Author Note
John Brand https://orcid.org/0009-0006-6505-911X
This paper was created for Strategic Intelligence Dynamics LLC. Strategic Intelligence Dynamics LLC. is a company created by the author. The author has no known conflicts of interest or financial relationships that could have influenced the work presented in this paper.
Correspondence concerning this article should be addressed to John Brand, Strategic Intelligence Dynamics LLC. Email: jdbrand1@liberty.edu
Abstract
Organizations rarely break all at once. More often, they keep producing, keep reporting, and keep telling themselves they are still on course while the underlying system has already started to rotate. The visible failure comes later. By then, the drift had usually been building for some time through delayed feedback, distorted incentives, and tolerance thresholds that moved without anyone naming it. This paper proposes a dynamic systems model for measuring that movement. It treats alignment as directional coherence between strategic intent and observable behavior over time, and drift as the changing rate of deviation between the two. The framework uses angular displacement, internal torque, external disturbance, and bounded tolerance to translate a familiar organizational problem into something that can be tracked before the lagging metrics collapse. Operationalization is demonstrated through the Error Recurrence Stability Index (ERSI), supported by an Incentive Alignment Coefficient (IAC), a Strategic Coherence Score (SCS), and a triangulation requirement designed to reduce metric distortion. The issue is not simply whether an organization is aligned at a moment in time. The issue is whether it is quietly rotating away from its own stated direction while still calling that stability.
Keywords: organizational drift, dynamic systems modeling, control theory, normalization of deviance, error recurrence, incentive torque, strategic alignment
Organizations talk about alignment as if it were a culture problem, a communication problem, or a leadership problem. That is usually where the discussion stays. Surveys are reviewed, dashboards are discussed, morale is interpreted, and management decides whether things feel on track. The problem is that drift does not need to announce itself in any of those places first. It can build inside the operating logic of the system long before anyone at the top is willing to call it movement.
Misalignment usually does not enter as collapse. It enters as small adjustments that seem reasonable in isolation. Incentives bend. Feedback slows. Exceptions accumulate. Tolerance expands. The system keeps producing just enough to preserve confidence, and that is often the most dangerous stage because the appearance of function gets mistaken for evidence of control. By the time outcome metrics visibly deteriorate, the organization is often no longer correcting from a stable position. It reacts from inside an accumulated deviation.
That gap is the real problem because most organizations are not short on stated goals. They are short on mechanisms that can detect whether actual behavior is still tracking those goals in motion. A strategic plan can remain unchanged on paper while the system beneath it has already reorganized around different rewards, different pressures, and different definitions of acceptable risk. The system did not fail all at once. It adjusted into failure. That is the problem this paper addresses.
Theoretical Foundation
Control theory begins with a simple reality: deviation is normal. Dynamic systems do not remain stable because deviation never occurs. They remain stable because deviation is detected early enough, interpreted accurately enough, and corrected with enough discipline to keep the system near its intended path. Engineering systems do this through feedback loops, reference trajectories, and bounded tolerances. Organizations are different in form, but not in principle. They also operate under shifting conditions, internal pressures, and delayed signals. They also drift when correction weakens (Teece, 2018).
In that sense, strategic direction functions as a moving reference trajectory, while operational outputs represent the behavior the system is actually producing. The issue is not whether some variance exists. Variance is inevitable. The issue is whether the organization still treats strategic intent as the reference point, or whether it has begun to redefine intent around whatever behavior the system is already producing. Once that reversal starts, alignment language becomes cosmetic. The system starts using current behavior to explain away deviation rather than using strategy to correct it. Unintentional drift in performance can emerge when intended states begin to yield to actual behavior under degraded corrective conditions (Parsa et al., 2017).
That is where incentive structures matter. Feedback channels, reinforcement patterns, communication quality, and corrective mechanisms do not sit at the edge of alignment. They shape it. They act as internal forces that influence the rate and direction of movement. External pressures do the same. Market volatility, regulatory change, supply instability, and macroeconomic disruption introduce disturbance whether the organization is ready or not. Because organizations are open systems, they cannot eliminate those pressures. What they can do is determine whether their internal design amplifies them or absorbs them (Teece, 2018).
The deeper problem is that organizational tolerance is often psychological before it is operational. Teams get used to recurring problems. Managers normalize workaround behavior. Risk gets renamed as experience. Safety science has already described this kind of boundary migration. The language changes from “this is unacceptable” to “this has happened before” and then to “this is still within range.” That is not stability. That is a system teaching itself to live closer to the edge while pretending the edge moved (Rasmussen, 1997; Morrison & Wears, 2021).
For that reason, alignment in this framework is defined as directional tracking coherence between strategic intent and behavioral output over time. Drift is not treated as a static condition. It is the rate at which that relationship is changing. That distinction matters because a system can look acceptable in a snapshot and still be moving the wrong way.
The Rotational Drift Model
Figure 1 The Rotational Drift Model
Note. The three torque arms represent the reward, effort, and performance forces the organization generates internally. Angular displacement θ(t) measures deviation between strategic intent and observable behavior, and drift is the rate at which that displacement changes over time. External pressure and the tolerance envelope determine how far the system rotates before correction restores it or it crosses a boundary.
This model, depicted in Figure 1, treats organizational alignment as a directional relationship between a strategic goal trajectory, G(t), and observable system behavior, B(t), over time. Instead of reducing alignment to a simple score, it represents deviation as angular displacement, θ(t), between intended direction and actual output. When θ(t) is near zero, the system is tracking. When that angle begins to widen, the system is rotating away from its stated aim even if surface performance has not yet collapsed.
Perfect alignment is therefore approximated by:
θ(t) ≈ 0
Drift is defined as the rate of change in that deviation:
Drift = dθ/dt
That definition matters because it moves the discussion away from static judgment and toward directional movement. An organization may still be profitable, compliant, or outwardly stable while its drift rate is increasing. In practical terms, that means it is getting worse before the dashboard is willing to say so. Appendix A provides a numerical demonstration showing that increasing perception delay (δ) transitions the system from bounded recovery to oscillatory overshoot and, at sufficient lag, boundary-crossing divergence under identical disturbance conditions (Appendix A).
The model identifies two broad force categories acting on this deviation. The first is internal torque. These are the forces generated by the organization itself.
Incentive Torque refers to distortions created when the system rewards behavior that does not actually support the stated objective.
Feedback Torque refers to delay, degradation, or loss of corrective signal integrity.
Learning Friction refers to the system’s inability to reduce recurrence of known failures.
The second category is external disturbance, represented as Dₑ(t). These are exogenous pressures such as tariff changes, demand shocks, regulatory shifts, or supply instability that alter system pressure regardless of internal design. External pressure is unavoidable. Internal amplification is not.
Operationalizing Drift: Error Recurrence Stability Index (ERSI)
To make the model usable, it must attach to something observable. Scrap rate in manufacturing is one possible anchor, but scrap is a lagging indicator. By the time scrap is visibly worse, the system has already been teaching itself the wrong lesson for some time. That is why the first operational metric in this framework is the Error Recurrence Stability Index, or ERSI.
ERSI measures whether known failure modes are actually being reduced after corrective action is taken. This is a basic question that organizations often answer too quickly and too loosely. A correction was documented. A meeting was held. A countermeasure was assigned. None of that proves the system learned. The only meaningful test is recurrence. If the same error type continues at the same rate, or increases, then the corrective structure is weaker than the forces producing the deviation. At that point, the paperwork says improvement while the system says otherwise.
Let fₖ(t) represent the recurrence frequency of a known error type k over time. When:
dfₖ/dt ≥ 0
The system is not demonstrating effective reduction of that failure mode. In plain terms, it is seeing the problem, talking about the problem, and still reproducing the problem. That is not a knowledge gap. That is learning friction.
Incentive Alignment Coefficient (IAC)
Organizations do not only reward performance through compensation or promotion. They reward it through attention, praise, visibility, and informal status. That is often where drift gets harder to detect because the formal system may still say the right things while the informal system quietly rewards something else. When that happens, the organization does not need open defiance to drift. It only needs repeated reinforcement of the wrong behavior.
The Incentive Alignment Coefficient estimates the relationship between measurable contribution, Pᵢ, and reinforcement frequency, Rᵢ:
IAC = corr(P, R)
A strong positive relationship suggests the organization is reinforcing what it claims to value. A weak or negative relationship suggests something else is being rewarded instead, often visibility, compliance with local politics, or performance theater. People learn that quickly. They always do. The issue is not whether the mission statement says one thing. The issue is what the system teaches people to optimize when nobody is explaining it out loud. This misalignment manifests as a measurable agency cost where individual utility decouples from organizational goals (Jensen & Meckling, 1976), a gap that is often bridged not by formal mandates, but by the informal reinforcement structures that truly govern behavior (Wang et al., 2023). Appendix C develops this dynamic in a commercial setting, where the reward structure itself generated the drift (Appendix C).
Strategic Coherence Score (SCS)
Drift is not always first visible in production metrics. Sometimes it appears in language. Leaders describe one priority, middle managers operationalize another, and frontline teams make tradeoffs based on a third. The system still uses the same words, but the meaning is no longer shared. That kind of divergence matters because strategy only guides behavior when people are making the same tradeoff under pressure.
The Strategic Coherence Score measures variance in how different layers of the organization understand strategic priorities and dominant tradeoffs. Participants identify top objectives independently, and variance is assessed across groups. High divergence signals interpretive drift, even when outcomes remain stable. That matters because organizations usually do not lose coherence in public first. They lose it in translation.
Signal Integrity and Triangulation
No single metric should be trusted on its own, especially in systems with internal political pressure, narrative bias, or selective reporting. Organizations are capable of gaming almost any isolated number once attention settles on it. For that reason, this framework requires triangulation. An Incentive Metric must be paired with at least one Friction Metric and one Leading Indicator Metric. If the desired outcome appears healthy while strain signals rise and precursor indicators worsen, that divergence is itself evidence of drift. Triangulation matters because stronger inference usually depends on more than one signal path or interpretive lens (Lawlor et al., 2016).
That safeguard applies because a clean dashboard can still conceal a dirty system. In some organizations, the most dangerous period is the one in which the key metric still looks acceptable while the floor is already absorbing the cost somewhere else. Somebody is usually paying for the appearance of order. The dashboard just may not be the place where that payment shows up first.
Tolerance Envelope and External Constraint Anchoring
The model includes a tolerance envelope, E(t), representing acceptable deviation under current operating conditions. But that envelope cannot be allowed to float on confidence alone. It must be anchored to external constraints, R(t), such as financial viability, safety thresholds, and regulatory limits. If tolerance expands beyond those real constraints, the organization is not adapting. It is relabeling risk.
E(t) ≤ R(t)
The Stable State, E < R: the organization’s internal “clearance” is tighter than the external “walls.” Even with some drift, there is a buffer. The Critical State, E ≈ R: the organization has “normalized” its behavior right up to the edge of catastrophe. There is zero clearance for error. The Failure State, E > R: this is the Challenger Moment (examined in Appendix B). The system has convinced itself it is within a safe range, but it has actually drifted past the physical or regulatory breaking point.
This is where normalization of deviance enters. A problem persists without immediate disaster. The absence of disaster becomes evidence that the condition is manageable. That logic repeats until the organization is no longer asking whether it is inside the real boundary. It is only asking whether the last exception produced a visible consequence. That is a dangerous substitution because physical, financial, and regulatory constraints do not relax just because management got used to the warning sign. Physics does not care about precedent. Measurement itself can also be distorted when the metric starts replacing the underlying reality it was meant to track (Manheim, 2023).
Measurement Resolution and Corrective Mapping
The framework operates at two levels.
Drift Snapshot Mode uses minimal inputs for rapid detection: one outcome metric, one leading indicator composite, and one friction metric.
Drift Diagnostic Mode adds normalized measurement, time-series analysis, and feedback lag intervals for higher resolution.
That distinction matters because organizations often need early signal before they need analytic precision. A rough but honest read on direction is often more useful than a polished report delivered after the system has already adjusted around the problem.
Each index is also tied to a corrective lever:
If ERSI declines, increase corrective review frequency and reduce feedback delay.
If IAC declines, rebalance recognition and increase reinforcement transparency.
If SCS variance rises, clarify strategic messaging and align tradeoff communication across layers.
If oscillation amplitude increases, reduce feedback lag and avoid overcorrection.
Measurement without intervention is observation disguised as management. The value of a model like this is not that it describes drift elegantly. The value is that it gives leaders a way to interrupt it before the system hardens around it.
Operational Toolchain
To support repeatable application of the framework, the author implemented a dedicated AI-based analysis assistant that executes a standardized pipeline (signal integrity checks → drift pattern detection → stability margin interpretation → forward symptom projection). The assistant accepts Likert-scale survey inputs and open-text responses, flags noise and hidden-drift conditions and produces a structured report with confidence labeling. The system is designed for diagnostic guidance and does not generate deterministic predictions; outputs are treated as modeled indicators derived from survey and behavioral-data inputs.
Limitations
These indices remain proxies. They do not directly observe belief, motive, or intent. Their reliability depends on data quality, honest signal capture, and disciplined triangulation. External disturbances may still exceed the system’s adaptive capacity even when internal alignment is comparatively strong. The framework reduces blind spots. It does not eliminate risk. The Appendix A simulation isolates delay effects under a simplified disturbance pulse and linear corrective gain; real organizations may exhibit nonlinearity, time-varying damping, and multi-loop feedback that the model does not capture.
Conclusion: When Drift Becomes Measurable
Organizations rarely lose alignment at one obvious moment. They lose it through repeated small permissions that seem manageable at the time. A delayed response here, a tolerated exception there, a reward structure that quietly favors the wrong behavior, and the system begins to rotate. It still produces enough to preserve confidence, which is why drift is so easy to miss early and so expensive to recognize late. The problem is not usually that leaders lack goals. The problem is that most organizations have no reliable way to tell whether actual behavior is still tracking those goals once pressure, delay, and local incentives begin to interfere.
That is what this framework is meant to address. By treating alignment as directional coherence rather than a static condition, the model shifts attention from whether the organization looks stable to whether it is still moving in the right direction. That distinction matters more than most dashboards admit. A system can look acceptable in a snapshot and still drift away from its own stated intent. Lagging indicators will not expose that early. They usually confirm it after the cost has already accumulated. By then, management is not steering. It is interpreting evidence of a problem that has already had time to harden.
The supporting concepts in this paper all point to the same operational truth. Closed-loop stability depends on timely feedback. Leading indicators matter because they surface movement before outcome metrics collapse. Corrective action must be calibrated to the timing and magnitude of deviation, or the response becomes part of the instability. None of those principles are abstract once they are translated into organizational settings. They describe the difference between a system that corrects itself and a system that learns to live with worsening conditions because the final consequence has not arrived yet. That is usually how failure enters. Not as surprise, but as tolerated direction.
The Challenger appendix makes that point concrete (Appendix B). The disaster was not only the explosion at the end. It was the longer period in which recurrence, incentive pressure, interpretive divergence, and expanding tolerance were all present without forcing meaningful correction. The warning signs were not absent. They were absorbed. That is why the appendix belongs here. It is not an illustration added after the theory. It is the theory in visible form. The system kept receiving signals that should have narrowed tolerance and sharpened response, but instead it adjusted around them until the deviation became catastrophic. The system did not fail in a single decision. It adjusted into failure.
That is also why a pilot program is necessary. The purpose is not to prove the model sounds plausible. The purpose is to calibrate it against the noise, friction, and distortion of an actual operating environment. Every organization has its own ways of hiding strain, delaying feedback, and rewarding appearances over corrective discipline. A pilot makes those conditions visible. It helps identify which leading indicators matter, what level of intervention stabilizes rather than disrupts, and whether the system is truly learning or only documenting that it intends to learn. Paper compliance is easy. Real correction is harder.
The point of this model is not theoretical neatness. It is earlier visibility and more disciplined response. Organizations do not drift because they lack mission statements, values language, or strategic plans. They drift because the internal mechanics of the system begin following something else. Delayed feedback, distorted reinforcement, weak learning loops, and tolerance detached from real constraints change the path long before the organization is willing to call it movement. The real issue is not alignment as a slogan or as a survey result. The real issue is whether the system still remains under directional control. Once that becomes measurable, correction stops being reactive and starts becoming possible. The framework has been operationalized into a deployable analysis workflow designed to standardize the collection, interpretation, and reporting of drift and stability signals for recurring application in live organizational environments; validation against live operating conditions remains the objective of the pilot program.
References
Consumer Financial Protection Bureau. (2016, September 8). Consumer Financial Protection Bureau fines Wells Fargo $100 million for widespread illegal practice of secretly opening unauthorized accounts [Press release]. https://www.consumerfinance.gov/enforcement/actions/wells-fargo-bank-2016/
Federal Reserve. (2018, February 2). Responding to widespread consumer abuses and compliance breakdowns by Wells Fargo, Federal Reserve restricts Wells’ growth until firm improves governance and controls [Press release]. https://www.federalreserve.gov/newsevents/pressreleases/enforcement20180202a.htm
Jensen, M. C., & Meckling, W. H. (1976). Theory of the firm: Managerial behavior, agency costs and ownership structure. Journal of Financial Economics, 3(4), 305–360.
Lawlor, D. A., Tilling, K., & Davey Smith, G. (2016). Triangulation in aetiological epidemiology. International Journal of Epidemiology, 45(6), 1866–1886.
Manheim, D. (2023). Building less-flawed metrics: Understanding and creating better measurement and incentive systems. Patterns, 4(10), 100842.
Morrison, J. B., & Wears, R. L. (2021). Modeling Rasmussen’s dynamic modeling problem: Drift towards a boundary of safety. Cognition, Technology & Work, 24(1), 127–145. https://doi.org/10.1007/s10111-021-00668-x
Office of the Comptroller of the Currency. (2020, January 23). OCC issues notice of charges against five former senior Wells Fargo Bank executives, announces settlement with others [Press release]. https://www.occ.gov/news-issuances/news-releases/2020/nr-occ-2020-6.html
Parsa, B., Terekhov, A., Zatsiorsky, V. M., & Latash, M. L. (2017). Optimality and stability of intentional and unintentional actions: I. Origins of drifts in performance. Experimental Brain Research, 235(2), 481–496.
Rasmussen, J. (1997). Risk management in a dynamic society: A modelling problem. Safety Science, 27(2–3), 183–213.
Teece, D. J. (2018). Dynamic capabilities as (workable) management systems theory. Journal of Management & Organization, 24(3), 359–368.
U.S. Department of Justice. (2020, February 21). Wells Fargo agrees to pay $3 billion to resolve criminal and civil investigations into sales practices involving the opening of millions of accounts without customer authorization [Press release]. https://www.justice.gov/archives/opa/pr/wells-fargo-agrees-pay-3-billion-resolve-criminal-and-civil-investigations-sales-practices
Wang, Y., Hu, S., Lee, H. W., Tang, W., Shen, W., & Qiang, M. (2023). To achieve goal alignment by inter-organizational incentives: A case study of a hydropower project. Buildings, 13(9), 2258.
Wells Fargo & Company, Independent Directors of the Board. (2017, April 10). Sales practices investigation report. Shearman & Sterling LLP.
Generative AI and AI-Assisted Technologies Disclosure
The author used AI-assisted tools during the preparation of this manuscript for tasks including drafting, structural editing, and language refinement. All content was reviewed, interpreted, and approved by the author; AI was not used as a substitute for original analysis, theoretical development, or scholarly judgment.
AI assistance also plays a functional role within the framework described. The drift and stability analysis assistant, referenced in the Operational Toolchain section, is an AI-based system that executes the standardized analysis pipeline, processes Likert-scale and open-text survey inputs, and generates structured diagnostic outputs. Its role is methodological rather than generative: it operationalizes the author’s framework and produces modeled indicators subject to human interpretation. This use is distinct from manuscript preparation and is disclosed here for full transparency. The assistant was developed as a research implementation to operationalize the framework for diagnostic application; it has not yet been deployed in a live organizational setting and is not offered as a commercial product.
Appendix AShow appendix
DDE Simulation: Perception Lag and Boundary Crossing in the Rotational Drift Model
Overview
The simulation tests a core prediction of the rotational drift model: that perception delay in organizational feedback does not merely slow correction, it fundamentally alters system stability. Three scenarios are compared under identical external disturbance conditions. The only variable is the perception delay parameter δ, representing the lag between when a deviation occurs and when the corrective mechanism registers it.
Model Specification
The simulation operationalizes the rotational drift model as a second-order delay differential equation (DDE). The two state variables are θ(t), angular deviation between strategic intent and observable behavior, and ω(t), the instantaneous drift rate. The governing equations are:
dθ/dt = ω(t)
I · dω/dt = −b · ω(t) − K · θ(t − δ) + τe(t)
The restoring term K · θ(t − δ) represents the corrective force applied to a delayed observation of the current deviation. When δ = 0, correction acts on current state. When δ > 0, correction acts on a stale reading of where the system was, not where it is. That distinction is what the simulation is designed to isolate.
Parameters
The base parameters are held constant across all scenarios: moment of inertia I = 1.0, damping coefficient b = 0.5, restoring gain K = 1.0, and internal lag τi = 0. The external disturbance τe(t) equals 0.5 for 1 ≤ t ≤ 3 and zero otherwise, simulating a bounded, time-limited shock applied identically to all three runs. The time horizon is t ∈ [0, 20] with a step size of dt = 0.01.
Scenarios
Three perception delay values are tested: δ = 0.0 (instantaneous correction), δ = 0.5 (moderate delay), and δ = 1.5 (significant delay). The irreversibility boundary is set at θ = 3.0, representing the constraint threshold R(t) in the tolerance envelope formulation from the main framework.
Numerical Method
The system is integrated using Forward Euler discretization. At each time step, the delayed state θ(t − δ) is retrieved from a stored history buffer. Initial conditions are θ(0) = 0 and ω(0) = 0. The full time series output contains approximately 2,000 time steps per scenario (dt = 0.01 over 20 units).
Output Metrics
Five metrics are computed per scenario: peak θ (maximum positive deviation), minimum θ (maximum negative deviation), boundary crossing status and first crossing time (θ ≥ 3.0), integral absolute error IAE = ∫|θ|dt (cumulative deviation cost over the full horizon), and root mean square deviation RMS(θ). IAE and RMS together quantify the total system cost of misaligned correction across the simulation window.
Results
Table A1 reports the five output metrics for each delay scenario, and Figure A1 plots the corresponding angular deviation trajectories across the full time horizon.
Table A1
DDE Simulation Results by Perception Delay Scenario
Scenario |
Peak θ |
Min θ |
Crossed Boundary (θ ≥ 3.0)? |
First Cross Time |
IAE ∫|θ|dt |
RMS(θ) |
δ = 0.0 |
0.6035 |
−0.2726 |
No |
— |
2.3600 |
0.1961 |
δ = 0.5 |
0.8052 |
−0.7940 |
No |
— |
9.0081 |
0.5221 |
δ = 1.5 |
10.6191 |
−18.3297 |
Yes |
11.4557 |
85.3190 |
6.6449 |
Figure A1
Organizational Drift DDE Simulation (Forward Euler)
Select a delay scenario to show or hide its trajectory. The dashed line is the irreversibility boundary at θ = 3.0.
Note. Three scenarios under identical external disturbance. The shaded region marks the disturbance window (t = 1 to t = 3). The dashed line marks the irreversibility boundary at θ = 3.0.
Interpretation
The δ = 0.0 scenario confirms baseline model behavior. The external shock produces a bounded deviation that returns near zero. Peak θ reaches 0.60, IAE is 2.36, and the trajectory never approaches the irreversibility boundary. The corrective mechanism operates in real time and the system stabilizes.
The δ = 0.5 scenario remains bounded, but the cost rises sharply. IAE increases from 2.36 to 9.01, a nearly fourfold increase for a half-unit of additional delay. RMS triples. The system recovers, but the cumulative toll of delayed correction is already measurable in the output metrics. This is operationally analogous to the Critical State condition in the tolerance envelope formulation, where the organization is still within bounds but the buffer is narrowing.
The δ = 1.5 scenario demonstrates phase-misalignment runaway. The corrective mechanism applies restoring force based on a reading that is increasingly out of phase with actual system state. Rather than dampening drift, the delayed correction amplifies it. θ crosses the irreversibility boundary at t ≈ 11.456 and diverges thereafter, reaching extremes of +10.62 and −18.33 by t = 20. This result operationalizes the Failure State condition E(t) > R(t). The system does not cross the boundary because the external shock was too large. It crosses because the internal corrective structure responded to where the system was rather than where it is. The delay itself is the mechanism of catastrophic divergence.
Appendix BShow appendix
Case Application: Challenger Disaster (STS-51-L, January 28, 1986)
Overview
The Challenger disaster did not begin on the launch pad. By the time the shuttle broke apart, the more important failure had already been in motion for years. The O-ring problem was known, recurring, and documented. Erosion and blow-by in the solid rocket booster field joints were not isolated surprises. They were signals that had been seen often enough to become familiar, and familiarity is where organizations get into trouble. What starts as a warning can become background noise if the system learns to live with it.
That is what makes Challenger such a useful case for this model. The problem was not a total absence of information. The problem was that the information did not produce correction proportional to what it revealed. Corrective action was discussed, redesign concerns were raised, and anomalies were tracked, but recurrence remained. The system continued moving in the same direction while treating the absence of catastrophe as evidence that the risk was still manageable. The issue was not that the warning signs were invisible. The issue was that they were repeatedly absorbed without changing the operating logic of the organization.
Key Historical Signals
The historical record shows a pattern, not a one-time miss. The first in-flight O-ring erosion appeared on STS-2 in November 1981. Blow-by, meaning soot passing the primary O-ring, appeared on STS-41-D in August 1984. The worst blow-by observed before Challenger occurred on STS-51-C on January 24, 1985, at roughly 53°F O-ring temperature, which was the coldest launch before the final mission. During 1985, O-ring erosion appeared on nearly every flight, with secondary O-ring erosion also documented on STS-51-B in April 1985. Across these flights, the recurrence pattern did not show decisive reduction after intervention.
That matters because recurrence is one of the simplest ways to tell whether a system is actually learning. A known failure mode that continues after review, discussion, and corrective attention is no longer just a technical issue. It is evidence that the corrective structure is weaker than the forces sustaining the problem. At that point, the organization is not resolving the deviation. It is managing its continued presence.
Mapping Challenger to the Drift Model
In this case, the strategic goal trajectory, G(t), did not remain fixed. Early in the shuttle program, anomalies could still be interpreted within the mindset of an experimental system learning through use. Over time, that posture shifted toward an operational transportation model shaped by schedule demands, public confidence, political pressure, and program continuity. That shift mattered because it changed what kinds of problems the system was willing to absorb. Risks that should have remained disqualifying became negotiable once the program needed to appear routine. The tolerance envelope did not stay anchored to physics. It began expanding around precedent.
Observable behavior, B(t), was not hidden. The system had measurable signals: erosion depth, blow-by incidence, soot between rings, and an emerging temperature relationship that suggested performance degraded in colder conditions. Those signals were real enough to track, but the meaning of them was repeatedly softened. Instead of treating the trend as directional evidence of increasing risk, the organization reframed it as experience. That is a dangerous word in failing systems. Experience can mean knowledge, but it can also mean repeated exposure without consequence severe enough to force correction.
The angular deviation, θ(t), therefore widened gradually over time. There was no single dramatic rotation until the end. The drift accumulated through repeated instances in which known anomalies failed to produce proportionate redesign, failed to tighten constraints, and failed to alter the launch logic. In terms of the model, dθ/dt remained positive. The system kept rotating away from its stated safety requirements while preserving the appearance of operational continuity.
ERSI: Error Recurrence as Early Warning
The Error Recurrence Stability Index is especially useful in this case because Challenger was preceded by a known failure mode that kept returning. If error type k is defined as O-ring erosion and blow-by, then the relevant question is whether recurrence declined after corrective intervention. The record suggests it did not. Across the 1984 to 1986 period, recurrence remained approximately flat or worsened, which in this framework means dfₖ/dt ≈ 0 or > 0. That is a direct signal that corrective capacity was not outpacing the problem.
This is where organizations often misread themselves. They assume that because a problem has been discussed, the system has responded. It has not. The test is not whether concern exists on paper. The test is whether recurrence falls. If the same failure continues showing up after attention has already been directed to it, then the system is learning slower than the threat is developing. In Challenger, the recurring anomaly was not just a technical precursor. It was the record of a failed feedback loop.
IAC: Incentive Torque and the Pull Toward “Go”
The Incentive Alignment Coefficient helps explain why warning signals did not carry the weight they should have. Formal safety language remained in place, but the practical reinforcement structure was not neutral. Launch cadence, schedule adherence, institutional credibility, and program continuity all carried organizational value. Conservative delay decisions, even when justified, created friction against those priorities. In that environment, the system did not need anyone to openly reject safety. It only needed repeated pressure that made proceeding easier to reward than restraint.
That is what incentive torque looks like in practice. The rewards do not have to be written down in a crude form. People learn them anyway. They learn what gets treated as helpful, what gets treated as obstructive, and which kinds of judgment calls create organizational inconvenience. Under those conditions, the structure begins rotating behavior toward launch acceptance even when the technical case is weakening. The issue is not motive in the moral sense. The issue is what the system trained people to carry and what it trained them to set aside.
SCS: Strategic Coherence Breakdown
The Strategic Coherence Score is visible in the final decision process. Engineers at Thiokol expressed concern over low-temperature effects and recommended a no-go position below 53°F during the January 27 teleconference. Management at NASA and Thiokol moved in a different direction, reframing the burden toward proving the launch was unsafe rather than proving it was safe. That divergence was not a communication glitch. It was a split in how risk, evidence, and decision standards were interpreted across layers of the system.
A system can survive disagreement. It cannot survive disagreement about the meaning of its own constraints while still pretending everyone is aligned. That is what SCS is meant to expose. The same organization was using the same vocabulary while operating from different threshold assumptions. Engineers were reading the data as a warning. Management was reading the absence of prior disaster as usable precedent. Once those two logics coexist, alignment is already compromised even before the final decision is made.
Tolerance Envelope and Constraint Decoupling
The tolerance envelope, E(t), expanded over time, but the real constraint, R(t), did not. O-ring resiliency at low temperature was governed by physical reality, not organizational comfort. Yet repeated non-catastrophic launches encouraged a broader acceptance range. “It worked before” became a substitute for “it is safe under these conditions.” That is the exact kind of decoupling this model is built to identify. Tolerance drifted outward while constraint reality remained fixed.
This is the part organizations almost never admit in real time. They do not usually cross the boundary by deciding to become reckless. They cross it by teaching themselves that the boundary was probably more flexible than they first thought. That is how normalization works. Repetition dulls alarm. A narrow exception becomes an acceptable pattern. Then the pattern becomes the new baseline. By the end, the system is no longer asking whether it moved. It is asking whether it can justify staying where it already is.
Triangulation Failure
The model also highlights a triangulation failure. The dominant lagging signal was simple: there had been no loss of vehicle. That single fact carried too much interpretive weight. Meanwhile, the leading indicators and friction signals were already present: recurring anomalies, temperature concerns, engineering objections, and unresolved evidence around joint performance. Those signals existed, but they were not required to converge into a binding decision logic. The organization accepted divergence where it should have treated divergence itself as the warning.
A clean outcome can hide a dirty process for a long time. That is one of the central lessons here. Previous launches that ended without catastrophe did not prove the system was stable. They only proved that the final margin had not yet been exhausted. When organizations rely too heavily on lagging success, they confuse survival with control. Those are not the same thing.
Visual Proxy of Drift
If this case were reduced to a simple visual proxy, the x-axis would track flight sequence from STS-2 through STS-51-L, and the y-axis would represent a normalized deviation measure such as cumulative anomaly count or erosion-related recurrence severity. The tolerance envelope would begin relatively narrow, then widen over time as precedent accumulated. The actual trajectory would show stepwise increases with no decisive sustained decline. Even in a simplified snapshot mode, recurrence rate, temperature correlation, and objection logs would likely have surfaced a clear directional signal by mid-1985.
That matters because the purpose of a drift model is not hindsight elegance. It is earlier visibility. Challenger is often treated as a catastrophic event analysis. It was also a slow-moving pattern analysis that the system failed to respect.
Corrective Mapping
Viewed through this framework, the corrective implications become more concrete. A declining ERSI would have required accelerated redesign cycles and tighter follow-through on unresolved recurrence. A low IAC would have required the organization to rebalance what behaviors were effectively rewarded, especially where conservative safety judgment created schedule friction. High SCS variance would have required cross-layer alignment around evidentiary standards and launch thresholds. Tolerance-envelope drift would have required explicit re-anchoring to physical constraints, including a hard no-go threshold below validated temperature limits. Table B1 summarizes how each index maps to the documented Challenger signals and the resulting diagnostic output.
Table B1
Challenger Signals Mapped to the Drift Model
Metric |
Historical Signal |
Drift Status |
Diagnostic Output |
ERSI |
O-ring erosion and blow-by recurring on nearly every 1985 flight. |
≥ 0 (non-declining recurrence) |
Learning Friction: Redesign cycles failed to outpace the failure mode. |
IAC |
Rewards favoring launch cadence and schedule over conservative “no-go” calls. |
< 0 (inverse alignment with mission) |
Incentive Torque: System reinforced schedule adherence over safety thresholds. |
SCS (Variance) |
Engineers saw “warning”; management saw “manageable precedent.” |
High Variance |
Interpretive Drift: Strategy (safety) and operations (launch) decoupled. |
Constraint |
Tolerance expanded based on successful past launches at higher temps. |
E(t) > R(t) |
Boundary Migration: The “Failure State” was reached before ignition. |
Closing Observation
Challenger is often described as a failure of judgment. It was that, but the deeper issue was structural. The system had already adjusted into a position where recurring warning signals, incentive pressure, interpretive divergence, and expanding tolerance could coexist without forcing correction. By the final launch decision, the organization was not choosing from a stable safety posture. It was deciding from inside accumulated drift. That is the point of this appendix. The disaster was not only the explosion. The disaster was the long period in which the system kept receiving directionally meaningful signals and kept teaching itself they did not yet mean enough.
Appendix CShow appendix
Case Application: Wells Fargo Cross-Sell Scandal (2011–2016)
Overview
The Wells Fargo case extends the model out of safety-critical engineering and into a commercial, incentive-driven setting, which is where it matters that the same mechanics apply. Nothing exploded. The bank stayed profitable, its stock rose, and its signature metric, products sold per household, kept climbing. Underneath that surface, the system had reorganized around a reward structure that paid for product count rather than customer benefit, and it kept doing so for years while the headline numbers said the strategy was working. The failure was not an event. It was a direction the organization held long after the signals said to turn.
Key Historical Signals
The record is well documented. Between 2011 and 2016, Wells Fargo employees opened roughly 1.5 million unauthorized deposit accounts and about 565,000 credit-card accounts to meet sales targets. Those figures, more than two million accounts, were the initial identification; later estimates raised the total impact to approximately 3.5 million accounts (CFPB, 2016). In September 2016 the bank paid $185 million to settle with the Consumer Financial Protection Bureau, the Office of the Comptroller of the Currency, and the City and County of Los Angeles, and disclosed that it had already terminated about 5,300 employees (CFPB, 2016). The driving target was the cross-sell goal promoted internally as eight products per household, enforced through hourly tracking, supervisor pressure, and bonus-weighted compensation (Wells Fargo Independent Directors, 2017). Warnings preceded the settlement by years. A 2013 Los Angeles Times investigation exposed the sales pressure, the Los Angeles City Attorney sued in 2015, and employees had escalated quota pressure to senior leadership as early as 2010 (Wells Fargo Independent Directors, 2017; OCC, 2020). The 2017 independent directors’ report traced the problems back roughly fifteen years, and the Department of Justice’s 2020 resolution had the bank admit misconduct spanning 2002 to 2016 (U.S. Department of Justice, 2020).
Mapping to the Drift Model
The stated goal trajectory, G(t), was deepening genuine customer relationships. The reference the system actually optimized was product count. Observable behavior, B(t), looked healthy on the metric the bank watched most closely: the cross-sell ratio rose and revenue climbed. That is the dangerous configuration the model is built to expose. The headline indicator stayed clean while the deviation widened beneath it. The angular deviation, θ(t), grew year over year as the reward structure pulled behavior further from the stated mission, and dθ/dt stayed positive through the entire pre-settlement period. In practical terms, θ(t) can be observed as the widening gap between reported cross-sell performance and verified customer-initiated demand. The dashboard leadership trusted was the last place the drift showed up.
IAC: Incentive Torque as the Primary Driver
This case is the clearest possible illustration of incentive torque, because the reward structure did not merely fail to support the objective. It actively rewarded the behavior that destroyed it. Compensation, recognition, and job security were tied to a product-count target that could be satisfied by opening accounts customers never wanted. In the model’s terms, the relationship between measurable contribution to the stated mission, P, and reinforcement, R, was not weak. It was negative. The system paid most reliably for exactly the behavior that eroded customer trust, and it penalized the restraint that would have protected it. Regulators later described employees as intimidated and badgered into compliance, with the sales goals defended because they fueled the bank’s profits (OCC, 2020).
The informal channel compounded the formal one. The cross-sell metric was the organization’s source of pride and the basis of executive standing, which meant questioning it carried reputational cost while hitting it carried reward. That is incentive torque operating through attention and status, not only through pay. The decisive point for the framework is causal rather than correlational. The incentive structure did not sit alongside the drift. It generated it. That is why IAC is the load-bearing index in this case, and why the model treats incentive torque as a force acting on θ rather than a symptom read off after the fact.
ERSI: Recurrence Despite Correction
For years, the bank’s response to the problem was to terminate the employees who committed the violations. About 5,300 were fired, and the behavior did not stop (CFPB, 2016). Termination addressed the outputs of the system, not its inputs. Because the incentive structure was left unchanged, recurrence of the known failure mode did not decline after corrective action, so dfₖ/dt stayed at or above zero, and the system kept producing the same failure faster than terminations removed it. That is learning friction in its purest form. The organization treated firing individuals as correction while leaving the force that produced the behavior, the incentive structure, fully intact. Removing the people who answered the incentive could never reduce recurrence, because the incentive kept producing new responders. A declining recurrence rate would have said what the terminations concealed: the corrective structure was weaker than the torque sustaining the problem.
SCS: Leadership and Frontline Divergence
The same words meant different things at different levels. The 2017 board investigation found that directors had believed only two to three hundred employees were involved and that the problem was largely confined to Southern California, when it was systemic and an order of magnitude larger (Wells Fargo Independent Directors, 2017). The chief executive read the cross-sell model as a success and reportedly characterized the division head internally as the “best banker in America,” while the frontline experienced the same model as an unmeetable quota enforced under threat of termination (Wells Fargo Independent Directors, 2017). Leadership read solutions and relationships. The branch read comply or be fired. That divergence is exactly what SCS is meant to surface: high interpretive variance across layers, masked by shared vocabulary, with the leadership stratum reporting far healthier conditions than the floor. The view from the top looked manageable precisely because the cost was being absorbed below it. The divergence was not inert. It prevented accurate escalation, so corrective decisions were made on systematically biased inputs, and senior executives at times presented the board with reports that minimized the problem’s extent and root cause (OCC, 2020).
Tolerance Envelope and Constraint Decoupling
Each year of quota-gaming without consequence widened the tolerance envelope, E(t). Because no regulatory or reputational penalty had yet landed, the practice was treated as normal, and rising profits substituted for evidence that it was acceptable. The real constraint, R(t), set by law, regulation, and customer trust, never moved. The 2013 press exposure and the 2015 lawsuit were signals that should have narrowed tolerance and sharpened response. Instead, they were absorbed, because the metric the bank trusted still looked strong. Those signals were opportunities to contract the tolerance envelope, but because the performance indicators stayed favorable, they reinforced its expansion instead. The boundary crossing arrived in 2016 with the regulatory action and hardened through the 2018 Federal Reserve growth restriction and the 2020 settlements, by which point E(t) had moved well past R(t) (Federal Reserve, 2018; U.S. Department of Justice, 2020). The constraint did not relax. The organization had simply taught itself the boundary was further away than it was. Table C1 maps each index to the documented Wells Fargo signals and the resulting diagnostic output.
Table C1
Wells Fargo Signals Mapped to the Drift Model
Metric |
Historical Signal |
Drift Status |
Diagnostic Output |
ERSI |
About 5,300 terminations across 2011–2016 with no decline in violations. |
≥ 0 (non-declining recurrence) |
Learning Friction: firing individuals left the incentive force intact. |
IAC |
Pay, recognition, and security tied to a product count satisfiable by harming customers. |
< 0 (inverse alignment with mission) |
Incentive Torque: the reward structure generated the drift directly. |
SCS (Variance) |
Board believed 200–300 involved and regional; reality was systemic and roughly 5,300. |
High Variance |
Interpretive Drift: leadership “success” versus frontline “comply or be fired.” |
Constraint |
Tolerance widened on rising profits; 2013 and 2015 warnings absorbed. |
E(t) > R(t) |
Boundary Migration: normalized until the 2016 regulatory crossing. |
Closing Observation
Wells Fargo failed the way the model predicts a healthy-looking organization fails. The metric leadership trusted kept rising while the system rotated away from the mission that metric was supposed to represent. The dominant force was incentive torque, and the corrective response, firing the people who answered the incentive, could not reduce recurrence because it never touched the force. Unlike Challenger, no safety threshold was at issue and nothing physical failed. The mechanics were identical. A reward structure pulled behavior off course, feedback was suppressed by fear and by leadership’s faith in its own metric, interpretation fragmented across layers, and tolerance expanded until an external boundary the organization had stopped watching finally arrived. The disaster was not the 2016 fine. It was the years in which the system kept being paid to drift. More broadly, the case shows that in incentive-driven systems, drift is not always a deviation from performance. It can be the mechanism by which performance is achieved.