Nothing reached the gate
The agent has been doing this for eight months. It reads approved tickets, renders them into firewall configuration, verifies the result against intent, and closes the loop. It is good at the job: faster than the network team it replaced, and it does not mistype an address at the end of a long shift. A change ticket arrives at 23:40. This ticket asks for a route from an engineering workstation segment to the historian database on the process network. The agent evaluates it against the policy set and finds it outside the permitted space: no path crosses into the process network without conditions the ticket does not carry. Execution stops. ...
The evidence starts too late
The hinge ended with a person doing the comparing: for example, an analyst who takes what the systems report, holds it against what is actually happening, and decides which of the two to believe. Route around that job in one place and it reappears in another. So the obvious next proposal: give the comparing to a model. Let it read the alerts, the tickets, the risk register and the audit evidence, and make the call. It reads faster, never tires, never has a bad Tuesday, and holds more in one context window than a shift of analysts holds in a year. ...

The hinge in the attention argument
Cassie Kozyrkov’s question is a good one: if machines now do the doing, what is left for leadership? Her answer is attention. Leadership becomes the design of what machines notice, optimise and repeat. That is a useful shift, but the argument becomes more interesting if Ashby’s law and Lewin’s field theory are read a little more literally than the familiar management versions allow. Ashby’s law does not say that a controller has to be as complex as the system it governs. It says that the regulator’s variety has to cover the variety of disturbances, relative to the outcomes that have to remain within limits. That difference gives two ways of closing the gap: increase the variety available to the regulator, or reduce the variety arriving at it. ...

All of it would survive an audit
The Monday report is accurate and on time. Its third column has a name that made sense to whoever built it, and that person moved teams in 2021. Everyone who reads it knows roughly what the column counts, and no two of them would write the same sentence about it. Down the corridor a working group is meeting for the fourth time. It has a chair, terms of reference and eleven open actions, three of them carried over from the group that came before it. What it was convened about happened again in September. ...
Concerns as an organising principle
The reorganisation was announced in October. Four directorates became three, the data team moved out of IT into a function called Information and Insight, two roles went and three were created. The intranet A to Z was updated inside a fortnight. By April the new structure was being asked what the old one had been asked: who owns this, why it broke at the handover, why it was found so late, and why nobody had the whole picture. ...
The organisation without a model of itself
In March a new starter sat for a week without a login. Six people met four times and recommended a pre-start checklist. The checklist was adopted. In September a new starter sat for a week without a login. The March report named three causes: unclear ownership of onboarding, a communication gap between IT and HR, and a need for better forecasting of start dates. All three were true. January, February, March In January IT consolidated identity management onto one platform. The licence cost fell, and provisioning moved from on request to a nightly run. ...
Why maturity models disappoint
The assessors came for three days in October. The evidence pack ran to 412 documents, 61 of them written that fortnight. The verdict was level three of five, with a roadmap to level four. The certificate hangs by the lift. In November a release went out without a rollback plan, the way releases had always gone out. Policies, minutes, screenshots Policies. Process descriptions. Minutes. Review schedules. Screenshots of the pipeline configuration. Nine interviews. None of it was untrue. ...
AI is exposing old organisational weaknesses
The assistant went live on a Tuesday, indexed the intranet, and was asked by somebody about to resign what notice period applies. It answered three months, quoting a policy page from 2019. The answer has been one month since the 2022 handbook. The pilot review recorded a hallucination. The model had not hallucinated. It had read the intranet. Nobody had taken the 2019 page down. There was never a reason to. The people reading it were checking a rule that applied to them, and they knew to go past it to the handbook. The ones who did not know asked somebody who did. The page does not link to the handbook, and the handbook does not link to the page. ...
Why intelligent people disagree while using exactly the same words
Four people leave a meeting agreed about the risk of moving payroll to a new provider in January. The minute says so, and none of them has reason to doubt it. In the room, the payroll manager meant the chance that the first run would come out wrong. Finance meant what it would cost to put right. Legal meant who would answer for wages paid late. The programme lead meant the three months of roadmap a parallel run would eat. All four said risk, all four heard risk, and nothing in the hour gave any of them cause to check. ...
Most organisations do not have an information problem
A familiar ritual follows organisational trouble. A decision goes wrong, a delivery slips, a risk materialises that somebody somewhere had documented, and the retrospective lands on a convenient conclusion: the information wasn’t good enough. The remedy writes itself. Another dashboard. A new report. A data lake, properly governed this time. An AI pilot to surface insights. More policy on how information ought to flow. The ritual is comfortable because it frames the problem as scarcity, and scarcity has an obvious cure. A walk through almost any large organisation suggests no shortage at all. Dashboards refresh nightly and go unwatched. The same metric appears in three decks with three different values. Reports run on schedules nobody remembers setting, for audiences nobody has confirmed still exist. Meetings re-litigate facts that were settled in other meetings. The organisation is not starving. It is standing in a warehouse of maps, unsure which one describes the territory outside. ...