Who Pulls the Cord? Why Tech Companies Fail When Information Doesn't Flow

Using the Space Shuttle Columbia disaster as a case study, the article analyzes why information flow breaks down in tech companies — middle management filters out bad news, and leadership makes decisions based on optimistically sanitized data. It introduces formal models of information flow (Bell-LaPadula, Biba) and shows how organizational culture determines whether critical information reaches the person making the decision.
In 2003, NASA engineer Rodney Rocha sat at a monitor, looking at footage that frightened him. A piece of insulating foam the size of a suitcase had broken loose during the launch of the Space Shuttle Columbia and struck the left wing. Rocha recognized the danger. He requested satellite imagery to assess the extent of the damage. His request was denied. He requested again. Denied. In total, at least a dozen attempts — direct and indirect. Linda Ham, head of the mission management team, declared that there was no need to address it. Sixteen days later, Columbia broke apart on re-entry into the atmosphere. Seven astronauts died.
The CAIB investigation board reached a conclusion that ought to hang framed in every conference room: NASA's organizational culture had not fundamentally changed since the Challenger disaster of 1986. Structural reforms had taken place — committees, processes, and forms were added. But the culture in which bad news cannot rise to the decision-maker remained untouched.
This is not a story about the space program. It is a story about every organization where information is filtered on its way up — and about why this is especially lethal in technology companies.
In 2026, technology companies face extraordinary pressure. Artificial intelligence is rewriting the rules of the game, competitive cycles have shortened from years to months, and time-to-market decides survival. In this environment, an organization's ability to process information — accurately, quickly, without distortion — is the most valuable asset. Not the code, not the data, not the hardware. The flow of information.
Yet most companies manage the flow of information in a way that would cause a catastrophe in aviation and lose a war in the military. Middle management filters bad news. Leadership decides on the basis of presentations that have passed through several rounds of "optimistic correction." Engineers know about the technical debt, but have no channel through which to escalate the problem without risking their careers. Project reviews glow green while inside they are red — a phenomenon known in project management as watermelon reporting: green on the surface, red at the core.
There are formal models that describe precisely why this is so. There are organizations that have solved it. And there is hard data on what happens when an organization does not.
In 1973, David Bell and Leonard LaPadula developed for the U.S. Air Force a mathematical model governing the flow of classified information in computer systems. The Bell-LaPadula model rests on two rules: no read up (with a clearance of Secret, you cannot read Top Secret documents) and no write down (with Top Secret clearance, you cannot write into a Secret system). Information naturally flows upward — it accumulates at higher levels but cannot descend back down without special procedures.
Two years later, Kenneth Biba introduced a model that is the exact mirror image: it addresses integrity instead of confidentiality. Biba defines no read down (a high-integrity subject should not read unverified data) and no write up (a low-integrity subject cannot alter high-integrity records). Here information flows naturally downward — a general gives an order to a colonel, but a private does not issue orders to a sergeant.
Why does this matter for a technology company?
Because every organization implicitly applies one of these models — and most do it wrong.
The military naturally applies Bell-LaPadula: intelligence flows upward, and classification protects sources. Corporations naturally apply Biba: verified directives, strategies, and decisions flow downward, and data integrity is the priority. But the most successful organizations — from the Prussian General Staff to Toyota — have understood that they need both at once: a reliable downward flow of directives and an unfiltered upward flow of reality.
When one of the directions fails, the consequences depend on which one it is. A failure of the downward flow (unclear strategy, contradictory goals, an information vacuum) leads to chaos and duplication. A failure of the upward flow — that is, systematic filtering of bad news, the embellishment of reality, fear of escalation — leads to catastrophes. Literally, in the case of space shuttles. Figuratively, in the case of companies — but with real consequences.
The term mushroom management — "keep them in the dark and feed them manure" — describes a state in which employees are given work without knowledge of the overall situation. A study in the Turkish healthcare sector found that 84% of the managers surveyed practice this style and 87% of employees perceive it. It may look like efficient delegation — "you don't need to know the context, just do it" — but in reality it creates an organization where no one at the lower levels has enough information to recognize a problem, let alone report it.
Lehman Brothers is a textbook example. CEO Richard Fuld systematically restricted the flow of information about the concentration of risky mortgage products. The result: bankruptcy with assets of 639 billion dollars — the largest in American history.
The mechanism is simple and insidious. A project manager has bad news — a slip, a technical problem, the departure of a key person. But he knows that his superior "doesn't like problems, he wants solutions." So in the review he frames things optimistically. His superior does the same for his own superior. At every level of the hierarchy, the project turns a little "greener." By the time the review reaches leadership, everything glows green.
Rob Gillham, a project management specialist, named the root cause: watermelon reporting does not thrive because people are dishonest — it thrives because honesty is not safe.
Quantitative research by Ben-Arieh and Pollatschek confirms this: only 28% of the information generated by middle management makes it up to leadership, while middle managers generate 46% of all communication in the organization. Middle management is not a bridge — it is an information bottleneck.
In 2007, Avinash Kaushik introduced a label for the situation in which the opinion of the highest-paid person in the room outweighs the data. Jim Barksdale, CEO of Netscape, paradoxically summed it up: if we have data, let's look at the data — if all we have are opinions, let's go with mine.
In a technology company this effect is especially destructive, because decisions about architecture, technology choice, or feature prioritization have right and wrong answers — and top leadership is often furthest from the code. When a CTO decides on a technology based on a conference impression and the engineers are afraid to object, the company deploys a solution that everyone at the lower levels knows is wrong. But they stay silent, because "the boss wants it."
Deploying systems for task orchestration, container management, and advanced operators — these are all legitimate tools. But only if they solve a real problem at a scale that requires them. When a team deploys a complex task-management system for a runtime environment that previously ran as a cron script and worked, that is not engineering work — that is résumé-building.
In an organization where information does not flow, this anti-pattern spreads like a contagion. Why? Because deploying a new internal tool is low risk and high visibility — a beautiful presentation at the company meeting. Conversely, improving search relevance or paying down technical debt is high risk and low visibility — hard to measure, easy to overlook. Without feedback flowing upward, no one at the top knows that the company is investing months in tools that deliver nothing to the end user.
The most extreme form is the systematic falsification of data — and you don't have to reach into history for examples. In every organization where people are evaluated on the basis of measurable indicators, there is pressure to "improve" those indicators in a way that does not reflect reality. Delivery velocity that rises without corresponding impact. Test coverage that measures lines, not quality. Customer satisfaction scores that improve because only satisfied customers receive the survey.
China's Great Leap Forward (1958–1962) shows where this leads in the extreme: local cadres competed in announcing ever more exaggerated grain yields. The state set procurement quotas based on the falsified figures. Some regions handed over practically their entire harvest. Estimates of the dead are around 30 million. Defense Minister Peng Dehuai challenged the strategy at the Lushan Conference in 1959. Mao stripped him of his post — and the Great Leap accelerated.
A technology company is, of course, not Maoist China. But the mechanism — an incentive structure that rewards the reporting of good news and punishes the reporting of bad — is identical. Only the magnitude of the consequences differs.
In Toyota's production system there is the andon system — every worker has within reach a cord whose pull signals a problem and, if necessary, stops the entire production line. The key lies in three principles that make the andon more than a button.
First: pulling the cord is framed as a duty, not a right. A worker who sees a problem and does not pull is breaking the rules.
Second: the team leader arrives within seconds and, as the first thing, thanks the worker. Unconditional positive reinforcement, regardless of whether the problem is confirmed.
Third: when the number of pulls per shift dropped from roughly a thousand to seven hundred, the CEO did not celebrate — he called a meeting. The decline might have meant that workers were ceasing to report problems.
The result: Toyota's defect rate is among the lowest in the industry. American automakers that copied the andon failed — because installing a cord is easy, but building a culture in which people are not afraid to pull it takes decades.
Amazon adopted the concept as the "Andon Cord for customer service" — customer-service representatives can pull a product from distribution if they notice a pattern of complaints. In 2004, Jeff Bezos additionally banned presentation slides and introduced a six-page narrative document. The justification directly addresses the degradation of information in the hierarchy: the narrative structure forces better thinking, whereas a presentation "gives permission to gloss over ideas and ignore interconnectedness."
On March 27, 1977, 583 people died at Tenerife — to this day the deadliest aviation accident in history. KLM captain Jacob van Zanten — the airline's most famous pilot, literally the face of its advertising campaigns — began the takeoff without clearance in dense fog. The co-pilot objected, but van Zanten cut him off. The flight engineer asked whether the other aircraft had cleared the runway; van Zanten answered dismissively, and the engineer did not press the point further.
The cause was not technical. It was organizational: an authority gradient — subordinate crew members did not feel entitled to question the decision of an authority figure.
The aviation industry responded by introducing Crew Resource Management. The captain ceased to be regarded as infallible. Subordinates were trained in assertive communication. The two-challenge rule was created, along with a graduated system of escalation: I'm concerned — I'm uncomfortable — This is a safety issue. The result over fifty years: the safety of civil aviation has improved roughly twelvefold — in large part because the co-pilot today may and must say "stop" to the captain.
In 1999, Amy Edmondson of Harvard Business School defined psychological safety as a shared belief that the team is safe for interpersonal risk-taking. Her seminal article is among the most cited in the field of organizational behavior.
Google tested this theory in Project Aristotle (2012–2014), which studied more than 180 teams. It found that who is on a team matters considerably less than how the team works together. Psychological safety proved to be the strongest predictor of effectiveness — ahead of dependability, clarity, meaning, and impact. High-performing teams exhibited equality in conversation and sensitivity to the emotions of others.
DORA (DevOps Research and Assessment) research confirmed that psychological safety predicts software delivery performance, organizational performance, and productivity — that is, precisely what a technology company needs.
In 2012, John Allspaw, CTO of Etsy, published a seminal text on blameless incident postmortems, inspired by the work of Sidney Dekker on human factors. The key principle: ask "what" and "how," not "why" — because "why" leads to speculation, hindsight bias, and blame.
Google's Site Reliability Engineering (SRE) team conducts a postmortem within 48 hours of every significant incident. A monthly newsletter shares the best ones. There is even a simulation exercise, the "Wheel of Misfortune," in which incident responses are rehearsed. The principle: "You can't fix people, but you can fix systems so they better support people in making the right decisions."
Etsy awards an annual "three-armed sweater" prize to the employee with the most surprising mistake. The signal is unambiguous: accidents are data, not disgrace.
After its catastrophic defeat at Jena in 1806, the Prussian army built a system that the historian Trevor Dupuy called "institutionalized genius." Instead of depending on a single brilliant commander — the model on which Napoleon's army rested — they created the General Staff and the doctrine of mission command (Auftragstaktik): the commander defines the objective and allocates resources, while the subordinate decides independently on the methods.
Information flows in both directions: intent downward, situational awareness and initiative upward. Subordinates are trained to understand the context two levels above their own position. This requires something that is unimaginable in many companies: trust in the competence of subordinates and the willingness of leadership to share context.
The opposite is the Soviet model of order-based command (Befehlstaktik) — detailed orders from above, which subordinates execute rigidly. When circumstances change, they must report back and wait for new orders. The consequences became dramatically apparent in Ukraine from 2022: the northern convoy heading toward Kyiv was stuck on the road for days because no lower-level commander adapted. Officers had to borrow the mobile phones of war correspondents in order to contact units. Russian soldiers sent into combat believed they were on an exercise — so tightly controlled was the flow of information that it prevented even basic situational awareness.
For a technology company the parallel is direct. A company run in the style of order-based command — detailed specifications from above, zero team autonomy, an obligation to report and wait — cannot adapt when the market changes. The engineers at the front line see the problem, but have neither the mandate nor the channel to solve it or escalate it. A company run in the style of mission command — a clear strategic intent, autonomous teams, a two-way flow of information — adapts in real time.
First: excessive transparency can be counter to the original intent. Ray Dalio's Bridgewater Associates introduced a system of "radical transparency" with a tool called the Dot Collector — employees rate one another in real time on dozens of attributes. The result? The firm lost roughly 25% of its employees after 18 months. Rob Copeland's investigative book The Fund (2023) alleges that Dalio manipulated the believability system to his own advantage. The Harvard researcher Ethan Bernstein warned that constant surveillance may paradoxically cause people to become more closed off. Transparency without psychological safety is surveillance, not openness.
Second: there is a real risk of information overload. Shannon's information theory tells us that every channel has a limited capacity. If leadership receives an unfiltered stream of all problems from all levels, it cannot decide effectively. The solution is not to stop filtering — the solution is the right filters. Stafford Beer, in his Viable System Model, defined the concept of algedonic signals — warning messages that bypass the normal hierarchy and escalate directly to top leadership when a situation crosses defined thresholds. The andon is an algedonic signal. A whistleblower is an algedonic signal. Normal operation filters — but once a threshold is crossed, the filter falls away.
Third: not every organization can be Toyota or Google. Building a culture of psychological safety takes years and requires consistent behavior from leadership — not a one-off seminar. But the alternative — not building it — is not neutral. The absence of a culture in which people can safely deliver bad news is an active decision with measurable consequences.
Principle 1: Measure the flow, not just the indicators. What percentage of information from the lower levels reaches leadership without filtering? If you don't know this, you can't manage it. Research shows that in the average organization it is 28%. In yours it may be less.
Principle 2: Establish algedonic channels. Define thresholds — technical debt above X person-days, project slip above Y weeks, the departure of Z key people in a quarter — upon whose crossing information bypasses the normal hierarchy and arrives directly at the decision-makers. Without filters, without optimistic correction.
Principle 3: Reward bad news. Toyota thanks the worker who pulls the cord. Etsy awards a prize for the most surprising mistake. Google's SRE team shares the best incident postmortems. The signal must be unambiguous and repeated: bringing bad news on time is more valuable than bringing good news late.
Principle 4: Ban presentation slides for strategic decisions. A narrative document forces thinking. A presentation forces simplification. A six-page text exposes the holes in an argument that hide behind bullet points.
Principle 5: Train assertive communication. Aviation introduced the two-challenge rule and a graduated escalation system. Healthcare introduced SBAR (Situation — Background — Assessment — Recommendation). A technology company needs an analogous structured protocol that allows a junior engineer to tell a senior architect "there's a problem here" without career risk.
Principle 6: Mission command, not order-based command. Define the intent and allocate resources. Let teams decide on the methods. Share context two levels above and below. Everyone in the organization should be able to answer the question "why do we do what we do" — not just "what do I do."
Principle 7: Culture is built by the behavior of leadership, not by declarations. The first time a leader punishes — even indirectly (by overlooking them, by passing them over for promotion) — a person who brought bad news, they destroy months of trust-building. Conversely, when they visibly act on bad news and thank its bearer, they strengthen the culture more than any seminar.
In 1956, W. Ross Ashby formulated a law that everyone who manages a complex organization ought to know: "Only variety can absorb variety." An organization must have sufficient internal complexity — a diversity of responses, capabilities, information channels — to match the complexity of the environment in which it operates.
Donella Meadows placed the structure of information flows sixth out of twelve leverage points for changing a system — high above all physical parameters. Her insight remains timeless: a missing feedback loop is one of the most common causes of system malfunction, and adding or restoring an information flow can be a powerful intervention, usually far simpler and cheaper than rebuilding the physical infrastructure.
The Soviet Union represents an extreme case of an organization that suppressed negative feedback for decades. Leading economists used CIA estimates instead of their own statistics. Gorbachev tried to restore the flow of information through glasnost — not to destroy the system, but to save it. The paradox: once information began to flow, it revealed the horrors of the past and the inefficiency of the present, and instead of saving the system it destroyed its legitimacy.
The lesson for a technology company is direct: when you suppress the flow of bad news for too long, the accumulated truth becomes so devastating that it destroys the system rather than saving it. The truth does not age — but the longer you ignore it, the more it hurts when it arrives.
After the Columbia disaster, Rodney Rocha told investigators that he had felt like "a grain of sand swept under the rug." Seven people died because information that existed at the lower levels of the hierarchy could not rise to those who were deciding. Not because it was missing. Not because it was unclear. But because the organization's culture ensured that no one wanted to hear it.
In a technology company it is usually not about lives. It is about products that fail to ship on time. About technical debt that accumulates until it becomes unpayable. About talented people who leave because no one listens to them. About competitive opportunities that whistle past while the company busies itself with internal tools that have no user impact.
But the mechanism is always the same. The person at the bottom knows. The person at the top does not. And between them is a hierarchy that reliably absorbs the information.
The question for every leader at every level is this: Who in your organization knows right now about a problem that you don't know about? And what is stopping them from telling you?
This article draws on research into security models (Bell-LaPadula, Biba), organizational theory (Edmondson, Beer, Ashby, Meadows), case studies (NASA, Toyota, Google, Etsy, Boeing, VW), and military doctrine (mission command). Data and sources were verified as of February 2026.
Transparency of creation:
The concept, structure, and editorial line of the article are the work of the author, who prepared the content outline, established the key theses, and directed the entire creative process. Generative AI (Claude, Anthropic) was used as a technical tool for research, fact-checking, and the fleshing out of the author's draft.
The author edited the outputs continuously, verified the key findings, and approved the final wording. No part of the text was published without human review. All factual data were verified against the publicly available sources cited in the text.
The procedure is in compliance with the requirements of Art. 50 of EU Regulation 2024/1689 (AI Act) on the transparency of AI-generated content. #poweredByAI
Read the Czech original on Médium.cz.
AI · Claude — machine translation, may contain inaccuracies.