Grounded ehs-human-factors-ontology Story

Story · 4 of 7 in the path

Why people err, as a graph

An investigation says the operator made a mistake. That is a label, not a cause. This repository writes the conditions people work under as a graph, so the reasoning from condition to consequence can be read back line by line.

Factors20
Contexts4
Crosswalk rows96
Inferences89

Counts read from docs/crosswalk-data.json and docs/walkthrough-data.json. Press P for presenter mode, M for the site map.

All 20 risk factors are conditions you can check before the job

Each factor sits in one of four context dimensions and carries a level, an observable proxy and a citation, so a claim about it can be evidenced from records a site already keeps.

Performance influencing factors by context

20factors in the graph
Source: docs/crosswalk-data.json, ontology/ehs-hfo.ttl
The shape

All 20 factors are conditions, not judgements about a person

Every node can be assessed before the job from a work order, a roster, a permit record or a lighting survey.

Human context

5human-context factors are the ones the organisation sets

Procedures, staffing, team and organisation, training, work processes. These are the conditions most often written up as root causes after the fact, and the easiest to evidence before it.

Operational context

5operational factors already have a measured proxy on most sites

Noise, resistance to movement, thermal conditions, access and visibility. Dosimetry, WBGT, illuminance surveys and permit records cover all five.

System context

3system factors cover what the plant tells the person

Equipment and tools, human-system interface, system transparency. It is the smallest group, and transparency has the weakest evidence base outside nuclear work.

Task context

7task factors make the largest group of the four

Familiarity, complexity, time pressure, mental fatigue, multitasking, physical demands and information availability. One non-routine job can move several of the seven at once, and that combination is what the rule set exists to catch.

31 links tie those 20 factors to 5 cognitive functions

A degraded condition matters through the work it makes harder, and 11 of the 20 factors bear on more than one function, so a single bad condition rarely stays in one place.

Which function each factor bears on

31factor to function links
Source: ontology/ehs-hfo.ttl, property ehs:appliesToFunction
Five functions

31 links spread the 20 factors across 5 functions

Detection, understanding, decision making, action execution and coordination. Eleven factors attach to more than one of them.

Detection

6 factors decide whether the cue reaches the person at all

Visibility, noise, interface, information availability, mental fatigue and multitasking. Nothing downstream recovers a cue that never arrived.

Understanding

6 factors decide whether the picture the person builds is right

Training, system transparency, information availability, scenario familiarity, task complexity and time pressure. A plant that does not show its state forces the person to infer it.

Decision making

5 factors reach decision making, and 4 of them fail in the next scene

Procedures, training, scenario familiarity, task complexity and time pressure. Four of those five are assessed below nominal in the worked scenario.

Action execution and coordination

Action execution carries 10 factors, coordination only 4

Action execution has the most attached factors, mostly physical and access conditions. Coordination has the fewest and the thinnest literature support of the five, which is written on the page rather than hidden.

One scenario fires 21 rules and 89 inferences to a stop-and-review band

Every step names the rule that produced it and the premises it used, so a screening decision can be argued with instead of taken on trust.

From assessed levels to a screening band

89inferences, 21 distinct rules
Source: docs/walkthrough-data.json (89 inferences, 21 distinct rules)
The input

4 of the 20 factors are assessed below nominal

A batch reactor restart after an unplanned trip. The operator qualified three weeks ago and has not run the recovery, the sequence has no approved procedure, and the outage window is fixed by a downstream commitment. The other sixteen factors are nominal.

Rules R01 and R02

Rules R01 and R02 turn those 4 levels into facts

Scenario familiarity is severely degraded. Procedures, training and time pressure are degraded. The ordinal ranks come from the ontology, not from the rule.

Rules R07 and R08

Rules R07 and R08 challenge 3 of the 5 functions

Understanding, decision making and action execution are all challenged. Three functions, from four conditions.

Rules R10, R11 and R23

3 rules turn unfamiliar work into an aggravated error mode

Low familiarity pushes the operator out of rule-based control, and degraded training leaves that demand unsupported. R23 names the combination: an unsupported knowledge-based demand under time pressure. This is where two ordinary-looking conditions stop being independent.

Rules R33 and R24

Rule R33 returns a screening band of stop and review

A severely degraded factor with no mitigation, plus an aggravated error mode. R24 also fires: with familiarity and procedures both degraded there is no rule-based fallback. The band is a screening output, not a probability, and the trace above is the whole argument for it.

Only 31 of 80 crosswalk cells are close matches to prior frameworks

Twenty-three map to a broader parent term, twenty are partial and six have no counterpart, so an assessment carried between frameworks can change meaning without anyone noticing.

Match strength against prior frameworks

80factor to framework cells
Source: docs/crosswalk-data.json (96 rows, 80 factor-framework cells)
All four

31 of 80 cells are close matches

Twenty-three map to a broader parent term, twenty are partial, and six have no counterpart at all.

HSE

13 of 20 factors match the HSE list closely

The highest count of the four frameworks. Both lists are written for industrial work rather than for a control room.

SPAR-H

5 factors have no SPAR-H counterpart at all

SPAR-H carries eight performance shaping factors written for a control room. A chemical plant floor has conditions it never had to name.

HFACS

8 HFACS cells map only to a broader term

HFACS has no procedures category at the precondition level, so the nearest home is the organisational operational process. It describes a different level of the system.

CREAM

CREAM covers every factor, but only 6 of 20 closely

Eight cells map to a broader CREAM term and six are partial. A close match lets a reader carry an existing assessment across; a broader or partial one warns that the two terms are not interchangeable. Recording the weak rows is what makes the strong ones usable.

All 80 crosswalk cells as a table
FactorFrameworkStrengthNearest term
Scene 05

What this does not establish

Read this before quoting anything above

  • The worked scenario is an illustrative example written by hand for this repository. It is not a record of a real event at any site and contains no site data.
  • The screening band is a screening output. It is not a human error probability and it is not calibrated against outcomes.
  • The rule set encodes relationships stated in published human reliability work. Encoding them does not validate them. No prospective study has been run against incident data.
  • Factor levels are assessed by a person. The graph reasons faithfully from whatever levels it is given, including wrong ones.
  • The crosswalk is a judgement about terminology made by one author and recorded so it can be disputed. Partial and broader rows are the ones most likely to be wrong.
  • Inter-team coordination has the fewest attached factors and the thinnest supporting literature of the five functions.
What a leader does Monday

Ask which condition, not who

Take your last three serious investigations and re-read the conclusions.

For each one that ends in a label about a person, name the conditions instead: was the task covered by a procedure, had the operator run it before, was the window fixed by someone downstream. Those three questions are factors in this graph, and each has a record on your site that can be pulled. If two or more come back degraded on the same job, that job was a stop-and-review before anyone touched it.