Every accident report eventually reaches for the same phrase: user error. It sounds like a diagnosis, precise and final, as though the investigation had traced a failure back to its true cause and found a person standing there instead of a machine. But the phrase is doing something quieter than diagnosing. It is comparing what someone did to what someone was supposed to do; and “supposed to do” comes from somewhere. It comes from a model of the user that existed before the person ever touched the device: attentive, trained, unhurried, reading the manual, following the sequence. Almost nobody matches that model all the time. Most people don’t match it most of the time. And yet it is the model against which their behavior gets judged.
This is not a story about careless engineers who forgot that real people are messy. Engineers know real people are messy; it’s one of the first things human factors training teaches. The more interesting story is about why the fiction persists anyway, what work it quietly does, and what happens when it hardens from a useful simplification into something closer to a verdict.
A model you cannot avoid building
Start with the constraint nobody escapes: you cannot design for every possible human. A doorknob has to assume something about hand size and grip strength. A warning label has to assume something about reading speed and attention span. A control panel has to assume something about which direction people expect a dial to turn. Even a chair assumes a spine. Specification requires abstraction, and abstraction requires deciding which variations matter and which get treated as noise.
So every designed object contains, whether anyone states it or not, an implied person; a composite built from averages, from training assumptions, from what the standards body decided was reasonable to expect. Call this the phantom user. The phantom user is not a lie exactly. It’s closer to a working fiction, the kind statisticians build when they need a distribution to reason about instead of an infinite scatter of individuals. Without it, nothing could be built at all.
The trouble starts when the fiction stops being treated as a fiction. A distribution is supposed to be provisional; revised as better data arrives, narrowed or widened as the population using the thing changes. A phantom user that hardens into an assumption is different. It stops being a tool for reasoning and becomes a boundary for assigning fault. Once that happens, the gap between the phantom and the real person isn’t read as evidence that the model was wrong. It’s read as evidence that the person was.
The switches that looked identical
The clearest place to watch this shift happen is in the history of aviation, because for a long time the aircraft themselves didn’t change and the explanation for why they kept crashing did.
During the Second World War, American bomber and transport aircraft experienced a pattern of accidents that made no obvious sense: experienced pilots, midway through otherwise uneventful landings, would retract the landing gear instead of the flaps, or the flaps instead of the gear. The investigations that followed did what investigations of that era almost always did; they found pilot error. The pilot had pulled the wrong lever. Case closed, next accident.

A psychologist named Alphonse Chapanis looked at the same accidents and asked a different question, not about the pilots but about the levers. In many of these cockpits, the gear switch and the flap switch were identical in shape, mounted next to each other, distinguishable only by a label a pilot under landing stress had no time to read. Chapanis proposed shaping the switches differently; a wheel-shaped knob for the gear, a small flap-shaped one for the flaps; so a pilot’s hand could tell them apart without looking. The mistake rate fell. Nothing about the pilots had changed. The interface had simply stopped assuming a version of the pilot that didn’t exist: one calm enough, under pressure, to read a label instead of reaching by feel.
This is usually told as an origin story for human factors engineering, and it is one. But there’s a second story tucked inside it that gets less attention: the reclassification. Before Chapanis, the same behavior; reaching for the wrong lever under stress, was coded as a failure of the person. After, it was coded as a predictable response to a bad design. The pilots hadn’t gotten better. The explanation had. What “counted” as an operator’s fault turned out to be something that could move, depending entirely on how carefully anyone had looked at the interface standing between the person and the task.
That’s the part worth sitting with. Blame, in engineered systems, is not simply discovered after an accident. It is allocated by the model of the user that was built in beforehand, often long before anyone imagines a specific accident at all.
The phantom user didn’t disappear
It would be satisfying to end there: engineers learned their lesson, human factors became a discipline, and the phantom user was retired in favor of designing for people as they actually are. That isn’t what happened. The phantom user didn’t go away. It got a better résumé.
Modern human factors design still builds around a model person; now informed by real anthropometric and cognitive data rather than guesswork, which is a genuine improvement. But the model is still bounded, and the boundary is still doing the same old work. It typically assumes a user operating the device as intended, under expected conditions, with typical sensory and cognitive capacity, for the purpose the device was built for. Step outside any one of those boundaries; a child instead of an adult, a distracted commuter instead of a focused operator, fatigue instead of alertness, one hand instead of two, low light, high stress, a second language, a body that doesn’t match the reference population; and you are, once again, outside the specification. Which means that when something goes wrong under those conditions, the paperwork still has somewhere to point that isn’t the design.
You can see the same structure in objects far more mundane than a cockpit. A childproof cap is designed to defeat the average four-year-old’s fine motor control and problem-solving persistence for the average length of time an average adult takes to notice a bottle within reach; which is exactly why it fails against the child who is older, more determined, or simply has more uninterrupted minutes than the model assumed. A smartphone interface assumes a user with full attention, a free hand, and a stable surface, which is a strange assumption to build into an object whose primary use case is walking, driving, and standing on trains. A safety guard on industrial equipment assumes an operator who hasn’t disabled it because it slowed down a production quota that management set without adjusting the guard. In each case, the fiction wasn’t unreasonable when written. It became a liability only when it quietly stopped being questioned.
Warning labels are not what they look like
Once you notice this pattern, a familiar object starts to look different: the warning label. It presents itself as a piece of instruction, there to help. But look at what most warning labels actually say; do not use near water, keep away from children, do not operate while fatigued, do not exceed rated load, and a different function becomes visible. These labels are rarely written to change behavior. Studies of warning compliance have shown for decades that most people don’t read them, and manufacturers largely know this. What the label actually does is complete a legal record. It documents, in advance, that the manufacturer specified the correct conditions of use — which means that when a real user, in real conditions, doesn’t match those conditions, the deviation has already been pre-classified as theirs to own.
This is the phantom user’s clearest and most literal form: a paragraph of small print defining, with legal precision, exactly who the device was designed for, so that everyone who isn’t quite that person has already been told, in effect, that whatever happens to them is not the manufacturer’s problem. The label isn’t primarily a communication tool. It’s a boundary marker for a fictional person, placed there so the real person can be measured against it later.
What actually changes when the model is honest
None of this argues for abandoning the phantom user, which is impossible, or for designing every object to withstand every conceivable misuse, which is also impossible and would make most objects unusable in the process. The Chapanis story doesn’t work because he eliminated the model of the pilot. It works because he replaced a bad model with a more honest one; a pilot under landing stress, hands too busy to read labels, rather than a pilot with time to spare, and then built the switches to match the model that was actually true, rather than the model that was administratively convenient.
That distinction is the whole difference. A model built from the most convenient assumption tends to drift toward whichever version of the user is cheapest to accommodate and easiest to blame when things go wrong. A model built from the most honest available evidence about how people actually behave under the actual conditions of use tends to drift the other way; toward interfaces, guards, and instructions that fail less often, because they were never measuring reality against a fiction to begin with.
The question worth asking of any designed system, then, isn’t whether it assumes a user: it has to. It’s whether that assumption was ever checked against anyone real, and whether the people who wrote it were the same people who’d be blamed if it turned out to be wrong. Those two questions, asked together, are usually enough to tell you whether “user error” on a given accident report means what it claims to mean, or whether it’s simply the last visible trace of a fiction nobody thought to revise.
THE END




