Caspian Office

Tripod Beta analysis

Analyse an incident the Tripod Beta way: agent, object and event trios, the barriers that should have stood between them, and the immediate cause, precondition and underlying cause behind each failure — classified against the eleven Basic Risk Factors. Export SVG or PNG. Saved on your device.

Open Tripod Beta analysis →
Private · runs in your browserOffline · after first loadFree · no signup

What is a Tripod Beta analysis?

A free Tripod Beta incident analysis tool that runs entirely in your browser. Tripod Beta is a barrier-based incident causation method from the Swiss-cheese school of accident analysis, used widely in upstream oil and gas. It describes what happened as a chain of trios: an agent (something with the energy or potential to cause harm) acts on an object (whatever is harmed), producing an event. Between the agent and the object there should have been barriers. For every barrier that failed, was missing or was inadequate, the analysis asks why in three deliberate steps — the immediate cause that defeated it, the precondition that made that likely, and the underlying organisational cause behind both. Each underlying cause is then classified against one of the eleven Basic Risk Factors, and the profile below the diagram counts them, so a weakness that shows up behind several independent barrier failures becomes obvious. Everything stays on your device.

How to use Tripod Beta analysis

  1. Describe the incident as trios — Start with the loss itself. Name the agent, the object it acted on and the event that resulted. Then work backwards: add a trio for each earlier step, since one trio's event usually becomes the next trio's agent. Mark the final loss as the top event.
  2. Add the barriers that should have stood in the way — For each trio, list the controls that were meant to keep the agent away from the object. Keep them to real, auditable things — a tagline, an exclusion zone, a trip, a permit — rather than vague ideas such as "awareness".
  3. Code each barrier by how it behaved — Set each barrier to effective, inadequate, failed or missing. Tripod codes what actually happened, not how good the control looks on paper. Recording the barriers that held is part of the analysis: they explain why the outcome was not worse.
  4. Explain every barrier that did not hold — A failed, missing or inadequate barrier gets a cause chain. Write the immediate cause (what defeated it), the precondition (the situation or state that made that likely) and the underlying cause (the organisational weakness behind it). Add more than one chain where several things went wrong at the same barrier.
  5. Classify each underlying cause against a Basic Risk Factor — Pick one of the eleven BRFs: Design, Hardware, Maintenance Management, Procedures, Error Enforcing Conditions, Housekeeping, Incompatible Goals, Communication, Organisation, Training or Defences. One factor per underlying cause.
  6. Read the profile, then export — The Basic Risk Factor profile below the canvas counts underlying causes per factor. A factor that appears behind several independent barrier failures is where the organisation is systemically weak, and where a recommendation will do the most good. Export the diagram as SVG or PNG, or save the analysis as JSON to carry on later.

Frequently asked questions

What exactly is a trio?

The three things Tripod needs to describe one step of an incident: the agent, the object and the event. The agent carries the harmful energy or potential; the object is what suffers it; the event is what happens when they meet. Drawing it this way forces you to be concrete about what actually touched what, instead of writing a vague narrative.

How many trios should an analysis have?

As many as it takes to get from the first loss of control to the final harm, and no more. Most incidents need two to five. If a trio's agent is just the previous trio's event, you are chaining correctly.

Why record barriers that worked?

Because they explain why the outcome stopped where it did. An effective barrier is evidence about what your management system does well, and it stops the analysis reading as though nothing worked. Effective barriers carry no cause chain — there is no failure to explain.

What is the difference between a precondition and an underlying cause?

A precondition is the state or situation that made the immediate cause likely — time pressure, fatigue, a crew running short, an unclear instruction. An underlying cause is the organisational decision or omission that allowed that state to exist, such as a procedure that never specified minimum manning. Preconditions describe the moment; underlying causes describe the system.

What are the eleven Basic Risk Factors?

Design, Hardware, Maintenance Management, Procedures, Error Enforcing Conditions, Housekeeping, Incompatible Goals, Communication, Organisation, Training and Defences. They are the standard Tripod set, and classifying underlying causes against them is what turns a single investigation into data you can compare across incidents.

Does anything leave my device?

No. The analysis is built and drawn in your browser and saved to this device's local storage. There is no account, no upload and no server, and the tool works offline — which matters when the incident data is confidential.

Tips

Related tools

← Browse all Caspian Office tools