Your Supply Chain Was Built on Borrowed Stability
Modern supply chains collapse when companies mistake borrowed stability for control, leaving firms helpless as global disruptions expose their fragile reliance on external conditions.
Global efficiency was real. The conditions that made it possible were never yours to control. The next advantage belongs to firms that can act before the operating window closes.
By Michael Carroll
Global Executive in Industrial Innovation and AI Research | LNS Research Fellow | Board Advisor
THREE TAKEAWAYS
At 7:12 on Monday morning, the bearing still has no confirmed ship date. The vessel carrying the container has been rerouted. A fertilizer quote expired overnight. The plant can run the schedule three different ways, and each version breaks a different promise.
Nobody on the call is careless. Procurement has called every approved supplier. Maintenance has checked the rebuild shelf and the repair houses. Operations has moved the sequence twice. Finance knows what early inventory will do to cash, and sales is already deciding which customer receives the first difficult call.
The room is not short of information. It has forecasts, alternatives, cost estimates, and people who understand the work. What it does not have is authority to move before the answer has become safe for everyone who can stop it. The operating window is closing while the organization is still proving that the window exists.
The shortage is not information. It is certainty. The enterprise has made certainty the price of permission.
The Spreadsheet Never Carried the Whole Bargain
The familiar explanation is that companies cut inventory too far, outsourced too much, and rewarded purchasing teams for a price that ignored exposure. That explanation is not wrong. Working capital improved. Asset-light models attracted capital. Redundancy looked like waste while routes stayed open and suppliers kept their dates.
It starts too late. By the time a buyer chose the supplier or finance challenged the buffer, the larger bargain had already been accepted. Insurance was available. Contracts were generally enforceable. Ports and railroads connected production to consumption. Geopolitical friction usually raised the cost of trade without stopping the movement of matter. Firms optimized inside those conditions, but they did not create them and could not guarantee them.
More than 80 percent of the volume of international trade in goods moves by sea. UN Trade and Development reported that rerouting pushed seaborne ton-miles up 5.9 percent in 2024, nearly three times the growth in cargo volume, while tonnage through the Suez Canal was still about 70 percent below 2023 levels in May 2025. The route did not disappear. The same cargo simply required more distance, more time, and more money.
The spreadsheet captured the invoice price. It did not capture the order that made the price possible. Global efficiency rested on a physical and institutional system that allowed distance, time, trust, and spare capacity to sit quietly in the background.
A supply chain is a trust architecture. Every handoff assumes that somebody will produce, inspect, insure, transport, receive, pay, and honor the rule that allows the next handoff to occur. When those assumptions hold, thin buffers and long specialization chains can produce extraordinary productivity. When they weaken, the same design returns as cash committed early, premium freight, missed promises, and customer confidence lost one difficult call at a time.
Globalization was not a management error. It created abundance on a scale isolated domestic systems could not have matched. Indiscriminate reshoring can destroy specialization, raise cost, and move concentration risk inside one border. A plant with one grid, one water source, and one critical supplier is not made resilient by geography.
Efficiency always has conditions. A company that cannot name them is not managing efficiency. It is borrowing stability from the outside world and keeping the debt off the balance sheet.
Figure 1. The hidden bargain beneath efficiency. External order allowed concentrated operating choices to appear safer than they were.
Forecasting Cannot Close the Distance
I have never run an operation that did not need a reasoned view of demand, capacity, inventory, cash, and customer commitments. Forecasting belongs in the work. It becomes dangerous only when leaders ask it to carry a burden that belongs to the operating system.
A forecast can sharpen judgment about what may happen. It cannot create supplier capacity, approve an alternate material, release emergency inventory, reroute a shipment, repair a machine, change a production sequence, or verify that an intervention improved the outcome. Those require authority, capability, and capacity in the place where the decision still has value.
The Federal Reserve Bank of New York built the Global Supply Chain Pressure Index because no single conventional measure captured transportation cost and manufacturing strain together. The index combines maritime and airfreight measures with delivery times, backlogs, and purchased stocks. It gives leaders a wider view of pressure moving through the system. It cannot tell one company which promise to protect or which lever it is allowed to pull before the customer leaves.
Most enterprises can see more than they could a decade ago. Forecasts update faster. Scenarios multiply. Dashboards refresh. The decision can still sit exactly where it sat before any of those tools existed.
The distance between signal and consequence has a path: event, detection, reasoning, permission, action, verification, stabilization, and learning. Time is spent at every handoff, and the clock does not pause because the next review is scheduled for Thursday. The bill appears as overtime, premium freight, rework, excess inventory, customer concessions, lost production, and margin that disappears without an income-statement line called decision latency.
Delay rarely calls itself delay. It arrives as diligence, alignment, risk review, escalation, or one more request for better data. Any one of those steps may be responsible. The sequence becomes irresponsible when it takes longer than the decision remains useful.
Automating the recommendation does not repair that architecture. Requiring review until nobody can be blamed for acting does not repair it either. One moves the answer faster into the same queue. The other turns the queue into the control system.
Visibility matters. It is not the same thing as control, and the difference is paid in the operating window.
Food Reveals the Whole Machine
I grew up on a farm in Ohio. We did not call it a supply chain, but we knew seed, fertilizer, diesel, parts, labor, weather, storage, and a working road had to arrive in the right order. We called it getting the crop in before daylight or weather took the decision away.
That physical truth is easy to lose when food is reduced to a commodity line. A harvest begins with soil, water, temperature, timing, pests, and disease, but it does not end there. Farmers commit seed, nutrients, fuel, labor, credit, and equipment months before anybody knows what the season will give back.
USDA identifies nitrogen, phosphate, and potash as essential nutrients for crops used for food, feed, fiber, and fuel. Nitrogen depends heavily on energy and industrial processing. Phosphate and potash depend on mines, chemical conversion, rail, ports, bulk transport, and a limited set of producing regions. USGS data shows that those mineral supplies remain concentrated. Trouble in energy, mining, sanctions, trade policy, rail, or port capacity can reach the field before the seed enters the ground.
Equipment creates another dependency. Planters, sprayers, combines, irrigation pumps, grain dryers, feed mills, and refrigeration systems are collections of bearings, hydraulic components, filters, tires, control units, sensors, software, and skilled repair. I have seen plants carry millions of dollars of inventory and still stop for a part that cost less than dinner. The price of the missing part did not own the economics. The operating window did.
A combine down during harvest is more than a maintenance event. It changes yield, cash, and what will be available later. The same logic continues after the field. Grain has to be dried, inspected, stored, moved, milled, or converted into feed. Protein requires feed, veterinary capacity, processing, and refrigeration. Not every product uses every stage, but the applicable chain must close before biological yield becomes available food.
Food is where a supply-chain failure becomes public legitimacy. People do not experience a network map. They experience the price, the empty place on the shelf, and whether the basic system still puts food on the table.
A society is not a factory, and people are not inventory. The comparison carries one lesson and should stop there. When several conditions must hold for an outcome to arrive, managing each condition separately does not mean the outcome is under control.
Figure 2. Food is a physical chain. A crop can survive the field and still fail before it becomes available food.
Begin With the Outcome
I have watched companies choose a control tower, a supplier program, a sourcing target, or an inventory policy before they agreed on the outcome the system had to protect. The forecast then made the initiative look disciplined. Good people can do all of that work well and still build the plan backward.
A plan that can survive volatility begins with the outcome and asks what must be true for that outcome to keep occurring. It names the conditions, tests how fragile they are, and separates what the enterprise controls from what it can influence and what it must treat as an externality.
The distinction is practical. A controllable condition can be changed through authorized action. An influence can be shaped through contracts, incentives, standards, relationships, or shared investment. An externality has to be observed, absorbed, hedged, or routed around. Another committee will not make weather, a chokepoint, or a foreign government governable.
An assumption can hide quietly in a presentation. A dependency needs an owner, a failure mode, a trigger, an intervention, and a date when somebody will test whether the response still works. That is where strategy stops being narrative and becomes architecture.
Probability still matters, but probability is not the decision. An essential condition that is fragile needs a different design from one that is useful and robust. Leaders can change the outcome, change the architecture so the condition is no longer essential, or buy an option that lets the condition fail without taking the enterprise with it.
A plan that requires a fragile condition to behave is a prayer with spreadsheets. Where I come from, the end of every prayer gets an Amen. The operating plan still needs another answer.
An Option Is Not Real Until It Can Be Used
The word resilience often triggers a purchasing response: larger warehouses, duplicate suppliers, domestic production, and inventory built against every imaginable disruption. Some of that may be justified. Much of it is an expensive way to avoid deciding which failures actually threaten the outcome.
Selective redundancy matters where the dependency map earns it. An alternate material specification may protect more value than a second warehouse. Repairable equipment may create more operating range than a spare machine. A contractual capacity reservation may matter more than another supplier name that has never made the product.
The more useful unit is the option. A buffer absorbs variation after it arrives. An option preserves the ability to act differently when the base plan stops working. Inventory, spare capacity, alternate routes, repair parts, modular design, approved substitutions, flexible contracts, trained people, tested playbooks, and pre-authorized decision rights buy different forms of operating range.
An option earns its cost only when it is tied to a defined failure mode. Its value depends on the outcome protected, the fragility of the dependency, the time required to activate the response, and the damage created by waiting. A second supplier that cannot meet the specification is not an option. Neither is inventory that cannot be released, capacity nobody can commit, or a contract that requires approval after the window closes.
Permission Has to Arrive Before the Event
Permission in advance is what makes an option executable. It defines the evidence, threshold, authority, boundary, capacity, escalation rule, and accountability before the event begins moving faster than the hierarchy. The design is usually ordinary: a freight threshold, an approved formula, repair authority, an inventory-release rule, customer-allocation logic, and a named owner responsible for closing the loop.
This is not permission without judgment. The boundary should tighten as the consequence becomes harder to reverse. A routing choice that can be undone may sit close to the work. A decision that can injure people, violate law, compromise quality, or transfer material risk across the enterprise needs broader perspective and a harder gate.
The same boundary applies to software agents. A fluent recommendation is still a recommendation. A system earns authority only when it is bounded, capable of doing the work, supplied with the capacity the work requires, and able to show what changed afterward. Otherwise the machine has accelerated analysis while the decision waits where it always waited.
Figure 3. The control loop has a clock. Intervention is not complete until the state is verified, stabilized, and used to improve the next decision.
The Board Owns the Gap
Boards and executive teams usually receive more detail about risk than they receive about response. Heat maps show likelihood and severity. Dashboards show indicators. Management presentations show mitigation activity. The material question is whether the enterprise can change the outcome before the risk becomes an invoice.
A board does not need to approve the freight move, alternate formula, maintenance repair, or inventory release. It needs evidence that authority, capability, capacity, controls, and verification exist where the decision has to be made.
Governance is not the accumulation of approvals. Financial controls do not require the board to authorize every transaction. They require defined authority, traceability, exception handling, and review. Operating decisions happen closer to physical consequence and lose value faster, which makes pre-designed boundaries more important, not less.
The goal is not the fastest decision. It is the fastest legitimate decision the evidence and consequence will support. Process compliance can coexist with outcome failure when the process is slower than the event. Oversight that cannot trace evidence through reasoning, permission, action, verification, stabilization, and learning is reviewing activity rather than governing control.
The Case for Waiting
The case for waiting
is stronger than most arguments about decision velocity admit. Global supply chains do adapt. Cargo reroutes. Prices pull capacity into production. Companies qualify new sources. Inventories eventually rebalance. The global network is not collapsing in one direction.
Moving authority closer to the event can also make a company act quickly and wrongly. A plant can protect its schedule while damaging enterprise cash, customer allocation, quality, safety, cybersecurity, or regulatory exposure. A local team can exercise an option that was sound when approved and dangerous after the context changed.
Redundancy carries its own bill. Multiple suppliers divide volume and bargaining power. Local capacity can cost more. Inventory can become obsolete. Alternate specifications can create quality risk. Buffers can hide poor process discipline and preserve a problem that should have been removed.
There are decisions where delay is not waste. It is prudence. Irreversible actions, and decisions that cross safety, legal, quality, cash, or enterprise-tradeoff thresholds, deserve a harder gate because the cost of being fast and wrong may exceed the cost of waiting.
If shorter decision latency produces more total harm than it prevents, the thesis fails. It also fails when options cost more than the exposure they protect, when the event could not reasonably have been detected or influenced, or when exercising the alternate simply moves a larger risk somewhere else.
That is why the design cannot be reduced to faster approval. Reversible, low-regret actions can be authorized close to the event. Harder decisions should escalate. The boundary needs evidence, an owner, an expiration date, and a record of consequence. Slow can be reckless. Speed can be reckless too.
Market adaptation does not settle the question for an individual firm. A route may recover after the selling season is gone. A commodity price may normalize after a farmer reduces application, a plant idles, or a customer moves. A network can be resilient in aggregate while one company fails because its alternative existed only on paper.
The useful comparison is concentration against executable option, and delay against legitimate action. Keep the specialization that creates value. Stop treating yesterday's smoothness as proof that tomorrow's dependency is safe.
The Claim Has to Survive the Clock
A claim about decision latency should be measured, not admired. Otherwise it becomes another management idea that sounds exact until the invoice arrives.
The next major supply disruption will probably be described first as a visibility problem. In many companies, the deeper avoidable loss will occur after the signal is visible and before action is authorized. The postmortem will find an alternate that was not approved, inventory that could not be released, capacity that nobody could commit, or a recommendation that no accountable owner was permitted to execute.
That prediction can be tested. For comparable disruptions, measure the time from verified signal to authorized action and the time required to exercise a qualified option. Then measure how many alternatives were technically and commercially usable inside the window, whether the intervention changed the intended state, what second-order harm it created, and how long stabilization took. Compare those measures with lost production, premium freight, working-capital expansion, missed commitments, and customer loss.
The thesis is wrong if firms with longer decision latency consistently perform better after exposure, option cost, and action quality are taken into account. It is wrong if the cost of mistaken intervention rises faster than the cost of waiting falls. It is also wrong if most consequential losses sit outside any practical ability to detect, hedge, absorb, influence, or act.
The test matters only if it changes the design. It should tell leaders where permission belongs, where it does not, which options cost more than the exposure they protect, and which risks have to be accepted rather than dressed up as manageable. A theory that cannot tell an enterprise where to stop is not an operating theory.
The point is not to prove this article right. It is to get the architecture right. I expect avoidable loss to track time to legitimate action more closely than time to detection, because visibility became abundant faster than enterprises learned how to use it.
The advantage will not belong simply to the company that saw the disruption first. It will belong to the company that had a real option, authority to use it while the window remained open, and evidence that the intervention changed the state that mattered.
What the Next Disruption Will Reveal
Every enterprise has already decided how much certainty it requires before action, even if nobody has written the decision down. The answer sits in approvals, specifications, contracts, thresholds, and the names of the people allowed to say yes. The next disruption will not wait for the company to debate that architecture. It will simply reveal it. Certainty may arrive after the decision is gone. The operating window will close on time.
References
I began with Peter Zeihan's The End of the World Is Just the Beginning, The Accidental Superpower, The Absent Superpower, and Disunited Nations, because those books press a useful question: how much of late twentieth-century globalization was a permanent economic condition, and how much was a constructed security, demographic, energy, and logistics order? I use that work as a frame, not as a forecast. The current maritime facts come from UN Trade and Development's Review of Maritime Transport 2025, while the Federal Reserve Bank of New York's Global Supply Chain Pressure Index and the related work of Gianluca Benigno, Julian di Giovanni, Jan Groen, and Adam Noble show what broad pressure indicators can reveal across freight costs, delivery times, backlogs, and purchased stocks. USDA Economic Research Service and the U.S. Geological Survey ground the food argument in the physical dependence of modern agriculture on nutrients, energy, mines, equipment, and transport. Judea Pearl supplies the necessary distinction among association, intervention, and counterfactual reasoning. W. Edwards Deming, Eliyahu Goldratt, Karl Weick and Kathleen Sutcliffe, Donella Meadows, and Peter Senge shaped the treatment of variation, constraints, reliability, feedback, and stabilization. Douglass North and Elinor Ostrom help explain why rules, permission, and legitimacy belong inside the operating system, and Nassim Nicholas Taleb sharpens the case for options when prediction is weakest. The governance boundary is consistent with NIST's AI Risk Management Framework, but no single source supplies the operating conclusion. That conclusion extends my own field work and published writing on Decision Latency, Permission in Advance, One-Degree Architecture, causal options, inspectable chains of reasoning, and the Automated Scientist, including The Line Item Every CEO Pretends Not to See, The Architecture of Permission No One Admits They Are Running, Most AI Agents Don't Change Outcomes, The Failure That Starts Before the Breach, and The Margin Was Spent Before the Month Closed.
agentic-authority, permission-in-advance, outcome-ownershipOpen in the Radiant ↗All dispatches