EXAMPLE LIBRARY
One grammar. Very different systems.
These cases are designed to teach transfer: the ability to recognize the same diagnostic structure in a broken lunch rush, a software incident, weak product adoption, and a system that worked exceptionally well.
Challenger: the nearest failure was not the strongest control.
The seal failure explains the physical mechanism. It does not explain why the launch system converted known concern into permission to proceed.
Cold → reduced seal performance → breach → structural loss
Seal vulnerability · normalized risk · schedule pressure · fragmented authority
Redesigning the seal matters. But authority can interrupt future hazardous launches even when the technical risk is not yet fully understood.
ILLUSTRATIVE TEACHING CASES
Practice seeing beyond the symptom.
These are invented, plausible cases—not research findings. Each is intentionally concise so a new reader can see one important EDF move.
The restaurant with “careless servers”
Wrong-side orders doubled on Friday nights. The manager’s first proposal was retraining.
18 of 126 peak-period orders had a side-item correction, up from a four-week average of 7.
Server entry error; kitchen screen truncation; menu-code ambiguity; rushed handoff at the expo station.
Tickets were entered correctly. Errors clustered on items whose modifier text wrapped off the kitchen display.
Long modifier → hidden text → cook sees default side → expo lacks a verbal confirmation → wrong plate reaches table.
Retraining servers would target the people nearest the complaint, not the path producing it.
The release that “made the API slow”
Latency rose 40 minutes after deployment—but only for one customer segment.
Enterprise search p95 latency rose from 480 ms to 2.8 s; standard accounts were unchanged.
New permission expansion; larger enterprise role graphs; cold cache after release; retry policy amplified load.
A simple code regression should have affected both account types. It did not.
Permission expansion → larger query → cold cache → timeout → retry → queue growth → higher latency.
The action is reversible and tests the modeled path. A rollback of the entire release is broader than the evidence requires.
The feature customers “didn’t want”
Only 9% of eligible teams used a new planning feature in its first month.
9% created a plan; 72% of creators returned the following week. Low adoption and low value are not the same claim.
Poor discoverability; unclear permissions; weak need; import friction; rollout reached the wrong role.
Most admins never saw the entry point. Users who created a first plan showed strong repeat use.
Whether repeat use reflects durable value or novelty cannot yet be established.
“Low adoption” is a manifestation. Removing the feature would be a decision made before diagnosing access to it.
The hiring pipeline that “lacked candidates”
A critical role stayed open for 94 days while the organization blamed the market.
Primary system: technical hiring pipeline. Context: compensation policy and executive approval. Focus: time to accepted offer.
Narrow requirements; below-market band; six interviews; interview rescheduling; approval only after final round.
Small pool → slow scheduling → candidate attrition → late compensation exception → declined offer → restart.
Recruiting can source; hiring managers can simplify; compensation can set bands; executives control exceptions.
More sourcing adds people to a pipeline designed to lose them.
The warehouse with recurring stockouts
The item was physically available upstream, yet stores repeatedly showed zero on hand.
Store stockouts, emergency transfers, excess regional inventory, and high forecast error in the dashboard.
Case-pack rounding; stale lead times; promotion data delay; manual overrides; incentive to minimize store inventory.
Late promotion signal → low forecast → rounded-down order → store shortage → emergency transfer → distorted history.
The emergency response contaminates the demand history used for the next forecast.
The strongest intervention changes both the forward path and the feedback loop.
The neighborhood festival that ran unusually well
Ten thousand visitors, severe weather, no safety incidents, and rapid recovery.
The event reopened safely 47 minutes after a weather suspension and retained 83% of scheduled programming.
Clear incident roles; rehearsed weather protocol; trusted local communication; modular vendor layout; empowered zone leads.
Early alert → shared trigger → distributed shutdown → verified sheltering → zone-by-zone inspection → controlled reopening.
Without delegated zone authority, the central team would have become a bottleneck during both closure and restart.
Success is not self-explanatory. EDF identifies the conditions that should survive budget pressure and staff turnover.
WHAT TRANSFERS
The visible problem changes. The reasoning discipline does not.
Describe before explaining
Every case starts with an outcome that does not smuggle in its cause.
Model the path
Origins matter because of how the system carries their effects forward.
Intervene at leverage
The best control is chosen, not assumed to be nearest the symptom or earliest cause.