Coordination Failure Modes and a Minimum Viable Pattern Language
Central finding
A relatively small set of functional failure loci recurs across hospitals, emergency response, aerospace, software, public institutions, commons, coalitions, movements, and collaborative governance. But the stronger version of the 80/20 claim does not survive scrutiny:
Failure loci concentrate; failure causes do not.
No evidence reviewed here supports ranking coordination causes by population frequency. The incident database most often used for such claims explicitly warns that reporting is voluntary, captures only a small share of actual events, is not epidemiological, and should not be used to infer the relative frequency of causes. It also notes that most events have multiple root causes. Complex-system failures generally require combinations of faults, while comparative commons research likewise finds that no single institutional principle is sufficient or necessary for success.1
The useful 80/20 result is therefore not “a few root causes explain most breakdowns.” It is that breakdowns repeatedly become visible at a small number of interfaces and functions:
- underspecified handoffs;
- divergent shared state;
- authority separated from relevant information;
- avoidable dependency load;
- failure to detect exceptions and close feedback;
- captured change rights or assurance;
- inadequate or misdirected boundary spanning;
- non-credible commitments;
- metric-induced goal displacement;
- excessive coordination and veto accumulation;
- over-constraining rules;
- power and incentive asymmetry; and
- concentrated capability without succession.
These are not independent root causes. They are recurrent places where multiple causes combine and where intervention is often possible.
The evidence also changes what counts as a solution. Delegation, standards, checklists, escalation channels, monitoring, sanctions, voting, facilitation, and audits are mechanisms. A reusable pattern combines mechanisms with roles, authority, information, state, interfaces, exception paths, feedback, permissions, and change rights. Across the evidence, isolated mechanisms repeatedly produced null results or reversals; configurations with explicit prerequisites have a better—though still far from conclusive—record.
The report’s minimum viable language consists of a preliminary dependency check and six patterns:
- explicit interface contracts with receiver obligations;
- canonical shared state with a named integrator;
- migratable authority with fixed accountability;
- built-in exception detection with pre-authorized response;
- bounded change rights with independent assurance; and
- accountable voice channels as a procedural-rights floor.
This is a defensible synthesis, not a proven optimal subset. No study located here compares complete pattern configurations on a common outcome.
1. What should count as a coordination failure?
“Communication failure,” “silos,” “lack of alignment,” and “poor culture” are not sufficiently causal descriptions. Each can arise from several different coordination failures requiring different responses.
A communication problem may mean:
- a message was never transmitted;
- responsibility crossed a boundary without being accepted;
- messages circulated but nobody integrated them;
- information was condensed until its uncertainty disappeared;
- people detected a problem but were unable or unwilling to speak;
- the recipient lacked authority or capacity to respond; or
- incentives made accurate disclosure irrational.
Likewise, a one-person bottleneck may be:
- avoidable dependency fan-in;
- a decision right held too centrally;
- a necessary integration role;
- scarce capability or permissions without succession;
- an assurance checkpoint intentionally designed to be singular; or
- genuinely tight coupling for which concentration is appropriate.
The visible symptom does not identify the causal locus. Good diagnosis begins by asking what coordination function is missing or malfunctioning: dependency management, transfer, integration, authority allocation, exception detection, commitment enforcement, learning, or governance of the coordination system itself.
Evidence labels used below
- Established: supported by multiple primary studies, a strong comparative design, a randomized study, or a substantial systematic review.
- Evidence-supported implication: a synthesis strongly suggested by established evidence but not directly tested as a complete claim.
- Practitioner knowledge: detailed documentation from a mature operating system, without comparative outcome evidence.
- Plausible synthesis: convergence across cases, not tested as a configuration.
- Proposed: a design hypothesis that remains unevaluated.
2. The priority failure set
The thirteen loci below are tiered by cross-domain recurrence, consequence, and tractability—not incidence. Tier I requires broad recurrence plus both a documented negative case and some measurement or intervention evidence. Tier II contains consequential recurring failures missing one of those supports. Tier III contains important but less tractable, less generalizable, or more contested failures.
Tier I: recurrent, consequential, and comparatively tractable
| Failure locus | Causal failure, affected interfaces, and consequences | Diagnostic discriminator | Evidence and uncertainty |
|---|---|---|---|
| 1. Interface and handoff under-specification | Work, information, materials, or authority cross a boundary without a minimum content set, named sender and receiver, defined transfer instant, receiver confirmation, or right to refuse. The result is orphaned responsibility, incompatible understandings, and defects discovered downstream. This is not simply low communication volume or absence of a form. | Is there a named receiver? When exactly does responsibility pass? Can the receiver hold or reject the transfer? Is transfer success measured, or only form completion? | Recurrent in clinical handoffs, surgery, refinery shift turnover, construction-to-operations transition, interagency response, software modules, and transitions of care. I-PASS reported 23% fewer medical errors and 30% fewer preventable adverse events, but it was an uncontrolled pre/post evaluation of a four-part implementation bundle, with significant reductions at six of nine sites. Ontario’s mandatory checklist rollout across 101 hospitals found no significant change in complications or mortality. The locus is high-confidence; the active ingredient is not.2 |
| 2. Shared-state divergence | Participants lack a reliable common representation of current conditions, provenance, uncertainty, commitments, and exceptions. Messages may be transmitted successfully while the integrated picture remains absent or distorted. Consequences include incompatible action, delayed recognition, and locally rational decisions that are collectively incoherent. | Was the message sent and received? If yes, the channel is not the problem. Who owns the integrated picture, separate from doing the work? Can cases be reconciled to the aggregate state? Is the state also a rewarded performance measure? | On 9/11, the Office of Emergency Management could have served as an information focal point but did not perform the integrating role. In the Columbia accident, danger-signaling uncertainties disappeared as a formal analysis was condensed into an informal verbal brief. A hidden-profile meta-analysis found groups eight times less likely to solve a problem when critical information was distributed. The Phoenix VA case shows that even a canonical record can become false when incentives attach to its variables and assurance is waived.3 |
| 3. Authority mislocated relative to decision-relevant information | Decision authority remains with a position lacking relevant information or expertise—or migrates informally without becoming visible or auditable. Both rigid centralization and undeclared devolution can fail. Interfaces affected include field-to-command, technical-to-managerial, and representative-to-constituency relationships. | Can the current decision holder be named? Under what condition did authority move there? If a bottleneck is removed, does that remove a decision right, an integration function, or a true dependency? | Incident Command System field research documents authority migrating to expertise while formal accountability remains fixed, but only where supervisors permit and direct that migration. NASA documented the opposite: an informal chain of command operating outside formal rules. The Clamshell Alliance had representatives without delegated authority and later a coordinating committee that assumed authority it did not possess. Conversely, decentralized planning produced risk-taking and coordination problems in multiteam experiments, and greater local logistics decision space was associated with poorer performance in Ghana and Guatemala.4 |
| 4. Excess dependency load created by partitioning | Work has been divided so that progress requires more parties, approvals, or cross-unit adjustments than the task intrinsically demands. Coordination cost is generated by organizational or technical architecture rather than by unavoidable coupling. | Count the parties whose action or assent is required. Which dependencies are intrinsic, and which would disappear if work or ownership were repartitioned? | Software and product evidence is unusually strong: geographically distributed work items took roughly 2.5 times as long as comparable colocated work; alignment between technical dependencies and coordination relations reduced issue-resolution time by an average of 32%; matched products differed by up to a factor of eight in potential change propagation. Generalization beyond software and product development remains untested.5 |
| 5. Exception non-detection and unclosed feedback | The system continues executing a plan after its assumptions cease to hold because detection is not built into the work, escalation criteria are not captured, local repair hides defects, or response authority is absent. | What fraction of cases meeting escalation criteria actually trigger escalation? If detection occurs, can the recipient act differently? Are workarounds logged and aggregated, or silently absorbed? | In the MERIT cluster-randomized trial, medical-emergency-team calls were much more common in intervention hospitals, but the composite outcome did not improve; the team was called for only 30% of patients meeting its criteria who were later admitted to intensive care. The problem was not simply channel capacity. Across 40 documented multiteam failures, acting exceeded monitoring and recalibration, although the sample contained failures only. Nurses and medication users routinely repaired defects locally, making the organization less likely to learn from them.6 |
Tier II: high consequence, but weaker intervention or comparative evidence
| Failure locus | Causal failure, variation, and consequences | Diagnostic discriminator | Evidence and uncertainty |
|---|---|---|---|
| 6. Assurance and change-rights capture | A coordination rule, record, metric, or safety structure exists, but the party it is supposed to constrain controls the audit, waiver, or amendment right. The structure can therefore be quietly un-built. | Who may waive the check? Who can amend the rule, metric, interface, or authority allocation? Is assurance institutionally independent of the measured party? | Three primary cases converge: a VA compliance-certification requirement was waived by the official whose operations it measured; NASA found decision-making outside its own rules and subsequently called for independent technical authority over requirements and waivers; the Clamshell coordinating committee exercised authority its constitution withheld, followed by a crisis over whether the rule could be changed. The failure route is well documented, but no outcome study compares change-rights designs.7 |
| 7. Boundary-spanning under-production or mis-targeting | Interdependent units devote insufficient effort to coordination across boundaries, or generic liaison activity is added without access, authority, task relevance, or a defined interface. Boundary work becomes hidden repair labor or another bottleneck. | Which boundary carries consequential interdependence? Does the liaison have access, translation capability, delegated authority, and backup? Is a generic forum replacing interface-specific work? | In a corpus of failed multiteam systems, between-team behavior was less common than within-team action. A controlled 233-system laboratory exercise found boundary-spanning activity helpful only when centered on the component team most critical to the task. That result should not be generalized directly to large coalitions. Meta-analytic evidence associates boundary spanning with performance and innovation but also role stress.8 |
| 8. Commitment-credibility deficits | Participants cannot rely on future compliance without continuous supervision because monitoring is absent, accountability channels fail, or sanctions are disproportionate or illegitimate. | Can behavior be observed at acceptable cost? Do reports reach an accountable authority? Are rules congruent with local conditions and are responses graduated? | A review of 91 commons studies found broad support for Ostrom-style principles, including monitoring and graduated sanctions, but configural analysis shows that no individual principle is sufficient or necessary. Six harmonized field experiments found community monitoring effects of about 0.10 standard deviations, with the accountability channel appearing most influential; only one study was powered near 80% for an effect of that size.9 |
| 9. Metric-mediated goal displacement | A rewarded indicator ceases to represent the underlying service or risk. Reported performance improves while real conditions stagnate or deteriorate. This differs from ordinary observability failure because incentive pressure actively corrupts the representation. | Can records be reconciled to individual cases? Is reward or punishment concentrated on one indicator? Who controls the audit and its waiver? | At the Phoenix VA, schedulers described false desired dates, same-time rescheduling that erased recorded waits, and paper lists kept outside the official system. Wells Fargo’s volume-driven sales regime produced unauthorized accounts and concealment. Reviews of performance-management systems identify gaming, information manipulation, selective attention, and transformed relationships as recurring effects of directive regimes.10 |
| 10. Coordination overhead and veto accumulation | Meetings, consultation, reporting, or consent requirements consume more capacity than the underlying interdependence justifies. Blocking rights accumulate and decision latency exceeds the environment’s rate of change. | Is the dependency real? How many consent points must a decision cross? Which frictions protect safety or legitimacy, and which merely reproduce process? | In the Clamshell Alliance, local meetings ran three to four hours, congresses took two to three days to make a handful of decisions, and organization-wide decisions required at least two months. Any individual could block action, and common agreement narrowed as membership grew. This is unusually concrete evidence from a movement, but comparative evidence on overcoordination remains limited.11 |
| 11. Uniform over-constraint | A protective rule is treated as a global invariant even though its safe application depends on context. The rule creates hazards in cases with the least slack, while informal deviation becomes necessary but ungoverned. | Does the constraint distinguish relevant operating conditions? Can necessary deviation be detected, justified, bounded, and reviewed? | A potassium-chloride safety intervention illustrates the appropriate response: differentiated concentration thresholds by clinical setting rather than simple relaxation. More broadly, operators can fail either by not adapting when adaptation is necessary or by adapting badly. The prescription is conditional rules plus reviewable exception authority—not unbounded discretion.12 |
Tier III: important conditions or domain-bounded risks
| Failure locus | Causal status and consequence | Diagnostic discriminator | Evidence and uncertainty |
|---|---|---|---|
| 12. Power and incentive asymmetry | Power asymmetry affects whether every other pattern can operate: who may speak, define the problem, bear coordination costs, control resources, and use formal procedures. It is patternable at the level of procedural rights, but the evidence does not show that coordination designs durably redistribute power or agenda control. | Do weaker participants possess usable representation, information, conflict, and appeal rights? Does a report reach someone accountable? Who controls resources and exit options? | Collaborative-governance research treats meaningful representation as necessary under major power imbalances. Yet a pre-registered randomized community-development intervention in Sierra Leone produced short-run output gains without sustained effects on collective action, decision processes, or marginalized groups’ involvement. Procedural protections are plausible; durable redistribution is not demonstrated.13 |
| 13. Capability concentration and succession fragility | Knowledge, permissions, or review capacity reside with one or two people without a transfer path. Failure can follow exit, overload, illness, or loss of access—but concentration may also be an efficient response to scarce expertise or low demand. | Is scarcity primarily knowledge, permission, trust, or workload? Is the bottleneck intentional? Can ownership and access be transferred in an emergency? | Among 1,932 popular GitHub projects, 57% had a truck factor of one and 25% a factor of two; 16% lost all core maintainers and only 41% of those recovered. The estimates depend on definitions and a selected open-source sample. Cross-domain causal generality remains uncertain.14 |
What the tiers do—and do not—mean
The ordering is most defensible as a priority for diagnosis and experimentation, not a statement about how frequently each cause occurs in the world. Tractability drives much of the tiering because it is the criterion with the most actual measurement. Different weights on consequence, recurrence, or tractability would move dependency load, change rights, power, and succession between tiers.
3. A failure-to-response map
The map below is a diagnostic aid, not a validated instrument. Its chief value is to block symptom matching: radios for an authority problem, meetings for a dependency problem, or escalation channels for a detection problem.
| Presenting symptom | Questions that split the symptom | Likely locus | Response family—and the common wrong response |
|---|---|---|---|
| “There is a one-person bottleneck.” | Does removing the person remove a dependency, a decision, an integrated picture, or only an access restriction? Is concentration intentionally providing assurance? | Dependency load; authority location; shared-state integration; succession; or no defect | Repartition work; migrate a bounded decision right; name an integrator; create a permission and succession ladder; or leave a designed bottleneck in place. Wrong: automatically adding reviewers or removing ownership. |
| “It is a communication failure.” | Was the message sent and received? Did uncertainty survive condensation? Did anyone integrate the reports? Could the recipient act? | Channel failure; interface failure; shared-state divergence; authority failure; voice suppression | Repair the specific channel, handoff, integration role, decision right, or protected voice route. Wrong: increasing message volume. |
| “People are not escalating.” | What proportion of qualifying cases trigger escalation? Do people detect but remain silent? Does escalation reach someone capable of changing the response? | Exception detection; power/voice; response capability | Build detection into work; protect dissent; or create downstream action capacity. Wrong: adding another channel without locating the binding constraint. |
| “The dashboard is green, but service is deteriorating.” | Can case records be reconciled to aggregates? Is the indicator highly rewarded? Who may waive the audit? | Gaming plus assurance capture | Reduce incentive concentration; use a measure portfolio and case-level reconciliation; separate assurance from the measured party. Wrong: adding more targets. |
| “Nobody knows the current state.” | Is the state absent or merely scattered? Does any role own integration apart from execution? | Shared-state divergence | Canonical state, named integrator, reconciliation, provenance, uncertainty, and exception status. Wrong: another unowned dashboard. |
| “Teams keep improvising around defects.” | Are workarounds captured, aggregated, assigned upstream, and verified closed? | Unclosed feedback | Exception register, recurrent-defect aggregation, named owner, deadline, verified closure. Wrong: punishing improvisation before repairing the conditions that require it. |
| “The plan continues after conditions change.” | Is there a built-in test? Is fallback pre-authorized? | Exception non-detection | Embedded tests and bounded fallback authority. Wrong: requiring permission from an overloaded center for every deviation. |
| “The protocol blocks a necessary response.” | Is the exceptional condition identifiable? Is deviation reviewable and time-critical? | Uniform over-constraint | Context-differentiated thresholds and retrospective review. Wrong: either rigid enforcement or wholesale deregulation. |
| “Meetings dominate and decisions are slow.” | Is the interdependence intrinsic or partition-created? How many parties have vetoes? | Dependency load or overcoordination | Remove avoidable dependencies first; then narrow consent requirements while preserving necessary safeguards. Wrong: adding a coordination forum. |
| “Broad participation has not produced equitable outcomes.” | Do weaker participants control resources, agenda, or decisions? Is there a working route to an accountable authority? | Power asymmetry | Representation, protected dissent, conflict forum, accountable appeal. Expect procedural improvement, not proven redistribution. Wrong: treating attendance as power sharing. |
| “Rules are routinely ignored.” | Are rules locally workable and legitimate, or are violations opportunistic? | Over-constraint or commitment deficit | Revise rules for congruence and load, or add accountable monitoring and graduated response. Wrong: assuming every violation needs stronger sanctions. |
| “The coordination system itself is contested.” | Who can amend it? Who can waive its safeguards? Is the assurance holder independent? | Change-rights and assurance capture | Entrenched but usable amendment procedures, separately typed waiver rights, independent assurance. Wrong: leaving constitutional questions to ordinary operational authority. |
Three questions have especially high diagnostic value:
- Was the message sent and received? If yes, stop calling the problem a channel failure.
- What fraction of cases meeting escalation criteria actually escalate? This separates detection from voice and response-capacity problems.
- Who may waive the check? This reveals whether a nominal control can be undone by the party it is supposed to constrain.
4. Mechanisms are not patterns
An isolated mechanism performs one function:
- delegation relocates a decision;
- an audit checks a representation;
- a checklist standardizes a sequence;
- an escalation channel transmits an exception;
- monitoring makes behavior visible;
- sanctions increase the cost of noncompliance;
- voting aggregates preferences;
- modularization removes or reshapes dependencies.
A pattern configures several such mechanisms together with:
- roles and capabilities;
- formal and current authority;
- shared state;
- bilateral interfaces;
- detection and escalation paths;
- feedback and learning;
- accountability;
- prerequisites;
- change and waiver rights.
This distinction is empirical as well as semantic. Nulls or reversals appear when escalation channels, mandated checklists, targets with sanctions, individual commons principles, generic cross-team forums, participation mandates, local decision-space expansion, or consensus rules are deployed without their supporting conditions. By contrast, Incident Command, Toyota-style production rules, Google’s incident-management structure, and accountable commons governance are explicitly described as configurations whose elements depend on one another.
That contrast is suggestive, not conclusive. Configurations are often documented by proponents, while isolated mechanisms are more often subjected to skeptical tests. No study in this evidence base directly compares one complete configuration with another.
5. Fifteen evidence-qualified coordination patterns
“Candidate pattern” below means a recognizable configuration with recurrent implementation evidence, not demonstrated superiority. “Proposed pattern” means the elements have support but the assembled configuration has not been evaluated.
1. Explicit Interface Contract with Receiver Obligation
Status: Candidate pattern; active ingredient uncertain.
- Problem addressed: underspecified handoffs, orphaned responsibility, and state loss at boundaries.
- Appropriate when: transfers are repeated, consequential, and can be described by a stable minimum state; especially useful across shifts, professions, teams, or producer–consumer boundaries.
- Inappropriate when: work is highly exploratory and the interface cannot be specified without suppressing necessary negotiation; or the receiver lacks capacity to inspect or refuse.
- Core structure: named sender and receiver; minimum content; transfer instant; receiver synthesis or read-back; explicit open items and uncertainty; binary accept/hold/refuse response.
- Mechanisms: standards, workflow, read-back, exception flags, transfer logs.
- Authority and interface: the receiver holds a real refusal or hold right. Without it, the “contract” becomes a form.
- State requirements: open-item register, provenance, completion criteria, and evidence that responsibility—not merely information—has transferred.
- Tradeoffs: additional transfer time and possible field proliferation.
- Predictable failures: ritual completion, excessive documentation, checkbox measurement, and implementation without local adaptation.
- Power effects: makes responsibility attributable and gives receivers procedural leverage, but can also shift blame onto them.
- Implementations and negative cases: I-PASS and Toyota’s direct customer–supplier connection illustrate the configuration; Ontario’s checklist null shows that a mandated artifact alone is insufficient.
- Evidence: established on the mixed intervention facts; only an evidence-supported implication that receiver obligation is the active ingredient.
2. Canonical Shared State with a Named Integrator
Status: Candidate pattern; no positive outcome trial of the full configuration.
- Problem addressed: scattered, stale, incompatible, or selectively condensed representations.
- Appropriate when: multiple units act on interdependent conditions and no single executor naturally holds the whole picture.
- Inappropriate when: centralization would delay rapidly local action or create a high-value target for manipulation without independent assurance.
- Core structure: one authoritative state carrying provenance, uncertainty, outstanding commitments, assumptions, and exception status; a named integrator maintains and reconciles it.
- Roles and authority: the integrator is distinct from primary executors and may require reconciliation, but should not be rewarded on a metric derived from the same state.
- Interfaces: contributors have defined update duties; users can challenge or reconcile entries; unresolved divergence is visible.
- Prerequisites: sufficient data quality, time to integrate, and assurance independent of the measured party.
- Tradeoffs: dedicated capacity, reconciliation cost, and possible central bottleneck.
- Predictable failures: stale dashboards, executive condensation, unowned records, metric substitution, and manipulation that makes the record look better as reality worsens.
- Power effects: the integrator gains agenda-setting power through control of visibility; challenge rights are therefore essential.
- Implementations and negative cases: Incident Command cognition management and the separation of incident communications from operations in Google practice; negative cases include the absent 9/11 integrating function and the corrupted VA scheduling state.
- Evidence: evidence-supported implication plus mature practitioner knowledge.
3. Migratable Authority with Fixed Accountability
Status: Candidate pattern with strong negative bounds.
- Problem addressed: decisions held by positions remote from relevant information, or authority that migrates invisibly.
- Appropriate when: expertise and local conditions change during execution, decisions are time-sensitive, and competent supervisors can recognize relevant expertise.
- Inappropriate when: local actors cannot observe system-wide externalities, decisions are irreversible, or devolution would fragment a tightly coupled response.
- Core structure: formal accountability remains fixed; decision authority moves temporarily under declared, reversible conditions; movement is recorded.
- Authority model: represent three distinct facts—formal accountability, current decision authority, and the conditions permitting migration.
- State and escalation: decision logs record the holder, basis, scope, duration, and return path; system-level conflicts escalate to the accountable role.
- Prerequisites: supervisors must permit and, where needed, direct migration; expertise must be recognizable; shared intent and trust must already exist.
- Tradeoffs: declaration overhead and temporary ambiguity.
- Predictable failures: silent informal authority, uncontrolled risk-taking, over-detailed role systems, or local decisions made without superior local information.
- Power effects: can move operational control toward knowledge while preserving accountability, but may merely legitimate informal elites if migration criteria are opaque.
- Implementations and negative cases: Incident Command and knowledge-based incident roles; negative cases include NASA’s informal chain of command, decentralized multiteam planning, and weak logistics performance under greater local decision space.
- Evidence: evidence-supported implication bounded by comparative and experimental negative cases.
4. Incident Command Spine with Autonomous Field Cells
Status: Candidate pattern; the most fully specified configuration reviewed, not proven comparatively superior.
- Problem addressed: volatile, interdependent response involving multiple specialties and organizations.
- Appropriate when: responders share a professional community, demands are at least partly routine, social and cultural emergence is limited, and prior training creates trust.
- Inappropriate when: participants do not understand the role language, authority is politically contested, the event is socially novel, or formal command is mistaken for substantive integration.
- Core structure: initial command bootstrap; activation and deactivation of roles; modular field cells; role switching; explicit authority migration; shared cognition; reset or fallback procedures.
- Mechanisms: hierarchy, modularity, delegation, standardized roles, span-of-control rules, shared state, escalation, and pre-authorized reset.
- Interfaces: command sets intent and integrates state; field cells retain bounded autonomy; commander handoff is explicit.
- Prerequisites: common training, trust, usable terminology, and supervisors who support rather than suppress authority migration.
- Tradeoffs: training cost, role overhead, contested command, and risk that the diagram creates false confidence.
- Predictable failures: nominal command without integrated communications, structure without recalibration, and transplantation into institutions unfamiliar with its language.
- Power effects: concentrates accountability but can preserve tactical autonomy; unresolved jurisdictional conflict can remain hidden beneath a unified chart.
- Implementations and negative cases: FEMA urban-search-and-rescue task forces and Google incident management; negative cases include 9/11’s nominal directive without unified response, Grenfell’s failure to recalibrate, and hospital implementations whose staff did not understand ICS terminology.15
- Evidence: practitioner and field evidence with explicit conditionality; no comparative effectiveness trial.
5. Built-In Exception Detection with Pre-Authorized Response
Status: Candidate pattern; positive evidence is largely practitioner-grade, while the strongest causal evidence is a mechanism-alone null.
- Problem addressed: plans persist after assumptions fail, or exceptions are noticed only through heroic vigilance.
- Appropriate when: relevant failure conditions can be operationalized and a safe fallback can be bounded in advance.
- Inappropriate when: criteria are too noisy, response capacity is absent, or automated alerts would overwhelm attention.
- Core structure: tests embedded in activities, handoffs, and pathways; measured criteria capture; immediate bounded fallback; later review and reset.
- Authority: frontline actors may invoke specified fallback without prior permission; expansion beyond the bound escalates.
- State requirements: qualifying events, detected events, acted-on events, false positives, overrides, and downstream outcomes must be distinguishable.
- Tradeoffs: alert burden, conservative action, and instrumentation cost.
- Predictable failures: adding a channel rather than a detector, alert fatigue, criteria gaming, and detection without authority to act.
- Power effects: reduces dependence on discretionary permission but can subject frontline workers to inflexible surveillance.
- Implementations and negative cases: Toyota’s built-in tests and Incident Command reset procedures; MERIT shows why an escalation team without reliable criteria capture is insufficient.
- Evidence: established negative evidence; practitioner knowledge for the positive configuration.
6. Failure-Triggered Learning Loop with Verified Closure
Status: Candidate pattern; outcome evidence for the full configuration is weak.
- Problem addressed: local repair restores service but prevents the organization from seeing recurring defects.
- Appropriate when: exceptions recur and an upstream owner can change the producing system.
- Inappropriate when: reporting exposes workers to retaliation or when no actor has change authority.
- Core structure: capture exceptions and workarounds; aggregate recurring defects; assign an upstream owner and deadline; review detection, mitigation, coordination, and communication; verify closure.
- Mechanisms: incident review, defect registers, ownership, feedback, peer review, and follow-up assurance.
- Authority: the review body must be able to assign work, while the change owner must have authority and resources to alter the source.
- State requirements: workaround frequency, recurrence, action status, closure evidence, and residual risk.
- Tradeoffs: review time, action-item load, and possible disclosure risk.
- Predictable failures: blame suppressing reports, ritual postmortems, decaying action lists, and “learning” without change rights.
- Power effects: can protect frontline knowledge or become another instrument for attributing blame upward or downward.
- Implementations: blameless postmortem practice and defect escalation in mature production systems.
- Evidence: practitioner knowledge; quantitative claims about debriefing benefits remain less securely grounded in this evidence base.
7. Bounded Change Rights with Independent Assurance
Status: Candidate structure; no outcome evidence. Highest priority for empirical testing.
- Problem addressed: operational actors can waive, rewrite, or bypass the rules and assurance functions intended to constrain them.
- Appropriate when: coordination rules govern consequential authority, safety, metrics, membership, or interfaces.
- Inappropriate when: entrenchment makes adaptation prohibitively slow or turns a procedural rule into an identity commitment that cannot be revised.
- Core structure: explicit amendment rights and procedures; ordinary decisions separated from constitutional changes; waiver rights typed separately; independent assurance; emergency change followed by review.
- Authority: the constrained party cannot unilaterally waive the check; assurance independence is itself protected from ordinary amendment.
- State requirements: versioned rules, decision and waiver logs, expiration dates, rationale, and appeal paths.
- Tradeoffs: rigidity, constitutional overhead, and slowed emergency adaptation.
- Predictable failures: nominal independence, capture of the assurer, permanent “temporary” waivers, and the explicitness trap—where changing a legitimate rule becomes symbolically impossible.
- Power effects: constrains operational and executive discretion but can empower an unelected assurance body.
- Implementations and negative cases: Python’s PEP 8016 self-limiting governance clause, the governance settlement following the io.js fork, and NASA’s call for independent technical authority over requirements and waivers; negative cases include VA assurance waiver and the Clamshell amendment crisis.
- Evidence: documented implementations and strong failure cases; the prescription remains proposed at the outcome level.
8. Modularization with Explicit Interfaces
Status: Candidate pattern within software and product development; proposed elsewhere.
- Problem addressed: excessive dependencies created by architecture and partitioning.
- Appropriate when: work can be decomposed while preserving clear inputs, outputs, ownership, compatibility, and integration tests.
- Inappropriate when: performance depends on dense integral design, learning requires frequent cross-boundary interaction, or coupling is intrinsic rather than designed.
- Core structure: remove avoidable coupling; align ownership and communication with actual dependencies; specify compatibility, change notice, and integration tests.
- Authority: module owners control local changes within interface constraints; system integrators govern cross-module compatibility.
- State and escalation: dependency maps, interface versions, failed integration tests, and propagation paths are visible.
- Tradeoffs: local optimization, hidden cross-module dependencies, reduced learning contact, and integration surprises.
- Power effects: grants substantial local autonomy but may turn interface owners into gatekeepers.
- Implementations: modular software and product architectures.
- Evidence: established within the demonstrated domain; speculative for commons, movements, coalitions, and public institutions.
9. Accountable Self-Governance Bundle
Status: Candidate pattern for repeated common-pool dilemmas.
- Problem addressed: non-credible commitments, overuse, under-contribution, and externally imposed rules lacking local fit.
- Appropriate when: users and resources are identifiable, interactions repeat, behavior is monitorable, and membership is sufficiently stable.
- Inappropriate when: boundaries are radically open, appropriation is unobservable, or local power prevents legitimate collective choice.
- Core structure: clear boundaries; locally congruent rules; participant rule-making rights; accountable monitoring; graduated sanctions; accessible conflict resolution.
- Authority: participants hold collective-choice rights; monitors answer to users or are users themselves; sanctions are bounded and reviewable.
- State and interfaces: resource condition, contribution, appropriation, violations, and sanctions must be observable at tolerable cost.
- Tradeoffs: surveillance, exclusion, local capture, and enforcement burdens.
- Predictable failures: importing isolated principles, sanctions without legitimacy, and institutional monocropping that violates local congruence.
- Power effects: can increase user control but can also harden community boundaries and local hierarchies.
- Implementations: established commons-governance arrangements.
- Evidence: strong review and configural evidence; explicit evidence against treating individual principles as standalone prescriptions.
10. Nested or Polycentric Coordination
Status: Proposed pattern.
- Problem addressed: local autonomy cannot manage cross-boundary spillovers, standards, appeals, or system-wide risks.
- Appropriate when: problems operate at several scales and local knowledge remains valuable.
- Inappropriate when: cross-center transaction costs, veto points, capture, or responsibility diffusion exceed the value of local autonomy.
- Core structure: autonomous local centers plus cross-scale forums for spillovers, standards, appeals, conflict resolution, and shared learning; explicit system-level authority for genuinely shared decisions.
- Authority: operational rights remain local; specified cross-scale issues move upward or sideways; appeals and change rights are explicit.
- State requirements: visibility across centers without forcing complete uniformity.
- Tradeoffs: duplicated capacity, transaction costs, weak accountability, exclusion, and status-quo reinforcement.
- Power effects: can prevent monopoly control, but also multiplies venues that well-resourced actors can dominate.
- Evidence: plausible synthesis only. The empirical tension is material: the “nested enterprises” principle was the weakest-supported element in a major commons review.
11. Learning-Oriented Measurement and Assurance
Status: Proposed pattern.
- Problem addressed: metrics cease to be reliable state because rewards and punishments induce gaming.
- Appropriate when: measurement is necessary but outcomes are multidimensional and case-level audit is possible.
- Inappropriate when: assurance is controlled by the measured party or the measure portfolio merely multiplies reporting burdens.
- Core structure: balanced measures; case-level reconciliation; indicators of gaming; protected reporting; periodic review of incentives; independent assurance and revision rights.
- Authority: metric owners cannot waive the audit; assurance can inspect source cases and require redesign.
- State requirements: raw case data, aggregate measures, exceptions, audit results, and incentive changes.
- Tradeoffs: administrative burden, strategic complexity, and new gaming surfaces.
- Predictable failures: dashboard proliferation, weak case linkage, punitive use of learning measures, and nominal assurance without independence.
- Power effects: limits managers’ unilateral control of performance narratives but may strengthen auditors.
- Negative case: nearly every artifact could exist nominally at the VA while the crucial independence condition remained absent.
- Evidence: strong evidence on the pathology; speculative evidence on the assembled response.
12. Mandated, Backed Boundary Integrator
Status: Proposed pattern.
- Problem addressed: consequential interdependence crosses unit or organizational boundaries without an owner.
- Appropriate when: a specific boundary is demonstrably critical and the integrator can obtain access and delegated authority.
- Inappropriate when: “coordination” is generic, interfaces are numerous and shifting, or the liaison becomes a substitute for direct relationships.
- Core structure: named liaison or integration team with access, translation competence, decision scope, backup, and explicit limits.
- Authority: enough delegated authority to resolve specified boundary issues; unresolved conflicts escalate to named principals.
- State requirements: interface dependencies, unresolved disputes, cross-boundary commitments, and decision status.
- Tradeoffs: role stress, hidden repair work, duplicated communication, and single-point-of-failure risk.
- Predictable failures: liaison without authority, generic forums, and permanent dependency on personal brokerage.
- Power effects: boundary actors can become brokers who control information and access.
- Negative case: the Clamshell spokesperson conveyed decisions but lacked representative authority.
- Evidence: plausible synthesis; direct targeting evidence comes from a small, symmetric simulated architecture and cannot establish a general field rule.
13. Maintainer Succession and Contributor Ladder
Status: Proposed pattern.
- Problem addressed: capability, review rights, and permissions concentrated in one or two maintainers.
- Appropriate when: continuity matters and new contributors can acquire competence through staged access.
- Inappropriate when: project demand is low, the work is complete, or expertise is genuinely non-substitutable.
- Core structure: documented ownership; staged permissions; paired review; newcomer pathway; succession triggers; emergency transfer rights.
- Authority: rights expand with demonstrated capability; emergency transfer is independently executable.
- State requirements: ownership map, bus/truck factor, review load, access status, and inactive-maintainer triggers.
- Tradeoffs: training and review overhead, access risk, and possible dilution of accountability.
- Predictable failures: nominal backups without permissions, contributor hurdles, and premature broad access.
- Power effects: reduces incumbent gatekeeping but can threaten maintainers’ identity or security concerns.
- Evidence: established problem incidence in a selected open-source sample; proposed response.
14. Protected Dissent with Independent Technical Authority
Status: Candidate pattern, based more strongly on negative cases than positive intervention evidence.
- Problem addressed: disconfirming evidence is suppressed by hierarchy, status, or managerial incentives.
- Appropriate when: decisions create safety or system-wide risk and specialist judgments may conflict with schedule or political goals.
- Inappropriate when: every disagreement becomes a veto or the authority lacks accountability.
- Core structure: required solicitation of contrary evidence; status-safe voice; independent technical or safety authority with substantive line authority; appeal path and reasoned disposition.
- Authority: technical authority can hold or escalate specified decisions; operational management cannot unilaterally waive that power.
- State requirements: dissent records, evidence, disposition, overrides, and waiver rationales.
- Tradeoffs: delay, adversarial ritual, and assurance-body capture.
- Predictable failures: symbolic invitations to speak, interpersonal coaching without structural protection, and independent review that lacks decision authority.
- Power effects: redistributes procedural leverage toward technical and lower-status participants but does not necessarily change resource control.
- Implementations and evidence: operating-room research associates leader coaching, speaking up, and boundary spanning with successful implementation; NASA provides strong primary evidence of the failure route. The positive evidence is observational.16
15. Power-Balanced Participation Compact
Status: Proposed pattern with a randomized negative boundary.
- Problem addressed: nominally inclusive collaboration in which weaker parties lack usable decision, agenda, conflict, or accountability rights.
- Appropriate when: interdependent parties must collaborate and power imbalances would otherwise make participation symbolic.
- Inappropriate when: sponsors are unwilling to share procedural rights or when facilitation is presented as a substitute for material redistribution.
- Core structure: shared problem definition; representative participation; explicit resource and decision rights; neutral facilitation; conflict forum; staged commitments; working route to accountable authority.
- Authority: representatives need real mandates; commitments and appeals must reach actors able to respond.
- State requirements: attendance is insufficient—agenda access, proposals, decisions, commitments, and responses must be observable.
- Tradeoffs: slower decisions, representation disputes, co-optation, and professionalized participation.
- Predictable failures: short-run output gains without institutional change, consultation fatigue, and sponsors retaining agenda control.
- Power effects: may create procedural rights; it cannot be claimed to redistribute resources or durable agenda power.
- Evidence: plausible configuration, bounded by the Sierra Leone randomized negative case.
6. The minimum viable pattern language
The smallest defensible language is not the six most popular practices. It is the smallest set that covers all Tier I loci plus the assurance and power conditions capable of disabling the rest.
Move 0: Check the dependency before coordinating it
Before adding meetings, reporting, integration roles, or escalation paths:
- identify the dependency;
- classify whether it is intrinsic or partition-created;
- count how many parties’ action or assent it requires;
- remove or reshape avoidable dependencies; and only then
- coordinate what remains.
This is a preliminary move rather than a universal pattern. The principle is definitional—if activities are not interdependent, there is nothing to coordinate—and the strongest measurements come almost entirely from software and product development.17
The six-pattern core
| Core pattern | Failure covered | Why it has leverage | Weakest evidential or practical link |
|---|---|---|---|
| M1. Explicit interface contract with receiver obligation | Handoff under-specification | Converts expectations into bilateral, checkable obligations and establishes when responsibility passes | The contribution of receiver obligation has not been separated experimentally from implementation intensity |
| M2. Canonical shared state with a named integrator | Shared-state divergence | Creates an accountable integrated picture with provenance, uncertainty, commitments, and exceptions | No positive trial of the full configuration; a canonical state can itself be gamed |
| M3. Migratable authority with fixed accountability | Authority–information mismatch | Moves decisions toward relevant expertise without making accountability disappear | Requires supervisors to permit and direct migration; can fail through either excess centralization or uncontrolled devolution |
| M4. Built-in exception detection with pre-authorized response | Exception non-detection and unclosed feedback | Makes detection structural rather than heroic and allows bounded action before escalation delay becomes fatal | Positive evidence is mostly mature practitioner knowledge; alert overload and criteria capture remain risks |
| M5. Bounded change rights with independent assurance | Assurance and change-rights capture | Prevents the constrained party from silently removing the constraint; permits adaptation without making every rule optional | No outcome study; entrenchment can become rigidity |
| M6. Accountable voice channel | Power asymmetry and commitment deficits | Provides a procedural route from governed actors to an authority required and able to respond | Best experimental effect is small and often underpowered; no evidence of durable power redistribution |
Why this set
The core covers:
- all five Tier I loci;
- the assurance failure that can disable any other pattern;
- a minimal procedural response to power asymmetry;
- portions of commitment credibility, metric gaming, boundary integration, and overcoordination.
It deliberately excludes several useful patterns from the universal core:
- Modularization has strong evidence but only within a narrow demonstrated domain.
- Incident Command is a rich configuration but highly conditional.
- Self-governance bundles fit recurring commons conditions rather than all coordinated action.
- Nested polycentricity has material evidence tensions.
- Succession ladders address a domain-bounded risk.
- Learning loops are important, but learning without change rights is theater.
- Boundary integrators cannot yet state a well-supported general targeting rule.
What to test first
- Assurance independence: Compare otherwise similar systems in which waiver and audit rights are, or are not, controlled by the measured party.
- Criteria capture: Measure qualifying exceptions, detected exceptions, escalations, responses, and outcomes—not merely channel use.
- Receiver obligation: Separate the effect of read-back and refusal rights from training intensity, observation, and implementation support.
- State–metric separation: Test whether separating the operational record from rewarded performance measures preserves accuracy.
- Configuration against configuration: Evaluate complete bundles, rather than continuing to compare named mechanisms with business as usual.
7. Why copied solutions fail
The most consequential finding is not that interfaces matter. It is that a coordination structure can be correctly designed and then undone by the authority it was meant to bind.
- The VA had a scheduling system and compliance requirement, but the assurance requirement was waived by the official whose operations it measured.
- NASA had formal decision rules, but an informal chain of command operated outside them; the subsequent inquiry emphasized independent authority over specifications, requirements, and waivers.
- The Clamshell Alliance had a constitutionally specified decision process, but its coordinating committee assumed authority it lacked, and the organization then struggled over whether it could amend its own rule.
In each case the visible structure existed. The missing protection was the independence of the function that kept it honest.
What travels is the structure. What often does not travel is the independence of the function that preserves the structure.
This conclusion is supported by unusually sharp failure cases, but it remains a design hypothesis rather than an established intervention result. There are no comparative outcome studies of assurance-independence arrangements. That combination—high potential leverage and almost no direct intervention evidence—is why it should be tested first.
8. Coordination is contingent, and its costs are part of the design
Reduce dependencies before adding coordination
Adding coordination is appropriate only after avoidable coupling has been removed. More meetings cannot compensate efficiently for architecture that forces every decision through many unrelated parties. In software and product work, party count, coordination congruence, and change propagation have measurable effects on completion time. Outside those domains, the same move remains plausible but untested.
Explicit interfaces can enable autonomy
A clear boundary does not necessarily centralize work. When inputs, outputs, uncertainty, acceptance, and change notice are explicit—and the receiver can refuse—a unit can operate more independently because it needs less continuous negotiation. Interface specification becomes a condition for local autonomy, not its opposite.
Some friction is protective
Checklists, required consultation, independent assurance, conflict forums, and review rights consume time. That cost may prevent premature closure, domination, unsafe deviation, or unreviewed change. The objective is not to minimize coordination, but to distinguish:
- friction that manages genuine interdependence or risk;
- friction that preserves legitimacy and accountability; and
- friction produced only by poor partitioning, duplicated approvals, or veto accumulation.
The potassium-chloride case is instructive: the answer to an overbroad safety constraint was neither rigid enforcement nor removal. It was differentiation by context.
Informal repair is both resilience and evidence of failure
Workarounds keep systems functioning. Nurses’ local repairs, paper records outside official systems, and rapid supplier improvisation after Toyota’s Aisin fire illustrate that actual operations are often the formal system plus informal repair. Eliminating repair capacity can make systems brittle.
But repair also hides defects. When frontline actors repeatedly absorb failures without an upstream learning loop, the organization sees restored service rather than a degrading process. A robust pattern language must protect adaptive capacity while making recurring repairs visible.
Explicitness can itself become a trap
Explicit roles, rules, and amendment procedures improve inspectability. Yet the Clamshell Alliance shows that a fully explicit and legitimate rule can become bound to organizational identity, making revision appear illegitimate. Entrenchment therefore needs:
- a usable amendment path;
- emergency procedures;
- sunset or review provisions where appropriate; and
- separation between core protections and ordinary operating rules.
Local autonomy is not invariably superior
Authority should move toward relevant information only when local actors actually possess better information and system-wide externalities remain controlled. Experimental multiteam evidence and logistics studies show that decentralization can increase risk, reduce integration, or worsen performance. “Push decisions down” is a mechanism-level slogan, not a pattern.
9. Architectural implications for a general model of coordinated action
Existing coordination theory already supplies a strong base: actors, activities, dependency types, and mechanism families. Malone and Crowston, for example, distinguish prerequisite, transfer, usability, simultaneity, task–subtask, and shared-resource dependencies.17 The evidence here suggests that an implementable general model must add or make explicit several entities that repeatedly disappeared in failed systems.
Inherited foundations
-
Actors, roles, capabilities, and capacity
- People and organizations should not be conflated with the roles they temporarily occupy.
- Capability and succession exposure need explicit representation.
-
Activities and typed dependencies
- Dependencies need direction, timing, criticality, and change-propagation properties.
- The model must distinguish intrinsic coupling from partition-created coupling.
-
Mechanism families
- Monitoring, delegation, hierarchy, contracts, standards, markets, sanctions, deliberation, and voting remain mechanisms attached to particular dependencies—not universal patterns.
Required additions
-
Roles separate from persons
- Roles need activation, reassignment, and deactivation.
- This permits role switching and avoids treating the formal organization chart as the current operating structure.
-
Authority as a triple
- Formal accountability
- Current decision authority
- Conditions under which authority migrates
A single “owner” field cannot represent either Incident Command’s explicit migration or NASA’s informal chain of command. Both place authority away from the formal chart; only one makes that displacement inspectable.
-
Bilateral interfaces
- Sender, receiver, transfer content, transfer instant, receiver obligation, accept/refuse response, and unresolved items must be explicit.
- An interface is not merely a data format.
-
Named shared state
- State should include provenance, uncertainty, assumptions, commitments, exceptions, and an accountable maintainer.
- The maintainer should be distinguishable from executors and from those rewarded by derived metrics.
-
Exceptions and response rights
- Detection tests belong to activities, connections, and pathways.
- A model should state which response is automatic, which is pre-authorized, and which requires escalation.
-
Typed decision, change, assurance, and waiver rights
- Ordinary decision rights do not imply constitutional amendment rights.
- Amendment rights do not imply waiver rights.
- Assurance independence must be representable as a constraint on who may alter or suspend the check.
-
Conditional constraints
- Rules must carry conditions of application rather than appearing as global invariants.
- This permits differentiated thresholds, bounded deviation, and retrospective review.
-
Specified versus enacted coordination
- Workarounds, shadow records, informal authority, and hidden repair should be representable rather than treated only as noise.
- The operating system is the specified system plus repair.
-
Coordination cost
- Time, cognitive load, transaction cost, role stress, hidden repair, delay, and exclusion should be modeled.
- Otherwise the architecture will prescribe coordination without accounting for its consumption of capacity.
-
Conditions of appropriateness
- A pattern should carry prerequisites and boundary conditions as first-class attributes.
- The recurring transplantation failure is that the visible artifact travels while training, trust, independence, local congruence, and response capacity do not.
Computational and AI compatibility
These requirements imply inspectability, not automation. A formal or computational representation could make authority, permissions, interfaces, exceptions, and change histories visible. Nothing in the evidence establishes that automating those functions is desirable, or that machine execution would preserve local judgment, informal resilience, legitimacy, or contestability.
Any computational implementation should therefore preserve:
- human authority and review;
- the ability to contest state and classifications;
- bounded exception rights;
- provenance and uncertainty;
- amendment and appeal paths;
- visibility into informal repair; and
- explicit accounting for coordination overhead.
The model should help people see how coordination operates. It should not assume that whatever can be represented should be automated.
10. Important uncertainties and unresolved questions
No incidence basis
The evidence cannot tell us that these thirteen loci account for a measured percentage of breakdowns. Structured accident-investigation corpora with consistently coded causal factors would be needed for a defensible incidence estimate. Even then, multi-causality would make simple rankings hazardous.
Instrumentation bias
Healthcare, aerospace, emergency response, and software are unusually well instrumented. Their investigators already look for handoffs, state, authority, and escalation failures. The recurrence of these loci may partly reflect what those domains know how to observe. Movement evidence reproduces many of the same loci and adds overcoordination, but one case does not eliminate the concern.
No complete pattern comparison
No pattern in this report has been evaluated as a complete configuration against an alternative configuration on a common outcome. Components have evidence; configurations mostly do not. The minimum language is therefore an evidence-qualified design agenda, not a demonstrated optimum.
Uneven domain coverage
Coalitions, movements, and collaborative public institutions have thinner causal evidence than healthcare, aerospace, emergency response, and software. Markets, prices, voting systems, and matrix organizations were not investigated deeply enough to treat them as patterns here.
Important missing practitioner tradition
Military mission command—especially bounded decentralized authority under commander’s intent—is a major mature tradition directly relevant to migratable authority and escalation, but it was not examined in the evidence base. Its absence materially limits the authority findings.
The active ingredient in handoff interventions remains unresolved
The contrast between successful intensive handoff programs and null mandatory checklist rollouts is compatible with several explanations:
- receiver obligation;
- local adaptation;
- training and observation;
- implementation intensity;
- baseline failure rates;
- measurement differences; or
- some combination.
The evidence does not isolate the mechanism.
Change-rights design has the highest leverage-to-evidence gap
Assurance independence is supported by three strong negative cases but no outcome study. It may prove central; it may also introduce rigidity, capture by assurance bodies, and unaccountable vetoes. Those are empirical questions.
Conclusion
The practical concentration in coordination breakdown is not a concentration of universal root causes. It is a concentration of places where coordination repeatedly becomes fragile: boundaries, shared state, authority, dependencies, exceptions, commitments, feedback, and the rules governing changes to those arrangements.
The corresponding design lesson is not “communicate more.” It is to make several distinctions explicit:
- transmission versus integration;
- authority versus accountability;
- detection versus escalation;
- operational state versus performance measurement;
- ordinary decisions versus change and waiver rights;
- productive autonomy versus unmanaged fragmentation;
- protective friction versus unnecessary dependency;
- resilience through informal repair versus concealment of recurring defects.
A minimum viable pattern language should therefore begin by removing avoidable dependencies and then establish bilateral interfaces, reliable shared state, conditional authority migration, built-in exception response, independently protected change rights, and accountable voice.
The most important unresolved proposition is also the most concrete: a coordination pattern cannot remain effective if the party it constrains can silently change, waive, or audit it. That proposition is strongly suggested by failure analysis and almost entirely untested as an intervention. It is the clearest place to begin the next empirical program.
References
Footnotes
-
The Joint Commission, Sentinel Event Data—Root Causes by Event Type, 2004–June 2013 and Sentinel Event Data 2024 Annual Review (2025), 2024 review; Richard I. Cook, “How Complex Systems Fail” (1998), https://how.complexsystems.fail/; Jacopo A. Baggio et al., “Explaining Success and Failure in the Commons: The Configural Nature of Ostrom’s Institutional Design Principles,” International Journal of the Commons 10, no. 2 (2016), DOI: 10.18352/ijc.634. ↩
-
Amy J. Starmer et al., “Changes in Medical Errors after Implementation of a Handoff Program,” New England Journal of Medicine 371 (2014): 1803–1812, DOI: 10.1056/NEJMsa1405556; David R. Urbach et al., “Introduction of Surgical Safety Checklists in Ontario, Canada,” New England Journal of Medicine 370 (2014): 1029–1038, DOI: 10.1056/NEJMsa1308261; Martin Müller et al., “Impact of the Communication and Patient Hand-Off Tool SBAR on Patient Safety: A Systematic Review,” BMJ Open 8 (2018), DOI: 10.1136/bmjopen-2018-022202. ↩
-
National Commission on Terrorist Attacks Upon the United States, The 9/11 Commission Report, ch. 9 (2004), https://9-11commission.gov/report/911Report_Ch9.htm; Columbia Accident Investigation Board, Report, Volume I (2003), NASA record; Li Lu, Y. Connie Yuan, and Poppy Lauretta McLeod, “Twenty-Five Years of Hidden Profiles in Group Decision Making: A Meta-Analysis,” Personality and Social Psychology Review 16, no. 1 (2012): 54–75, DOI: 10.1177/1088868311417243; Department of Veterans Affairs Office of Inspector General, Review of Alleged Patient Deaths, Patient Wait Times, and Scheduling Practices at the Phoenix VA Health Care System, Report 14-02603-267 (2014), PDF. ↩
-
Gregory A. Bigley and Karlene H. Roberts, “The Incident Command System: High-Reliability Organizing for Complex and Volatile Task Environments,” Academy of Management Journal 44, no. 6 (2001): 1281–1299, DOI: 10.5465/3069401; Jo Freeman, “The Tyranny of Structurelessness” (1970), https://www.jofreeman.com/joreen/tyranny.htm; Gary L. Downey, “Ideology and the Clamshell Identity: Organizational Dilemmas in the Anti-Nuclear Power Movement,” Social Problems 33, no. 5 (1986): 357–373, DOI: 10.2307/800656; Klodiana Lanaj et al., “The Double-Edged Sword of Decentralized Planning in Multiteam Systems,” Academy of Management Journal 56, no. 3 (2013): 735–757, DOI: 10.5465/amj.2011.0350; José A. McCord, John S. Patykewich, and Zinaida M. Mikhail, “Is Decentralization Good for Logistics Systems? Evidence on Essential Medicine Logistics in Ghana and Guatemala,” Health Policy and Planning 22, no. 2 (2007): 73–82, DOI: 10.1093/heapol/czl041. ↩
-
James D. Herbsleb and Audris Mockus, “An Empirical Study of Speed and Communication in Globally Distributed Software Development,” IEEE Transactions on Software Engineering 29, no. 6 (2003): 481–494, DOI: 10.1109/TSE.2003.1205177; Marcelo Cataldo, James D. Herbsleb, and Kathleen M. Carley, “Socio-Technical Congruence,” ESEM 2008, DOI: 10.1145/1414004.1414008; Alan MacCormack, Carliss Baldwin, and John Rusnak, “Exploring the Duality Between Product and Organizational Architectures,” Research Policy 41, no. 8 (2012): 1309–1324, DOI: 10.1016/j.respol.2012.04.011. ↩
-
Ken Hillman et al., “Introduction of the Medical Emergency Team System: A Cluster-Randomised Controlled Trial,” The Lancet 365, no. 9477 (2005): 2091–2097, DOI: 10.1016/S0140-6736(05)66733-5; Campbell et al., “A Multilevel Historiometric Analysis of Coordination Behaviors in Multiteam System Failures,” Group & Organization Management (2022), PMC8960246; Ross Koppel et al., “Workarounds to Barcode Medication Administration Systems,” Journal of the American Medical Informatics Association 15, no. 4 (2008): 408–423; Anita L. Tucker and Steven J. Spear, “Operational Failures and Interruptions in Hospital Nursing,” Health Services Research 41, no. 3 (2006): 643–662, DOI: 10.1111/j.1475-6773.2006.00502.x. ↩
-
Department of Veterans Affairs OIG, Phoenix VA Health Care System; Columbia Accident Investigation Board, Report, Volume I; Downey, “Ideology and the Clamshell Identity”; Nathaniel J. Smith and Donald Stufft, “PEP 8016—The Steering Council Model” (2018), https://peps.python.org/pep-8016/. ↩
-
Robert B. Davison et al., “Coordinated Action in Multiteam Systems,” Journal of Applied Psychology 97, no. 4 (2012): 808–824, DOI: 10.1037/a0026682; Campbell et al., “Multiteam System Failures”; Yuanmei Lan et al., “Benefits and Costs of Employee Boundary-Spanning Behavior: A Meta-Analytic Review,” Acta Psychologica Sinica 54, no. 6 (2022): 665–683, DOI: 10.3724/SP.J.1041.2022.00665. ↩
-
Michael Cox, Gwen Arnold, and Sergio Villamayor-Tomás, “A Review of Design Principles for Community-Based Natural Resource Management,” Ecology and Society 15, no. 4 (2010): 38, DOI: 10.5751/ES-03704-150438; Baggio et al., “Configural Nature”; Paul J. Ferraro and Arun Agrawal, “Synthesizing Evidence in Sustainability Science through Harmonized Experiments: Community Monitoring in Common Pool Resources,” PNAS 118, no. 29 (2021), DOI: 10.1073/pnas.2106489118. ↩
-
Department of Veterans Affairs OIG, Phoenix VA Health Care System; U.S. Department of Justice and FDIC OIG, “Wells Fargo Agrees to Pay $3 Billion to Resolve Criminal and Civil Investigations into Sales Practices” (2020), https://www.fdicoig.gov/news/investigations-press-releases/wells-fargo-agrees-pay-3-billion-resolve-criminal-and-civil; Monica Franco-Santos and David T. Otley, “Reviewing and Theorizing the Unintended Consequences of Performance Management Systems,” International Journal of Management Reviews 20, no. 3 (2018): 696–730, DOI: 10.1111/ijmr.12183. ↩
-
Downey, “Ideology and the Clamshell Identity.” ↩
-
Kaoru Sakai et al., “Improving the Safety of High-Concentration Potassium Chloride Injection,” BMJ Open Quality 8, no. 2 (2019), DOI: 10.1136/bmjoq-2019-000666; Sidney Dekker, “Failure to Adapt or Adaptations That Fail,” Applied Ergonomics 34, no. 3 (2003): 233–238, PMID 12737923. ↩
-
Chris Ansell and Alison Gash, “Collaborative Governance in Theory and Practice,” Journal of Public Administration Research and Theory 18, no. 4 (2008): 543–571, DOI: 10.1093/jopart/mum032; Katherine Casey, Rachel Glennerster, and Edward Miguel, “Reshaping Institutions: Evidence on Aid Impacts Using a Pre-Analysis Plan,” Quarterly Journal of Economics 127, no. 4 (2012): 1755–1812, DOI: 10.1093/qje/qje027. ↩
-
Guilherme Avelino et al., “On the Abandonment and Survival of Open Source Projects: An Empirical Investigation,” ESEM 2019, arXiv:1906.08058; SayedHassan Khatoonabadi et al., “On Wasted Contributions: Understanding the Dynamics of Contributor-Abandoned Pull Requests,” ACM Transactions on Software Engineering and Methodology 32, no. 1 (2023), DOI: 10.1145/3530785. ↩
-
Bigley and Roberts, “Incident Command System”; Dick A. Buck, Joseph E. Trainor, and Benigno E. Aguirre, “A Critical Evaluation of the Incident Command System and NIMS,” Journal of Homeland Security and Emergency Management 3, no. 3 (2006), DOI: 10.2202/1547-7355.1252; Donald P. Moynihan, “The Network Governance of Crisis Response,” Journal of Public Administration Research and Theory 19, no. 4 (2009): 895–915, DOI: 10.1093/jopart/mun033; Paria Bahrami et al., “Factors Affecting the Effectiveness of Hospital Incident Command System,” Bulletin of Emergency & Trauma 8, no. 2 (2020): 62–76, DOI: 10.30476/BEAT.2020.46445; Andrew Stribblehill and Kavita Guliani, “Managing Incidents,” in Site Reliability Engineering (2016), https://sre.google/sre-book/managing-incidents/. ↩
-
Amy C. Edmondson, “Speaking Up in the Operating Room,” Journal of Management Studies 40, no. 6 (2003): 1419–1452, DOI: 10.1111/1467-6486.00386; Columbia Accident Investigation Board, Report, Volume I. ↩
-
Thomas W. Malone and Kevin Crowston, “The Interdisciplinary Study of Coordination,” ACM Computing Surveys 26, no. 1 (1994): 87–119, DOI: 10.1145/174666.174668. ↩ ↩2