Skip to main content
Transformidy

Article

How a Warning Becomes Wallpaper

Early risk signals rarely fail loudly. They get explained away one at a time, this instance was a fluke, that one was an outlier, until a pattern that would have been obvious viewed together has been rationalized, individually and reasonably each time, into background noise nobody is watching anymor

Published
July 21, 2026
Updated
August 19, 2026
Reading time
9 min
Paper-cut editorial illustration for How a Warning Becomes Wallpaper

The Global Signal

On January 28, 1986, the Space Shuttle Challenger broke apart 73 seconds after launch, killing all seven crew members, due to the failure of an O-ring seal in one of the solid rocket boosters in unusually cold launch-morning temperatures. The Rogers Commission, the presidential commission that investigated the disaster, found that engineers at contractor Morton Thiokol had documented O-ring erosion and blow-by on prior shuttle flights for years before the accident, and had raised concerns about launching in cold temperatures the night before the flight, concerns that were ultimately overruled in the final launch decision (Rogers Commission Report, 1986). Sociologist Diane Vaughan's subsequent study of the decision, "The Challenger Launch Decision" (1996), coined the term "normalization of deviance" to describe how each prior instance of O-ring erosion, technically a deviation from the design specification, had been reviewed, explained, and accepted as within an expanding definition of acceptable risk, so that by the night before the final launch, a genuinely dangerous pattern had been absorbed into what counted as normal.

No single review of any one flight's O-ring data was dishonest or obviously wrong. Each review, taken alone, reached a defensible conclusion. The pattern only became visible in hindsight, once someone looked at the flights together instead of one at a time.

The pattern only became visible in hindsight, once someone looked at the flights together instead of one at a time.

The Hidden Signal

A risk indicator that recurs across separate incidents, each reviewed and explained individually, can accumulate into a clear pattern that no single review is positioned to see, because each review's job is to explain that one instance, not to compare it against the accumulating series. Consider a hypothetical scenario, smaller than Challenger's case but illustrative of the same mechanism: a manufacturer experiences a minor product defect rate that ticks up slightly each quarter for two years. Each quarterly review explains that quarter's uptick with a specific, plausible cause, a supplier delay, a seasonal demand spike, a training gap on one shift, and each explanation is individually reasonable. No single review compares all eight quarters together, so the underlying, worsening trend is never named as a trend; it exists only as eight separately explained blips.

What changes

What changes when patterns are reviewed, not just incidents

Reviewing each incident individually, however competently, cannot detect a pattern accumulating across the full series.

A standing, separate review comparing this period's accepted explanation against prior periods' catches a quietly widening risk before an individual review ever could.

Why the Visible Metric Misleads

A quarterly or per-incident review answers a narrow question well, what explains this specific instance, and that narrow framing is exactly what prevents it from answering a different, more important question: does this instance belong to a worsening pattern across time. The more revealing practice is not better individual incident reviews, which were often genuinely competent on their own terms in Challenger's case, but a separate, standing review that looks specifically for whether prior "acceptable" explanations are recurring and whether the range being called acceptable has quietly widened. The Rogers Commission found that Morton Thiokol's own engineers had, in effect, already updated their internal sense of acceptable O-ring erosion multiple times before the fatal flight, each update reasonable given the immediate data, cumulatively dangerous given the full series.

The Leadership Move

The right move is not to demand zero deviations or treat every minor anomaly as a crisis. It is to build a standing review, separate from routine incident-by-incident analysis, whose specific job is to ask whether this quarter's "acceptable" explanation matches or exceeds prior "acceptable" explanations, flagging when the accepted range itself is quietly expanding.

Ownership

The team closest to an incident, engineering, quality, or frontline operations, typically owns explaining that specific instance well. A separate function, risk, safety, or an independent review body, needs to own comparing the accumulating series of explanations against each other, since the team explaining instance number twelve is rarely positioned to notice that instances one through eleven quietly redefined what counts as acceptable.

Tradeoff

A standing pattern review that looks across incidents, rather than at each one individually, costs real time and will sometimes flag a pattern that turns out to be genuinely benign. The alternative, Challenger's case shows starkly, is a pattern that only becomes visible after the worst possible outcome has already occurred.

Human consequence

The seven Challenger crew members were served by an organization in which every individual review of prior O-ring problems was defensible on its own terms, and none of those reviews, taken alone, was positioned to see that the accepted range of risk had been expanding flight after flight.

Implication for Operators

Any organization that reviews risk incidents one at a time, however competently, should assume that a genuine pattern can accumulate invisibly across those reviews, because no single review is built to compare itself against the full series. The practical shift is establishing a standing, separate review whose explicit purpose is checking whether this period's accepted explanation matches or exceeds prior periods', not simply reviewing each new incident on its own merits.

Challenger's O-ring problem was documented, discussed, and individually explained for years before the disaster. The organization was not blind to the existence of the risk. It was blind to the fact that each reasonable explanation was quietly widening what counted as acceptable, and no standing mechanism existed to compare this flight's explanation against the accumulating series that came before it.

The decision blindness here is not a hidden risk. It is a risk explained competently, one instance at a time, until the explanations themselves became the pattern nobody was watching for.

Next Move

Reflection question

Name a recurring minor issue your organization has explained individually more than once. Has anyone compared this period's explanation against prior periods' to check whether the accepted range has grown?

Practical step

Establish a standing review, separate from routine incident analysis, whose explicit job is comparing this period's accepted explanation for a recurring issue against prior periods', flagging any quiet widening of what counts as acceptable.

Soft invitation

Transformidy's decision-workflow review helps organizations distinguish a well-explained incident from a pattern accumulating invisibly across many well-explained incidents.

Signal checkEvidence to ActionRegistry-backed

How often does your organization review incidents together to see whether the explanations themselves are becoming a pattern?

FAQ

Was the Challenger disaster a failure of the engineers who reviewed O-ring data?

The Rogers Commission's findings and Diane Vaughan's subsequent study describe a more structural failure: engineers raised concerns the night before launch that were overruled, and prior individual reviews of O-ring erosion were each defensible given the data available at the time. The deeper failure was the absence of a standing mechanism comparing those reviews against each other across the full series of flights.

What does "normalization of deviance" actually mean?

Diane Vaughan's term, from her 1996 study of the Challenger decision, describes how a deviation from a design specification, if reviewed and explained enough times without consequence, gradually becomes redefined as acceptable, so the organization's own sense of "normal" quietly shifts to include what was originally a warning sign.

How can an organization tell if it is normalizing deviance?

Ask whether anyone is comparing this period's "acceptable" explanation against prior periods' explanations for the same category of issue, specifically checking whether the accepted range has grown. If no one holds that comparison as an explicit, standing responsibility, the organization has no defense against the pattern Challenger's case illustrates.

Is reviewing every incident individually still valuable?

Yes, and Challenger's individual incident reviews were often technically competent. The point is not to replace incident-by-incident review but to add a separate, standing review whose job is comparing the accumulating series, which individual reviews are not designed to do.

Who should own the standing pattern review?

A function independent from the team explaining individual incidents, typically risk, safety, or an audit-style function reporting outside the operational chain being reviewed, so the comparison is not performed by the same people whose prior explanations are being checked.