American aviation runs on a strange trade. Break a regulation, descend below minimums, wander into airspace that was not yours, and you can file a report with NASA within ten days. If it was inadvertent, the FAA waives the penalty.1 The reports go to NASA rather than the regulator. NASA strips the identities, mails your identifying strip back as a time-stamped receipt, and publishes the lessons.
The FAA agreed to this because it wanted the near-misses more than the scalps. Punish every deviation and the deviations stop being reported, and the sky fills up with ways to die that nobody wrote down. Under the program, a mistake you report is forgiven, and a mistake you hide can cost you your certificate. Fifty years of that trade produced one of the largest bodies of error knowledge any industry has, and the amnesty is the reason it exists.
An institution's mistakes are smaller moral events than they look, because fallibility is structural. Forecasts miss, rules misfit, execution slips, and no procedure gets rid of any of it. A trustworthy institution differs from a dangerous one in what happens after an error starts to repeat. At that point the trustworthy institution is arranged so that finding the error is possible, cheap and consequential. The dangerous one is arranged so that finding it is expensive, dangerous and beside the point. The descriptive question about an error is whether it was foreseeable. The political question is what the institution did once the error started announcing itself, and forgiveness has always tracked the political one.
What forgiveness buys
Amnesty is a form of procurement, since a safe harbor for honest error buys information that punishment destroys: the near-miss, the anomaly, the warning that would have reached everyone. The forgivable class of institutional errors is big, and it should be.
Forecasts fail under uncertainty no model removes. One-off implementation mistakes are the normal cost of any system nobody holds in their head whole. Some anomalies are genuinely unprecedented, and no rule can encode a case nobody imagined. Categories compress reality, so occasional misclassification at the edges is a property of governing at all. A defensible policy can lose to chance. A bad outcome does not prove the decision was bad. Waiting for decisive evidence can be responsible when the alternative is thrash. A metric known to be partial, used with its limits in view, is ordinary instrument-making. A reform that fails, even a reform of the reform, is what correction looks like when it is honest.
In all of those cases, the institution was exposed to correction while it made the error, and the error was allowed to count, which is all the word "forgivable" promises. Demand that this class be eliminated and you have demanded infallibility, and infallibility teaches concealment. The safe harbor works as a maintenance contract for the institution's senses. Institutions punished for every bad outcome stop reporting, stop experimenting, and stop saying "we don't know," which are the three behaviors every later correction depends on.
The gradient
Forgivability is a property of the path an error takes once it has happened.
%% title: The biography of an error %% caption: The first occurrence is a fact. Everything after it is a series of choices. Forgiveness decays along the evidence axis and dies where power is used to keep the error from counting. flowchart TD classDef state stroke-width:1.6px; classDef decay stroke-width:2.4px,font-weight:bold; A[First<br/>occurrence]:::state B[Evidence<br/>accumulates]:::state C[Revised,<br/>cost absorbed]:::state D[Redefined,<br/>cost transferred]:::state E[Error defended<br/>by power]:::decay A -- "sensing: did the institution<br/>arrange to know?" --> B B -- "recognition,<br/>attribution,<br/>response" --> C B -- "the exception hardens<br/>into a category" --> D D -- "concealment, retaliation,<br/>immunity from review" --> E
An unforeseeable first occurrence can be excused, but the tenth cannot. By then the institution has evidence, capacity and opportunity, and continuing to route the consequences elsewhere is a choice wearing a mistake's clothes. The gradient runs on three variables: how much evidence existed, how foreseeable the harm had become, how much capacity to respond had piled up. Uncertainty is a depreciating defense, and invoked after the evidence has arrived, it stops describing what the institution knew and starts describing what it preferred not to act on.
Designed ignorance
"We didn't know" and "we arranged things so we wouldn't have to know" are different sentences, and only one describes an accident. An organization can miss a problem because the data did not exist, the signal was buried, or the thing had no precedent, and that is forgivable. Manufacturing the absence is something else. It means suppressing adverse reports, punishing messengers, underfunding inspection, and declining to collect the outcome data that would obviously indict a practice. It means building a chain of command that strains bad news out on the way up. The cost of sensing is the institution's to pay. Pushing it onto the people the not-knowing hurts is the first theft, and every later one depends on it.
The exception industry
Recognition is where classification goes defensive. One anomaly can reasonably be called noise, and ten deserve an investigation of the rule. At a hundred, "exception" has stopped describing the cases and started protecting the rule. The category exists so the rule never has to stand trial.
Compression guarantees that a governing rule leaves a residue.2 The political question is whether the institution's categories are set up so the residue can pile into evidence, or so it can be reclassified fast enough to stay invisible. An exception mechanism under periodic review is a pressure valve, while one that never faces review becomes an industry.
Patience and delay
Not updating right away can be responsible. Evidence is noisy, reversals cost money and trust, and an institution that lurches at every signal is overfitting to its own turbulence. That kind of patience rests on a judgment that the evidence is not yet decisive.
Strategic delay has a different signature. The demand for evidence never converges, because a met threshold produces a new one and a finished study produces a request for another. Meanwhile the delay reliably benefits whoever would lose from the revision. The tell is who pays during the interval. Harm arrives on one clock and review runs on another. In the gap between them, the injured absorb the cost of a correction the institution has decided it can afford to postpone.3 Waiting is forgivable when everyone pays for the wait equally. When the injured pay it and the institution holds the extension cord, patience is a transfer.
The four attacks
The pathologies of error governance boil down to four attacks on correction itself. The first attacks knowing: suppress reports, punish messengers, tune the metric until it flatters. The senses go dark, and darkness is deniable. The second attacks classification: define failure as exception, reclassify until the pattern cannot accumulate. No trial can be assembled, so the rule is never on trial.4
The third attacks attribution: assign causes wherever they least threaten authority. Scapegoating is different in kind from getting causation wrong, because it reliably moves blame away from the people with the power, and reliability in that direction is design.5 The fourth attacks response: findings that bind nothing, appeals that route back into the implicated institution, corrective authority declared exempt from its own review.6 All four convert an institutional limitation into an institutional advantage. Fallibility costs something, and these attacks make someone else pay it. A mistake should not systematically profit from itself.
The safe harbor
The line an institution may claim is narrow, and it is enough. It may claim the error was hard to foresee: genuine uncertainty, reasonable procedure, no reckless disregard of a known risk. It may claim prompt detection and honest disclosure. The costs, it may say, were absorbed where the authority lived, and the learning was real, visible in changed rules rather than changed statements. None of that covers the tenth occurrence, because the harbor is for the first mistake, and it decays with every repetition it failed to prevent.
One test exposes a counterfeit harbor. Ask what happens if the same error recurs, and recurs, and recurs, and the answer still ends in no consequence for the people with the power to prevent it. At that point the harbor has become a moat that protects the error from the world.
The unforgivable category is small and sharp. It covers the institution that has converted being wrong into a defended arrangement. That institution holds power over whether the error counts, who may name it, who pays for it, and whether anything changes. Against that, "we're only human" makes a strange defense, and reads more like the crime's opening statement.
The first mistake is information. The political question starts with who gets made to pay for the second.
Notes
The Aviation Safety Reporting Program: FAA Advisory Circular 00-46F and 14 CFR § 91.25. A written report to NASA within ten days, the violation inadvertent and not deliberate, waives penalty. Criminal matters and accidents are excluded. NASA de-identifies reports and returns the reporter's identifying strip as proof of filing.
What a rule's compression leaves outside, and who gets assigned to absorb it: Nine Thousand Claims and One Woman.
The three clocks, harm, review, memory, and who pays for the interval between them: The Apology Was Flawless.
What protects a rule from its own evidence: The Rule Is Never on Trial.
Why blame pools where it is survivable rather than where the authority lived: The Nurse Has No Committee.
The distance between testimony and control, and what a finding has to be able to do to bind: Filed at the Wrong Size.