Fail-Deadly
Updated 2026-08-08
INTRODUCTION
English translation pending.
CORE DEFINITION
The term contrasts with fail-safe, where a fault causes a system to shut down or move to a safe state. A fail-deadly design instead responds to detected failure, sabotage, or loss of command by launching a devastating response, the logic behind the Soviet Perimeter system of the Cold War. The engineering reading is narrower: some failures, such as a pressure vessel rupture, are irreversible and demand prevention rather than tolerance.
SCAFFOLDING EFFECT
Reduce cognitive load
- Mark the deadly class: separate failures that can be recovered from those that end the game - Prevent rather than tolerate: invest in layers that stop the event instead of buffers that absorb it - Make retaliation credible: bind an irreversible response to attack when deterrence requires it
Anchor fast decisions
Some failures destroy the system before any recovery path can act, so redundancy provides no protection. When the outcome is fatal, the only effective strategy is to prevent the initiating event through independent protective layers. In deterrence, the same irreversibility is deliberately installed so that a threat cannot be withdrawn.
MINIMUM ACTION
In progress 0/1Practice this model in one real situation:
account_treeGenealogyexpand_more
menu_bookReferencesexpand_more
Source support: Explicit
- en.wikipedia.orghttps://en.wikipedia.org/wiki/Fail-deadlyverified
PRIVATE NOTES · Only visible to you
SAVED Q&A
ENTRY Q&A · Private saving available
Ask with a clear boundary
thinkingmodels answers from published entry context only.
Your question is sent to thinkingmodels. The answer uses public entry context only.
RELATED MODELS