Coordinate and act
The Control Map
Map who can see and stop each step
Draw every controller in a workflow, person and machine, and find the moments where control fails.
Borrowed from System-Theoretic Process Analysis (STPA), a safety method developed by Nancy Leveson at MIT. Read the original source.
One session · An hour or more to set up · Needs senior backing
Try this first
Draw one workflow on a whiteboard. Mark every point where a person can stop the machine. Count them.
Use it when
AI has taken over steps in a workflow and nobody in the room can say who is accountable for a bad output, or who would catch one.
Skip it when
It needs a workflow the room knows well and can bound. On a vague or brand-new process there is nothing accurate to draw, and the map becomes a wish.
How to introduce it
We are going to draw this workflow as a set of controllers. Anything that can take an action counts, whether it is a person, a team, or a model. For each one, we mark what it can do, what it can see, and who can stop it. Then we look for the four ways any of those actions goes wrong. Safety engineers use this to find failures in systems where nothing broke and the system still failed.
How to show up
Keep the room drawing rather than debating. Push for the actual current state instead of the intended one. When someone says the model just recommends, ask what happens when a recommendation is never overridden.
How long it takes
Half a day for one bounded workflow. A full analysis takes longer and this is the first pass.
What makes it hard
People draw the org chart instead of the control structure, so the first pass usually shows reporting lines rather than who can act. The other hard part is that a half-day gets you a first pass. Say so, or the room will leave thinking the analysis is finished.
What it looks like when it's working
The team can point at a specific step and name who would catch a bad output there. Vague answers about review processes mean the map has not been drawn honestly.
How long until it sticks
Two or three workflows before the room stops drawing reporting lines and starts drawing control.
How you know it stuck
New workflows get mapped before they go live rather than after something goes wrong.
The idea behind it
Nothing has to break for this to go wrong. Every part can work as designed and the system can still produce a bad outcome, because the parts interact in a way nobody drew.
Where it comes from
Systems safety. An AI agent is a controller. It acts, it gets feedback, and its picture of the process can be wrong. The map shows where a person can still step in, and where that point has closed. The team draws every controller in one workflow, person and machine. What each can do, what each can see, who can stop whom. Then it walks the four ways any of those actions goes wrong.
Why it matters for senior teams
Only a senior team can install it
Pairs with
How Did You Know?, which supplies what the human controller actually knows. Real Independence, which decides whether a check is a check.