Psychological Safety vs Trust vs Error Tolerance: 3 Questions Plant Leaders Must Answer Before They Measure Culture
Psychological safety, trust, and error tolerance answer different leadership questions. This comparison gives plant leaders a practical matrix for choosing evidence, cadence, and response without collapsing culture into one vague score.

Key takeaways
- 01Psychological safety measures whether people can raise concerns, while trust measures whether they expect a reliable response.
- 02Error tolerance must distinguish human fallibility, weak work design, and conscious disregard of a known control.
- 03A high culture score does not prove that concerns become decisions or that commitments are completed and verified.
- 04Plant leaders should use separate evidence for voice, response reliability, and post-error boundaries instead of one vague culture index.
- 05Andreza Araujo's Safety Culture: From Theory to Practice connects cultural diagnosis with observable behavior, ownership, and field evidence.
A plant leader can hear a concern, see a high score on a culture survey, and still misunderstand what the team is willing to say when a production target is at risk. Psychological safety, interpersonal trust, and tolerance for error are related, but they are not interchangeable. Treating them as one construct creates a measurement problem before it creates a culture problem.
This comparison gives EHS managers and operations leaders a decision rule. Psychological safety is the team belief that a person can speak, question, or admit uncertainty without interpersonal punishment. Trust concerns whether another person or system will act with reliability and good faith. Error tolerance concerns the boundary leaders set between learning from an unintentional failure and accepting a conscious violation. The three constructs require different evidence and different responses.
What should leaders compare before choosing a measure?
Leaders should compare the three constructs across five dimensions, namely the question being asked, the observable behavior, the time horizon, the owner of the response, and the risk of misreading the result. Psychological safety asks whether people can raise a concern. Trust asks whether they expect the response to be fair and dependable. Error tolerance asks whether the organization distinguishes human fallibility from deliberate disregard of a known control.
A survey can provide a useful signal, but it cannot settle the diagnosis on its own. Amy Edmondson's research on psychological safety is most useful when it is connected to conversations, decisions, and follow-through. James Reason's work on active and latent failures adds another test, because a leader should examine the work system that shaped an action rather than stop at the person who made it.
The practical comparison therefore uses six dimensions: definition, main evidence, leadership response, safety risk, useful cadence, and failure mode. A monthly executive review may need all three, although each should remain a separate line of inquiry. If the measures are merged into one score, a strong trust relationship can hide silence about risk, while a permissive response to mistakes can be misread as psychological safety.
For a broader explanation of the construct itself, the article on the four dimensions leaders often mix up is a useful companion. This comparison goes further by showing when that construct should not be used as a proxy for the other two.
Psychological safety: can people speak before the loss?
Psychological safety measures whether people believe they can take an interpersonal risk at work, such as challenging a decision, asking for clarification, reporting a weak control, or admitting that a task is beyond their current competence. It is a team-level condition described by Amy Edmondson, not a promise that every suggestion will be accepted or that every error will be excused.
The strongest evidence appears in moments with social cost. A supervisor can ask, “What could make this job fail?” and then observe whether the answer contains a real concern or a safe answer that protects the meeting. A maintenance planner can reject a rushed start and record why. A new contractor can question a permit without having to prove courage before the question is considered.
Psychological safety becomes visible in the interval between bad news and the leader's first response. When a leader asks for evidence, protects the speaker from ridicule, and still investigates the control weakness, the team learns that candor is useful. When the leader searches for a person to blame before understanding the exposure, the next concern is often edited before it is spoken.
That does not mean psychological safety is the same as comfort. A team can feel safe enough to speak and still lack competence, authority, or resources to solve the issue. It can also speak freely while leaders ignore the information. The measure is valuable because it identifies voice conditions, but it must be paired with evidence that concerns become decisions.
Measure psychological safety through recurring questions, observed meeting behavior, concern-to-decision traceability, and the quality of dissent during operational changes. The most important result is not a high score. It is whether a concern can travel from the front line to a control owner without losing its meaning.
Interpersonal trust: will the response be reliable?
Trust measures the expectation that another person, team, or system will act with competence, honesty, consistency, and care. A worker may feel able to speak in a meeting yet distrust the follow-through, which produces a different risk from silence. Psychological safety concerns the permission to raise the issue; trust concerns the expectation that raising it will lead to a credible response.
Trust is tested by promises that have consequences. If a plant manager says that a contractor concern will be reviewed before mobilization, the next question is whether the review occurs and whether its decision is explained. If a supervisor says that stop-work decisions will not damage a person's standing, the team watches the next stop-work event more closely than it watches the statement.
Reliability matters as much as goodwill. A leader may care deeply about safety but repeatedly miss deadlines, change priorities without explanation, or close actions without verification. The team can interpret that pattern as a lack of trustworthiness even when the leader's intention is positive. In this setting, a survey question about trust can identify a concern, but action records and observed commitments explain it.
Trust also operates between functions. EHS may trust operations to own a control, while operations may distrust EHS because previous reviews produced requirements that could not be performed in the real work sequence. The gap is not solved by another communication campaign. It requires a decision whose owner, resources, constraints, and verification method are visible to both sides.
Measure trust through commitment reliability, decision transparency, consistency across shifts, and whether leaders return to unresolved concerns. A useful review asks which promises were made, which were kept, and what changed when a promise could not be kept. That evidence is more actionable than a single trust index.
Error tolerance: where does learning stop and permissiveness begin?
Error tolerance measures how the organization responds when an action or outcome falls short of the expected standard. It should distinguish an unintentional mistake, a difficult-to-perform procedure, an inadequate design, and a conscious decision to bypass a known control. Without that distinction, leaders can punish ordinary human fallibility or excuse deliberate exposure in the name of learning.
The central question is not whether an error occurred. It is whether the person had a workable control, understood the expectation, possessed the authority and resources to follow it, and knowingly chose to disregard it. James Reason's distinction between active failures and latent conditions helps investigators keep that question open. Andreza Araujo's Sorte ou Capacidade, glossed as Luck or Capability, also supports a systemic reading of events in which the visible act is only one part of the causal path.
Error tolerance becomes dangerous when leaders use it as a blanket response. “We are learning” cannot mean that a critical safeguard may be bypassed without review, nor can “accountability” mean that retraining is the automatic answer to every deviation. A fair boundary requires evidence about intent, capability, work design, supervision, and the availability of the control at the moment of the decision.
The measurement therefore belongs in incident reviews, field verifications, and action-quality audits. Leaders should check whether teams can report a mistake early, whether investigations examine the conditions surrounding it, and whether conscious transgression receives a proportionate response. The output is not a permissiveness score. It is a clear boundary that people can understand before the next difficult decision.
For post-event application, compare this approach with the five decisions that influence reporting after an incident. The comparison helps leaders avoid treating a post-incident conversation as a general test of culture when it actually contains several separate decisions.
What does the decision matrix show?
The decision matrix shows that no construct answers all three leadership questions. Psychological safety is strongest when the concern is whether people can speak. Trust is strongest when the concern is whether commitments and responses are dependable. Error tolerance is strongest when the concern is how the organization distinguishes fallibility, system weakness, and conscious disregard of a known control.
| Dimension | Psychological safety | Interpersonal trust | Error tolerance |
|---|---|---|---|
| Core question | Can I speak or question? | Will the response be reliable? | What boundary applies after an error? |
| Best evidence | Dissent, questions, concern reporting | Kept commitments, transparent decisions | Investigation reasoning and proportional response |
| Primary owner | Team leader and team | Every role that makes commitments | Operational leader with EHS governance |
| Main risk if misread | Confusing voice with action | Confusing goodwill with reliability | Confusing learning with permissiveness |
| Useful cadence | Weekly or monthly team review | Monthly commitment review | After events and during control verification |
| Leadership response | Invite, receive, and route concerns | Make, keep, and explain commitments | Set a fair, evidence-based boundary |
The matrix is deliberately practical. A high psychological-safety result should not close an action if people report concerns but nothing changes. A high trust result should not be used to dismiss evidence that commitments are repeatedly late. A low error-tolerance result may show fear of blame, but it may also show that the boundary around deliberate control bypass is unclear.
When leaders use the matrix, they can choose a response that fits the problem. A meeting in which nobody questions a shutdown plan calls for a psychological-safety intervention. A control owner who repeatedly promises a field check and does not complete it calls for a trust and accountability intervention. A near miss followed by automatic retraining calls for an error-tolerance review that examines the work design first.
Which construct should a plant leader measure first?
A plant leader should measure psychological safety first when the organization lacks credible information from the front line. Without voice, trust and error-tolerance data are often based on polished answers, because the team has already learned which topics are safe to discuss. The first diagnostic should therefore ask where people hesitate, who receives concerns, and what happens after the concern is raised.
Measure trust next when voice exists but follow-through is weak. A team may report hazards every day while watching the same actions drift across weeks. In that case, another listening campaign adds little value. The leader should review commitments, decision rights, resource constraints, and verification evidence with the people who depend on the response.
Measure error tolerance when an incident, deviation, or failed control exposes uncertainty about the boundary between mistake and disregard. This is especially important when the organization has a strong slogan about learning but inconsistent practice after a serious event. The review should examine intent, competence, system conditions, control availability, supervision, and the consequences of the response.
Across 25+ years of executive EHS work, Andreza Araujo has treated the difference between declared culture and operated culture as a management question, not a communications exercise. Her book Safety Culture: From Theory to Practice is a useful reference for connecting diagnosis with observable behavior, ownership, and field evidence.
How can leaders combine the three without creating one vague score?
Leaders can combine the three constructs in one review without collapsing them into one score. Keep separate questions, assign a different evidence source to each, and agree in advance on the decision that follows a weak result. The review becomes useful when every line leads to a control, an owner, and a verification date.
- Start with voice. Ask which concerns were raised, which were not, and where the team experienced social cost for speaking.
- Test response reliability. Sample commitments from the previous review and check whether the promised response was completed, explained, and verified.
- Review one difficult error. Examine the work conditions, control availability, intent, supervision, and the proportionality of the response.
- Separate actions. Do not assign one generic culture action to three different findings. Voice, reliability, and response boundaries need distinct owners.
- Return to the field. Ask the people who perform the work whether the changed control is usable under normal pressure.
The sequence prevents a common leadership mistake, which is to treat a survey instrument as the intervention. Measurement only becomes management when it changes a decision. A team that sees a concern move into a visible decision trail receives stronger evidence than a team that receives another request to rate its culture.
Leaders who want a short operational routine can use a daily safety meeting designed to surface bad news, then route the evidence into the three separate questions. The meeting should not become a forced confession. It should make it easier to identify a weak control while the response is still possible.
What should the executive recommendation be?
The executive recommendation is to use psychological safety, trust, and error tolerance as a sequence of distinct management tests. Start with psychological safety to understand whether information can move. Use trust to test whether the organization responds reliably. Use error tolerance to define what happens when the expected control fails or is knowingly bypassed.
The comparison matters because each construct can look healthy while another is weak. People may speak freely but stop believing that leaders will act. They may trust a manager personally but avoid challenging a production decision. They may experience a forgiving team climate while remaining uncertain about the consequences of bypassing a critical control.
A useful dashboard therefore shows three short narratives rather than one culture number. The first records a concern that traveled from the worksite to a decision. The second records a commitment that was kept or transparently renegotiated. The third records an error review whose conclusion explains why the response was proportionate. That format gives the C-suite evidence that can be tested in the field.
Andreza Araujo's A Ilusão da Conformidade, glossed as The Illusion of Compliance, gives the final warning. A completed survey, a signed action, or a positive meeting does not prove that the operating condition changed. The leader must still ask what people can say, what they can rely on, and which boundaries the organization will defend when pressure rises.
Frequently asked questions
What is the difference between psychological safety and trust?
Is error tolerance the same as psychological safety?
Which construct should a plant leader measure first?
Can these three constructs appear on one dashboard?
How does Andreza Araujo frame culture measurement?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.