The scrap of paper was handwritten in ballpoint, folded once, and placed under the plexiglass on a console in the Staff Support Room in Houston. It listed every program alarm the Apollo Guidance Computer could throw during a lunar descent, and next to each one, in Jack Garman’s shorthand, a single instruction: land, or abort. On July 20, 1969, at roughly 1,800 metres above the Sea of Tranquility, the number 1202 lit up on Buzz Aldrin’s display. Garman glanced at his list, said one word into his headset, and the first crewed landing on another world was cleared to continue.
The word was go.

A 24-year-old with a piece of paper
Jack Garman was 24 years old in July 1969. He worked in the back room of Mission Control as a support engineer for the Apollo Guidance Computer, the machine designed at MIT’s Instrumentation Laboratory under Margaret Hamilton that ran the lunar module. His job was to know the AGC inside out — every subroutine, every fault code, every way it could complain.
The reason the list existed at all was a simulation run weeks earlier. During a rehearsal descent, the AGC threw a program alarm and the flight controller called an abort. Flight director Gene Kranz was furious when engineers realised afterwards that the alarm had not actually required aborting. As Garman recounted in an interview later published by IFLScience, Kranz told him to go and learn every alarm the computer could produce, and to know, for each one, whether the mission could keep going.
So Garman sat down and wrote them out by hand. Ones and twos, threes and fours. Overflow alarms, executive alarms, restart alarms. Next to each, a note: continue, or abort. He placed the list under the plexiglass on his console in the Staff Support Room adjacent to the main Mission Operations Control Room.
Twelve minutes into the descent
On July 20, Neil Armstrong and Aldrin undocked the lunar module Eagle from the command module Columbia and began powered descent above the lunar surface. The AGC was running its descent guidance program, feeding thrust commands to the descent engine while ingesting data from two radars — the landing radar looking down at the Moon, and the rendezvous radar, which normally tracked the command module for an emergency abort back to orbit.
The rendezvous radar switch had been left in a position that dumped a steady stream of unnecessary data into the guidance computer. The AGC had limited memory and processing power. It was being asked to fly a lander to the Moon while a rogue peripheral kept knocking at the door.
About five minutes into the descent, Aldrin keyed his mic. “Program alarm.” A pause. “It’s a 1202.”
In the main control room, capsule communicator Charlie Duke — the astronaut talking to the crew — later recalled that his heart sank when he heard the alarm code.
What 1202 actually meant
A 1202 alarm, in the AGC’s fault taxonomy, is an executive overflow — the operating system’s way of saying it has more jobs queued than it can service in a single cycle. On almost any other computer of the era, that would have meant a crash. What saved the landing was the architecture Hamilton’s team at the MIT Instrumentation Laboratory had built into the software: a priority scheduler that could shed low-value tasks and restart the important ones without losing the descent guidance loop, as documented in participant accounts and technical reconstructions of the AGC’s design.
Hamilton, leading the on-board flight software team, had insisted on that fault-tolerant design partly because of an anecdote about her young daughter accidentally crashing a simulator by pressing the wrong key. If a child could break the software by accident, so could an astronaut under stress. Scientific American has documented how that instinct became the priority-driven executive at the heart of the AGC.
So when the 1202 fired, the software was doing exactly what it was designed to do: dropping the useless rendezvous radar processing, restarting itself, and keeping the descent guidance running. But nobody in Mission Control could confirm that in real time without knowing the alarm code by heart.
The 17 seconds
The call came down from Eagle. Steve Bales, the guidance officer known by his call sign GUIDO, had limited time to analyze the situation before he had to give Duke a call. Bales leaned over to the loop connecting him to the back room. Garman, list in front of him, was already looking at line 1202.
Garman told them to proceed with that alarm. As long as it wasn’t continuous, the computer was recovering.
Bales relayed the decision upward that they should continue despite the alarm. Duke pressed his mic and told Armstrong and Aldrin: “We’re go on that alarm.” Eagle kept descending.
Then the computer threw another. And another. Over the next four minutes, the AGC generated five program alarms — 1202s and their cousin, the 1201, a different flavour of executive overflow. Each time, Garman checked the list, said go, and the call passed up the chain. Florida Today’s reconstruction of the descent notes that the alarms almost certainly contributed to Armstrong looking inside the cabin at the display instead of out the window, which is part of why Eagle overshot its planned landing site and ended up flying manually over a boulder field.

The word that went into the history books
The go/no-go poll that mattered came moments after the first alarm. Kranz went around the room: “GUIDO?” Bales, still processing Garman’s advice, answered go. It was, as Space.com’s chronology of Apollo landmarks records, one of the tightest calls in spaceflight history — a decision made with seconds to spare, based on a piece of paper written by a 24-year-old engineer at the direction of a flight director who had lost his temper in a simulator weeks earlier.
The Apollo 11 crew received widespread recognition following the successful mission. Garman, sitting one room removed from the main floor, was not in the spotlight. But in the community of engineers who understood what had actually happened, his name became the answer to a specific question: who saved the landing?
In the years after, engineers and flight controllers who were there credited Garman with the preparation and the split-second call that allowed the landing to continue.
Why a piece of paper worked when computers couldn’t
The Apollo Guidance Computer had limited memory — erasable memory for working data and read-only rope-core memory physically woven by hand at the Raytheon plant in Waltham, Massachusetts. Every bit of code Hamilton’s team wrote was literally stitched into hardware. Once Eagle lifted off from Cape Kennedy on July 16, the software was frozen. There was no patching it in flight.
That constraint is why Garman’s paper mattered. The computer could not explain itself. It could only flash a number and hope somebody, somewhere, knew what the number meant. Garman was that somebody. The 1202 alarm has since become a kind of folk emblem in software engineering — cited in analyses of everything from fly-by-wire aircraft to autonomous vehicles whenever the question comes up of how a safety-critical system should handle overload without giving up.
The answer Hamilton’s team gave in 1969 — degrade gracefully, restart cleanly, keep the mission-critical loop running — is now a standard pattern. The answer Garman gave — memorise every possible fault and write it down where you can read it in one glance — is a different kind of engineering wisdom, older than computers, and it is still how the best mission control rooms operate.
The rest of the descent
After the fifth alarm, the AGC settled. Armstrong took manual control, flew Eagle laterally to clear the boulder field around the original target, and set down in the Sea of Tranquility with roughly 25 seconds of descent-stage propellant remaining before an abort would have been mandatory. Charlie Duke, still on the mic, exhaled the reply that has been quoted ever since: “Roger, Tranquility, we copy you on the ground. You got a bunch of guys about to turn blue. We’re breathing again. Thanks a lot.”
Other Apollo moments saw single decisions separate triumph from catastrophe — most notably the 96-hour improvisation that brought Apollo 13 home, and the private Communion Aldrin took on the lunar surface a few hours after touchdown. Both stories share a quality with Garman’s list: the Apollo program ran on institutional knowledge that lived, in the end, inside individual human beings.
What happened to the paper
Garman’s original list did not survive as an artifact in the way the flight plan or the checklists did. He described it as a small handwritten note, produced quickly, placed under the plexiglass for the shift. It was a working document, not a keepsake. What survived is the transcript — the loop recordings from Mission Control that capture Bales’s voice saying we’re go on that alarm, five times in four minutes, each call preceded by the faint sound of the back room checking a piece of paper.
Garman went on to a long career at NASA, working on the Space Shuttle and later the International Space Station’s software architecture, retiring in 2000. He spoke often, in interviews recorded before his death, about how strange it had felt to fly a vehicle with a computer at all in 1969 — how most systems in the aerospace world were still analogue, and how the AGC seemed overly complex even to those who built it.
More than five decades on, the Sea of Tranquility still holds the descent stage of Eagle, sitting in vacuum where Armstrong set it down. The rope-core memory that carried Hamilton’s software is in museums. Somewhere in the archives of the Johnson Space Center are the voice loops that captured Garman’s answer travelling from a back-room console up through Bales, through Duke, and into a radio signal that took about 1.3 seconds to reach the Moon. On the recording, you can hear the pause before each go — the fraction of a second in which a young engineer looked at his own handwriting and decided that the machine was still flying.