Home/Concepts/Feedback loops and system archetypes in emergency management
Feedback loops and system archetypes in emergency management
On the intake axis, control requires a closed loop, and a closed loop requires observation that does not stop. A frozen corpus cannot see the effect of anything it caused; a…
What arrives
An emergency operations centre during a hurricane, a wildfire, a chemical release, or a flood does not receive one signal. It receives several, on different clocks, in different formats, at different confidence levels. Hazard sensors — river gauges, seismographs, plume dispersion models, satellite fire-detection passes — arrive on cycles from minutes to hours. Population movement arrives from mobile network location data, traffic sensor counts, and cell broadcast acknowledgement rates, often lagged by fifteen to thirty minutes behind the actual movement. Infrastructure status — substation trips, water pressure, road closures — arrives as event-driven alerts mixed with stale polling: a substation that failed at 2.14 a.m. might not register until the next SCADA sweep. Forecasts arrive as probability cones, not points: a National Hurricane Centre track has a 48-hour position error historically averaging over 100 kilometres.
None of this is a corpus. None of it is a scene with a fixed boundary. It is streams, running concurrently, each with its own delay and its own decay rate for how long a reading stays trustworthy.
What is held
The emergency manager's operating picture is not the raw feed. It is a held state: a set of beliefs about where the hazard is, where people are, what infrastructure will take the load, and how confident each of those beliefs currently is. A river gauge reading from six minutes ago is treated differently from a gauge reading from six hours ago, even though both are "the current level" on the display. That difference — how much a stale observation should still count — is itself a variable being tracked, a decay function attached to each stream.
This is the core structural fact the archetypes make legible. A gauge reading, on its own, is an open arc: number in, number displayed, nothing regulated. It becomes part of a balancing loop only when it feeds a decision that changes the system's future state — issuing an evacuation order that moves population away from the projected inundation zone, which then shows up in the next population-movement reading as reduced exposure, which is compared against the forecast to check whether the order worked. The loop is: observe hazard, decide action, observe population response, compare against hazard trajectory, revise the action. Held state is what makes that comparison possible across the gap between decision and consequence.
What triggers revision
Revision is not continuous rebalancing of everything against everything; that would be noise-chasing, and it is the failure mode systems thinking warns about explicitly. Revision is triggered by threshold crossings against the held beliefs, with deliberate dead bands. A river gauge that rises 2 centimetres does not retrigger the evacuation model. A gauge that rises past a rate-of-change threshold — say, faster than the 90th percentile of historical rise rates for that basin — does, because rate of rise is a better predictor of flash flood timing than absolute level.
Provenance is what makes this defensible rather than arbitrary. Every revision to the evacuation trigger should be traceable to which stream moved it: this expansion of the zone followed the 3.40 a.m. gauge reading at station 14, cross-checked against the updated forecast cone at 3.52 a.m., not "the model updated." When an order later proves to have been too early, too late, or geographically wrong, provenance lets the after-action review find the specific observation-to-decision link that failed, rather than blaming "the system" undifferentiated. Without that record, every failure looks the same and nothing is learned that transfers to the next event.
What the operator sees
The interface an emergency manager works from is not the streams. It is a small number of derived quantities, each carrying its confidence and its age: projected arrival time of the hazard front at each zone, estimated evacuation completion percentage per zone, estimated clearance time given current road capacity and observed movement rate, and infrastructure capacity remaining along evacuation routes. Each of these is a belief, not a fact, and each should be shown as one: a clearance-time estimate with a stated range, not a single number implying false precision.
The characteristic failure of this domain — the evacuation order following the hazard rather than leading it — is exactly what happens when this operator view collapses to the newest observation and drops the derived, forward-looking belief. If the manager watches the gauge instead of the trajectory-and-clearance-time estimate, the order gets issued when the water is already rising visibly, which is the moment the loop should have already returned an action twenty minutes earlier. The gap between observation and order is where the balancing loop's delay lives, and if that delay is not designed for — buffered, anticipated, budgeted into the trigger threshold — the loop degenerates into what the archetype catalogue calls Fixes that Fail: the order goes out, it is late, the response is to wait for even clearer confirmation next time, which makes the next order later still.
What it costs
Running the loop has a real price, and pretending otherwise is the weak version of this argument that must be rejected. Continuous multi-stream intake means false alarms cost credibility: a wildfire evacuation zone drawn and then redrawn twice in three hours, each time on updated wind-model output, teaches residents that orders are noisy and can be discounted, a documented effect in post-event compliance surveys after several Californian fires. That cost is not hypothetical; it is the price of a badly tuned loop, not evidence that the loop should not exist.
Batch situation reports every two hours, reviewed by a human duty officer before release, are a deliberate brake against exactly this kind of thrash. Continuous automated revision is what produces Shifting the Burden — the operator stops trusting their own judgement and defers to the model's constant churn.
This is close to right and worth conceding most of. The fix is not removing the loop; it is loop design — a rate limit on how often the evacuation boundary can change, a dead band on rate-of-rise, a required human sign-off before any zone contraction (contractions are far more dangerous to get wrong than expansions), and provenance logging so that a reversed order is auditable rather than mysterious. A scheduled two-hour situation report is itself a loop, just a low-bandwidth one with a long fixed delay; the delay is the design choice, and in some hazards, riverine flooding with slow rise rates, that delay is entirely defensible. In a fast-onset hazard — a dam breach, a chemical plume with a wind shift — a two-hour cycle is too slow to be a balancing loop at all with respect to the hazard's own timescale, and the "brake" becomes an open arc by another name.
The second objection worth taking seriously concerns import: systems thinking's archetypes describe how organisations and ecosystems behave, and describing is not prescribing. That the National Guard's logistics loop or a floodplain's hydrology forms a Limits to Growth pattern does not by itself argue that an emergency management information system ought to be built as a continuous loop. That step is separate and conditional, not automatic. The conditional is narrow but holds here specifically: if the goal is regulating a hazard whose dynamics include delays — the time between rainfall and river crest, between wind shift and plume arrival, between order and completed evacuation — then the regulating system must itself close a loop over those same delays, because an open arc, whether a static plan or a periodic report shorter than the delay it needs to span, structurally cannot compensate for effects it never observes. That is what makes emergency management the domain where the Large World Model's scene-bounded loop is visibly insufficient: the fire does not end when the operator's shift does, the river does not reset when the situation report closes, and any system that stops observing at the scene's edge inherits the same blindness a frozen corpus has, just with a longer leash.