ESSAY · FAILURE · RISK · INSTITUTIONS
The deepest problem with advice to “take risks” is that risk is not evenly priced. Before asking whether someone is brave enough to fail, ask what failure is permitted to mean about them.
Joyce DiDonato has described an earlier stage of her singing in language that is valuable precisely because it is technical rather than inspirational. She says she “was really good at forcing” her voice. She used tongue tension to make the sound happen. She describes resistance, pressure, and force, then describes the long reversal: roughly a year to release the muscular habit, another period learning to connect the breath, and still more time learning to trust the process rather than returning to pressure under nerves.
The story is easy to sentimentalize. One could turn it into a lesson about letting go, trusting oneself, or discovering authenticity. But the more useful reading begins with a harder question: what did the forcing buy?
It bought certainty. Or, more exactly, it bought the short-term sensation of certainty. Press, tighten, control the mechanism, and reduce the probability that the public result will escape command. In a field where an unstable top note, a cracked phrase, or an ill-chosen audition can become evidence about readiness, the temptation is rational. If error is expensive, the body learns to insure against error. The insurance premium is force.
The trouble is that insurance policies reorganize behavior. A system optimized to prevent one kind of loss may narrow the very range that mature performance requires. The singer can become reliable in a defensive sense while losing resonance, flexibility, ease, and the capacity to respond freely to the room. The technique solves the problem the court has made urgent and, in solving it, creates another problem inside the person.
This is the starting point for what I call a failure budget: the finite, survivable capacity to be wrong in public without the error becoming annihilating evidence about the person. A failure budget is not confidence, optimism, resilience, or a positive attitude toward mistakes. It is a material and social condition. It is the amount of error a person can absorb before livelihood, belonging, reputation, safety, or future possibility begins to collapse.
Perfection as insurance
Perfectionism is often described as a private pathology: the anxious person sets impossible standards, fears mistakes, and suffers because they cannot accept ordinary human imperfection. That account captures something real but misses the political economy of the fear. Sometimes perfectionism is not a distorted response to a forgiving world. Sometimes it is an intelligent response to a punishing one.
Research on perfectionism already contains the conceptual pieces for this distinction. Randy Frost and his colleagues identified concern over mistakes as a central dimension of perfectionism. Paul Hewitt and Gordon Flett distinguished self-oriented perfectionism from socially prescribed perfectionism: the felt conviction that others demand perfection and that acceptance depends upon meeting those demands. The important shift is from taste to consequence. A high standard becomes coercive when the person believes that failure will alter how others classify them.
Under those conditions, perfectionism functions as risk management. The graduate student overprepares because one visibly weak performance may be interpreted as evidence that admission was a mistake. The junior employee edits the message six times because ambiguity may be read as incompetence. The new manager scripts the conversation because one clumsy sentence may become evidence that they cannot lead. The precarious artist stays inside the repertoire that already works because experimentation can look exactly like decline before anyone knows what the experiment was.
This does not mean every perfectionist inhabits a harsh environment, or that self-imposed standards are never irrational. It means that a serious account has to separate two questions: how much threat does the person perceive, and how much threat does the environment actually impose? A person can overestimate the punishment gradient. An institution can also create a punishment gradient steep enough that hypervigilance becomes adaptive.
The distinction matters because the usual advice—be less afraid of failure—may be psychologically sound and structurally obtuse. If a mistake can cost housing, promotion, professional standing, immigration security, medical access, or membership in a field, the problem is not solved by teaching the person to feel differently about error. The world must also change what error is allowed to do.
Who gets to bomb?
DiDonato supplies the decisive boundary condition herself. Reflecting on risk in a role she had already mastered publicly, she writes: “I am safe because the whole world knows I can sing Sesto.” The sentence should stop any attempt to turn her story into a universal sermon about courage.
She is naming reputational slack. The same unstable night can mean two different things depending on what the surrounding world already believes. For an established performer with a long record of excellence, a failure can be interpreted as variance: an unusual event within a known distribution. For an unknown performer, the same failure may become the distribution. There is no reservoir of prior evidence large enough to contain the anomaly, so the anomaly becomes the person.
This is what a failure budget changes. It does not make failure painless. It changes the scale on which failure is interpreted. Reputation, money, time, alternative opportunities, strong relationships, contractual protection, institutional advocates, and multiple routes back into the field can turn an error from a terminal judgment into expensive information. The person still pays. The point is that the payment does not liquidate the future.
“Who gets to bomb?” is therefore not a comic question. It asks who can produce a bad result in public and remain socially continuous with the person they were before it happened. Who gets an off night rather than a revelation of incompetence? Who gets an experiment rather than a failure of judgment? Who gets eccentricity rather than instability? Who gets a learning curve rather than proof they were never qualified?
The answers are rarely distributed evenly. Status matters. Money matters. Rank matters. Race, gender, disability, accent, class, age, and institutional belonging can all alter how rapidly an observer generalizes from a local error to a global judgment. Some people receive individualized mistakes. Others receive category-confirming mistakes. Some are read generously because the institution has already invested in their future. Others are read narrowly because the institution has not imagined a future for them yet.
The budget is material
The word budget is intentionally material. A budget is not a mood. It is a finite reserve that can be spent, depleted, replenished, borrowed against, or destroyed. Failure behaves similarly. A person with savings can survive a bad quarter differently from a person living at the edge of rent. A tenured professor can attempt an unfashionable line of inquiry differently from an adjunct whose contract is renewed term by term. A famous artist can abandon a successful style differently from an unknown artist still trying to become legible to a market.
Pierre Bourdieu’s account of economic, cultural, and social capital gives this reserve a useful grammar. Capital is accumulated history. It changes not only what a person can acquire but how long they can remain in motion after something goes wrong. Economic capital can buy time. Cultural capital can make an unconventional choice intelligible to gatekeepers. Social capital can produce advocates, introductions, second hearings, and alternate routes. Reputational capital can keep one error from rewriting the entire record.
A failure budget therefore has at least two sides: buffers and exposures. Buffers include money, time, patronage, contractual protection, tenure-like security, audience trust, network redundancy, schedule autonomy, strong private relationships, and credible recourse. Exposures include debt, time scarcity, precarious employment, stigma vulnerability, retaliation risk, bodily fragility, dependence on a single gatekeeper, and documentary systems that turn local error into permanent evidence.
The same nominal mistake means something different on two different ledgers. Missing a deadline is not identical for the worker whose competence is already trusted and the worker whose legitimacy is still under review. Taking an artistic detour is not identical for the performer with multiple presenters and the performer whose only contract depends on one institution. Publicly revising an opinion is not identical for the person whose flexibility will be praised and the person whose change will confirm stereotypes about unreliability.
This is why stories of reinvention so easily become hagiography. Biography compresses the ledger. It remembers the courageous pivot and forgets the savings account, the patron, the spouse, the established audience, the institutional credential, the mentor, the secure passport, the health insurance, the second venue, the reputation large enough to survive an ugly transitional period. None of these conditions erases personal discipline. They explain how discipline had somewhere to operate.
When error becomes identity
The central danger is not error itself. It is inferential escalation: the speed with which an event becomes a story about the person who produced it.
Erving Goffman’s work on stigma remains useful because it shows how a local attribute can reorganize the observer’s interpretation of the whole person. Once an identity is spoiled, subsequent information is read through the spoiled category. James C. Scott’s work on legibility adds an institutional dimension: systems prefer simplified objects they can classify and govern. A complex person becomes easier to process once an error is converted into a stable type.
Modern record systems intensify this temptation. The performance review, transcript, dashboard, incident report, customer rating, audition file, complaint, disciplinary note, or searchable digital trace can extend the life of an event beyond the context in which it occurred. Recordkeeping can protect people from institutional amnesia and concealment; it can also prevent error from decaying. A moment that should have become history remains retrievable as present evidence.
The problem is not documentation in itself. The problem is the absence of a theory of evidentiary scope. What is this record authorized to prove? For how long? To whom? Under what conditions may it be reinterpreted? Does a failed experiment remain evidence of current capacity five years later? Does an early-career mistake remain admissible after demonstrated change? Does vulnerability disclosed in a learning context become evidence in an employment context? Institutions often record before answering these questions.
A person who knows every error may become durable evidence behaves differently from a person whose errors can decay. They predefend. They overprepare. They choose safer problems. They conceal uncertainty. They wait until an idea is defensible before sharing it. They learn to produce polished competence rather than visible learning.
The institution may then mistake this narrowing for professionalism.
Psychological safety is not enough
Amy Edmondson’s work on psychological safety gives a clean empirical bridge between interpersonal climate and learning behavior. Teams learn differently when members believe they can ask questions, admit mistakes, seek help, and take interpersonal risks without suffering humiliation or career damage. This matters because it reframes error as a system variable rather than a private weakness.
But psychological safety can become too easy a phrase if it remains at the level of atmosphere. A room can feel warm and still maintain punitive record systems. A leader can invite candor while retaining unilateral power to reinterpret disclosure later. A team can say failure is welcome while promotion decisions quietly reward the people whose experiments never became visible failures.
A genuine failure budget requires more than the belief that one can take interpersonal risk. It requires reasons for that belief to be rational. Protection must exist outside mood. The institution has to change the architecture through which mistakes acquire consequence.
This is the difference between kindness and recourse. Kindness depends on who is in the room. Recourse survives the room. Kindness can interpret a mistake generously. Recourse gives the person a defined way to contest an ungenerous interpretation. Kindness may create temporary safety. Governance makes some forms of safety durable against personnel change, panic, conflict, and memory.
How to build a failure budget
An institution that genuinely wants experimentation has to distinguish learning from production. It cannot expose every draft to the same evidentiary regime as final work. It cannot invite exploratory behavior while preserving the right to treat the artifacts of exploration as proof of incompetence.
The first design principle is bounded evaluation. Continuous judgment produces continuous self-defense. Serious systems need explicit windows in which evaluation occurs and other spaces in which people can practice, test, revise, and ask without every movement becoming dossier material. Standards can remain high inside the judgment window. The point is that judgment does not colonize the entire environment.
The second is protected rehearsal. A prototype, draft, mock hearing, simulation, practice review, learning clinic, or early design session should have explicit evidentiary limits. People need to know whether an error is being observed for formation or for adjudication. When those two functions are collapsed, learning becomes performance.
The third is funded recourse. If a mistake or disputed judgment can produce material consequences, the person must have an intelligible, affordable, timely way to contest the interpretation. Recourse that exists only formally but requires extraordinary time, money, status, or political courage is not a meaningful buffer.
The fourth is non-retaliation. An institution cannot claim to want truth if speaking truth predictably worsens the speaker’s position. Retaliation includes more than dismissal. Surveillance, exclusion from opportunities, reputational labeling, sudden scrutiny, social freezing, and the quiet reclassification of a person as difficult can all teach a system to stop reporting what it knows.
The fifth is documentary restraint. Some records are essential. Some records are dangerous precisely because they outlive the context that gave them meaning. Institutions need rules for what is recorded, who may access it, what downstream inferences are authorized, and when evidence should decay. Permanent memory is not the same as accountability.
The sixth is inference discipline. A disclosed struggle should narrow the inference to the problem actually observed, not widen it into a theory of the person. One failed presentation is evidence about one presentation unless further evidence justifies a larger conclusion. One request for help is not evidence of generalized incapacity. One period of illness is not a moral category. This sounds obvious until one watches institutions reason from files.
These protections are not a permission slip for carelessness. In high-stakes domains, the need for rehearsal is stronger precisely because production cannot tolerate certain kinds of failure. Aviation, medicine, law, engineering, and financial systems do not become humane by lowering the consequences of dangerous production errors. They become safer by relocating learning into simulations, protected investigation, peer review, redundant systems, and procedures designed to surface weak signals before catastrophe. The right to experiment is bounded by the duty not to make other people absorb unchosen risk.
The counterfeit innovation culture
Organizations often want the aesthetic of experimentation without paying for its protection. They say “fail fast” while increasing surveillance. They praise learning while making performance records more permanent. They celebrate candor while treating difficult disclosures as evidence of poor judgment. They ask people to take risks and then reward those whose risks succeeded quickly enough to look inevitable.
This is not a failure budget. It is a refined court.
The counterfeit works because the language is correct. Experimentation does require failure. Learning does require candor. Innovation does require uncertainty. The lie appears in the asymmetry between rhetoric and consequence. The institution invites behavior that it remains structurally prepared to punish.
Dashboards can intensify the contradiction. Once exploratory work is continuously translated into comparative metrics, people learn quickly which kinds of deviation will remain legible as experiment and which will look like underperformance. The metric may have been designed for learning; if it also allocates promotion, prestige, security, or access, the learner is rational to optimize the metric rather than the underlying practice.
The institutional question is therefore not whether leaders say failure is allowed. It is what happens after a visible failure. Who explains it? Who records it? Who can contest the explanation? How long does the record travel? Does the error shrink with time and contrary evidence, or does it become a permanent interpretive lens? Are people promoted after intelligent failed experiments, or only after experiments that happened to work?
A culture is what its punishment gradients teach, not what its values statement announces.
Range instead of flawlessness
Return to the voice. DiDonato’s long technical reorganization did not replace discipline with spontaneity. It changed the mechanism of discipline. Preparation remained. Technique became more exact, not less. What diminished was the need to guarantee the result through force.
That distinction suggests a better account of excellence. Flawlessness is attractive to institutions because it is easy to evaluate. Range is harder. Range is the capacity to remain in relation when conditions change: when the room is unfamiliar, the body is tired, the problem is new, the first attempt fails, the audience misreads, or the available script no longer fits.
Range requires standards, but it also requires survivable variance. A system that punishes every deviation will produce people who become excellent at reproducing what has already been certified. It may produce routine competence and call the result maturity. What it will struggle to produce is adaptive expertise: the capacity to change method without losing integrity when circumstances change.
This is why a failure budget is not opposed to high standards. It is one of the infrastructures that makes high standards capable of producing range rather than fear. A singer needs enough safety to stop forcing. A student needs enough safety to ask the malformed question. A scientist needs enough safety to report the failed hypothesis. A worker needs enough safety to surface the weak signal before it becomes an incident. An institution needs enough safety to discover that one of its own assumptions was wrong.
None of this abolishes consequence. A finite budget can be exhausted. Patterns matter. Negligence is not experimentation. Harm to others cannot be laundered as learning. The point is precisely to make consequence more intelligent: proportional to the actual event, sensitive to context, open to contrary evidence, and capable of distinguishing a mistake from a person.
The moral temptation is always to conclude with courage. Be willing to risk. Do not be afraid to fail. Reinvent yourself. The ledger refuses that ending because it asks what such advice costs the person receiving it.
Before telling someone to be braver, ask what happens to them if they are wrong.
Works cited
Bourdieu, Pierre. “The Forms of Capital.” Handbook of Theory and Research for the Sociology of Education, edited by John G. Richardson, Greenwood Press, 1986, pp. 241–258.
DiDonato, Joyce. OPERA America Onstage: An Oral History with Joyce DiDonato. Interview by Marc A. Scorca, recorded 7 Dec. 2015, published 26 Aug. 2025, OPERA America.
DiDonato, Joyce. “Risk.” Joyce DiDonato, journal archive.
Edmondson, Amy C. “Psychological Safety and Learning Behavior in Work Teams.” Administrative Science Quarterly, vol. 44, no. 2, 1999, pp. 350–383.
Frost, Randy O., et al. “The Dimensions of Perfectionism.” Cognitive Therapy and Research, vol. 14, no. 5, 1990, pp. 449–468.
Goffman, Erving. Stigma: Notes on the Management of Spoiled Identity. Prentice-Hall, 1963.
Hewitt, Paul L., and Gordon L. Flett. “Perfectionism in the Self and Social Contexts: Conceptualization, Assessment, and Association with Psychopathology.” Journal of Personality and Social Psychology, vol. 60, no. 3, 1991, pp. 456–470.
Scott, James C. Seeing Like a State: How Certain Schemes to Improve the Human Condition Have Failed. Yale University Press, 1998.