From Conceptual BowTie to Operational Ex Dashboard

The third layer of the Operations BowTie, and arguably the one that matters most: degradation elements explain why a well-designed Ex management system still fails in practice. An overdue inspection does not make equipment unsafe, but it does erode what Operations knows about actual condition. The article traces how backlogs and repeatedly extended findings normalise a degraded state, defines the POI as the moment degradation becomes visible, and sets out five responses available at that moment, plus the case for treating "accept and continue" as a traceable decision in its own right.

A worker operates industrial machinery on a busy factory production floor.

Follow up on BOWTIE with Head of Operations. Today’s pick is blocking / degradation elements.

This is the most important layer for the Head of Operations, because degradation elements describe why a good Ex management system can fail in real life.

Here I would define the POI as the moment Operations becomes aware that a preventive barrier is losing effectiveness.
The desired outcome it is:
Recognize degradation → assess its significance → decide → compensate/restore/escalate/STOP → verify.

✅See blocking elements below


Blocking and degradation elements in a table


Blocking and degradation elements in a table



For a threat, the POI asks:
“Can we stop this threat reaching the Top Event?”
For a preventive barrier, it asks:
“Is this barrier actually effective?”
For a degradation element, the question becomes:
“Do we know that one of our barriers is becoming weaker?”

That is closer to the daily reality of a Head of Operations.
Consider an inspection backlog.
An overdue inspection does not automatically mean the equipment is unsafe.
But it does mean something important:
Inspection barrier ↓
Knowledge about actual Ex condition ↓
The POI therefore occurs before the situation becomes “we don’t know whether the plant is compliant.”
Operations sees:
5% overdue → 15% → 25% → critical equipment overdue → inaccessible assets → repeated extensions
At some defined point, this requires an operational decision.
The same principle applies to findings:
Finding → deadline → overdue → extension → second extension → mitigation expires → still operating
It is the gradual normalization of the degraded condition.

So let us give the Head of Operations five possible responses at a degradation POI:
RESTORE — restore the barrier to its intended condition.
COMPENSATE — introduce a justified temporary barrier/control.
RESTRICT — reduce the operating envelope, activity, equipment or exposure.
ESCALATE — obtain competent Ex/engineering decision where Operations cannot determine acceptability.
STOP — where the required Ex-safe condition cannot be demonstrated or maintained.

And importantly, “accept and continue” should also be recognized as an operational decision. If continued operation is justified, that justification should be traceable.
This gives us the complete left side
Your three layers now work together:
THREAT
What can cause us to lose Ex control?
↓
PREVENTIVE BARRIER
What prevents that from happening?
↓
DEGRADATION ELEMENT
What can make that barrier ineffective?
↓
POI
How do we know the barrier is degrading, and when must Operations act?
↓
OPERATIONAL DECISION
Continue / Restore / Compensate / Restrict / Escalate / STOP
↓
TOP EVENT prevented — or reached

A Head of Operations cannot personally inspect every Ex asset, review every certificate or engineer every modification.
But ‘HoO’ need a system that tells them when the barriers they rely on are degrading—and when an operational decision is required.
That can turn this from a conceptual BowTie into an actual Operational Ex dashboard.