THE FAILURE MARGIN
Read Chapter 27: THE LAST REVIEW
At seventy-eight, Luc was invited to serve on an independent review of a European spacecraft failure.
He almost declined.
Then he read that the vehicle had been lost after a software command encountered an unexpected sensor state. No crew had been aboard. The investigation involved conflicting simulation results and pressure to classify the event as a rare corner case.
He accepted.
The technology was nearly unrecognizable from Apollo. Digital buses, software builds, automated telemetry, simulation farms. Young engineers carried more computing power in laptops than entire 1960s control rooms had possessed.
The organizational arguments sounded exactly the same.
“The condition was outside expected operational space.”
“The probability is negligible.”
“The simulation that failed used an unrealistic input combination.”
Luc listened.
Then he asked, “Was the failed simulation run before launch?”
Silence.
A software lead answered. “Yes.”
“Was it in the readiness package?”
“No.”
“Why?”
“It was classified as non-representative.”
“Who classified it?”
Another silence.
Luc felt the decades collapse.
Different machine.
Same temptation.
He did not accuse anyone. He asked them to reconstruct the decision exactly: what was known, who knew it, what assumptions justified exclusion, and whether anyone outside the schedule chain reviewed the classification.
The final report concluded that the launch failure resulted not from a single software defect but from an organizational failure to preserve dissenting test evidence.
A journalist later asked Luc whether he was surprised.
“No,” he said.
“Disappointed?”
“Always.”
“Do we never learn?”
Luc considered the question.
“We learn. Then new people arrive and must learn again.”
The independent spacecraft review in Luc’s final years became famous inside European aerospace circles because he refused to let the board use the phrase “human error” in its executive summary.
“The software team excluded a failed simulation,” one director argued. “That was human error.”
“Which human?” Luc asked.
“The responsible engineer.”
“Why did he exclude it?”
“He believed the input was unrealistic.”
“Why?”
“The mission model did not include that sensor combination.”
“Who approved the mission model?”
A systems group.
“Who required schedule closure before all corner cases were classified?”
Program management.
“Who designed the review process so the same group that owned schedule also approved exclusions?”
Silence.
Luc folded his hands.
“If you write human error, the next program will remove one human and preserve the system that produced the decision.”
The final report instead described a chain of incentives, assumptions and missing independent review.
Young engineers grumbled that the wording was too long.
Luc replied, “Reality is often longer than blame.”
That line, like many of his remarks, circulated later without attribution.
He preferred it that way.
In his final months, Luc kept one last habit from Houston. Whenever a newspaper announced a spacecraft failure, he ignored the first explanation. Early explanations, he said, were emotional placeholders. They protected people from uncertainty until evidence arrived.
Claire once asked whether that made him distrustful.
“No,” he said. “Patient.”
He had spent a career learning that the first story was rarely the final mechanism. A broken component might reveal a design weakness. A design weakness might reveal a test gap. A test gap might reveal a contract incentive. The further investigators traveled from the visible failure, the more human the system became.
That did not make engineering less exact. It made exactness more demanding.
Continue Reading Free
Unlock This Chapter
Watch a short ad to unlock this chapter.
No payment required.