
I spent a week assuming my bank was still deciding. It had decided on day one — it just never told me, and the app kept insisting otherwise.
You submit something, and nothing happens for so long you wonder whether nothing is the answer.
Here's mine. I applied for a balance transfer in my banking app. Enter the amount, add the other card, confirm. Then silence. A week later I called. It had been auto-rejected under a rule nobody mentioned — you can't transfer more than half your available limit. Fine, rules exist. What I couldn't let go of wasn't the rejection: while the agent explained it on the phone, my screen still said submitted. Two versions of reality, and I was the only one holding both.
The Insight: Silence Is an Error State — Just an Undesigned One
We treat error states as a writing problem — the friendly 404, the red text under a form field. That half gets reviewed. The hard half produces no words.
In 1985, Ed Hutchins, Jim Hollan and Don Norman named what goes missing: the gulf of evaluation — the effort of working out what a system is doing, and whether it did what you asked. Silent failure is that gulf at infinite width — but my bank did something their idea doesn't stretch to. The screen wasn't hard to read. It was wrong.
Sidney Dekker and David Woods have the sharper phrase: "wrong, strong, and silent" automation — a system that can't tell whether its model of the world is the world it's in. They study fatal aviation accidents; carrying the phrase to a banking app is my leap, not theirs.
Real-World Lens: When the Record and the Screen Disagree
The Post Office and Horizon (UK)
For two decades, Horizon showed shortfalls in Post Office branches that the public inquiry later called illusory — and the organisation treated its output as ground truth anyway. Sir Wyn Williams' first volume, published July 2025, says the organisation "maintained the fiction that its data was always accurate."
Horizon isn't my story scaled up. Postmasters were prosecuted on the strength of those shortfalls, and much of what made that possible was legal: a presumption that computer evidence is right unless you disprove it. That fiction was maintained; mine was just unowned. But the divergence is the same: a record saying one thing, an institution acting on it, one person holding both.

A phone contract in Austria (EU)
The law is catching up — though I'd like to know what the principles applied sounds like on a helpline. A woman was refused a mobile contract because an automated credit score said no. She asked why; the agency called its method a trade secret. In February 2025 the EU's top court disagreed: the agency must tell her the principles applied, concretely enough to know what would have changed the answer. Not the algorithm — the reason.

Under the Hood
Three things stacked up in my week, worth keeping apart. The sorting is mine, not a framework:
What broke | What I was owed | What I got | Who should own it |
|---|---|---|---|
The rule | Named before I applied | Told after I called | Whoever sets the rule |
The outcome | Sent when it happened | Nothing | Whoever sends the messages |
The screen | Updated to match the record | "Submitted" | Whoever syncs the screen |
Only the third is exotic. The first two are work nobody was assigned.
The objection to that is real. In the UK it can be a criminal offence for a bank to tell you it filed a suspicious-activity report, where that would prejudice an investigation. And publish an exact threshold, the worry goes, and people engineer applications just under it — serious for a fraud control, thin for a limit like mine.
Nor should everything reach you. In intensive care, studies put false clinical alarms anywhere between 72% and 99%, and staff stop hearing them. The job isn't to surface every failure — only the ones that change what someone can do next.
“Withholding the threshold is a policy. Where nothing forbids it, withholding the outcome is a failure.”
India's central bank priced that silence: since 2019 a failed retail payment must reverse itself on a clock, and every day it doesn't costs the provider ₹100, credited "suo moto, without waiting for a complaint or claim." That's a door of a kind: a way back in rather than a dead end. It tells you nothing, though — it just fixes things before you ask.
So What?
I only know one bank's version of this. But it's cheap to look for: somewhere in what you run, there's a moment where the system knows something the customer would act on, and doesn't say it. Ask what reaches them when it happens. And if it turns out to be wrong, ask whether putting it right starts with them proving it.
A service can't always tell you why. It can almost always tell you that it said no.
Reply and tell me: when did a service last leave you guessing — and what was the screen saying?
Next Wednesday: Why is it asking me this again? — the form that demands what the service already knows, and what that reveals about who it was built for.
If someone forwarded this to you: The Listening Loop is one invisible piece of service design, pulled apart every Wednesday.
See you next week.
Go deeper: The Design of Everyday Things, Don Norman — the accessible route into the gulf of evaluation, and the book that explains why you keep blaming yourself for doors.
Sources:
