Y6.05.3Fatigue risk work–rest limitsdesignresearch

Continuous work needs enforced rest limits

Aliases: work-rest limits · hours of service · fatigue risk management

What it is

Fatigue risk work–rest limits place non-negotiable boundaries on continuous duty length, the minimum recovery interval between shifts, and how far overtime can escalate. The point is to cut off exposure before capability becomes unreliable, not to assume everyone fails at the same hour on the clock. These limits are usually a core component of a fatigue risk management system (FRMS).

Why it happens

Fatigue-related risk does not rise linearly with hours on duty; past a certain point it accelerates sharply, closer to a steep curve than a straight line, so an extra hour late in a shift costs far more than an extra hour early on. The deeper mechanism is that fatigue accumulates across shifts: if the interval between shifts is too short to complete a full sleep cycle, fatigue carries forward as unpaid debt into the next shift, and after several such shifts the cumulative risk can exceed the safety margin even though every individual shift was compliant on duration. That is exactly why an enforced limit cannot be defined by single-shift length alone — a rule that only checks per-shift duration can be satisfied by a roster where every shift is legal but the interval between them never is.

Fatigued individuals also become worse judges of their own capability, the same dissociation seen in the circadian trough between felt state and actual performance, so relying on a person to call a halt when they "feel tired" leaves a real monitoring gap. Enforced limits shift the stopping decision away from an individual under production pressure and onto the scheduling system itself — at the cost of needing a separate plan for the new risk created when an emergency forces someone past the limit anyway, meaning the handover itself needs a predefined procedure.

Studying it

Field research relates duty hours, rest timing, and circadian phase to error rates on a target task, often using natural experiments around schedule changes plus repeated performance testing to see how errors move as continuous duty lengthens. More recent work uses biomathematical fatigue models that take sleep opportunity, continuous wake time, and circadian phase as inputs to produce a predicted fatigue-risk score for a specific roster, then checks that score against independently collected vigilance or error data.

Total hours worked alone is not an adequate variable; continuous wake time, actual sleep opportunity, task demands, and commute time all need to be included. Correlations between incident rates and duty length also cannot be converted directly into a precise causal threshold — incident reporting itself is incomplete and subject to attribution bias, so a specific numeric limit ends up being a policy decision that data inform rather than dictate.

Where it stops holding

The actual limit is set jointly by regulation, collective agreements, sector risk level, and emergency duties, so a universal number detached from those conditions is meaningless. Compliance on single-shift duration does not equal safety — if the recovery interval between shifts is chronically too short for a full sleep cycle, even short shifts can accumulate high risk. Conversely, reaching a limit does not license abandoning a plant that is still unsafe; there must be a predefined safe handover or safe-state procedure as the exit path. A short nap or a single mandated rest period cannot repay chronic accumulated sleep debt, which is why the numeric limit and the recovery arrangement have to be designed together rather than treated as one standalone figure.

Applying it

  • Have the scheduling system hard-check continuous duty length, inter-shift recovery interval, and consecutive days on duty within a rolling window together, arranging relief before any one boundary is approached rather than reacting after it is crossed.
  • For genuine emergencies that require exceeding the limit, require an independently authorized override with an accompanying risk assessment, mandatory compensatory rest afterward, and an audit trail — not a verbal call from an ordinary supervisor.
  • Validate against actual target-task performance, the frequency of overrides, and defects recorded during handovers, rather than nominal roster compliance alone; bucketing this data by recovery-interval length shows whether the system is actually controlling cumulative risk, not just the single-shift-duration figure.

Related

  • Same group: Y6.05.1 Vigilance systematically declines during night shifts · Y6.05.2 Shift rotation direction affects circadian adaptation · Y6.05.4 Interfaces should reduce nonessential load under fatigue
  • Nearby: Y1.07 Shift handover · Y7.04 Tension between production and safety
  • Search terms: fatigue risk management system · work-rest limits · hours of service

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Y6.05.3