How Corrie Pitzer Thinks About Alarms That Turn Workers Into Passive Victims
Corrie Pitzer's Episode 9 argument is a warning about control dependence. An alarm can add protection, but if the design removes human verification, people may stop looking for changing conditions and become passive recipients of a signal that can arrive late or fail entirely.

Key takeaways
- 01An alarm is a control component, not proof that the exposure is understood or managed.
- 02Corrie Pitzer warns that a safeguard can reduce attention when workers stop looking and wait for the signal.
- 03Leaders should test what happens when the alarm is delayed, unavailable, misunderstood, or ignored.
- 04A strong design keeps human verification active without turning people into a substitute for engineering controls.
- 05The practical test is whether the control changes exposure before the alarm becomes the main event.
Episode 9 of the Headline Podcast, published on November 6, 2025, features Corrie Pitzer discussing risk competence, control reliance, and the limits of measuring safety by the absence of accidents. His argument changes how leaders should evaluate alarms, because a safeguard can become part of the hazard when people stop verifying the work.
Corrie described the danger through a memorable fragment: “I put a control in place.” The workers then stopped looking and waited for the alarm. That is not a reason to reject technology, but it is a reason to test whether the design keeps attention, judgment, and earlier controls alive.
Why an alarm is not the same as control
An alarm detects or announces a condition. A control prevents exposure, limits consequence, or makes a safer decision possible. The alarm becomes weak when the organization treats its presence as proof that the whole risk is managed.
An alarm has a place in a layered system, especially when a condition can change after work begins. The problem starts when it becomes the only visible safeguard. Workers may assume that the system will warn them before harm develops, while leaders read a successful alarm test as evidence that the operating risk is acceptable.
Ask which exposure the alarm addresses, how quickly the condition can become harmful, what the alarm can miss, and who must act when it sounds. If the answer depends on a person noticing a signal during a noisy or crowded task, the human response is part of the control design.
The OSHA Recommended Practices for Safety and Health Programs support a management approach that identifies hazards, controls them, and involves workers in the process. An alarm can support that cycle, but it cannot replace hazard identification or field verification.
How passive reliance develops
Passive reliance develops when a signal becomes easier to trust than the work evidence. People stop checking the condition directly because the system has trained them to wait for an alarm, even when the alarm cannot cover every failure mode.
The shift is gradual. A new alarm catches one serious deviation, so the team gains confidence. After several quiet weeks, verification begins to feel unnecessary. A supervisor asks whether the alarm is working, not whether the barrier remains effective under current conditions.
Corrie Pitzer's warning matters when an automated safeguard produces reassurance without changing the exposure. The system can be available while the task becomes more dependent on timing, attention, network connection, calibration, or a response that no one has rehearsed.
Observe what workers inspect before the alarm activates, what they do when it activates, what they do when it does not activate, and what evidence remains afterward. These observations reveal whether the system supports competence or gradually displaces it.
What should leaders test before trusting the signal?
Leaders should test the alarm's detection, meaning, response, and recovery chain. A green test result is insufficient if the system detects only one scenario or if the response cannot be completed within the available time.
Start with the detection boundary. What condition triggers the alarm, and which conditions remain outside its field of view? Then test the signal itself. Can people hear, see, or interpret it during the actual task, including when production noise, weather, lighting, or workload changes?
The third test concerns response. A signal has value only when a named person can take the required action. That action may be to stop work, isolate energy, move people, call for help, or verify an instrument. If the response depends on a person who is not present for every shift, the control is incomplete.
The fourth test concerns recovery. After a false alarm, missed signal, or delayed response, does the team know how to return to a safe state? The ISO 31000 risk-management principles connect risk treatment with monitoring, communication, and review rather than a one-time approval.
When does automation reduce attention?
Automation reduces attention when it removes the reason to inspect the condition directly. The safest design automates repetitive detection while preserving the human questions that reveal context, drift, and a mismatch between the planned task and the work in front of people.
Consider a mobile equipment alarm that warns of a person entering a restricted zone. The alarm may work as designed, yet the operation can still become more fragile if workers stop checking sight lines, route changes, lighting, or communication quality. The system has improved one layer while allowing other layers to decay.
When people receive repeated alerts without learning what caused them, the signal becomes background noise. When every alert triggers a punitive response, people may mute, ignore, or work around the system. Both outcomes weaken the evidence that leaders believe they are receiving.
The NIST AI Risk Management model, published in 2023, is useful when an alarm includes prediction or automated classification. It emphasizes context, validity, transparency, and human oversight, which are necessary because a model can be accurate in a test and still mislead people in a changing work environment.
How can a team keep verification active?
Verification remains active when the team checks the condition before relying on the alarm, confirms that the alarm can be heard and understood, and reviews whether the response changed the exposure rather than only acknowledging the signal.
A supervisor can build this into the first 10 minutes of a high-risk task. Ask what condition the alarm is meant to detect, what earlier control should prevent it, and what the team will do if the signal is absent. These questions prevent the system from becoming the only safety story.
Review the same control at 7, 30, and 90 days. The 7-day check catches early workarounds, the 30-day review shows whether the response is becoming routine, and the 90-day review tests whether maintenance, staffing, or production pressure has changed the assumptions.
Andreza Araujo's published work on safety culture supports this emphasis on repeated decisions. A safeguard becomes part of culture when people use it under pressure, question it when conditions change, and receive support when the evidence says that the original design no longer fits.
What should leaders compare in the control hierarchy?
Leaders should compare the alarm with the controls that come before it. The question is not whether the alarm works in isolation, but whether the system reduces exposure early enough that the alarm is a backup rather than the normal route to safety.
| Control question | Alarm-dependent design | Stronger layered design |
|---|---|---|
| What prevents exposure? | People wait for the warning | Design or separation reduces access |
| What detects change? | One signal carries the burden | People, instruments, and field checks provide independent evidence |
| Who responds? | Ownership is assumed | A named person has authority and time |
| What happens after failure? | The team restarts when the alarm clears | Recovery is verified before work resumes |
For related reading, compare the tests for safety-critical alarms before startup, the gaps that make critical-control dashboards look better than the work, and the questions that keep risk decisions grounded.
What changes when the alarm is unavailable?
That balance protects attention and accountability during ordinary work and during abnormal conditions.
A control is not resilient if the safe method disappears when the signal is unavailable. The team should know the manual fallback, the boundary that stops work, and the person who decides whether recovery is possible.
Run one deliberately controlled exercise in which the alarm is treated as unavailable. Do not create an unsafe condition. Instead, remove the signal from the decision sequence and ask the team to identify the earlier barriers, the observable evidence, and the point at which work must stop. The exercise reveals whether competence lives in the system or only in the notification.
Document 3 findings. Record which control prevented exposure, which assumption was missing, and which decision owner had to be called. Then correct the design before the next task, because a fallback that exists only in a procedure is not yet a dependable control. Share the result with every shift that depends on the alarm.
Recommendation
Choose one alarm that workers rely on and observe the task before, during, and after activation. Then strengthen the earliest practical control, define the response owner, and keep a verification step that can challenge the alarm's assumptions.
Corrie Pitzer also used a comparison about proving that there are no whales in the ocean by sending people out with buckets. The point is that absence of an event does not prove that the system is safe. A quiet alarm history may show low exposure, low detection, good prevention, or simply that no one noticed the failure.
Leaders should measure the quality of verification, not only alarm availability. Record whether the underlying condition was checked, whether the alarm was understood, whether the response occurred within the required time, and whether the control remained usable after the work changed.
Listen to the full Episode 9 conversation with Corrie Pitzer for the argument behind this design test. A control earns trust when it reduces exposure before people become dependent on a signal that may arrive too late.
Frequently asked questions
What is Corrie Pitzer's warning about alarms?
Can an alarm be a weak safety control?
How should leaders test an alarm system?
What should replace alarm dependence?
What should an EHS manager take from Episode 9?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.