Good intentions are not a reason; the place is
2026-08-27 · Fragility, Resilience & Early Warning
There is a finding that keeps turning up in systems work: people usually locate the right place to push, and then push it in the wrong direction. Failing to find the leverage point is not the main failure mode. Finding it and reversing the sign is.
Hanoi, 1902. Plague was closing in, and the French colonial administration decided to kill every rat in the city. The method was blunt: bring in a rat tail, collect a few cents. The first days brought a few hundred. Soon it was seven thousand a day, then fourteen thousand; on the worst day for Hanoi's rodents, more than twenty thousand tails were reported.
Three months in, officials discovered two things. On the city's edge, households were breeding rats, cutting off the tails for the bounty and releasing the tailless animals to breed again — and there was a smuggling route bringing rats into Hanoi from the surrounding province. They wanted fewer rats. What they bought was tails. The system supplied, in full, exactly the thing they had priced.
This is not a story about stupidity. The bounty was a perfectly reasonable policy, and it failed for reasons that have nothing to do with diligence, ethics or intelligence. It failed because of where it pushed: too shallow, while the system had its own moves available at a deeper place. This issue is about place — when you intervene in a system that answers back, which places are available to push, how far apart their effects are, and how to design the push given that you will almost certainly get it wrong.
How this sits with earlier issues: Topic 6 covered the structure of feedback loops; Topic 26 covered the fact that adaptive agents learn your model once you publish it; Topics 38 and 39 covered how to build yourself to take a hit. This issue closes out the phase by converting all of it into one question: when it is your turn to act, where does the hand go?
First, how the eating actually happens.
A quantity in a complex system usually sits at its current value not because nobody is managing it, but because several forces are pulling it in different directions and currently balance. The rat population of a city sits where it sits because food, shelter, predators, disease and human clearance are holding each other off. Add a force from outside and the others do not stand still: each one's strength already depends on the current state, so when the state moves, they move.
Systems researchers call this policy resistance, and the mechanism underneath it is compensating feedback: your push activates a balancing loop that was previously dormant, the loop drags the system back toward where it was, and you keep paying to push. → ref · System Dynamics (Stocks & Flows)
Hanoi is one notch worse than that. The bounty did not merely meet resistance; it created an inflow that had not existed before. Rats went from being a thing to be removed to being a thing that could be produced. That step is specific to complex systems: the objects of your intervention include agents who do arithmetic, and they will go find the price you just posted.
There is a test you can take away immediately. When your intervention lands on an indicator, and human behaviour sits between that indicator and the goal you actually want, the indicator will move first — and may be the only thing that moves. The difference is not between good people and bad people: the rat farmers and the tail collectors in Hanoi were the same people, taking the cheapest path across the terrain you had just redrawn.
A correction on the better-known version of this. The phenomenon is usually called the "cobra effect", after the German economist Horst Siebert's 2001 book of that name, which tells of a British bounty on dead cobras in Delhi and the cobra farms that followed. No archival evidence for that story has ever been found, and it is very likely a later invention. The Hanoi tail bounty, by contrast, is documented in the colonial files — the historian Michael Vann found it in a dossier marked "Destruction of Hazardous Animals". Keep the name if you like; swap the example for the one with a paper trail.
Before launching any intervention, write down two sentences. First: "If this works, which specific number moves in three months?" Second: "Where will the system get it back from?" If you cannot answer the second, it is not because there is no answer — it is because you have not looked. Do not push until you have. Otherwise you will see either the indicator move while the goal does not, or the goal move and then return, and you will already have paid.
If pushing the wrong way is the norm, you first need a map of where the places are.
The person who drew that map was Donella Meadows, one of the principal authors of The Limits to Growth. In 1997 she was sitting in a meeting about the North American Free Trade Agreement, listening to a room argue about tariff rates, when it struck her that everyone was arguing at one single level — and that level determines almost nothing. Afterwards she wrote a list: leverage points, twelve places in a system where you can push, ordered from least useful to most.
The part worth chewing on is not the ranking itself but the mismatch it exposes: effectiveness and resistance run in the same direction. The easiest place to move — a number — barely changes behaviour, because behaviour is produced by structure and the number is just a blank being filled in. The place that does change behaviour — goals, paradigms — is precisely what everyone defends hardest. So a rational organisation drifts, all by itself, into spending everything in the bottom two rows. That is not laziness; it is the path of least resistance.
Here is an example that makes the difference between levels visible. To raise organ donation rates, the level-12 move is more advertising and more subsidy. The level-5 move is the tick-box default on the form: is it "not a donor unless you tick", or "a donor unless you tick"? Johnson and Goldstein compared European countries in Science in 2003. Countries with the first default had registered consent in the single digits to the low twenties per cent; countries with the second were close to 100%. Same people, same values, same piece of paper — one default value apart, and tens of percentage points of difference.
Notice what is easy to miss here: the advertising budget can be increased without limit, and no amount of it produces that gap. The force was not insufficient; the place was wrong. Which is also why "try harder" is so often a completely inert piece of advice in a complex system.
Take every intervention you are running or about to run and label it with a level number. If nine tenths of a year's actions sit at levels 12 and 11 — tuning numbers, adding buffers — that is not an execution problem, it is a year spent pushing where the resistance is lowest. Then do one thing: pick an action at level 6 (information flows) — take a number that someone currently cannot see and make it a number they see every day. That level is usually the best value on the whole list, because it is easier to move than rules and far more effective than parameters.
Finding the place is not sufficient. There is a harder constraint, and it has nothing to do with how clever you are — only with counting.
In 1956 the British psychiatrist and cyberneticist W. Ross Ashby stated a law in An Introduction to Cybernetics — the law of requisite variety — in wording short enough to pass for a proverb: only variety can destroy variety. → ref · Cybernetics and Its Lineage
"Variety" here is countable: the number of distinct states a thing can take. The weather's variety is how many different ways it can be; your variety is how many genuinely different responses you can produce. The law says: how far you can compress the outcomes depends on the number of distinct responses you have. When your hands are fewer than the situations, the remainder leaks through, and effort does not enter the calculation.
Count it and it is obvious. Suppose there are 8 situations you must handle and you can produce 3 distinct responses. Those 3 responses partition the 8 situations into at most 3 classes; different situations inside one class receive the same action, so their outcomes still differ. The number of distinct outcomes is therefore at least 8 ÷ 3, rounded up — 3. You can squeeze 8 outcomes down to 3. You cannot squeeze them into 1.
The law earns its keep by turning a vague kind of frustration into a number you can compute. When someone repeatedly "cannot get a grip" on something, the usual diagnosis is willpower, competence, focus. Ashby's diagnosis is not enough kinds of response — and the three exits are exhaustive: add distinct responses; reduce the number of situations you face (block some at the door, or standardise them); or openly declare which outcomes you do not guarantee. The third sounds like surrender and is in fact the only honest way to downgrade — at minimum it tells other people where else to go for cover.
Take something you have chronically "failed to control" and do the count: list the distinct situations that actually occurred last month, and count them; then list the distinct responses you actually produced, and count those. If the second number is clearly smaller, stop adding effort — effort only performs the same response harder, and the law constrains kinds, not intensity. Pick one of the three exits: add response types, cut the scope you accept responsibility for, or state plainly which part you do not guarantee.
Put the first three sections side by side and you land somewhere uncomfortable.
The system eats your intervention; you are probably pushing at the least useful level; and your hands are fewer than the situations. Add what Topic 11 established — that for some systems there is, in principle, no shortcut to computing the behaviour — and the standard procedure ("work out which option is right, then execute") turns out to be unrunnable. It presupposes a judgement you have just been told you cannot make.
So change the criterion. Since "which is more right?" cannot be answered in advance, ask something that can be: which option can be undone if it turns out wrong? That question requires no prediction of the system's response — only an inventory of your own exits, and exits can be counted.
In engineering and ecosystem management this goes by one name: safe-to-fail. It does not aim to get this step right; it requires that getting it wrong is bounded in loss and productive in information. It is the opposite of fail-safe design, which assumes you already know what to guard against.
Making the criterion operational takes three extra columns next to each option: how long to undo, how much it costs to undo, whose sign-off undoing requires. Options where all three can be filled in are reversible doors. Any option with a blank column should be treated as a one-way door — which does not mean never walking through it, but means walking slower, smaller, and having said out loud in advance what you will live on once you are through.
Make the first question at any design review not "which is better?" but "which one can be undone if it is wrong — how long, how much, whose sign-off?" When expected returns are close, take the reversible one. When the irreversible one has a clearly higher return, shrink it and run it once at small scale until it becomes reversible, then talk. This rule will always look costly on an expected-value ledger: what it buys is not return, it is the right to keep sitting at the table.
All four sections above are useful, and being useful is exactly why they get overextended. Boundaries, one at a time.
The leverage-point list is not a theory; it is a list. Meadows was explicit that the ordering came from experience and intuition rather than being derived from any model, and she invited readers to argue with it. It provides no operational rule telling you which level an action belongs to — the same act, re-described, moves from level 12 to level 5. This produces its characteristic misuse: after the fact, successful interventions get called high-leverage and failed ones low-leverage, so the list is always right and never predictive. There is only one defence: write the level down before you act, and write down what should happen in three months if it really is that level.
"Variety" is usually uncountable in the field. The 8-divided-by-3 in section 3 was clean because I enumerated both sets in advance. In a real situation, "how many kinds of case do I face" depends entirely on how you carve them: carve coarsely and it is 3, carve finely and it is 300 — and the law holds for both carvings while giving different conclusions. So treat it as a structural reminder (the number of kinds of response is a constraint independent of effort), not as a calculator. Any claim that computes a precise conclusion from it owes you its carving rule first.
Reversibility-first is not universally optimal, and it is not free. Choosing a second-best option to keep an exit costs real expected value, and over a long run it loses to a rival who always takes the best option — provided that rival survives. Worse, an entire class of interventions is indivisible by nature: a dam, a constitution, a mass vaccination campaign, a surgical procedure. You cannot build a quarter of a dam as a trial. For that class, this issue does not say "don't" — it says shift the effort into making every step before the irreversible one reversible, and into agreeing in advance who declares failure, and when.
And the one most often skipped: doing nothing is also an intervention. "Complex systems are hard to intervene in" is regularly read as "so don't touch it", but holding still changes the system too — it lets the currently dominant loop keep running. Every criterion above has to be applied symmetrically to the do-nothing option: it has a level number, it has an exit cost, and if it is wrong it may not be undoable either. Treating caution as the default answer is the easiest mistake in this issue to make and the hardest to notice, because it always looks like the more sober choice.
One conjecture: the things that can be changed easily are easy precisely because changing them does not threaten the system's persistence, so no protective mechanism ever evolved around them. Conversely, goals and paradigms are defended fiercely because changing them makes the system a different system — the strength of the guard is itself evidence that this is the vital spot. If the conjecture holds, resistance becomes a detector for leverage: the more violently someone reacts to your proposal, the closer you are to a high leverage point. That corollary is suspiciously convenient — it could equally be a way of repackaging "annoying people" as "having insight". Telling those two apart is a real problem.
Technically it is the most honest way to downgrade; organisationally it is often the most expensive sentence available. A possible reason: the other two exits (add capability, cut scope) both look like solving the problem, whereas this one looks like shirking, even though it is the only one that conceals no constraint. There may be something more general hiding here — when a constraint is mathematical rather than moral, people still receive it morally.
Yes. That is this rule's most realistic failure mode: any option can be asked to become smaller and more reversible, so intervention is deferred indefinitely while inaction keeps changing the system. One possible fix is to attach an expiry to reversibility — not "is this reversible?" but "before what date is it reversible, and after which it is not?" That turns "when must this be decided" into a quantity rather than a matter of temperament.
Topic 26 covered this: agents in complex adaptive systems learn, and publishing a model changes the thing modelled. Once the leverage-point list is public, defenders will use the same list to position their defences, and high leverage points get guarded harder. Interestingly, this need not invalidate the list — it might make the "resistance" signal more reliable. But the opposite is also available: both sides know level 5 matters, so the fight over default values becomes as fierce and as deadlocked as the fight over tax rates was. Which of these two futures happens is not something this issue's mechanisms can answer.