A second difficult case can reveal whether the first one changed anything durable.
Consider an illustrative cybersecurity team inside a regional bank. Farah El-Sayed is investigating a sequence of authentication events that the automated system has ranked as low risk. The logins appear to move between two countries at a speed no traveller could manage, although the timing falls outside the rule designed to identify automated attacks. The alerting system has therefore produced a reassuring score for behaviour that would require an unusually committed passenger and access to experimental aviation.
Farah combines identity logs with a recent conditional-access change, knowledge of session renewal and a note from Malik Thompson, an infrastructure engineer who remembers a superficially similar false alarm from the previous quarter. She tests several explanations, isolates the affected accounts and later learns from forensic evidence that the attacker exploited a timing interval sitting between two existing controls.
The incident changes Farah's understanding of the authentication system, especially the assumptions sitting between two controls that previously looked independent. During the review, she also notices that the automated risk score anchored her first interpretation longer than she realised. Her investigative method changes as the team works through what evidence was requested too late and which queries helped separate the competing explanations.
Four months later, another incident presents a different surface pattern. The developmental question begins there. If Farah can recognise a related structure, adapt the earlier method and regulate the pressure of challenging a trusted control again, the first episode has altered the starting conditions of the second.
The Unified Skills Map uses this reciprocal possibility to connect the capability families over time. Generative Skills can participate in learning and performance, after which newly organised Knowledge may alter later action. Enacted Practical Skills return fresh evidence to the person's understanding, and meaningful repetition may eventually change some of the analytical, creative or emotional processes mobilised across those episodes. Our framework organises these relationships into one system logic. External research supports the component mechanisms with different levels of directness.
Development therefore depends on what happens between one episode and the next. A company can accumulate incidents, meetings, projects and years of service while improving very little. It can also become exceptionally efficient at repeating an explanation that the available evidence stopped supporting several quarters ago.
The Next Attempt Inherits Something From the Previous One
Capability compounds when an earlier episode leaves a usable change that affects later interpretation or action.
Farah's first investigation changes her Conceptual Knowledge because she now understands a timing weakness between authentication controls that previously appeared independent. It also deepens Contextual Knowledge about the bank's monitoring environment, including which automated scores receive organisational trust and how quickly analysts can obtain infrastructure evidence during an incident.
Those changes matter only when later work retrieves them in a useful form. The second attack uses another technique, so remembering the old sequence step by step would provide limited help. Farah needs to recognise a structural similarity: two controls can each behave as designed while leaving a gap between their assumptions.
First incident
Logins between two countries at a speed no traveller could manage, outside the rule for automated attacks
Four months later
Another technique and another surface pattern
Two controls each behave as designed and leave a gap between their assumptions.
Conceptual Knowledge
A timing weakness between controls that looked independent
Contextual Knowledge
Which automated scores the bank trusts and how fast infrastructure evidence arrives
Practical Skills
Faster token tracing and more precise evidence requests, local in scope
Transfer research gives this part of the cycle a difficult boundary. Barnett and Ceci (2002) showed that transfer varies with distance across knowledge domain, physical and social setting, temporal context and function. A lesson attached tightly to one surface configuration can remain dormant when the next case looks different.
The earlier episode can also affect Practical Skills. Farah has become faster at tracing token renewal and more precise about the evidence she requests from infrastructure. Those gains are fairly local. Claiming that she has become broadly "better at cybersecurity" would compress several distinct changes into a flattering label and remove most of the information needed to understand what actually developed.
Reciprocal development therefore operates through specific carry-over. Knowledge has to remain retrievable, practical methods have to improve against a valid criterion and the next task has to exercise something related enough for previous learning to matter.
Cycles Appear in Research Without Arriving as One Universal Loop
Several research traditions describe development through repeated phases in which the result of one attempt informs the next.
Self-regulated learning models are an important example. Zimmerman (2000) described cyclical relations among forethought, performance and self-reflection, while Panadero's (2017) review shows considerable variation across six major models in how monitoring, motivation, strategy use and regulation are conceptualised. These models provide established mechanisms for adjustment across learning attempts, although their evidence base is concentrated heavily in educational settings.
Recent intervention research supports the possibility that some self-regulatory processes can change. Chen's (2022) meta-analysis of self-regulated learning interventions in second-language education found positive average effects on achievement, strategy use and self-efficacy, with substantial variation across studies and a domain that remains far removed from professional cybersecurity. The evidence demonstrates modifiable learning processes inside a defined context; it offers no licence to assume that every repeated workplace challenge creates stronger self-regulation.
Conceptual and procedural knowledge provide another bounded example of reciprocity. Rittle-Johnson, Siegler and Alibali (2001) found iterative development in children's learning of decimal fractions, where gains in conceptual understanding contributed to procedural gains and improved procedures created opportunities for further conceptual development. The study establishes a reciprocal relation within a specific learning domain, which is exactly the level of evidence that a system claim should preserve.
These literatures support reciprocal development within bounded mechanisms and domains. The complete three-family, three-capacity loop remains our architectural synthesis because the available studies examine narrower relationships under different conditions.
Repeated Use May Change the Capacities Doing the Work
The most ambitious part of the system concerns the possibility that repeated meaningful activation contributes to stronger Generative Skills.
Evidence differs across the three capacities, so the claim needs an uneven treatment.
For Creative Capacity, recent meta-analytic evidence is substantial enough to support trainability within defined outcomes. Sio and Lortie-Forgues (2024) synthesised 169 studies and found positive average effects of creativity training, while estimates became considerably smaller after adjustments for publication bias and study quality. McKay et al. (2024), focusing on organisational settings, also found positive overall effects, with stronger results for learning outcomes than for behaviour transferred into the workplace.
Emotional Capacity has a recent workplace evidence base of its own. Mehler et al.'s (2024) systematic review and meta-analysis examined interventions targeting emotional intelligence, empathy and emotion regulation at work. The programmes produced positive average effects across emotional-competence outcomes, accompanied by substantial heterogeneity, study-quality limitations and uneven follow-up. Improvement is therefore credible at the level of trained outcomes, while durability and transfer remain dependent on the intervention, measure and setting.
The research nearest to Analytical Capacity requires greater interpretive care because critical thinking, cognitive reflection and analytical reasoning overlap with parts of our construct without mapping onto it exactly. Liu and Pásztor's (2022) meta-analysis synthesised 50 problem-based-learning studies involving 5,210 higher-education participants and found positive effects on critical-thinking skills and dispositions, with moderator effects and heterogeneity across conditions. Simonovic et al. (2023) then tested a brief online critical-thinking intervention with 148 higher-education participants and reported improvement in cognitive reflection, argument evaluation and several metacognitive outcomes, while analytic writing did not improve.
These studies support the narrower proposition that reasoning-related performances can change through intervention under specified conditions. Their constructs overlap with parts of Analytical Capacity while covering a smaller and differently defined territory, which keeps any inference about broad cross-domain development appropriately limited.
The three evidence bases therefore converge on malleability with different construct matches, outcome measures and transfer limits. Repeated activation may contribute to development when it genuinely exercises the relevant process and when later performance shows a durable change. Volume of use supplies weak evidence on its own.
Creative Capacity
169 creativity-training studies report positive average effects, smaller after adjustment for publication bias and study quality
Emotional Capacity
Workplace programmes on emotional intelligence, empathy and regulation report positive average effects with heterogeneity and uneven follow-up
Analytical Capacity
Critical-thinking and reasoning studies overlap with part of the capacity and cover a smaller, differently defined territory
Overlaps are drawn for illustration.
A Loop Can Become Very Good at the Wrong Lesson
Reciprocal development also has a darker property: the system can reinforce error.
Imagine the bank praises Farah's team only for containment speed. After several incidents, analysts learn that closing accounts aggressively produces excellent response-time metrics, while false positives are reviewed by another department three weeks later. The team becomes faster and more confident. Customers become increasingly familiar with the phrase "temporary security measure".
The team is learning efficiently against a criterion that rewards containment speed while hiding the cost of unnecessary disruption.
Feedback research helps explain the risk. Zhang and Fiorella's (2023) model of learning from errors places detection and correction at the centre of whether an error becomes useful for learning. Consequences that remain invisible or are interpreted through a weak causal account can leave the original model intact. Workplace experience can therefore strengthen an effective response, an ineffective response or a response optimised for the wrong outcome.
A different failure occurs when the cycle never closes. Farah may resolve an incident and move immediately to the next alert because the team is understaffed. Logs remain in separate systems, the forensic review arrives after the details have faded and the colleague who understood the access-policy change transfers to another department. Experience accumulates while the information required for consolidation disappears.
Knowledge can also deepen without influencing later action. A post-incident review may identify exactly why the first response failed, yet the team continues using the old procedure because authority to change it sits elsewhere. The organisation has learned on paper while operational practice preserves the previous behaviour.
These trajectories show why development cannot be inferred from recurrence. Repetition tells us that something happened again. The developmental content sits in the quality of the challenge, the evidence generated, the interpretation applied and the opportunity to carry a revision into later work.
Closed on the wrong criterion
Containment speed earns praise while the cost of unnecessary disruption is reviewed elsewhere three weeks later.
Never closes
Logs sit in separate systems, the forensic review arrives late and the colleague who understood the change has moved on.
Closes on paper
A review explains why the first response failed while the authority to change the procedure sits elsewhere.
The Environment Helps Decide Which Cycle Survives
Farah's capabilities operate inside a system of tools, colleagues, incentives and authority. That environment affects which parts of an episode can become developmental.
Malik's infrastructure knowledge gives her access to evidence she could not generate alone. Yuna Park, the incident-response lead, allows the team to challenge an automated score without treating disagreement with the system as operator error. A later forensic review returns outcome information quickly enough for the investigation to be reconstructed accurately. Each condition helps connect one episode to the next.
A different organisation could produce the opposite trajectory from the same analyst. Restricted access can force reliance on weak proxies. Punitive responses to uncertainty can reward concealment. Narrow role boundaries can prevent somebody from testing a better method. Excessive workload can convert every incident into successful survival followed immediately by another incident.
Farah’s team
First incident
- Malik’s infrastructure evidence
- Room to challenge an automated score
- Forensic review that returns outcomes quickly
Second incident
A different organisation
First incident
- ×Restricted access forces reliance on weak proxies
- ×Punitive responses reward concealment
- ×Narrow role boundaries block a better method
- ×Workload turns each incident into survival
Second incident
Adaptive-expertise research repeatedly identifies interactions among individual characteristics, task demands and environmental conditions, while reviews also note substantial conceptual inconsistency and limited causal evidence for proposed developmental routes (Pelgrim et al., 2022). Hissink et al.'s (2025) scoping review of measurement instruments in healthcare found only 19 instruments across 17 included articles, with varied operationalisations and uneven evidence supporting measurement quality.
That measurement problem matters because claims about compounding can easily outrun what organisations have actually observed. Faster performance may indicate procedural fluency. Better explanation may indicate stronger Knowledge. Improved reasoning across a family of related cases may provide evidence relevant to Analytical Capacity within that domain. One confident presentation after a difficult project establishes very little about broad adaptability.
Development becomes easier to defend when the object of change is specified and observed across time, retention and meaningful variation.
Compounding Changes the Starting Point Without Finishing the Development
Four months after the first incident, Farah faces the new authentication anomaly with a different starting model. She checks the automated score without granting it immediate authority, traces the timing assumptions behind two controls and asks Malik for infrastructure evidence earlier in the investigation. She also raises a competing hypothesis before the team commits to containment, partly because the previous review showed how quickly one plausible explanation can dominate the room.
The earlier incident survives in Farah's changed account of the authentication system and in the way she conducts the investigation. She also notices the anchoring tendency earlier, before the automated score settles too comfortably into the team's explanation. The new case will generate its own evidence, and some of that evidence may force another revision.
Our contribution in the Unified Skills Map is to organise these movements as a reciprocal capability system while keeping their developmental status conditional. Generative Skills can support learning and action; Knowledge Domains can alter later performance; Practical Skills can expose understanding to consequences; repeated engagement may contribute to changes in the capacities mobilised during later work. Research supports these component relations with different levels of directness, and transfer remains domain-sensitive.
Capability compounds when one episode changes what becomes possible in the next and the change survives contact with new conditions. The same system can stall when evidence never returns, or drift when the environment repeatedly rewards the wrong lesson. A useful developmental architecture therefore has to leave room for correction, because the ability of the next cycle to revise the previous one is part of what keeps growth aligned with reality.