Autoimmunity
A protective function’s failure mode isn’t just that it grows too large, it’s that it starts misclassifying the healthy, ordinary parts of the organization as the threat it exists to stop, and it’s nearly impossible to self-diagnose because appropriate scrutiny and overreach feel identical from inside.
What Is It?
In biology, the immune system’s defensive mechanism sometimes misidentifies healthy tissue as a threat and attacks it, a failure mode built into the very mechanism that makes defense possible at all. Organizationally, protective functions, compliance, security, legal review, exist for the same reason: to defend against real threats. The same mechanism that makes them effective can also lead them to classify ordinary organizational activity as if it were the threat they were created to defend against, compliance starts treating every exception as suspicious, legal starts treating every experiment as unacceptable risk, security starts treating ordinary employees as adversaries, audit starts optimizing for procedural purity rather than business outcomes. Those aren’t just cases of “too much security,” they’re the defensive system mistaking healthy tissue for the enemy.
Why Does It Matter?
A security policy so disconnected from actual threat that employees quietly route around it, or a review process so broad it slows down work that was never risky, isn’t a sign the function is broken, it’s the same mechanism as biological autoimmunity, defense that has stopped distinguishing between danger and ordinary activity. Over time, success changes the environment: the original threat shrinks, but the protective function often retains the same mandate, staffing, and instincts, making false positives increasingly likely. The organization pays the cost twice: once in the friction the overreach creates, and again in the routing-around behavior it provokes, which often reintroduces exactly the risk the function was meant to prevent. The failure isn’t that the protective mechanism stopped working, it’s that it kept working after it stopped telling danger apart from ordinary activity.
What Changes Once You See It?
You stop assuming that more scrutiny is automatically safer, and start asking whether a protective function’s scope still matches the actual threat it was built to address.
You also stop assuming that the people applying the scrutiny can reliably tell the difference between appropriate caution and overreach, since from inside a defensive function, both feel like doing the job well.
Common Misunderstandings
- It isn’t a claim that protective functions are inherently bad or should be minimized on principle. The mechanism that enables real protection is the same one that can overreach, the two aren’t separable.
- It doesn’t mean every complaint about a compliance or security process is evidence of autoimmune overreach. Some scrutiny is genuinely proportional to real risk, the diagnostic has to look at scope relative to actual threat, not just at how much friction people feel.
- It isn’t easily self-corrected from inside the function doing the scrutinizing. Because appropriate caution and overreach feel the same from that vantage point, an outside check tends to be more reliable than internal self-assessment.
- It isn’t about individual personalities becoming power-hungry. Even conscientious people inside protective functions get constant feedback about failures to stop threats, and almost none about unnecessary interventions that quietly slowed healthy work.
Diagnostic Question
Is this function primarily stopping genuine threats, or has it started treating ordinary work as if it were one?
Explore Further
Field Notes
None yet.
Related Field Guide
Origin
Borrowed by analogy from immunology; the organizational application here is interpretive rather than a named management framework, though the underlying pattern of protective functions outgrowing their original threat is widely recognized in discussions of institutional security culture.