Every organisation I have worked in has had a document that everyone cites and nobody follows.
Somebody wrote it because they cared about it. They enforced it for a while, and enforcing it meant refusing things. Refusals cost them meetings, goodwill, and at least one working relationship. Then they moved on.
The document stayed. Nobody withdrew it. Nothing broke that anyone traced back to it. It is still on the intranet, still handed to new joiners, still quoted in a design review when somebody needs to win an argument. It simply stopped changing what anyone does, and there was no day on which that happened.
I have written one of those documents. Post 12 was about what it cost to keep it.
That is where this season ended up. It is not where it started.
The claim I opened with
Capability decides nothing on its own. The structure placed around a capability decides what it becomes.
I called that structure a harness, and Post 2 gave it its cleanest form. The model reasons. The harness decides what matters.
It is a good argument. It is also the argument a technology function reaches for when a board asks how an AI programme will be kept safe. The answer the board hears is a control framework. The answer the board is buying is that somebody will say no when it counts, on a day when saying no is expensive.
Where it came apart
The objection to my own argument was sitting in Post 3, and I did not see it for another nine posts.
A guardrail without enforcement is a wish.
I read that at the time as advice. Write good guardrails, then make sure they are enforced. Two tasks, both of them mine to design.
Read it again and it sets a limit instead. A guardrail is a rule. A rule does not apply itself. A person applies it, and that person has to be willing to apply it on the day doing so is expensive. So the thing deciding the outcome was never the guardrail. It was whoever was standing behind it.
I missed it because I was looking for the weakness in the wrong place. I expected a technical hole. This was a human one.
The same shape then turned up in four more posts, and I treated each as a separate subject.
Post 8 was about debt an institution already knows it carries. Someone has to price the delay before the market does it for them, and whoever prices it early becomes unpopular for it.
In Post 9 the subject was proof. A proof filed once stops being a proof. Someone has to keep being able to give it.
Post 10 dealt with work that prevents failure. It leaves no trace, so someone has to keep defending a budget with nothing to point at.
Then Post 11, on failures that carry on after the cause is fixed. Someone has to keep watching a thing that already looks solved.
Four subjects, one shape underneath. In every case the structure was in place. In every case it held only while a person was carrying a cost, and nothing in the system noticed the day they stopped.
Post 12 finished it. An institution never inherits a rule. It inherits the memory of what the rule cost the person who kept it.
So here is the correction. A harness is not something you install. It is a position somebody occupies. It works for as long as that person is visibly bound by it and pays something for staying bound. Take the person out and you do not get a failure. You get the document.
The obvious objection, which I have made myself
Automate the enforcement. Put the standard in the pipeline, fail the build, and the problem of the departing enforcer disappears.
It does not disappear. It moves.
An automated control still has to be kept current as the estate changes underneath it. Exceptions still have to be granted, and every exception is a refusal somebody decided not to make. In more than one organisation over the years I have seen a gate that still runs, still reports green, and carries a permanent exception list longer than the rule it enforces. The build passes. Nobody is bound by anything.
Automation gives you better evidence that a control ran and worse evidence that anyone is still standing behind it. You end up with the document either way. It just executes on a schedule.
What writing it revealed
I set out to write a season about design and finished writing one about people.
The drafts that stalled were always the same kind. I would be three quarters of the way through, reaching for the control that would make the argument close, and there would not be one. A gate. A standard that enforces itself once installed. Something I could specify and hand over. Each time, the sentence I was avoiding turned out to be about who was carrying the cost.
That is an uncomfortable finding for someone whose instinct is architectural. It is also the only one the evidence supported.
To everyone who read, replied, or disagreed in the comments. Thank you. The disagreements changed more of this season than the agreements did.
Where that leaves the governing sentence
I would not withdraw the sentence I opened with. I would add a line to it.
When the system can do anything, leadership is defined by what it chooses not to become, and by who is still paying to hold that choice in place.
Choosing is the easy half. Every institution can choose. Most have a principles page to prove it. The hard half comes after the person who made the choice has gone, and I have not seen an institution solve that part.
Three things I take as settled at the close of the season.
Capability is no longer the constraint. Designing as though it still is puts the controls in the wrong place.
A structure changes behaviour only while someone is bound by it and pays for staying bound.
Control testing shows that a control ran. Whether anyone is still bound by it is a separate question, and it is rarely asked.
The question I am left with
If an institution is held together by a cost somebody is still paying, then succession is a harder question than who takes the role. The one that matters is who has paid enough to know what the role is for.
A great deal of what is being automated right now sits directly on top of that question. I have not seen it asked. It is where I am going next.
An institution never loses its standards. It loses the person who was paying for them, and from the inside those two look identical.
If you found this useful, the likelihood is someone you know is asking the same question. Pass it on.


