The trigger is often the most visible part of a failure—and the least complete explanation.
A drought arrives. A bank fails. A war begins. A transformer trips. A virus spreads. These events matter. But civilisation failure usually depends on the field the event enters: what was exposed, which vulnerabilities already existed, what amplified the loss, where bottlenecks formed, how dependencies transmitted stress, and whether repair capacity survived.
One-sentence answer: civilisation failure propagates when an initiating disturbance reaches exposed and vulnerable functions, is amplified by coupling, overload, feedback or concentration, crosses one or more load-bearing thresholds, and then spreads faster than containment and repair can restore the affected field.
The Reason for Existence
The old version of this page tried to identify a small number of “collapse levers” and a repeatable failure physics behind rise, stall, regression and collapse.
Its strongest insight survives: the visible trigger is not the whole cause, and collapse becomes more likely when problems compound faster than the civilisation can learn, coordinate and repair.
What does not survive is the idea that civilisation failure can be reduced to one universal Education → Governance → Production → Constraint sequence, or that collapse is mechanically the same across cultures, technologies and eras.
There is no single failure physics for civilisation. There are reusable propagation mechanisms.
This page therefore owns the propagation question: how does a bounded failure become a wider one?
The propagation chain
TRIGGER → EXPOSURE → VULNERABILITY → INITIAL LOSS → AMPLIFIER → BOTTLENECK / DEPENDENCY → THRESHOLD BREACH → PROPAGATION → CASCADE → RECOVERY CONSTRAINT → CONTAINMENT OR WIDER FAILURE
Each term is a different object. Collapse analysis becomes weaker whenever two or more are merged into one dramatic explanation.
Trigger is not cause
A trigger is the event that changes the load or state of the system.
- drought;
- flood;
- war;
- pandemic;
- cyberattack;
- financial panic;
- leadership transition;
- equipment fault;
- price shock;
- rapid migration;
- technological disruption.
The trigger matters, but it does not tell us why the loss became large.
The same trigger can produce inconvenience in one civilisation, disaster in another, and transformation in a third.
Exposure: what was in the path?
Exposure asks which people, assets, institutions, ecosystems and capabilities were reachable by the trigger.
A flood cannot directly damage an inland data centre it never reaches. But it can still affect that data centre indirectly if roads, power or staff access fail.
Exposure therefore has at least three forms:
- direct exposure — physically in the event;
- dependency exposure — dependent on something in the event;
- receiver exposure — unable to receive the service after upstream disruption.
Vulnerability: why could exposure become serious loss?
Vulnerability is the condition that allows exposure to become damage.
- poor maintenance;
- thin reserves;
- single-source dependence;
- unsafe design;
- weak legitimacy;
- low trust;
- limited mobility;
- inadequate staffing;
- ecological depletion;
- concentrated knowledge;
- fragile finance;
- unclear authority;
- missing receiver access.
A trigger can be unavoidable while vulnerability is partly created by prior choices.
Amplifiers: what makes the first loss larger?
An amplifier increases the consequence of an initial disturbance.
| Amplifier | How it enlarges loss |
|---|---|
| High utilisation | Little spare capacity remains when load transfers. |
| Concentration | One supplier, route, platform or institution carries too much. |
| Feedback | Failure changes behaviour in ways that worsen the failure. |
| Delay | Evidence or response arrives after the repair window narrows. |
| Information distortion | Bad data or suppressed reports create wrong actions. |
| Leverage | Small value changes create large financial consequences. |
| Network coupling | One node influences many others quickly. |
| Adversarial action | An intelligent actor exploits the weakened system. |
| Receiver inequality | Low-buffer groups cross thresholds earlier and amplify social stress. |
Bottlenecks: where does the system become singular?
A bottleneck is a constrained point whose usable capacity limits the wider system.
The bottleneck may be physical, informational, institutional or human.
- one bridge;
- one port;
- one transformer;
- one cloud identity service;
- one legal approval;
- one rare spare part;
- one specialist engineer;
- one language or credential required to access the system;
- one trusted information channel.
The important question is not whether the system has many components. It is whether too much function must pass through too few routes.
Dependency is not automatically fragility
Civilisation works because systems depend on one another.
Dependency creates capability. It becomes dangerous when it is hidden, singular, poorly maintained, tightly coupled or difficult to substitute.
Interdependence is not the problem. Unseen interdependence with no repair route is.
Common-mode failure: many backups, one hidden dependency
Two or ten backup systems do not provide independence if all of them depend on the same underlying point.
- different apps share one identity provider;
- different hospitals use one logistics supplier;
- multiple generators depend on the same fuel route;
- different agencies use one communications network;
- separate teams depend on the same expert;
- several payment channels depend on one electricity or data layer.
Common-mode mapping is one of the highest-value ways to stop apparently local failures becoming simultaneous ones.
Threshold breach: when propagation becomes a floor problem
The companion article Failures of Civilisation | When the Floor Gives Way defines the boundary.
A threshold breach occurs when a required capability falls below the level needed for its function.
Propagation becomes civilisational when the breached function is load-bearing enough that dependent systems begin losing their operating conditions.
LOCAL LOSS ≠ CIVILISATIONAL FAILURE LOCAL LOSS + LOAD-BEARING THRESHOLD BREACH + PROPAGATION + WEAK CONTAINMENT / REPAIR = CIVILISATIONAL FAILURE RISK
The main propagation geometries
| Geometry | How failure travels |
|---|---|
| Serial chain | A loses output, B loses input, C then loses B. |
| Branching cascade | One failed node disables several dependent functions. |
| Convergent overload | Several damaged systems transfer demand onto one survivor. |
| Common-mode | Apparently independent systems share one failure point. |
| Geographic | Co-located systems are damaged by the same event. |
| Logical / institutional | One rule, price, model or authority failure affects many systems. |
| Information cascade | False or missing signals cause coordinated wrong actions. |
| Behavioural cascade | Fear, hoarding, flight, runs or withdrawal worsen the original problem. |
| Temporal cascade | Present performance is maintained by consuming future capability. |
| Capability cascade | Loss of people or knowledge reduces the ability to operate and repair other systems. |
| Adversarial cascade | An intelligent opponent exploits the emergency or recovery route. |
| Receiver cascade | Failure at the last mile creates secondary health, economic or trust effects. |
A cascade is not yet collapse
A large cascade can still be bounded.
The important question is whether the civilisation retains enough capacity to isolate, reroute, prioritise, repair and learn.
A blackout affecting millions can be enormous while still leaving the wider society able to restore power, investigate causes, improve rules and continue.
Cascade describes propagation. Collapse describes loss of continuity or the route back.
Recovery constraints: the second failure field
After the first loss, a second field becomes decisive: can civilisation still repair?
- Can the real condition be observed?
- Can competent people interpret it?
- Does legitimate authority exist?
- Are money, parts, energy and labour available?
- Can repair crews reach the site?
- Are communications working?
- Can institutions coordinate?
- Will receivers cooperate?
- Are fallback systems independent?
- Can the repair be retested?
- Can successors continue if current experts are lost?
This is why a modest initiating event can become catastrophic in a system with weak repair capacity, while a huge event can remain recoverable in a system with strong repair machinery.
Amplification speed versus repair speed
The old article’s “problem speed versus adaptation speed” idea remains useful if treated as an orientation rather than a universal law.
IF PROPAGATION + DAMAGE + DRIFT GROW FASTER THAN OBSERVATION + CONTAINMENT + REPAIR + ADAPTATION, THE RECOVERY CORRIDOR NARROWS.
The objective is not merely to make institutions faster. Speed without correct information or authority can amplify failure too. Civilisation needs enough accurate response speed relative to the process it is trying to control.
The propagation map must include the receiver
Infrastructure maps often stop at the technical system.
CivilisationOS follows the output to the receiver.
SOURCE → INFRASTRUCTURE → INSTITUTION → SERVICE → LAST MILE → RECEIVER → HUMAN / SYSTEM OUTCOME → WORLD RETURN
A technically functioning relief system can still fail if medicine never reaches the patient. A payment platform can function while a person without usable identity or connectivity cannot access it. A school can operate while the learner cannot transfer what was taught.
Propagation can travel into the receiver even when the upstream system still declares itself operational.
The propagation map must include time
Some cascades are immediate. Others take years.
- power loss can stop pumping within minutes;
- maintenance debt can become asset failure over years;
- teacher-pipeline weakness can become professional capability loss over a generation;
- ecological depletion can reduce future production long after current output rises;
- trust damage can accumulate slowly and become visible only during crisis.
A propagation map without time can miss the largest consequence because it lies outside the reporting horizon.
The propagation map must include scale
A failure can move upward, downward and sideways across scales.
- a household failure can aggregate into neighbourhood stress;
- a city infrastructure failure can become national economic loss;
- a national policy can create local receiver failures;
- a global supply interruption can appear first as one hospital’s missing part.
See How Civilisation Changes With Scale.
Where Article 1, 2, 3, 4 and 5 now connect
PERFECT REFERENCE / ACTUAL / DELTA
↓
DRIFT
↓
WARNING SIGNATURE
↓
DIAGNOSIS
↓
PREVENTION
↓
THRESHOLD BREACH
↓
PROPAGATION
↓
CONTAINMENT OR CASCADE
↓
WORLD RETURN
This page owns the propagation segment. It should not duplicate the signature, diagnosis or prevention jobs.
Case study: electricity → water → health
Suppose a major electricity failure affects a city.
The trigger is the initiating grid event.
Propagation depends on:
- whether water pumping has independent power;
- how much stored water remains;
- whether hospitals have working backup generation;
- whether fuel can reach generators;
- whether communications remain available;
- whether repair crews can access damaged assets;
- whether sanitation can continue;
- whether vulnerable households can cope with loss of lifts, cooling or medical devices.
The electricity failure becomes a wider civilisation problem only through the dependency and receiver field.
Case study: finance
A bank fails.
The trigger may be losses, fraud, liquidity stress or a confidence shock.
Propagation depends on interbank exposure, shared assets, payment-system dependence, depositor behaviour, liquidity, legal resolution mechanisms and confidence in public backstops.
If the failed institution can be resolved while payments continue and other banks remain solvent, the event remains bounded.
If forced selling, payment disruption, runs and common exposures spread simultaneously, the same initiating event becomes a cascade.
Case study: education and succession
Suppose a profession loses experienced people faster than it trains replacements.
The first visible effect may be longer training times and more supervision.
Then capability loss propagates:
EXPERT LOSS → LOWER TRAINING CAPACITY → WEAKER SUCCESSOR INDEPENDENCE → GREATER KEY-PERSON DEPENDENCE → SLOWER MAINTENANCE / REPAIR → HIGHER FAILURE RATE → EVEN MORE EXPERT LOAD
The cascade is not primarily educational or technical. It crosses both.
Case study: drought
Drought is the trigger.
Whether it becomes a civilisational cascade depends on storage, demand, crop diversity, trade routes, energy, pricing, governance, household buffers, public trust and ecological condition.
One region may adapt through conservation and alternative supply. Another may cross a food or water threshold. Migration can then alter housing, labour, politics and public-health load elsewhere.
The mechanism is a network, not “drought causes collapse.”
Case study: information failure
False information can be both trigger and amplifier.
A false bank rumour can cause withdrawals. A false emergency message can redirect traffic into danger. A hidden maintenance fault can remain uncorrected because reports are suppressed.
Information failure propagates especially quickly when many actors use the same signal.
Shared information can coordinate civilisation. Corrupted shared information can coordinate the wrong move at scale.
How to stop propagation
The exact intervention belongs to the relevant domain experts and legitimate authorities. But the propagation map suggests general containment moves:
- isolate damaged components where possible;
- reduce coupling so the failure cannot travel freely;
- protect bottlenecks and scarce repair resources;
- unload non-critical demand;
- activate independent alternatives rather than nominal backups;
- prioritise receivers already near survival or access thresholds;
- restore observability and truthful information;
- protect repair crews and routes;
- prevent overload transfer into surviving systems;
- preserve options so one rescue path does not become another single point of failure.
The Propagation Audit
- What exactly is the trigger?
- Which assets, populations and capabilities are exposed?
- Which vulnerabilities make exposure dangerous?
- What is the first actual loss?
- What amplifies that loss?
- Where are the bottlenecks?
- Which dependencies are load-bearing?
- Which dependencies are hidden?
- Which backups share the same failure mode?
- Which receivers have no substitute?
- What threshold could be crossed next?
- Which serial chains exist?
- Which branching cascades exist?
- Where can demand converge and overload survivors?
- Which systems are geographically co-located?
- Which rules, prices or platforms create logical coupling?
- Can bad information create coordinated wrong action?
- Can human behaviour amplify the event?
- Can an adversary exploit the response?
- Which present workaround creates future failure?
- What repair capability depends on the failed system?
- Can the failure be isolated?
- Can demand be reduced?
- Can a truly independent alternative carry the function?
- Who owns containment?
- Can the receiver still be reached?
- What is the speed of propagation?
- What is the speed of accurate containment and repair?
- What evidence would show the cascade is stopping?
- What World Return would show recovery is real?
The Propagation Gate
TRIGGER OCCURS
↓
EXPOSURE?
NO → NO DIRECT PATH
YES
↓
VULNERABILITY SUFFICIENT FOR LOSS?
NO → ABSORBED
YES
↓
INITIAL LOSS
↓
LOAD-BEARING FUNCTION?
NO → BOUNDED DOMAIN FAILURE
YES
↓
THRESHOLD BREACH?
NO → STRESS / DEGRADATION
YES
↓
AMPLIFIER / BOTTLENECK / COMMON-MODE PATH?
NO → CONTAINED BREACH
YES
↓
DEPENDENT FUNCTIONS FAILING?
NO → RESTORE
YES
↓
PROPAGATION OUTRUNNING CONTAINMENT?
NO → BOUNDED CASCADE
YES
↓
REPAIR MACHINE INTACT?
YES → TRIAGE / ISOLATE / REBUILD
NO → RECOVERY FAILURE RISK
↓
CONTINUITY STILL REPRODUCIBLE?
YES → TRANSFORMED / SUCCESSOR CONTINUITY
NO → CONTINUITY FAILURE
What this article refuses to claim
- There is no universal sequence that every civilisation follows before collapse.
- Education, governance, production and physical constraints remain useful domains, but they are not the only possible failure entry points.
- A trigger is not automatically the root cause.
- Complexity does not automatically create collapse.
- Interdependence is not automatically fragility.
- Cascades can be enormous and still recoverable.
- External shocks are not proof of incompetence.
- Political failure does not automatically equal civilisation failure.
- Not every bottleneck should be eliminated; some are deliberate and manageable.
- Speed alone is not resilience; wrong fast action can amplify damage.
- No propagation model replaces domain expertise or evidence from affected receivers.
Frequently Asked Questions
What causes civilisation collapse?
There is no single universal cause. Collapse risk rises when triggers enter a vulnerable dependency field, load-bearing thresholds are breached, failure propagates across systems, and containment or recovery capacity is insufficient.
What is the difference between a trigger and a cause?
A trigger is the event that initiates or exposes the problem. Causes include the vulnerabilities, dependencies, amplifiers and repair constraints that determine why the trigger produced the observed consequence.
What is a cascading failure?
A cascading failure occurs when loss in one system creates additional loss in dependent or overloaded systems, causing the failure to spread beyond the initiating component.
Does a cascade mean civilisation has collapsed?
No. A cascade can remain bounded if the wider civilisation retains enough repair, substitution, coordination and continuity capacity.
What is a common-mode failure?
It occurs when apparently independent systems fail together because they share the same underlying vulnerability, supplier, platform, location, fuel, authority or human expert.
How can cascading failure be prevented?
Map dependencies before crisis, preserve margin, reduce unnecessary coupling, test backup independence, protect bottlenecks, build degraded safe modes, restore truthful information quickly and preserve the repair machine.
Where this fits in the Civilisation library
- Civilisation Hub — runtime router.
- How Civilisation Changes Direction — Reference, Actual and Delta.
- Civilisation Drift — persistent separation from the reference.
- How to Read Collapse Signatures — warning evidence geometries.
- How to Diagnose a Suspected Civilisation Failure — bounded diagnosis.
- How to Prevent Civilisation Collapse — keep failure recoverable.
- Failures of Civilisation — threshold breach and floor failure.
- Bottlenecks in Civilisation — the dedicated bottleneck branch.
This page owns the propagation question: how a disturbance becomes a wider failure through exposure, vulnerability, amplification, bottlenecks, dependence and repair constraints.
The shortest useful summary
- Trigger is not the whole cause.
- Exposure determines what the trigger can reach.
- Vulnerability determines how much damage exposure can create.
- Amplifiers enlarge the initial loss.
- Bottlenecks concentrate dependence.
- Common-mode failures defeat nominal redundancy.
- A threshold breach turns a domain problem into a floor problem.
- A cascade is propagation, not automatically collapse.
- Recovery constraints determine whether the route back survives.
- Receiver and time effects belong inside the propagation map.
- The key comparison is propagation speed versus accurate containment and repair speed.
- World Return determines whether containment actually worked.
The real propagation condition
Civilisation does not fail because one bad thing happened.
It becomes vulnerable when the bad thing reaches a field with too little margin, too much hidden coupling, too few alternatives, weak feedback and a damaged repair machine.
The job is not merely to ask what broke. It is to ask what the break can reach, what makes it larger, what it can pull down next, and whether civilisation still has enough room to stop it.
