"A complex system that works is invariably found to have evolved from a simple system that worked."
— John Gall, Systemantics, 1975Key Takeaways
- The metro is not a transport system. It is a living model of engineered cooperation.
- Shisa Kanko — Japan's pointing-and-calling technique — reduces human error by up to 85%, revealing how ritual and procedure encode organizational intelligence.
- Reliability is never accidental. It is the accumulated residue of ten thousand deliberate decisions, most of them invisible to the passenger.
- Gall's Law: every complex system that works evolved from a simple system that worked. You cannot design reliability from scratch. You grow it.
- The Sphinx Problem: when every person and every procedure in an institution has been replaced, what makes it still the same institution? The answer is its memory. Strip that memory, and you have not reformed an institution — you have destroyed one.
- The answer is always the same: standards, memory, feedback, and trust — in that order.
Part I: Something Strange on the Platform
The first time I noticed it, I thought I had misread the situation.
A station attendant in a crisp uniform was standing at the edge of a platform. The train had just arrived. Passengers were boarding and alighting in the usual choreographed rush. And then the attendant did something unexpected.
He raised his arm, extended his index finger, pointed down the length of the platform, swept his gaze in the direction of his finger, and called out — to no one in particular, or perhaps to everyone — a short declarative phrase. Then he pointed again, in the other direction, and called again. Only after this did he signal the driver.
Nobody around him seemed to find this strange. Passengers glanced at their phones. The train departed on schedule. The whole thing lasted perhaps four seconds.
I filed it away as one of those quietly fascinating moments that travel offers — a local ritual, culturally specific, probably meaningless to an outsider.
I was wrong about that last part.
What I had witnessed was not a local eccentricity. It was one of the most rigorously studied safety techniques in the world. And embedded within that four-second gesture was an entire philosophy about how human beings make reliable decisions under pressure — a philosophy with implications far beyond any single train platform.
The more I learned about it, the more I realized I had not simply been watching a safety procedure.
I had been watching civilization think.
Part II: The Discovery
The technique has a name: Shisa Kanko (指差喚呼) — loosely translated as "point with finger and call."
Its origins trace to the early twentieth century in Japan, when a train engineer named Yasoichi Hori began losing his eyesight. Worried that his failing vision would cause him to miss a signal and drive through a red light, he began calling out the status of each signal to his fireman, who would confirm it. The practice spread quietly, informally, operator to operator. By 1913, it had been formalized in a railway manual as kanko oto — call and response. The gesture came later: point first, then call, then listen to your own voice confirming what your eyes have just verified.
By the time the practice was studied scientifically — in a 1994 experiment by Japan's Railway Technical Research Institute — the results were striking. Workers performing simple, repetitive tasks made approximately 2.38 errors per 100 actions under normal conditions. With Shisa Kanko applied, the error rate dropped to 0.38 errors per 100 actions. An 85% reduction in mistakes, from a pointed finger and a called phrase.
This is not a small finding. It is a structural one.
The technique works because it converts an internal cognitive act — checking a status — into an external, embodied one. The eyes alone are insufficient; habit dulls them. The mind alone is insufficient; distraction undermines it. But when the hand points, the eyes must follow. When the mouth speaks, the brain must form a complete sentence. When the ears hear the voice, the nervous system loops back and confirms the action has been completed. Four sensory channels, synchronized, for one verification. The body becomes a self-checking system.
Diagram — The Shisa Kanko Attention Loop
┌─────────────────────────────────┐
│ TASK OR STATUS │
│ (Signal · Timetable · Door) │
└────────────────┬────────────────┘
│
┌──────────▼──────────┐
│ EYES OBSERVE │
│ (Visual input) │
└──────────┬──────────┘
│
┌──────────▼──────────┐
│ HAND POINTS │
│ (Motor engagement) │
└──────────┬──────────┘
│
┌──────────▼──────────┐
│ MOUTH CALLS │
│ (Verbal encoding) │
└──────────┬──────────┘
│
┌──────────▼──────────┐
│ EARS CONFIRM │
│ (Auditory loop) │
└──────────┬──────────┘
│
┌──────────▼──────────┐
│ ACTION VERIFIED │
│ Error rate: -85% │
└─────────────────────┘
Shisa Kanko is not a gesture. It is an architecture. By engaging four sensory channels in sequence, the technique forces the brain to complete a full verification cycle before allowing action to proceed.
What began as one engineer's adaptation to personal limitation became, over a century, the encoded intelligence of an entire railway culture.
This is how organizational learning actually works. Not through grand policy announcements. Not through leadership retreats or strategy documents. But through the slow accumulation of specific practices, refined over decades, embedded in the daily behavior of thousands of individuals who may never know why they do what they do — only that it works.
Part III: The Mechanism
There is a concept in systems engineering called organizational memory.
It is distinct from individual memory. A single person can remember the lesson from a near-miss. An organization can either encode that lesson into its standard procedures — or let it die with the person who learned it.
The Japanese railway system chose to encode.
The Shinkansen, Japan's high-speed rail network, launched in 1964 and has since carried more than ten billion passengers. In over sixty years of operation, it has recorded zero passenger fatalities from derailment or collision. Trains on the Tokaido line — linking Tokyo and Osaka — run at up to 285 kilometres per hour, at three to six minute intervals, with an average delay measured in seconds. Not minutes. Seconds.
This is not magic. It is not luck. And it is not solely technology.
It is the product of what engineers call layered redundancy — a philosophy in which no single point of failure is ever sufficient to cause a catastrophe. Every signal has a backup. Every procedure has a check. Every human judgment has a confirmation ritual. And the whole system is designed with the assumption that individual humans are fallible, that distraction is inevitable, and that attention — unassisted — cannot be trusted at scale.
Human factors engineering — the discipline that studies how humans interact with complex systems — emerged formally after the Second World War, when accident investigators began noticing something troubling: most industrial accidents were not caused by equipment failure. They were caused by the gap between what systems assumed humans could do, and what humans actually do under pressure, fatigue, distraction, and routine.
The insight sounds simple. It was revolutionary.
Systems must be designed for humans as they are, not as designers wish them to be. Standards must encode collective knowledge, not assume individual vigilance. Procedures must be ritualized, not improvised. And when accidents happen — as they inevitably do — the system must learn from them, not suppress them.
This is the logic of feedback loops. Every Japanese railway incident generates a report. Every report feeds a review process. Every review either modifies a procedure, updates a training protocol, or reinforces an existing standard. The knowledge does not stay in the mind of the individual investigator. It moves into the system, where it becomes permanent, until the next incident teaches the system something new.
This is institutional memory in its most functional form: the capacity of an organization to remember what individuals cannot be trusted to remember consistently.
A civilization that cannot do this is a civilization that repeats its disasters.
Diagram — Layers of Institutional Reliability
┌──────────────────────────────────────────────────────┐
│ PASSENGER EXPERIENCE │
│ (What the rider sees and feels) │
└────────────────────────┬─────────────────────────────┘
│
┌────────────────────────▼─────────────────────────────┐
│ OPERATIONAL LAYER │
│ Timetabling · Staff Procedures · Signaling │
└────────────────────────┬─────────────────────────────┘
│
┌────────────────────────▼─────────────────────────────┐
│ MAINTENANCE LAYER │
│ Preventive Cycles · Incident Reports · Upgrades │
└────────────────────────┬─────────────────────────────┘
│
┌────────────────────────▼─────────────────────────────┐
│ INSTITUTIONAL MEMORY LAYER │
│ Standards · Historical Records · Encoded Learning │
└────────────────────────┬─────────────────────────────┘
│
┌────────────────────────▼─────────────────────────────┐
│ CULTURE LAYER │
│ Safety Norms · Accountability · Trust in System │
└──────────────────────────────────────────────────────┘
Each layer depends on the one below it.
Failure at any layer propagates upward.
The passenger only sees the top.
Reliability is a stack. What a passenger experiences as punctuality or safety is the visible output of multiple invisible layers, each dependent on the integrity of the one beneath it.
Part III-B: Gall's Law and the Sphinx
There are two questions that every serious student of complex systems eventually has to sit with.
The first is about how complexity gets built. The second is about what holds it together once it exists. They sound related. They are not. And confusing them is one of the most reliable ways to destroy a functioning institution while believing you are improving it.
On how complexity gets built: Gall's Law
John Gall was an American paediatrician who, in 1975, published a small, irreverent book called Systemantics. Most of it reads like satire. One sentence in it is one of the most important observations in the literature of systems thinking:
"A complex system that works is invariably found to have evolved from a simple system that worked."
This is Gall's Law. And when you understand it, the history of Shisa Kanko stops being a quaint origin story and becomes a template.
Consider the progression: a near-sighted engineer calls out signals to his fireman. That is a simple system — two people, one verification, one task. It works. The practice spreads informally because it works. By 1913 it becomes a railway manual entry. The manual entry becomes a training protocol. The training protocol becomes a standard. The standard becomes a national norm. The national norm becomes an internationally studied technique adopted by transit systems from New York to Jakarta.
What was added at each stage was not a new idea. It was a new layer on a working foundation.
You cannot design a complex system from first principles and deploy it fully formed. The history of such attempts is a history of failures — from Soviet central planning to enterprise software implementations that consume years and produce systems no one uses. Every time, the pattern is the same: the designers underestimate the complexity of the environment, overestimate the reliability of human compliance, and produce something that is theoretically correct and practically inert.
The skateboard is not a failed Vespa. It is the first step toward one. Gall's Law is, at its core, a law of humility. It says: the world is more complex than your model of it, so begin with something small enough to be tested, simple enough to be corrected, and honest enough to admit when it is failing.
On what holds complexity together: the Sphinx Problem
The Sphinx of Greek myth posed a riddle to every traveller who approached Thebes: What walks on four legs in the morning, two at noon, and three in the evening? The answer — man — is not merely a clever observation about the stages of life. It is a question about identity across radical transformation.
The infant and the old man share almost nothing physically. Different height, different strength, different cognition, different dependencies. And yet we say they are the same person. We hold them legally continuous, morally continuous, narratively continuous. Something persists through the transformation.
Now apply the same question to an institution.
The Japanese National Railways was founded in 1872. Today's Shinkansen operators bear almost no physical resemblance to those early railways. The technology has been replaced multiple times over. Every employee from 1872 is dead. The organizational structure has been reorganized, privatized, and subdivided. Even the tracks have been rebuilt.
In what sense is it the same institution?
The answer, I think, is in its memory. Not the memory of any individual within it — individuals die and retire and forget. But the procedural memory that lives in the standards, in the training manuals, in the incident reports, in the accumulated record of what was tried, what failed, what was corrected, and why.
Strip that memory, and you do not have a reformed institution. You have a new one, wearing the old one's name, and about to rediscover — at considerable cost — the things the old one spent generations learning.
This is why the deliberate destruction of institutional memory is one of the most consequential — and most underappreciated — acts of political violence. It does not look like violence. It looks like reform. It looks like efficiency. It looks like clearing out the old guard to make room for new thinking.
Gall's Law tells you how to build. The Sphinx tells you what you are risking when you tear down. Together, they explain why the hardest thing in institutional design is not creating something new. It is preserving what is already quietly working, while still having the courage to change what is not.
Part IV: The Zoom Out
Spend enough time thinking about the metro and you realize that the train is almost incidental.
The real subject is coordination.
How do you get a thousand strangers — with different schedules, different destinations, different tolerances for delay — to move through a shared space without chaos? You engineer the space. You design clear lanes, visible signals, audible warnings. You make the right behavior easy and the wrong behavior hard. You post maps at entrances, announcements at intervals, colored lines on floors. You train staff to recognize edge cases. You build procedures for when things go wrong.
None of this is passive. Every element of a functioning metro system is a deliberate answer to a question that someone, at some point, had to ask: What will go wrong here, and how do we design for it?
Now zoom out one level. A hospital operates on the same logic. Its checklists before surgery, its drug dispensing protocols, its isolation procedures for infectious patients — these are not bureaucratic inconveniences. They are the accumulated answers to questions that were, in most cases, written in someone's blood. Atul Gawande documented this in The Checklist Manifesto: introducing a nineteen-point surgical safety checklist in eight hospitals across eight countries reduced complications by 36% and deaths by 47%.
A pointed finger in a hospital saves lives too. It just looks different.
Zoom out again. A functioning government operates on the same logic, or should. Its regulatory agencies encode lessons from industrial accidents. Its judicial record encodes lessons from disputed rights. Its budget processes encode assumptions about what a society values and what it cannot afford to lose. When those systems work, they accumulate wisdom. When they fail — when institutional memory is disrupted, when procedures are abandoned for efficiency, when feedback loops are severed by political will or bureaucratic inertia — the system begins repeating failures it should have already learned to prevent.
The metro is, in a sense, civic infrastructure made visible. When a city's metro works, it signals something beyond transport. It signals that the institutions of that city are capable of sustained collective action. The metro is a demonstration of institutional competence, running twenty hours a day.
Broken metro systems are not merely inconvenient. They are symptoms.
This is why transit is a political subject everywhere. It is not really about transport. It is about what kind of institutions a society is capable of sustaining.
Diagram — One Principle, Many Systems
STANDARDS ── MEMORY ── FEEDBACK ── TRUST
│ │ │ │
▼ ▼ ▼ ▼
┌────────────────────────────────────────────────────────┐
│ METRO │ Safety regs │ Incident logs │ On-time │
│ │ Procedures │ Route data │ record │
├───────────┼──────────────┼───────────────┼─────────────┤
│ AVIATION │ Checklists │ Black boxes │ Crew CRM │
│ │ FAA rules │ NTSB reports │ culture │
├───────────┼──────────────┼───────────────┼─────────────┤
│ MEDICINE │ Protocols │ Mortality │ Disclosure │
│ │ Dosage maps │ reviews │ norms │
├───────────┼──────────────┼───────────────┼─────────────┤
│ GOVT │ Law │ Judicial │ Legitimacy │
│ │ Regulation │ record │ mandate │
├───────────┼──────────────┼───────────────┼─────────────┤
│ CITY │ Planning │ Census data │ Civic │
│ │ codes │ Civic record │ norms │
└────────────────────────────────────────────────────────┘
The specific content differs. The architecture is identical.
Every system that must coordinate strangers at scale faces the same design problem. The ones that solve it consistently share the same four components.
Part V: The Universal Architecture
If you study enough complex systems — railways, hospitals, aviation, financial markets, governments, ecosystems — a pattern emerges. Every system that achieves sustained reliability shares four features.
01 — Standards
Codifying what exceptional individuals know
Reliable systems convert the judgment calls of exceptional individuals into procedures that ordinary individuals can follow consistently. This is not about eliminating expertise. It is about preserving it. The expert's insight becomes the standard; the standard outlives the expert. Aviation learned this after decades of fatal crashes. Medicine is still learning it. Governance, in most places, has barely begun.
02 — Institutional Memory
Remembering what must not be forgotten
Reliable systems remember their failures. They investigate incidents not to assign blame but to extract learning. They store that learning in places where it can be retrieved and applied — in procedures, in training programs, in design modifications, in the accumulated record of what went wrong and why. A system without institutional memory is a system that must re-learn everything from first principles, at the cost of whoever is unfortunate enough to be present at each re-learning. This is the definition of preventable tragedy.
03 — Feedback Loops
Listening to the system's own signals
Reliable systems listen to themselves. They monitor performance, detect deviation, and respond. The Shinkansen knows, to the second, when any train deviates from schedule. When feedback loops are severed — when reporting is discouraged, when data is not collected, when signals of dysfunction are ignored by the people with authority to act on them — the system becomes blind. Blind systems do not improve. They drift toward failure, one unacknowledged deviation at a time.
04 — Trust
The most fragile ingredient, and the most essential
No standard is followed without some degree of trust in the institution that created it. No feedback loop functions if individuals fear punishment for honest reporting. No institutional memory is maintained if the culture of an organization treats the record of past failures as a liability rather than a resource. Trust is not sentiment. It is infrastructure. When citizens trust a metro system, they plan their lives around it. That trust creates the ridership that justifies the maintenance budget that keeps the system running on time. Break the trust — through chronic delays, unexplained fare increases, safety incidents that feel preventable — and the loop runs in reverse.
Part VI: The Reflection
I have ridden metro systems in several cities. Some of them feel like infrastructure. Clean, functional, purpose-built for the movement of bodies from point to point. Others feel like something more. Like you are moving through an institution — one that has been thinking about your journey longer than you have, that has learned from the journeys of millions before you, that is quietly doing ten thousand things correctly so that you can do the one thing you came to do: arrive.
That feeling is the product of accumulated intelligence. It is what Shisa Kanko means, at its deepest level. Not merely a safety technique. An attitude. A philosophy that says: the world is more complex than any individual's attention, and the appropriate response to that complexity is not confidence — it is ceremony.
Point. Call. Confirm. Move.
Gall's Law tells us that this encoding had to begin small. The Shinkansen began with a near-sighted engineer and a fireman. The surgical checklist began with a clipboard and a surgeon willing to feel slightly absurd. Every reliable system began with someone solving today's problem carefully, not someone designing tomorrow's system brilliantly.
And the Sphinx reminds us what we are protecting when we protect these systems. Not the buildings, not the org charts, not the individuals. The memory. The accumulated residue of every correction, every near-miss, every procedure written because something once went wrong and someone decided it must not go wrong again.
The question worth taking with you, when you step off the platform, is whether the institutions you inhabit — the ones that govern your city, that manage your healthcare, that process your vote, that allocate your taxes — have learned the same lesson.
Or whether they are still, in some fundamental sense, running on hope.
The train that arrives on time is the visible end of a very long chain.
Somewhere in that chain, a century ago, a near-sighted engineer started calling out the signals.
Nobody told him he was building a philosophy.
But he was.
Reliability is not a condition. It is the memory of ten thousand decisions not to take the shortcut.
— Collins KanyekiQuestions I'm Still Thinking About
Books & References
Human Factors Engineering & Reliability
- Dekker, S. (2006). The Field Guide to Understanding Human Error. Ashgate.
- Reason, J. (1990). Human Error. Cambridge University Press.
- Perrow, C. (1984). Normal Accidents: Living with High-Risk Technologies. Basic Books.
Checklists & Procedure
- Gawande, A. (2009). The Checklist Manifesto: How to Get Things Right. Metropolitan Books.
Systems & Complexity
- Gall, J. (1975). Systemantics: How Systems Work and Especially How They Fail. Quadrangle/NYT Books.
- Meadows, D. (2008). Thinking in Systems: A Primer. Chelsea Green Publishing.
Institutional Memory & Organizational Learning
- Levitt, B., & March, J. G. (1988). Organizational Learning. Annual Review of Sociology, 14, 319–340.
- Argote, L. (1999). Organizational Learning: Creating, Retaining and Transferring Knowledge. Springer.
Japanese Railway Safety
- Railway Technical Research Institute, Japan (1994). Study on Pointing and Calling Error Reduction.
- Shinkansen safety and operational data: Japan Railway & Transport Review.
Cities & Infrastructure
- Jacobs, J. (1961). The Death and Life of Great American Cities. Random House.
- Graham, S., & Marvin, S. (2001). Splintering Urbanism. Routledge.