A10.14.5Interlock defeat under excessive forcing-function loaddesignresearch

Stacking too many forcing functions drives skilled users to hunt for unconventional shortcuts

Aliases: interlock defeat · safety device bypass · workaround behavior

What it is

This entry is about a failure mode specific to forcing functions: when too many "impossible to proceed unless the precondition is met" mechanisms — lock-in, lockout, interlock — pile up in the same flow, for a user who's already thoroughly familiar with the whole operation and clear on where the real risk boundaries sit, these mechanisms stop being a gate that only catches a handful of genuinely dangerous situations and become a flat tax paid every single time. So they find a way to disable or route around the mechanism itself, rather than dutifully going through the full process each time. This is different from ordinary shortcut-taking for convenience: what's being bypassed here isn't some optional rule, it's the very physical or logical barrier meant to block a specific class of high-consequence failure — and once that barrier is disabled, it stops working for everyone, including whoever less experienced comes along afterward.

Why it happens

Forcing functions are typically calibrated around the least-skilled user in the system, the one who most needs protecting, which means that for a skilled user who can already reliably judge "this really is safe," most of what the mechanism blocks was never going to go wrong in the first place — its actual effect is close to nothing but slowing them down. When several such mechanisms stack in the same flow, a skilled user's friction cost accumulates layer by layer, while the extra protection they gain from it approaches zero. This mismatch between cost and benefit is the fundamental driver behind seeking a permanent bypass — physically disabling it, hard-coding a way to skip a step, sharing a trick that satisfies every precondition at once — rather than deciding case by case whether to comply: a case-by-case decision still has to be re-weighed every time, while a permanent bypass zeroes out the friction for good.

Studying it

This kind of failure is usually confirmed through physical inspection rather than interviews: checking equipment or a system for signs that a safety device has been physically removed, taped down to skip it, or had a software setting permanently changed to a bypass state. Such traces are themselves the most direct evidence, more reliable than asking operators afterward whether they've ever bypassed anything — operators often don't consider a bypass they use routinely to be "defeating a safety device" at all; to them it's simply become the normal way the job gets done. Another approach compares bypass rates for the same class of equipment across different levels of stacked friction — more layers of friction generally correlates with a higher bypass rate, and that correlation helps locate which flows sit in the high-risk zone.

Where it stops holding

This phenomenon only occurs under the premise that the mechanism has stopped meaningfully reducing real risk for skilled users. If a forcing function blocks a risk that still carries substantial probability even for the most skilled person — judgment can briefly fail under fatigue or distraction — the motivation to bypass it is much weaker, because skilled users themselves know the barrier still does something for them. Whether a given forcing function sits in a high-bypass-risk zone depends on the real residual probability of the failure mode it blocks within the skilled population, not on how skilled that population subjectively believes itself to be.

Applying it

Audit any scenario where multiple forcing functions stack in the same flow, and estimate each layer's true marginal protection for the experienced, reliably-judging portion of the user base. If several layers together add almost no further risk reduction for this group, consider offering verified, experienced users a lower-friction path that's still audited, rather than making everyone bear every layer indifferently. Don't treat a rise in bypass behavior as simply a discipline problem to be punished — punishment doesn't fix the underlying mismatch between friction and benefit. Verification: check the system or equipment for signs that a forcing function has been physically removed, that a software setting has been hard-coded to skip it, or that the flow is being systematically completed through some "back door" route. Any such trace means that mechanism has effectively stopped working for the population that has bypassed it, and calls for re-evaluating that layer's necessity and friction cost — not for tightening it further or escalating punishment.

Related

  • Same group: A10.14.1 forcing functions are implemented as lock-in, lockout, or interlock, each matching a different risk pattern · A10.14.2 software-level forcing functions can be bypassed by privileged users, physical ones usually can't
  • Nearby: A10.13 violations and deviation · A10.07 the Swiss cheese model · A11.04 novice-expert behavioral differences
  • Search terms: interlock defeat · safety device bypass · risk compensation

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/A10.14.5