Surreal illustration of agile safety with software code and construction symbolism.

Agile Safety: How to Build Safety-Critical Systems in a Fast-Moving World

"Discover how safety documentation adapts to agile development, ensuring both speed and safety in creating critical systems."


In today's rapidly evolving technological landscape, Agile methodologies have become increasingly popular for software development. However, when it comes to safety-critical systems—those where failure could result in significant harm or loss—the traditional, heavyweight documentation approaches often clash with Agile's emphasis on flexibility and speed. This creates a challenge: how do we ensure safety without sacrificing the responsiveness and efficiency that Agile promises?

Traditionally, safety-critical systems rely on extensive documentation to meticulously detail every aspect of the system's design, development, and testing. While thorough, this approach can be slow and cumbersome, making it difficult to adapt to changing requirements or incorporate new technologies quickly. Agile methods, on the other hand, prioritize working software over comprehensive documentation, continuous delivery, and close collaboration.

The key to bridging this gap lies in adapting safety documentation to fit within the Agile framework. This means finding ways to create documentation that is lightweight, focused, and integrated directly into the development process. The goal is to improve communication, enhance the safety culture, and maintain—or even improve—the overall safety assurance of the system without slowing down the development team. The question then is, how do you strike the perfect balance between thoroughness and agility to ensure safety in every sprint?

AI Search Multiple angles on this topic

Psychological Safety as the Foundation of Agile

Psychological safety is widely recognized as a precondition for agile to work at all, with HBR reporting that agile fails without it and offering five practical ways to increase psychological safety on collaborative teams. The safety check is likewise a critical practice of the agile retrospective, because before a team can reflect on the past, everyone participating must feel comfortable sharing information, and a single unsafe individual represents the most critical data in the room. Beyond team culture, the Agile Safety Plan addresses process-level safety by forcing the applicant to be specific about the safety process, which enables the certification body to be proactive and plan its work around the applicant's schedule.

Where Standards and Agility Collide

A core limitation of the standard approach is that safety standards tend to be prescriptive rather than goal-oriented, which means either agile must be adapted to the standards or the standards must be adapted to agile. Companies doing agile development for safety-critical work still need to cover the same hazard mitigation, documentation, and regulatory compliance activities they always have, and adopting an agile approach is challenging. Products with safety-critical aspects can find that their safety-critical parts significantly limit the potential speed-up from agile methods, even in the non-safety-critical parts. Agile adaptations can nonetheless be performed across all lifecycle parts, including SafeScrum and DevOps approaches, and the plan can incorporate an MVP approach that clarifies how MVP certification requirements relate to the system's certification.

Origins of the Agile Safety Plan

The agile safety plan concept was introduced with a brief overview of its history, along with definitions of key terms for developing and implementing strategies to achieve functional safety. A defining feature of the concept is that it forces the applicant to be specific about the safety process, enabling the certification body to be proactive and to plan its work according to the applicant's schedule. Related foundational work introduced the idea of safety stories as a new concept in agile development. For organizations combining agile and safety, certain prerequisites must be met for the approach to be suitable, beginning with backlog preparation in which the product owner prioritizes coherent user stories.

Bridging the Gap: Agile Safety Documentation in Practice

Surreal illustration of agile safety with software code and construction symbolism.

The adaptation of safety documentation within Agile frameworks involves several key strategies designed to maintain rigorous safety standards while embracing flexibility. The core approach centers on introducing specific documentation patterns tailored for Agile environments, such as safety epics, safety stories, and agile safety plans. These components ensure that safety considerations are integral at every stage of development, from initial planning to iterative execution.

One effective method is the use of 'safety epics' to define high-level safety requirements. These are broad objectives crafted collaboratively between users and developers, setting the overarching safety goals for the system. 'Safety stories' then break down these epics into smaller, actionable items that can be addressed within a single sprint. This approach ensures that every development cycle includes specific, manageable tasks related to safety. The integration of Systems-Theoretic Processes Analysis (STPA) enhances these processes, ensuring thorough analysis and risk management throughout the development lifecycle.

To maximize the effectiveness of Agile safety documentation, consider the following points:
  • Focus on Clarity: Ensure that all safety documentation is clear, concise, and easily understandable by all team members.
  • Integrate into Workflow: Incorporate safety tasks directly into the sprint backlog to make them a natural part of the development process.
  • Encourage Collaboration: Foster open communication between developers, safety experts, and stakeholders to address safety concerns proactively.
  • Regular Review: Continuously review and update safety documentation to reflect changes in the system or its environment.
AI Search Multiple angles on this topic

SafeScrum and the Agile Safety Case

Recent research into agile practices for developing safety systems centers on SafeScrum, Scrum, the safety case, and the IEC 61508 standard series. Studies examine how to implement safety-critical design processes within an agile-based process and how to meet IEC 61508 series requirements in an agile project. The research also identifies specific things to check when assessing the process, giving practitioners a concrete checklist for reconciling agile development with safety certification.

When Safety Is Overlooked

A frequent criticism of agile is that safety is rarely or ever mentioned when discussing the methodology, even though agility requires safety. Observers note that companies with a safety problem typically also have a transparency problem, and vice versa, meaning the two failures reinforce each other. The agile safety case responds to this gap by forcing the applicant to be specific about the quality and safety process alongside technical safety aspects, which enables certification to proceed in parallel with development and lets the certification body evaluate current information at any point in time.

Comparing Culture and Traceability Levers

On the cultural side, agile methods are seen as actively encouraging psychological safety, with project leaders playing an instrumental role in establishing an atmosphere conducive to it and paving the way for innovative sparks within their teams. On the engineering side, however, managing traceability in an agile, safety-critical development environment highlights the contrast between agile methodologies and traceability requirements, prompting teams to adopt application lifecycle management tools such as Codebeamer ALM. Together these two levers show that effective agile safety depends on both human factors and disciplined tooling.

Another innovative approach is the implementation of an 'agile safety plan,' which provides a high-level overview of the safety assurance process. This plan outlines the key activities, responsibilities, and timelines for ensuring safety throughout the project. Unlike traditional safety plans, the agile safety plan is designed to be flexible and adaptable, allowing it to evolve as the project progresses. Continuous updates and collaborative reviews ensure that the safety plan remains relevant and effective.

The Future of Agile Safety

The journey to integrate safety documentation into Agile development is ongoing, but the principles of adaptation, integration, and collaboration provide a solid foundation. By embracing these strategies, organizations can build safety-critical systems that are not only robust and reliable but also responsive to change and innovative in their design. The key is to view safety as an integral part of the development process, rather than an afterthought, ensuring that safety and agility can coexist harmoniously.

AI Search Multiple angles on this topic

Expert Views on Verification and Analysis

Expert commentary on agile development of safety-critical products draws on the opinions of bodies such as AAMI and the ESE when considering how to test safety-relevant products in agile processes. Practitioners can learn from ISTQB guidance, and approaches such as static code analysis and hardware-in-the-loop testing are discussed as verification tools that fit agile workflows. A complementary method performs safety analysis directly from user stories in an agile setting, using a generic hazards list combined with FMEA as the chosen analysis technique.

Toward Continuous, Traceable Assurance

A promising frontier is leveraging traceability to visualize and analyze changes as they occur in safety-critical systems, allowing teams to mitigate potential hazards while supporting greater agility. In automotive contexts, the V-model rigidity typically associated with ISO 26262 can clash with agile's iterative and flexible nature, so ensuring functional safety in an agile environment requires careful consideration and adaptation of traditional safety practices. Industry efforts are responding with workshops aimed at project and safety managers, safety engineers, and developers who want to combine the agile development mentality with the key principles of safe development and functional safety.

Systemic Tension Between Speed and Rigor

For organizations moving to agile processes for safety-related activities, there can be significant challenges to overcome, arising because agile emphasizes delivering results and rapid change over processes, tools, documentation, and plans. This systemic tension is being addressed through techniques such as safety envelopes, operational modeling, and incremental or pilot implementation. These approaches show how agile concepts are being adapted in challenging fields to transform safety assurance rather than abandon it.

Case Studies Across Cultures and Teams

Practical, real-world case studies provide solid grounding for agile safety work while emphasizing the critical cultural values necessary for agile to flourish. One body of case research documents how agile and plan-driven development can be meshed within safety-critical software projects. An exploratory study of scrum in a 40-person development organization distributed between Norway and Malaysia reports that scrum practices were successfully applied, for example using teleconferencing and web cameras for daily scrum meetings across the distributed team.

About this Article -

Written with AI assistance from published research, and reviewed by the Mystum team. See our About page for more information.

This article is based on research published under:

DOI-LINK: 10.1145/3120459.3120482, Alternate LINK

Title: A Study Of Safety Documentation In A Scrum Development Process

Journal: Proceedings of the XP2017 Scientific Workshops

Publisher: ACM

Authors: Yang Wang, Ivan Bogicevic, Stefan Wagner

Published: 2017-05-22

Everything You Need To Know

1

What does "Agile safety" mean in the context of developing safety-critical systems, and how does it differ from traditional approaches?

Agile safety adapts safety documentation to fit within the Agile framework. It focuses on creating documentation that is lightweight and integrated directly into the development process. This improves communication, enhances safety culture, and maintains overall safety assurance without slowing down the development team. This includes safety epics, safety stories, and agile safety plans to integrate safety considerations into every stage of the development.

2

What are "safety epics" and "safety stories," and how do they contribute to integrating safety considerations into Agile development sprints?

Safety epics define high-level safety requirements collaboratively between users and developers. They set the overarching safety goals for a system. Safety stories break down these epics into smaller, actionable items that can be addressed within a single sprint. This approach ensures every development cycle includes manageable tasks related to safety. The use of Systems-Theoretic Processes Analysis (STPA) enhances these processes, ensuring thorough analysis and risk management throughout the development lifecycle.

3

How does an "agile safety plan" differ from a traditional safety plan, and what makes it more suitable for fast-paced Agile projects?

An agile safety plan provides a high-level overview of the safety assurance process. It outlines key activities, responsibilities, and timelines for ensuring safety throughout the project. Unlike traditional safety plans, it is designed to be flexible and adaptable, evolving as the project progresses. Continuous updates and collaborative reviews ensure the safety plan remains relevant and effective. A traditional safety plan is slow and cumbersome, making it difficult to adapt to changing requirements or incorporate new technologies quickly.

4

What are some best practices for implementing Agile safety documentation to ensure it is effective and well-integrated into the development workflow?

To maximize effectiveness, safety documentation should be clear, concise, and easily understandable by all team members. Integrate safety tasks directly into the sprint backlog to make them a natural part of the development process. Foster open communication between developers, safety experts, and stakeholders to address safety concerns proactively. Documentation should be reviewed and updated to reflect changes in the system or its environment.

5

What are the key challenges in using Agile methodologies for safety-critical systems, and how does "Agile safety" help address these challenges?

Agile methodologies prioritize working software over comprehensive documentation, continuous delivery, and close collaboration. However, safety-critical systems traditionally rely on extensive documentation to meticulously detail every aspect of the system's design, development, and testing which can be slow and difficult to adapt to. Agile safety bridges this gap by adapting documentation to fit within the Agile framework, focusing on lightweight, integrated documentation to improve communication, enhance safety culture, and maintain safety assurance.

Newsletter Subscribe

Subscribe to get the latest articles and insights directly in your inbox.