[{"data":1,"prerenderedAt":18},["ShallowReactive",2],{"post-the-firefighting-paradox":3},{"slug":4,"title":5,"excerpt":6,"content":7,"tags":8,"readingTime":15,"publishedAt":16,"published":17},"the-firefighting-paradox","The firefighting paradox, or: the operators we accidentally undervalue","A note on the version of the management problem where the people preventing fires are the people nobody sees, while the people putting out fires are the people who get promoted. The argument is not that firefighting is bad. The argument is that an organisation that rewards visible rescues over invisible prevention will, over time, end up with a team that has incentives to start fires.","\n## The observation\n\nThere is a line in the Chinese military classic — 善战者无赫赫之功, 善医者无煌煌之名 — that I keep coming back to in operations work. The best fighters do not have famous victories. The best doctors do not have famous names. The victories, when they happen, are quiet. The names, when they are remembered, are usually the names of the people who showed up after the quiet work had failed.\n\nThe line is, on the face of it, a piece of modesty rhetoric. The reason I have been holding onto it for the last year is that the line is, in my reading, also a precise description of the management failure mode I keep watching in operations teams. The failure mode is not the obvious one — the team that cannot put out a fire. The failure mode is the team that cannot *avoid* a fire, and the team that *rewards* the people who put out fires it should never have allowed to start.\n\nI have been watching a version of this in three different companies, in three different verticals, across the last few years. The pattern, in my reading, is the same pattern every time. The operations team that ships the most heroic rescues in a quarter is, more often than not, the operations team that produced the most crises in that same quarter. The team that does not have heroes is, more often than not, the team whose systems were designed by someone who does not need to be a hero to feel useful.\n\nThe pattern is not, I should say, a judgement on the operators. Most of the operators I have watched in this position are good at their jobs. The pattern is a judgement on the *incentive system* the operators are inside. The system rewards the rescue. The system does not reward the prevention. The system, in the long run, produces more rescues.\n\n## What I am trying\n\nI am trying to name a version of the management problem that I have not seen named well in the operations literature I have read. I have been calling it the *firefighting paradox* in my head — mostly as a placeholder, but the name has stuck. The paradox, stated as a sentence, is this:\n\n> The same organisation that rewards its best fire-preventers the least is the same organisation whose fire-preventers, over time, stop fire-preventing.\n\nThe line is, in my reading, the inverse of the principle I keep returning to in [[why-dirty-work-deserves-serious-consideration|the dirty-work piece]]. There, the argument was that dirty work belongs to the system. Here, the argument is that *invisible* work — the work of preventing the crisis that never quite materialised — belongs to a system of evaluation that the manager is supposed to design. The system of evaluation, in most teams I have watched, is not designed. The system of evaluation is a leftover from the moment the team was small enough that the manager could see the work. The moment the team grows past the point where the manager can see, the system of evaluation stops being a system of evaluation and starts being a system of *visible work*. Visible work, in operations, tends to be firefighting.\n\nThe same line is, I think, the inverse of the principle I tried to articulate in [[why-kpi-deserves-serious-skepticism|the KPI piece]]. The KPI, in failure mode A, was a system that pretended to be a workaround for the manager's inability to see. The KPI, in failure mode B, was a system that welded the workaround to the compensation. The firefighting paradox is, in my reading, the third version of the same pattern — the version where the system of evaluation, in trying to make the manager's job tractable, has made invisible work invisible, and the manager, in turn, has stopped seeing it.\n\nI am also trying, in the same piece, to be honest about a temptation I have felt in my own work — and I expect the temptation is, in some form, present in most operators who have ever been paid to look after something that is mostly working. The temptation is this: when a small problem is solvable, the operator has the option of solving it quietly and getting no credit, or letting it sit for a week, watching it grow into a medium problem, and then solving it loudly in front of the people who need to be reminded the operator exists. The first option is, in the long run, the right thing. The second option is, in the short run, the more visible thing. The second option is, over time, the option the system selects for. The system does not need to be evil. The system only needs to reward the visible work, and the operator, in private, will eventually figure out which work is visible.\n\nThe temptation is, in my reading, the version of the dirty-work problem that operates on the operator's incentives rather than the operator's hours. The dirty-work piece was about hours. This piece is about *attention*. The two pieces are, I think, the same piece, looked at from two sides of the org chart.\n\n## The principle, in one sentence\n\nHere is the principle, stated positively.\n\n> The manager's job is to design a system of evaluation that rewards the absence of crisis, not the resolution of crisis — and to do so without making the absence of crisis a performance of its own.\n\nThe first half of the sentence is the easy part. The second half is the hard part, and I have not seen a team do it well yet. The risk of building a system that rewards the *absence* of crisis is that the operator, in turn, learns to *avoid* crisis the way an employee learns to avoid work — by being invisible, by being unhelpful, by being the kind of person nobody can point to and say is the reason things went well. The system, in trying to reward prevention, produces a different version of the same failure mode: the operator stops doing anything at all, in case the doing produces a crisis that gets attributed to them.\n\nThe principle has to be held loosely. I am less sure than I was a year ago that the principle can be made fully operational, in the way the dirty-work principle can be made operational. The dirty-work principle can be operationalised by building a system that takes the work. The firefighting principle has to be operationalised by building a *judgement* — the judgement of a manager who can tell the difference between a person who is preventing fires and a person who is being unhelpful. The judgement is, in my reading, the part the system cannot replace.\n\n## What this looks like, in practice\n\nThe principle shows up in three places. I have been watching all three.\n\n**The first place is the evaluation system itself.** The KPI, in the version I see most often, is a list of visible numbers — number of issues resolved, number of campaigns shipped, number of crises averted by date. The list, in the version of the team I have been watching for the last year, is dominated by *resolution* numbers. The resolution numbers, in turn, are dominated by the crises that did happen, and the operator's score, in turn, rises and falls with the crisis calendar. The operator learns, in private, to keep the crisis calendar full. The system has not been designed to reward prevention. The system has been designed to reward what the manager can see, and what the manager can see is what came over the horizon.\n\nThe fix, in my reading, is to add two new columns to the KPI — and to weight them seriously. The first is *process indicators* — the small, measurable signals that the operator is doing the quiet work. The number of monitoring alerts triaged. The number of weekly audits run. The number of customer conversations that surfaced a small problem before the small problem grew. The second is, harder, *counterfactual outcomes* — the number of crises that did not happen, attributed to the operator's prevention. The counterfactual is, by construction, hard to measure. The point, in my reading, is not to measure it precisely. The point is to *acknowledge* that it is there. The manager who acknowledges it is the manager who, in the operator's experience, is a manager worth working for.\n\n[[why-kpi-deserves-serious-skepticism|The KPI piece]] I wrote a few months ago goes deeper on why this is, in my reading, the right way to think about KPI in general — the principle there was that the KPI is a workaround for the manager's inability to see, and the right response to a broken workaround is to fix the seeing, not the form. The firefighting paradox is, in my reading, the same principle applied to a different surface.\n\n**The second place is the incentive structure around visible rescues.** When the team that puts out a fire is, every quarter, publicly thanked, given a bonus, given a promotion, the team learns — quickly, probably within a quarter — that the fire is the asset. The fire is the moment the operator becomes visible. The fire is the moment the operator gets to demonstrate competence in front of the people who decide whether the operator is good at the job. The team that *prevents* the fire has, by construction, no such moment. The prevention is invisible. The prevention is the thing nobody ever sees.\n\nThe fix is, in my reading, not to stop rewarding the fire-rescuer. The fire-rescuer is, in the moment of the fire, doing the work the team needs. The fix is to also reward the fire-preventer — visibly, structurally, at the same level. The fire-preventer, in the version of the team I have been watching, is the person who changed the process so the fire would not happen again. The fire-preventer is the person who, six months ago, quietly wrote the postmortem that became the new standard. The fire-preventer is the person who, in private, told the manager that the system was about to break. The fire-preventer is, in most teams I have watched, the person the manager has the *least* to say about, because the manager has the *least* to point to.\n\nI have been watching this version of the failure mode close, slowly, in companies I have worked with. The closure is, in my reading, almost always the same closure. The fire-rescuer gets promoted. The fire-preventer gets a good review. The fire-rescuer, in two years, is a senior manager. The fire-preventer, in two years, is looking for a job — because the prevention, by construction, does not compound into promotion material.\n\n**The third place is the conversation between manager and operator.** The 1-on-1, in most teams I have watched, opens with a question like *what did you ship this week?* or *what are you working on?*. The question, in my reading, is a *visible-work* question. The question presupposes that the work the operator is doing is the kind of work that can be summarised in a sentence and pointed to in a meeting. The question, in turn, rewards the operator for having such work. The operator, in private, learns to manufacture such work. The small fires, in the operator's account, become medium fires, and the medium fires, in the operator's account, become large fires, and the large fires, in the operator's account, become heroic rescues. The narrative is, in my reading, the narrative the question produces.\n\nI have been changing the question, in the last few months, to something closer to *is there a problem you noticed early and quietly handled before I saw it?* The question, in my reading, is a *prevention* question. The question presupposes that the work the operator is doing includes a category of work that is invisible, that the work is real, and that the manager is interested in hearing about it. The operator, in turn, has a category of work to report on. The operator, over time, has a reason to be good at the invisible work, because the invisible work is, in this version of the 1-on-1, what the manager is paying attention to.\n\nThe change is, I should be clear, small. The 1-on-1 is still thirty minutes. The agenda is still mostly operational. The question, in itself, is one question out of eight or ten. The change is small in the meeting and large in the operator's incentive structure. The operator, in my experience, notices the change within a quarter. The operator, in my experience, also notices whether the change is real — whether the manager is *actually* interested in the invisible work, or whether the manager is performing interest for the meeting. The operator, in my experience, is very good at distinguishing the two.\n\n## What I am not saying\n\nI am not saying firefighting is bad. The fire, in the moment it happens, is the fire the team has to put out. The operator who puts out the fire is doing the work the team needs. The reward, in the moment, is deserved.\n\nI am not saying the fire-preventer is morally superior to the fire-rescuer. The fire-preventer is, in most cases, the operator who had the benefit of a system the fire-rescuer did not have. The fire-preventer is, in most cases, the operator who got the new monitoring tool, the new process, the new hire that took the old dirty work off the operator's plate. The fire-preventer, in most cases, is the operator who was hired into a team that had already done some of the system work, and the fire-rescuer, in most cases, is the operator who was hired into a team that had not. The difference is, in many cases, a difference in starting conditions, not a difference in virtue. I do not want to be read as saying otherwise.\n\nI am not saying the manager is the villain. The manager, in most cases, is the person who is *trying* — trying to see the work, trying to reward the right work, trying to design a system of evaluation that captures both the visible and the invisible. The system of evaluation, in most cases, is a system the manager inherited. The system of evaluation, in most cases, was designed for a smaller team, when the manager could still see the work. The system of evaluation, in most cases, is now a workaround for a problem the manager has not yet solved. I do not want to be read as blaming the manager for a problem the system produced.\n\nI am also not saying the firefighting paradox is the only thing happening in an operations team. Most operations teams have, in my experience, a mix of crises, a mix of quiet work, and a mix of operators who are good at one or the other. The principle, in my reading, is about *incentives*, not about *people*. The principle is about designing a system of evaluation that does not push the operator, in private, towards the visible work at the expense of the invisible. The principle is, in the last analysis, about the team's incentive structure, not about the operator's character.\n\n## Where this connects\n\nThe closest cousin on this site is [[why-kpi-deserves-serious-skepticism|the KPI piece]]. The KPI, in failure mode A, was a hollow form. The KPI, in failure mode B, was a system with teeth that cut the wrong thing. The firefighting paradox is, in my reading, the third failure mode — the failure mode where the system of evaluation, in trying to capture the work the manager can see, has made the work the manager *cannot* see invisible, and the operator, in turn, has been pushed, in private, to manufacture the visible work. The three failure modes are, in my reading, the same failure mode applied to three different surfaces. The fix is the same fix: design a system of evaluation that does not, by construction, push the operator towards the wrong work.\n\nThe next-closest cousin is [[why-dirty-work-deserves-serious-consideration|the dirty-work piece]]. The dirty-work piece was about hours. The dirty work consumes the hours of the operator, and the operator's role, over time, is defined by the dirty work. The firefighting paradox is about incentives. The incentive structure consumes the operator's attention, and the operator's role, over time, is defined by the work the incentive structure rewards. The two are, in my reading, the same argument applied to two different layers of the operator's day — one is the layer of *time*, the other is the layer of *attention*. Both are, in my reading, instances of the same principle: the system should be designed to push the operator towards the work the team actually needs, not towards the work the system happens to make visible.\n\nThe next piece down the line is [[paved-paths-in-the-agent-era|the paved-paths piece]]. The paved-paths argument was that the company needs a role whose job is to lay the infrastructure that takes the work the team should not be doing off the team's plate. The firefighting paradox is, in my reading, the *evaluation-side* companion to the paved-paths argument. The paved-paths piece was about the system that prevents the dirty work. This piece is about the system that *rewards* the prevention. The two pieces, together, are the same argument from two ends: build the system that prevents the crisis, and design the evaluation that rewards the prevention. Either one, alone, is half-built.\n\nThe agent-pipeline piece — [[pushing-requirements-down-through-agents|the structured form, the review agent, the coding agent, the architect]] — is the same principle at a smaller surface. The pipeline exists, in part, to take the dirty work off the operator's plate so the operator can do the work the team needs. The pipeline also exists, in part, to surface, in the data, the small problems the operator prevented before they grew. The pipeline, in my reading, is a worked example of the prevention system. The evaluation system that goes around the pipeline is the part I have not yet built, and the part this piece is, in part, an attempt to design.\n\nThe 16:00 break — [[the-16-00-break|the half hour in the middle of the long afternoon]] — is a related move. The half hour is the moment the operator switches from focused mode to diffuse mode, and the diffuse mode, in my reading, is the mode in which the small problem is most likely to be noticed before the small problem grows. The 16:00 break is, in part, a system that *protects* the operator's ability to notice. The firefighting paradox is, in part, the consequence of an evaluation system that does not protect the operator's noticing. The two are, in my reading, the same argument about *attention* applied to two different moments of the operator's day.\n\n## What the literature already says\n\nI did not invent any of this. The framing here is borrowed, openly, from work that has been around much longer than I have.\n\n**Henry Mintzberg, *The Nature of Managerial Work*.** Mintzberg's study of what managers actually do — as opposed to what management textbooks say they do — is, in my reading, the most honest version of the principle I am trying to articulate here. The manager's work, in Mintzberg's reading, is fragmented, intuitive, context-driven, and largely invisible. The fragmentation is, in his reading, the *defining feature* of managerial work, not a bug. The firefighting paradox is, in my reading, the moment the manager stops seeing the fragmentation as a feature and starts treating the visible fragments as the work. The visible fragments are, by construction, the fires. The invisible fragments are, by construction, the prevention. The manager who treats the visible fragments as the work is, in Mintzberg's reading, the manager who has lost track of what the work is.\n\n**Donald Schön, *The Reflective Practitioner*.** Schön's argument, which I have come back to repeatedly in the last two years, is that the work of the professional is not the application of a rule. It is the recognition of the situation, the framing of the problem, the naming of the trade-offs. Schön calls this *reflection-in-action*. The firefighting paradox, in my reading, is the moment the system of evaluation stops rewarding the reflection-in-action and starts rewarding the application of the rule. The application of the rule, in operations, is the put-out-the-fire protocol. The reflection-in-action is the small adjustment that prevents the fire from happening in the first place. The system of evaluation that rewards the protocol over the reflection is the system that, over time, produces more fires and less reflection. Schön would recognise the failure mode instantly. He would also recognise the fix: the system of evaluation has to be designed to reward the reflection, in a form the system can see.\n\n**Chris Argyris, *Flawed Advice and the Management of Professional Crises* (and the double-loop learning work).** Argyris's distinction between single-loop learning (fix the symptom) and double-loop learning (fix the system that produced the symptom) is, in my reading, the most precise version of the principle I am trying to articulate. The single-loop learner is the fire-rescuer — the operator who, every time the fire happens, gets better at putting it out. The double-loop learner is the fire-preventer — the operator who, after the fire, goes back to the system that produced the fire and changes the system so the fire cannot happen again. The system of evaluation that rewards single-loop learning, in Argyris's reading, is the system that produces more single-loop learners. The system of evaluation that rewards double-loop learning is the system that produces fewer fires, and fewer fire-rescuers, and more operators whose work is, by construction, invisible.\n\n**Michael Polanyi, *The Tacit Dimension*.** Polanyi's argument that *we know more than we can tell* is, in my reading, the deepest layer of the principle. The fire-preventer, in the version of the team I have been watching, is the operator who has, over years, built a tacit model of the system that the operator cannot fully articulate. The tacit model is, by construction, the source of the prevention. The tacit model is, by construction, also the part of the operator's work that no system of evaluation can capture — because the model is, by Polanyi's argument, the part of the knowing that cannot be put into words. The system of evaluation that punishes the tacit model is the system that pushes the operator out. The system of evaluation that, at least, *acknowledges* the tacit model — without pretending to measure it — is the system that keeps the operator in the room.\n\nI am not going to re-explain them here. The point is the same point.\n\n## A postscript, on the version I have not yet named\n\nI want to add one more thing, even though I am not sure how to make it fully operational.\n\nIf a manager's team has, every quarter, someone who is publicly rescuing a fire — if the team's narrative, every quarter, has a hero — I would expect the manager to ask a question that the narrative tends to suppress. The question is: *what is it about the system that produced a fire worth rescuing?*\n\nThe question is uncomfortable, because the question implies that the system the manager is responsible for is the thing that produced the fire, and the manager, by implication, is part of the reason the fire happened. The question is also, in my reading, the question that the 善战者无赫赫之功 line is trying to put into the manager's head. The line is not about the operator. The line is about the *system* the operator is inside. The line is about the system that has, by its design, produced a fire worth rescuing, and the system that has, by its design, rewarded the rescue.\n\nI would expect, in a team that has been well designed, the absence of a fire to be unremarkable. The absence of a fire is, in a well-designed system, the default. The team that has a hero every quarter is, in my reading, a team whose system has, by its design, produced a fire worth having a hero for. The team that has no hero is, in my reading, a team whose system has, by its design, removed the conditions for the fire. The difference is not the operator. The difference is the system the operator is inside. The manager, in my reading, is the person who owns the system. The manager, in my reading, is also the person who, every quarter, is implicitly endorsing the system by the way the manager rewards the work the system produces.\n\nI do not have a formula. I do not have a checklist. I do not have a way to make the principle operational, in the way the agent makes the system operational. The principle, in my reading, is the kind that has to be held by a person — held loosely, and held against the temptation of the moment. The temptation, in this case, is the temptation to look like the manager whose team has heroes. The principle, in this case, is the principle that the manager whose team has heroes is, more often than not, the manager whose system is producing the fires the heroes are putting out.\n\nI am going to keep stating it. In the systems I help run. In the 1-on-1s I have. In the small decisions about what to reward and what to not reward. The principle is, in my reading, the most under-stated version of the dirty-work principle, and the one most likely to be forgotten the moment a fire actually happens. The principle, in my reading, is also the one the team will, in the long run, be quietly grateful for — even if the team will never, in any single quarter, be loudly grateful.\n\nThe hardest part is not the principle. The hardest part is holding the principle in the moment the fire is actually happening, when the hero is actually saving the day, and the temptation to celebrate the hero is the strongest.\n    ",[9,10,11,12,13,14],"Process","Org Design","Team Design","KPI","Dirty work","Note to self",9,"2026-07-15",true,1786196470091]