The Corrupting Power of Permission
In 2000, two economists studied what happened when a group of Israeli daycare centers introduced a fine for parents who picked up their children late. The hypothesis was straightforward: create a financial consequence for a behavior that was causing problems, and the behavior would decrease.
The opposite happened. Late pickups increased — and stayed elevated even after the fine was removed.
The explanation, when it came, was both simple and unsettling. Before the fine, parents operated under a social contract: being late was an imposition on the staff, and most parents felt genuine discomfort about it. The fine replaced that social contract with a transaction. Parents were no longer violating a norm — they were purchasing a service. The moral weight of the behavior evaporated, and with it the informal pressure that had been keeping it in check. The control mechanism didn't reinforce the standard. It corrupted it.
I've thought about this study many times over the course of my career, because I see versions of it play out in organizational life. The pattern is consistent: a formal control is introduced to address a problem, and the control ends up giving people permission — implicit, unintentional, but real — to be less conscientious than they were before. The requirement becomes the standard. Meeting it becomes the goal. Whatever the requirement was designed to produce recedes into the background.
Most of us have lived a version of this. Think about the last compliance training module you completed. You were given a time requirement and a passing score to achieve. You met both. Somewhere, a system recorded your completion and generated a certificate. And the organization — your employer, your regulator, whoever commissioned the training — received a signal that the compliance problem had been addressed.
But had it? The people whose behavior the training was designed to change now have permission to consider themselves trained. The organization has permission to consider the requirement fulfilled. The vendor has permission to consider the product successful. Everyone in the system is technically meeting the standard. Whether anyone's behavior has actually changed — whether the thing the certification was designed to produce has been produced — is a question the system is no longer asking, because the system got what it asked for.
I saw a version of this play out closer to my own field of practice when a large organization I worked with introduced a cross-functional committee to review promotion decisions above a certain level. The intent was sound: promotion rates had been climbing in ways that felt disconnected from both candidate merit and business need, and a more rigorous review process seemed like the right corrective.
What happened instead was familiar in retrospect. The committee was large — representative of virtually every department, which made it feel thorough and fair. But large committees diffuse accountability in ways that small ones don't. No single member felt responsible for the outcome of any given decision. The group's size made genuine deliberation unwieldy, so the committee became, in practice, a rubber stamp. And here's the part that maps most directly to the daycare study: managers who had previously been cautious about borderline promotion cases — aware that the decision was theirs to own — became more willing to advance fringe candidates once the committee existed. The control that was designed to add scrutiny ended up providing cover. Promotion rates went up, not down.
The more familiar version of this dynamic — the one most of us have lived through personally — is worth examining more closely. Compliance training is perhaps the purest organizational expression of the corrupting power of permission, because the gap between what the requirement asks for and what it's designed to produce is so legible once you name it. The requirement asks for time and a test score. What it's designed to produce is behavior change — employees who understand a policy, a regulation, or a risk well enough to act differently because of it. Those are not the same thing. And the existence of a completion metric gives every party in the system permission to pretend that they are.
This is not an argument against formal controls. It's an argument for designing them carefully — specifically, for testing any proposed control mechanism against a single question before deploying it: does this sharpen individual accountability, or does it diffuse it?
The daycare fine diffused accountability by converting a social norm into a transaction. The promotions committee diffused accountability by distributing a decision across too many people for any of them to own it. The compliance certification diffuses accountability by substituting a measurable proxy for the actual goal — and giving everyone involved permission to treat the proxy as if it were the thing itself.
Controls that sharpen accountability tend to be specific, visible, and owned by someone with skin in the game. Controls that diffuse it tend to be broad, procedural, and designed to demonstrate that something was done rather than to ensure that something was achieved. The distinction is worth examining every time an organization reaches for a new formal mechanism to address a problem that informal norms were previously managing — however imperfectly — on their own.