On 11 December 1998, NASA launched the Mars Climate Orbiter. Nine and a half months later, on 23 September 1999, it arrived at Mars and was never heard from again. It came in at roughly 57 kilometres above the surface instead of the planned 226, hit air far denser than it was built for, and was gone.
The cause is now a famous piece of trivia. The ground software built by Lockheed Martin reported thruster impulse in pound-force seconds. The navigation software at JPL read those same numbers as newton-seconds. One pound-force second is about 4.45 newton-seconds, so every figure that crossed between the two teams arrived meaning roughly a fifth of what it had meant when it left. The mission cost $327.6 million.
The trivia version stops there, and it stops one step too early. The interesting thing is not that two teams used different units. Both units are legitimate measures of the same physical quantity. Neither team was working with bad numbers, and neither team was being careless. The number was correct when it was written and correct when it was read. What was lost in between was not accuracy. It was meaning.
And nobody caught it for nine months.
The failure was not the error. It was the silence after it.
Each individual thruster firing was tiny. A momentum-unloading burn barely moves a spacecraft, so being wrong about it by a factor of four barely moves the predicted position either. Any one of those events, on its own, would have been invisible in the noise.
The trouble was that they kept happening. The orbiter had a single solar panel, which made it need these corrections far more often than its sister craft. By the operations navigation team’s own expectations, ten to fourteen times more often than anticipated. So a rounding-error-sized discrepancy occurred, and occurred again, and occurred a few hundred more times, and quietly accumulated for the length of a pregnancy into a fatal one.
This is the shape of the failure worth taking seriously. Not a dramatic error that someone should have caught, but a small, structurally invisible mismatch with a long, uninterrupted runway on which to compound. On the day it started, checking would have been trivial. On the day it mattered, checking was no longer possible. Every day in between looked exactly like a normal day.
You do not find these by being more careful. Carefulness catches things that look wrong. This did not look wrong to anyone, at any point, until it was over.
The same shape, on a Tuesday
A product team at a B2B software company moves a feature out of Q3. It is the right call. The underlying dependency slipped, and shipping it half-built would have been worse. The decision is made in the right room, by the right people, and written up properly in the roadmap doc that afternoon.
Nobody carries it over to Sales. Not out of negligence: everyone in the room assumes someone else will, or that the roadmap doc is the mechanism, or that it will come up in the next sync.
That same week, an account executive runs a deal review with a prospect and the Q3 timeline is still in the deck, because it is still in the version of the deck she has. The deal closes. Customer Success builds the onboarding plan around a capability arriving in Q3. The customer’s own project manager, who has to justify this purchase internally, builds a rollout plan and tells their operations team what to expect in October.
Nothing looks wrong. Every one of those people did their job correctly using the best information available to them. The roadmap doc says one thing, four downstream plans say another, and no surface anywhere in the company compares the two.
Twelve weeks later the escalation arrives. The customer’s rollout is blocked, their PM has spent internal credibility on a date that is not going to happen, and the conversation is no longer about a feature. Legal reads the contract language. The renewal, six months out, is suddenly something the account team talks about in hushed tones.
By then, the cost is not the feature slip. It is four downstream plans, three months of a customer’s internal politics, and a trust relationship that took two years to build. The slip was a scheduling change. The damage was propagation failure.
The shape does not belong to software. A lender’s risk committee tightens an eligibility rule, and the partner channel keeps pre-approving applicants against the old criteria for six weeks, so every one of those applicants is told yes and then told no. A logistics operator changes a carrier cut-off time, the account team keeps quoting next-day delivery, and the first anyone hears of it is when a customer’s customer does not get their order. Same structure every time: a correct decision, made by the right people, that quietly invalidated work already in motion somewhere downstream, with no mechanism that noticed.
Why nobody catches it
Because catching it requires knowing there is something to catch, and that is precisely what is missing.
This is the part that makes decision decay different from an information problem, and it is why the last few years of enterprise tooling have not touched it. We have spent that time making company knowledge findable. Search across every system. Answer engines over the whole corpus. Retrieval that is genuinely, remarkably good.
All of it is pull. Every one of those tools waits to be asked. And the account executive with the old deck does not ask, because she is not confused. She is confident, working from a version of the truth that was accurate the last time she checked. Confidence does not generate queries. The people most exposed to a stale decision are, by definition, the least likely to go looking for it.
A wiki has the same limitation from the other direction. It stores what is true. It does not store what stopped being true, when it stopped, or which commitments elsewhere in the company were built on the old version and are still standing on it. Update the roadmap doc and the doc is now correct. The four downstream plans are still wrong, and the doc has no idea they exist.
JPL had the numbers. They had them for nine months. Having them was never the problem.
Telling the people who are still standing on it
What was missing on the Mars Climate Orbiter was not data and not diligence. It was a mechanism that noticed when one team’s output no longer meant what another team assumed it meant, and said so, without being asked, while there was still time to correct.
That is a narrower thing to build than it sounds, and it is what GapfAI is: one shared memory of the decisions a company actually makes, a model of which teams and which commitments each decision touches, and a push into the tools those teams already work in when a change invalidates something they are still acting on. Not a place to search. A thing that arrives.
NASA in 1999 had some excuse. A company in 2026 has none at all. The decisions are already being made in writing, in Slack and in docs and on recorded calls, and the only missing piece is the connection between a decision changing and the people whose work it just quietly invalidated.
We should be straight about what we have not proven. There is no public dataset that measures decision decay, so we cannot tell you what it costs at your company, and we are not going to borrow a number that measures something else and imply it does. We are running structured interviews to build that figure ourselves. Until it exists, the argument above is a mechanism, not a measurement.
Which leaves a question worth sitting with, about your own company rather than a spacecraft. Somewhere in it right now, someone is confidently telling a customer something that was true the last time they checked. What in your organisation would tell them otherwise, not the intention and not the norm but the actual mechanism, and how long would it take?
Frequently asked
- What happened to the Mars Climate Orbiter?
- NASA launched it on 11 December 1998 and lost it on 23 September 1999 as it arrived at Mars. Ground software built by Lockheed Martin reported thruster impulse in pound-force seconds while JPL’s navigation software read the same values as newton-seconds, a factor of about 4.45. The accumulated trajectory error brought the spacecraft in at around 57 kilometres altitude instead of the intended 226, where it was destroyed. The mission cost $327.6 million.
- Why did it take nine months to notice?
- Because each individual discrepancy was too small to see. The error came from momentum-unloading burns, which are low-energy events, so a fourfold error in any single one produced a negligible change in the predicted trajectory. The orbiter needed these corrections far more often than expected, and the error compounded through repetition rather than appearing all at once. Every day of the cruise looked normal until the last one.
- What is decision decay?
- Decision decay is what happens when a decision is superseded and the teams already acting on the old version are never told. The new decision is recorded correctly. The work built on the previous one continues, uncorrected, because nobody downstream knows anything changed. It is invisible while it is happening, and its cost compounds with every day and every commitment made on the stale version.
- Why does enterprise search not solve this?
- Because search is pull. It answers questions, and someone has to ask. A person working from a superseded decision is not uncertain, so they have no reason to query anything. Exposure and likelihood of searching are inversely related. Fixing this requires push: a system that identifies which teams and which commitments a change invalidates, and reaches them without being asked.
- How do you actually prevent it?
- Three things have to exist together: a shared record of decisions captured from where they are already made, a model of which downstream teams and commitments each decision touches, and a delivery mechanism that reaches those teams in the tools they already use when something changes. A record alone is a wiki. A record plus search is an answer engine. Only the third piece closes the loop, and it is the piece almost nobody has built.
Sources
- NASA, Mars Climate Orbiter Mishap Investigation Board Phase I Report (1999)The units mismatch, the altitude figures, and the higher-than-expected frequency of momentum-unloading events.
If any of this is recognisable at your company, tell us where it costs you the most.