THIS EXPLANATION
THE ROOM
ECO·26 Economics & Business 7 MIN · 8 STATIONS

Just-in-time fragility

A Socratic walk-through of just-in-time fragility — reasoned out one step at a time, not lectured.

abcdefgh
a

The question we started with

THE QUESTION #

Why does a supply chain tuned for efficiency break so badly when a single plant stops?

A supply chain running lean is usually described as one that has removed waste. That framing makes its collapse under a single failure look like an unforeseen side effect, a hidden bill arriving late. But what was removed was not only waste, and the people who removed it knew exactly what went with it. So what job was that inventory doing that nobody was paying it to do — and why does its absence turn one fire into a continental stoppage?

b

Reasoning it through

REASONING #

Ask what a pile of parts between two stages of production actually does. It lets the downstream stage keep working while the upstream one is stopped, for exactly as long as the pile lasts. A buffer holding four hours of parts buys four hours of independence between the two stages, and not one minute more.

So buffer depth is not a quantity of stock. It is a quantity of time — the interval before an upstream problem becomes a downstream problem. Drive it toward zero and you have not made the system likelier to fail; you have made every failure arrive downstream immediately.

And here is what makes this deliberate rather than accidental. In the Toyota system that consequence is not tolerated, it is the point. Inventory conceals problems: a stage quietly producing defects or breaking down is invisible while a buffer absorbs the shortfall. Remove the buffer and the problem stops the line today, visibly, and so gets fixed rather than accommodated. The stoppage is the measurement — the same bargain a shop makes when it accepts that the occasional cheap stockout is what tells it where its buffer's edge really is.

But that explains a stoppage, not a catastrophe. Why should one plant halting stop a continent? Two further things travel with lean production and are often mistaken for it. First, single sourcing: deep several-deliveries-a-day relationships are expensive per supplier, so firms keep fewer of them and many parts end up made in exactly one plant. Second, geographic and process concentration — frequent delivery needs proximity, and specialised tooling may exist nowhere else. A part made in one place with no substitute is a cut vertex in the network: there is no path around it.

Now test the account both ways against an unusually well documented case. On 1 February 1997 a fire destroyed Aisin Seiki's Kariya plant, which made the brake proportioning valve for nearly every Toyota vehicle. Toyota's assembly lines began stopping within about two days. That is the first direction confirmed, and it is the firm part of the story: the pipeline held hours of that part, not weeks, so buffer depth set the onset almost exactly.

Now the other direction. Output was largely restored within roughly a week — faster than a firm with deep buffers and arm's-length suppliers would plausibly have managed — because Aisin's drawings were shared across the supplier group and something on the order of two hundred firms improvised production on general-purpose machines. The same tight structure that had removed the buffer also supplied the recovery. So "lean equals fragile" is too crude. The invariant is a pair: buffer depth sets how long you have; substitutability sets how long you need. Lean shortens the first, and its supplier relationships can shorten or lengthen the second depending on whether anyone else can make the thing at all.

Which is why the worst shocks are those where substitutability is genuinely zero. When the missing part is a semiconductor from a fab that takes years and billions to duplicate, no goodwill improvises a replacement and the disruption runs in quarters rather than days. Estimates of vehicles not built in the 2021 chip shortage range from roughly eight to eleven million depending on who counts; the figure to lean on is not the total but the timescale, on which every account agrees.

c

The analogy

THE ANALOGY #
THE FIGURE

Think of a household that keeps no cupboard and buys each meal on the way home. It is efficient, nothing spoils, and no capital sits idle. One shut shop means no dinner tonight — not next month, tonight — because the interval between supply and need was deliberately reduced to zero.

WHERE IT BREAKS DOWN

the household has a dozen substitutable shops within walking distance, so its exposure ends at inconvenience, whereas the plant that stopped is often the only one in the world holding the tooling — and it is that missing substitute, not the empty cupboard, that turns a night's annoyance into a quarter's shortfall.

d

Clarifying the model

THE MODEL #

Three refinements.

First, the fragility is not a defect in just-in-time; it is the same property named from the other side. Tight coupling forces problems into the open and gets them fixed, and firms running it have historically had fewer disruptions, not more — paying for that with a shorter fuse when one arrives.

Second, the popular diagnosis of the 2020-22 disruptions as "too much just-in-time" is contested and probably overstated. Much of what happened was demand whiplash rather than buffer depth: automakers cancelled chip orders when the pandemic began, foundry capacity was reallocated to consumer electronics, and orders then returned all at once — the order-amplification story, which multiplies a modest change in end demand into wild swings upstream regardless of how much inventory anyone holds. How much was buffers and how much amplification is genuinely unresolved.

Third, this sits alongside two other accounts of the same property. A uniform crop field converts many independent questions into one asked everywhere at once; a machine whose two channels share a power feed has fewer independent paths than its part count suggests. Just-in-time removes independence in a third dimension — across time rather than genotype or hardware. In each case a system is only as robust as the number of genuinely independent ways it can absorb the same shock, and in each the sameness that removes them was bought deliberately because it is productive.

e

A picture of it

THE PICTURE #
Just-in-time fragility
Just-in-time fragility Read left to right as elapsed time, each entry's first line the event and the second what it tells you. The gap between the second and third entries is the whole fragility argument -- roughly two days from fire to stopped assembly is a direct readout of how much time the buffer held. The fourth and fifth entries are the counterweight: recovery was fast because a valve is a shape other machine shops can cut. The last entry is the contrast case, where nobody can improvise the missing item and the same structure yields a completely different timescale. {"generator":"mermaid-svg-renderer@3.2.1","source":"../Socrates/.diagram-cache/_src/just-in-time-fragility.md","sourceIndex":1,"sourceLine":4,"sourceHash":"cfe0c242ab73e0de0a0fe24f1ee1045f378baa37cab8b144b7f11dbc7d9f1154","diagramType":"timeline","layoutVariant":"source","repairedDuplicateIds":[],"motion":"entrance-with-reduced-motion-fallback","presentation":"editorial","attempt":1,"viewBox":{"x":0,"y":0,"width":1554,"height":636},"qa":{"passed":true,"findings":[]}} Before the fire One plant makesthe proportioningvalve for almostevery Toyota Deliveries runseveral times a dayand assemblyholds hours ofstock 1 February Fire destroys theKariya productionlines Tooling isspecialised andcannot berelocated 2 to 4 February Toyota assemblystops across mostlines The buffer isexhausted withinabout two days 4 to 6 February Drawings circulatethrough thesupplier group On the order of twohundred firmsimprovise lines ongeneral purposemachines 7 to 10 February Output restarts andthen runs abovenormal Most lost volume isrecovered over thefollowing weeks Later shocks Tohoku 2011 andthe 2021 chipshortage Where no secondmaker existsrecovery takesquarters not days

How to readRead left to right as elapsed time, each entry's first line the event and the second what it tells you. The gap between the second and third entries is the whole fragility argument — roughly two days from fire to stopped assembly is a direct readout of how much time the buffer held. The fourth and fifth entries are the counterweight: recovery was fast because a valve is a shape other machine shops can cut. The last entry is the contrast case, where nobody can improvise the missing item and the same structure yields a completely different timescale.

f

What became clearer

WHAT CLEARED #
WHAT CLEARED

Inventory between two stages is stored time — the interval before an upstream failure becomes a downstream one — and just-in-time removes it on purpose, because a problem that stops the line is a problem that gets fixed. So the sharp onset of a lean chain's collapse is not a surprise; it is the designed behaviour, arriving on a day nobody wanted it. What is not designed, and what decides whether the stoppage is a week or a year, is whether anybody else can make the missing thing. Buffer depth buys time; substitutability sets how much time you need, and the two are fixed by different decisions that firms too often treat as one.

g

Where to go next

ONWARD #
  • How firms decide which of thousands of parts deserve a second source, given that dual sourcing everything is unaffordable.
  • What a cut-vertex analysis of a bill of materials reveals that a tier-one supplier list does not.
h

Key terms

TERMS #
TermWhat it means
Decouplingthe property a buffer provides: making two stages independent for a bounded interval.
Single sourcingbuying a part from exactly one supplier, usually for coordination and volume pricing.
Cut vertexa node whose removal disconnects the network, so no alternative path exists around it.
Substitutabilitywhether another producer could make the missing item, and how fast; what sets recovery time.

Every term the collection defines is gathered in the glossary.

Nearby on the shelf

4