In which agility turns out to be a polite word for lost.
Forgetting as Governance
Every institution has rules whose origins have gone missing.
A required dropdown has one option left, and the option is Other. Somewhere a standing meeting outlives the project it was created to rescue. Purchases over five hundred dollars still need a second signature, a threshold set in 2020 and never revisited, because years ago something happened that nobody can now describe without beginning the story with "I think." The rule remains even as the story thins, and because no one can prove that the original danger has disappeared, following it feels safer than asking why it is still there.
Most of these structures began in a room shortly after something went wrong. Someone reconstructed the sequence of events. Someone else identified the point where another review, another approval, or another person paying attention might have changed the outcome. Then came the proposal: a tighter gate, a new check-in cadence, a standing committee that would meet every two weeks until further notice.
Further notice rarely arrives.
Nobody in the room is proposing anything unreasonable, which is what makes the accumulation difficult to challenge. Each addition points to something real: an error, an oversight, a moment when the system failed in front of people whose opinions mattered. Error can remain abstract, but embarrassment has witnesses, and institutions tend to remember the experience of being visibly unprepared more vividly than they remember the underlying mechanics of what went wrong.
The response to that embarrassment is usually structural. A new gate shows that the company has learned, and a recurring review keeps the lesson in view. The committee gives the risk a permanent address. The safeguard may prevent the same failure from happening again, but it also performs something immediately useful: it proves that the institution has taken the failure seriously. The result is scar tissue, a thickening at the site of the injury, useful at first and permanent by default.
Adding a step therefore reads as diligence, while removing one reads as exposure. The person proposing a new approval can point to the incident it might prevent. The person proposing its removal has to argue that the continuing cost of protection now exceeds the remaining risk, knowing that the cost is distributed across hundreds of slowed decisions while the next failure, should it occur, will be specific, memorable, and attached to the person who loosened the control.
I've sat in these rooms and watched the next layer get added. I've nodded because the logic was sound and because objecting would have required me to argue, while everyone was still angry or embarrassed, that the thing we were discussing did not justify everything we were preparing to build around it. Of course it justified a response. The harder question was whether it justified a permanent one, and I did not ask it. Proposing an expiration date while the wound is still fresh means volunteering to be the person who argued for less protection, and I wanted the meeting to end.
So the committee formed after one bad quarter becomes permanent. An approval step introduced during a compliance scare survives three leadership transitions. The risk log outlives the risk it was created to track, one row still marked Mitigated in a color nobody can explain. Each layer has a history, but most organizations maintain no usable history of the layer itself: who added it, which event justified it, what conditions it assumed, or what evidence would eventually allow it to be removed.
That missing history matters because every safeguard changes more than the process it appears to protect. A new approval centralizes discretion, and a reporting requirement narrows autonomy. Escalation paths turn certain people into permanent arbiters of decisions that once belonged elsewhere. Over time, the structure creates its own constituency: someone chairs the meeting, someone prepares the materials, someone gains authority from being the required signature. The meeting acquires a recurring invitation, which is the corporate equivalent of tenure. None of those people is especially likely to be rewarded for deciding that the organization no longer needs them in that role.
Reaction gradually hardens into identity. The company that added controls after a painful failure begins describing itself as disciplined, rigorous, or appropriately mature, and those descriptions may be accurate. They also make the structure harder to examine, because removing a review now sounds like an attack on rigor itself rather than a question about whether this particular review still earns the time and authority it consumes.
The opposite lesson hardens just as well. A company that once lost an opportunity through delay begins stripping away reviews, deferring documentation, and treating every request for coordination as evidence that bureaucracy is returning. Speed becomes the company's account of itself, and the workarounds created in its name acquire the same permanence as the committees and gates elsewhere. What differs is tempo, not structure. Cautious systems tend to decline gradually, through the erosion visible in exit interviews nobody reads and pipeline metrics that soften slowly enough to explain away. Fast ones tend to fail all at once, when a hidden dependency breaks or the person holding the undocumented knowledge leaves. Neither recognizes itself as miscalibrated. A cautious system looks like professionalism all the way down, right up until it cannot ship anything that matters.
Systems need memory. An organization that forgets every failure condemns itself to repeat them, often with the same people explaining afterward that the lesson had once been learned but was never written down. Memory gives experience somewhere to accumulate.
Memory also needs expiration. A safeguard created for a specific moment should carry some account of that moment with it: what happened, what the new structure was meant to prevent, who owns the structure now, and what would have to become true before the organization could safely reconsider it. Without that record, the incident fades while the response remains, leaving later employees to inherit the cost without access to the reasoning.
Almost no organization does this consistently. Incident reviews ask what should be added. Audit findings produce remediation plans. Leadership changes generate new cadences, new templates, and new decision rights. Far fewer processes arrive with a date on which someone must ask whether they still work, because an expiration clause can feel like doubt about the lesson at precisely the moment everyone is trying to demonstrate that the lesson has been learned.
The difficulty is that overcorrection rarely looks excessive one layer at a time. One more review may genuinely help. One more approval may catch the next mistake. One more escalation path may give an ignored risk the attention it deserves. The sincerity of each response is what allows the total structure to grow beyond anyone's design, because challenging the accumulation requires arguing against a series of decisions that remain individually defensible.
Years later, a new employee asks why the second signature is required, why the committee still meets, or why a report that nobody appears to use must be finished by Friday. The answer is usually some version of "because we always have," sometimes followed by a partial story about an incident whose details no longer matter enough for anyone to verify.
By then, the event has disappeared, the people who designed the safeguard have moved on, and the structure no longer looks like a reaction to a particular moment. It looks like the natural shape of the institution.
The scar has become anatomy.
Footnotes
The asymmetry survives contact with evidence. A control that prevents nothing leaves no record of the failures it did not cause, so its value can be asserted indefinitely without ever becoming measurable. A control that gets removed produces a clean before and after, and any subsequent failure will be read against the decision whether or not the two are related. Anyone weighing the positions is choosing between a benefit that is difficult to falsify and a risk that will be judged with the clarity of hindsight.
Engineers have language for technical debt because it can be inspected in code, traced through version history, and connected to the decisions that produced it. Process debt lives in meeting structures, approval flows, templates, and informal norms that often accumulate without any comparable record. By the time someone notices the weight, reconstructing the origin of every layer requires more institutional archaeology than most companies can justify, so the layers remain.
The cautious company looks at the fast company's collapse and sees recklessness. The fast company looks at the cautious company's stagnation and sees timidity. Both readings can be accurate, and neither requires the observer to ask which old wound its own system is still organized around. This is one reason institutions rarely learn from each other's failures: the lesson on offer is usually about the other company's visible behavior, while the history that made the behavior seem necessary stays hidden.
Some safeguards are foundational rather than episodic. Financial controls, security reviews, and safety protocols often exist because the downside risk remains structural even when no recent failure has occurred. The question is not whether every protection should expire, but whether a response calibrated to one moment should retain the same intensity after the moment has passed. Nobody watches for that expiration, because watching for it would require admitting that the original response was, in part, emotional.
| Published | 1 December 2024 (2 years ago) |
|---|---|
| Reading time | 8 min |
| Tags | standards, effectiveness |
| Constellation | The Scaffold |
Reply
I’d welcome your thoughts on this essay. Send me a note →

