Y4.04.2Consequence-matched safeguard strengthdesign

How hard a safeguard should be to trigger depends on the consequence, its reversibility, and how fast it's noticed

Aliases: consequence-matched safeguard strength · hazardous energy control

What it is

Safeguard strength should be graded along three dimensions — the credible consequence if an inadvertent action occurs, whether that consequence is reversible, and how quickly it would be noticed afterward — rather than applying the same confirmation process to every action. A reversible, low-impact parameter adjustment should not bear the same friction as an irreversible energy release; conversely, a genuinely catastrophic command needs far more than a generic "are you sure" dialog.

Why it happens

A strong safeguard has a real cost — it consumes operating time, adds cognitive load, and under frequent repetition breeds an incentive to work around it (field staff propping open a cover or skipping a confirmation for efficiency). That cost is exactly why strong safeguards must be a scarce resource: only by concentrating them on the small set of actions with severe, hard-to-recover consequences does the safeguard's own signal — "this one is different, take extra care" — retain any meaning. Spread the same heavy safeguard evenly across every action, and operators quickly become desensitized to it, so it loses the warning value it was meant to provide. Layers of protection should also remain as independent as possible; if a second layer relies on exactly the same basis of judgment as the first, one misconception defeats both at once, and the "second layer" is really just a repeated display of the first, adding no real protection.

Where it stops holding

Severity is not the only dimension to weigh: a scenario with severe consequence but an extremely short response window (action required within seconds) can be made worse, not better, by a lengthy strong-safeguard process, leaving no time to complete every required step within the window that actually calls for action. Action frequency and the number of people a single inadvertent action could expose also shift the balance. More subtly, the same physical control can be a routine, low-risk action in maintenance mode and a catastrophic one in operating mode — safeguard level cannot be fixed to the control alone; it must also track which mode is currently active.

Applying it

Use formal hazard analysis to classify actions, and for each class specify explicitly the type of physical barrier, the specific independent-check requirement, the required authorization level, and whether interlock involvement is needed, recording the rationale behind each classification for later review.

  • If a given layer is found being routinely bypassed or temporarily disabled in the field, that is a signal to reexamine the task's own risk model and workflow — not an excuse to stack on another layer just as easy to bypass.
  • How to check: test the same control's false-activation rate, correct-completion rate under deliberate operation, and frequency of observed bypass separately in maintenance mode and in operating mode, to confirm safeguard level actually tracks consequence severity rather than staying fixed to the control type.

Related

  • Same group: Y4.04.1 Intent-discriminating safeguards · Y4.04.3 Verifiable safeguard state
  • Nearby: Y3.05 Inadvertent-operation protection · Y4.06 Safety integrity levels
  • Search terms: Consequence-matched safeguard strength · hazardous energy control · safety-critical work

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Y4.04.2