Control Without Controllability
Governance layers can paradoxically increase operational latency, taxing productivity by prioritizing surface legitimacy over systemic capability.
The meeting ends with a familiar promise. If we tighten the artifacts, the results will follow. If we copy the symptoms of good quality, we will have good quality. If we copy the characteristics of confidence, we will be confident. If we measure the characteristics with a score, leaders will become what the score says leaders should be. That belief is not only wrong. It is expensive. The piece is about causal blindness, the superstition that if we assemble the visible indicators of an outcome, the outcome will appear. It is the habit of treating symptoms as levers, then treating measurement as control. It is common in industry and it is common in society, because both prefer tidy proof to messy causality. The cost shows up as drift, latency, and the slow loss of control that firms mislabel as “execution.” “What would have to be true for this outcome to keep repeating.” That line sounds simple until you try to answer it without blaming the nearest person. It forces the enterprise to stop narrating what it can see and start tracing what is producing what it sees. It forces the room to admit that most symptoms are byproducts of the landscape of operation, not personal defects, not isolated events, and not proof that more process is needed. [CALLOUT] Symptoms are easy to copy. Causes are hard to face. [/CALLOUT]
The binder that passes, the line that fails
Causal blindness survives because it behaves like responsibility. It produces artifacts. It produces meetings. It produces owners. It produces a record. A record can be defended, and defense has career value. A record also creates the illusion of control, and illusion has emotional value when the system is already slipping. The deeper work is different. It does not begin with the artifact. It begins with the producer. It asks whether the design of the system makes the right behavior likely, even under pressure, and whether it makes the wrong behavior rational. It asks whether the decision rights are clear enough to let action happen without escalation. It asks whether feedback arrives fast enough to correct drift before drift becomes damage. It asks whether the enterprise has built a control system, or a compliance theater. This distinction is not philosophical. It is operational. If a plant is not capable, documentation can become a mask. If a supply chain is not stable, governance can become a brake. If a leadership culture cannot tolerate uncertainty spoken aloud, “confidence” becomes an act, then the act becomes a requirement, then the requirement becomes a score. Quality is the cleanest place to see the reversal because quality has always been tempted by the visible. The organization wants good quality, so it copies the symptoms of good quality. It builds the binders, the training, the posted standards, the audits, the gates, the sign offs. It does these
things because good plants often have them. The reasoning feels sound, and it is where the mistake begins. The presence of quality artifacts is often a signature of capability, not the cause of capability. In a truly capable system, the artifacts exist because the work is stable enough to describe, stable enough to train, stable enough to audit. The binder is evidence left behind by a system that holds. When the system does not hold, the binder becomes a substitute. The organization keeps producing paperwork while the process keeps producing variation, and the enterprise calls this maturity. The difference shows up on the floor, not in the binder. Capability is the ability to produce within specification repeatedly, under real variability, without heroics, without containment as a lifestyle. It is variation reduction, measurement integrity, maintenance discipline that prevents drift, supplier capability that does not inject surprise, scheduling that does not force shortcuts, and incentives that do not reward throughput at the expense of conformance. It is also permission, because a stop the line policy that cannot be used without penalty is not a control. It is a poster. There is a reason the old quality thinkers kept returning to prevention. They were not making a moral point. They were describing mechanism. Detection catches defects after the system already produced them. Prevention changes the producer so defects become less likely. The symptom superstition changes the surface and then expects the producer to comply. When someone says, “if we emulate the symptoms of good quality we will have good quality,” they are treating the signature as a lever. They are trying to reverse causality. They are trying to create capability by copying the artifacts that capable systems leave behind. The same reversal happens in the way firms talk about productivity decline. The enterprise sees the output of a slipping system, then responds by adding controls that make the output easier to explain. Those controls can reduce embarrassment in the short run. They can also increase latency in the only way that matters, which is the time between signal and action. That time is rarely called delay because delay sounds like failure. It is called governance, alignment, diligence, and risk control. Each word sounds responsible. The bill still arrives.
The map with arrows that refuses to be simplified
Your productivity map is the opposite of a list, and that is why it is useful. The top band names “Triggers and Controls.” The center band names “Operational Challenges.” A band below names “Mitigants.” The bottom band names “Challenges Resulting from Productivity Decline.” In the middle sits the outcome, the decline of manufacturing productivity, and the page is laced with arrows that refuse to respect org charts. The key lesson is not any single box. The key lesson is the density of linkage. A trigger pushes on the system, and the push does not stay local. A challenge amplifies another challenge. A mitigant reduces one failure mode and feeds another. Downstream consequences climb back
upstream as new constraints. The map looks like a storm system because that is how coupled operations behave. Most enterprises still want it to behave like a spreadsheet. They want each symptom to have an owner, each owner to have an initiative, each initiative to have a metric, and each metric to have a score that can be carried into a board packet. That structure produces comfort because it converts messy causality into tidy accountability. It also produces disappointment because it treats coupling as if it were optional. This is how causal blindness takes root in competent places. The firm can see the system is coupled, but it still acts as if the coupling can be managed through ownership assignments. Planning fixes planning. Quality fixes quality. Maintenance fixes maintenance. HR fixes turnover. IT fixes systems. Finance fixes cost. Each function takes the box it recognizes, then defends its box in meetings. The arrows do not care. The map also exposes a darker habit. “Mitigants” are often treated as virtues rather than as interventions. The enterprise adds controls, reviews, approvals, audits, gates, escalation protocols, and reporting cadence, then calls the added structure a mitigation. Sometimes it truly mitigates. Often it merely converts operational risk into latency, and latency into cost. When the enterprise cannot restore capability quickly, it often tries to restore the appearance of control quickly. Appearance is cheaper in the short run. It is also the path that makes long run recovery harder. [CALLOUT] A symptom map can become a catalog, and a catalog can become a substitute for control. [/CALLOUT] What the map demands is not more categorization. It demands causal discipline. It demands that the enterprise identify which nodes are signatures, which nodes are levers, which links are real, which links are directional, which links are delayed, and which links are reversible. Without that discipline, the firm will keep collecting symptoms the way people collect evidence bags, then wonder why the outcome does not change. The tragedy is that the firm often thinks it is doing systems thinking because it has a system diagram. A diagram is not a causal model. A causal model is a set of hypotheses that can be tested, audited, and revised. The difference between the two is the difference between narration and control. The map also makes a prediction without stating it. If a productivity decline is the product of many linked mechanisms, then local symptom corrections will leak. You will fix one box and another will swell. You will improve one measure and another will degrade. The system will route around the correction, then the enterprise will blame execution, then it will add more controls, and drift will continue with a cleaner surface. This is why the symptom superstition is dangerous in board rooms. It makes slow decline feel managed.
Confidence theater and the score that teaches people to lie
Causal blindness is not limited to factories. It shows up in the way people try to build inner states the way they build processes. The confidence example matters because it is the same mechanism in a different costume. A person wants confidence, so they copy the characteristics of confidence. Eye contact. Strong voice. Fast answers. No hedging. A posture that says certainty. They are taught that if they get the characteristics right, confidence will follow. Sometimes it works for a narrow moment, usually because the act reduces visible anxiety and helps the person stay in the task long enough to get real feedback. That is the counterexample, and it is real. Behavior can influence feeling. The superstition begins when the act is treated as the producer. Durable confidence is more often a byproduct of competence and evidence. It comes from mastery experiences, feedback that is accurate, and the repetition that teaches the nervous system what reality will allow. When those conditions are absent, copying the signature does not fix the producer. It can hide the instability. It can also increase brittleness because the energy goes into performance rather than learning. Now scale that mistake into leadership development, and the cost multiplies. Organizations love competency models because competency models create legibility. They turn an intangible quality into observable traits, then they score the traits. Leaders in confidence are some percentage complete. Leaders in confidence demonstrate certain characteristics. The model implies that leadership can be installed by compliance. The moment the score exists, it becomes an incentive. It travels into promotion decisions, succession planning, internal status, and reputational safety. The score becomes real because the enterprise treats it as real. The danger is not that leaders become more confident. The danger is that leaders become more performative, because the system now pays for the performance. A confidence score rewards the appearance of certainty. It rewards quick answers. It rewards dominance in rooms. It tends to punish the language that keeps organizations alive, which is the ability to say, without penalty, “I do not know yet,” followed by a plan to test, measure, and correct. When the enterprise punishes that sentence, it forces leaders to convert uncertainty into theater. The theater looks like control. It also increases latency because it delays the moment when truth is allowed to appear in the record. This is where leader and follower reinforcement becomes a mechanism, not a mood. Leaders learn what kind of certainty the system rewards. Followers learn what kind of truth the system punishes. Both groups participate in the same bargain. The enterprise gets a cleaner story, and it pays for the story later. There is a falsifiable prediction here, and it would be embarrassing if wrong. In any enterprise that ties leadership advancement to scored “confidence behaviors,” the time from first negative signal to acknowledged escalation will increase, and the first report will more often be framed as “under control” before reality proves otherwise. You can measure this without interpreting motives. Pull the timestamps on early defect signals, safety near misses, customer complaints,
and schedule risks. Compare them to the timestamp of the first formal escalation and the timestamp of the first material corrective action. Track the language of the early reports. If the confidence score is a real incentive, the record will show it. The prediction matters because it ties inner theater to outer cost. When early truth is delayed, the blast radius grows. When the blast radius grows, the enterprise spends more on containment and less on prevention. When prevention is underfunded, drift accelerates. The organization calls this bad luck. The ledger calls it a structural tax. [CALLOUT] When you score a posture, you get a posture, not the cause that produced it. [/CALLOUT]
The metric that eats the control system
It is tempting to treat this as a character flaw. It is not. It is a measurement problem and an incentive problem, which is to say it is a system problem. Once a measure becomes a target, people route behavior toward the target. That does not require bad intent. It requires bounded rationality and career survival. If a manager knows the next review will focus on the training completion percentage, the manager will complete the training. If a leader knows the next calibration will score confidence behaviors, the leader will perform confidence behaviors. If a plant knows the next audit will focus on whether the binder is current, the plant will keep the binder current. None of this is irrational. It is the system producing what it pays for. The tragedy is that these measures are often chosen because they correlate with the outcomes we want. Good plants do tend to have good documentation. Good leaders do tend to speak with composure. Stable operations do tend to have strong cadence. The enterprise then treats correlation as causation and tries to manufacture the outcome by manufacturing the proxy. That is causal blindness in its pure form. It is association treated as control. The productivity map makes this visible by separating “Triggers and Controls” from “Mitigants” and from “Operational Challenges.” The enterprise often confuses controls with mitigants, and mitigants with causes. It adds governance, and calls it control. It adds meetings, and calls them alignment. It adds reporting, and calls it visibility. The visibility can be real and still fail to produce action, because permission has not been delegated and latency has not been reduced. The cost of that failure is not abstract. Time between signal and action is a cash variable. If a defect signal is delayed, more product is produced wrong. If a reliability signal is delayed, more downtime is accumulated. If a schedule risk is delayed, more expedites are paid for. If a customer signal is delayed, more churn is baked in. The firm pays for time as if time were free, then it acts surprised when competitors buy the future with speed.
The symptom superstition also corrodes culture in a particular way. It teaches people that truth is what survives the meeting, not what reflects reality. That changes what people say. It changes what they record. It changes what they escalate. It changes what they fix. The enterprise becomes better at defense and worse at correction. This is why leaders and followers can reinforce the fallacy together. Leaders want clean surfaces because clean surfaces are safer. Followers provide clean surfaces because clean surfaces are rewarded. The system tightens the bargain by scoring the surface. Then it calls the surface a cause. What would have to be true for this outcome to keep repeating. The answer, in too many firms, is that the enterprise has built a machine that converts uncertainty into theater, theater into scores, scores into promotions, and promotions into more theater. Drift is the byproduct. [CALLOUT] If truth cannot travel fast, the system will pay for latency in cash. [/CALLOUT]
The questions that force causality into the record
A board can spot causal blindness without reading a single diagram if it listens for the wrong kind of certainty. In the operating review, when the same outcome repeats, do leaders talk as if the repeated outcome is a coincidence, or as if it is being produced. Do they ask why the metric moved, or do they ask what conditions made the move likely. Do they treat the artifact as evidence of control, or do they treat the artifact as evidence of attention. When an audit passes and the outcome still fails, does anyone ask whether the audit is checking the producer or only the signature. When confidence scores are high and bad news arrives late, does anyone ask what the scoring system taught people to do. When a mitigant is added and the system becomes slower, does anyone ask whether the mitigant reduced risk or merely converted risk into latency. A second set of questions matters because it ties directly to permission, which is where many systems die. When a negative signal appears on the floor, how many approvals does it require before the enterprise can act. Who can stop the line without penalty. Who can spend money on prevention without escalation. Who can change a schedule without a meeting. Who can tell the truth in the record without being punished for the truth. If the system requires escalation for every meaningful action, then action will be slow, and the enterprise will call the slowness governance. A third set of questions matters because it reveals drift. When a corrective action is announced, is the enterprise changing the producer or only the paperwork. Is it reducing variation or documenting variation. Is it improving measurement integrity or adding inspection. Is it building capability or adding controls. Is it reducing latency or adding cadence. Is it giving permission or adding sign off.
These questions are not rhetorical decoration. They are diagnostic. They force the enterprise to choose between two stories. One story says outcomes are the sum of the symptoms we can measure. The other says outcomes are produced by system design, and the symptoms are merely the record of what the design produces. The map with arrows is an accusation. It says the system is coupled. It says local fixes leak. It says control lives in the producer, not in the binder. There is a counterexample worth keeping honest. Sometimes symptom work does help. A checklist can prevent omission under stress. A cadence can coordinate a team that would otherwise fragment. A posture can steady a person long enough to perform and learn. Those are real mechanisms. They work when they change behavior in a way that changes results, and when they are paired with feedback that tightens the link between signal and action. The danger is taking that partial truth and turning it into a universal rule. The moment the enterprise believes the proxy is the cause, it begins funding theater. It begins selecting for performance. It begins measuring what is easy to count and calling counting control. It begins building a compliance machine that can pass audits while drift continues. That is the core misunderstanding in industry and in society. People treat symptoms as if they are building blocks. They treat leaders and followers as if they are independent causes rather than outputs of the systems that shape them. They assume that if they can get enough visible traits in place, the outcome will comply. It will not. [CALLOUT] A clean surface can hide drift, and drift always collects its payment. [/CALLOUT] The only enduring correction is causal sight, the habit of treating symptoms as evidence and treating system design as the intervention surface. That correction is slow at the start because it requires the enterprise to trade comfort for truth. It also becomes inevitable, because the firm that cannot reduce latency, cannot grant permission, and cannot arrest drift will eventually lose control in ways that no scorecard can explain. The last line the board should carry is not a program. It is a question, and it does not go away once you have learned to ask it. What is producing what we keep calling a surprise. References This piece draws on W. Edwards Deming’s work on systems, variation, and management responsibility in Out of the Crisis and his broader writing on why most persistent performance failures are system produced, on Walter A. Shewhart’s foundations for statistical control as the
boundary between capability and inspection theater, on Joseph Juran and Philip Crosby for the operational distinction between prevention and detection and the cost of confusing documentation with conformance, on Judea Pearl and Dana Mackenzie’s account of association versus intervention and why correlation cannot be reverse engineered into control, on Daniel Kahneman’s research on bounded rationality and the human habit of answering easier questions than causal ones, on Albert Bandura’s self efficacy theory for why durable confidence is typically a byproduct of competence and feedback rather than an installed posture, on Charles Goodhart and Donald Campbell for the distortion that follows when measures become targets under institutional pressure, on James Reason and Charles Perrow for why layered defenses and tightly coupled systems produce failures that look like individual error while being structurally likely, and on Michael Carroll’s own longform doctrine, including The Latency Tax and The One Degree World, for the operational link between permission, legitimacy, decision latency, drift, and whether a system can shape an outcome.