EXAMPLE LIBRARY

One grammar. Very different systems.

These cases are designed to teach transfer: the ability to recognize the same diagnostic structure in a broken lunch rush, a software incident, weak product adoption, and a system that worked exceptionally well.

Repository validation caseIllustrative teaching case
VALIDATION CASE · EDF–2

Challenger: the nearest failure was not the strongest control.

The seal failure explains the physical mechanism. It does not explain why the launch system converted known concern into permission to proceed.

OUTCOME

Vehicle and crew lost after launch

←
PROPAGATION

Cold → reduced seal performance → breach → structural loss

←
ORIGIN NETWORK

Seal vulnerability · normalized risk · schedule pressure · fragmented authority

CONTROL POINTEngineering authority in the launch decision

Redesigning the seal matters. But authority can interrupt future hazardous launches even when the technical risk is not yet fully understood.

ILLUSTRATIVE TEACHING CASES

Practice seeing beyond the symptom.

These are invented, plausible cases—not research findings. Each is intentionally concise so a new reader can see one important EDF move.

OPERATIONS · EDF–1

The restaurant with “careless servers”

Wrong-side orders doubled on Friday nights. The manager’s first proposal was retraining.

Observable outcome

18 of 126 peak-period orders had a side-item correction, up from a four-week average of 7.

Competing origins

Server entry error; kitchen screen truncation; menu-code ambiguity; rushed handoff at the expo station.

Discriminating evidence

Tickets were entered correctly. Errors clustered on items whose modifier text wrapped off the kitchen display.

Propagation

Long modifier → hidden text → cook sees default side → expo lacks a verbal confirmation → wrong plate reaches table.

BETTER CONTROLReformat modifier display and add an expo check for affected items.

Retraining servers would target the people nearest the complaint, not the path producing it.

SOFTWARE · EDF–1

The release that “made the API slow”

Latency rose 40 minutes after deployment—but only for one customer segment.

Observable outcome

Enterprise search p95 latency rose from 480 ms to 2.8 s; standard accounts were unchanged.

Origin network

New permission expansion; larger enterprise role graphs; cold cache after release; retry policy amplified load.

Contradiction

A simple code regression should have affected both account types. It did not.

Propagation

Permission expansion → larger query → cold cache → timeout → retry → queue growth → higher latency.

FIRST RESPONSIBLE ACTIONDisable expansion for enterprise accounts and watch queue depth.

The action is reversible and tests the modeled path. A rollback of the entire release is broader than the evidence requires.

PRODUCT · EDF–1

The feature customers “didn’t want”

Only 9% of eligible teams used a new planning feature in its first month.

Outcome, not story

9% created a plan; 72% of creators returned the following week. Low adoption and low value are not the same claim.

Origin candidates

Poor discoverability; unclear permissions; weak need; import friction; rollout reached the wrong role.

Evidence

Most admins never saw the entry point. Users who created a first plan showed strong repeat use.

Unknown

Whether repeat use reflects durable value or novelty cannot yet be established.

CONTROL POINTTest role-appropriate discovery before changing the feature.

“Low adoption” is a manifestation. Removing the feature would be a decision made before diagnosing access to it.

PEOPLE SYSTEMS · EDF–2

The hiring pipeline that “lacked candidates”

A critical role stayed open for 94 days while the organization blamed the market.

System context

Primary system: technical hiring pipeline. Context: compensation policy and executive approval. Focus: time to accepted offer.

Origin network

Narrow requirements; below-market band; six interviews; interview rescheduling; approval only after final round.

Propagation

Small pool → slow scheduling → candidate attrition → late compensation exception → declined offer → restart.

Control distribution

Recruiting can source; hiring managers can simplify; compensation can set bands; executives control exceptions.

HIGHEST LEVERAGEPre-approve a realistic band and reduce interview handoffs.

More sourcing adds people to a pipeline designed to lose them.

SUPPLY CHAIN · EDF–2

The warehouse with recurring stockouts

The item was physically available upstream, yet stores repeatedly showed zero on hand.

Manifestations

Store stockouts, emergency transfers, excess regional inventory, and high forecast error in the dashboard.

Origin network

Case-pack rounding; stale lead times; promotion data delay; manual overrides; incentive to minimize store inventory.

Propagation

Late promotion signal → low forecast → rounded-down order → store shortage → emergency transfer → distorted history.

Feedback loop

The emergency response contaminates the demand history used for the next forecast.

SYSTEM CONTROLProtect promotion signals and separate emergency transfers from demand history.

The strongest intervention changes both the forward path and the feedback loop.

SUCCESS · EDF–2

The neighborhood festival that ran unusually well

Ten thousand visitors, severe weather, no safety incidents, and rapid recovery.

Outcome

The event reopened safely 47 minutes after a weather suspension and retained 83% of scheduled programming.

Success network

Clear incident roles; rehearsed weather protocol; trusted local communication; modular vendor layout; empowered zone leads.

Propagation

Early alert → shared trigger → distributed shutdown → verified sheltering → zone-by-zone inspection → controlled reopening.

Counterfactual

Without delegated zone authority, the central team would have become a bottleneck during both closure and restart.

PRESERVEKeep rehearsals and distributed decision authority.

Success is not self-explanatory. EDF identifies the conditions that should survive budget pressure and staff turnover.

WHAT TRANSFERS

The visible problem changes. The reasoning discipline does not.

01

Describe before explaining

Every case starts with an outcome that does not smuggle in its cause.

02

Model the path

Origins matter because of how the system carries their effects forward.

03

Intervene at leverage

The best control is chosen, not assumed to be nearest the symptom or earliest cause.

Try EDF on your system →