Models

Four models. Four questions.

These are the models the practice runs on. Each one answers a single question, states its mechanic in a sentence, reports two foundations it refuses to blame, and names the ways it goes wrong. They are not a sequence — you reach for whichever one matches the question in the room.

Most rooms contain all four questions wearing each other's clothes. "Why isn't the CRM working" is usually a capacity question. "We tried that and it failed" is almost always a consequence question. And "we need to move faster" is nearly always a question about how long the organisation can be wrong without noticing.

Where are we? · Capacity

The Digital Maturity Pyramid

AI is the top of a pyramid, not a shortcut. Each layer consumes what the one below it produces, so the least-built layer underneath AI caps the value of everything above it.

The order is physics, not stage theory. Every layer's reason you cannot skip it is a specific input dependency — a model cannot read what was never captured, and it cannot learn from a process that only ever happened in an email thread. The pyramid measures capacity: what your organisation is currently able to convert investment into.

The five layers

  1. 01

    Digitisation

    Getting out of the analogue world: paper, filing cabinets and tribal knowledge become digital records that are searchable and machine-readable.

    Why you can't skip it AI cannot read what was never captured. Every unscanned contract and undocumented process is simply invisible to every layer above this one.

  2. 02

    Digitalisation

    Work moves out of inboxes and spreadsheets into systems, so processes produce structured data as a side effect of running.

    Why you can't skip it Models learn from structure and history. A process that lives in email threads has neither.

  3. 03

    Interoperability

    Systems start talking. APIs, pipelines and shared schemas turn islands of data into one navigable map, and a customer is the same customer everywhere.

    Why you can't skip it AI's value comes from joined context. Siloed systems cap every model at a single department's view — answers that are locally right and globally wrong.

  4. 04

    Automation & Intelligence

    Systems begin to act and to learn. Rote work is automated, decisions get model support, and outcomes feed back in.

    Why you can't skip it AI without actuation is just advice. The feedback loops built here generate exactly the labelled history serious AI needs to learn from.

  5. 05

    AI

    Language models, vision and prediction working inside real workflows on your own data, with measured return — not a demo searching for a use case.

    Why you can't skip it This layer multiplies whatever the stack below provides. On structured, connected foundations it compounds; on silos and scans it hallucinates confidently.

The mechanic

Realised value is min() over the layers below, not their average. A strong average cannot buy off a weak layer, which is exactly why most maturity models cannot tell you what to do on Monday. Raising the weakest layer moves the number. Raising the AI budget barely does.

And the refusal is in the name: you can't leapfrog the layers — you can speed-run them.

The two foundations

Innovation culture & leadership support

Leadership that sponsors the climb and a culture that treats change as normal work. Every layer above is a change project wearing a technology costume.

Reliable IT infrastructure & operations

Networks, identity, devices, backups, patching. An AI pilot on infrastructure nobody trusts never makes it to production.

Both are reported alongside the score and neither is ever named as the ceiling, for a stated reason: "fix your culture" is not an actionable next layer to climb. A foundation explains; it does not instruct.

The failure modes

  • The leapfrogger. A maximum AI budget on a hollow pyramid. The weakest layer gates the whole investment and a shaky foundation taxes whatever gets through, so most of the spend produces demos rather than capability.
  • The laggard. Nothing to leapfrog from and nothing compounding. The good news is that the bottom of the pyramid is the cheapest place to start, and the work starts paying immediately.
  • The speed-runner. The one that is not a failure — same order as everyone else, built in quarters instead of decades, with both foundations solid so a moderate AI budget compounds instead of leaking.

Live: the model, with the leapfrog simulator and the 28-statement self-assessment, which names your weakest layer and refuses to defend its own arithmetic.

What happens when we move? · Consequence

Orders of Consequence

A change is not an event. It is a propagation — and two things travel in opposite directions.

Intent attenuates. It leaves your mouth whole and arrives in fragments, weaker at every hop, until the person who actually has to do something differently has received a rumour of a priority. Consequence amplifies. The first-order effect is the one you planned; the fourth is what becomes possible because all of it happened, and it arrives late enough that nobody connects it to you. Almost every change that fails, fails in the gap between those two.

You are judged at Order 2 and paid at Order 4. At Order 2 the costs are visible, specific and attached to named people; the benefits are not there yet, and when they arrive they will be diffuse and attached to nobody. Judge in between and you get a confident false negative — a decision that feels rigorous, is supported by real evidence, and is wrong.

The five orders

  1. 0

    The Decision

    What was actually decided, as opposed to what was announced, discussed or minuted. Somebody can state it in one sentence without using the word "strategy", and the sentence has a verb in it.

    Why you can't skip it Every order above is a consequence of something. If the decision is a direction rather than a change, there is nothing for the orders to be consequences of.

  2. 1

    The Mechanics

    What changes in the work itself — the system, the process, the form, the step added or removed. There is a date, a budget line and a person.

    Why you can't skip it Nothing propagates from an intention. Until something concretely changes, there is nothing for anyone to work around. The trap: this is the part with a Gantt chart, so it is the part that gets managed, and it is rarely the part that decides the outcome.

  3. 2

    The Workarounds

    What people do to keep the work moving while Order 1 lands on them. The parallel spreadsheet, the WhatsApp group, the one person who still knows the old way and is quietly doing it for everybody.

    Why you can't skip it This is where the real cost of every change sits, and it is never in the business case. The trap: workarounds are read as resistance. They are almost always competence — treat them as misbehaviour and you lose both the information and the informant.

  4. 3

    The Adaptations

    The new habits, norms and informal structures that form around the change and then outlive it. Who people ask now. What the meeting is for now. What "done" means now.

    Why you can't skip it This is where a change becomes irreversible. Below it, removing the mechanic removes the change; above it, the organisation would have to be changed back on purpose.

  5. 4

    The Compounding

    What becomes possible because the change happened. Not the benefit you promised — the second thing, the one that was unaffordable before and is now routine.

    Why you can't skip it You cannot skip it, but you can fail to claim it, and organisationally that is the same thing. An Order 4 benefit nobody attributes buys no credibility for the next change.

The mechanic

Your change horizon is the deepest order at which you can name a concrete instance that has already happened. Not one you can imagine. Not one you can argue for. One you can name, with a person attached.

Most organisations, measured honestly, have a horizon of Order 1. A change judged below the order where its benefit lives will be killed — not by short-termism, but by rigour applied to a truncated dataset. The mechanic has no opinion on the merits: it scores the observer, not the change.

The two foundations

Transmission

A message has not been sent until it has been received in a form the receiver can act on. An all-hands, an email and an intranet post are one form repeated three times. A changed template is a different form. A default that no longer permits the old way is the strongest one.

Slack

Whether anyone has the capacity to absorb Order 2. A change landing on a saturated organisation produces workarounds and nothing else. It never reaches Order 3, because forming new habits requires attention that is entirely committed to keeping the current output up. The organisation is not resisting; it is full.

Attenuation runs at roughly half per hop. That number is a teaching claim, not a measured coefficient — if someone wants to argue about the fraction, agree immediately and ask the question it was standing in for: how many genuinely different forms has the person who has to change actually received this in?

The failure modes

  • The Confident False Negative. Killed at Order 2, where all cost and no benefit is visible, by people doing exactly what good governance asks of them. Recognise it by evidence that is genuinely strong, genuinely relevant, and entirely about cost.
  • The Announcement. Transmitted once, in one form, and mistaken for landed. Recognise it by "we've communicated that" said in the past tense, and by a leadership team who can all state the change while nobody two levels down can.
  • The Saturated Org. Every change individually sensible, collectively nothing sticking, and the diagnosis lands on culture. Ask how many active changes are landing on the same forty people and watch nobody know.
  • The Unclaimed Win. Order 4 arrives and nobody connects it to the decision that caused it. Recognise it by an organisation that has plainly improved and a leadership team who still say "we're not good at change".
  • The Order-1 Manager. Runs the mechanic superbly and believes that is the job. Recognise it by an implementation that came in on time and on budget and changed nothing.
Why isn't it working? · Diagnosis

The Narrowing

Diagnosis is a search, and the only legal move is one that eliminates territory.

Everything that feels like progress and is not — the theory that explains the symptom, the meeting where four people offer four causes, the fix that ships on Friday — has the same property. It adds an explanation without removing a possibility. The search space is exactly as large as it was before, and now there is a story attached to it. Hypotheses are free. Elimination is the work.

"Show me" is not rudeness. It is the cheapest experiment available. You have not found the cause until you can switch it on and off.

The five moves

  1. 01

    Reproduce

    Making the fault happen on demand, in front of you. You can say "watch this" and then the thing goes wrong, and the conversation has stopped being about whether it happens.

    Why you can't skip it Without reproduction you cannot halve an interval, confirm a cause, or ever know your fix worked. The trap: "it's intermittent" is not a property of the fault. It is a statement that you have not yet found the variable that makes it deterministic.

  2. 02

    Draw the path

    What happens immediately before and immediately after the point where the fault appears — end to end, including the parts nobody owns. There is a drawing, it fits on one page, and the people who own each segment agree it is accurate.

    Why you can't skip it An interval requires two ends and a middle. Without the path there is only a list of suspects, which cannot be halved. Where two teams draw the boundary differently, stop — the gap between their drawings is where faults live.

  3. 03

    Halve the interval

    Choosing tests that eliminate half of what remains, and running them. Test in the middle, not at the ends: if the likely cause were it, someone would have found it already. Ten halvings clear a thousand possibilities.

    Why you can't skip it This is the only move that makes the problem smaller. The test every test must pass: what will this rule out if it comes back clean? A test that cannot fail tells you nothing.

  4. 04

    Establish the cause

    Demonstrating control, not explanation. You can turn it on. You can turn it off. You can turn it on again. The room has gone quiet because there is nothing left to argue about.

    Why you can't skip it This is the falsifiability gate. Without it you have a hypothesis that survived, which is not the same as one that is true and behaves identically until the fault returns. One direction is a correlation with better lighting.

  5. 05

    Change the structure

    Fixing the thing that allowed the fault to exist rather than the instance of it. You can say what class of fault is now impossible, not just which ticket is closed.

    Why you can't skip it Skipping it is not free; it is a loan. The same structure will produce a different-looking fault later, and the diagnosis will start from zero because nobody connects the two.

The mechanic

Every step must eliminate territory. Progress is measured in what has been ruled out, not in what has been proposed.

Four plausible theories and no eliminations is not four times the progress of one theory. It is zero progress, four times. A diagnosis therefore has a measurable state at any moment — the size of the remaining space — and if nobody in the room can say roughly how much smaller it got today, the diagnosis is not being run, it is being attended.

The two foundations

Instrumentation

Whether you can see inside the system at all. An organisation with poor instrumentation does not have slow diagnosis; it has lucky diagnosis, which looks identical on the good days and is unbounded on the bad ones.

The honest test: when something goes wrong, is the first action to look at something, or to ask someone?

Blamelessness

Whether people will show you what actually happened. Without it, move 01 is not an experiment, it is a negotiation — and nobody experiences being lied to, they experience a problem that took a strangely long time.

The honest test: has anyone here ever said "I did that" in a review, and been fine afterwards?

Neither is ever the verdict. "Improve your culture" and "buy observability" are not next moves, and a model that ends there has stopped being useful precisely where it started being needed.

The failure modes

  • The Plausible Story. A cause that explains the symptom, has never been tested, and stops the search. Recognise it by how good it feels: the room relaxes, the explanation is coherent, and nobody can say what would prove it wrong.
  • The Unreproduced Fix. Closed without ever having been seen to fail. Recognise it by "we think it was" and the absence of a before-and-after. It will be back, and it will not be recognised as the same fault.
  • Solving the Reported Problem. Move 02 skipped, so the place the symptom appeared is mistaken for the place the fault lives. Recognise it by a fix in the component that raised the error rather than the one that produced the condition.
  • The Fix That Ships. Move 05 skipped. The instance is repaired, the structure reloads. Recognise it by a team that is good at firefighting and cannot say why there are so many fires.
  • The Suspect List. Move 03 attempted without move 02 — testing suspects rather than halving a path. Recognise it by a diagnosis that has been busy for a week and cannot say what it has ruled out.
  • The Committee. Four people, four theories, no tests, and a decision by seniority. The loudest hypothesis wins and nobody notices that no information was added.
How do we move quickly? · Exposure

The Correction Rate

You do not go faster by working faster. You go faster by being wrong sooner.

Every choice that looks like a delivery decision — batch size, branch lifetime, slice shape, release cadence, how much is in flight, whether it ships behind a flag — turns out to be the same choice wearing different clothes: how long you are willing to be wrong without finding out. This is not a claim about care. Careful work and careless work are equally wrong when the thing being built is not what was needed, and careful work stays wrong for longer.

Which is why the model names its own misreading up front. "Slow is smooth, and smooth is fast" is a claim about execution under known-correct intent, and in delivery the target is exactly what is in dispute. Smoothness is real and it belongs here — but slow is not what makes you smooth. Cheap is.

The five segments of the loop

  1. 01

    Commit

    Deciding what you are going to be wrong about, in a form that can lose. Not "if adoption is poor" — "if fewer than a third of branches use it by March".

    Why you can't skip it A loop with no commitment cannot close. If nothing was claimed, no observation can contradict it and every result reads as partial success. The trap: a goal is what you want; a bet is what you would accept as evidence that you were wrong to want it.

  2. 02

    Slice

    The shape of the thing you will build before you look. Thin and whole: one narrow journey running end to end, in production, for someone real, with everything else honestly absent rather than half-present.

    Why you can't skip it This is the size term of exposure, and it is the term people actually control. The test is brutal and simple: can a real person get a real outcome from this, today? If the answer needs a "once we also…", it is not a slice.

  3. 03

    Expose

    Getting it in front of reality. Deploy and release are separate events: the code is out, and who sees it is a decision you can change in seconds and reverse without a meeting.

    Why you can't skip it Reality is the only instrument that answers this question. Internal review, however senior, is a simulation of the answer produced by people who already share the assumption being tested.

  4. 04

    Observe

    Whether reality can actually answer the question you committed to. The measure existed before the release, and it can move against you — a metric that only goes up is a scoreboard, not an instrument.

    Why you can't skip it This is where most loops silently fail to close. The thing shipped, nobody was lying, and no one ever established whether it worked — so the exposure never resolves, it just stops being discussed.

  5. 05

    Correct

    Acting on the answer, including — especially — stopping. Something has actually been killed: not descoped, not paused. Stopped, on the evidence, by the people who wanted it.

    Why you can't skip it A loop that cannot change the plan is a reporting cycle, and running it faster produces reports faster. Agree at segment 01 who decides and on what date, or the kill decision becomes a referendum on somebody's judgement and never gets taken.

The mechanic

Exposure = size × time. The amount of wrong you are carrying is how much you built multiplied by how long you went before reality answered. It is an area, not a point.

Both terms are yours. Halve the slice and halve the cycle and exposure falls to a quarter — which is the whole mechanism behind small batches, and why the effect feels disproportionate to the change. Craft does not appear in the formula: it governs how often you are wrong, not how long you stay wrong. Neither does velocity. An organisation can raise its correction rate while shipping less, and frequently should.

The two foundations

Reversibility

How cheaply you can undo it. A team that cannot roll back is not being careful when it delays — it is being correct, given its constraints. Fix the constraint and the caution evaporates on its own.

The honest test: when was the last rollback, and did anyone have to be woken up?

Loop cost

What it costs to run the loop once, in time, money and ceremony. This is where "smooth is fast" is true, and the only place: a release that costs three weeks of coordination cannot be run monthly.

The honest test: how long from decided to in front of someone real — measured, not estimated. Most organisations have never measured it and are out by a factor.

Neither is ever the verdict. "Invest in your pipeline" is not a next move for a team that has just been told its loop is open; it is a budget conversation, and it belongs in a different meeting from this one.

The failure modes

  • The Careful Disaster. High craft, huge batch, long cycle. Recognise it by how defensible everything is: the process was followed, the work is good, and the thing is not wanted.
  • The Open Loop. Shipped, never observed. Recognise it by the absence of anyone who can say whether the last three releases worked — asked directly, people describe what was delivered rather than what changed.
  • The Unkillable Bet. Segment 01 was written as an aspiration, so no evidence can retire it. Recognise it by a project that has been "nearly there" through two changes of sponsor.
  • The Smooth Runway. A beautifully automated loop around a question nobody asked. Recognise it by excellent delivery metrics and a flat business.
  • Motion Without Correction. Short cycles, small batches, no observation. Recognise it by teams who are exhausted, shipping constantly, and cannot name a decision that changed because of something they learned.
  • The Simulated Answer. Exposure replaced by internal review. Recognise it by "we walked the exec team through it" standing where a user would be.

Where they come from

Each model is the structural expression of one part of Digital Optimism — the position the whole practice rests on. Four parts, and not one of them is optimism about outcomes.

Digital Optimism Becomes
01 · Progress is structural, not instantaneous Orders of Consequence — because judging in between produces a confident false negative
02 · Sustained investment; maturity is not for sale The Digital Maturity Pyramid — you can't leapfrog the layers, you can speed-run them
03 · You cannot optimise what you do not understand The Narrowing — end to end, before you touch any part of it
04 · Continuous, natural refinement The Correction Rate — you go faster by being wrong sooner

A model invented to fill a gap in a curriculum is a framework. A model that falls out of a position you already hold, and that you have already argued for in front of a room, is a claim. These are the second kind.

What makes something a keystone model

Six rules. The Pyramid satisfies all six, which is why it works, and the other three were built against them. Anything proposed as a fifth is held to them too.

  1. An ordered structure with a stated dependency law. Not stage theory — an argument, per element, for why the one below is consumed by the one above. Every "why you can't skip it" is a specific input dependency, not an assertion about maturity.
  2. A sharp mechanic, not an average. The test: state the mechanic in one sentence without using the word "framework". min() passes. If it needs a paragraph, it is not a mechanic, it is a diagram.
  3. Two foundations, reported but never the verdict. Every model carries two foundations under it and the same refusal to name either as the answer. A foundation explains; it does not instruct.
  4. A refusal built into the name. "You can't leapfrog the layers. You can speed-run them." The model pre-empts its own worst misreading in the same breath as its claim, because the misreading will otherwise arrive within a minute of the slide.
  5. Named failure modes, as characters. The leapfrogger, the laggard, the speed-runner. Not "common pitfalls" — people, with behaviour you can recognise in your own organisation. A failure mode nobody can see themselves in has not been named yet.
  6. Declared limits, and declared provenance. "A starting position to argue with, not a rating to defend." The instruction is to refuse to defend the formula and re-ask the question the formula was standing in for. And naming what you read is not a concession that the model is derivative — it is the thing that lets you say precisely where you depart, which is where the model actually lives.

How a session closes

A session on any of these does not close on a summary. It closes on decisions. The Pyramid spends its last fifteen minutes getting two of them made, because a strategy with no number is an aspiration and accountable means one name — not consulted, not "all of us". Each model names what its session has to produce. If you get nothing else, get those.

Model The session must produce
Pyramid A budget figure, and one accountable name
Orders of Consequence The order this change will be judged at, and the date — agreed before it starts
The Narrowing The next test, and what it will rule out — written down before it is run
The Correction Rate What would make you stop, and when you will look

Three of the four have no instrument yet. When they get one it will be shaped like the maturity assessment and inherit its rules: statements about what you did last quarter rather than what you believe, unanswered scoring zero so a partial take reads as low rather than as flatteringly average, and own-data only — because a manager reading a self-report as a performance review turns an honest answer into a defended one, and the measurement destroys itself.