From Aviation to Governance - A Methodology for Identifying Candidate Operational Invariants
ENGLISH
From Aviation to Governance
A Methodology for Identifying Candidate Operational Invariants
Wanhong Huang · huangwanhong@serendip.ngo
Abstract
The study of governance has concentrated on institutions, incentives, legitimacy, and the modes by which rule is exercised. It has attended far less to a different order of question: by what operational means any governing arrangement, whatever its institutional form, sustains reliable action when information is incomplete, conditions shift, and error is costly. This paper takes that operational order as its object and proposes a way to study it. Its instrument is a single mature domain, civil aviation, whose accumulated practice under uncertainty is unusually explicit; its aim is to extract from that domain what we call candidate operational invariants, operational functions that a governing arrangement may preserve across changes of scale, culture, organizational type, historical period, and the presence or absence of adversaries. The word invariant is used in its exact sense, as preservation under a specified group of transformations, and a candidate is admitted only with the transformations it is claimed to survive and the observations that would show it does not. The contribution is therefore a method, and the candidates are its worked output. Aviation furnishes the first application of that method; whether the candidates it yields survive beyond aviation is the question the method poses and the later work it invites, and it remains open here.
Keywords: governance; operational invariants; high-reliability organizations; renormalization; reliability under uncertainty; methodology.
A note on the standing of this paper. This is a methodology paper built on a single case. It takes one mature operational domain, aviation, and asks whether the functions it has developed for acting reliably under uncertainty can be extracted as candidates worth testing across governance more widely. The candidates offered here have the standing of hypotheses; each is stated together with the transformations it is claimed to survive and the observations that would falsify it. No cross-domain validation is performed, and none is claimed. Should the reliability literatures be shown already to contain the method proposed here, the paper loses its ground. Objection, correction, and counter-evidence are welcome at huangwanhong@serendip.ngo.
§1 Introduction
The study of governance is, for the most part, a study of institutions and their justification. It asks which arrangements of authority are legitimate, how incentives may be set so that self-interested actors produce tolerable collective outcomes, by what modes rule is exercised and contested, and how the resulting order is to be evaluated against standards of justice or efficiency. These are the right questions for much of what governance is, and the traditions that pose them are deep. They share, however, a common level of attention. They are concerned above all with the constitution of a governing arrangement, with what it is and by what right it stands; its conduct from one hour to the next, under conditions it did not choose, receives a lighter share of their attention.
There is a second order of question, less often posed in these terms, which concerns the operation of an arrangement, a matter lying beneath its constitution. Any body that governs anything, a state, a firm, a hospital, a household, an open-source project, must act on incomplete information, must continue to act as conditions change beneath it, must detect and absorb its own errors, and must do these things reliably enough that the arrangement persists. The means by which it does so are operational, and they lie at a level beneath the institutional. They include the estimation of a situation before a decision is taken upon it, the switching between ordinary and degraded modes of functioning, the maintenance of capacity in advance of its failure, and the conversion of failures into knowledge. These means cut across institutional forms. A hospital and a legislature differ at almost every institutional point, yet each must estimate its state before acting, and each must have some way of continuing to function when a part of it is impaired.
This paper is concerned with that second order of question, and with a difficulty peculiar to it. The operational functions just named are easy to observe in any single arrangement and hard to state in a way that is neither trivial nor false across arrangements. Stated concretely, they are the practices of a particular domain and belong to it. Stated abstractly, they slide toward truisms that no arrangement could fail to satisfy and that therefore explain nothing. The problem is to find, between the concrete practice and the empty abstraction, a level of description at which an operational function is both general enough to travel between domains and specific enough that a real governing arrangement could lack it. Finding that level, and defending the claim that a given function occupies it, is the methodological problem this paper takes up.
Our approach is to begin from a domain in which the operational order of governance is developed to an unusual degree and recorded with unusual explicitness. Civil aviation is such a domain. It has operated for a century under exactly the conditions that make operation difficult, namely uncertainty, irreversibility, and the high cost of error, and it has responded by developing an elaborate and documented body of operational practice, together with an institutionalized habit of learning from its failures. This makes aviation a convenient place to look. It does not make aviation a source of universal truths, and the paper is at pains not to treat it as one. The domain is used as an observatory, and what is observed there is offered as a hypothesis to be tested elsewhere, not as a law already established.
The central move of the paper is to name the object of that hypothesis precisely. We do not claim to identify the operational invariants of governance. We claim to identify candidate operational invariants, and the adjective carries the paper’s entire epistemic weight. An invariant, in the sense we take from physics and hold to throughout, is a quantity preserved under a specified group of transformations; the transformations are part of the claim, and a quantity said to be invariant without them is not yet making a claim at all. A candidate operational invariant is accordingly a function offered together with the transformations it is conjectured to survive, advanced so that the conjecture may be examined and, where it fails, refined or withdrawn. The difference between this and the assertion of invariants is the difference between a hypothesis and a result, and it is the difference on which the paper’s defensibility rests.
The contribution is therefore a method, of which the candidates are the worked output. The paper offers, first, a working notion of invariance that fixes both the transformations under which a candidate must be preserved and the conditions under which it must be rejected, so that the extraction of candidates has the power to discriminate among functions and does more than abstract from them. It offers, second, a worked application of that notion to aviation, in which a small number of candidate functions are extracted and each is put through the same test. It offers, third, the outline of a research program in which candidates extracted from one domain are carried to others and either survive or do not. What the paper does not offer is the outcome of that program. The candidates are left as candidates, and the work of validation is named as work, so that the ambition of the enterprise does not outrun the evidence a single case can bear.
The remainder proceeds as follows. §2 sets the operational question against the literatures that have already studied reliability under uncertainty, in order to mark both the debt this paper owes them and the point at which it departs. §3 develops the working notion of invariance, naming the group of transformations and the conditions of failure. §4 states why aviation is used and, more importantly, the limits of what a case so chosen can show. §5 carries out the extraction, running each candidate through the test of §3. §6 generalizes the procedure into a program for invariant discovery. §7 sets down the limits of the whole, and a short conclusion follows.
§2 The Operational Gap and Prior Art
The claim that governance theory has neglected the operational order must be made with care, because a substantial body of work has studied precisely how organizations act reliably under uncertainty, and this paper builds upon that work and leaves it standing. Three literatures are pertinent, and the paper’s relation to each is one of debt qualified by a specific departure.
The theory of high-reliability organizations grew from the observation that certain organizations operate hazardous technologies for long periods with remarkably few catastrophic failures, and asked what allows them to do so. LaPorte & Consolini (1991) set out the theoretical challenge such organizations pose to a social science accustomed to treating reliability as a by-product of structure, and Roberts (1990) characterized the features that distinguish one class of them. Weick et al. (1999) gave the tradition its sharpest early statement, locating reliability in a set of ongoing cognitive processes they named collective mindfulness: a preoccupation with failure that treats small anomalies as symptoms, a reluctance to simplify interpretations, a sensitivity to operations as they actually run, a commitment to resilience, and an underspecification of structures that lets decision migrate toward expertise under stress. Several of these processes reappear, renamed and rescoped, among the candidates of §5, and the debt is direct. Closest of all to the present concern is the study by Weick & Roberts (1993) of cognition on carrier flight decks, which treats reliable operation as a property of heedful interrelation among actors, a level above any single actor’s competence, and which reads, in effect, as an extraction of operational function from the same domain this paper uses.
What this literature did not do, because it was not its purpose, was to ask whether the processes it identified are invariant in any exact sense, or under what transformations they are preserved. It described the reliable organization and traced its habits with care; it left those habits attached to the organizational form in which they were observed. Collective mindfulness is offered as a characterization of a kind of organization, and the question this paper presses, namely whether a given process survives the passage to arrangements that are not organizations of that kind at all, to households, to states, to voluntary communities, and whether it survives the passage to settings where the parties do not share an end, is a question the tradition had no occasion to raise. The present paper takes the processes the tradition surfaced and asks of each the question the tradition left open.
Resilience engineering approached a neighboring question from the side of design. Hollnagel et al. (2006) and the tradition around them shifted attention from the prevention of failure to the maintenance of function under disturbance, treating the capacity of a system to adjust its functioning before, during, and after change as the proper object of study. This is close to the operational order named here, and the debt is direct. The difference, once more, is one of aim. Resilience engineering seeks to build systems that hold; the present paper seeks a method for deciding which of the functions such systems exhibit are invariant across domains, which is a question about the transportability of a function, one step removed from its realization in a given system.
Normal accident theory supplies the necessary counterweight. Perrow (1984) argued that in systems of sufficient interactive complexity and tight coupling, serious accidents are normal properties of the system, native to its structure, so that no accumulation of operational practice can render such systems safe. The lesson for this paper is cautionary, and it is taken seriously in §4. If some operational functions are defeated by the very structure of the systems they are meant to protect, then the invariance of a function cannot be inferred from its usefulness, and the failure conditions of §3 must have real teeth. Normal accident theory is, in effect, an argument that candidates can fail, and the method proposed here must be able to record such failures and let them stand.
The novelty claimed by this paper is accordingly narrow and, we think, defensible. The observation that aviation uses checklists, and the discovery that some organizations are reliable, both belong to the literatures just named, and the paper claims neither. Its own proposal is to treat operational functions as candidate invariants in the exact sense, to fix in advance the transformations under which they must be preserved and the conditions under which they must be abandoned, and to make the extraction and testing of such candidates a research program in its own right. The literatures above furnish the raw functions and the warning that functions can fail. The method for turning those functions into testable cross-domain claims is what this paper adds.
§3 A Working Notion of Invariance
Before extracting anything from aviation, we owe the reader an account of what would make a candidate deserve the word invariant, and of what would make one fail. Without such an account, extraction is not discovery. One may take almost any operational practice, describe its function at a sufficiently high level of abstraction, and arrive at a statement general enough to sound independent of its domain. The generality would then be an artifact of the phrasing, owing nothing to governance itself. This section fixes the criteria that prevent that outcome, and it fixes them before the case is examined, so that the case cannot be arranged to meet them.
3.1 Invariance as preservation under a transformation group
We take the word invariant from physics deliberately and keep its structure intact. In physics a quantity is never invariant in itself; it is invariant under a specified group of transformations, as a length is invariant under rotation, an interval under a change of reference frame, a critical exponent under coarse-graining. The transformation group is what gives the claim its content, for to say that a quantity is preserved is to invite the question, preserved under what, and a claim that cannot answer it asserts nothing testable. We therefore commit in advance to the transformations under which a candidate operational invariant must be preserved if it is to earn the name. A candidate is a claim of the form: this operational function survives transformation $T$. We propose five transformations as the working group for governance.
Scale. The passage from a small arrangement, a two-person cockpit or a household, to a large one, an agency or a state. A function that holds for the few and dissolves for the many is scale-dependent, and it fails under this transformation.
Culture. The passage across differing norms of authority, communication, and trust. A function that presupposes one culture’s relation to hierarchy has failed once the change to another culture removes it.
Organizational type. The passage across firms, states, non-governmental bodies, households, and voluntary communities. A cross-domain program principally tests this transformation, since it is the one under which surface implementation differs most.
Historical period. The passage across technological and institutional eras. A function tied to the tooling of one period belongs to that period as an implementation of it, and its survival across eras remains to be shown.
Adversariality. The passage from cooperative settings, in which the parties share an objective, to contested ones, in which their objectives conflict. This is the most demanding of the five, and, as §4 argues, the one that aviation is least equipped to probe.
A candidate may be of interest even where it survives only some of the five transformations, provided the discipline of the method is kept: we must always say which transformations it is claimed to survive and which lie beyond its reach. A function scoped to scale and historical period, with adversariality left outside its claim, is a sharper and more honest object than a function offered as invariant without qualification. The scoping is the content of the claim, and the claim gains its precision from it.
3.2 Functions, not implementations, under coarse-graining
The transformations of the working group apply to functions, leaving implementations aside, and the distinction is what a renormalization view contributes to the method. Coarse-graining, in the sense given to it by Kadanoff (1966) and Wilson (1971), asks whether a quantity survives when we cease to resolve fine detail and describe a system at a higher level. An aircraft checklist, a surgical timeout before an operation, and a household’s agreed plan for emergencies are not alike as practices, and no inspection of their surfaces would group them. They may nonetheless instantiate a single function that survives coarse-graining across all three, namely the external stabilization of correct execution when the cognition of the actor is degraded by stress, fatigue, or haste. The claim is never that the practice is universal, for checklists plainly are not; it is that the function the practice serves is preserved when the practice’s specific form is coarse-grained away.
This shifts the object of study from surface similarity to functional equivalence, which is at once the richer question and the harder one. It also imposes a burden on anyone who would advance a candidate. The candidate must be stated at the level of function from the outset, and its proponent must be able to say what the function is independently of any single realization of it. The sentence “checklists are invariant” is not a candidate, because it names an implementation. The sentence “the external stabilization of execution under degraded cognition is preserved under coarse-graining across implementations” is a candidate, because it names a function and specifies the operation, coarse-graining, under which the preservation is claimed.
3.3 Conditions of failure
A criterion that never rejects anything is not a criterion. If every practice observed in aviation yields a candidate, then extraction has no power to discriminate, and the paper collapses back into the abstraction it set out to avoid. We therefore state, in advance of the case, the conditions under which a proposed candidate is to be rejected or downgraded.
Implementation-boundness. The proposed function cannot be stated without reference to a mechanism specific to aviation, a particular instrument, regulation, or role. When this is so, what was offered as a function is in truth an implementation, and it has not survived coarse-graining.
Transformation failure. A plausible instance under one of the five transformations removes the function altogether, leaving nothing to re-implement. A function that vanishes the moment objectives become adversarial has failed under the adversariality transformation, and it must be rescoped to exclude that case or abandoned.
Vacuity. The function is stated so abstractly that every governing arrangement exhibits it, and no counterfactual arrangement, one that operates without the function and is the worse for the lack, can be described. A candidate that survives every transformation by saying nothing, in the manner of the sentence “governance involves acting,” is a definition wearing the dress of a finding.
These three conditions are what give the candidates of §5 the status of hypotheses. Each candidate is required to state both the transformations it claims to survive and the observation that would show it does not, and a candidate for which no such observation can be named is, by the third condition, refused admission.
§4 The Aviation Case and Its Scope
Aviation is used here as an observatory, and the choice needs both a justification and a boundary. The justification is that aviation has developed the operational order of reliable action further, and recorded it more explicitly, than almost any comparable domain. It has operated for a century under uncertainty and irreversibility, it codifies its procedures in a way that makes them available for inspection, and it has institutionalized the study of its own failures to a degree that few domains match. For the purpose of extracting operational functions and seeing them clearly, these are precisely the properties one wants. Aviation puts the operational order on the surface, where it can be read.
The boundary matters more than the justification, because it is where the paper’s honesty is tested. Aviation is not a neutral sample of governing arrangements. It is a domain that was deliberately and expensively engineered toward reliability across decades, and its operational order bears the marks of that engineering. Its characteristic failures are rare and catastrophic where those of other domains are frequent and diffuse; its components are tightly coupled; its operators are trained experts, selected and drilled for the role; and, decisively, its setting is cooperative. The parties in a cockpit, in an air traffic control system, and in a maintenance organization share an objective, the safe completion of flight, and their ends run together. Whatever operational functions aviation has developed have been developed under these conditions and are shaped by them.
Two consequences follow, and the paper accepts both. The first is that the candidates extracted from aviation will be biased toward the profile of the domain. They will be the operational functions of an engineered, tightly coupled, expert, cooperative system, and their apparent generality must be treated with suspicion exactly where the target arrangement departs from that profile. The second consequence fixes the scope of the paper’s claim. Aviation illuminates the reliability dimension of governance, the dimension concerned with sustaining correct action under uncertainty, and it is largely silent on the dimensions that much governance theory treats as central, namely the contest of conflicting interests and the exercise of power among parties who do not share an end. A candidate extracted here is, until shown otherwise, a candidate for the reliability dimension only.
This scoping belongs to the method as one of its working parts, and it connects directly to the adversariality transformation of §3 and to the caution of normal accident theory. Because aviation is cooperative, it cannot itself test whether a function survives the passage to adversarial settings; that transformation must be probed in domains aviation does not reach. And because, as Perrow (1984) argued, some systems defeat operational practice by their very structure, the usefulness of a function within aviation leaves its survival elsewhere an open question. The case is therefore strong for the work it is asked to do, the clear surfacing of candidates, and it stops short of the further work of establishing them. Holding those two roles apart is the discipline the rest of the paper tries to observe.
§5 Candidate Extraction from Aviation
This section applies the method of §3 to the case of §4. It is a demonstration of the procedure, standing at one remove from the substance of the paper’s claim; the candidates that follow are worked examples of extraction, offered so that the method may be seen to bite, and at least one is included because the failure conditions visibly strain it. Each candidate is set out in the same order: the aviation practice from which it is drawn, the operational function that practice serves, the candidate invariant stated at the level of function, the transformations it is conjectured to survive, and the observation that would show it does not.
5.1 State estimation before decision
The practice, in aviation, is the disciplined construction of a picture of the situation before a decision is taken upon it: the scan of instruments, the cross-check of one source against another, the explicit recognition that an instrument may be unreliable and must be confirmed against others. On a crewed flight deck this construction is distributed across actors who cross-check one another, and Weick & Roberts (1993) treat exactly this heedful mutual monitoring as the seat of reliable operation, which places the practice at the level of a small collective and not only of a single operator. The operational function is the separation of estimating the state of the world from acting upon it, so that action is taken against a representation that has been deliberately assembled. The candidate invariant, stated under coarse-graining, is that reliable governance requires an explicit stage of state estimation prior to optimization, held distinct from the choice of action and kept from collapsing into it. The transformations it is conjectured to survive are scale, culture, historical period, and organizational type; a household, a firm, and a public agency may each be said to estimate before deciding. Its survival under adversariality is doubtful and is left open, since where parties contest the state itself, estimation ceases to be a shared prior stage and becomes a move in the conflict. The observation that would falsify the candidate is a governing arrangement that reliably acts well with no separable estimation stage, folding assessment into action without loss; were such arrangements common, the separation would be one style among several, its claim to invariance lost.
5.2 Mode-switching between normal, degraded, and emergency operation
The practice is the maintenance of distinct operating modes with defined transitions between them, so that an aircraft is flown differently, by different procedures, when systems are normal, when they are impaired, and when an emergency is declared. The operational function is the replacement of a single universal decision procedure by a small set of regimes, each matched to a condition, with explicit criteria for passing between them. The candidate invariant is that reliable governance distinguishes operating modes and manages the transitions among them, in place of governing by one procedure across all conditions. The transformations it is conjectured to survive are scale, organizational type, and historical period; arrangements of many kinds carry some notion of ordinary functioning as against emergency functioning. Its survival under culture is only partial, since what counts as an emergency and who may declare it are culturally shaped, and this qualification is stated openly. The falsifying observation is a reliable arrangement that governs uniformly across radically different conditions and is no worse for it; were such arrangements ordinary, mode-switching would stand as an aviation habit, its claim to invariance withdrawn.
5.3 Externalized procedural memory
The practice is the checklist, and more broadly the placing of required steps in an external artifact, held outside the memory of the actor; the design of such artifacts is itself a studied subject, and Degani & Wiener (1993) document how much of a checklist’s reliability turns on details of its form, over and above its mere existence. The operational function, already used above as an illustration, is the external stabilization of correct execution when the actor’s cognition is degraded by stress, fatigue, load, or haste. The candidate invariant, under coarse-graining, is that reliable action under degraded cognition is supported by externalized procedural memory, whatever the form the artifact takes. The transformations it is conjectured to survive are broad: scale, culture, organizational type, and historical period all appear to leave the function intact, since the surgical timeout, the legal filing checklist, and the household emergency plan realize it differently while preserving it. This candidate is the strongest of the four on its face, and for that reason it is the one on which the vacuity condition must be pressed. The guard against vacuity is the counterfactual: there exist arrangements that rely wholly on the trained memory of expert individuals and that fail, distinctively, when those individuals are impaired, and the function names exactly the difference between such arrangements and those that externalize. Because that counterfactual can be described, the candidate is not vacuous; were it undescribable, the candidate would be a definition in disguise and would be withdrawn.
The breadth of the candidate’s claimed survival is itself a warning, and honesty requires that the warning be stated. A function that appears to pass four transformations at once may owe its success to the height of its phrasing, and the finding by Degani & Wiener (1993) that a checklist’s form governs its effect supplies the concrete danger: the coarse-grained function survives the passage across domains precisely where the fine detail that makes an artifact work does not. The candidate as stated is therefore true and thin. It holds that externalized procedural memory supports reliable action under degraded cognition, and it is silent on the conditions that divide a helpful externalization from a harmful one, which is where the operational content lives. This is a candidate that the method admits and then marks for refinement, since its survival across transformations has been bought, in part, by abstracting away the very features a later and narrower candidate would need to name.
5.4 Institutionalized post-event learning
The practice is the investigation of incidents and accidents as a matter of routine, conducted so that failures become inputs to revised procedure, with blame set to one side. The operational function is the conversion of failure into knowledge through a standing mechanism that operates whether or not any individual chooses to learn. The candidate invariant is that reliable governance institutionalizes learning from its failures, so that the conversion of failure into revised practice holds independently of individual will. The transformations it is conjectured to survive are scale, organizational type, and historical period. Its survival under adversariality is where the candidate strains most instructively, and the strain is worth stating plainly. In cooperative settings the investigation of failure is a shared good; in adversarial ones the record of failure is itself contested, since to establish what failed and why is to assign fault among parties who resist it, and the standing mechanism that aviation relies upon presupposes an authority to investigate that adversarial settings may lack. The candidate therefore appears to fail, or at least to require heavy rescoping, under the adversariality transformation, and by the honesty the method demands this stands on the page as a limit of the candidate. The falsifying observation, within the reliability dimension, is a durable arrangement that learns reliably from failure with no institutionalized mechanism at all, purely through the initiative of individuals; the candidate predicts that such arrangements are fragile across turnover, and evidence that they are not would tell against it.
5.5 The yield of the extraction
Four candidates have been drawn from aviation, and their standing is that of hypotheses, held short of the operational invariants of governance. They are offered to show that the method of §3 does real work. It forces each function to be stated independently of its aviation implementation; it requires each to declare the transformations it claims and to concede those it does not; and it has, on two of the four, produced strain of the kind a working criterion should produce. Institutionalized post-event learning visibly fails under adversariality, where the contest over the record of failure removes the shared authority the function presupposes. Externalized procedural memory shows the opposite pathology: it passes almost every transformation, and the very breadth of that success exposes it as pitched too high, true across domains at the cost of the fine detail in which its operational content resides, so that the method admits it and marks it for refinement. A set of candidates that passed cleanly and uniformly would be evidence that the criteria could not bite; the two strains are evidence that they can. The extraction has surfaced hypotheses with their falsifiers attached. Whether the hypotheses hold is a question for the program the next section describes.
§6 A Program for Invariant Discovery
The procedure carried out on aviation generalizes, and stating it as a general procedure is the paper’s principal contribution. The steps are five. First, one selects a mature domain in which the operational order of reliable action is highly developed and explicitly recorded, and extracts from it operational functions stated at the level of function, with their implementations set aside. Second, one states each function as a candidate invariant, attaching to it the transformations from the working group that it is conjectured to survive and those it is not. Third, one carries each candidate to domains that differ from the source under the transformations at issue, and observes whether the function survives the passage or is destroyed by it. Fourth, one refines the candidates that survive in altered form, rescopes those that fail under particular transformations, and withdraws those that fail generally or prove vacuous. Fifth, and only for candidates that have survived a range of transformations, one seeks a formal representation of the surviving function, so that it may be compared and composed with others with more precision than prose allows.
The posture of this program differs from the prevailing one in governance research, and the difference is the point. Much of that research proceeds by the proposal of frameworks, each internally coherent and each competing with the others for adoption, so that progress comes to be measured by the proliferation of frameworks, with the elimination of error left aside as a standard. The program proposed here measures progress differently. It advances by subjecting candidate functions to transformations that may destroy them, and it counts the destruction of a candidate as a result in its own right. Its aim is a slowly accumulating set of functions that have survived the attempt to break them, together with a record of exactly which transformations each has survived; a preferred model of governance lies outside that aim. Whether such a set can in fact be assembled is not settled by this paper. What this paper settles is the form the attempt should take, and the discipline, drawn from the exact meaning of invariance, that would let its candidates fail honestly.
§7 Limits of the Account
The account rests on claims that may be wrong, and setting them down as such belongs to the account. Its empirical base is a single domain, and a single domain of a particular profile at that; the candidates of §5 bear the marks of an engineered, cooperative, expert system, and their bias toward that profile is a property of the method’s starting point, native to it and carried forward from it. The low adversariality of the case is the sharpest of these limits, since it leaves the most demanding transformation of the working group essentially untested from within the paper, and the reliability dimension to which the paper scopes its claims is precisely the dimension least exposed to the contests of interest and power that occupy much of governance theory. The abstraction risk named at the outset persists to the end: generality can be manufactured by phrasing, and the failure conditions of §3 stand guard against that manufacture while falling short of a proof against it, a discipline whose force depends on being observed with care, its hold loosening the moment it is observed loosely. Finally, no validation is performed here. The candidates are carried nowhere; they are stated with their falsifiers and left standing, and the work of taking them into other domains, the work on which their status as invariants entirely depends, is named as the work this paper opens and does not do.
§8 Conclusion
Governance has an operational order that its dominant literatures, fixed on institutions and their justification, have tended to look past, and that order can be studied. This paper has proposed a way of studying it that borrows the exact meaning of invariance from physics, fixes in advance the transformations under which an operational function must be preserved and the conditions under which it must be abandoned, and uses a single mature domain as an observatory from which candidate functions may be drawn. Aviation has served as that observatory, and four candidates have been extracted from it, each stated at the level of function, each declaring the transformations it claims to survive, and one of them failing openly under the transformation it cannot meet. The candidates are not the paper’s contribution. The contribution is the method that produced them and that would, applied across further domains, either establish them as invariants of the reliability dimension of governance or break them. Which of these occurs is the question the method poses. Posing it so that the answer can go against the conjecture is what this paper has tried to do.
A note on method. The word invariant is used here in its exact sense, as preservation under a specified group of transformations, and it is kept clear of the loose honorific sense in which a thing is called invariant merely for being general or important. Where the paper cannot name the transformation under which a function is claimed to be preserved, it says so and lowers the claim accordingly. No formal representation of the candidates is attempted. Two honest presentations of the material are available: clear prose, and, in later work, a genuine connection to the language of dynamical systems, in which an operational function would answer to an invariant of the arrangement’s own dynamics with the exactness a figure of speech lacks. Only the first is claimed here.
References
Degani, Asaf, and Earl L. Wiener (1993). Cockpit Checklists: Concepts, Design, and Use. Human Factors, 35(2), 345–359.
Hollnagel, Erik, David D. Woods, and Nancy Leveson, eds. (2006). Resilience Engineering: Concepts and Precepts. Aldershot: Ashgate.
Kadanoff, Leo P. (1966). Scaling Laws for Ising Models near $T_c$. Physics Physique Fizika, 2(6), 263–272.
LaPorte, Todd R., and Paula M. Consolini (1991). Working in Practice but Not in Theory: Theoretical Challenges of “High-Reliability Organizations.” Journal of Public Administration Research and Theory, 1(1), 19–48.
Perrow, Charles (1984). Normal Accidents: Living with High-Risk Technologies. New York: Basic Books.
Roberts, Karlene H. (1990). Some Characteristics of One Type of High Reliability Organization. Organization Science, 1(2), 160–176.
Weick, Karl E., and Karlene H. Roberts (1993). Collective Mind in Organizations: Heedful Interrelating on Flight Decks. Administrative Science Quarterly, 38(3), 357–381.
Weick, Karl E., Kathleen M. Sutcliffe, and David Obstfeld (1999). Organizing for High Reliability: Processes of Collective Mindfulness. In B. M. Staw and R. S. Sutton, eds., Research in Organizational Behavior, 21, 81–123. Stanford: JAI Press.
Weick, Karl E., and Kathleen M. Sutcliffe (2001). Managing the Unexpected: Assuring High Performance in an Age of Complexity. San Francisco: Jossey-Bass.
Wilson, Kenneth G. (1971). Renormalization Group and Critical Phenomena. Physical Review B, 4(9), 3174–3183.
中文
从航空到治理
一种辨认候选操作不变量的方法论
黄万宏 · huangwanhong@serendip.ngo
摘要
治理研究一直集中于制度、激励、正当性,以及统治被行使所经由的诸模式。它远较少留意一个不同层次的问题:任何治理安排,无论其制度形式为何,凭什么操作性手段在信息不完整、条件变动且错误代价高昂时维系可靠的行动。本文把那个操作层次当作它的对象,并提出一种研究它的方式。它的工具是单一的一个成熟领域,即民用航空,其在不确定性之下累积的实践异常明确;它的目标是从那个领域中提取我们所称的候选操作不变量,即一个治理安排可能跨尺度、文化、组织类型、历史时期,以及对手之在场或缺席的诸变化而保存的操作功能。不变量这个词以它的精确意义被使用,即在一个被界定之变换群下的保存,而一个候选只连同它被声称经受住的诸变换、以及会显示它并未经受住的诸观察一道被接纳。因而这一贡献是一个方法,而这些候选是它实做的产出。航空提供那个方法的第一次应用;它所产出的候选是否在航空之外存续,是那个方法所提出的问题、也是它所邀请的后续工作,而它在此处保持悬而未决。
关键词: 治理;操作不变量;高可靠性组织;重整化;不确定性之下的可靠性;方法论。
关于本文定位的一则说明。 这是一篇建立在单一案例上的方法论论文。它取一个成熟的操作领域,即航空,并问它为在不确定性之下可靠行动而发展出的诸功能能否作为值得跨治理更广泛地检验的候选而被提取。此处所提供的诸候选具有假说的地位;每一个都连同它被声称经受住的诸变换、以及会证伪它的诸观察一道被陈述。没有跨领域的验证被执行,也没有任何验证被声称。倘若能证明可靠性诸文献已然含有此处所提议的方法,本文便失去它的立足之处。反对、更正与反证欢迎寄至 huangwanhong@serendip.ngo。
§1 引言
治理研究,大体上,是一种对制度及其辩护的研究。它问哪些权威安排是正当的、激励可如何被设定以使自利的行动者产生可容忍的集体结果、统治凭什么模式被行使与被争夺,以及由此产生的秩序要如何对照正义或效率的诸标准被评估。对于治理之为治理的许多东西,这些是正确的问题,而提出它们的诸传统是深厚的。然而它们共享一个共同的注意层次。它们首要地关切一个治理安排的构成,即它是什么、凭什么权利而立;它从一小时到下一小时、在它未曾选择的诸条件下的举止,受到它们较轻的一份注意。
有一个第二层次的问题,较少以这些术语被提出,它关乎一个安排的运作,一件躺在它构成之下的事。任何治理任何东西的机体,一个国家、一家公司、一所医院、一个家庭、一个开源项目,都必须在不完整的信息上行动、都必须在条件于它之下变化时继续行动、都必须侦测并吸收它自己的错误,且都必须足够可靠地做这些事以使那个安排持续。它做到这些所经由的诸手段是操作性的,而它们躺在一个制度之下的层次。它们包括在一个决定被作出于其上之前对一个情境的估计、在功能之寻常与降级诸模式之间的切换、在能力失效之前对它的维持,以及诸失败向知识的转化。这些手段横切诸制度形式。一所医院与一个立法机关在几乎每一个制度点上都不同,然而每一个都必须在行动之前估计它的状态,而每一个都必须有某种方式在它的一部分受损时继续运作。
本文关切那个第二层次的问题,以及一个它所特有的困难。方才所命名的诸操作功能,在任何单一安排中都易于观察,而以一种跨诸安排既非平凡也非虚假的方式陈述则难。具体地陈述,它们是一个特定领域的诸实践、并属于它。抽象地陈述,它们滑向没有任何安排会未能满足、因而什么也解释不了的老生常谈。那个问题是要在具体的实践与空洞的抽象之间,找到一个描述层次,在其上一个操作功能既足够一般以在诸领域之间行进、又足够具体以致一个真实的治理安排能缺它。找到那个层次、并为一个给定功能占据它这一主张辩护,是本文所接手的方法论问题。
我们的进路是从这样一个领域开始,在其中治理的操作层次被发展到一个不寻常的程度、并以一种不寻常的明确性被记录。民用航空是这样一个领域。它已在恰恰使运作困难的诸条件之下运作一个世纪,即不确定性、不可逆性,以及错误的高代价,而它以发展一套繁复且有记录的操作实践、连同一种从它的诸失败中学习的制度化习惯来回应。这使航空成为一个方便查看之处。它并不使航空成为普适真理的一个来源,而本文竭力不把它当作一个。这个领域被用作一座观象台,而在那里所观察到的东西,作为一个要在别处被检验的假说被提供,而非作为一个已被确立的定律。
本文的中心动作是精确地命名那个假说的对象。我们不声称辨认治理的诸操作不变量。我们声称辨认候选操作不变量,而那个形容词承载本文的全部认识论分量。一个不变量,在我们从物理学取来并通篇坚守的意义上,是一个在一个被界定之变换群下被保存的量;那些变换是那个主张的一部分,而一个被说成不变、却不带它们的量,尚未在作出任何主张。因而一个候选操作不变量是一个连同它被猜想经受住的诸变换一道被提供的功能,被推进以使那个猜想可被考察,并在它失败之处被精炼或被撤回。这同断言诸不变量之间的差别,是一个假说与一个结果之间的差别,而它正是本文的可辩护性所依据的那个差别。
因而这一贡献是一个方法,而这些候选是它实做的产出。本文提供,第一,一个不变性的工作概念,它既固定一个候选必须被保存于其下的诸变换、也固定它必须被拒绝于其下的诸条件,从而候选的提取有能力在诸功能之间辨别、并做多于从它们抽象出来的事。它提供,第二,那个概念对航空的一次实做应用,在其中少数几个候选功能被提取,而每一个都被通过同一个检验。它提供,第三,一个研究纲领的纲要,在其中从一个领域提取的候选被带到其他领域、并或存续或不存续。本文所不提供的,是那个纲领的结果。这些候选被留作候选,而验证的工作被命名为工作,从而这一事业的抱负不超出单一案例所能承受的证据。
其余部分如下推进。§2 把那个操作问题对照那些已然研究了不确定性之下之可靠性的诸文献放置,以标记本文既欠它们的债、也标记它背离的那一点。§3 发展那个不变性的工作概念,命名那个变换群与失败的诸条件。§4 陈述为什么航空被使用,以及更重要地,一个如此选取的案例所能显示之物的诸界限。§5 执行那次提取,把每一个候选跑过§3的检验。§6 把那个程序一般化为一个不变量发现的纲领。§7 放下整体的诸界限,而一个简短的结论随之而来。
§2 操作缺口与先前工作
治理理论已忽视操作层次这一主张必须被谨慎地作出,因为一大批工作已恰恰研究了诸组织如何在不确定性之下可靠地行动,而本文建立在那一工作之上、并使它立着。三个文献是相关的,而本文对每一个的关系都是一种被一个特定背离所限定的债。
高可靠性组织的理论从这一观察生长而来,即某些组织长时期地运作危险技术、而灾难性失败显著地少,并问什么容许它们如此做。拉波特与孔索利尼(1991)铺陈这样的组织对一门习惯于把可靠性当作结构之副产品的社会科学所提出的理论挑战,而罗伯茨(1990)刻画把它们中的一类区分开来的诸特征。韦克等人(1999)给了这一传统它最锐利的早期陈述,把可靠性定位在一组它们命名为集体正念的持续认知过程之中:一种把小反常当作症状来对待的、对失败的先占;一种不愿简化诸诠释;一种对如其实际运行之运作的敏感;一种对韧性的承诺;以及一种对诸结构的欠界定,它让决策在压力下向专长迁移。这些过程中的数个,被重新命名并重新界定范围,在§5的诸候选中重现,而这份债是直接的。同当下关切最接近的,是韦克与罗伯茨(1993)关于航母飞行甲板上认知的研究,它把可靠的运作当作诸行动者之间留心互联的一个性质、一个高于任何单一行动者之能力的层次,而它实际上读起来是从本文所使用的同一个领域提取操作功能。
这一文献所未曾做的,因为那不是它的目的,是问它所辨认的诸过程在任何精确的意义上是否不变、或在什么变换下被保存。它描述了那个可靠的组织、并谨慎地追踪它的诸习惯;它把那些习惯留作附着于它们被观察到于其中的那个组织形式。集体正念作为一种组织之一类的刻画被提供,而本文所施压的问题,即一个给定过程是否经受住到那些根本不是那一类之组织的诸安排的过渡,到家庭、到国家、到自愿共同体,以及它是否经受住到诸方并不共享一个目的之诸情境的过渡,是那个传统没有场合去提起的一个问题。当下这篇论文取那个传统所浮现的诸过程,并向每一个问那个传统所留下未决的问题。
韧性工程从设计一侧接近一个邻近的问题。霍尔纳格尔等人(2006)以及围绕他们的传统把注意力从失败的防止转到扰动之下功能的维持,把一个系统在变化之前、之中与之后调整其功能的能力当作研究的适当对象。这同此处所命名的操作层次接近,而这份债是直接的。那个差别,再一次,是一个目的的差别。韧性工程寻求建造持住的诸系统;当下这篇论文寻求一个方法,用以决定这样的系统所展现的诸功能中哪些是跨诸领域不变的,这是一个关于一个功能之可运输性的问题,同它在一个给定系统中的实现相隔一步。
常态事故理论供出那个必要的抗衡。佩罗(1984)论证在足够交互复杂且紧耦合的诸系统中,严重事故是那个系统的常态性质、是它结构所固有的,从而没有任何操作实践的累积能使这样的系统安全。对本文的教训是告诫性的,而它在§4中被认真对待。倘若某些操作功能被它们意在保护之系统的结构本身所击败,那么一个功能的不变性便无法从它的有用性推断出,而§3的失败诸条件必须有真正的牙齿。常态事故理论实际上是一个候选能失败的论证,而此处所提议的方法必须能记录这样的失败并让它们立着。
因而本文所声称的新颖性是狭窄的,而我们认为是可辩护的。航空使用检查单这一观察、以及某些组织是可靠的这一发现,都属于方才所命名的诸文献,而本文对二者都不主张。它自己的提议是把操作功能当作精确意义上的候选不变量、事先固定它们必须被保存于其下的诸变换与它们必须被放弃于其下的诸条件,并使这样的候选之提取与检验成为一个自成其类的研究纲领。上面的诸文献提供那些原始功能、以及功能能失败这一警告。把那些功能转成可检验之跨领域主张的方法,是本文所添加之物。
§3 一个不变性的工作概念
在从航空中提取任何东西之前,我们欠读者一个说明,关于什么会使一个候选配得上不变量这个词,以及关于什么会使一个候选失败。没有这样一个说明,提取便不是发现。人可以取几乎任何一个操作实践、在一个足够高的抽象层次上描述它的功能,并抵达一个足够一般以听起来独立于其领域的陈述。那个一般性于是会是措辞的一个人为产物,一无所欠于治理本身。本节固定防止那个结果的诸判据,而它在那个案例被考察之前固定它们,从而那个案例无法被安排成迎合它们。
3.1 不变性作为在一个变换群下的保存
我们刻意地从物理学取来不变量这个词、并使它的结构保持完好。在物理学中一个量从不自身不变;它是在一个被界定之变换群下不变,一如一个长度在旋转下不变、一个间隔在参照系的一个改变下不变、一个临界指数在粗粒化下不变。那个变换群正是给那个主张以内容之物,因为说一个量被保存,是招致这个问题,即在什么之下被保存,而一个无法回答它的主张什么可检验之物也没断言。因而我们事先承诺于一个候选操作不变量若要挣得那个名字便必须被保存于其下的诸变换。一个候选是一个形如这样的主张:这个操作功能经受住变换 $T$。我们提议五个变换作为治理的工作群。
尺度。 从一个小安排,一个两人驾驶舱或一个家庭,到一个大安排,一个机构或一个国家的过渡。一个对少数成立、而对多数消解的功能是尺度依赖的,而它在这一变换下失败。
文化。 跨权威、沟通与信任之不同规范的过渡。一个预设一种文化对层级之关系的功能,一旦到另一种文化的改变移除了它,便已失败。
组织类型。 跨公司、国家、非政府机体、家庭与自愿共同体的过渡。一个跨领域纲领主要检验这一变换,因为它是表层实现差异最大的那一个。
历史时期。 跨技术与制度诸时代的过渡。一个系于一个时期之工具的功能,作为它的一个实现而属于那个时期,而它跨诸时代的存续尚待被显示。
对抗性。 从合作情境,其中诸方共享一个目标,到争议情境,其中它们的诸目标冲突的过渡。这是五个中最苛求的,而且,如§4所论证,是航空最不具备条件去探查的那一个。
一个候选即便在它只经受住五个变换中的一些之处也可能有旨趣,只要那个方法的纪律被保持:我们必须总是说出它被声称经受住哪些变换、以及哪些躺在它可及范围之外。一个被限定范围到尺度与历史时期、而把对抗性留在它主张之外的功能,是一个比一个不加限定地作为不变而被提供之功能更锐利、更诚实的对象。那个范围限定是那个主张的内容,而那个主张从它获得它的精确。
3.2 是功能,而非实现,在粗粒化之下
那个工作群的诸变换应用于功能、把诸实现搁在一边,而这一区分是一个重整化视角对该方法所贡献之物。粗粒化,在卡达诺夫(1966)与威尔逊(1971)赋予它的意义上,问一个量在我们停止分辨精细细节、并在一个更高层次描述一个系统时是否存续。一张飞机检查单、一次手术之前的手术前暂停核对,以及一个家庭商定的应急计划,作为诸实践并不相像,而对它们表层的任何检视都不会把它们归为一组。它们尽管如此可能例示一个跨所有三者经受住粗粒化的单一功能,即当行动者的认知被压力、疲劳或匆忙所降级时对正确执行的外部稳定化。那个主张从不是那个实践是普适的,因为检查单显然不是;它是那个实践所服务的功能,在那个实践的具体形式被粗粒化掉时,被保存。
这把研究的对象从表层相似移到功能等价,这同时是那个更丰富的问题与那个更难的问题。它也对任何要推进一个候选的人施加一份负担。那个候选必须从一开始便在功能的层次被陈述,而它的支持者必须能独立于它的任何单一实现说出那个功能是什么。”检查单是不变的”这个句子不是一个候选,因为它命名一个实现。”在被降级的认知之下对执行的外部稳定化在跨诸实现的粗粒化之下被保存”这个句子是一个候选,因为它命名一个功能、并界定那个保存被声称于其下的操作,即粗粒化。
3.3 失败的诸条件
一个从不拒绝任何东西的判据不是一个判据。倘若在航空中观察到的每一个实践都产出一个候选,那么提取便没有辨别的能力,而本文便坍缩回它出发要避免的那个抽象。因而我们在那个案例之前陈述一个被提议的候选要被拒绝或被降级于其下的诸条件。
实现束缚性。 那个被提议的功能无法在不指涉一个航空所特有之机制、即一个特定仪器、法规或角色的情况下被陈述。当这如此时,作为一个功能被提供之物实际上是一个实现,而它未曾经受住粗粒化。
变换失败。 五个变换之一下的一个可信实例把那个功能完全移除,留下无物可重新实现。一个在诸目标变得对抗的那一刻消失的功能,在对抗性变换下已失败,而它必须被重新限定范围以排除那个情形、或被放弃。
空洞性。 那个功能被陈述得如此抽象,以致每一个治理安排都展现它,而没有任何反事实的安排,一个在没有那个功能的情况下运作、并因那一缺失而更糟的安排,能被描述。一个通过什么也不说而经受住每一个变换的候选,以”治理涉及行动”这个句子的方式,是一个穿着一个发现之外衣的定义。
这三个条件正是给§5的诸候选以假说之地位的东西。每一个候选都被要求既陈述它主张经受住的诸变换、也陈述会显示它并未经受住的那个观察,而一个无法为其命名任何这样一个观察的候选,按第三个条件,被拒绝接纳。
§4 航空案例及其范围
航空在此被用作一座观象台,而这一选择既需要一个辩护、也需要一条边界。那个辩护是,航空已把可靠行动的操作层次发展得比几乎任何可比领域都更远、并把它记录得更明确。它已在不确定性与不可逆性之下运作一个世纪、它以一种使它的诸程序可供检视的方式把它们编纂成典,而它已把对它自己诸失败的研究制度化到一个少数领域所匹敌的程度。为提取操作功能并清楚地看到它们这个目的,这些恰恰是人所想要的诸性质。航空把那个操作层次放在表面,在那里它能被读。
那条边界比那个辩护更要紧,因为它是本文的诚实被检验之处。航空不是治理诸安排的一个中性样本。它是一个跨数十年被刻意且昂贵地朝向可靠性工程化的领域,而它的操作层次带着那一工程化的诸印记。它特征性的诸失败是罕见且灾难性的,而其他领域的那些是频繁且弥散的;它的诸组件是紧耦合的;它的操作者是被训练的专家,为那个角色被选取并被操练;而且,决定性地,它的情境是合作的。一个驾驶舱、一个空中交通管制系统,以及一个维修组织中的诸方,共享一个目标,即飞行的安全完成,而它们的诸目的一道运行。航空所发展出的无论什么操作功能,都是在这些条件之下被发展的、并被它们所塑造。
两个后果随之而来,而本文接受两者。第一个是,从航空提取的诸候选将偏向那个领域的轮廓。它们将是一个被工程化的、紧耦合的、专家的、合作的系统的诸操作功能,而它们表面的一般性必须恰恰在那个目标安排背离那个轮廓之处被以怀疑对待。第二个后果固定本文主张的范围。航空照亮治理的可靠性维度,即关切在不确定性之下维系正确行动的那个维度,而它对许多治理理论当作核心来处理的诸维度,即诸冲突利益的争夺与不共享一个目的之诸方之间权力的行使,大体上沉默。此处提取的一个候选,直到别样被显示为止,是一个仅供可靠性维度的候选。
这一范围限定作为该方法的一个工作部件而属于它,而它直接连接到§3的对抗性变换、以及常态事故理论的告诫。因为航空是合作的,它自身无法检验一个功能是否经受住到对抗情境的过渡;那个变换必须在航空够不到的诸领域中被探查。而因为,如佩罗(1984)所论证,某些系统凭它们的结构本身击败操作实践,一个功能在航空之内的有用性,使它在别处的存续成为一个悬而未决的问题。因而该案例对它被要求做的工作,即候选的清晰浮现,是强的,而它止步于确立它们的那份进一步的工作。把那两个角色分开来是本文其余部分试图遵守的纪律。
§5 从航空提取候选
本节把§3的方法应用于§4的案例。它是那个程序的一次演示,站在与本文主张之实质相隔一步之处;随之而来的诸候选是提取的实做例子,被提供以使那个方法可被看到咬合,而至少有一个被纳入是因为那些失败条件可见地使它紧绷。每一个候选都以同一个次序被铺陈:它从中被抽取的那个航空实践、那个实践所服务的操作功能、在功能层次被陈述的那个候选不变量、它被猜想经受住的诸变换,以及会显示它并未经受住的那个观察。
5.1 决定之前的状态估计
那个实践,在航空中,是在一个决定被作出于其上之前对情境的一幅图像的有纪律构建:对仪器的扫视、一个来源对照另一个的交叉核对、对一个仪器可能不可靠且必须对照其他仪器被确认的明确认识。在一个有机组的飞行甲板上,这一构建被分布于彼此交叉核对的诸行动者,而韦克与罗伯茨(1993)恰恰把这一留心的相互监视当作可靠运作的所在,这把那个实践放在一个小集体的层次、而不仅仅是一个单一操作者的层次。那个操作功能是把估计世界的状态同作用于它分开,从而行动是对着一个已被刻意组装的表示被采取。那个候选不变量,在粗粒化之下被陈述,是可靠的治理要求一个先于优化的明确的状态估计阶段,同行动的选择保持有别、并被保持不坍缩进它。它被猜想经受住的诸变换是尺度、文化、历史时期与组织类型;一个家庭、一家公司与一个公共机构可各被说成在决定之前估计。它在对抗性下的存续是可疑的、并被留作悬而未决,因为在诸方争夺状态本身之处,估计不再是一个共享的先行阶段、而成为那个冲突中的一个动作。会证伪那个候选的观察是一个在没有一个可分开之估计阶段的情况下可靠地行动得好的治理安排,把评估折入行动而无损失;倘若这样的安排常见,那个分开便会是数种风格中的一种,它对不变性的主张丧失。
5.2 在正常、降级与紧急运作之间的模式切换
那个实践是对带它们之间被界定之诸过渡的诸不同运作模式的维持,从而一架飞机在系统正常时、在它们受损时,以及在一个紧急被宣告时,以不同的诸程序被以不同的方式驾驶。那个操作功能是以一小组制度替换一个单一的普适决策程序,每一个制度都匹配于一个条件,带在它们之间通过的明确判据。那个候选不变量是可靠的治理区分诸运作模式并管理它们之间的诸过渡,而非以一个程序跨所有条件治理。它被猜想经受住的诸变换是尺度、组织类型与历史时期;许多种类的诸安排都携带某种寻常功能相对于紧急功能的概念。它在文化下的存续只是部分的,因为什么算作一个紧急、以及谁可以宣告它,是被文化塑造的,而这一限定被公开地陈述。那个证伪观察是一个跨极其不同的诸条件均一地治理、并不因此更糟的可靠安排;倘若这样的安排寻常,模式切换便会作为一个航空习惯而立,它对不变性的主张被撤回。
5.3 外部化的程序性记忆
那个实践是检查单,而更宽泛地是把所要求的步骤置于一个外部人工物之中、被保持在行动者的记忆之外;这样的人工物的设计本身是一个被研究的主题,而德加尼与维纳(1993)记录一张检查单的可靠性有多少转在它形式的诸细节上、超出它的单纯存在之上。那个操作功能,上面已被用作一个例证,是当行动者的认知被压力、疲劳、负荷或匆忙所降级时对正确执行的外部稳定化。那个候选不变量,在粗粒化之下,是被降级之认知下的可靠行动被外部化的程序性记忆所支持,无论那个人工物采取什么形式。它被猜想经受住的诸变换是宽的:尺度、文化、组织类型与历史时期看来都使那个功能保持完好,因为手术前暂停核对、法律归档检查单,以及家庭应急计划,以不同方式实现它、同时保存它。这个候选表面上是四个中最强的,而正因这一缘由它是那个必须对之施压空洞性条件的那一个。防空洞性的守卫是那个反事实:存在完全依赖专家个体之被训练记忆、并在那些个体受损时独特地失败的诸安排,而那个功能恰恰命名这样的安排同那些外部化的安排之间的差别。因为那个反事实能被描述,那个候选不是空洞的;倘若它不可被描述,那个候选便会是一个伪装的定义、并会被撤回。
那个候选被声称之存续的宽度本身是一个警告,而诚实要求那个警告被陈述。一个看来同时通过四个变换的功能,可能把它的成功归于它措辞的高度,而德加尼与维纳(1993)关于一张检查单的形式支配它效果的发现,供出那个具体的危险:那个被粗粒化的功能恰恰在使一个人工物起作用的那个精细细节不经受住之处、经受住跨诸领域的过渡。因而如所陈述的那个候选是真的、且薄的。它主张外部化的程序性记忆支持被降级之认知下的可靠行动,而它对把一个有帮助的外部化同一个有害的外部化分开的诸条件沉默,而那正是操作内容所居之处。这是一个该方法接纳、然后标记为待精炼的候选,因为它跨诸变换的存续,部分地,是通过把一个日后且更狭窄的候选会需要命名的那些特征本身抽象掉而买来的。
5.4 制度化的事后学习
那个实践是把诸事件与诸事故的调查当作一件例行之事、如此进行以使诸失败成为对被修订之程序的诸输入,而把归咎搁在一边。那个操作功能是通过一个无论任何个体是否选择学习都运作的常设机制,把失败转化为知识。那个候选不变量是可靠的治理把从它诸失败中的学习制度化,从而失败向被修订之实践的转化独立于个体意志而成立。它被猜想经受住的诸变换是尺度、组织类型与历史时期。它在对抗性下的存续是那个候选最富教益地紧绷之处,而那个紧绷值得直白陈述。在合作情境中对失败的调查是一个共享的好处;在对抗情境中失败的记录本身被争议,因为确立什么失败了以及为什么,是在拒绝它的诸方之间指派过错,而航空所依赖的那个常设机制预设一个对抗情境可能缺的调查权威。因而那个候选看来失败、或至少要求沉重的重新限定范围,在对抗性变换下,而按该方法所要求的诚实,这作为那个候选的一个界限立在纸面上。那个证伪观察,在可靠性维度之内,是一个在根本没有任何制度化机制的情况下、纯粹通过个体的主动而可靠地从失败中学习的持久安排;那个候选预测这样的安排跨人员更替是脆弱的,而它们并非如此的证据会不利于它。
5.5 那次提取的产出
四个候选已从航空被抽取,而它们的地位是假说的地位,尚不及治理的诸操作不变量。它们被提供以显示§3的方法做真正的工作。它迫使每一个功能独立于它的航空实现被陈述;它要求每一个申报它所主张的诸变换、并承认它所不主张的那些;而它已在四个中的两个上产生一个工作判据应产生之种类的紧绷。制度化的事后学习可见地在对抗性下失败,在那里对失败之记录的争夺移除那个功能所预设的共享权威。外部化的程序性记忆显示相反的病态:它通过几乎每一个变换,而那一成功的宽度本身把它暴露为定得太高,跨诸领域为真、代价是它操作内容所居于其中的那个精细细节,从而该方法接纳它并标记它待精炼。一组干净且均一地通过的候选会是那些判据无法咬合的证据;那两个紧绷是它们能咬合的证据。那次提取已浮现出诸假说、连同它们的证伪者一道附着。那些假说是否成立,是供下一节所描述之纲领的一个问题。
§6 一个不变量发现的纲领
在航空上执行的那个程序一般化,而把它陈述为一个一般程序是本文的主要贡献。步骤有五。第一,人选取一个成熟领域,在其中可靠行动的操作层次被高度发展且被明确记录,并从它提取在功能层次被陈述、其诸实现被搁在一边的操作功能。第二,人把每一个功能陈述为一个候选不变量,把工作群中它被猜想经受住的诸变换与它所不经受住的那些附着于它。第三,人把每一个候选带到在争议之诸变换下有别于那个来源的诸领域,并观察那个功能是否经受住那个过渡、还是被它摧毁。第四,人精炼那些以被改变之形式存续的候选、重新限定那些在特定变换下失败的候选之范围,并撤回那些一般地失败或被证明空洞的候选。第五,且只对已经受住一系列变换的候选,人为那个存续的功能寻求一个形式表示,从而它可被以比散文所容许的更多精确同其他功能被比较与被复合。
这个纲领的姿态不同于治理研究中占主流的那个,而那个差别正是要点。那一研究的许多都通过诸框架的提议进行,每一个都内部融贯、每一个都同其他框架争夺采纳,从而进步渐渐被以诸框架的增殖来度量,而把错误的消除作为一个标准搁在一边。此处所提议的纲领以不同方式度量进步。它通过把候选功能置于可能摧毁它们的诸变换之下而推进,而它把一个候选的摧毁算作一个自成其类的结果。它的目标是一组缓慢累积的、已经受住破坏它们之尝试的功能,连同一个关于每一个恰恰经受住哪些变换的记录;一个受偏爱的治理模型躺在那个目标之外。这样一组是否事实上能被组装起来,不由本文了结。本文所了结的,是那个尝试应采取的形式,以及那份从不变性之精确意义中抽取的、会让它诸候选诚实地失败的纪律。
§7 该说明的诸界限
该说明依据可能是错的诸主张,而如此地把它们放下属于那个说明。它的经验基础是单一的一个领域,而且是一个特定轮廓的单一领域;§5的诸候选带着一个被工程化的、合作的、专家的系统的诸印记,而它们朝那个轮廓的偏向是那个方法之起点的一个性质,是它所固有的、并从它被向前携带。那个案例的低对抗性是这些界限中最锐利的,因为它使那个工作群中最苛求的变换从本文之内基本上未受检验,而本文把它诸主张限定范围于其上的那个可靠性维度,恰恰是最不暴露于占据许多治理理论的那些利益与权力之争夺的维度。开篇所命名的那个抽象风险持续到末尾:一般性能被措辞制造出来,而§3的失败诸条件对那一制造站岗、同时达不到一个针对它的证明,一种其力量取决于被谨慎地遵守的纪律,它的把持在它被松散地遵守的那一刻松脱。最后,此处没有执行任何验证。这些候选被带到无处;它们连同它们的证伪者一道被陈述并被留着立着,而把它们带入其他领域这份工作,即它们作为不变量的地位完全依据的那份工作,被命名为本文所开启而不做的工作。
§8 结论
治理有一个操作层次,它固着于制度及其辩护的诸主流文献倾向于看漏它,而那个层次能被研究。本文已提议一种研究它的方式,它从物理学借来不变性的精确意义、事先固定一个操作功能必须被保存于其下的诸变换与它必须被放弃于其下的诸条件,并把单一的一个成熟领域用作一座观象台,从其中候选功能可被抽取。航空已充当那座观象台,而四个候选已从它被提取,每一个都在功能层次被陈述、每一个都申报它主张经受住的诸变换,而它们中的一个在它无法满足的那个变换下公开地失败。这些候选不是本文的贡献。那个贡献是产生它们的那个方法,而它会,被应用于更多的领域,或把它们确立为治理之可靠性维度的诸不变量、或打破它们。这些中的哪一个发生,是那个方法所提出的问题。把它提出得使那个答案能与那个猜想相悖,是本文所试图做的。
关于方法的一则说明。 不变量这个词在此以它的精确意义被使用,即在一个被界定之变换群下的保存,而它被保持清楚于那个松散的敬称意义之外,在那个意义中一样东西仅因是一般的或重要的便被称为不变。在本文无法命名一个功能被声称被保存于其下之变换之处,它如此说、并相应地降低那个主张。没有那些候选的形式表示被尝试。该材料的两种诚实呈现是可得的:清晰的散文,以及,在日后的工作中,一个到动力系统之语言的真正连接,在其中一个操作功能会以一个修辞格所缺的精确答对那个安排自身动力学的一个不变量。此处只有第一种被主张。
参考文献
Degani, Asaf, and Earl L. Wiener (1993). Cockpit Checklists: Concepts, Design, and Use. Human Factors, 35(2), 345–359.
Hollnagel, Erik, David D. Woods, and Nancy Leveson, eds. (2006). Resilience Engineering: Concepts and Precepts. Aldershot: Ashgate.
Kadanoff, Leo P. (1966). Scaling Laws for Ising Models near $T_c$. Physics Physique Fizika, 2(6), 263–272.
LaPorte, Todd R., and Paula M. Consolini (1991). Working in Practice but Not in Theory: Theoretical Challenges of “High-Reliability Organizations.” Journal of Public Administration Research and Theory, 1(1), 19–48.
Perrow, Charles (1984). Normal Accidents: Living with High-Risk Technologies. New York: Basic Books.
Roberts, Karlene H. (1990). Some Characteristics of One Type of High Reliability Organization. Organization Science, 1(2), 160–176.
Weick, Karl E., and Karlene H. Roberts (1993). Collective Mind in Organizations: Heedful Interrelating on Flight Decks. Administrative Science Quarterly, 38(3), 357–381.
Weick, Karl E., Kathleen M. Sutcliffe, and David Obstfeld (1999). Organizing for High Reliability: Processes of Collective Mindfulness. In B. M. Staw and R. S. Sutton, eds., Research in Organizational Behavior, 21, 81–123. Stanford: JAI Press.
Weick, Karl E., and Kathleen M. Sutcliffe (2001). Managing the Unexpected: Assuring High Performance in an Age of Complexity. San Francisco: Jossey-Bass.
Wilson, Kenneth G. (1971). Renormalization Group and Critical Phenomena. Physical Review B, 4(9), 3174–3183.