Skip to content
Mental Models

Margin of Safety: Build for More Than You Expect

How Big? Sizing the Margin to Your Uncertainty

A margin of safety isn't a fixed number — it's a function of how wrong you might be. The fuzzier your estimate and the wilder the domain, the fatter the buffer needs to be. Here's how to size it honestly.

13 min Updated Jun 25, 2026

By now you believe in the buffer. Lesson 1 showed you why every estimate needs a cushion; lesson 2 showed you the investor’s version — buy a dollar for fifty cents so a wrong valuation still leaves you whole. So the obvious next question, the one that’s been quietly nagging since the start, is: how big? Fifty cents on the dollar? Twenty? A safety factor of 2, or 5, or 10? A cash buffer of one month, or six?

The lazy answer is to pick a number you like and slap it on everything — “I always keep 20% slack,” “we always demand a 30% discount.” That feels disciplined. It isn’t. A fixed margin applied to every decision is like wearing the same coat to the beach and the Arctic: comfortable somewhere, fatal somewhere else. The right answer is almost embarrassingly simple to state and surprisingly hard to live by: size the margin to your uncertainty, not to your habit. The fuzzier your estimate, the wilder the domain, and the more honestly you account for how often you’re wrong, the fatter the buffer needs to be. This lesson is about doing that honestly.

Before you read — take a guess

Two teams each estimate a project will cost about €100k. Team A has built this exact thing ten times and is confident to within ±10%. Team B has never done it before and admits it could be off by ±60%. If both add the SAME 15% contingency buffer, what's wrong?

The fuzzier the estimate, the fatter the margin

Here is the principle the whole lesson hangs on: a margin should scale with the width of your error bars, not with your point estimate. Two projects can have the same expected cost and need completely different buffers, because what a margin defends against isn’t the number you expect — it’s the spread of numbers you might actually get.

A point estimate (“about €100k”) is a single dot. But reality doesn’t hand you a dot; it hands you a range. The honest version of your estimate is “€100k, give or take” — and the size of that “give or take” is the error bar. A tight error bar means the truth is almost certainly close to your dot. A wide one means the truth could be far away in either direction. The buffer’s only job is to cover the bad side of that range, so the buffer’s size is governed by the width of the range, full stop.

Watch it with two projects that look identical on paper:

ProjectExpected costError-bar width (how wrong you could be)Plausible worst caseSensible contingency margin
A — done it 10× before€100k±10%~€110k~10–15% (€10–15k)
B — first attempt, new vendor€100k±60%~€160k~50–70% (€50–70k)

Same €100k headline. Project A’s truth lives in a narrow band, so a 10–15% cushion covers the realistic overrun. Project B’s truth could land anywhere up to €160k, so a cushion under €50k is theatre — it looks like prudence while leaving you exposed to most of the range you yourself admitted was possible. If you forced both to “15% because that’s our policy,” you’d over-pad A slightly (mild waste) and under-pad B catastrophically (real risk of blowing the budget). The fixed number got both wrong, in opposite directions.

The mental move is to stop asking “what do I expect?” and start asking “how wrong could I be, and in which direction does wrong hurt?” The buffer is sized against the second question.

Info:

Point estimate vs. error bar

Your point estimate is your single best guess (€100k). Your error bar is how far the truth could realistically sit from it (±10%? ±60%?). A margin of safety is sized off the error bar, not the point estimate — because the buffer exists to cover the cases where your best guess was simply wrong.

A founder budgets two line items, each with an expected cost of €50k. Salaries are locked by contract (error bar ±2%). A first-ever marketing campaign in a new country has an error bar of ±80%. How should the contingency buffers compare?

When to use it

Reach for this every time you set a buffer, a contingency, a reserve, or a discount. Before you write the number, write down your error bar honestly — your realistic high-and-low, not your hope. Then size the margin to cover the bad end of that range, not the middle. Two estimates with the same expected value but different spreads are not the same decision, and they don’t deserve the same buffer.

Some worlds are wilder than others (fat tails)

So far we’ve treated “how wrong could I be” as a tidy ±range, symmetric and bounded. For some domains that’s roughly true. For others it’s a dangerous fiction — because in those domains the rare extreme is so large it dominates everything, and a polite ±range badly understates it. The name for this is fat tails.

A fat-tailed domain is one where rare, extreme events are far more frequent — and far more consequential — than a “mild” bell-curve intuition predicts. The tail of the distribution (the far-out, unlikely values) is “fat”: those rare events carry so much weight that they, not the average, decide the outcome. Market crashes, pandemics, viral hits, wars, earthquakes, a single lawsuit that ends a company — these live in fat-tailed worlds. One event you’ll see a few times a century swamps the thousands of ordinary days.

Contrast that with a mild (thin-tailed) domain, where outcomes cluster tightly around the average and extremes are genuinely negligible. Human height is the classic example: the average adult is around 1.7 m, and no matter how many billions of people you measure, you will never find one who is 50 metres tall, or even 3. The tail is thin — extremes barely happen and, when they do, they’re small. In a mild domain the average tells you almost everything; in a fat-tailed domain the average is a comforting lie that hides the thing that actually gets you.

FeatureMild / thin-tailed worldWild / fat-tailed world
ExampleHuman height, daily commute timeMarket returns, pandemics, viral reach, lawsuits
What dominates the totalThe typical, average caseA single rare extreme
Can one event ruin you?No — extremes are smallYes — one tail event can swamp everything
Is a ±10% error bar honest?Often, yesNo — the tail is far fatter than ±10%
How to size the marginFor the average plus a modest bandFor the tail, not the average

This is the deep tie back to lesson 1. The Hyatt walkways didn’t fail on an average day with an average crowd; they failed on the tail — the packed-house, worst-case load. The whole point of a margin of safety is that the load you didn’t predict is exactly the tail event. So in a fat-tailed domain, sizing your buffer to “a bit more than average” isn’t conservative — it’s sizing for the wrong thing entirely. You size for the tail, because in a fat-tailed world the tail is not a footnote; it’s the headline.

Warning:

Averages lie in fat-tailed worlds

“On average it’s fine” is a true and useless sentence in a fat-tailed domain. The average can be reassuring while a once-a-decade extreme is the event that actually determines whether you survive. Size the margin for the tail you’d lose to, not the average you’ll usually see.

A trader's strategy makes a small steady profit on 99% of days and is fine 'on average.' On the remaining 1% of days — market crashes — it can lose more than a year of those profits in an afternoon. What's the core mistake in calling it 'safe on average'?

Calibration: are your error bars even honest?

We’ve said “size the margin to your error bar.” But that assumes your error bar is honest — and here’s the uncomfortable research finding: for most people, most of the time, it isn’t. People are overconfident, and specifically overprecise: when asked for a range they’re “90% sure” contains the true answer, their ranges catch the truth far less than 90% of the time — often closer to 50%. We draw our error bars too narrow. We feel 90% sure and we’re really 60% sure.

This matters enormously for margins, because if your error bar is secretly too tight, then a margin sized “correctly” off that error bar is also too tight. The overconfident thinker doesn’t just make bad point estimates — they systematically under-size every buffer they build, because the buffer inherits the false narrowness of the range it was based on. Overconfidence isn’t a personality quirk here; it’s a direct cause of thin, dangerous margins.

The fix is unglamorous: widen your honest ranges. When you catch yourself stating a tight, confident band, ask “would I really be shocked, genuinely blindsided, if the truth came in outside this?” If the answer is “well, not shocked,” your band is too narrow — stretch it until being wrong would actually surprise you. A well-calibrated thinker’s ranges are wider than an overconfident one’s, so their margins come out fatter too — not because they’re timid, but because they’re being honest about how often they’re wrong.

This is what the forecasting research on so-called superforecasters points at, lightly: the people who predict best aren’t the boldest or the most certain — they’re the ones who hold wider, humbler ranges, update often, and resist the pull toward false precision. We won’t overclaim it as a magic formula. The takeaway is modest and sturdy: calibrate before you size. A margin built on an overconfident range is a margin that will fail you exactly when you were most sure it wouldn’t.

The matching trap to name is false precision: a confident point estimate dressed up as a certainty. “It’ll cost €100,000” stated flatly — no range, no “give or take” — feels rigorous because of the round, specific number, but it has quietly thrown away the error bar entirely, which means it has quietly thrown away any honest basis for sizing the margin. A number with no error bar isn’t an estimate; it’s a wish wearing a decimal point.

Tip:

Calibrate, then size

Before you size a margin, sanity-check the error bar it rests on. If you wouldn’t be genuinely shocked to be wrong outside your range, the range is too narrow — and so is any buffer built on it. Honest, wider ranges produce fatter, safer margins.

Fill in the calibration idea:

Pick the right option for each blank, then check.

Most people are : the ranges they call '90% sure' catch the truth far less than 90% of the time, so the margins they build come out too . The fix is to your honest ranges until being wrong would actually surprise you.

A worked example: cash runway

Let’s put error bars and tails together in a decision every business faces: how many months of cash should you hold in reserve? Cash runway is just a margin of safety denominated in months — the buffer between the revenue you expect and the revenue you can survive on if things go wrong. And its right size is governed by exactly one thing: how volatile your revenue is.

Picture two companies, each spending €100k per month, each expecting to roughly break even on average. The difference is the shape of their revenue.

  • SteadyCo sells annual software subscriptions to large, sticky customers. Revenue barely moves month to month — call it ±5%. Its error bar is tight, its tail is thin. A bad month is a slightly-below-average month.
  • LumpyCo does big bespoke projects that close unpredictably. Some months it bills €250k; some months, nothing. Revenue swings wildly — ±100% is normal — and it’s fat-tailed: a key client can vanish or a deal can slip a full quarter.
CompanyMonthly spendRevenue volatilityRealistic worst dry spellSensible cash buffer
SteadyCo€100k±5% (tight, thin-tailed)1–2 lean months3 months (€300k)
LumpyCo€100k±100% (wild, fat-tailed)6+ months with little revenue9–12 months (€0.9–1.2M)

Same €100k burn, same break-even-on-average expectation — and a buffer that should differ by 3–4×. SteadyCo can run lean: its revenue rarely dips far, so three months of cash comfortably covers the realistic bad patch. LumpyCo running on three months of cash is gambling its life on deals closing on schedule, which is exactly the thing it admitted it can’t predict; it needs nine to twelve months to survive a plausible dry spell. If both followed a one-size-fits-all “keep 3 months of runway” rule of thumb, SteadyCo would be fine and LumpyCo would be one slow quarter from insolvency. Steadier revenue earns a thinner buffer; lumpy, fat-tailed revenue demands a fatter one. The volatility sets the size — not the average, and certainly not a fixed habit.

LumpyCo's CFO argues: 'Our average monthly revenue equals our €100k spend, so on average we break even — three months of cash is plenty.' Spot the trap.

Match and sort: sizing in practice

Match each situation to the right margin response:

Pick a term, then click its definition.

Sort each situation by the margin it calls for: a THIN buffer is reasonable, or a FAT buffer is required?

Place each item in the right group.

  • Cash runway for a lumpy, project-based revenue business
  • Cash runway for a stable annual-subscription business
  • Estimating tomorrow's commute time on your usual route
  • Locked, contracted salary costs for next month
  • A first-ever product launch in an unfamiliar market
  • Exposure to a strategy that can crash hard in a rare market panic

An analyst uses one fixed rule — 'always demand a 25% margin of safety' — for every decision: a stable utility stock, a speculative biotech startup, and an emergency cash reserve. What's the underlying error?

The complete move

Sizing a margin honestly is three questions, asked in order. First, how wide is my error bar? — because the buffer covers the spread, not the point estimate. Second, how fat is the tail? — because in wild domains the rare extreme, not the average, is what you must survive. Third, is my error bar even honest? — because overconfidence quietly narrows every range, and a margin built on a too-narrow range is too thin no matter how careful the arithmetic looked.

Get those three right and the size of the buffer falls out almost automatically: fatter where you’re uncertain, fatter where the tail is wild, fatter still where you’ve caught yourself being overconfident — and leaner, without guilt, where the estimate is tight, the domain is mild, and your range is genuinely honest.

Success:

The key idea

A margin of safety isn’t a fixed number — it’s a function of how wrong you might be. Size it to the width of your error bars and the fatness of the tail, after honestly widening ranges you’re overconfident about. Fuzzier estimate, wilder world, shakier calibration → fatter buffer. A single fixed margin applied to everything is the mistake.

When to use it

Use this sizing discipline any time you’re about to commit a buffer of any kind — a project contingency, a cash reserve, an investment discount, a schedule pad, a safety factor on a design. Before you write the number, run the three questions: how wide is my error bar, how fat is the tail, and is my range honest? If you find yourself reaching for the same percentage you always use, regardless of the decision in front of you, stop — that’s the fixed-margin trap, and it’s silently over-padding your easy calls while leaving your dangerous ones exposed. Match the buffer to the uncertainty, every time.

Next up

You now know how big a margin should be. But so far we’ve treated a margin as a single number — 30% more cash, a safety factor of 5, three extra months of runway. In the next lesson, Backups, Slack & Fail-Safes, margins stop being a single number and start wearing disguises: the spare tire, the redundant server, the emergency fund, the fail-safe that breaks gently. Redundancy and spare capacity, it turns out, are just margins of safety in different clothes — and once you can see them that way, you’ll spot them, and their absence, everywhere.

Mark lesson as complete