A decision discipline that converts ambiguous technology priorities into explicit, owned, and measurable choices. For engineering leaders and CTOs. Produces a Decision Record, quantified risk exposure, leading and lagging KPIs, and a fixed governance cadence.
Decision Context & Trigger
Define the decision before scoring risks. A trigger forces the choice now. Constraints bound the options. Success is a single measurable outcome at 90 days.
Trigger Examples
- Incident Post-Mortem: Three P0 outages in 60 days traced to a legacy component.
- Budget Cycle: Q3 allocation must choose between platform refactor and revenue features.
- Vendor EOL: Critical library reaches end-of-life in 90 days; migration or support contract required.
- Capacity Crunch: Hiring freeze limits engineering headcount to current roster for two quarters.
Constraints (document all that apply)
- Budget ceiling (e.g., $400k discretionary Q3 spend).
- Headcount availability (e.g., 6 engineers max for initiative).
- Compliance deadline (e.g., SOC2 Type II audit in 90 days).
- Technical debt ceiling (e.g., no new critical debt without CTO sign-off).
- Strategic OKRs (e.g., "Ship Enterprise SSO by Q4" vs. "Reduce MTTR 50%").
Success Definition (one sentence, measurable at 90 days)
"Reduce auth-related P1 incidents by 60% while delivering the Enterprise SSO feature, validated by incident metrics and feature flag adoption at Day 90."
Stakeholder Map & Ownership (RACI/DACI)
Assign a single Decision Owner. Committees do not decide. Use the table below to lock decision rights and risk accountability.
| Role | Name/Title | Decision Right | Risk Accountability |
|---|---|---|---|
| Decision Owner | CTO | Decide | Total portfolio risk exposure |
| Risk Owner | Platform Tech Lead | Own Risk | Legacy auth service risk score |
| Input Provider | VP Engineering | Input | Delivery capacity risk |
| Input Provider | Product Director | Input | Revenue feature delay risk |
| Approver | Security Lead | Approve | Compliance and breach risk |
| Input Provider | SRE Lead | Input | Operational stability risk |
| Informed | Engineering Managers | Inform | Team-level execution risk |
| Informed | CEO | Inform | Strategic and financial risk |
Rule: Only the Decision Owner (CTO) can change the decision after the Decision Record is published. All escalations route to the Decision Owner within 48 hours.
Risk Matrix Construction (The "How-To")
Build a 5x5 matrix with defined probability and impact scales. Calculate Risk Exposure = Probability × Impact. Draw a risk appetite threshold line: Tolerate ≤6, Mitigate 7–15, Escalate >15.
Probability Scale (1–5)
| Score | Label | Definition |
|---|---|---|
| 1 | Rare | <10% likelihood in the planning horizon |
| 2 | Unlikely | 10–30% likelihood |
| 3 | Possible | 30–60% likelihood |
| 4 | Likely | 60–90% likelihood |
| 5 | Almost Certain | >90% likelihood |
Impact Scale (1–5)
| Score | Label | Financial Definition | Time Definition |
|---|---|---|---|
| 1 | Insignificant | <$10k | <1 day |
| 2 | Minor | $10k–$50k | 1 week |
| 3 | Moderate | $50k–$250k | 1 month |
| 4 | Major | $250k–$1M | 1 quarter |
| 5 | Catastrophic | >$1M | >1 quarter |
5x5 Heat Map (Alt-Text Description)
A 5×5 grid with Probability (1–5) on the Y-axis and Impact (1–5) on the X-axis. Cells colored green (1–6), yellow (7–15), red (>15). A thick black diagonal line separates Tolerate (green) from Mitigate (yellow) at Exposure 6, and Mitigate from Escalate (red) at Exposure 15. Each cell shows the Exposure score (Probability × Impact). Risks plotted as numbered markers referencing the risk register.
Risk Register Example (Case Study Scoring)
| Risk ID | Risk Description | Probability | Impact | Exposure | Appetite Zone |
|---|---|---|---|---|---|
| R1 | Legacy auth service breach | 4 (Likely) | 5 (Catastrophic) | 20 | Escalate |
| R2 | Feature delay (Enterprise SSO) | 3 (Possible) | 4 (Major) | 12 | Mitigate |
| R3 | Refactor overrun >12 weeks | 3 (Possible) | 3 (Moderate) | 9 | Mitigate |
Options Analysis & Quantified Trade-offs
Evaluate a minimum of three options: Status Quo, Incremental, Transformative. Score each dimension. Use the table below to compare.
| Option | Estimated Cost | Delivery Time | Residual Risk Exposure | Opportunity Cost | Technical Debt Delta | Strategic Alignment (1–5) |
|---|---|---|---|---|---|---|
| Status Quo | $0 | 0 weeks | 20 (R1) | $600k ARR | +High | 2 |
| Incremental (Wrapper API) | $150k | 6 weeks | 12 (R2, R3) | $200k ARR | +Medium | 3 |
| Full Refactor | $400k | 12 weeks | 4 (R3 only) | $600k ARR | -High | 5 |
Interpretation: Status Quo leaves catastrophic breach risk (Exposure 20) unaddressed. Full Refactor eliminates breach risk but delays revenue features 12 weeks, costing $600k ARR. Incremental Wrapper reduces breach risk to Exposure 12 in 6 weeks at $150k, preserving optionality for Full Refactor in Q4.
KPIs & Measurement Plan
Define leading indicators (weekly) and lagging indicators (monthly/quarterly). Assign a Dashboard Owner and update frequency.
Leading Indicators (Weekly)
| KPI | Numerator / Denominator | Target | Dashboard Owner | Frequency |
|---|---|---|---|---|
| Risk Mitigation Action Closure Rate | Actions closed / Actions due | ≥80% | Risk Owner (Platform TL) | Weekly |
| Decision Cycle Time | Days from trigger to Decision Record publish | ≤14 days | Decision Owner (CTO) | Weekly |
| Stakeholder Confidence Pulse | Avg. score (1–5) across RACI roles | ≥4.0 | Decision Owner (CTO) | Weekly |
| Wrapper Test Coverage | Covered lines / Total lines (auth wrapper) | ≥85% | Risk Owner (Platform TL) | Weekly |
| Incident MTTR (Auth) | Mean time to resolve auth incidents | <30 min | SRE Lead | Weekly |
Lagging Indicators (Monthly/Quarterly)
| KPI | Numerator / Denominator | Target | Dashboard Owner | Frequency |
|---|---|---|---|---|
| Actual vs. Planned Risk Events | Count of risk events / Planned risk events | ≤1.0 | Risk Owner (Platform TL) | Monthly |
| Cost Variance | Actual spend / Budgeted spend | ±10% | VP Engineering | Monthly |
| Delivery Predictability | Features delivered on date / Features committed | ≥90% | Product Director | Monthly |
| Customer Impact Incidents | P1/P2 incidents affecting customers | 0 P1, ≤2 P2/qtr | SRE Lead | Monthly |
| Portfolio Risk Balance Shift | % risks in Escalate zone vs. prior quarter | Decreasing | Decision Owner (CTO) | Quarterly |
Governance Cadence & Escalation Path
Fixed cadence prevents drift. Each gate has a defined purpose, attendees, and output.
| Cadence | Meeting | Duration | Attendees | Purpose | Output |
|---|---|---|---|---|---|
| Weekly | Risk Owner Standup | 15 min | Risk Owner, SRE Lead, Platform TL | Action status, new risks, blocker escalation | Updated action tracker, new risk log entries |
| Monthly | Decision Owner Review | 60 min | Decision Owner, Risk Owner, VP Eng, Product Dir | KPI dashboard review, go/no-go on mitigation funding | Funding decision, Decision Record amendment if needed |
| Quarterly | Leadership Portfolio Review | 90 min | CTO, VP Eng, Security Lead, CEO | Risk appetite recalibration, strategic pivot check | Updated appetite thresholds, portfolio rebalancing |
Escalation Path
- Trigger: Any risk Exposure >15 (Escalate zone) or leading KPI misses target for two consecutive weeks.
- Action: 48-hour Decision Owner call with Risk Owner and relevant Input Providers.
- Documentation: Decision Record amended with new context, revised decision, or additional mitigation funding.
- Communication: Updated Decision Record distributed to all RACI roles within 24 hours of call.
Implementation Roadmap (30/60/90 Days)
| Phase | Days | Activities | Owner | Exit Criteria |
|---|---|---|---|---|
| Build | 1–30 | Align probability/impact scales; run first scoring workshop with RACI roles; populate risk register; publish Decision Record v1; set dashboard baseline. | Risk Owner (Platform TL) | Decision Record v1 signed by Decision Owner; dashboard live with Week 1 data. |
| Execute | 31–60 | Execute top 3 mitigations (Wrapper API development, auth monitoring hardening, test coverage push); instrument leading KPIs; conduct first Monthly Decision Owner Review. | Risk Owner (Platform TL), VP Eng | Wrapper API shipped to staging; leading KPIs green for 2 consecutive weeks; Monthly Review minutes published. |
| Calibrate | 61–90 | Quarterly Leadership Portfolio Review; recalibrate probability/impact scales based on actuals; document lessons learned; update Decision Record v2; greenlight/refactor Q4 plan. | Decision Owner (CTO) | Q4 refactor go/no-go decision recorded; lessons learned doc published; Decision Record v2 signed. |
Decision & Governance Checklist (Refined)
Print this table. Assign each item. Track status weekly.
| Check Item | Owner | Due | Status | Evidence Link |
|---|---|---|---|---|
| Decision trigger documented | Decision Owner (CTO) | Day 1 | Done | Incident post-mortem #2024-07-15 |
| Probability/impact scales agreed | Risk Owner (Platform TL) | Day 5 | Done | Workshop Miro board v1 |
| Risk register populated (min 5 risks) | Risk Owner (Platform TL) | Day 10 | Done | Risk register v1.2 |
| Decision Record v1 published | Decision Owner (CTO) | Day 14 | Done | Confluence page #DEC-2024-042 |
| RACI confirmed with all roles | Decision Owner (CTO) | Day 14 | Done | Email thread 2024-07-18 |
| Dashboard live with leading KPIs | Risk Owner (Platform TL) | Day 21 | In Progress | Grafana dashboard #risk-auth |
| Top 3 mitigations scoped & staffed | VP Engineering | Day 30 | Not Started | — |
| First Monthly Review completed | Decision Owner (CTO) | Day 45 | Not Started | — |
| Quarterly Portfolio Review scheduled | Decision Owner (CTO) | Day 75 | Not Started | Calendar invite sent |
| Lessons learned documented | Risk Owner (Platform TL) | Day 90 | Not Started | — |
Concrete Technology-Organization Case Study: Platform Refactor vs. Feature Velocity at Mid-Series B SaaS Co (120 Engineers, $18M ARR)
Trigger
Three P0 incidents in 60 days linked to legacy authentication service. CTO must decide Q3 budget allocation before August 1 planning freeze.
Decision Context
- Refactor Budget: $400k available in Q3 discretionary fund.
- Revenue Risk: Two delayed features carry $600k ARR risk if not shipped by Q4.
- Capacity Constraint: Maximum 6 engineers can be allocated without delaying other commitments.
- Compliance Deadline: SOC2 Type II audit window opens in 90 days; auth service is in scope.
Stakeholder Map (Populated)
| Role | Name/Title | Decision Right | Risk Accountability |
|---|---|---|---|
| Decision Owner | CTO (A. Chen) | Decide | Total portfolio risk exposure |
| Risk Owner | Platform Tech Lead (M. Rodriguez) | Own Risk | Legacy auth service risk score |
| Input Provider | VP Engineering (S. Patel) | Input | Delivery capacity risk |
| Input Provider | Product Director (J. Kim) | Input | Revenue feature delay risk |
| Approver | Security Lead (R. Okonkwo) | Approve | Compliance and breach risk |
| Input Provider | SRE Lead (L. Nguyen) | Input | Operational stability risk |
Risk Matrix Scoring (Populated)
| Risk ID | Risk Description | Probability | Impact | Exposure | Appetite Zone |
|---|---|---|---|---|---|
| R1 | Legacy auth breach | 4 (Likely) | 5 (Catastrophic) | 20 | Escalate |
| R2 | Feature delay (Enterprise SSO) | 3 (Possible) | 4 (Major) | 12 | Mitigate |
| R3 | Refactor overrun >12 weeks | 3 (Possible) | 3 (Moderate) | 9 | Mitigate |
Options Table (Populated)
| Option | Estimated Cost | Delivery Time | Residual Risk Exposure | Opportunity Cost | Technical Debt Delta | Strategic Alignment (1–5) |
|---|---|---|---|---|---|---|
| Status Quo | $0 | 0 weeks | 20 (R1) | $600k ARR | +High | 2 |
| Incremental (Wrapper API) | $150k | 6 weeks | 12 (R2, R3) | $200k ARR | +Medium | 3 |
| Full Refactor | $400k | 12 weeks | 4 (R3 only) | $600k ARR | -High | 5 |
Decision
Incremental Wrapper (Phase 1) + Full Refactor approved for Q4 contingent on Phase 1 risk reduction ≥50%.
Rationale: Wrapper API reduces breach exposure from 20 to 12 in 6 weeks at $150k, buying data for Q4 go/no-go. Full Refactor remains funded in Q4 budget ($350k) if wrapper achieves ≥50% reduction in auth-related P1 incidents.
KPIs (Case Study Specific)
| KPI | Type | Target | Owner | Frequency |
|---|---|---|---|---|
| Wrapper test coverage % | Leading | ≥85% | Platform TL | Weekly |
| Auth incident MTTR | Leading | <30 min | SRE Lead | Weekly |
| Auth-related P1 count | Lagging | 60% reduction vs. baseline | Platform TL | Monthly |
| Feature delivery % (Enterprise SSO) | Lagging | 100% by Q4 | Product Dir | Monthly |
| Refactor go/no-go gate | Lagging | Decision by Day 90 | CTO | Quarterly |
90-Day Outcome (Documented)
- Week 7: Wrapper API shipped to production behind feature flag.
- Week 8–12: Auth-related P1 incidents dropped 60% (from 3 in prior 60 days to 0 in 30 days post-launch).
- Day 90: Quarterly Portfolio Review — Full Refactor greenlit for Q4 with $350k budget and 8-engineer allocation. Decision Record v2 published.
Decision Record Template (Filled for Case Study)
| Field | Entry |
|---|---|
| Context | Three P0 incidents in 60 days caused by legacy auth service. SOC2 audit in 90 days. $400k Q3 budget. 6-engineer capacity cap. Two revenue features ($600k ARR) competing for same capacity. |
| Options | 1) Status Quo — accept breach risk. 2) Incremental Wrapper API — $150k, 6 weeks, reduces breach exposure to 12. 3) Full Refactor — $400k, 12 weeks, reduces breach exposure to 4 but delays revenue features. |
| Decision | Approve Incremental Wrapper (Phase 1) for immediate execution. Approve Full Refactor for Q4 contingent on Phase 1 achieving ≥50% reduction in auth-related P1 incidents by Day 90. |
| Owner | CTO (A. Chen) |
| Review Date | Day 90 (Quarterly Portfolio Review) — October 15, 2024 |
| Success Metrics | Wrapper test coverage ≥85%; auth P1 count 60% reduction; Enterprise SSO on track for Q4; refactor go/no-go gate passed. |
| Escalation Path | Risk Exposure >15 → 48-hour CTO call → Decision Record amendment → distribute to RACI within 24 hours. |
Printable Decision & Governance Checklist (Populated for Case Study)
| Check Item | Owner | Due | Status | Evidence Link |
|---|---|---|---|---|
| Decision trigger documented (3 P0s) | CTO (A. Chen) | 2024-07-15 | Done | Post-mortem #2024-07-15 |
| Probability/impact scales agreed | Platform TL (M. Rodriguez) | 2024-07-20 | Done | Workshop notes v1 |
| Risk register populated (R1–R3) | Platform TL (M. Rodriguez) | 2024-07-25 | Done | Risk register v1.2 |
| Decision Record v1 published | CTO (A. Chen) | 2024-07-29 | Done | Confluence #DEC-2024-042 |
| RACI confirmed with all 6 roles | CTO (A. Chen) | 2024-07-29 | Done | Email 2024-07-29 14:32 |
| Dashboard live (5 leading KPIs) | Platform TL (M. Rodriguez) | 2024-08-05 | Done | Grafana #risk-auth |
| Wrapper API scoped & staffed (4 eng) | VP Eng (S. Patel) | 2024-08-12 | Done | Jira Epic #PLAT-882 |
| First Monthly Review completed | CTO (A. Chen) | 2024-08-26 | Done | Meeting notes 2024-08-26 |
| Quarterly Portfolio Review held | CTO (A. Chen) | 2024-10-15 | Done | Meeting notes 2024-10-15 |
| Lessons learned documented | Platform TL (M. Rodriguez) | 2024-10-15 | Done | Confluence #LL-2024-042 |
| Refactor greenlit for Q4 ($350k) | CTO (A. Chen) | 2024-10-15 | Done | Decision Record v2 |
Conclusion
Run the Risk Matrix Decision Framework on one live initiative this week. Define the trigger, constrain the options, assign a single Decision Owner, score risks with the 5×5 matrix, publish a Decision Record, and set the first review date. The framework makes disagreement visible early, shows why a choice was made, and creates a governed path to adjust when evidence changes. Revisit at the next planning cycle to confirm the decision still holds given new incidents, shifted priorities, or changed constraints.