Human Error Is Design Error
Norman counts 75 to 95 percent of industrial accidents blamed on human error and reads the number as an indictment of design. One note for the machinery: affordances, signifiers, conceptual models, the seven stages of action, and the error taxonomy that hands each failure class its fix.
The Core Insight
Accident reports blame human error for 75 to 95 percent of industrial accidents. Norman's rebuttal is arithmetic: at 1 to 5 percent he is ready to believe people are at fault. A label that absorbs almost every failure describes the system instead, so he renames the category: design error.
The Design of Everyday Things appeared in 1988 as The Psychology of Everyday Things. Norman revised it in 2013 to hold until 2038, on one bet: technology changes fast, and human psychology does not. Between the editions computers grew five thousand times more powerful, and the doors stayed confusing. The field calls them Norman doors. He also sat on the Three Mile Island review committee, which found control rooms that made error inevitable.
Most product teams read user confusion as a training gap and route the fix through onboarding, tooltips, and support macros. Norman argues the confusion is a defect in the artifact. The mechanism is distance: the designer never meets the user, so every belief the user forms comes from the product and its surround. He calls that surface the system image, and it carries the entire burden of communication.
His General Electric refrigerator is the specimen. Two labeled controls imply two thermostats. The machine holds one thermostat and one cooling unit, and the second control splits the cold air. The manual asks owners to allow twenty-four hours for the temperature to stabilize, so every adjustment is a day-long blind experiment. Norman collected reader letters about it for twenty-five years, and the same controls kept shipping. Users blame themselves and stay quiet, the pattern he calls a conspiracy of silence, and bad design outlives its feedback.
The Framework
Every interaction crosses two gulfs. The Gulf of Execution separates intent from the right action. The Gulf of Evaluation separates the device's state from a judgment of whether the goal was met. Signifiers, constraints, mappings, and a conceptual model bridge the first. Feedback and the same model bridge the second. Norman treats either gulf as a product opportunity, and he names the two information flows feedforward and feedback.
Seven stages of action span the gulfs: form the goal, plan, specify the sequence, perform it, perceive the result, interpret it, compare against the goal. Each incident fails at one stage, and the stage points to the repair. Six concepts supply the repairs.
- An affordance is a relationship: the actions possible between this object and this person.
- A signifier is any perceivable mark or sound that communicates where and how to act.
- A mapping ties controls to effects, and spatial likeness makes it natural.
- A constraint removes wrong actions before anyone attempts them.
- Feedback reports what an action did, within a tenth of a second.
- A conceptual model is the user's working story of how the thing operates.
The four constraint types show up whole on a fifteen-piece Lego motorcycle. Physical, cultural, semantic, and logical constraints leave each piece one place, and strangers assemble it unaided. Discoverability and understanding are the two marks of good design, and the six concepts exist to produce them.
Key Ideas
Signifiers Outrank Affordances
An affordance is a relationship between object and person, a term Norman borrowed from the psychologist J. J. Gibson. A chair affords sitting to anyone and lifting only to someone strong enough. Glass affords seeing through and blocks passage, and birds hit windows because that anti-affordance is invisible.
The 2013 revision exists because designers kept saying affordance when they meant sign. Affordances set what is possible. Signifiers mark where and how to act, and they are the half a designer controls. A friend of Norman's stood trapped between two rows of glass swinging doors at a European post office. He pushed the hinge side, because the designer erased every line and pillar for beauty.
Users Act on the Story the Product Tells
A conceptual model works by predicting, and a false model directs confident wrong action. Most people model a thermostat as a valve that meters heat, so they set the maximum to warm the room faster. In most homes the thermostat is an on-off switch. The extreme setting speeds nothing, bypasses the automatic shutoff, overshoots the target, and wastes energy. That is worse than having no model at all.
Mapping is the cheapest correction. A standard stove puts four burners in a rectangle and four controls in a line. That layout permits four mappings, and all four are in commercial use, resolved only by labels. Ergonomics textbooks carried the fix for over fifty years, and the field called the layout bad for roughly a century. Stoves still ship with it, because the purchaser is often not the user.
Put the Knowledge in the World
Nickerson and Adams asked American college students in 1979 to pick the correct penny from a set of drawings. Fewer than half succeeded, and every one of them spends money without error. Precise behavior emerges from imprecise knowledge because the world carries half the load through constraints and conventions.
Working memory holds five to seven items, and Norman's practical design number is three to five. One interruption empties it. So the direction is fixed: make memory unnecessary. Put the state on screen, the options in view, and the reminder inside the flow. An ATM returns the card before it delivers the money, because people forget the card and never the goal. The tradeoff is real: knowledge in the world works at first encounter, and knowledge in the head runs faster once learned.
Slips and Mistakes Take Different Fixes
A slip executes the right goal wrongly. A mistake executes the wrong goal well. Working with James Reason, Norman splits slips into two classes, action-based and memory-lapse, and mistakes into three: rule-based, knowledge-based, and memory-lapse. Mapped onto the stages, mistakes come from the top three, slips from the bottom four, and memory lapses strike at any of the eight transitions. Slips land on experts more than novices, because skill runs on autopilot.
Mode errors are the slip software manufactures, and they arrive whenever actions outnumber controls. An Airbus crew entered minus 3.3 as a descent angle, which means about 800 feet per minute. The autopilot sat in vertical speed mode and flew 3,300 feet per minute down, and the crash was fatal. The fix was notation: vertical speed took four digits, angle took two. The Gimli Glider sits in the taxonomy too: its crew computed fuel weight in pounds instead of kilograms, a knowledge-based mistake.
Feedback failures hide the modes. In 1997 the Royal Majesty's GPS antenna cable came loose and navigation reverted to dead reckoning, announced by two tiny letters, dr. The ship ran from Bermuda toward Boston for days and grounded on Cape Cod, at a cost of several million dollars.
The Investigation Starts Where the Blame Stops
Root cause analysis fails in two ways: most accidents have several causes, and the analysis halts the moment a human error appears. A broken part triggers further questions, and a blamed person triggers none. Norman's correction: when human error appears in the chain, the work begins. The tool is the Five Whys from Toyota, run past the first comfortable answer.
The F-22 record runs the pattern in public. A 2010 crash killed the pilot. The Air Force blamed pilot error in 2012. In 2013 the Inspector General asked why sudden incapacitation was not considered a factor.
Reason's Swiss cheese model replaces the single cause. Every defense layer is a slice with holes, and the accident happens only when holes in all four slices align. Three fixes follow: add slices, shrink or close holes, and alert operators when several holes line up. The NTSB chair credits layered defenses for moving about two million US air passengers safely each day. Social pressure is a hole of its own: the Air Florida first officer voiced concern four times during the 1982 takeoff, and seventy-eight people died.
Never Solve the Problem as Given
Norman's consulting rule bans solving the problem he is asked to solve, because the request names a symptom. Engineers train to solve problems. Designers train to find the right problem first, and a brilliant answer to the wrong problem does more damage than none.
The British Design Council published the double diamond in 2005. The first diamond diverges and converges to find the right problem, the second to find the right solution. Inside each runs the human-centered loop: observe, generate ideas, prototype, test, repeat. Jakob Nielsen's testing number is five users studied one at a time, then five more after the fixes. Requirements gathered by asking people what they need come out wrong, and requirements written in the abstract come out wrong. Watching people inside the activity produces the real ones.
Norman's Law prices the constraint: the day a product development process starts, it is behind schedule and above budget. His remedy keeps design researchers in the field full time, so the answers exist before the deadline arrives.
Practical Applications
Rewrite your most common error message as guidance. Norman's rules for that moment: treat difficulty as a signifier of where to improve, assume the action was partially correct, never force a restart. A dead-end dialog converts a design defect into the user's homework.
Sort last month's tickets into slips and mistakes, using the two-class and three-class split. Slips point at controls and feedback. Mistakes point at the model your interface teaches. The sort moves most of the backlog from training requests to design work.
Audit feedback next. Acknowledge every action within a tenth of a second, and show slow operations the slowest predicted value, so reality beats the promise. Then prioritize the channel: a product that beeps for everything trains its owner to silence it, and the silencing happens mid-emergency.
Guard the irreversible paths with forcing functions. An interlock forces the safe sequence, a lock-in protects unsaved work, and a lockout blocks the dangerous branch. Add sensibility checks to money and quantity fields. At roughly 1,000 won to the dollar, a won balance typed into a dollar field becomes a million-dollar transfer request, and the check refuses it.
Watch five users run the real activity before the next release. Ask nothing during the run, and mark which of the seven stages breaks. Five sessions, fixes, five more.
Who This Is For
Founders who own an interface get the most from it, and so does whoever reads the support queue. The book supplies a shared vocabulary that ends taste arguments: name the failing stage, name the missing principle, change the artifact. The error taxonomy alone reprices every postmortem that ends in retraining.
The vintage is visible. The core argument dates to 1988, the revision to 2013, and the worked examples are doors, faucets, stoves, cockpits, and a refrigerator. Norman kept named companies out so the book survives to 2038, and the price of that durability is distance from your stack. Software metrics culture gets one aside, A/B tests at perhaps 10 percent of visitors per variant, and funnels and retention curves never appear. The evidence is lab psychology and accident reports, so every rate you care about still needs your own measurement.
Skip it if this quarter needs channel benchmarks or growth mechanics. The book teaches diagnosis, and each prescription needs translation onto screens you own.
The Decision
Pull the worst support ticket of the week and walk it through the seven stages. Name the stage where the user fell: goal, plan, specify, perform, perceive, interpret, compare. Then classify the fall. A slip calls for feedback and constraints at the failing step. A mistake calls for a better conceptual model, because the product taught the story the user acted on.
One outcome ends the exercise early. If you cannot name the stage, the failure is invisible from inside your own product, and that is the finding. Write the fix as a design change, ship it, and watch whether the ticket class returns. Blame the user, and it returns on schedule.