Gall's law
working simple system · complex systems from simple ones
A complex system that works is invariably found to have evolved from a simple system that worked. John Gall's 1975 corollary is the useful half: a complex system designed from scratch never works and cannot be patched into working.
In practice
The rebuild that will fix everything is specified in full, takes a year, and ships something worse than what it replaced. The version that works started as something too small to be worth specifying.
The common mistake
Using it to justify never rebuilding. Gall's claim is about how a working system is reached, not about whether the current one should survive. The replacement has to start simple. It still has to exist.
John Gall, in Systemantics in 1975: a complex system that works is invariably found to have evolved from a simple system that worked. The corollary is the part that costs people money: a complex system designed from scratch never works and cannot be made to work. You have to start over with a working simple system.
Why the ground-up rebuild fails
A working system contains an enormous amount of knowledge that is nowhere written down. Every odd condition it handles is there because that condition occurred. Every apparently pointless step is somebody's fence.
A specification written in advance contains only what the authors knew to ask about, which is the predictable part. So the rebuild handles the imagined cases well and fails on the accumulated real ones, and each of those has to be rediscovered by breaking something in production.
This is also why the replacement usually takes far longer than the original. The original grew while being used, discovering requirements at the rate they arose. The replacement has to reproduce all of them at once, before it is used by anyone.
The working version
Start with something too small to fail. One step, one customer, one report. Something that delivers value while being simple enough that it obviously works.
Grow it under real use. Each addition made because a real case demanded it. The system accumulates the same knowledge the old one had, in the same way, which is the only way that knowledge gets in.
Replace in pieces, never in one move. Strangle the old system gradually rather than swapping it. Each piece proven in use before the next.
The claim is not that systems should stay simple, since the working complex systems Gall describes are complex. It is that complexity has to be arrived at rather than specified, because most of what makes a system work is discovered rather than designed.
Concept web
Open the full webQuestions
What is Gall's law?
That a complex system which works is always found to have evolved from a simple system that worked, and that a complex system designed from scratch never works and cannot be patched into working.
Why do ground-up rewrites fail?
Because a working system encodes knowledge nobody wrote down — every odd condition it handles is there because that condition occurred. A specification contains only the predictable cases, so the rest must be rediscovered in production.
Does Gall's law mean you should never rebuild?
No. It says the replacement must start as something simple that works and grow under real use, rather than being specified in full and launched at once. Replacing in pieces is the working version.