Mode Error

An action that is right for the mode a person believes a system is in, but wrong for the mode it is really in.

12 min read

Reviewed by Ravi SuranaUpdated

Quick answer

~20 sec

A mode error is an unintended action in which a person does the right thing for the wrong mode. The person believes the system is in one mode, it is really in another, and the same key or lever does something they did not intend. Typing commands into a text editor in insert mode is the classic case.

011 min

A mode error on the approach to San Francisco

On 6 July 2013, Asiana Airlines flight 214, a Boeing 777, was on its final approach to San Francisco International Airport. The pilot flying was a trainee captain with 33 hours on the 777. An instructor pilot sat beside him, and a third pilot watched from the jump seat.

High on the approach, the pilot flying selected an autopilot mode called flight level change, shown on the panel as FLCH SPD. The airplane was below the altitude set on the panel, so the mode started a climb. To stop the climb, the pilot disconnected the autopilot and pulled the thrust levers back to idle.

That one movement switched the autothrottle into a mode called HOLD, in which it does not control airspeed. The autothrottle is the system that sets engine power to hold a chosen speed. None of the three pilots noticed the change. All three believed the autothrottle was still holding the speed, as it normally does.

The airplane slowed and sank below the glidepath. It hit the seawall short of runway 28L. Three of the 291 passengers died.

Nothing on the airplane failed. The pilot pulled the levers he meant to pull. The action was right for the mode the crew believed the autothrottle was in, and wrong for the mode it was really in. That gap between belief and fact is the whole of a mode error.

023 min

How a mode error happens

The Asiana crew's slip has the same structure as a much smaller one on a keyboard. A mode is a state of a system in which the same input has a different meaning. Caps Lock is a mode: while it is on, the letter keys type capitals.

A mode error needs two things at the same time:

  • The system gives one action two or more meanings, depending on its mode.
  • The person's belief about the current mode is wrong.

Take away either one and the error cannot happen. A control with one meaning cannot be misread. A person who knows the current mode picks the action that fits it.

This is why mode errors are hard to catch. The person forms the right goal, picks the right action and carries it out well. Only their picture of the system's state is wrong, and that picture is the thing that would have warned them. In other words, their mental model no longer matches the machine, and nothing in the action itself shows it.

right action + wrong belief about the mode = the system reads the action differently

The same pattern appears wherever one control has more than one job:

SystemMode the person believedMode it was inWhat happened
vi text editorinsertcommandtyped words ran as commands
KeyboardCaps Lock offCaps Lock onthe password was rejected
Drawing programselect toolpencil toola drag drew a line instead of moving a shape
Word processorinsertoverwritenew text deleted the text after it
Cardrivereversethe car moved backwards
Boeing 777 autothrottleholding speedHOLDthe airplane slowed down

Time and interruptions make it worse. A person who sets a mode, then takes a phone call, comes back with an older picture of the system.

Mode changes that come as a side effect

Most people picture a mode error as forgetting a mode they set on purpose. Asiana 214 shows a second route. The pilot flying never chose HOLD. Pulling the levers to idle in that kind of descent switched the autothrottle to HOLD as a side effect. The pilot's action had a goal, stopping the climb, and a second result he did not ask for, the end of automatic speed control. A mode change that comes along with another action is easy to miss, because the person is watching their goal, not the side effect.

A protection that is missing in one mode

The 777 also had a feature that should have caught the falling speed. If the autothrottle is armed but not active and the speed drops too low, the system switches itself on and adds power. Pilots call this the autothrottle wakeup. But the wakeup works in every pitch mode except two: FLCH SPD and takeoff/go-around. FLCH SPD was the mode this crew had selected. The pilot flying had seen the wakeup in training and remembered being surprised that the airplane recovered by itself. So the crew counted on a protection that, in this one mode, was not there. A rule that holds in almost every mode teaches people to expect it in all of them.

031 min

Where the term mode error comes from

Mode errors were named long before cockpits were full of automation, in early text editors. Those editors had one mode for typing text and another for giving commands, and people often typed into the wrong one.

In 1981 the cognitive scientist Donald Norman published a study of everyday slips in the journal Psychological Review. He sorted slips into three groups and placed mode errors in the first group, errors in forming the intention. His point was that in a mode error the hands do nothing wrong. The person carries out exactly the action they intended. The fault lies earlier, in how they read the situation before they acted.

In the same years, the computer scientist Larry Tesler argued strongly that the answer was to do away with modes altogether. Tesler had built text editing software without modes at Xerox PARC in the 1970s. His view became the basis of what is now called modeless design. Few interfaces reached it fully. Even the Apple Macintosh, sold as modeless, changed what a click meant when a dialog box was open.

042 min

The foot-pedal study of mode errors

If modes cannot always be removed, the next question is whether people can be helped to notice them. In 1992 Abigail Sellen, Gordon Kurtenbach and Bill Buxton at the University of Toronto tested this with vi, a Unix text editor known for causing mode errors. In normal vi, you press the i key to enter insert mode, type, and press Escape to return to the mode for moving around the file.

The team built a second version. In the pedal version, a person held a foot pedal down while typing new text and let go to move around the file. They also tested a signal on the screen: the whole screen changed colour while the editor was in insert mode. Experienced vi users and people who had never used vi did editing tasks. A second computer next to them kept interrupting with a small task, to make them lose track of the mode.

Both kinds of signal reduced mode errors. Holding the pedal worked better than the screen colour, both for reducing errors and for reducing the mental effort of changing modes.

A second experiment asked why. The team added a pedal that latched: press once for insert mode, press again to leave it, like Caps Lock. The latching pedal did not do as well as the pedal that had to be held. The authors concluded that a mode the person keeps up with their own body prevents mode errors better than a mode the system keeps for them.

The reason is simple. When the mode ends the moment you let go, you cannot forget it, because you can feel the pedal under your foot the whole time. A latching pedal, or a key like Caps Lock, stores the mode inside the machine, and the person has to remember it or look for it. Designers call a mode that lasts only while it is held a spring-loaded mode, or a quasimode. The Shift key is the everyday example. Nobody forgets that Shift is on, because they are still pressing it.

typingheld downmovelet go
Watch the foot. While it presses, the editor takes text; once it lifts, the mode is over, so there is nothing to forget.

052 min

A mode error on a navy destroyer

Feeling a mode through the body works on a keyboard, and four years after Asiana a navy destroyer showed what can happen without that feeling. On 21 August 2017, the US Navy destroyer John S McCain was overtaking a tanker, the Alnic MC, in the Singapore Strait. The crew believed the ship had lost steering. In the next minutes, control of steering and thrust moved between stations on the bridge.

The two propeller throttles had been ganged, which means paired so that moving one moves the other. While thrust control was moving to a new station, the system unganged them, because each throttle had to be moved over on its own. The lee helmsman, the sailor who controls the ship's speed, was then ordered to slow down. The lee helmsman slowed the port throttle and believed the starboard one would follow, but it stayed where it was.

The NTSB concluded that when the order to slow down came, the two throttles were no longer paired, so moving only the port one left the two sides unequal. With more thrust on the starboard side, the destroyer turned to port, into the tanker's path. Ten sailors died.

When another station changes the mode

The McCain's steering was running in a backup manual mode at the time. The NTSB listed this backup manual mode as a contributing factor, because it let control of steering move to another station without anyone meaning it to. This matters for mode errors because the person at the controls did not make the change. Nothing in their own actions reminded them that the state was different. A design that lets a second person or a second station change a mode has to tell the first person, at the place where they are working.

Touch screens that hide the mode from the hand

The McCain's throttles were not levers. They were controls on a touch screen. The NTSB noted that mechanical throttles let an operator check, by sight or by feel, whether the throttles are ganged and moving together. A touch screen gives the hand no such signal. This is the foot-pedal finding again, from the other side. When the body holds or feels the state, people keep track of it. When only a screen shows it, people can miss it, even a screen that the whole team can see.

throttlesportstarboardbelieveddestroyertanker
Compare the starboard row with the dashed row beneath it. The sailor's belief and the real setting were far apart, and the ship turned toward the tanker.

062 min

How mode errors show up in everyday software

Most mode errors in everyday software cost a few minutes, not lives, and the same software shows both the problem and the fixes.

Caps Lock. Caps Lock is a latching mode, like the latching pedal in the Toronto study. Its signal is a small light on the key or the keyboard, near the fingers and away from the eyes. People type a password, see it rejected, and only then look for the light. The login screens of macOS and Windows now warn about Caps Lock inside or beside the password field, where the person is already looking.

vi and Vim. In vi, the same letter keys type text in one mode and run commands in the other. Vim, the most widely used successor to vi, turns its showmode option on by default, while the original vi left it off. With showmode on, Vim prints a message such as -- INSERT -- on the last line of the screen. That helps, but the last line is far from the cursor, which is where the person is looking.

Drawing tools. Drawing programs have a mode for each tool: select, pencil, eraser, and more. Most change the shape of the mouse pointer to match the tool. That puts the mode at the exact spot where the person is about to click. A highlighted button at the edge of the window would be easy to ignore.

Insert and overwrite. Word processors once let the Insert key switch between adding text and typing over it. One accidental press made new typing delete the text after the cursor, with no warning. Microsoft Word now has an option to use the Insert key to control overtype mode, and that option decides whether the key can change the mode at all.

Two modes that share one display

Sometimes the two modes look almost the same. On 20 January 1992, Air Inter flight 148, an Airbus A320, crashed into high ground near Mont Sainte-Odile in France while approaching Strasbourg. French investigators found that the crew had left the autopilot in vertical speed mode when they meant to use flight path angle mode. They set 33, meaning a 3.3 degree descent. At the time, the display showed only the first two digits of a vertical speed, so 3,300 feet per minute appeared as 33. The airplane descended at 3,300 feet per minute instead of 3.3 degrees, and most of the people on board died. Afterwards, Airbus changed the display so that a vertical speed is shown as four digits, which cannot be read as an angle.

071 min

Common misreadings of mode errors

Because the person's action looks like the cause, mode errors are often explained in ways that point to the wrong fix.

Misreading: a mode error means someone was careless

After Asiana 214 it would be easy to blame one pilot. The investigation found something wider. Other Asiana pilots and instructors, interviewed after the accident, appeared to share some of the same gaps in how they understood the autothrottle. When many trained people hold the same wrong belief, the belief comes from the design and the training, not from one person's lack of care. Blaming the individual leaves the cause in place for the next crew.

Misreading: more training will fix it

Training matters, but it did not close the gap on its own. The pilot flying had finished all of the classroom and simulator training for the 777, and still told investigators he was not confident he understood the system. The NTSB's answer was to reduce the complexity of the design as well as to improve training. A mode that needs hours of study to predict will still surprise people under stress. The surer fix is a design whose behaviour is the same in every mode, or that shows its mode where people look.

082 min

Mode error vs. nearby concepts

Several nearby terms describe related failures, and naming the wrong one leads to the wrong fix.

ConceptWhat goes wrongHow it differs from a mode error
SlipThe action is not the one the person intendedA mode error is one kind of slip. Here the action is the intended one; the person's reading of the system's state is wrong
MistakeThe goal or the plan itself is wrongIn a mode error the goal is right. A mistake comes from a wrong plan, so training and information fix it better than interface changes
Capture errorA familiar habit takes over from the intended actionIn a capture error the person does the usual action instead of the intended one. In a mode error they do the intended action in the wrong state
Modal dialogA window blocks all other input until it is answeredA modal dialog is visible and demands attention, so it rarely causes a mode error. Its risk is that people click through it without reading
Gulf of evaluationThe person cannot tell what state the system is inA wide gulf of evaluation is the most common cause of mode errors. The gulf is the missing information about the state; the mode error is the action taken without it
Automation surpriseAn automated system does something its operator did not expectOften the result of a mode change the operator missed, as in Asiana 214. It is one of the costs described by the irony of automation

091 min

How to spot mode errors in a product

Before a team can fix mode errors, it has to find them, and mode errors leave traces that can be counted.

  • Undo right after a burst of input. A person types or clicks several times, then undoes all of it. They were working in the wrong mode.
  • Failed logins that succeed after a key press. Password failures followed by a Caps Lock press and a successful login.
  • Support tickets that say the product acted by itself. Reports that the product deleted text, typed nonsense or changed on its own often describe a mode the person did not know was on.
  • Repeated Escape presses or clicks on empty space. In session recordings, people do this to force the system into a state they know before they act.
  • Mode changes nobody says out loud. In cockpit and control-room reviews, a mode change on the display that no one called out or acknowledged.

103 min

Designing against mode errors

Each case in this article points to a design move. Here they are, roughly from strongest to weakest:

  1. Remove the mode.

    If a control can have one meaning, give it one meaning. Typing should type.

  2. Make it a quasimode.

    For short, frequent modes, make the person hold the mode, as with Shift or the held pedal. Letting go ends it.

  3. Show the mode where the eyes already are.

    Put the signal at the cursor, in the field, or on the control in use. This is visibility of system status applied to modes. A light at the edge of a keyboard is easy to miss.

  4. Make the modes look different.

    If two modes accept the same input, make their displays impossible to confuse, as Airbus did with the four-digit vertical speed.

  5. Keep actions apart across modes.

    If a key is harmless in one mode and destructive in another, change one of them. Then a mode error costs a moment, not a file.

  6. Never change a mode silently as a side effect.

    If moving the thrust levers ends automatic speed control, that change should be as noticeable as the movement that caused it.

  7. Make the result easy to undo.

    One-step undo turns a mode error into a small delay. It works better than a confirmation dialog, because people learn to click through confirmations.

A different approach removes the choice of mode from the person. Some cockpit designs let pilots pick the kind of descent they want, such as normal, early or emergency, and the system chooses the mode that delivers it.

When removing modes makes things worse

Modes exist for a reason. They let a small set of keys do many jobs. An expert edits fast in vi because every letter key is also a command. Removing the modes means adding menus, longer shortcuts or more buttons, and each of those has its own errors.

Quasimodes have limits too. A person cannot hold a pedal or a key through a long task, and in the Toronto study some people said they expected their foot to get tired. Holding works best for short, frequent modes. For long modes, a clear signal in the right place is the better choice.

Accessibility pulls the other way. For people who cannot press two keys at once, operating systems offer Sticky Keys, which turns Shift and the other modifier keys into latching modes. That trade is deliberate. It makes the keyboard usable, and it brings back the risk of a forgotten mode, which is why these systems show on screen which keys are latched.

So the decision for any mode is: can it go? If not, can the person hold it? If not, is it shown where they are looking, and can its mistakes be undone?

?4 questions

Questions people ask

Can a mode error happen on a phone?

Yes. Silent mode, airplane mode and the keyboard's number layer are all modes. A person who does not notice that the phone is on silent misses calls, because the same incoming call now makes no sound.

Do experienced users make fewer mode errors?

Not always. Mode errors are slips, and slips come from actions done without conscious thought, which is how experts work. In the Toronto pedal study, feedback reduced mode errors for experts and novices alike.

What is mode confusion?

Mode confusion is the aviation term for a crew that is unsure which automation mode is active. It is the state before a mode error: the error is the action taken while confused.

How do you test a design for mode errors?

Give people a realistic task with interruptions, as the Toronto study did. Log every action the system read differently from what the person meant, then ask which mode they believed the system was in.

§8 sources

Sources

  1. Donald A. Norman, "Categorization of action slips", Psychological Review 88(1), 1981, pp. 1–15. ocw.tudelft.nl

  2. Abigail Sellen, Gordon Kurtenbach and William Buxton, "The prevention of mode errors through sensory feedback", Human-Computer Interaction 7(2), 1992, pp. 141–164. Author's copy. billbuxton.com

  3. National Transportation Safety Board, Descent Below Visual Glidepath and Impact With Seawall, Asiana Airlines Flight 214, Aircraft Accident Report NTSB/AAR-14/01, 2014. ntsb.gov

  4. National Transportation Safety Board, Collision between US Navy Destroyer John S McCain and Tanker Alnic MC, Marine Accident Report NTSB/MAR-19/01, 2019. ntsb.gov

Show all 8 sources
  1. "Air Inter Flight 148", Wikipedia summary of the accident and the BEA investigation. en.wikipedia.org

  2. Vim reference manual, options.txt, the 'showmode' option. vimhelp.org

  3. Victor Riley, "Reducing Mode Errors Through Design", Avionics, 1 March 2005. aviationtoday.com

  4. "Mode (user interface)", Wikipedia overview of modes, quasimodes and mode-error incidents. en.wikipedia.org)

Keep reading

More from Design

All of Design
All of Design