Chapter 17 distinguished procedural participation from substantive influence. Even when residents' opinions genuinely alter a plan, implementation still passes through budgeting, scheduling, procurement, data systems, and appeals. The people at each link may abide by their own rules, yet the final result still deviates from the shared goal. Collective failure is most easily obscured by two opposite stories: one story searches for a unified mastermind, while the other, because no one unified planned anything, declares that no one is responsible. The city retains the minimum night ferry, but the budget system cuts crewing according to average ridership, the contractor reduces maintenance as contracted, the dispatch software prioritizes punctuality, and customer service classifies denied boarding as individual lateness. Each department has local grounds, and no evidence shows that they jointly planned the exclusion of night-shift passengers; three months later, the night crossing nominally exists, its actual availability keeps declining, and the report still shows the participation commitment as fulfilled.
This chapter does not call every failure within a complex system an obedience machine, nor does it exempt deliberate concealment, benefit transfer, or retaliation from responsibility when the evidence is sufficient. What it aims to show is a harsher and more common possibility: without any central conspiracy, dispersed authority, information loss, metric adaptation, and cost transfer can stably produce the same adverse outcome; the organization may even use "everyone was merely following procedure" to protect this outcome. Critique must match responsibility to the nodes that are able to change things, rather than writing the structure as a subjectless fate.
Failures in Interfaces, Classification, and Hierarchy
The budget department controls expenditure, the contractor performs as agreed, the dispatcher pursues punctuality, and customer service handles cases by category; these goals sustain public services. The problem is not that local goals exist, but whether they jointly cover the original commitment, and who ranks them when they conflict. In the absence of an overall interface, reasonable goals push unaccounted losses to the edges of the system. Opposing local optimization does not require everyone to understand the entire system. Organizations should give key dependencies, conflicts, and anomalies a clearly designated receiver, so that the division of labor remains effective without becoming a division of responsibility.
Chapter 12 already traced how summarization deletes uncertainty level by level along the vertical reporting chain; this section attends to something else: how responsibility breaks apart when the same reduction occurs across organizational boundaries. A resident's explanation that late-night arrivals are affected by hospital shift changes is first compressed by the consultation meeting into a one-line lateness record, then enters the budget department's demand table, and finally lands in the average-passenger-count clause of the contractor's contract. The three handoffs belong to three mutually independent bodies, each compression had local justification at the time, yet no party believes that it rewrote the facts: the meeting took itself to be drafting minutes, the budget department took itself to be filling in a form, and the contractor took itself to be fulfilling a contract. The original consequence was not deleted by anyone; it evaporated between three individually lawful transcriptions.
The particular risk of cross-organizational handoffs is that reduction is often not automatically reversible. Once a contract is signed on average passenger counts, modification requires renegotiation; once the budget is locked in, revisiting the original objection requires first proving eligibility for exception. The point of reversibility therefore becomes a question of responsibility: who is obligated, at the handoff, to check whether the raw material is still sufficient for downstream reconsideration. A reasonable allocation is that the receiving party, before converting the material into binding form — a contract, a locked budget, a public metric — verifies whether high-risk exceptions are preserved, while the transmitting party states where compression occurred and where the original records are kept. Both obligations should be written into the handoff documents; otherwise every interface becomes a one-way valve that admits but never releases, and retrospective investigation can find only a string of people who all followed the rules.
Customer service can only issue refunds, so it understands denied boarding as a ticketing problem; the dispatcher has no authority to change the budget, so the structure of shifts goes unrecorded. Staff describe reality within the range they are able to change, and the system therefore sees only what it can process. Cross-department problems require an entry point that can receive without immediately reclassifying. Nor should the entry point become a new omnicompetent center. It is responsible for routing, aggregation, and escalation; the final decision remains with the authorized department, which bears it and records its reasons.
The budget declines on target, punctuality improves, case closure accelerates, and every department meets its marks; yet night-shift workers cannot reliably board the ferry. Metrics that are individually true do not suffice to show that the public goal has been realized. Overall evaluation should return to those whom the service serves, to basic functions, and to distributed consequences, checking whether there are costs transferred between local successes. Overall metrics can also obscure the local. Multi-level evaluation is not a constant increase in numbers, but letting each level answer only its own question, with a responsible subject present whenever they conflict.
Errors Can Become Invisible within Classification
The customer service system has only "lateness", "suspension", and "refund"; passengers cannot register "the boat ran but no usable assistance was available". Once the nearest category is chosen, statistics show the main problem to be personal lateness. Classification eases aggregation, but it rewrites experience the institution does not recognize into recognized objects. Open annotations and periodic review of unclassifiable material can reveal the boundary. A new category cannot be created for every individual case, otherwise information cannot be coordinated. Whether to add one depends on recurrence, harm, mechanism, and use in decision, together with an appropriate opportunity to reassign old records.
Those who fail to enter the system generate no tickets, and the reports read the blank as absence of demand. The absence may come from difficulty of access, exhaustion, digital exclusion, or the problem genuinely not existing. Active sampling, field observation, and different channels help distinguish among these, without deriving any single explanation directly from silence. Full coverage is likewise unrealistic. Institutions need to state the scope of observation and the unknowns, so that decision-makers cannot hide the invisible zone behind precise tables.
The "lateness" label enters the budget model, the performance reviews, and the public reports, and every later link cites the previous layer. Citation counts increase; independent evidence does not. Correction requires notifying the principal downstream parties and recalculating the affected decisions, not merely editing a customer-service note. A source graph can identify repeated consensus. Downstream parties need not re-investigate the original event every time. Return is warranted only when high-consequence or anomalous cases appear; ordinary matters may reasonably rely on qualified upstream sources, provided the dependency is visible and carries error notification.
Front-line staff choose the category, but the departments that design the options, train the rules, and use the data also participate in the outcome. An entry clerk who knowingly picks arbitrarily despite the mismatch may bear responsibility, but if the system offers no other entry, the main problem lies in design and management. Responsibility distributes with authority, knowledge, and replaceability; it does not all shift downward simply because the last person to click is the most visible. The purpose of accountability is not to find a scapegoat, but to match repair with those who can change the interface, the rules, the data, and the consequences.
Hierarchies Amplify Good News and Attenuate Bad News
Chapter 12 already showed why the vertical reporting chain rewards certainty and completion: sentences grow more certain as they ascend, and good news reaches the top more intact than bad. What this chapter adds is the horizontal counterpart: without any department lying, the overall success narrative is nonetheless stitched together from each department's true good news. The budget department reports spending falling on plan, dispatch reports punctuality improving, customer service reports closure times shortening, procurement reports contract compliance meeting standard; all four sentences are true, yet stitched together they yield "the night ferry commitment has been fulfilled" — a sentence no department ever said and for which no department is answerable. The stitching occurs at the aggregation layer of reporting: whoever combines four independent reports into one overall statement produces this sentence that exists nowhere else.
The concealment of stitching lies in its being addition rather than rewriting. The aggregator does not feel it is making a judgment, only compiling; yet choosing which on-target items enter the summary and omitting which mutual constraints — for instance, how canceled sailings raise punctuality, or how faster closure depends on pushing complex matters out of the system — is itself judgment. The overall evaluation layer therefore bears the responsibility of taking things apart: a synthesized statement must attach the scope and boundaries of each component, mark the dependencies and trade-offs among components, and state who answers for the claim of overall success. Where this cannot be done, the honest course is to report only the components and leave synthesis to the level authorized to rank values.
Management says "retain the night ferry within budget"; by the scheduling layer only "do not overspend" remains, and the priority of the service commitment has disappeared. Orders should carry the goal, the constraints, the handling of conflicts, and the conditions for escalation. Executors need not read the entire history of meetings, but they still need to know whom to report to when the incompatible strikes. Excessive detail in turn disables the front line from adapting. Limited discretion and feedback paths are more reliable than unlimited rules or complete freedom.
The dispatch supervisor must be punctual, frugal, and safe while refusing no one passage, yet has received neither additional resources nor ranking authority. Their choices are easily punished afterward against the unmet targets. When conflicting demands are not made public, the system induces surface compliance and concealed costs. The upper level must state priorities and exceptions and bear the trade-offs itself. The middle level may likewise exploit ambiguity to expand personal discretion. Decision records and cross-checking keep background pressure from serving as a license for arbitrary sanction.
That the responsible official did not see the night-shift problem is not necessarily personal indifference; the reporting chain may transmit only metrics. Those who hold power still bear the responsibility to build a structure that can receive bad news, especially when they have made public commitments on the strength of good news. "I did not know" must be followed by further questions: whether one should have known, whether one had the capacity to know, who blocked knowing. Facts impossible to know do not generate equal culpability, but refusing to change after discovering the blind spot raises it.
Outsourcing, Metrics, and the Allocation of Responsibility
The contractor can perform only by counts of sailings, staffing, and maintenance, and cannot bear complete transport equity. Contracts need limited objects, but the purchaser cannot transfer public responsibility away because deliverables meet standard. Values that could not be contracted remain the responsibility of the authorizing body, and enter through oversight, exceptions, and revision. Nor is the contractor a mere instrument. It holds field knowledge, should report evident risks, and cannot use contractual silence to exempt itself from foreseeable harm.
Budget pressure travels downward and field anomalies travel upward; each layer retains management overhead and strips information, while the personnel at the far end absorb the costs in time and safety. The result does not prove coordinated exploitation by all parties, but it shows that the structure distributes risk in a stable way. Publishing the chain, minimum labor conditions, and overall accountability can bound it. Actual contract law requires concrete verification. This chapter only establishes relations of responsibility and rules on no actual dispute.
A low bid may come from innovation, or from cutting training, redundancy, and handover. Procurement that looks only at short-term price selects risks that are difficult to observe immediately. Whole-life-cycle cost, anomaly reporting, and minimum standards improve matters, but may also raise the entry threshold, requiring that new suppliers be allowed to demonstrate capability in equivalent ways. Protecting quality must not become an excuse for incumbent contractors to exclude competition. Standards still need task evidence and review.
The contract states that the contractor bears responsibility; if it lacks the funds, the data, or the authority to repair, the clause merely leaves the failure with a shell. The purchaser must verify insurance, handover, data portability, and alternatives. That a punishable subject exists does not mean the public service has been restored. Conversely, a government backstop must not leave the contractor without consequences. Recovery, remediation, and service continuity are handled separately, so that the public does not wait out the liability dispute.
Metrics Induce Rational Adaptation in What Is Measured
The dispatch system excludes canceled sailings from the punctuality denominator, and the metric improves while service shrinks. The rule's designers may merely have carried over an industry convention, with no intent to deceive. Publishing the denominator, supplementing cancellation rates and subject-level outcomes, keeps one metric from monopolizing the result. Too many metrics add noise. The key is not to collect everything, but to keep the principal evasion paths and losses from having no place.
Customer service handles refunds first while structural accessibility problems are referred onward indefinitely, and average handling time falls. Staff make rational choices under performance pressure, yet no one owns the individual case. Complex cases need dedicated resources, a named responsible person, and a suspension of ordinary deadlines, so that difficulty does not become a reason for abandonment. Complexity does not mean unlimited processing. Staged response, referral, and stopping conditions protect both the service and the staff's available margin.
The night ferry receives less budget because complaints are few; service decline leads more people to give up using it, and low ridership in turn proves the cut justified. Forecast and resource form a self-confirming loop. Evaluation needs to record how the intervention changed its object and compare limited counterfactuals — a universal entry point, temporary support, or similar routes. Counterfactuals can never be fully observed, and conclusions should be proportionate in strength. Nor can one reason backward from the existence of feedback in the model to declare all low demand spurious.
Chapter 12 already pointed out that stand-in labor must be able to return to formal resources; otherwise the shadow process maintains the institution's facade. This chapter asks further: how is the executors' available margin itself to be seen, and how does it signal before exhaustion. Crew quietly assisting passengers, postponing breaks, covering shifts for absent colleagues — this labor appears on no work order; the metrics see punctuality and closure, not the net outflow of available margin. Measurement need not and should not become a new scorecard: let coordination and care enter the record in the lightest way — a one-minute subjective load notation at shift handover, a weekly team review of available margin — where the purpose of the record is to trigger a resource decision, not to assign the margin yet another score that will be optimized. Once the margin itself becomes a ranking metric, the most honest people learn to conceal exhaustion, and measurement reproduces the very distortion it was meant to prevent.
Rotation and formal takeover need a timetable, not a statement of principle. After how many consecutive episodes of substitution, covering how many shifts, the arrangement must convert to formal scheduling should be written down in advance; when the threshold is exceeded and no one takes over, what is triggered is a mandatory review at the budget level, not a word of thanks to the person who filled in. Early-warning signals of exhaustion should likewise be fixed in advance: the same group of people carrying nearly all the informal labor, substitution shifting from occasional occurrence to an implicit premise of scheduling, experienced crew suddenly taking leave or transferring out. These are not morale stories but harbingers of a resource gap about to become public. For the institution not to act when the signals appear is to choose that the gap will eventually be settled through service interruption or personnel exit; by the time responsibility is pursued then, the answer is already contained in each of the prior silences.
Joint Action Both Dilutes and Distributes Responsibility
Budgeters, contract designers, dispatchers, and customer service hold different authority at different nodes. Calling the failure collective responsibility without decomposition usually amounts to no one bearing it. A responsibility map should list who knew, who decided, who executed, who benefited, and who can remedy, assigning a subject to each repair. Systemic outcomes may exceed any single person's control; this calls for coordinated responsibility, not the dissolution of individual obligations.
The exclusion of the night shift may have accumulated from conventions and interfaces, with no one intending harm. The actual losses still require restoration, compensation, and rule changes. Degree of intent affects disciplinary sanction; it does not determine whether those affected are worth repair. Understanding responsibility only as moral condemnation lets organizations pass inspection on the strength of good intentions. No-fault arrangements may still require public risk sharing, because the institution chose and managed the service.
If someone deleted misrouted complaints knowing they were misclassified, or altered schedules as retaliation, structural complexity cannot exempt them. Investigation must preserve individual decisions and contemporaneous materials, preventing "systemic problem" from becoming a generalization that shields the highly authorized. Individual sanction likewise cannot replace repair of the metrics and the hierarchy that created the opportunity. Structure and intent are layers of explanation that can hold simultaneously; neither cancels the other.
That the contractor profits from reduced maintenance and that management gains repute from improved metrics warrant scrutiny; later benefit cannot by itself prove earlier conspiracy. Contracts, directives, concealment, and selective rules are what support stronger attribution. Even absent planning, excess gains and risk transfer can be addressed under fairness and institutional duty. Critiquing interested relations does not require writing the organization as a single person.
Joint Authorization and the Discovery of Error
When managers say that residents have already consented to retaining the minimum night ferry, they convert an implementation failure into a collective choice. What participants authorized was a direction, not every contract and scheduling detail. What was not delegated remains the responsibility of the administrative body; a single meeting cannot absorb unknown consequences. If a resident-proposed plan genuinely causes problems, it should likewise account for itself according to its information and authorization. Joint participation does not mean joint guilt.
Most passengers accept the cut; night-shift workers depend heavily on the service. The majority may authorize the direction of resources, but minimum service, proportionate alternatives, and review still protect the minority. Unadopted opinions should have their trigger conditions preserved, so that they can be returned to once outcomes appear. Nor may the minority freeze public budgets indefinitely on the strength of affected status. Facts, harm, alternatives, and authority decide together.
Once the project is named a "joint plan", staff find it harder to admit failure, as though critique equaled opposing the public. Joint commitment should raise the duty of explanation, not lower it. Published versions, anomalies, and revisions demonstrate that the institution can learn, without demanding the image of zero error.
All departments reflecting together, with expression, can repair relations; if no one changes the classification, the contracts, and the resources, shared bearing only leaves actual authority further invisible. Apology, sanction, compensation, and institutional reform serve different functions and should be verified separately. Publicly shaming the employee closest to the public likewise cannot substitute for upstream change.
Discovering Collective Failure Requires Crossing Organizational Boundaries
Placing the meeting commitment, the budget revision, the contract signing, the scheduling, and the complaints on a single timeline shows at which layer information vanished. Temporal proximity does not automatically prove causation; authority and materials must still be examined. The timeline offers a map of questions, not a chart of conspiracy. The timeline's own failure mode is being mistaken for a causal graph: a column of decisions arranged by date naturally suggests that sequence is influence, when what is actually sought is which decisions had already been made before the materials arrived. Cross-organizational aggregation has practical thresholds as well — different bodies retain records for different periods and in different formats; meeting minutes, contract versions, and scheduling tables are scattered in separate places; the timeline needs someone responsible for maintaining its version and stating which dates are inferred. Nor may it include only the nodes favorable to critique: the ridership warnings preceding the cut and the signs of improvement following it belong on the line equally, or the investigation itself becomes the selection of evidence.
Chapter 12 already showed that the same material repeated ten times does not become ten independent sources; the first task of the source graph is to draw exactly this: five reports claiming low demand, if all trace back to the same misclassified customer-service data, amount to a single independent confirmation. The common source may still be correct, but the strength of the conclusion should be recalculated at the sampling and classification layers rather than accumulated by report count. A single source graph only prevents mistaking echo for chorus; discovering collective failure usually requires the timeline, the source graph, the consequence graph, and the authority graph to be used in concert. The combination has its own failure modes: skipping the source graph and telling the story straight from the timeline comes closest to conspiracy narrative, because unchecked citation chains pave echoes into the appearance of collusion; using only the consequence graph without the authority graph leaves critique at accusation — the losses have witnesses but repair goes unclaimed; using only the authority graph without the consequence graph strips repair of priority, everything being listed as equally urgent; with all four graphs present but their blanks unlabeled, the investigation report becomes a new authoritative version. Graphs are investigative tools, not conclusion formats; each graph should state which lines remain undrawn and which materials are unobtainable, so that users know where the boundaries of the conclusion lie.
Budget savings enter the city ledger; waiting, lost work, and care enter households. Setting gains and losses side by side, local success no longer equals overall success. Not every experience can be monetized, yet subject, time, reversibility, and substitutes can still be described. The consequence graph's failure mode is treating non-monetizable items as nonexistent items: savings the ledger states to the decimal, and night-time waiting that can only be described, are naturally unequal on the same page; even set side by side, one must still explain why they cannot simply be subtracted. Loss material should not be extracted repeatedly and gratis from those affected — the same night-shift experience collected once each by consultation, audit, and investigation is itself a cost the consequence graph must record. The graph should clearly mark uncounted items and the scope of sourcing, so that readers know which losses are merely those no one has yet had the strength to report.
Customer service can change records, dispatch can arrange ad hoc sailings, procurement can amend contracts, and management can reallocate the budget. Demanding that errors be reported up level by level while no one holds pause authority renders discovery ineffective. Every high-consequence signal needs a receiver, temporary protection, and a final decision-maker. The authority graph's failure mode is copying the organizational chart: those with authority in title may never actually exercise it, while the position actually able to amend a contract annex or add an ad hoc sailing may be some unremarkable post in the middle tier. Authority also changes over time — budget windows, negotiation nodes, and review cycles open or close possibilities for action — so the authority graph needs to record exercise conditions and validity periods, maintained by a cross-department position. An authority graph drawn once and never updated leads repairers, like an expired map, to doors that no longer exist.
Why Repair Is More Than Adding Oversight
A newly created audit department that still reads the same metrics and summaries adds only a name. Independence lies in sources, authority, and the capacity to alter outcomes. External audit also has boundaries of knowledge and interest, requiring open methods and appeals.
Requiring more approvals to prevent error can lengthen services and scatter responsibility further. High-risk items receive stronger review while ordinary items retain discretion; process strength should be proportionate to consequence. Each added link should state what error it detects and who uses the result.
A unified data platform can reduce duplicate entry, and can also let errors travel faster across domains. Algorithms can flag anomalies; they cannot decide the weights of efficiency, equity, and safety. The final decision-maker must remain visible, and technology suppliers bear corresponding responsibility for the data and the known limitations.
Issuing new rules, completing training, and forming working groups are inputs. Whether the night ferry is reachable, whether misclassification can be corrected, whether stand-in labor declines, whether the minority retains an entry point — these show results. Absent improvement, the plan should be allowed to shrink, be replaced, or be terminated, rather than continue on the ground of what has already been invested.
Returning from Collective Failure to Correctable Collaboration
The riverside consortium links resident commitments, budgets, contracts, scheduling, and work orders into a responsibility map. Customer service adds an unclassifiable entry, so complex cases have a receiver; the dispatch's goal conflicts are ranked by the authorized party; the contractor reports field anomalies while the purchaser retains overall public responsibility; the scope of participatory opinion is no longer used to ratify unknown execution. Each link retains its professional division of labor while errors can travel back across the links. This arrangement will not discover every problem, and it does add coordination costs. Collective failure has no single center that could be thoroughly removed, because it arises from limited knowledge, local tasks, and dynamic adaptation. What institutions can do is preserve sources, clarify handovers, protect bad news, distribute pause authority, and let those with real authority repair once consequences appear. The timeline, source graph, consequence graph, and authority graph should not be investigative tools assembled only after incidents, but a standing minimum account maintained by a cross-department position; the same holds for the review of executors' available margin, whose value lies not in the record itself but in the budget level actually convening when a threshold is triggered.
The conclusion that no conspiracy is required does not soften the critique. A system can lack unified malice yet long impose losses on the same group; participants can be sincere yet jointly produce injustice out of obeying local rules. Conversely, structural explanation must not swallow deception and retaliation that the evidence already supports. Only when responsibility returns from overall moral labels to concrete authority does the critique neither manufacture enemies by imagination nor let procedure become a cage in which no one is responsible. The next chapter advances the fourth layer to the temporal boundary of standards, giving standards a validity period: when a rule was once reasonable, and the environment, the objects, and the consequences have since changed, who bears the responsibility of proving anew that it still applies.