011 min
A mode error on the approach to San Francisco
On 6 July 2013, Asiana Airlines flight 214, a Boeing 777, was on its final approach to San Francisco International Airport. The pilot flying was a trainee captain with 33 hours on the 777. An instructor pilot sat beside him, and a third pilot watched from the jump seat.
High on the approach, the pilot flying selected an autopilot mode called flight level change, shown on the panel as FLCH SPD. The airplane was below the altitude set on the panel, so the mode started a climb. To stop the climb, the pilot disconnected the autopilot and pulled the thrust levers back to idle.
That one movement switched the autothrottle into a mode called HOLD, in which it does not control airspeed. The autothrottle is the system that sets engine power to hold a chosen speed. None of the three pilots noticed the change. All three believed the autothrottle was still holding the speed, as it normally does.
The airplane slowed and sank below the glidepath. It hit the seawall short of runway 28L. Three of the 291 passengers died.
Nothing on the airplane failed. The pilot pulled the levers he meant to pull. The action was right for the mode the crew believed the autothrottle was in, and wrong for the mode it was really in. That gap between belief and fact is the whole of a mode error.
023 min
How a mode error happens
The Asiana crew's slip has the same structure as a much smaller one on a keyboard. A mode is a state of a system in which the same input has a different meaning. Caps Lock is a mode: while it is on, the letter keys type capitals.
A mode error needs two things at the same time:
- The system gives one action two or more meanings, depending on its mode.
- The person's belief about the current mode is wrong.
Take away either one and the error cannot happen. A control with one meaning cannot be misread. A person who knows the current mode picks the action that fits it.
This is why mode errors are hard to catch. The person forms the right goal, picks the right action and carries it out well. Only their picture of the system's state is wrong, and that picture is the thing that would have warned them. In other words, their mental model no longer matches the machine, and nothing in the action itself shows it.
right action + wrong belief about the mode = the system reads the action differently
The same pattern appears wherever one control has more than one job:
| System | Mode the person believed | Mode it was in | What happened |
|---|---|---|---|
| vi text editor | insert | command | typed words ran as commands |
| Keyboard | Caps Lock off | Caps Lock on | the password was rejected |
| Drawing program | select tool | pencil tool | a drag drew a line instead of moving a shape |
| Word processor | insert | overwrite | new text deleted the text after it |
| Car | drive | reverse | the car moved backwards |
| Boeing 777 autothrottle | holding speed | HOLD | the airplane slowed down |
Time and interruptions make it worse. A person who sets a mode, then takes a phone call, comes back with an older picture of the system.
Mode changes that come as a side effect
Most people picture a mode error as forgetting a mode they set on purpose. Asiana 214 shows a second route. The pilot flying never chose HOLD. Pulling the levers to idle in that kind of descent switched the autothrottle to HOLD as a side effect. The pilot's action had a goal, stopping the climb, and a second result he did not ask for, the end of automatic speed control. A mode change that comes along with another action is easy to miss, because the person is watching their goal, not the side effect.
A protection that is missing in one mode
The 777 also had a feature that should have caught the falling speed. If the autothrottle is armed but not active and the speed drops too low, the system switches itself on and adds power. Pilots call this the autothrottle wakeup. But the wakeup works in every pitch mode except two: FLCH SPD and takeoff/go-around. FLCH SPD was the mode this crew had selected. The pilot flying had seen the wakeup in training and remembered being surprised that the airplane recovered by itself. So the crew counted on a protection that, in this one mode, was not there. A rule that holds in almost every mode teaches people to expect it in all of them.
031 min
Where the term mode error comes from
Mode errors were named long before cockpits were full of automation, in early text editors. Those editors had one mode for typing text and another for giving commands, and people often typed into the wrong one.
In 1981 the cognitive scientist Donald Norman published a study of everyday slips in the journal Psychological Review. He sorted slips into three groups and placed mode errors in the first group, errors in forming the intention. His point was that in a mode error the hands do nothing wrong. The person carries out exactly the action they intended. The fault lies earlier, in how they read the situation before they acted.
In the same years, the computer scientist Larry Tesler argued strongly that the answer was to do away with modes altogether. Tesler had built text editing software without modes at Xerox PARC in the 1970s. His view became the basis of what is now called modeless design. Few interfaces reached it fully. Even the Apple Macintosh, sold as modeless, changed what a click meant when a dialog box was open.
042 min
The foot-pedal study of mode errors
If modes cannot always be removed, the next question is whether people can be helped to notice them. In 1992 Abigail Sellen, Gordon Kurtenbach and Bill Buxton at the University of Toronto tested this with vi, a Unix text editor known for causing mode errors. In normal vi, you press the i key to enter insert mode, type, and press Escape to return to the mode for moving around the file.
The team built a second version. In the pedal version, a person held a foot pedal down while typing new text and let go to move around the file. They also tested a signal on the screen: the whole screen changed colour while the editor was in insert mode. Experienced vi users and people who had never used vi did editing tasks. A second computer next to them kept interrupting with a small task, to make them lose track of the mode.
Both kinds of signal reduced mode errors. Holding the pedal worked better than the screen colour, both for reducing errors and for reducing the mental effort of changing modes.
A second experiment asked why. The team added a pedal that latched: press once for insert mode, press again to leave it, like Caps Lock. The latching pedal did not do as well as the pedal that had to be held. The authors concluded that a mode the person keeps up with their own body prevents mode errors better than a mode the system keeps for them.
The reason is simple. When the mode ends the moment you let go, you cannot forget it, because you can feel the pedal under your foot the whole time. A latching pedal, or a key like Caps Lock, stores the mode inside the machine, and the person has to remember it or look for it. Designers call a mode that lasts only while it is held a spring-loaded mode, or a quasimode. The Shift key is the everyday example. Nobody forgets that Shift is on, because they are still pressing it.
052 min
A mode error on a navy destroyer
Feeling a mode through the body works on a keyboard, and four years after Asiana a navy destroyer showed what can happen without that feeling. On 21 August 2017, the US Navy destroyer John S McCain was overtaking a tanker, the Alnic MC, in the Singapore Strait. The crew believed the ship had lost steering. In the next minutes, control of steering and thrust moved between stations on the bridge.
The two propeller throttles had been ganged, which means paired so that moving one moves the other. While thrust control was moving to a new station, the system unganged them, because each throttle had to be moved over on its own. The lee helmsman, the sailor who controls the ship's speed, was then ordered to slow down. The lee helmsman slowed the port throttle and believed the starboard one would follow, but it stayed where it was.
The NTSB concluded that when the order to slow down came, the two throttles were no longer paired, so moving only the port one left the two sides unequal. With more thrust on the starboard side, the destroyer turned to port, into the tanker's path. Ten sailors died.
When another station changes the mode
The McCain's steering was running in a backup manual mode at the time. The NTSB listed this backup manual mode as a contributing factor, because it let control of steering move to another station without anyone meaning it to. This matters for mode errors because the person at the controls did not make the change. Nothing in their own actions reminded them that the state was different. A design that lets a second person or a second station change a mode has to tell the first person, at the place where they are working.
Touch screens that hide the mode from the hand
The McCain's throttles were not levers. They were controls on a touch screen. The NTSB noted that mechanical throttles let an operator check, by sight or by feel, whether the throttles are ganged and moving together. A touch screen gives the hand no such signal. This is the foot-pedal finding again, from the other side. When the body holds or feels the state, people keep track of it. When only a screen shows it, people can miss it, even a screen that the whole team can see.
062 min
How mode errors show up in everyday software
Most mode errors in everyday software cost a few minutes, not lives, and the same software shows both the problem and the fixes.
Caps Lock. Caps Lock is a latching mode, like the latching pedal in the Toronto study. Its signal is a small light on the key or the keyboard, near the fingers and away from the eyes. People type a password, see it rejected, and only then look for the light. The login screens of macOS and Windows now warn about Caps Lock inside or beside the password field, where the person is already looking.
vi and Vim. In vi, the same letter keys type text in one mode and run commands in the other. Vim, the most widely used successor to vi, turns its showmode option on by default, while the original vi left it off. With showmode on, Vim prints a message such as -- INSERT -- on the last line of the screen. That helps, but the last line is far from the cursor, which is where the person is looking.
Drawing tools. Drawing programs have a mode for each tool: select, pencil, eraser, and more. Most change the shape of the mouse pointer to match the tool. That puts the mode at the exact spot where the person is about to click. A highlighted button at the edge of the window would be easy to ignore.
Insert and overwrite. Word processors once let the Insert key switch between adding text and typing over it. One accidental press made new typing delete the text after the cursor, with no warning. Microsoft Word now has an option to use the Insert key to control overtype mode, and that option decides whether the key can change the mode at all.
Two modes that share one display
Sometimes the two modes look almost the same. On 20 January 1992, Air Inter flight 148, an Airbus A320, crashed into high ground near Mont Sainte-Odile in France while approaching Strasbourg. French investigators found that the crew had left the autopilot in vertical speed mode when they meant to use flight path angle mode. They set 33, meaning a 3.3 degree descent. At the time, the display showed only the first two digits of a vertical speed, so 3,300 feet per minute appeared as 33. The airplane descended at 3,300 feet per minute instead of 3.3 degrees, and most of the people on board died. Afterwards, Airbus changed the display so that a vertical speed is shown as four digits, which cannot be read as an angle.
071 min
Common misreadings of mode errors
Because the person's action looks like the cause, mode errors are often explained in ways that point to the wrong fix.
Misreading: a mode error means someone was careless
After Asiana 214 it would be easy to blame one pilot. The investigation found something wider. Other Asiana pilots and instructors, interviewed after the accident, appeared to share some of the same gaps in how they understood the autothrottle. When many trained people hold the same wrong belief, the belief comes from the design and the training, not from one person's lack of care. Blaming the individual leaves the cause in place for the next crew.
Misreading: more training will fix it
Training matters, but it did not close the gap on its own. The pilot flying had finished all of the classroom and simulator training for the 777, and still told investigators he was not confident he understood the system. The NTSB's answer was to reduce the complexity of the design as well as to improve training. A mode that needs hours of study to predict will still surprise people under stress. The surer fix is a design whose behaviour is the same in every mode, or that shows its mode where people look.
082 min
Mode error vs. nearby concepts
Several nearby terms describe related failures, and naming the wrong one leads to the wrong fix.
| Concept | What goes wrong | How it differs from a mode error |
|---|---|---|
| Slip | The action is not the one the person intended | A mode error is one kind of slip. Here the action is the intended one; the person's reading of the system's state is wrong |
| Mistake | The goal or the plan itself is wrong | In a mode error the goal is right. A mistake comes from a wrong plan, so training and information fix it better than interface changes |
| Capture error | A familiar habit takes over from the intended action | In a capture error the person does the usual action instead of the intended one. In a mode error they do the intended action in the wrong state |
| Modal dialog | A window blocks all other input until it is answered | A modal dialog is visible and demands attention, so it rarely causes a mode error. Its risk is that people click through it without reading |
| Gulf of evaluation | The person cannot tell what state the system is in | A wide gulf of evaluation is the most common cause of mode errors. The gulf is the missing information about the state; the mode error is the action taken without it |
| Automation surprise | An automated system does something its operator did not expect | Often the result of a mode change the operator missed, as in Asiana 214. It is one of the costs described by the irony of automation |
091 min
How to spot mode errors in a product
Before a team can fix mode errors, it has to find them, and mode errors leave traces that can be counted.
- Undo right after a burst of input. A person types or clicks several times, then undoes all of it. They were working in the wrong mode.
- Failed logins that succeed after a key press. Password failures followed by a Caps Lock press and a successful login.
- Support tickets that say the product acted by itself. Reports that the product deleted text, typed nonsense or changed on its own often describe a mode the person did not know was on.
- Repeated Escape presses or clicks on empty space. In session recordings, people do this to force the system into a state they know before they act.
- Mode changes nobody says out loud. In cockpit and control-room reviews, a mode change on the display that no one called out or acknowledged.
103 min
Designing against mode errors
Each case in this article points to a design move. Here they are, roughly from strongest to weakest:
Remove the mode.
If a control can have one meaning, give it one meaning. Typing should type.
Make it a quasimode.
For short, frequent modes, make the person hold the mode, as with Shift or the held pedal. Letting go ends it.
Show the mode where the eyes already are.
Put the signal at the cursor, in the field, or on the control in use. This is visibility of system status applied to modes. A light at the edge of a keyboard is easy to miss.
Make the modes look different.
If two modes accept the same input, make their displays impossible to confuse, as Airbus did with the four-digit vertical speed.
Keep actions apart across modes.
If a key is harmless in one mode and destructive in another, change one of them. Then a mode error costs a moment, not a file.
Never change a mode silently as a side effect.
If moving the thrust levers ends automatic speed control, that change should be as noticeable as the movement that caused it.
Make the result easy to undo.
One-step undo turns a mode error into a small delay. It works better than a confirmation dialog, because people learn to click through confirmations.
A different approach removes the choice of mode from the person. Some cockpit designs let pilots pick the kind of descent they want, such as normal, early or emergency, and the system chooses the mode that delivers it.
When removing modes makes things worse
Modes exist for a reason. They let a small set of keys do many jobs. An expert edits fast in vi because every letter key is also a command. Removing the modes means adding menus, longer shortcuts or more buttons, and each of those has its own errors.
Quasimodes have limits too. A person cannot hold a pedal or a key through a long task, and in the Toronto study some people said they expected their foot to get tired. Holding works best for short, frequent modes. For long modes, a clear signal in the right place is the better choice.
Accessibility pulls the other way. For people who cannot press two keys at once, operating systems offer Sticky Keys, which turns Shift and the other modifier keys into latching modes. That trade is deliberate. It makes the keyboard usable, and it brings back the risk of a forgotten mode, which is why these systems show on screen which keys are latched.
So the decision for any mode is: can it go? If not, can the person hold it? If not, is it shown where they are looking, and can its mistakes be undone?
?4 questions
Questions people ask
Can a mode error happen on a phone?
Do experienced users make fewer mode errors?
What is mode confusion?
How do you test a design for mode errors?
§8 sources
Sources
Donald A. Norman, "Categorization of action slips", Psychological Review 88(1), 1981, pp. 1–15. ocw.tudelft.nl
Abigail Sellen, Gordon Kurtenbach and William Buxton, "The prevention of mode errors through sensory feedback", Human-Computer Interaction 7(2), 1992, pp. 141–164. Author's copy. billbuxton.com
National Transportation Safety Board, Descent Below Visual Glidepath and Impact With Seawall, Asiana Airlines Flight 214, Aircraft Accident Report NTSB/AAR-14/01, 2014. ntsb.gov
National Transportation Safety Board, Collision between US Navy Destroyer John S McCain and Tanker Alnic MC, Marine Accident Report NTSB/MAR-19/01, 2019. ntsb.gov
Show all 8 sourcesShow fewer sources
"Air Inter Flight 148", Wikipedia summary of the accident and the BEA investigation. en.wikipedia.org
Vim reference manual, options.txt, the 'showmode' option. vimhelp.org
Victor Riley, "Reducing Mode Errors Through Design", Avionics, 1 March 2005. aviationtoday.com
"Mode (user interface)", Wikipedia overview of modes, quasimodes and mode-error incidents. en.wikipedia.org)