Q2: Demand segmentation for fast-path vs controlled-path flow
- Three classification axes (risk level, reversibility, and standardisation) appear independently across ITIL 4, SRE, Reinertsen's product development flow, and healthcare triage as the operative criteria for segmenting fast-path from controlled-path demandAXELOS (2019)Challoner et al. (2018)Reinertsen (2009)Ahrq (n.d.)
- ITIL 4 Change Enablement defines three change types (standard, normal, and emergency) where standard changes are pre-authorised because they are low-risk, documented, and repeatable, and normal changes require per-instance risk and impact assessment with Change Advisory Board approvalAXELOS (2019)
- Reinertsen's four classes of service (expedite, fixed-date, standard, and intangible) are defined by cost of delay profile and each implies a handling policy that cannot be derived from organisational status or requester seniorityReinertsen (2009)
- DORA research shows that elite technology delivery teams achieve high deployment frequency and low change failure rate simultaneously, a result consistent with demand segmentation that routes low-risk standard work through automated pre-approved lanes and high-risk novel work through controlled review lanesDORA (2024)Alvidrez (2017)
- Three observable boundary tests (template test: a pre-approved documented pattern exists; recovery test: the failure mode has been tested with a validated rollback procedure; blast radius test: potential impact is contained within a defined boundary) operationalise class assignment without requiring specialist risk knowledge at intake timeAXELOS (2019)Alvidrez (2017)Reinertsen (2009)
- The healthcare triage principle that under-triage (routing a high-acuity patient to the fast track) is a patient safety failure while over-triage (routing a low-acuity patient to the main track) is only a capacity waste translates directly to work intake design, establishing conservative boundary classification as a safety propertyAhrq (n.d.)Mitchell (2026)
- Two-class segmentation (fast and controlled only) is insufficient in a split-authority delivery system because it collapses routine assessed work and genuinely exceptional high-consequence items onto the same controlled path, intensifying the bottleneck and reproducing the queue fragmentation failure mode identified in the organisational failure modes evidenceGithub (n.d.)Mitchell (2026)
- Applying full pre-approval controls to Class 1 (fast-path) work converts an enabling governance control into a coercive one, generating queue congestion without proportionate risk reduction because the control intensity no longer matches the transaction hazardMitchell (2026)Ed (n.d.)
Research Question
Which work items are low-risk, standard, and reversible enough for fast-path handling, and which require slower expert review or tighter controls?
Findings
Executive Summary
Work items should be classified on three axes (risk level, reversibility, and standardisation) and assigned to one of three demand classes: Class 1 (fast path, pre-authorised), Class 2 (standard path, assessed per-instance), and Class 3 (exception path, full expert review). Three classes are the minimum viable number: fewer collapse distinct control requirements onto the controlled path, intensifying the bottleneck, while more add classification overhead without distinct control actions. This three-class structure is the common abstraction across ITIL 4 Change Enablement, Site Reliability Engineering practice, Reinertsen's product development flow classes of service, and clinical triage systems, providing convergent cross-domain evidence for its robustness. When boundary tests produce ambiguous results, conservative classification (assigning to a higher-control class) is the correct default because the governance failure cost of under-classifying a high-risk item exceeds the throughput cost of over-classifying a low-risk item.
Key Findings
-
Three classification axes (risk level, reversibility, and standardisation) appear independently across ITIL 4, SRE, Reinertsen's product development flow, and healthcare triage as the operative criteria for segmenting fast-path from controlled-path demand.
-
ITIL 4 Change Enablement defines three change types (standard, normal, and emergency) where standard changes are pre-authorised because they are low-risk, documented, and repeatable, and normal changes require per-instance risk and impact assessment with Change Advisory Board approval.
-
Reinertsen's four classes of service (expedite, fixed-date, standard, and intangible) are defined by cost of delay profile and each implies a handling policy that cannot be derived from organisational status or requester seniority.
-
DORA research shows that elite technology delivery teams achieve high deployment frequency and low change failure rate simultaneously, a result consistent with demand segmentation that routes low-risk standard work through automated pre-approved lanes and high-risk novel work through controlled review lanes.
-
Three observable boundary tests (template test: a pre-approved documented pattern exists; recovery test: the failure mode has been tested with a validated rollback procedure; blast radius test: potential impact is contained within a defined boundary) operationalise class assignment without requiring specialist risk knowledge at intake time.
-
The healthcare triage principle that under-triage (routing a high-acuity patient to the fast track) is a patient safety failure while over-triage (routing a low-acuity patient to the main track) is only a capacity waste translates directly to work intake design, establishing conservative boundary classification as a safety property.
-
Two-class segmentation (fast and controlled only) is insufficient in a split-authority delivery system because it collapses routine assessed work and genuinely exceptional high-consequence items onto the same controlled path, intensifying the bottleneck and reproducing the queue fragmentation failure mode identified in the organisational failure modes evidence.
-
Applying full pre-approval controls to Class 1 (fast-path) work converts an enabling governance control into a coercive one, generating queue congestion without proportionate risk reduction because the control intensity no longer matches the transaction hazard.
-
Delivery-operations demand (BAU change, minor enhancement, incident response) and build-mode demand (novel capability delivery) accumulate independently, and a segmentation scheme that ignores this distinction risks misclassifying high-volume BAU work as exception-path simply because no pre-approved template exists yet, rather than because the work is genuinely novel or high-consequence.
Assumptions
-
Four or more demand classes add classification overhead without operationally distinct control actions. Justification: no evidence identifies a fourth mandatory class with a distinct control form; Reinertsen's four types and ITIL 4's three types both reduce to three distinct control policies when mapped by action rather than demand characteristic.
-
The three boundary condition tests can be administered reliably without specialist risk knowledge, given a maintained template catalogue and blast radius tooling. Justification: ITIL 4 requires standard change classification to be operable without per-instance specialist review; SRE toil criteria are designed to be self-evident from change documentation.
Analysis
The weight of evidence supports the three-class demand model, but the model is grounded in cross-domain inference rather than a published empirical study of split-authority delivery segmentation. Each individual source provides primary evidence for a specific domain (ITIL 4, SRE, Reinertsen, clinical triage); the inference that they converge on the same classification structure is the substantive synthesis claim.
The principal alternative model is a single-axis risk score. This analysis rejects the single-axis risk score model on the grounds that risk level alone does not determine the correct control action: a high-risk but fully reversible item with a tested rollback procedure should travel the standard path, not the exception path. Reversibility is an independent axis that modifies the risk interpretation.
This analysis rejects a four-class model (splitting Class 2 into bounded-low and bounded-high sub-classes) on the grounds that the control actions for both sub-classes are assessed pre-approval; the difference would be in approval authority level, not control form. Routing to different approval authority levels is a decision rights placement question (Q4), not a segmentation question. A four-class model adds classification overhead without a corresponding distinct control action at the new boundary.
ITIL 4 Change Enablement endorses automated pre-approval for low-risk changes in the same framework that defines controlled paths for high-risk ones, removing the apparent incompatibility between ITIL and DevOps segmentation approaches.
The completed item on AI and low-code risk tier classification found that risk tiers for AI-generated and low-code work use the same axes (risk level, reversibility, and standardisation) as the three-class model proposed here, confirming that the classification structure generalises beyond IT service change management to software delivery work items. The completed item on human-in-the-loop AI automated workflows found that the boundary between automated handling and mandatory human review is determined by reversibility and blast radius of the automated action, which maps directly to the Class 1 versus Class 2/3 boundary tests defined in this item.
Risks, Gaps, and Uncertainties
- No published study directly tests the three-class demand model in a split-authority delivery context; the evidence base is cross-domain inference.
- The blast radius test requires maintained dependency mapping tooling; without it, the test degrades to subjective judgment.
- The template test requires active catalogue governance; without it, Class 1 items accumulate in Class 2 over time as templates become stale.
- Items near class boundaries will be inconsistently classified without a maintained calibration and monitoring regime.
- The conservative classification default generates some Class 2 overhead for items that would correctly be Class 1. This overhead is the cost of the safety property, not a design failure.
Open Questions
- How should a split-authority system handle mid-execution class reassignment when a Class 1 item encounters an unexpected complication? (Q3 scope)
- What classification rate, reclassification rate, and mis-classification incident data should be collected to validate and calibrate the three-class model over time? (Q6 scope)
- Does the demand stream distinction (BAU versus build-mode) require an explicit field in the intake form, or is it derivable from the boundary tests? (Q3 scope)
- Can automation accelerate template creation from historical change records, reducing the initial classification overhead of building a Class 1 catalogue? (tooling question, outside current scope)
Output
- Type: knowledge
- Description: A three-class demand segmentation model with three observable boundary tests, grounded in convergent evidence from ITIL 4, SRE, Reinertsen's product development flow, and clinical triage, directly enabling Q3 routing design, Q5 control model trade-off analysis, Q6 leading indicator design, and Q1 flow constraint validation.
- Key sources:
sources
- [x] Reinertsen, D.G. (2009) The Principles of Product Development Flow: Second Generation Lean Product Development, Celeritas Publishing -- classes of service and cost of delay segmentation criteria
- [x] PeopleCert / AXELOS (2019) ITIL 4 Change Enablement Practice Guide -- standard, normal, and emergency change type definitions
- [x] Challoner et al. (2018) Site Reliability Engineering Workbook: Eliminating Toil -- standard change automation and toil reduction criteria
- [x] Alvidrez, M. (2017) Site Reliability Engineering: Embracing Risk -- risk continuum and service level classification
- [x] DORA (2024) DORA Metrics and Four Keys -- change lead time, change failure rate, and deployment frequency segmentation evidence
- [x] TOC Institute (2024) Five Focusing Steps -- constraint exploitation and flow segmentation
- [x] Mitchell (2026) Operating model synthesis for split-authority delivery systems -- B1-B2 demand segmentation synthesis
- [x] Mitchell (2026) Internal governance controls: effectiveness conditions in regulated enterprises -- control proportionality to transaction hazard
- [x] Mitchell (2026) Variance control comparison across delivery modes -- structural vs behavioural controls and pre-effect detection
| version | date | commit | summary |
|---|---|---|---|
| 1.0 | 2026-05-30 | a525c3d | Initial completion |