· Systems · 14 min read
Meet Reckless — Because Meaningless Isn't Enough
Meaningless is the optimistic case. When a true finding survives the writing stage and then dies anyway — killed by a scoreboard, or overruled a floor above you — blameless has quietly become the fig leaf over reckless.

Last week we buried a post-mortem that died of politeness. It got softened, de-named, de-teamed, and generalized down to nothing, until the report offended no one and taught nothing. A horoscope with a severity rating. That was meaningless — the death of a conclusion that was never allowed to be said out loud.
But I called that the optimistic case, and I meant it. On its own, meaningless looks like nothing worse than a pointless ritual — an afternoon spent producing a document nobody will act on. Wasteful, but survivable. Except the road doesn’t end at the pointless ritual. Because sometimes the ritual actually works: sometimes the culture holds, the room is brave, and you walk out with the real conclusion intact — named, generalized, honest, agreed. A genuine action item, the kind that would actually move the needle.
And then it goes looking for a place in the plan. And that, it turns out, is where the worse thing lives.
This is where you meet the second death of a true finding — not softened into nothing, but written down, agreed to, and quietly never done. And the culture of the organization pushes it there by at least two different routes. One is diffuse and needs no villain at all: a set of incentives that quietly makes everyone stop caring about the fix. The other is sharp and specific: a decision, made a floor above you, that the risk you flagged simply doesn’t rank. Two mechanisms, one destination. Say hello to reckless.
Reckless isn’t a synonym for brave
Let’s get the word right first, because “reckless” sounds like bravery’s unhinged cousin. Something with adrenaline in it. Pulling a kid out of a burning building, charging in without thinking.
That’s not this at all. The reckless I mean has no adrenaline and no heroism. It’s crossing a six-lane highway blindfolded — not once, on a dare, but as your standing commute — on the strength of that one time you did it in the dead of night when nothing was coming. It worked then, so it must work always, and anyway taking the blindfold off is a whole project, and we’ve got it slotted for Q3. Of some year.
It’s closer to the legal sense of the word, the one that lives next to negligence. In practice it means you knew, you wrote it down, and you decided the risk was someone else’s problem for now — like a child who’s certain that if he can’t see you, you can’t see him, except the thing he can’t see is a truck. Recklessness is negligence with a paper trail. It’s the difference between “we never saw it coming” and “we saw it coming, logged it, and chose to keep the blindfold on.”
And that second one is so much worse, precisely because the paper trail exists. A team that didn’t know is ignorant, and ignorance is fixable — you go find out. A team that knew and pretended otherwise is something else. It has, in writing, chosen not to fix a thing it understood. When that thing finally goes off, the post-mortem for that outage gets to include the beautiful sentence: “a previously identified risk.” Identified. By us. And then left there, armed, because it didn’t fit the quarter.
The action item didn’t fail because it was wrong. It failed because it was inconvenient, and inconvenient loses to the roadmap every single time.
The first route: nobody has to decide anything
Here’s the unsettling part. You don’t need a villain to get to reckless. You don’t need a VP spiking a fix or a manager burying a warning. The diffuse version needs no decision at all — just incentives left running unattended, and blameless holding the door.
Watch how it assembles itself. Delivery speed is rewarded — it’s on the dashboard, it’s in the OKRs, it’s what gets you promoted. Quality is, at best, discussed. It gets a nod in planning and a paragraph in the values deck, but nothing measures it and nothing is staked on it. So the team does the only rational thing: it optimizes for what’s measured. It ships. Fast. And it gets very, very good at shipping fast, because that’s the muscle you’re paying to grow.
Now add blameless — the good, real, psychologically-safe kind. The feature that ships held together with zip ties and crossed fingers goes out the door, and when it wobbles, nobody’s punished, because we don’t do that here. So the engineer collects the reward for shipping the feature and pays no price for the feature being garbage. Both halves of the incentive point the same way: ship, don’t worry, ship again.
And to be clear, the answer is not to start punishing the engineer — psychological safety is doing exactly its job. The answer is to notice you’ve built a reward function in which quality has no economic signal at all. Properly wired, blameless makes quality part of how the work is valued. Wired to a scoreboard that only counts throughput, it just removes the last thing that used to make anyone slow down.
And the post-mortems that catch the wobbles? We already spent last week watching those get sanded down to meaningless — so the incidents get documented, beautifully, in reports that name nothing and change nothing. Delivery speed triples on paper. Incidents-per-feature triple right alongside it. And the team gets praised for its efficiency, because the dashboards are green and the post-mortems are immaculate.
That’s the machine. Nobody chose recklessness. Everybody just responded, sensibly, to the scoreboard in front of them — and the scoreboard only counted one thing.
And notice it got there without anyone doing anything wrong on purpose: reckless as an emergent property of a scoreboard. The second route is less patient. It has a decision in it, and a decider.
”We’ll track it” is where fixes go to die
Here’s the sharper mechanism, and it’s so mundane you’ve probably nodded along to it this month.
The honest action item gets written. It’s real, it’s good, and it’s big — because the honest ones usually are. “Map our undocumented service dependencies.” “Fix the deploy process that let this ship blind.” “Give team B the capacity to stop firefighting long enough to address the root cause.” None of these fit in a sprint. All of them cross a boundary. Each one needs someone with actual authority to move a priority.
So it gets a ticket. The ticket gets a label — tech-debt, or reliability, or the truly damned P3. It goes into the backlog, which is
the organizational equivalent of the drawer where you put the thing you’re definitely going to deal with later. And then the quarter turns,
the OKRs are what the OKRs are, and the honest fix sits there accumulating dust and staleness while the roadmap marches past it.
Nobody kills it. That’s the elegant part. Nobody has to stand up and say “we’ve decided not to fix the thing that took down checkout.” That would be a decision, and decisions have owners, and owners can be asked about them later. Instead it just… doesn’t happen. It’s not rejected. It’s deprioritized, which is the corporate passive voice — the same trick we saw last week, moved up a floor. “A mistake was made” becomes “the item was deprioritized.” No hand on it. It deprioritized itself.
Job done. Ticket closed. Back to shipping features.
This was never really about post-mortems
Now let me widen the lens, because if you think this is a post-mortem problem, you’ve been looking at the smallest version of it.
The post-mortem is just the place where it’s easiest to see, because there’s a document. But the same machine runs everywhere, and most of the time there’s no incident and no report to make it legible. It’s the load-bearing pattern of how organizations ignore the people who can see the wall coming.
Someone on the floor — the engineer actually holding the system — raises a hand. “This is going to break.” “We’re one bad week from running out of headroom.” “The thing you’re asking for in Q3 depends on the thing we’ve been warning you about since Q1.” It’s specific, it’s early, and it’s correct. It is also, from the tower, noise. Because the tower is optimizing for the roadmap it committed to, and a warning that doesn’t fit the roadmap isn’t a warning. It’s a scheduling inconvenience.
This is the actual shape of it: the people with the most context have the least authority, and the people with the most authority have the least context — and we have built an entire ritual of quarterly planning that ensures information flows in exactly the wrong direction. The floor sees the failure and can’t fund the fix. The tower funds the work and can’t see the failure. And the gap between them is measured in outages.
And it’s worse than a context gap, because you could close a context gap — you’d just have to listen. It’s an incentive gap. The tower isn’t only missing the information; it’s rewarded for missing it. Leadership is measured on roadmap completion, not on the outage that hasn’t happened yet, so every hour spent on the boring preventative fix is an hour not spent on the thing they’re actually graded on. Ignoring the warning isn’t a lapse. It’s the locally rational move. And here’s the kicker: when the risk finally detonates, they won’t be the ones holding the pager at the worst possible hour. That’s the floor’s job too. So the tower gets to deprioritize the fix, collect the roadmap bonus, and hand the eventual cleanup back down to exactly the people who flagged it in the first place. The warning and the wreckage both live on the floor. Only the decision lives upstairs — and the pager that goes off at the worst possible hour stays down on the ground floor, with the people who saw it coming.
You’ve watched this. Capacity that everyone knew was too thin. Tech debt that got a stern paragraph in three consecutive planning docs and never a single sprint. The migration everyone agreed was necessary and no one was ever allowed to start. The warning that turned out to be exactly right, six months early, and cost nothing to ignore right up until it cost everything.
The sentence the template doesn’t have a field for
And here’s where it loops back to last week, and this is the part I actually want you to sit with.
When that ignored warning finally detonates — when the thin capacity runs out, when the deprioritized dependency takes down production — we hold a post-mortem. Of course we do. We’re mature like that.
And in the root cause section, there is a sentence that cannot be written. Not “shouldn’t.” Cannot. The true root cause is: “this broke because six months ago people told us it would break, and we decided the quarterly plan mattered more.” That is the honest finding. And it is structurally impossible to put in the document, because it doesn’t point at a bad deploy or a missing test or a tired engineer. It points up. At a prioritization decision made a floor above the people writing the report.
Watch how the two halves of this series close the same trap from opposite ends. Last week, “blameless” forbade you from saying the junior broke it — it protected the person at the bottom. This week, “blameless” forbids you from saying leadership ignored it — it protects the decision at the top. Same word. Same shield. It just happens to face downward when it’s shielding a junior from a witch hunt, and upward when it’s shielding a VP from a consequence. Funny how the noble version and the convenient version use the identical vocabulary.
So the blameless post-mortem, the one we invented to help us learn, turns out to be structurally incapable of recording its own most important cause — because that cause isn’t technical and isn’t on the floor. It lives in the prioritization, one level up, in the decision that the roadmap outranked the risk. And there is no field in the template for “the org chose this.” There never will be. The people who own the template are the people that field would name.
The one place blameless suddenly stops applying
There’s a tell, and once you see it you can’t unsee it.
“Blameless” is offered generously right up until the moment someone uses it to point upward. Take down production with a bad deploy? All is forgiven, we don’t blame here, let’s learn together. But say the corporate version of I told you so — stand up in the retro and note, calmly and correctly, that this exact failure was flagged two quarters ago and deprioritized — and watch how fast the warmth drains out of the room.
Nobody will punish you for it right there. That’s not how it works. The culture is far too polished for an on-the-spot reprisal. But you can be reasonably certain that nobody will be reaching for the “blameless” principle at your year-end review, either. It won’t show up as “insubordination,” because that word would leave a mark. It’ll show up as not a team player. Struggles with stakeholder alignment. Communicates in a way that creates friction. The vocabulary of the performance review is even better at laundering a grudge than the post-mortem template is.
So blameless turns out to have an implicit exception clause nobody prints on the poster: blameless applies to failures that point sideways or down. Aim it up the org chart and you discover, quietly and personally and about six months later, that it was conditional all along. The rule that supposedly protects everyone protects everyone equally — except the one person willing to say the single most useful thing in the building.
Standing ovation for the school play
Put both routes together — the scoreboard that quietly rots the floor, the hierarchy that quietly overrules it — and what you end up with is theater. Not the metaphor thrown around lightly. The full production.
There’s a stage. There’s a script, and everyone has their lines: the incident review, the five whys, the action items, the follow-up nobody follows up on. The director and the cast perform it with total conviction, straight-faced, as though this is high art — a rigorous, mature, learning organization at work. The audience rises for a standing ovation, Broadway-grade, because look how well-scripted it all is, look at the costumes and the decor, appreciate the sheer effort that went into the preparation.
And everyone in the building has quietly agreed not to mention that it’s a school nativity play. Cardboard sets, kids reciting lines they don’t understand, and nothing on that stage has ever prevented a single thing it claims to be about. We all clap. We all know. We all keep the secret.
This is not a blameless culture. This is a reckless culture with better documentation.
Reckless, defined
So here’s the whole descent. Three words, one slope.
Blameless was the ideal, and it was a good one. Don’t punish people for honest mistakes, so they’ll tell you the truth, so you can actually learn and fix the thing. Name it, protect the person, learn, improve. Nobody sane is arguing against that. I’m certainly not.
Meaningless was the first fall, and last week was about it: we got so careful with the language — don’t name the person, don’t name the team, don’t point anywhere that stings — that the report quietly stopped meaning anything. Bad, but survivable.
Reckless is the bottom, and it’s where both of this week’s roads lead. The committee thought carefully, understood completely, wrote the fix down in plain view — and then didn’t do it, because a scoreboard rewarded something else, or because a decision one floor up outranked it. Everything was tracked. Everything was visible. Everything was, in the end, ignored on purpose. That’s not a culture that failed to see the risk. That’s a culture designed to remain blind to it.
“Blameless” on the office wall is a lovely value. But a lot of the time, in practice, it’s the fig leaf we drape over reckless — a word that sounds like accountability while quietly guaranteeing that the one decision that actually caused the outage is the one decision no post-mortem is allowed to name.
Learn from that. If they’ll let you.



