All essays
Go-to-Market Engineering / Go-to-Market Engineering

Failure Modes of Demand Systems

A discipline is defined by its theory of failure. Go-to-market has anecdotes, and that is the difference.

Alex Albano | | 16 min read

A discipline is defined by its theory of failure. Go-to-market has anecdotes, and that is the difference.

When an aircraft crashes, a specific machine swings into motion. Investigators recover the wreckage, read the recorders, reconstruct the sequence of events to the second, and produce a report that names the chain of causes precisely and feeds the findings back into design, training, and regulation so that the particular way this aircraft failed becomes a way no aircraft is allowed to fail again. The process is slow, expensive, and unsentimental, and it is the reason flying became as safe as it is. The safety came from a discipline that studied every failure as though it were a teacher, extracted the lesson, and wrote the lesson into the foundations of the field, rather than from aircraft that never failed.

Now consider what happens when a go-to-market effort fails, when a quarter collapses or a launch lands flat or a once-reliable engine of growth stops working. There is rarely an investigation in any real sense. There is a meeting, and the meeting produces a narrative, usually one that locates the cause in a person or a vague external condition, the market softened, the team underperformed, the timing was wrong. Someone may lose their job. A few resolutions are made about doing better next time. And then the whole thing is filed away and largely forgotten, its lessons unrecorded, its causes undiagnosed, so that the same failure is free to happen again at the next company, or the same company a year later, with no accumulated understanding to prevent it. The field survives its failures, narrates them, and moves on, without ever quite studying them, and the difference between studying a failure and merely surviving it is most of the difference between a discipline and a practice.

A discipline is built out of its failures

There is a deep point here that the engineer Henry Petroski spent a career making, which is that engineering advances primarily through the study of failure. His argument, captured in the title of his best-known book, is that to engineer is human, that error is intrinsic to the act of building, and that the way a field gets better is by understanding its failures with great care, because a failure reveals exactly where the prevailing understanding was wrong in a way that success never does. A bridge that stands tells you it was strong enough, which you mostly already believed. A bridge that falls tells you precisely where your model of bridges was mistaken, which is new and valuable knowledge, paid for at a high price and worth recovering. The great advances in structural engineering came after failures, from the systematic study of why specific structures came down, and the knowledge so gained was written into codes that made every subsequent structure safer.

Aviation has its own founding example, and it is worth telling because it shows the process at its starkest. When the world’s first commercial jetliner, the de Havilland Comet, began breaking apart in mid-air in the early 1950s, the cause was a mystery, and the investigation that followed was extraordinary, including the reconstruction of a wrecked aircraft and the testing of an entire fuselage submerged in a water tank, cycled to simulate the pressurization of flight after flight. What it found was metal fatigue concentrated at the corners of the square windows and other cutouts in the skin, where stress accumulated invisibly until the structure tore. The finding rewrote aircraft design. The rounded windows on every airliner since are a direct inheritance from those crashes, and the discipline of fatigue testing the investigation established has prevented an unknowable number of later failures. The Comet crashes were a catastrophe, and they were also one of the most productive failures in the history of engineering, because the field treated them as something to be understood completely rather than survived and forgotten.

This is why a discipline can be recognized by its relationship to failure. A mature discipline treats failure as its richest source of knowledge, studies it without flinching, builds a shared body of understanding about how its artifacts break, and uses that understanding to design against the known modes of failure. The field accumulates a catalogue of the ways things go wrong, and the catalogue becomes one of the most valuable things it owns, because it lets each practitioner benefit from every failure the field has ever suffered rather than relearning each one personally at full cost. The catalogue of failures is, in a real sense, the discipline, the compressed record of everything the field has learned the hard way.

Go-to-market has no such catalogue. It has war stories, which are not the same, because a war story is shaped for telling rather than for learning, polished into a narrative with a hero and a lesson that flatters the teller, stripped of the unglamorous specifics that a real failure analysis lives on. It has the occasional post-mortem, but the post-mortems are private, inconsistent, and usually aimed at assigning responsibility rather than at understanding mechanism, and they are almost never collected, compared, or turned into shared knowledge. The field has suffered an enormous number of failures, easily enough to have built a rich science of how demand systems break, and it has built almost nothing, because it never treated the failures as data.

Toward a taxonomy

So let me begin the catalogue, in the knowledge that a first attempt will be crude and incomplete, because a crude catalogue is the start of a real one and the absence of any catalogue is the thing to fix. A taxonomy of failure earns its keep without being complete, as long as it names the recurring modes clearly enough that practitioners can recognize them, anticipate them, and design against them, and even a handful of well-named failure modes would be more than the field has now.

The first mode is overload. A demand system has a capacity, a limit on how much it can handle while still performing, and when the load pushed onto it exceeds that capacity the system degrades, often sharply, as the work backs up faster than it can be cleared. The sales team flooded with more leads than it can work, the onboarding flow swamped by more users than it can guide, the support function buried past its ability to respond, all are overload failures, and they share a signature, a system that was performing well falling apart through sheer congestion, with nothing inside it broken, simply because it was asked to carry more than it was built for. Overload failures are the most predictable of all, because capacity is in principle measurable and load is in principle observable, and a field that thought about capacity would see them coming. The field mostly does not, and is mostly surprised.

The second mode is brittleness. A brittle system performs well within a narrow band of conditions and fails badly the moment conditions move outside that band, because it was tuned to one regime and has no tolerance for variation. A go-to-market motion built around a particular channel at a particular cost, a message calibrated to a particular moment, a model that assumed a particular kind of customer, all work beautifully until the channel changes or the moment passes or the customer turns out to be different, at which point they shatter instead of bending. Brittleness is the failure of systems that were optimized hard for conditions that then failed to hold still, and it is common precisely because optimization, pursued without regard for tolerance, produces brittleness as a byproduct, tuning the system so tightly to today that it cannot survive tomorrow.

The third mode is the untested tolerance, which is brittleness that has not yet been discovered. Every system has a range of conditions over which it works and limits beyond which it fails, and a system whose limits have never been characterized is a system whose failure point is unknown until it is reached. A great deal of go-to-market runs this way, on systems that have only ever been observed in benign conditions and have never been tested toward their edges, so that nobody knows how much price sensitivity the model can absorb, how much the market can shift before the message stops working, how far any of it can be pushed before it breaks. The failure, when it comes, feels like a sudden discovery, and it is, because the tolerance was never tested and the edge was never mapped, so the system ran blindly toward a limit no one had measured.

The fourth mode is the single point of failure, the dependence of an entire system on one component whose loss brings everything down. A company that draws nearly all its demand from one channel, that depends on one platform whose rules it does not control, that relies on one person who holds the working knowledge of how the system runs, has built a system with a single point of failure, and such a system carries a hidden fragility that stays invisible until the channel saturates, the platform changes its rules, or the person leaves. Single-point-of-failure dependence is seductive because concentration is efficient, because pouring everything into the one thing that works is the locally optimal move, and it builds a system that is excellent until the day the one thing fails and then has nothing to fall back on. The platform version of this has caught the most companies. A business builds its whole demand engine on a single platform’s algorithm or ad system, prospers while the platform’s terms are favorable, and treats the arrangement as permanent, until the platform changes a rule, a ranking, or a price, for its own reasons, and the demand the business depended on vanishes overnight through no failure of the business itself. The dependence was the failure, formed long before the day it showed, on the day the company decided that one channel was working well enough that it never needed another.

The fifth mode is feedback collapse, the failure of a system’s own steering. A demand system that is managed through feedback can be driven into instability if it is corrected too hard on information that arrives too late, so that it oscillates between extremes or spirals away from where it should be, and the failure here lives in the loop rather than in any component, in the way the system senses and responds to itself. A team that lurches between strategies, over-correcting in one direction and then the other, never settling, is suffering a feedback collapse. Picture a team that yanks its budget out of a channel the moment last month’s cost per customer ticks up, only for the cut to take effect weeks later, just as the previous month’s spending finally pays off and the numbers improve, so the team reads the improvement as vindication, pours the budget back, and is punished again a month later when that decision lands, chasing a signal that always reports the consequences of the decision before last. The cruelty of it is that the harder they try to control the system the worse the instability becomes, because the instability is a property of how they are steering rather than of what they are steering.

The sixth mode is resource exhaustion, the depletion of a finite reserve that the system was quietly spending without accounting for it. The clearest case is the goodwill of a market, the reservoir of attention and trust a company can draw on, which refills slowly and can be drained, so that a system contacting its market too aggressively converts a renewable resource into a spent one and finds, too late, that the audience that used to respond has stopped. Resource-exhaustion failures are insidious because they look like success until the moment they do not, the depletion hidden beneath rising activity, the reserve running down while every visible number points up, until the reserve is gone and the system that was working stops working with no proximate cause that any dashboard shows.

Why the field cannot see its own failures

A taxonomy like this is only a beginning, and the modes overlap and interact, but even this much makes something visible, which is how systematically the field is set up to not learn from what goes wrong. The failure to study failure is itself a structural condition with identifiable causes.

The first cause is that failure is embarrassing and careers are at stake, so the incentives around a go-to-market failure push toward narrative and blame rather than toward forensic understanding, because a clear analysis of mechanism tends to implicate decisions and the people who made them, and self-protection is a stronger force in most rooms than collective learning. Aviation solved a version of this deliberately, with investigation processes insulated from blame so that the goal of understanding could override the instinct of self-protection, and go-to-market has built no such insulation, so its failures are processed by the part of the organization most motivated to obscure them. You can see the incentive operating in the language a failing quarter produces, the passive constructions and the externalized causes, the market that softened and the headwinds that arose, all of which describe a world in which nothing anyone decided had anything to do with the outcome. That language is self-protection doing exactly what self-protection does, rather than stupidity, and it is fatal to learning, because a cause you have placed outside the system is a cause you can never design against.

The second cause is the absence of a shared object, which has run through this whole inquiry. You cannot analyze the failure of a thing you have never named, and a field that has no agreed account of the system it builds has no stable object whose failures it could catalogue, so each failure is described in whatever ad hoc terms the moment supplies, and the descriptions do not accumulate because they share no common frame. A taxonomy of failure requires a taxonomy of the thing that fails, and the field has neither.

This is why two people describing the same failure so often seem to be describing different events. One calls it a positioning problem, another a channel problem, another an execution problem, and they may not be disagreeing about what happened at all, with each one projecting a single undescribed event onto whatever frame they carry, and the frames fail to reconcile because there is no shared object underneath them to reconcile against. A field with a named artifact and a named set of failure modes could at least argue about which mode was operating, which is a productive argument that converges on an answer. The field as it stands has arguments that never converge, because the participants are not even pointing at the same thing.

The third cause is survivorship, the overwhelming bias of the field’s attention toward its successes. The entire genre of go-to-market knowledge is built around how the winners won, the case studies of the companies that grew, the playbooks reverse-engineered from outcomes that happened to work, and this is exactly backwards from how a discipline learns, because the survivors are a biased sample that cannot tell you what killed the others. The companies that failed do not write case studies, and their lessons are lost, so the field studies the handful that lived and draws confident conclusions from a sample that has had all the failures removed from it, which is a recipe for learning things that are not true.

The classic illustration comes from wartime, when analysts studying returning bombers proposed adding armor where the returning planes showed the most bullet holes, until the statistician Abraham Wald pointed out the error. The planes they were studying were the ones that had made it home, and the places they were unscathed were precisely the places where a hit was fatal, because the planes hit there did not come back to be studied. The armor belonged where the survivors showed no damage at all. Go-to-market reasons about its returning bombers constantly, studying the companies that made it home and drawing conclusions from where they happen to be strong, blind to the fact that the fatal hits are exactly the ones absent from the sample, because the companies that took them are not in the room.

What an analysis would look like

It is worth being concrete about what studying a failure would actually involve, because the gap between the meeting that assigns blame and the investigation that produces knowledge is wide and specific. A real failure analysis of a demand system would begin by reconstructing the sequence precisely, what changed and when, what the system was doing in the period before it broke, the way an investigator reconstructs the minutes before a crash. It would resist the first plausible narrative, the soft market and the underperforming team, long enough to ask what the mechanism actually was, which of the failure modes was operating, whether the system was overloaded or brittle or quietly running on an exhausted reserve. It would look for the chain rather than the single cause, because real failures are usually a sequence in which several things had to go wrong together, and the chain teaches more than any one link. And it would write the finding down in terms general enough to transfer, so that the lesson outlives the incident and the company and becomes part of a record the next person can consult.

None of this is exotic, and all of it is routine in fields that take failure seriously. What stops go-to-market from doing it is partly the incentives, partly the missing object, and partly that the field has never seen failure analysis as a source of value, has never quite believed that the careful study of a collapse is worth the discomfort it costs. The belief that it is worth the discomfort is one of the things a discipline has and a practice lacks, and acquiring it is less a matter of technique than of deciding that the failures have become too expensive to keep wasting.

The beginning of reliability

The point of a taxonomy of failure is not pessimism, and it is the opposite of dwelling on what goes wrong for its own sake. A catalogue of failure modes is the most practical thing a discipline can own, because once you know the ways a system characteristically breaks, you can do the things that follow from knowing, designing against each mode, watching for its early signs, building in the margins and redundancies that guard against it, and recognizing a failure in progress while there is still time to act. The aircraft is safe because the field knows, in detail, the ways aircraft fail, and has designed against each of them. The knowledge of failure is what makes reliability possible, and a field that refuses to study its failures has forfeited reliability before it begins.

There is a quiet optimism buried in this, which is that failure is the cheapest teacher a field can have once it decides to learn from it, because the failures have already happened and already been paid for, and all that remains is to extract the lessons that were bought at such cost and left lying on the ground. The field has a century of its own failures sitting unexamined, an enormous inheritance of hard-won knowledge that no one has bothered to collect. Beginning to collect it would cost almost nothing next to what the failures themselves cost, and it would compound, each studied failure making the next one less likely, in the way that aviation’s safety compounded over decades of refusing to waste a single crash.

This is where the next question opens. Once you have begun to name the ways a demand system fails, the natural thing to ask is how to make a system that does not fail in those ways, how to build in the margin that survives overload, the tolerance that resists brittleness, the redundancy that removes the single point of failure, the gentle control that avoids feedback collapse. That is the question of reliability, of how a discipline deliberately produces systems that keep working under conditions that would break a naive design, and it turns out that engineering has a great deal to say about how reliability is manufactured, almost none of which go-to-market has ever tried to hear.


References

  • Henry Petroski, To Engineer Is Human: The Role of Failure in Successful Design (St. Martin’s Press, 1985), on failure as the primary engine of engineering progress.
  • On failure analysis and reliability, and on blame-insulated investigation (the model of aviation safety boards), see the literature on reliability engineering and safety-critical systems.
  • On survivorship bias in inference from successful cases, see standard treatments in statistics and the history of its recognition in wartime operational research.

Alex Albano

AI-native growth operator. Based in Southeast Asia.

More essays →

One essay, every other Tuesday.

Growth architecture, brand positioning, and the commercial mechanics behind AI and deep tech. The next one drops the moment your competitors wish they had read it first.

2,400+ operators, founders, and the occasional VC. Unsubscribe in one click.