Temperance Boiling is not a real person, though her name — for a food safety engineer who spent fifteen years obsessing over temperature thresholds at critical control points — is exactly the kind of coincidence that makes you suspect the simulation is getting lazy. What follows is a constructed conversation based on the publicly documented principles, failure modes, and design logic of HACCP systems as codified by the FDA and the Codex Alimentarius Commission. The perspective is imagined. The problems are not.
Every food product you've eaten today passed through a system designed in the 1960s for astronauts who couldn't afford to vomit in zero gravity. That system, Hazard Analysis and Critical Control Points (HACCP), solved a problem that sounds simple until you try: how do you prove food is safe?
Turns out you can't. Not directly. Before HACCP, the standard approach was to test finished products. Pull samples off the line, culture them for pathogens, wait for results. The FDA's own guidance acknowledges why this collapsed: a sampling protocol adequate to reliably detect low levels of pathogens requires so many samples that it's functionally impossible at production scale.1 The astronaut food program tried it. Most of the food failed testing. Not because it was dangerous, but because the testing regime was too blunt to distinguish dangerous from safe with any confidence.
HACCP's design response was to substitute an unbounded negative claim (no Salmonella in this batch) with a bounded positive measurement: this product reached 165°F internal temperature for 16 seconds.1 The system doesn't monitor for pathogens. It monitors for the conditions scientifically established to eliminate them.
But the substitution was only half the problem. The harder half was scoping. A food production line has dozens of steps. Which ones get elevated to Critical Control Points, with continuous monitoring, documented readings, and pre-planned corrective actions for any deviation? Which ones don't? And what happens when you draw that boundary in the wrong place?
Temperance Boiling, who insists on "Temp" (because of course she does), spent fifteen years designing HACCP plans for seafood processors before moving into broader food safety consulting. Her specific obsession: the decision tree that determines what is not a critical control point.
You've described your job as "professional subtractor." What does that mean?
Temp: Most people assume food safety means monitoring more things. More checks, more data, more control points. So when I show up to review a processor's HACCP plan and my main recommendation is to remove three of their seven CCPs, they look at me like I've suggested we skip handwashing.
The FDA guidance is explicit about this, though. Too many CCPs is a recognized failure mode.1 It dilutes monitoring attention. If everything is critical, nothing gets the attention that "critical" is supposed to guarantee. The whole architecture depends on a small number of well-defined points getting serious focus. Not checkboxes. Actual, real-time measurement by someone who understands what they're looking at and has the authority to stop the line.
How do you decide what's out?
Temp: The Codex decision tree has this beautiful question built into it: "Will a subsequent step eliminate the identified hazard or reduce it to an acceptable level?"2 If yes, then the earlier step isn't your CCP. The later one is. You don't need elevated monitoring at both points. You need it at the one that actually resolves the hazard.
This drives people crazy. They want to monitor at receiving too, because it feels safer. And look, you can have a control point there. Check the temperature of incoming product, sure. But a control point and a critical control point are formally different things in HACCP.1 The critical one gets the documentation, the calibrated instruments, the pre-planned corrective actions, the independent verification. The regular one gets good practice and a pat on the back.
What happens when someone ignores that distinction?
Temp: I reviewed a plan once where a processor had eleven CCPs for a single product line. Eleven. The monitoring logs were immaculate. Every box checked, every temperature recorded, beautiful penmanship. And the operation was a mess.
Here's why. The FDA guidance actually warns about this specific pathology: people assigned to monitor CCPs want to show the process is under control, so they record the specified criterion regardless of what they actually observed.1
When you have eleven CCPs and a worker is responsible for checking all of them every thirty minutes, you're not getting monitoring. You're getting performance art.
That's a harsh way to put it.
Temp: It's the FDA's way of putting it. I'm paraphrasing, but barely.
So the scoping decision is load-bearing for the entire system?
Temp: It is the system. The guidance says it directly: if the hazard analysis isn't done correctly and the hazards warranting control aren't identified, the plan won't be effective regardless of how well it's followed.1 The critical limits, the monitoring procedures, the corrective actions, all of it downstream is only as good as the scoping.
And this cuts both directions. Scope too broadly and you get the eleven-CCP problem, where monitoring becomes theater. Scope too narrowly, exclude a hazard because you judged it "not reasonably likely," and if that judgment was wrong, no amount of perfect monitoring at your other CCPs will catch it. The system is blind to hazards it decided not to look for.
How do you know if your scope is wrong?
Temp: Consumer complaints. Which sounds almost quaint, right? But the FDA guidance treats complaints as evidence that the declared inspection surface may have missed something.1
If people are getting sick and your monitoring logs show perfect compliance, the logs aren't lying. Your scope is wrong. You're measuring the right things at the right points and the hazard is somewhere you decided not to look.
This is why validation is separate from monitoring. Monitoring asks, "Are we within our critical limits right now?" Validation asks, "Do these critical limits actually control the hazard we think they control?"1 Different questions. Different timescales. Different evidence. You can pass every monitoring check for a year and still have an invalid plan.
What's the most common mistake you see in how people think about HACCP?
Temp: They think it's a testing system. It's a scope declaration system. The entire architecture, the hazard analysis, the decision tree, the prerequisite programs underneath, the flow diagram that defines what's inside the establishment's control and what isn't1, all of it exists to answer one question: where are we looking, and where are we deliberately choosing not to?
The monitoring matters, obviously. But the real power sits in the boundary. Get the boundary right and mediocre monitoring will still catch problems. Get the boundary wrong and flawless monitoring just gives you a beautiful record of looking in the wrong places.
Last question. Does your name ever come up in professional settings?
Temp: Every single time. Every. Single. Time. I once handed someone a business card and they asked if it was a joke. I said, "My parents named me Temperance. I spent my career measuring temperatures. I go by Temp. I've made peace with it."
They hired me anyway. Probably figured anyone who'd survived that name in this industry had to be stubborn enough to be useful.
Footnotes
-
FDA, HACCP Principles & Application Guidelines, National Advisory Committee on Microbiological Criteria for Foods, adopted August 14, 1997; content current as of 02/25/2022. https://www.fda.gov/food/hazard-analysis-critical-control-point-haccp/haccp-principles-application-guidelines ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9
-
FAO, Hazard Analysis and Critical Control Point (HACCP) System and Guidelines for its Application, Codex Alimentarius. https://www.fao.org/4/y1579e/y1579e03.htm ↩
