Executive attention, information, and organizational sensing
Columbia's foam strike was visible on launch video, yet the damage never became an authoritative in-flight safety problem. Engineers sought imagery while program managers treated prior foam loss as evidence that the mission remained safe. Organizational sensing fails not when data is absent, but when a weak signal cannot acquire meaning, standing, and access to the authority that can act.
Governing questionHow does an ambiguous cue become an authoritative situation before the time to protect people closes?
The strike was visible before the danger became believable
About 82 seconds after the space shuttle Columbia launched on January 16, 2003, insulating foam separated from the external tank and struck the orbiter's left wing. Launch cameras recorded the event. Image analysts identified an unusually large debris strike, engineers formed a Debris Assessment Team, and participants sought higher-resolution imagery of the wing.1
The observation did not become an authoritative safety-of-flight problem. The Columbia Accident Investigation Board found that managers relied on prior foam events and early reassurance, while the assessment team lacked adequate imagery and a validated model for the observed impact. Program managers placed the burden on engineers to demonstrate an unsafe condition rather than requiring the program to establish safety for an event outside validated experience.1
On February 1, superheated air entered through a breach in the left wing during re-entry and the orbiter was destroyed. Rick Husband, William McCool, Michael Anderson, Kalpana Chawla, David Brown, Laurel Clark, and Ilan Ramon died.1 The physical breach explains how the vehicle was lost. The decision record asks why visible uncertainty did not produce the evidence, standing, and action needed while a useful decision window remained open.
The working model has four steps: observation, interpretation, standing, and authorized response. That sequence is editorial, not a scale tested by the Board. Columbia supports it as a way to organize the record; one case cannot establish that every sensing failure follows those steps or that faster escalation always improves safety.
Earlier foam loss supported incompatible interpretations
Foam had separated on earlier shuttle flights without destroying an orbiter. Managers could read safe returns as evidence that foam loss was an understood maintenance issue. The Board instead emphasized that debris-shedding requirements had repeatedly not been met and that prior success had substituted for engineering evidence about the margin of safety.1
The same history therefore supported two situations: recurring but tolerable damage, or a requirement violation whose consequences remained incompletely characterized. The Board described the normalization of foam loss as part of the organizational cause.1 Independent organizational scholars have used Columbia to examine safety drift, language, deadlines, learning, and limits, but their chapters offer several interpretations rather than one experiment that isolates a cause.2
A category such as “in-family” can absorb a new event into a familiar explanation. That is an analytical inference from the record, not proof that categories always suppress anomalies. Reports and databases can preserve evidence while also making a settled label easier to retrieve than the possibility that the label has failed.
Imagery requests lost standing in the hierarchy
The Board reconstructed three separate initiatives to obtain outside imagery. Confusion surrounded who had requested it, whether the request was official, and which channel it should follow. Managers asked about the request's origin and procedure while members of the Debris Assessment Team did not understand that management had decided not to pursue the imagery they wanted.1
Those facts distinguish expression from organizational standing. Analysts could raise concern, but program management controlled whether the concern acquired resources and a place in mission-level deliberation. The Board found that early informal reassurance from an accessible expert went unchallenged while the assessment team's unresolved analysis did not become a safety-of-flight issue.1
Burden of proof was therefore part of the attention system. If uncertainty must prove danger before it interrupts a mission, missing evidence protects the current plan. If an event outside validated experience requires a renewed safety showing, the same uncertainty can trigger investigation. Which rule is warranted depends on stakes, reversibility, evidence cost, and authority; Columbia does not supply one stopping rule for every domain.1
The people bearing the risk did not control the inquiry
The seven crew members were the people most immediately exposed. The reviewed record does not show that they received a diagnosis of wing damage or the imagery dispute in a form that let them contest management's risk interpretation. Engineers closest to the analysis could not independently obtain national imagery, while senior managers received concern through channels shaped by program roles, prior classifications, and resource authority.1
The Board joined launch video, emails, schedules, analyses, testimony, debris, and organizational history after the loss. That retrospective integration is its strength and its limit. It was an official accident investigation with broad access, not a neutral real-time view available to participants or a representative survey of every engineer, contractor, manager, family member, or community affected by the accident.1
The Board recommended more independent technical authority and safety oversight. Later NASA inspector-general reviews examined implementation, and a 2017 GAO report found that dual programmatic and technical roles could still impair independence in a different human-spaceflight organization.3 These later reviews show that governance design remained contested. They do not re-perform the Columbia investigation or prove that one organizational chart prevents failure.
Independent scholarship widens the explanation without settling it
Organization at the Limit brought organizational scholars to the Columbia record. Its chapters examine history, safety drift, relational breakdown, language, deadlines, learning, systems safety, and resilience.2 The plurality matters: attention failure can be described through cognition, communication, power, schedule, technical limits, or interdependence without assuming that those labels are interchangeable.
Secondary analysis can reveal mechanisms that an official inquiry underplays, but it can also inherit the inquiry's archive and hindsight. The anthology is a strong independent interpretive source, not participant testimony, a representative workforce study, or causal identification across accidents.2 The Board remains the primary source for what its investigation found; the scholarly volume supplies competing explanations of that record.
Andon is a response-design comparison, not a genealogy
Toyota describes andon as a visible signal used when a worker or machine detects an abnormality, with a route to call the responsible leader and, in specified circumstances, stop production.4 The corporate source establishes Toyota's stated practice. It does not independently measure how consistently workers can stop a line, how retaliation and production pressure operate, or whether the practice transfers to spacecraft operations.
The Columbia comparison is limited. Cameras, analysts, meetings, email, and review roles already existed. Adding an alert would not by itself have changed the burden of proof, access to imagery, or authority to reframe the strike. The useful contrast is between a signal that carries an expected response and one whose status must be renegotiated as it rises.1
There is no reviewed evidence that NASA adopted, rejected, or was influenced by Toyota andon. The internal Toyota record and the official Toyota source support a parallel practice, not institutional descent.41
Attention, sensemaking, and reliability ask different questions
Herbert Simon argued that information abundance makes attention scarce and shifts design toward allocating attention effectively.5 That primary conceptual source supports a general attention problem; it does not analyze STS-107 or establish which routing rule would have changed the mission.
Karl Weick asks how ambiguous cues become plausible situations. Sensemaking in Organizations supplies that theoretical lens.6 Applying it to “maintenance issue” versus “crew threat” is an editorial comparison, not a finding that Weick's named mechanisms caused a particular manager's judgment.
Managing the Unexpected describes high-reliability practices such as preoccupation with failure, reluctance to simplify, sensitivity to operations, resilience, and deference to relevant expertise.6 The Board itself used high-reliability organizations as a comparison, but neither the book nor the accident record shows that adopting a checklist of principles guarantees safety.1
The three lenses therefore remain distinct. Simon foregrounds scarce attention, Weick foregrounds situation construction, and reliability theory foregrounds patterns of organizing around anomaly and expertise. None was documented as directing the STS-107 mission in the reviewed sources.561
Digital sensing can accelerate both inquiry and error
An event record containing source, time, actor, affected object, expected state, observed state, evidence, uncertainty, and local action is a local product proposal. So are automated correlation, dependency propagation, and materiality-based routing. The Columbia record motivates reconstructability, but it does not validate those fields or an AI-assisted workflow.
Generative AI can summarize evidence and propose relationships quickly. NIST identifies confabulation, information-integrity, bias, privacy, and human-AI configuration risks. Semantic-entropy research detects one class of arbitrary wrong answers while explicitly leaving systematic errors unresolved. A field experiment found gains on some knowledge-work tasks and worse performance on tasks outside the tested capability frontier.7 These sources support bounded risk and task-fit claims, not general decision improvement.
A system trained on prior classifications could reproduce a settled category with greater speed and fluency. That is a design warning, not a demonstrated counterfactual about Columbia. Original evidence, dissenting analysis, uncertainty, model version, and the distinction between observation and inference must be tested as safeguards rather than assumed effective.
Digital sensing also creates governance costs. Comparative workplace studies and policy reviews identify intrusive monitoring, privacy, agency, dignity, and job-quality risks in some algorithmic-management settings.8 Those findings are sector- and country-bounded; they do not establish that every event system is surveillance or that worker consent is meaningful under every employment relationship.
AI and data infrastructure require electricity. A U.S. Department of Energy summary reports rising aggregate data-center electricity demand, not the attributable footprint of one sensing system.8 Location-specific energy mix, cooling and water, hardware supply chains, land, and ecological consequences remain outside the evidence assembled here. No reviewed source measures the net ecological effect of the proposed designs.
Six product hypotheses remain untested
The six structured proposals are research hypotheses, not conclusions drawn from Columbia:
- I16-P01 proposes an event envelope. Tests must measure reconstruction, source fidelity, calibration, usefulness, spoofing, sensitive-data retention, and whether comprehensive capture becomes surveillance.
- I16-P02 proposes correlating events into a situation while preserving original evidence and separating fact from inference. Tests must measure precision, recall, lead time, minority-signal loss, and false causal stories.
- I16-P03 proposes propagating possible impact through linked intent, work, authority, customer, resource, dependency, and assumption records. Tests must compare predicted with observed effects and identify people, ecosystems, and dependencies missing from the graph.
- I16-P04 proposes routing by materiality and legitimate decision authority. Tests must show that urgent situations reach valid authority without letting a narrow materiality definition hide external harm or permitting self-assigned power.
- I16-P05 proposes a compressed executive brief. Tests must measure comprehension, action, recall of uncertainty, dissent preservation, and whether compression or AI framing creates a new bottleneck.
- I16-P06 proposes separate latency measures for capture, verification, interpretation, propagation, routing, comprehension, decision, execution, and learning. Tests must distinguish useful delay from avoidable delay and check gaming, hidden queues, measurement overhead, consent, and accuracy.
Neither the accident sources nor the later AI and workplace studies validate these product mechanisms. Each requires prospective and retrospective tests across domains, including failed deployments and people unable to appeal.
Eight nodes and seven edges form an editorial map
The nodes mix broad history, case records, theory, and a recent design horizon. I16-N01 is a deliberately broad label for messengers, scouts, logs, and councils; I16-N02 groups military and naval reporting arrangements; I16-N03 marks railroads, telegraphy, and standardized time; I16-N04 marks DuPont and GM management information; I16-N05 marks World War II operations research; I16-N06 marks Toyota andon; I16-N07 marks attention, sensemaking, and high-reliability inquiry; and I16-N08 marks event-driven systems and AI.
The first five nodes are supported only through their linked institutional records, not through a newly researched continuous genealogy here. I16-N06 is bounded by Toyota's official account, I16-N07 by the named theoretical works, and I16-N08 by recent task- and policy-specific evidence.4567
All seven edges are grade-C comparative relations:
- I16-E01 places broad human reporting chains before specialized staff arrangements. Roman military, British Royal Navy, and Prussian–German General Staff source IDs support examples, not one transmission.
- I16-E02 places staff reporting before railroad communications and dispatch. Prussian–German General Staff and U.S. railroads, 1855–1887 support endpoints, not a military-to-railroad lineage.
- I16-E03 places railroad coordination before DuPont and GM reporting. Railroads, DuPont, and GM under Alfred Sloan support separate cases, not one corporate nervous system.
- I16-E04 places corporate reporting before wartime operations research. DuPont, GM, and Allied and U.S. World War II mobilization support distinct endpoints, not direct causal passage.
- I16-E05 contrasts wartime analyst support with Toyota's abnormality response. The mobilization and Toyota records support the comparison, not descent.
- I16-E06 places Toyota practice beside attention, sensemaking, and reliability theories. Toyota, Sensemaking in Organizations, and Managing the Unexpected support endpoints, not influence or synthesis.
- I16-E07 asks how digital systems alter those theoretical problems. Sensemaking in Organizations and Managing the Unexpected support the theory endpoint; recent external research supports only bounded AI comparisons.
Evidence grades describe support for each bounded relation, not importance or effect size. These relations are editorial comparisons, not evidence of causal influence or institutional descent.
Related records are routes, not prerequisites
The six direct relations serve distinct purposes:
- culture, informal organization, trust, and voice is an adjacent route for whether a person can raise and sustain concern;
- organizational ignorance is an adjacent route for unknowns produced or protected by categories and incentives;
- Sensemaking in Organizations is the primary theoretical route for constructing an ambiguous situation;
- learning, quality, and reliability is an adjacent route for anomaly response and institutional learning;
- NASA Apollo program is a historical NASA comparison, not evidence that Apollo and Shuttle organization were identical; and
- benefit for all life is an ethical route for asking whose reality and external effects may interrupt a plan.
No structured reading dependency is recorded. These routes can be read in any order, and relatedness does not establish agreement, historical influence, or shared findings.
Established institutions are comparison paths, not descendants
The institution links are editorial test routes. Their internal records provide their own sourcing. Listing them together does not assert a common practice, performance level, theory adoption, moral status, or institutional lineage.
Historical, military, transport, industrial, and operational comparisons:
- Roman military, British Royal Navy, U.S. railroads, 1855–1887, General Motors under Alfred Sloan, Allied and U.S. World War II mobilization, Procter & Gamble brand management, General Electric, NASA Apollo program, and Joint Special Operations Command / Team of Teams.
Corporate sensing, strategy, ownership, and failure comparisons:
- Amazon, Apple, Blockbuster, Dell, The Hershey Company and Milton Hershey School Trust, Intel, Meta / Facebook, Microsoft, Purdue Pharma, Steward Health Care.
Public-health, regional, resource, and coordination comparisons:
- Africa CDC's regional coordination system, ECOWAS and The Gambia's 2016–2017 transition, Nauru Phosphate Royalties Trust, Nigeria's Ebola Emergency Operations Center, Project Cybersyn, and Rival Libyan state institutions.
Coercion, corruption, secrecy, state capture, and catastrophic-harm comparisons:
- Eskom under state capture, Islamic State administrative apparatus in Iraq and Syria, Odebrecht's bribery organization, Operation Condor, local administrative machinery in the 1994 genocide against the Tutsi in Rwanda, Tatmadaw military-business complex, United Fruit in Guatemala, and Vale and the Brumadinho dam disaster.
The bounded comparison asks how observations acquire meaning, standing, resources, and authority in each case. The links add no new factual assertion about an institution's conduct or consequences.
Impact is real but not classified as one net effect
No structured impact record is assigned. The deaths of seven crew members are documented human consequences, not an unassessed abstraction.1 The sources also establish organizational change and continuing oversight debates, but they do not support one net classification across crew families, NASA civil servants, contractors, managers, recovery participants, taxpayers, communities touched by debris and operations, future crews, nonhuman life, ecosystems, or future generations.3
The absence of an impact record means impact is unclassified, not absent. It also prevents the goal of better executive sensing from standing in for privacy, dignity, labor, equity, energy, water, material, and ecological effects that current product hypotheses do not yet measure.8
Evidence still needed
- Contemporaneous records from the crew, engineers, contractors, and managers that clarify what each person knew, when they knew it, what they believed they could do, and how later testimony changed under hindsight.
- Accounts from crew families, recovery participants, affected communities, and less powerful workers that do not treat official investigators or senior leaders as proxies for their experience.
- Comparative incident studies testing whether burden-of-proof rules, independent technical authority, protected dissent, imagery access, and local stop authority change outcomes across domains.
- Research strong enough to replace I16-N01 through I16-N05 with narrower historical nodes and documented relations, or to retire the implied sequence.
- Independent observation of Toyota andon across plants, worker groups, contract types, production pressure, and retaliation conditions.
- Product trials for I16-P01 through I16-P06 across task types and model versions, including false negatives, minority signals, spoofing, appeal, privacy, disability, labor displacement, and security.
- Lifecycle evidence allocating energy, water, hardware, land, and supply-chain effects to specific sensing designs rather than aggregate data centers.
- Measures of who defines materiality and who can challenge an AI-produced situation when affected people, communities, animals, ecosystems, or future generations have no direct seat.
Paths into deeper study
- Read the Board report's accident analysis and chapter 6 decision history together; separate evidence available during flight from conclusions assembled after the loss.
- Compare the official inquiry with Organization at the Limit and the later oversight reports; note where source roles and causal accounts differ.
- Read Sensemaking in Organizations and Managing the Unexpected as different questions about ambiguity and reliability.
- Continue into measurement, accounting, and control for the categories that make a situation visible, and culture, informal organization, trust, and voice for why a material signal may not retain standing.
Additional reciprocal institution comparisons
Newly developed institutional records add these reciprocal comparison paths:
- China’s reform-era party-state capitalism — institution-comparison
- FedMart — institution-comparison
- Singapore — institution-comparison
- Venice — institution-comparison
Each path identifies a sourced case where this idea is a defining emphasis. The relation is editorial comparison, not evidence of direct influence, shared terminology, or equivalent outcomes.
Source notes
Primary official and participant records assembled by the Columbia Accident Investigation Board. Volume I supplies the launch and accident chronology, physical-cause analysis, chapter 6 decision history, organizational findings, and recommendations; see especially pp. 34, 49–84, and 121–191, NASA Technical Reports Server. Volume II preserves supporting appendices and investigation material, NASA Technical Reports Server. Kennedy Space Center preserves debris-research artifacts and explains their continuing technical use, NASA. NASA's memorial identifies the STS-107 crew and records the agency's remembrance, NASA. The Board had broad retrospective access and incorporated participant records, but its official reconstruction was produced after the loss. It is not a contemporaneous shared picture, a neutral view from nowhere, or a representative account of all workers, families, and communities.
↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩ ↩William H. Starbuck and Moshe Farjoun, eds., Organization at the Limit: Lessons from the Columbia Disaster (2005), contents and publisher description, including chapters on safety drift, relational failure, language, deadlines, learning, systems safety, and resilience, Wiley. The multi-author volume supplies independent organizational interpretations and disagreement. It is secondary analysis of a rare case, not a representative comparison, direct participant record, or causal experiment.
↩ ↩ ↩Later public oversight of NASA's response and technical-authority design. GAO-18-28, highlights and pp. 19–28, examines dual programmatic and technical roles in later human-spaceflight programs and relates the independence concern to Columbia, U.S. Government Accountability Office. NASA OIG's 2005 summary collects its reviews of the agency's response to the Board recommendations, NASA Office of Inspector General. GAO is external legislative-branch oversight and OIG is independent oversight within NASA. Both assess later governance and implementation; neither re-investigates the foam strike or identifies the independent effect of a technical-authority structure.
↩ ↩Toyota Motor Corporation, “Toyota Production System,” sections on jidoka and andon, including abnormality detection, worker call controls, and line stopping, Toyota. This authoritative corporate source establishes Toyota's stated system and terminology. It is not independent observation of implementation, worker freedom to stop production, comparative performance, or transferability to NASA.
↩ ↩ ↩Herbert A. Simon, “Designing Organizations for an Information-Rich World,” manuscript dated October 4, 1969, especially pp. 6–8 on information abundance and attention scarcity, Carnegie Mellon University Libraries. This is Simon's primary conceptual argument. It does not analyze STS-107, validate a specific escalation design, or estimate effects.
↩ ↩ ↩Karl E. Weick, Sensemaking in Organizations (1995), publisher description and chapter structure, SAGE. Karl E. Weick and Kathleen M. Sutcliffe, Managing the Unexpected: Sustained Performance in a Complex World, 3rd ed. (2015), publisher description, Wiley. These are primary theoretical works for the named lenses, not direct evidence about Columbia participants or proof that importing their principles produces reliability.
↩ ↩ ↩ ↩NIST, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024), official publication record and report access, NIST. Sebastian Farquhar et al., “Detecting Hallucinations in Large Language Models Using Semantic Entropy,” Nature 630 (2024), distinguishes detected arbitrary confabulation from consistent errors, Nature. Fabrizio Dell'Acqua et al., “Navigating the Jagged Technological Frontier,” Organization Science 37 (2026), reports a task-bounded field experiment with consultants, INFORMS. The sources provide official risk guidance and bounded empirical findings; they do not test the proposed event system, establish legitimate authority, or support a Columbia counterfactual.
↩ ↩Uma Rani, Annarosa Pesole, and Ignacio González Vázquez, Algorithmic Management Practices in Regular Workplaces (2024), logistics and healthcare case studies across four countries, International Labour Organization. Angelica Salvi del Pero, Peter Wyckoff, and Ann Vourc'h, Using Artificial Intelligence in the Workplace (2022), reviews privacy, fairness, agency, dignity, transparency, safety, and accountability risks, OECD. The U.S. Department of Energy summarizes Lawrence Berkeley National Laboratory estimates of aggregate U.S. data-center electricity use through 2028, U.S. Department of Energy. The workplace evidence is sector- and country-bounded, and the energy source covers aggregate data centers. None allocates privacy, labor, energy, water, or ecological effects to a particular sensing design.
↩ ↩ ↩
Research record
Evidence basis
Claim Cited. Material claims carry source locators; comparative interpretation may still evolve.
Open questions and affected lives
Benefit-to-life status: Seed
- Whose signals are captured, believed, and elevated to executive attention?
- What privacy and freedom from surveillance must sensing preserve for workers, customers, and communities?
- Who defines materiality, especially for harms outside current organizational goals?
- How can people affected by an AI interpretation inspect it, contest it, and preserve dissenting evidence?
These questions remain open; absence from the record does not imply absence of benefit or harm.
Structured atlas record
Lineage nodes
- Messengers, scouts, logs, and councilsbroad editorial label for human reporting chains rather than one documented institutional lineage
- Military staffs and naval reportinggroups several specialized reporting and planning arrangements documented separately in linked institution records
- Railroads, telegraphy, and standardized timemarks a communications-and-dispatch comparison without claiming descent from military staff systems
- DuPont and GM management informationmarks financial and operating-report practices documented separately in the DuPont and GM records
- World War II operations researchmarks wartime analyst-operator collaboration documented in the mobilization record
- Toyota andon and genchi genbutsusupplies a comparative response design in which abnormalities are made visible near their source
- Attention, sensemaking, and high-reliability inquiryoffers distinct lenses on scarce attention, constructed situations, and deference to relevant expertise
- Event-driven systems and AImarks a recent design horizon whose benefits, errors, surveillance risks, and resource effects remain task- and context-dependent
Typed relationships
CMessengers, scouts, logs, and councils → Military staffs and naval reporting
Editorial Periodization: places broad human reporting chains before specialized military and naval staff arrangements
The linked institution records support examples at both endpoints; no reviewed source establishes one transmission from messengers, scouts, logs, and councils to modern staffs.CMilitary staffs and naval reporting → Railroads, telegraphy, and standardized time
Editorial Periodization: places specialized staff reporting before railroad-era telegraphy, dispatch, and standardized time
The linked records support the endpoints, not a direct military-to-railroad lineage or one uniform communications revolution.CRailroads, telegraphy, and standardized time → DuPont and GM management information
Editorial Periodization: places railroad coordination before DuPont and GM financial and operating-report practices
The source IDs document separate cases; they do not establish a direct railroad-to-DuPont-to-GM transmission or warrant the metaphor of one corporate nervous system.CDuPont and GM management information → World War II operations research
Editorial Periodization: places corporate management reporting before wartime operations-research collaboration
The linked records support distinct practices, not a causal passage from DuPont or GM reporting into wartime operations research.CWorld War II operations research → Toyota andon and genchi genbutsu
Editorial Counterpoint: contrasts analyst support to command with Toyota practices that expose abnormalities near production
The endpoints are documented separately; no reviewed source establishes that Toyota andon descended from wartime operations research.CToyota andon and genchi genbutsu → Attention, sensemaking, and high-reliability inquiry
Editorial Counterpoint: places a shop-floor response practice beside theories of attention, sensemaking, and high reliability
The linked works and Toyota record support distinct endpoints, not direct influence or one modern synthesis.CAttention, sensemaking, and high-reliability inquiry → Event-driven systems and AI
Editorial Extension: asks how event systems and AI alter attention, interpretation, escalation, and apparent authority
The local works support theoretical endpoints only; recent AI evidence is task-bounded, and no local AI source record supports a general transformation claim.Provenance and sources
Online anchors
- https://ntrs.nasa.gov/citations/20030093634
- https://ntrs.nasa.gov/citations/20030107225
- https://www.nasa.gov/centers-and-facilities/nesc/protecting-the-future-of-spaceflight-by-preserving-the-columbia-legacy/
- https://www.nasa.gov/remembering-columbia-sts-107/
- https://www.gao.gov/products/gao-18-28
- https://oig.nasa.gov/office-of-inspector-general-oig/ig-05-015/
- https://www.wiley-vch.de/en?isbn=9781405131087&option=com_eshop&title=Organization+at+the+Limit&view=product
- https://iiif.library.cmu.edu/file/Simon_box00054_fld04052_bdl0003_doc0001/Simon_box00054_fld04052_bdl0003_doc0001.pdf
- https://uk.sagepub.com/en-gb/eur/sensemaking-in-organizations/book4988
- https://www.wiley-vch.de/en/areas-interest/finance-economics-law/business-management-13ba/general-introductory-business-management-13ba0/managing-the-unexpected-978-1-118-86241-4
- https://global.toyota/en/company/vision-and-philosophy/production-system/
- https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence
- https://www.nature.com/articles/s41586-024-07421-0
- https://pubsonline.informs.org/doi/10.1287/orsc.2025.21838
- https://www.ilo.org/publications/algorithmic-management-practices-regular-workplaces-case-studies-logistics
- https://www.oecd.org/en/publications/using-artificial-intelligence-in-the-workplace_840a2d9f-en.html
- https://www.energy.gov/articles/doe-releases-new-report-evaluating-increase-electricity-demand-data-centers