The World We Make TogetherPart I — Who Makes History?
Chapter 3 — The Clock
Central question: How does time pressure turn incomplete information into concentrated interpretation?
A clock tells when a decision must be made without saying what it should be; afterward, time looks as if it had been counting toward the outcome. Inside the Challenger teleconference hour, incomplete information becomes social, and attention gathers toward whoever will explain the moment for everyone else. Power often enters as orientation under time pressure.
The Clock
A clock becomes most noticeable when it can no longer help.
We look at it while waiting for an answer that has not arrived. The second hand moves with complete confidence. The meeting begins in four minutes. The train leaves in twelve. The doctor said the results would be available by noon.
Time is precise even when the situation is not.
At 11:58, we may still believe the call will come before twelve. At 12:01, the same silence begins to mean something else. Nothing visible has changed except the position of the hands, yet uncertainty acquires pressure as time passes.
A clock can tell us when a decision must be made.
It cannot tell us what the decision should be.
This difference is easy to miss when we look backward. After an event, time appears organized around what eventually happened. There was the final warning, the last opportunity, the moment when someone should have known. Earlier choices line up behind the outcome as though every clock had been counting toward it.
People living through the event did not experience time that way.
The warning might have been wrong. The apparent opportunity might have led nowhere. Another piece of information might have arrived. The crisis might have passed. A delay might have prevented harm or created a different one. What later became a turning point was, at the time, one uncertain moment among many.
History remembers the hour after it knows the outcome.
The people inside the hour had no such advantage.
On the evening of January 27, 1986, engineers and managers participated in a teleconference about the scheduled launch of the space shuttle Challenger the following morning.
Temperatures at Kennedy Space Center were expected to be unusually low. Morton Thiokol, the contractor responsible for the shuttle’s solid rocket boosters, raised concerns about the rubber O-rings sealing the boosters’ field joints. During the first phase of the call, Thiokol representatives recommended delaying the launch. The discussion focused on whether the rings would respond quickly enough in the cold to prevent hot gases from escaping through a joint. The company initially advised against launching at temperatures below 53 degrees Fahrenheit.1
The recommendation did not end the discussion.
Participants examined data from earlier flights and tests. They tried to determine whether a reliable relationship had been established between temperature and O-ring performance. The evidence was troubling but incomplete. Engineers had observed erosion and blow-by in earlier missions, yet the shuttle had returned safely each time. The anomalies suggested that the joint was not behaving as originally expected, but they had not yet produced catastrophe.2
The teleconference paused while Thiokol personnel discussed the matter privately. Management then reversed the company’s recommendation and supported the launch. Some engineers continued to object. Senior decision-makers elsewhere in NASA did not receive a full account of the initial no-launch recommendation, the continuing engineering opposition, or the recent history of O-ring concerns.3
The following morning was cold.
Challenger lifted off at 11:38 a.m. Eastern time. Seventy-three seconds later, the vehicle broke apart, killing all seven crew members.4
The outcome gives every earlier moment a terrible clarity.
The cold mattered.
The O-rings mattered.
The objections mattered.
The reversal mattered.
The gaps in communication mattered.
Once the vehicle was gone, the decision to launch looked almost incomprehensible. A recommendation had been made not to proceed in the anticipated temperature. Engineers had expressed concern. The system had shown warning signs. The shuttle launched anyway.
From after the explosion, the correct decision appears to have been waiting at the end of the teleconference.
But the lesson becomes less useful if we imagine that everyone on the call possessed the knowledge created by the accident.
They did not know that Challenger would fail.
Some believed the launch was unsafe. Others believed the available data did not demonstrate that conclusion. Previous missions had flown despite O-ring erosion. Tests had produced partial and sometimes conflicting evidence. Managers were not choosing between a known safe outcome and a known disaster. They were interpreting an imperfect record under schedule pressure, organizational expectation, technical uncertainty, and unequal access to the information.
Restoring that uncertainty does not excuse the decision.
It allows us to judge the decision more precisely.
The presidential commission that investigated the accident did not conclude merely that managers had guessed wrong.
It found that the process itself was flawed.
The people who approved the launch lacked important information. Communication failures allowed safety concerns to bypass key managers. Engineering data and managerial judgment were handled through a process that did not preserve the seriousness of the dissent. In its discussion of ice on the launch structure, the commission also criticized a reversal in the burden of proof: NASA appeared to require a contractor to demonstrate that launch was unsafe rather than requiring confidence that it was safe.5
This is a different kind of failure from uncertainty.
Uncertainty means that no participant can know the outcome in advance.
A flawed decision process determines what people do with that condition.
Do they preserve warnings as they move upward?
Do they distinguish an absence of proof from proof of safety?
Do they ask who will bear the consequences of being wrong?
Do they allow schedule, reputation, or earlier success to change the standard of evidence without saying so?
Do they make it possible for someone with less authority to interrupt the momentum of the institution?
The presence of uncertainty makes these questions more important, not less.
A person can act responsibly without knowing the outcome. They can identify what remains unknown, test the assumptions carrying the decision, protect dissent, and choose a margin of safety proportionate to the stakes.
They can also use uncertainty selectively.
A warning can be dismissed because it is not conclusive while the belief that everything will be fine is accepted without the same demand for proof. Doubt can be treated as a weakness when it slows action and as wisdom when it protects an established plan. The uncertain evidence against proceeding receives scrutiny. The uncertain evidence for proceeding is called judgment.
After the disaster, it is easy to say that the warning should have controlled the decision.
Before the disaster, the deeper responsibility was to build a process in which uncertainty could not be quietly converted into confidence merely because the organization wanted to move.
Earlier success complicated the decision.
The shuttle program had experienced O-ring erosion and blow-by before Challenger. Because those flights had not ended in disaster, the history of successful launches began to function as evidence that the anomalies could be accepted. Richard Feynman, serving on the investigating commission, later argued that this reasoning confused survival with safety. Unexpected erosion was a warning that the system was behaving outside its intended design; the fact that earlier missions survived did not establish that a later mission would do the same.6
Success can conceal risk as effectively as failure reveals it.
An institution encounters a problem and nothing catastrophic happens. The deviation becomes familiar. The next decision begins from the fact that the previous one worked. A boundary once treated as exceptional becomes the new normal.
The clock moves forward without announcing that the meaning of the evidence has changed.
The first anomaly creates alarm.
The second creates comparison.
The third creates a pattern.
Eventually the absence of disaster is mistaken for proof that the system is understood.
This is one of the ways time reorganizes judgment before the outcome, not only after it. Repetition changes what people consider acceptable. The institution remembers that it survived and forgets that survival was not the same as control.
Later, once failure occurs, the same history is rearranged again.
Each anomaly becomes an obvious warning.
Each successful flight becomes a missed opportunity.
The sequence looks like a countdown.
People inside it did not hear the ticking with equal clarity.
A fair account of historical action must therefore restore at least three different times.
There is the time before the choice.
There is the time of choosing.
And there is the time after the outcome has changed what the earlier evidence appears to mean.
Before
Before a decision, the situation contains more possibilities than history will preserve.
A warning may indicate danger or reflect excessive caution. A protest may grow into a movement or disappear before the week is over. An early compromise may prevent violence or merely postpone it. A new policy may correct an injustice or create an unforeseen dependence. A person considering whether to speak does not know whether others will join them.
Information arrives unevenly.
One participant sees technical data. Another understands the political pressure. Someone knows what happened in an earlier case but not what has changed since. Someone else has less information and greater authority.
The future remains plural.
During
During the decision, time narrows the possibilities.
The launch window approaches. The crowd is gathering. The contract expires. The medication must be administered. The vote is called. Delay may preserve options, but delay also has consequences.
People act.
Some speak clearly. Some soften what they know. Some wait for someone else to take responsibility. Some accept the prevailing interpretation because they lack the standing to reopen it. Others overstate confidence because visible uncertainty would weaken their authority.
A decision emerges before the situation is fully understood.
After
Afterward, the result becomes part of the evidence.
If the action succeeds, judgment appears sound. If it fails, the same judgment appears reckless. Warnings gain credibility when disaster follows them and lose credibility when the feared event does not occur.
The range of possible futures collapses into one actual past.
Then the story begins editing.
The person who guessed correctly becomes perceptive. The person who guessed incorrectly becomes blind. A risk that materialized becomes obvious. A risk that did not becomes exaggerated.
We start judging the quality of the decision by the outcome the decision helped produce.
Sometimes that is reasonable. Outcomes matter. A theory that repeatedly predicts badly should lose our confidence. A leader whose decisions repeatedly create avoidable harm cannot hide forever behind uncertainty.
But one result cannot tell us everything about the quality of the judgment that preceded it.
Good processes can produce bad outcomes.
Bad processes can get lucky.
History has difficulty remembering the difference because luck leaves no label on the event.
The opposite of Challenger is not a decision that succeeded.
It is a danger that became difficult to see because people successfully responded to it.
During the final years of the twentieth century, governments and businesses prepared for the Year 2000 computing problem. Many older computer systems stored years using two digits rather than four. Without correction, “00” could be interpreted as 1900 rather than 2000, producing errors in calculations involving dates and elapsed time. The risks extended across interconnected systems used for financial transactions, government benefits, utilities, transportation, health care, and other critical services.7
The threat had an exact deadline.
Clocks around the world would reach midnight. Systems would process a date they had never encountered. Unlike many technological risks, the moment could not be postponed by a committee vote.
Governments designated systems for review. Programmers inspected and remediated code. Agencies tested their operations, developed contingency plans, coordinated with state and private partners, and tracked readiness across critical services. In the United States, the Government Accountability Office placed Y2K on its High-Risk List in 1997, issued more than 160 reports and testimony statements, and developed guidance for testing, continuity planning, and readiness.8
The feared national collapse did not occur.
Most Y2K-related errors reported by the federal government were minor and did not disrupt operations or service delivery. By December 1999, the major federal agencies had increased reported compliance of their mission-critical systems from 21 percent in May 1997 to 99.9 percent. GAO later concluded that focused remediation, leadership, oversight, coordination, and contingency planning helped the United States avoid major national failures during the rollover.9
Nothing dramatic happened.
That outcome invited a different kind of hindsight.
If the catastrophe did not occur, perhaps the danger had been exaggerated.
If the systems continued working, perhaps the years of remediation, planning, public warning, and expense had been unnecessary.
The very success of prevention weakened the evidence that prevention had been needed.
This is the paradox of an avoided disaster.
When preparation fails, the harm proves that officials should have done more.
When preparation succeeds, the absence of harm is used to prove they did too much.
The clock reaches midnight either way.
What disappears is the work performed before it did.
Y2K does not prove that every warning deserves massive intervention.
Some predictions are inflated. Institutions can spend money poorly. Fear can make unlikely scenarios appear imminent. A deadline can concentrate attention around a problem that is real but less dangerous than advocates claim.
The peaceful rollover cannot tell us that every decision made under the Y2K banner was wise.
It can tell us that the final absence of catastrophe is insufficient evidence that the original risk was imaginary.
The condition people feared was altered by the action taken in response to it.
This creates a historical problem. We want outcomes to validate judgment, but prevention changes the outcome against which the judgment will later be measured.
A person repairs a weakened bridge, and the bridge does not collapse.
A public-health team contains an outbreak, and the disease never becomes visible to most people.
A diplomat makes a concession that prevents escalation, and the war that might have followed leaves no archive.
A supervisor addresses a safety concern before anyone is injured, and the intervention begins to look cautious rather than necessary.
The success exists partly in an event that did not happen.
History has few photographs of absence.
There is no wreckage. No line of casualties. No dramatic hour after which everyone agrees that the warning mattered.
Only the clock continuing.
The difference between Challenger and Y2K is not simply that one ended badly and the other ended well.
Together they reveal the unfair advantage outcomes possess over earlier judgment.
After Challenger, the danger appears inevitable.
After Y2K, the danger can appear imaginary.
In one case, failure sharpens every warning.
In the other, prevention dulls them.
The work of responsible judgment is to reconstruct the information available before the outcome took control of the story.
What was known?
What remained uncertain?
How reliable were the warnings?
What were the consequences of acting unnecessarily?
What were the consequences of failing to act?
Who possessed the authority to decide?
Who would bear the cost if the decision was wrong?
Did the process preserve disagreement or filter it out?
Was confidence earned through evidence, or produced by momentum?
Did the people making the decision remain open to correction?
These questions do not eliminate hindsight.
We cannot unknow the result. The explosion remains real. So does the uneventful rollover.
But we can resist allowing the ending to write every earlier scene.
Restoring uncertainty also changes how we judge courage.
A person who joins a successful movement can later appear to have recognized the direction of history. A person who joins an unsuccessful one may appear naïve, disorganized, or premature.
At the beginning, neither person knows which story they are entering.
The worker deciding whether to join a strike does not know whether others will remain once wages stop. The first person to report misconduct does not know whether the institution will investigate or retaliate. The family entering a public protest does not know whether the day will remain peaceful. The official refusing an order does not know whether the refusal will isolate them or open a path for others.
Later narratives make participants look as though they chose the outcome itself.
They chose only the act available at the time.
This does not mean every failed action was wise. Some movements misunderstand the public, conceal internal abuse, choose ineffective tactics, or impose risks on people who never consented. Some early warnings are poorly supported. Some courageous refusals are also mistaken.
Uncertainty does not convert sincerity into correctness.
It changes what fairness requires from judgment.
We should ask whether the actor investigated what could be known, whether they acknowledged what could not, whether they imposed greater certainty than the evidence allowed, and whether they treated the consequences for others as part of the decision.
A person can be morally serious and factually wrong.
Another can be factually right for reasons that deserve little trust.
History often rewards the correct prediction without examining how it was reached.
There is also a temptation to treat uncertainty as an individual weakness.
The confident person appears to understand the moment. The hesitant person appears unprepared. Institutions often reward those who can convert incomplete information into a clear direction, especially when time is short.
But uncertainty belongs to the situation before it belongs to the person.
No amount of confidence can make unavailable information appear. No title gives someone access to the future. Expertise can narrow uncertainty, identify patterns, and improve judgment. It cannot abolish contingency.
The strongest decision-maker may be the one who knows which uncertainty matters.
They distinguish what must be decided now from what can remain open. They notice where the institution has mistaken familiarity for safety. They ask whether dissent reached the room intact. They do not require certainty from warnings while allowing optimism to proceed untested.
This kind of leadership does not look dramatic from a distance.
It may produce a delay.
A revised procedure.
A question asked one more time.
An uneventful midnight.
Nothing happens, and the clock continues.
The clock in the waiting room has not stopped helping entirely.
It tells us that twelve has passed. It tells us how long we have waited. It may tell us when to call again, when to leave, or when delay itself has become information.
What it cannot do is interpret the silence.
For that, we look elsewhere.
We reread the message. We examine the faces of other people waiting. We watch the receptionist. Has something gone wrong? Is this ordinary? Does anyone appear concerned?
Uncertainty becomes social before anyone names it.
A room full of people can possess the same incomplete information and still experience the moment differently. Some continue talking. Some prepare to leave. Some grow alarmed. Others wait for a signal that alarm is permitted.
Then attention begins to gather.
People look toward the person with the title, the experience, the confidence, the uniform, or simply the willingness to respond first. A pause becomes meaningful. A gesture becomes reassurance. Silence becomes an interpretation.
The moment does not explain itself.
Someone begins to explain it for everyone else.
That is one way power enters the room.
Footnotes
-
See Report of the Presidential Commission on the Space Shuttle Challenger Accident (Rogers Commission) on the January 27, 1986, teleconference, Thiokol’s low-temperature O-ring concerns, and the initial recommendation against launching below 53°F. ↩
-
See the Rogers Commission report and Richard P. Feynman, Appendix F, on prior O-ring erosion and blow-by and the treatment of earlier successful flights as evidence of acceptability. ↩
-
See the Rogers Commission findings on communication failures, Thiokol’s reversal, and conflict between engineering data and management judgment. ↩
-
See NASA records that Challenger launched on January 28, 1986, after unusually cold overnight temperatures and was lost shortly after liftoff. ↩
-
See the Rogers Commission’s conclusions on the flawed launch-decision process and the handling of incomplete information and safety concerns. ↩
-
See Richard P. Feynman, Appendix F to the Rogers Commission report, arguing that prior mission success had been improperly treated as evidence of safety despite unexpected O-ring erosion and blow-by. ↩
-
See U.S. Government Accountability Office materials explaining two-digit year fields and the risk that “00” would be processed as 1900, with cascading effects across loans, pensions, tax records, and benefits. ↩
-
See GAO’s 1997 designation of Y2K as a federal high-risk area and subsequent readiness, testing, and contingency-planning guidance. ↩
-
See U.S. Government Accountability Office, Year 2000 Computing Challenge (GAO/AIMD-00-290), reporting compliance rising from 21 percent in May 1997 to 99.9 percent by December 1999 and that most reported federal errors were minor. ↩
