Grounded ehs-human-factors-ontology Story
Why people err, as a graph
An investigation says the operator made a mistake. That is a label, not a cause. This repository writes the conditions people work under as a graph, so the reasoning from condition to consequence can be read back line by line.
Counts read from docs/crosswalk-data.json and docs/walkthrough-data.json. Press P for presenter mode, M for the site map.
All 20 risk factors are conditions you can check before the job
Each factor sits in one of four context dimensions and carries a level, an observable proxy and a citation, so a claim about it can be evidenced from records a site already keeps.
Performance influencing factors by context
All 20 factors are conditions, not judgements about a person
Every node can be assessed before the job from a work order, a roster, a permit record or a lighting survey.
5human-context factors are the ones the organisation sets
Procedures, staffing, team and organisation, training, work processes. These are the conditions most often written up as root causes after the fact, and the easiest to evidence before it.
5operational factors already have a measured proxy on most sites
Noise, resistance to movement, thermal conditions, access and visibility. Dosimetry, WBGT, illuminance surveys and permit records cover all five.
3system factors cover what the plant tells the person
Equipment and tools, human-system interface, system transparency. It is the smallest group, and transparency has the weakest evidence base outside nuclear work.
7task factors make the largest group of the four
Familiarity, complexity, time pressure, mental fatigue, multitasking, physical demands and information availability. One non-routine job can move several of the seven at once, and that combination is what the rule set exists to catch.
31 links tie those 20 factors to 5 cognitive functions
A degraded condition matters through the work it makes harder, and 11 of the 20 factors bear on more than one function, so a single bad condition rarely stays in one place.
Which function each factor bears on
31 links spread the 20 factors across 5 functions
Detection, understanding, decision making, action execution and coordination. Eleven factors attach to more than one of them.
6 factors decide whether the cue reaches the person at all
Visibility, noise, interface, information availability, mental fatigue and multitasking. Nothing downstream recovers a cue that never arrived.
6 factors decide whether the picture the person builds is right
Training, system transparency, information availability, scenario familiarity, task complexity and time pressure. A plant that does not show its state forces the person to infer it.
5 factors reach decision making, and 4 of them fail in the next scene
Procedures, training, scenario familiarity, task complexity and time pressure. Four of those five are assessed below nominal in the worked scenario.
Action execution carries 10 factors, coordination only 4
Action execution has the most attached factors, mostly physical and access conditions. Coordination has the fewest and the thinnest literature support of the five, which is written on the page rather than hidden.
One scenario fires 21 rules and 89 inferences to a stop-and-review band
Every step names the rule that produced it and the premises it used, so a screening decision can be argued with instead of taken on trust.
From assessed levels to a screening band
4 of the 20 factors are assessed below nominal
A batch reactor restart after an unplanned trip. The operator qualified three weeks ago and has not run the recovery, the sequence has no approved procedure, and the outage window is fixed by a downstream commitment. The other sixteen factors are nominal.
Rules R01 and R02 turn those 4 levels into facts
Scenario familiarity is severely degraded. Procedures, training and time pressure are degraded. The ordinal ranks come from the ontology, not from the rule.
Rules R07 and R08 challenge 3 of the 5 functions
Understanding, decision making and action execution are all challenged. Three functions, from four conditions.
3 rules turn unfamiliar work into an aggravated error mode
Low familiarity pushes the operator out of rule-based control, and degraded training leaves that demand unsupported. R23 names the combination: an unsupported knowledge-based demand under time pressure. This is where two ordinary-looking conditions stop being independent.
Rule R33 returns a screening band of stop and review
A severely degraded factor with no mitigation, plus an aggravated error mode. R24 also fires: with familiarity and procedures both degraded there is no rule-based fallback. The band is a screening output, not a probability, and the trace above is the whole argument for it.
Only 31 of 80 crosswalk cells are close matches to prior frameworks
Twenty-three map to a broader parent term, twenty are partial and six have no counterpart, so an assessment carried between frameworks can change meaning without anyone noticing.
Match strength against prior frameworks
31 of 80 cells are close matches
Twenty-three map to a broader parent term, twenty are partial, and six have no counterpart at all.
13 of 20 factors match the HSE list closely
The highest count of the four frameworks. Both lists are written for industrial work rather than for a control room.
5 factors have no SPAR-H counterpart at all
SPAR-H carries eight performance shaping factors written for a control room. A chemical plant floor has conditions it never had to name.
8 HFACS cells map only to a broader term
HFACS has no procedures category at the precondition level, so the nearest home is the organisational operational process. It describes a different level of the system.
CREAM covers every factor, but only 6 of 20 closely
Eight cells map to a broader CREAM term and six are partial. A close match lets a reader carry an existing assessment across; a broader or partial one warns that the two terms are not interchangeable. Recording the weak rows is what makes the strong ones usable.
What this does not establish
Read this before quoting anything above
- The worked scenario is an illustrative example written by hand for this repository. It is not a record of a real event at any site and contains no site data.
- The screening band is a screening output. It is not a human error probability and it is not calibrated against outcomes.
- The rule set encodes relationships stated in published human reliability work. Encoding them does not validate them. No prospective study has been run against incident data.
- Factor levels are assessed by a person. The graph reasons faithfully from whatever levels it is given, including wrong ones.
- The crosswalk is a judgement about terminology made by one author and recorded so it can be disputed. Partial and broader rows are the ones most likely to be wrong.
- Inter-team coordination has the fewest attached factors and the thinnest supporting literature of the five functions.
Ask which condition, not who
Take your last three serious investigations and re-read the conclusions.
For each one that ends in a label about a person, name the conditions instead: was the task covered by a procedure, had the operator run it before, was the window fixed by someone downstream. Those three questions are factors in this graph, and each has a record on your site that can be pulled. If two or more come back degraded on the same job, that job was a stop-and-review before anyone touched it.