../

Systems thinking

How to see and change the structures that produce behavior over time: stocks and flows, feedback loops, delays, causal loop diagrams, the recurring archetypes, Donella Meadows' twelve leverage points, the iceberg model, and the laws that describe how systems resist and surprise their designers. Includes worked math, a step-by-step analysis template and applications to startups, organizations, habits and software. First principles thinking takes a problem apart; this sheet is about how the parts behave once connected. For queueing and failure handling in real services see system design.

What a system is

Donella Meadows (Thinking in Systems, 2008): "A system is an interconnected set of elements that is coherently organized in a way that achieves something." Every system has three kinds of thing:

PartMeaningStartup exampleHow easy to seeEffect of changing it
Elementsthe things: people, machines, money, stock, usersengineers, servers, customers, casheasiestusually small, unless an element is also a rule-maker
Interconnectionsthe relationships and information flows that link elements: physical flows, rules, signalspricing, referral mechanics, pay plans, who reports to whom, dashboardsharderoften large
Purpose or functionwhat the system actually does, deduced from behavior rather than stated goals"grow ARR" on the slide; "hit this quarter's number at any cost" in practicehardestthe largest

Meadows' point: the elements are what we notice, but you can replace every player on a football team and it is still the same team; change the rules or the purpose and it becomes a different system. Judge purpose by what the system does, not by what it says (a company that says "quality first" but promotes whoever ships fastest has a speed purpose).

TermMeaning
Boundarywhat you choose to include; drawn for the question, not given by nature
Environmenteverything outside the boundary that affects the system but is not affected by it (in your model)
Open vs closedwhether the system exchanges matter, energy or information with its environment (organizations always do)
Statethe values of all the stocks at a moment
Behaviorhow the state changes over time; the thing you actually care about
Structurestocks, flows, feedback loops, delays and rules; structure produces behavior

The core claim of systems thinking: structure produces behavior. Similar structures produce similar behavior whatever the content, so a small vocabulary (stocks, flows, loops, delays) explains a large range of problems.

Stocks and flows

A stock is an accumulation you could count at an instant: water in a bath, money in an account, users, inventory, technical debt, trust, skill. A flow is a rate that changes a stock: liters per minute, pounds per month, sign-ups per week. Stocks change only through flows.

Users stock (a level) sign-ups / month churn / month churn = c × Users source sink (inflow valve: a rate) (outflow valve: a rate) Users(t+1) = Users(t) + sign-ups − churn steady state when inflow = outflow: Users* = sign-ups ÷ c e.g. 1,000 sign-ups a month and 5% monthly churn level off at 20,000 users
Stock and flows: the bathtub model of a user base with churn
St+1=St+inflowt−outflowtor, continuously,dSdt=inflow(t)−outflow(t)S_{t+1} = S_t + \text{inflow}_t - \text{outflow}_t \qquad\text{or, continuously,}\qquad \frac{dS}{dt} = \text{inflow}(t) - \text{outflow}(t)
RuleConsequence
a stock rises when inflow exceeds outflow, whatever their absolute sizesyou can grow users by cutting churn as well as by adding sign-ups
dynamic equilibrium: inflow = outflow, so the stock is constant while material moves through ita "stable" headcount can hide 30% annual turnover
stocks change slowly relative to flows; they are the system's memory and inertiareputation, skills, culture and debt take years to build or pay down
stocks act as buffers that decouple inflow from outflowinventory, cash reserves and queues let the two sides run at different rates
you cannot see a stock's future from its level alone; look at the flows"we have 18 months of runway" depends on the burn rate trend
the time a unit spends in a stock is stock ÷ throughput (Little's law, below)a 600-ticket backlog handled at 100 a week is a 6-week wait

Worked example: bank balance

Stock: balance, starting at $2,000. Inflow: salary $4,000 a month. Outflow: spending $3,600 a month. Net flow +$400, so the balance grows linearly: $2,400, $2,800, $3,200, … Add interest at 0.4% a month and a reinforcing loop appears (the interest inflow depends on the stock), so growth becomes slightly exponential. Doubling time for a stock growing at gg% per period:

tdouble≈70g(rule of 70; e.g. 7% a year doubles in about 10 years)t_{\text{double}} \approx \frac{70}{g} \quad\text{(rule of 70; e.g. 7\% a year doubles in about 10 years)}

Worked example: user base with churn

New users arrive at a constant AA per month; a constant fraction cc of existing users leave each month.

Ut+1=Ut+A−cUt⇒U∗=Ac,Ut=U∗+(U0−U∗)(1−c)tU_{t+1} = U_t + A - cU_t \quad\Rightarrow\quad U^* = \frac{A}{c}, \qquad U_t = U^* + (U_0 - U^*)(1-c)^t
ScenarioSign-ups AAMonthly churn ccSteady state U∗U^*Users after 12 months from 0Half-way time
base1,0005%20,0009,190~13.5 months
double acquisition2,0005%40,00018,390~13.5 months
halve churn1,0002.5%40,00010,480~27 months

Lessons: with constant acquisition, growth always levels off at A/cA/c (a balancing loop through churn). Halving churn has the same effect on the ceiling as doubling acquisition, but takes longer to show, which is why churn work is chronically undervalued in monthly reviews. The gap to steady state closes by a fraction cc each month; the half-way time is ln⁡0.5/ln⁡(1−c)\ln 0.5 / \ln(1-c), roughly 0.69/c0.69/c.

Feedback loops

A feedback loop exists when a change in a stock affects the flows into or out of that same stock, directly or through a chain of causes. There are two kinds.

+ + + Customers Word of mouth New sign-ups R reinforcing + + − Queue length Servers requested Capacity B balancing 0 negative links: amplifies 1 negative link: pushes back + same direction · − opposite direction · || delay (new servers take minutes to boot)
A reinforcing (R) and a balancing (B) loop with link polarities and a delay
Reinforcing (R, "positive") loopBalancing (B, "negative") loop
Effectamplifies change in whichever direction it startscounteracts change; pushes the stock toward a goal
Behavior aloneexponential growth or collapsegoal seeking; with delays, oscillation
Signature"the more X, the more X"; virtuous or vicious circlea gap between actual and desired state drives corrective action
Negative links in the loopeven number (0, 2, …)odd number (1, 3, …)
Examplescompound interest, network effects, word of mouth, bank runs, tech debt slowing fixes, burnout spiralsthermostat, inventory reordering, autoscaling, hunger, market price adjustment, hiring to a headcount plan
Management trapassuming growth continues; ignoring the vicious versionfighting a balancing loop you did not see (policy resistance)

"Positive" and "negative" mean the loop's polarity, not good and bad. A reinforcing loop of rising tech debt is positive feedback and very bad news.

Loop dominance: real systems contain many loops, and which one dominates changes over time. S-shaped growth is a reinforcing loop dominating early and a balancing loop (a limit) dominating later. Most surprises are shifts in dominance that nobody modeled.

Delays, non-linearity and bounded rationality

Delays and oscillation

A delay is a lag between cause and effect: between an action and its result, or between a result and your perceiving it. Balancing loops with delays overshoot and oscillate, because the corrective action continues after the gap has closed.

ExampleDelayWhat happens
Showera few seconds between turning the tap and feeling the temperature changeyou turn it hotter, feel nothing, turn it more, get scalded, overcorrect to cold, and so on
Beer game (MIT, developed by Jay Forrester's system dynamics group from the 1960s)order and shipping delays of several weeks at each of four stages: retailer, wholesaler, distributor, factorya single step increase in customer demand produces large swings in orders and inventory upstream (the bullwhip effect); Sterman (1989) found players typically blame the swings on outside demand rather than their own ordering
Hiring3–6 months from opening a role to a productive hireteams hire for last quarter's workload, then have too many people when demand has already turned
Autoscalingminutes for new instances to boot and warm upnaive scaling on current load overshoots, then scales in too far, then thrashes
Interest ratesmonetary policy acts with long and variable lagscentral banks that react only to current inflation risk overshooting in both directions
To reduce oscillationWhy it works
act on the supply line (what is already ordered, hired or booting), not just the current gapstops you ordering the same correction twice
make smaller corrections and wait longer between themreduces the gain of the balancing loop relative to the delay
shorten the delay (faster information, faster delivery)the loop sees its own effects sooner
hold buffers (inventory, cash, spare capacity)absorbs the gap while the correction arrives

Meadows lists delay length, relative to the rate of system change, as leverage point 9: often you cannot shorten the delay, and then slowing the system down so the delay matters less is the fix.

Non-linearity

Effects are rarely proportional to causes. Relationships have thresholds, saturation and tipping points: the first server doubling capacity cuts latency a lot, the fifth barely at all; a queue at 50% utilization is fine, at 95% it explodes (see the software section). Linear extrapolation from the current range is the most common modeling error.

Bounded rationality

Herbert Simon's term: people make reasonable decisions given the limited, delayed and local information they have. In systems terms, each actor can behave rationally and the system still produce an outcome nobody wants (fishers overfishing, teams hoarding shared staff, suppliers over-ordering in the beer game). Meadows' conclusion is that replacing the people rarely helps; changing the information and incentives they see does.

Causal loop diagrams

A causal loop diagram (CLD) shows variables joined by arrows labeled with polarity, and the loops those arrows form. It is a thinking tool: cheap, qualitative and good for conversations. For numbers you need a stock-and-flow model (spreadsheet, or tools such as Vensim, Stella or Insight Maker).

NotationMeaning
variablea noun phrase that can go up or down: "customer satisfaction", not "satisfy customers"
arrow A → Ba change in A causes a change in B, all else equal
+ (or s, "same")A up → B up, and A down → B down, compared with what B would otherwise have been
− (or o, "opposite")A up → B down, and A down → B up
‖ across an arrowa significant delay
R / B in a loopreinforcing / balancing loop, often with a name ("R1: word of mouth")

Polarity rule: count the negative links around a loop. Even (including zero) → reinforcing. Odd → balancing. Check by walking the loop: assume the first variable rises, follow the signs around, and see whether you come back with "rises" (reinforcing) or "falls" (balancing).

  1. Start from a behavior over time

    Pick one or two variables whose trend is the problem and sketch the graph: "support tickets per week, rising for 9 months". The diagram must explain that shape.

  2. Name the key variables

    Write 5–10 nouns that can increase or decrease. Use the positive sense ("morale", not "low morale"). Include goals, perceived states and pressures as well as physical quantities.

  3. Draw causal links and label polarity

    For each link ask "if A goes up, does B go up or down, all else equal?" Only draw direct causes. Mark significant delays.

  4. Close the loops and label them

    Find the circles. Count negative links to label each R or B. Name each loop in a few words.

  5. Tell the story and check it against the data

    Walk each loop aloud. Does the dominant loop explain the observed trend? What would have to change for another loop to dominate? If the diagram cannot reproduce the behavior, it is missing a loop, a delay or a limit.

  6. Look for leverage

    Mark where you could add, cut or weaken a link, change a goal, shorten a delay or change who sees what information. Check each intervention for side effects by walking the loops again.

Common CLD errorFix
variables that are actions or events ("launch campaign")make them quantities ("marketing spend")
ambiguous polarity ("it depends")the link hides two mechanisms; split it into two variables
everything connected to everythingkeep 5–15 variables per diagram; one diagram per question
correlation drawn as causationdraw a link only if you can describe the mechanism
no delays markedask of every link "how long before the effect shows?"
no goals shownbalancing loops need a goal or desired state; draw it explicitly

Behavior over time patterns

A small number of structures produce almost all observed behavior (Sterman, Business Dynamics, 2000, calls these the fundamental modes of dynamic behavior). Match the graph to the structure, then look for that structure.

PatternShapeStructure that produces itSimple modelExample
Exponential growth or decaycurving ever steeper up (or down)a dominant reinforcing loopSt+1=St(1+g)S_{t+1} = S_t(1+g)compound interest, early viral growth, a bank run
Goal seekingrises or falls quickly, then flattens at a targeta dominant balancing loopSt+1=St+k(G−St)S_{t+1} = S_t + k(G - S_t)coffee cooling to room temperature, filling a hiring plan
Oscillationrepeated overshoot above and below a targeta balancing loop with a significant delaygoal seeking where the correction acts on an old gapshower temperature, inventory cycles, commodity price cycles
S-shaped growthexponential start, then levelling offa reinforcing loop meeting a balancing loop (a limit)logistic: dSdt=rS(1−SK)\dfrac{dS}{dt} = rS\left(1 - \dfrac{S}{K}\right)product adoption in a finite market, a new team's output
S-shaped growth with overshootgrows past the limit, then oscillates around itS-shaped growth where the limiting loop is delayedlogistic with a delaya population rising past its food supply, hiring past demand
Overshoot and collapsegrows past the limit and falls sharplygrowth that erodes or consumes its own limit (a resource, trust, a customer base)the carrying capacity KK itself falls when exceededfisheries, a platform that burns its users' goodwill with ads, a credit bubble

System archetypes

Archetypes are recurring combinations of loops with a known story and known leverage. Peter Senge popularised them in The Fifth Discipline (1990), building on work at Innovation Associates and MIT; Daniel Kim and the journal The Systems Thinker developed the practitioner versions, and William Braun's 2002 summary lists ten. Accidental Adversaries comes from Jennifer Kemeny (The Systems Thinker, 1994).

ArchetypeStructureSymptom (what you hear)ExampleLeverage
Limits to GrowthR (growth engine) runs into B (a limiting condition)"we're working harder but growth has stalled"a product grows through referrals until the reachable market or support capacity saturatesfind and remove or weaken the limit before it binds; stop pushing the growth engine harder
Shifting the Burdena quick symptomatic fix (B1) and a slow fundamental fix (B2); the quick fix has a side effect that weakens the fundamental one"it keeps coming back, but the quick fix works for now"senior engineers firefight every incident, so the team never learns to; discounts instead of a better productuse the symptomatic fix only to buy time; invest in the fundamental solution; watch for dependency
Eroding Goals (drift to low performance)gap between goal and reality closed by lowering the goal rather than by corrective action"that target was unrealistic anyway"on-call SLOs quietly relaxed each quarter; "good enough" test coverage slidinganchor goals to external benchmarks or customers; make the history of the goal visible
Escalationtwo balancing loops, each party responding to its position relative to the other, forming a reinforcing figure of eight"we have to respond to what they just did"price wars, feature arms races, hospital building races, arms racesfind a way for one side to de-escalate unilaterally, or reframe the goal so it is not relative
Success to the Successfultwo reinforcing loops competing for a shared resource: success brings resources, which bring more success"they've earned it"; "the other team never delivers"the flagship product gets all the engineers while a promising new one starves; network effectsquestion the allocation rule; separate goals and budgets; level the playing field for new entrants
Tragedy of the Commonseach actor's reinforcing gain from using a shared resource; total use depletes it (a shared balancing loop with a delay)"why is the shared service so slow for everyone?"a shared platform team, a shared database, CI runners, a fishery, a common pasturemake the cumulative cost visible to each user; charge for or allocate use; govern the commons (Ostrom)
Fixes that Faila quick fix relieves the symptom (B) but causes delayed unintended consequences that worsen it (R)"it worked at first, now it's worse than before"adding people to a late project (Brooks's law); cutting maintenance to hit a budget; retries that amplify an outagemap side effects before acting; watch for the delay; prefer fixes that address the cause
Growth and UnderinvestmentLimits to Growth where the limit is capacity that could be expanded, but demand falls first because of poor performance, which "proves" investment is not needed"demand is soft, so we can't justify more capacity"a startup that never hires support, so slow response loses customers, so it never "needs" supportinvest in capacity ahead of demand based on external signals; hold performance standards fixed
Accidental Adversariestwo partners whose own fixes unintentionally obstruct each other, turning a collaborative reinforcing loop into mutual damage"they keep undermining us" (from both sides)Procter & Gamble's promotions and Walmart's forward-buying, as told by Kemenybring both parties together to map the whole system; agree shared measures (P&G moved to everyday low pricing)

Meadows' Thinking in Systems has a parallel list she calls system traps: policy resistance, tragedy of the commons, drift to low performance, escalation, success to the successful, shifting the burden to the intervenor, rule beating, and seeking the wrong goal. Rule beating (following the letter of a rule to defeat its purpose) and seeking the wrong goal (optimizing the measured proxy) are the two most common in companies; they are Goodhart's law in systems language.

Leverage points

From Donella Meadows, "Leverage Points: Places to Intervene in a System" (1999). The list runs from least to most effective. The wording in the first column is Meadows' own summary list; the examples are ours.

#Leverage point (Meadows' wording)Company example
12Constants, parameters, numbers (such as subsidies, taxes, standards).tweaking a discount from 10% to 15%, a sales quota, an SLO target
11The sizes of buffers and other stabilizing stocks, relative to their flows.cash runway, inventory, spare server capacity, slack in the roadmap
10The structure of material stocks and flows (such as transport networks, population age structures).the physical architecture: data centers, office locations, the org's seniority mix
9The lengths of delays, relative to the rate of system change.deploy lead time, time to hire, how fast sales feedback reaches product
8The strength of negative feedback loops, relative to the impacts they are trying to correct against.incident review strength, code review, customer complaint escalation, auditors
7The gain around driving positive feedback loops.referral incentives, network effects, compounding reinvestment, how fast tech debt compounds
6The structure of information flows (who does and does not have access to information).showing engineers the cloud bill or customer tickets; public dashboards; transparent pay bands
5The rules of the system (such as incentives, punishments, constraints).compensation plans, promotion criteria, approval rules, pricing model
4The power to add, change, evolve, or self-organize system structure.teams allowed to form, split and change their own process; an internal platform others build on
3The goals of the system."growth at all costs" vs "profitable growth"; "ship features" vs "retain customers"
2The mindset or paradigm out of which the system — its goals, structure, rules, delays, parameters — arises.shared beliefs such as "software is a cost center" or "customers are the enemy of margin"
1The power to transcend paradigms.holding no model as final truth; being able to switch frames as the situation demands
Observation from the essayPractical reading
Meadows says parameters are "dead last" on the list, yet get most of our attention (she guesses "90, no 95, no 99 percent")most management meetings argue about numbers; the structure producing them goes unexamined
she quotes Jay Forrester: people often know intuitively where leverage points are, but push them "IN THE WRONG DIRECTION"a leverage point found by intuition still needs its direction checked against the loops
the list began as a nine-item list scribbled at a meeting and was revised over years; she calls it "a work in progress"treat the order as a heuristic, not a law
information flows (6) are cheap and powerful: "Missing feedback is one of the most common causes of system malfunction."before changing rules, make the consequences visible to the people causing them

The iceberg model

A teaching device used widely in systems thinking courses: what you see (events) is the tip; below it are patterns, the structures producing them, and the mental models that sustain the structures. No single originator is documented; Senge's The Fifth Discipline distinguishes event, pattern-of-behavior and structural explanations, and practitioner versions add mental models as the deepest layer.

LevelQuestionTypical responseExample: production outages
Eventswhat just happened?react: fix it nowthe site went down on Tuesday
Patternswhat has been happening over time?anticipate: plan for itoutages cluster after big Friday releases; three this quarter
Structureswhat is causing the pattern?design: change the systemweekly batch releases, no canarying, on-call rota staffed by the release authors, incentives to ship by the sprint deadline
Mental modelswhat beliefs keep the structure in place?transform: change the thinking"moving fast means skipping process"; "outages are bad luck"; "ops is someone else's job"

Leverage rises as you go down; so does the difficulty and time needed.

Emergence, resilience, self-organization and hierarchy

PropertyMeaningImplicationExample
Emergencesystem-level behavior that none of the parts has alone and that comes from their interactionsyou cannot understand it by studying parts in isolation; you can only change it via interactionstraffic jams, market prices, team culture, a flash crash
Resiliencethe ability to survive and recover from disturbance, from a variety of redundant balancing loops (Meadows)it is often invisible until lost; optimizing for efficiency strips it outjust-in-time supply chains in 2020–21; a single engineer who knows the billing system
Self-organizationthe capacity to make its own structure more complex: learn, diversify, evolveproduces surprises; suppressing it for control reduces adaptabilityopen-source ecosystems, internal tooling that spreads team to team
Hierarchysubsystems nested in larger systems, each mostly self-regulating, with fewer links between than within themmakes complex systems stable and evolvable; fails when the top over-controls (centralization) or the parts optimize against the whole (suboptimisation)microservices, divisions, cells in organs

Herbert Simon's "The Architecture of Complexity" (1962) makes the hierarchy argument with a parable of two watchmakers: the one who builds from stable sub-assemblies finishes watches; the one who builds each watch as a single assembly loses all progress whenever he is interrupted (paraphrased). The same logic underlies Gall's law, below.

Laws, effects and traps

Law or effectStatementUse
Gall's lawJohn Gall, General Systemantics (1975): "A complex system that works is invariably found to have evolved from a simple system that worked. A complex system designed from scratch never works and cannot be made to work. You have to start over, beginning with a working simple system." (wording varies slightly between editions)ship the simplest working version and grow it; distrust big-bang rewrites and grand org redesigns
Goodhart's lawCharles Goodhart (1975): "Any observed statistical regularity will tend to collapse once pressure is placed upon it for control purposes." Marilyn Strathern's 1997 generalization: "When a measure becomes a target, it ceases to be a good measure."pair every target with a counter-metric; rotate metrics; keep some measures for observation only
Campbell's lawDonald Campbell (1976; published 1979): "The more any quantitative social indicator is used for social decision-making, the more subject it will be to corruption pressures and the more apt it will be to distort and corrupt the social processes it is intended to monitor."the social version of Goodhart: expect gaming, not just drift
Conway's lawMelvin Conway, "How Do Committees Invent?" (Datamation, 1968): "organizations which design systems (in the broad sense used here) are constrained to produce designs which are copies of the communication structures of these organizations."design team boundaries to match the architecture you want (the "inverse Conway maneuver")
Brooks's lawFred Brooks, The Mythical Man-Month (1975): "Adding manpower to a late software project makes it later."a Fixes that Fail instance: onboarding and communication costs arrive before the extra capacity
Second-order effectsthe consequences of the consequences; first-order effects are usually intended, later ones often notfor each intervention ask "and then what?" at least twice
Unintended consequences / perverse incentivesan incentive rewards the measured proxy, so people produce the proxypay for outcomes that are hard to fake; test incentives on a small scale first
Policy resistancea system pushes back against an intervention because its actors keep pulling toward their own goals (Meadows' trap; Senge: "compensating feedback")find out what each actor wants and why; align goals rather than pushing harder

The cobra effect, the story of a colonial bounty on cobras in Delhi leading to cobra farming, is the standard illustration of perverse incentives, but it is anecdotal: the term was coined by the economist Horst Siebert (Der Kobra-Effekt, 2001) and no contemporary record of cobra breeding has been found. The better-documented case is the Great Hanoi Rat Massacre of 1902, researched by historian Michael Vann: the French administration paid a bounty per rat tail, and people cut off tails and released the rats to breed.

Le Chatelier's principle in chemistry says a system at equilibrium responds to a disturbance by shifting to counteract it. Policy resistance is the social analogue, and the reason Jay Forrester called social systems "counterintuitive" ("Counterintuitive Behavior of Social Systems", 1971): intuitive policies often attack symptoms, trigger compensating loops, and leave the problem as bad or worse.

Senge's "laws of the fifth discipline" (The Fifth Discipline, ch. 4), condensed and paraphrased:

Law (paraphrased)Loop behind it
today's problems come from yesterday's solutionsFixes that Fail, Shifting the Burden
the harder you push, the harder the system pushes backpolicy resistance, compensating balancing loops
behavior grows better before it grows worsedelayed side effects
the easy way out usually leads back in; the cure can be worse than the diseasesymptomatic fixes that erode the fundamental solution
faster is slowerpushing past a system's optimal rate triggers limits
cause and effect are not closely related in time and spacedelays, and effects that appear in another part of the system
small changes can produce big results, but the highest-leverage areas are often the least obviousleverage points
dividing an elephant in half does not produce two small elephantsemergence: the whole has properties the parts lack
there is no blamethe structure, not the individual, produces the behavior

Applying it

To a startup

QuestionSystems framingWhat to look at
Why has growth stalled?stock of customers near its steady state A/cA/c, or a growth loop meeting a limitcompute A/cA/c; list the limits (market size, support capacity, onboarding friction, channel saturation)
Which growth loops do we have?reinforcing loops: referral (users → invites → users), content (users → content → search traffic → users), paid (revenue → ad spend → customers → revenue)the gain of each loop (e.g. invites per user × conversion) and its delay; a loop with gain below 1 per cycle does not self-sustain
Why does churn keep rising as we grow?Growth and Underinvestment: support, onboarding and reliability capacity lag demandresponse times, incident rate and churn by cohort; invest ahead of the limit
Why do discounts not stick?Shifting the Burden: discounting relieves the sales gap but trains customers to wait for discounts and reduces pressure to improve the productshare of revenue on discount over time; win-rate at full price
Why is our metric improving but the business not?Goodhart and seeking the wrong goala counter-metric for every target (activation with 30-day retention, velocity with change failure rate)

To an organization

SymptomLikely structureIntervention
a shared platform team is overwhelmed and every team complainsTragedy of the Commonsvisible cost per requesting team, a published intake policy, self-serve tooling
senior people are always firefightingShifting the Burden to the intervenorpair on incidents, runbooks, rotate on-call through the whole team
targets quietly lowered each quarterEroding Goalsanchor to customer-facing or external benchmarks; publish the target's history
teams "throwing work over the wall"Conway's law plus Accidental Adversariesredraw team boundaries around the product flow; shared goals across the handoff
reorganizations every year with no lasting changeintervening at the level of parameters and elements, not goals, rules or information flowschange what information people see and what they are rewarded for

To personal habits

Habit dynamicStructureLever
fitness, skill and savings build slowly and decay slowlystocks with small flows and long delaysjudge the inflow (sessions, hours, deposits), not the stock, week to week
a streak keeps itself goingreinforcing loop: practice → competence → enjoyment → practicemake the first cycles easy so the loop starts
caffeine to cover lost sleepShifting the Burden: the quick fix worsens the underlying sleep deficitfix the fundamental (sleep time) and use the quick fix only while transitioning
"I'll run 3 times a week" becomes once, then "when I can"Eroding Goalsfix the goal to an external anchor (a race date, a training partner)
weight regain after a dietbalancing loops (appetite, metabolic adaptation) resisting a parameter changechange the structure (environment, routines), not just the target number

To software

Queues, retries and autoscalers are feedback systems; most large outages are loops nobody drew. See system design for the architecture patterns.

ConceptSystems viewNumbers or rule
Little's lawstock = flow × time in the stockL=λWL = \lambda W: 200 req/s × 0.05 s = 10 requests in flight
Queueing and utilizationnon-linear: waiting time explodes as utilization ρ\rho approaches 1single-server M/M/1 queue: W=S/(1−ρ)W = S/(1-\rho); with a 10 ms service time, 20 ms at 50%, 100 ms at 90%, 1 s at 99%
Backpressurea balancing loop: a full downstream buffer slows the upstream producerbounded queues, rejecting or slowing input when full, rather than unbounded buffering
Retry stormsa reinforcing loop: failures → retries → more load → more failures3 retries per call means up to 4× load on a failing service; 3 retrying layers compound to up to 43=644^3 = 64×
Exponential backoff with jitterweakens the retry loop's gain and spreads its timingcap attempts; randomize delays so clients do not retry in sync
Circuit breakers and load sheddingadd a balancing loop that cuts load when error rates cross a thresholdfail fast, serve degraded responses, protect the constrained resource
Autoscaling with warm-up delaybalancing loop with a delay: oscillates if tuned aggressivelyscale on leading signals, add cool-down periods, keep a buffer of warm capacity
Metastable failuresa system that stays broken after the trigger is removed because a reinforcing loop (retries, cache misses, queue growth) sustains the overload (Bronson et al., HotOS 2021)the fix is to break the loop (shed load, drop queues, disable retries), not to wait
Cachesa buffer stock; its failure removes a balancing loop protecting the databasecold-cache start after an outage can overload the origin: warm caches gradually

Systems analysis template

SYSTEMS ANALYSIS: <problem>
 
1. BEHAVIOR OVER TIME
   Variable(s) that show the problem, with units:
   Sketch the trend (past 1-3 years) and the desired trend:
   Pattern: growth / decline / goal-seeking / oscillation /
            S-curve / overshoot-and-collapse
 
2. BOUNDARY AND HORIZON
   What is inside the system? What is environment?
   Time horizon long enough to see the delays:
 
3. STOCKS AND FLOWS
   Stock            Inflows              Outflows
   ..............   ..................   .................
   Implied steady state (inflow / outflow rate):
 
4. FEEDBACK LOOPS (causal loop diagram)
   R1 ................  (links, polarity, delays)
   B1 ................  (goal it seeks, delay)
   Which loop dominates now? Which will dominate later?
 
5. ARCHETYPE MATCH (if any)
   Limits to Growth / Shifting the Burden / Eroding Goals /
   Escalation / Success to the Successful / Tragedy of the
   Commons / Fixes that Fail / Growth and Underinvestment /
   Accidental Adversaries
 
6. ICEBERG
   Events:        ...
   Patterns:      ...
   Structures:    ...
   Mental models: ...
 
7. ACTORS AND BOUNDED RATIONALITY
   Actor   Goal   Information they see   Incentive
   Why is each actor's behavior locally rational?
 
8. LEVERAGE POINTS (Meadows 12 -> 1)
   Candidate interventions, with the level of each:
   Parameter / buffer / delay / loop strength / information /
   rules / self-organization / goals / paradigm
 
9. SIDE EFFECTS AND SECOND-ORDER EFFECTS
   For each intervention: "and then what?" twice.
   Which loop might push back (policy resistance)?
   What gets gamed if this becomes a target (Goodhart)?
 
10. TEST AND MONITOR
    Smallest reversible experiment:
    Leading indicator + counter-metric:
    Expected delay before the effect shows:
    Review date:

Common mistakes

MistakeWhy it hurtsInstead
Drawing everythinga 60-variable diagram explains nothing and persuades no oneone question, one diagram, 5–15 variables; the boundary is set by the question
Ignoring delaysyou misread slow results as failure, double the dose, and overshootmark every significant delay; set the review date after the delay, not before
Treating symptomsthe fix relieves pressure and the cause persists or growsask which loop produces the symptom; check for Shifting the Burden and Fixes that Fail
Blaming peoplereplacing people inside the same structure reproduces the behaviorask why the behavior is locally rational; change information, rules or goals
Linear extrapolationthe dominant loop will change; limits appearlook for the limit and the balancing loop that will take over
Confusing stocks and flows"revenue fell" (a flow) treated like "customers fell" (a stock)label units: a stock is "X"; a flow is "X per period"
Only intervening at parametersthe cheapest intervention is the weakestwalk down the leverage list before settling on a number change
Systems thinking as an excuse for inaction"it's complex" becomes a reason not to actpick the smallest reversible intervention and learn from it
Unfalsifiable diagramsa CLD can explain any outcome after the factwrite down in advance what the model predicts; check it

Critiques and limits

CritiqueSubstanceResponse
Qualitative diagrams are not modelsCLDs cannot tell you magnitudes, timing or which loop wins; two people can draw opposite diagramsquantify the key stocks and flows in a spreadsheet or a system dynamics tool before big decisions
Easy to be vague"everything is connected" is true and uselessinsist on units, polarities, delays and a testable prediction
Hindsight fittingarchetypes can be matched to almost any story after the factuse them prospectively: predict what happens next, then check
Boundary choice is subjectivewhat you leave out drives the conclusionstate the boundary; test whether widening it changes the answer
The Limits to Growth controversythe 1972 world model that launched much of the field was heavily criticized by economists for omitting prices, substitution and technical changemodels are aids to thinking about structure; they are not forecasts
Tragedy of the Commons is not inevitableElinor Ostrom (Governing the Commons, 1990) documented many communities that manage shared resources sustainably through local rules, monitoring and sanctionsthe archetype describes an unmanaged commons; governance is a leverage point
Can ignore power and politicsdiagrams of "the system" can hide who benefits from the current structureinclude actors and their goals explicitly (template step 7)
Over-complicationfor a simple, linear, well-understood problem, a loop diagram is overheaduse it when behavior is recurring, counterintuitive or resists fixes

References