I Stopped Believing That Ten Instruments Are Better Than Two

Industrial Philosophy

I Stopped Believing That Ten Instruments Are Better Than Two

When redundancy becomes a volume knob, we don’t buy safety-we just double the noise and the cost.

Marco handles logistics for a high-end restoration firm in Milan, a job that mostly involves telling people why their 18th-century marble fireplace hasn’t arrived yet. He once told me that when he has to ship something truly irreplaceable, he doesn’t put it in a bigger crate or hire two trucks to drive side-by-side.

He spends three days investigating the specific suspension system of a single trailer. To Marco, the second truck is just a second opportunity for the same pothole to ruin his life. He understands something that the industrial validation world has spent the last decade forgetting: redundancy is not a volume knob.

🕳️

The Single-Point Truth

Two trucks hitting the same hole doesn’t save the cargo; it just doubles the damage report.

I thought about Marco this morning while I was staring at a piece of sourdough. I’d already taken a bite when I noticed the bloom of green-grey mold on the heel. My immediate, lizard-brain reaction was to check the rest of the loaf.

If I found a slice that looked clean, I’d be safe, right? But that’s the independence fallacy. The mold isn’t a localized event; it’s a symptom of the environment the entire loaf shared. Adding more slices to the bag doesn’t give me a higher probability of a clean meal; it just gives me more moldy bread.

The Seductive Math of “More”

In the world of thermal validation-where we stick dataloggers into massive industrial autoclaves to prove that life-saving medicine has been properly sterilized-we are currently obsessed with “more.” If a process once required five sensors, the new protocol demands twelve.

If twelve was the standard last year, the auditor is now hinting at twenty-two. The logic is seductive in its simplicity. We assume that if the probability of a single logger failing is 1%, then the probability of two failing is 0.01%, and the probability of five failing is practically zero.

1%

Single Failure

0.01%

Theoretical Double

100%

Shared Environment

The mathematical beauty of independence versus the brutal reality of shared environments.

This math is beautiful, clean, and entirely fraudulent.

It relies on the assumption of independence. In a coin toss, the result of the first flip has zero influence on the second. But a datalogger in a steam sterilizer is not a coin. It is a physical object subjected to a shared, brutal environment.

If the steam is saturated incorrectly, if the pressure spike exceeds the seal’s rating, or if the chemical environment triggers a specific corrosion, it doesn’t matter if you have two loggers or two hundred. They are all sitting in the same “bag of bread.”

I’ve spent a lot of time as an online reputation manager, which is really just a fancy way of saying I watch how people react when systems break. When a company loses a data set because their “redundant” servers were all in the same basement during a flood, the public doesn’t see a statistical fluke.

They see a fundamental misunderstanding of risk. We treat redundancy as a linear shield-double the units, double the safety-when in reality, we are often just doubling the noise and the cost without moving the needle on the actual failure mechanism.

The O-Ring Trap

Let’s look at how this actually works in a high-pressure processing environment. You have a chamber. You fill it with sensors. Each of those sensors has a glass-to-metal seal or a polymer O-ring. These seals are the gatekeepers.

In a standard redundant setup, a technician might use thirty identical sensors from the same production batch. If there is a microscopic flaw in the batch’s material composition, or if the process temperature reaches a point that causes that specific polymer to lose elasticity, every single sensor will fail at roughly the same moment.

The industry treats the “lost measurement” as a random act of God. We act as though the sensor simply decided to stop working, like a heart attack in an otherwise healthy patient. Because we frame the failure as random, we think more units will solve it.

But in thermal validation, failures are almost always environmental or design-based. The sensor didn’t “die”; the environment killed it. And if the environment can kill one, it can kill thirty of the same kind.

This obsession with quantity creates a massive amount of “data debt.” More sensors mean more calibration certificates to track, more batteries to charge, more data points to filter, and more opportunities for a technician to drop a unit on a concrete floor.

We are complicating the process to solve a problem that quantity was never meant to fix. We are trying to outrun a systemic failure with sheer mass.

I’ve been guilty of this myself. I used to advise clients to “flood the zone”-to put out so much positive content that the negative stuff would be buried by sheer volume. It’s the same logic.

But if the core of the reputation problem is a fundamental truth about the company’s behavior, it doesn’t matter if you have ten thousand positive articles. A single, well-documented failure will cut through all of them because they all share the same weakness: they don’t address the root cause.

The Swiss Approach to Precision

In the Swiss Alps, where the air is thin and the engineering is uncomfortably precise, there is a different approach. The engineers at

Valimetric

don’t seem particularly interested in selling you a bucket of thirty loggers to cover your tracks.

Their entire philosophy is built on the rejection of the shared failure mechanism. If the problem is that steam and pressure destroy sensors, the solution isn’t more sensors; it’s a sensor that steam and pressure cannot kill.

HE-TEST

They build around the PT1000 platinum RTD sensor, housed in a hermetically sealed stainless-steel body that is helium leak tested. It’s a specialized, rugged response to a specific, hostile environment.

When you remove the mechanism that causes the failure-like the ingress of moisture or the death of a battery under high heat-the need for “safety in numbers” begins to evaporate. You don’t need a dozen witnesses to a crime if the crime never happens.

The “Redundancy Paradox” is that the more identical units you add to a system, the more you hide the underlying fragility of the design. You feel safe because the lights on the dashboard are green, but those lights are all connected to the same failing engine.

We see this in finance, where “diversified” portfolios are actually just a collection of different assets that all happen to crash when interest rates move. We see it in infrastructure, where redundant power lines are all strung on the same poles that a single storm can knock down.

A Perfectly Documented Disaster

I remember a specific incident where a pharmaceutical manufacturer lost a three-million-dollar batch of vaccine. They had forty-eight dataloggers in the cycle. It was a masterpiece of redundancy.

$3.0M

Lost Batch Value

48 sensors. 0 readable files. 100% failure rate.

On paper, the probability of losing that data was astronomical. But the steam was “wet”-it had too much liquid water-and it caused a specific type of thermal shock that cracked the standard housings used across their entire fleet. Forty-eight loggers went in; forty-eight unreadable files came out.

If they had used two loggers that were actually built for the environment, they would have saved the batch. But the protocol-written by people who love spreadsheets and hate physics-demanded forty-eight.

The protocol was followed, the data was lost, and the auditors were satisfied because the “redundancy requirements” were met. It was a perfectly documented disaster.

This is the danger of the “Redundancy Security Blanket.” It allows us to stop thinking. It gives us a metric-quantity-that is easy to measure but often irrelevant to the outcome. We stop asking, “Why would this fail?” and start asking, “How many do we have?”

True reliability is the absence of shared failure modes. It’s the realization that three slices of moldy bread are not better than one. It’s the shift from a “quantity-based assurance” model to a “design-based assurance” model.

It requires us to look at the instrument not as a disposable commodity that we can stack high, but as a piece of critical infrastructure that must be inherently capable of surviving the journey.

I still think about Marco and his marble fireplace. He’s probably in a warehouse right now, ignoring a fleet of extra trucks and instead checking the torque on a single set of bolts. He knows that in a world of shared risks, the only thing that matters is the integrity of the point of contact.

Everything else is just more weight to carry when things go wrong. We would do well to apply that same Swiss-level scrutiny to our own data.

More isn’t better. Better is better.

And until we acknowledge that correlation is the enemy of redundancy, we’re just buying more sourdough and hoping for a different result.