psychological safety asks how we prevent the failure.

At Spatz, we also ask what happens when prevention fails.

We think the second question is where the process thinking begins.

Leave a comment

Blog at WordPress.com.

Up ↑