People · 3.2
How a control looks from the machine
How a control looks from the machine. What it costs, who decides, and what usually goes wrong.
Where workforce visibility is separately justified and disclosed, more information describes a related monitoring use case; it should not be treated as proof of intent.
For an independent reference point, see NCSC guidance on managing people risk.
The day
Throughput, handover, and a job that has to ship
An operator's day is measured in parts produced. A shift starts, a handover happens in a few minutes, a job runs, something goes wrong with a tool, and the schedule is already tight.
Every control introduced into that day costs seconds at a moment when seconds are contested. Controls that cost seconds at the wrong moment do not get followed; they get worked around, and the workaround is invisible to everybody who designed the control.
What a control looks like from there
Three examples
A password at a terminal. Forty seconds with gloves on, several times a shift, on a keyboard with a film over it. The predictable outcome is a shared login written on a card, and it is not a discipline problem.
An authorised transfer route. If it takes ten minutes and involves finding somebody in an office, the memory stick wins whenever the office is empty, which is most of the second and third shifts.
A locked USB port. Solves the transfer route and does not replace it. If nothing replaces it, the job stops or somebody finds another way, and one of those two is what will actually happen.
The principle
The compliant route has to be the fast route
Where following the control is quicker than avoiding it, the control holds without enforcement. Where it is slower, enforcement is required permanently and will fail during the busy week.
This is the single most useful sentence in this part of the blog and it costs money to honour, which is why it is frequently skipped in favour of a policy.
Designing with them
Ask three operators before deploying anything
What would make this unworkable? When in the shift would this hurt most? What would you do if it did not work and the job had to run?
The answers take twenty minutes, they are specific, and they are almost always things nobody in the office had considered. The third question in particular predicts the workaround before it exists.
Who the threat model is
Operators are not the enemy
A programme that arrives on the floor as suspicion produces resentment and concealment. Almost all of what governance on the floor catches is error, convenience and drift rather than malice, and saying so plainly changes how it is received.
The entry on what staff are told is about doing that properly.
Shift patterns
Design for the third shift
Anything that depends on somebody in an office being available is a control that works on days and fails at night. Nights are when the unusual transfers happen, for entirely ordinary reasons.
Either the route works unattended or it does not work.
Feedback after deployment
Go back in a fortnight
Not to check compliance: to ask what is annoying. The answers arrive freely if nothing is at stake and they identify the workaround while it is still one person's shortcut rather than the way things are done.
The pilot machine
Deploy to one first and listen
One machine, one shift, a fortnight. Whatever is wrong will be apparent and will cost one machine's disruption rather than the whole floor's. Suppliers who skip this step generally do it anyway, later, as a rollback.
Gloves, noise and light
Physical conditions defeat controls designed indoors
Touchscreens with gloves. Passwords under machine noise. Screens in sunlight or in a dark corner. Badge readers mounted where a person carrying something cannot reach.
Every one of these has produced a shared credential somewhere, and every one is visible in ten minutes of watching.
Also
Elsewhere in people
- What compliance actually costs, itemisedWhat compliance actually costs, itemised. What it costs, who decides, and what usually goes wrong.
- Reading a proposal that quotes a certificateReading a proposal that quotes a certificate. What it costs, who decides, and what usually goes wrong.
- What to build and what to buyWhat to build and what to buy. What it costs, who decides, and what usually goes wrong.
- Making the budget case to somebody who resents itMaking the budget case to somebody who resents it. What it costs, who decides, and what usually goes wrong.
- The costs that arrive after the purchase orderThe costs that arrive after the purchase order. What it costs, who decides, and what usually goes wrong.
- Doing this with almost no moneyDoing this with almost no money. What it costs, who decides, and what usually goes wrong.
- Who owns compliance, and why it cannot be nobodyWho owns compliance, and why it cannot be nobody. What it costs, who decides, and what usually goes wrong.
- Running it as a project rather than as a documentRunning it as a project rather than as a document. What it costs, who decides, and what usually goes wrong.
- Reporting to a board that wants one numberReporting to a board that wants one number. What it costs, who decides, and what usually goes wrong.
- When the date slips, which it willWhen the date slips, which it will. What it costs, who decides, and what usually goes wrong.
- Staying compliant after the assessmentStaying compliant after the assessment. What it costs, who decides, and what usually goes wrong.
- Working to two standards at onceWorking to two standards at once. What it costs, who decides, and what usually goes wrong.
- Training that changes what people doTraining that changes what people do. What it costs, who decides, and what usually goes wrong.
- Contractors, temps and the visiting engineerContractors, temps and the visiting engineer. What it costs, who decides, and what usually goes wrong.
- Hiring for a role most suppliers have never filledHiring for a role most suppliers have never filled. What it costs, who decides, and what usually goes wrong.
- Giving people a way to say a control is unworkableGiving people a way to say a control is unworkable. What it costs, who decides, and what usually goes wrong.
- What staff are told about monitoringWhat staff are told about monitoring. What it costs, who decides, and what usually goes wrong.
- What counts as an incidentWhat counts as an incident. What it costs, who decides, and what usually goes wrong.
- Reporting obligations and their clocksReporting obligations and their clocks. What it costs, who decides, and what usually goes wrong.
- Being able to answer afterwardsBeing able to answer afterwards. What it costs, who decides, and what usually goes wrong.
- The first hour, and who decidesThe first hour, and who decides. What it costs, who decides, and what usually goes wrong.
- Telling a customer something happenedTelling a customer something happened. What it costs, who decides, and what usually goes wrong.
- What changes afterwards, and what shouldWhat changes afterwards, and what should. What it costs, who decides, and what usually goes wrong.
- The other frameworks you have also metThe other frameworks you have also met. What it costs, who decides, and what usually goes wrong.
- Export control, named and not advised onExport control, named and not advised on. What it costs, who decides, and what usually goes wrong.
- Your own suppliers, and what to ask themYour own suppliers, and what to ask them. What it costs, who decides, and what usually goes wrong.
- Suppliers outside the United StatesSuppliers outside the United States. What it costs, who decides, and what usually goes wrong.
- Where the data physically sitsWhere the data physically sits. What it costs, who decides, and what usually goes wrong.
- What is changing, and how to tellWhat is changing, and how to tell. What it costs, who decides, and what usually goes wrong.