Q2: Demand segmentation for fast-path vs controlled-path flow

2026-05-29 · governance-policy organisational-design cost-performance tools-infrastructure enterprise-adoption · medium · source → · wiki →
key claims
  1. Three classification axes (risk level, reversibility, and standardisation) appear independently across ITIL 4, SRE, Reinertsen's product development flow, and healthcare triage as the operative criteria for segmenting fast-path from controlled-path demandAXELOS (2019)Challoner et al. (2018)Reinertsen (2009)Ahrq (n.d.)
  2. ITIL 4 Change Enablement defines three change types (standard, normal, and emergency) where standard changes are pre-authorised because they are low-risk, documented, and repeatable, and normal changes require per-instance risk and impact assessment with Change Advisory Board approvalAXELOS (2019)
  3. Reinertsen's four classes of service (expedite, fixed-date, standard, and intangible) are defined by cost of delay profile and each implies a handling policy that cannot be derived from organisational status or requester seniorityReinertsen (2009)
  4. DORA research shows that elite technology delivery teams achieve high deployment frequency and low change failure rate simultaneously, a result consistent with demand segmentation that routes low-risk standard work through automated pre-approved lanes and high-risk novel work through controlled review lanesDORA (2024)Alvidrez (2017)
  5. Three observable boundary tests (template test: a pre-approved documented pattern exists; recovery test: the failure mode has been tested with a validated rollback procedure; blast radius test: potential impact is contained within a defined boundary) operationalise class assignment without requiring specialist risk knowledge at intake timeAXELOS (2019)Alvidrez (2017)Reinertsen (2009)
  6. The healthcare triage principle that under-triage (routing a high-acuity patient to the fast track) is a patient safety failure while over-triage (routing a low-acuity patient to the main track) is only a capacity waste translates directly to work intake design, establishing conservative boundary classification as a safety propertyAhrq (n.d.)Mitchell (2026)
  7. Two-class segmentation (fast and controlled only) is insufficient in a split-authority delivery system because it collapses routine assessed work and genuinely exceptional high-consequence items onto the same controlled path, intensifying the bottleneck and reproducing the queue fragmentation failure mode identified in the organisational failure modes evidenceGithub (n.d.)Mitchell (2026)
  8. Applying full pre-approval controls to Class 1 (fast-path) work converts an enabling governance control into a coercive one, generating queue congestion without proportionate risk reduction because the control intensity no longer matches the transaction hazardMitchell (2026)Ed (n.d.)

Research Question

Which work items are low-risk, standard, and reversible enough for fast-path handling, and which require slower expert review or tighter controls?

Findings

Executive Summary

Work items should be classified on three axes (risk level, reversibility, and standardisation) and assigned to one of three demand classes: Class 1 (fast path, pre-authorised), Class 2 (standard path, assessed per-instance), and Class 3 (exception path, full expert review). Three classes are the minimum viable number: fewer collapse distinct control requirements onto the controlled path, intensifying the bottleneck, while more add classification overhead without distinct control actions. This three-class structure is the common abstraction across ITIL 4 Change Enablement, Site Reliability Engineering practice, Reinertsen's product development flow classes of service, and clinical triage systems, providing convergent cross-domain evidence for its robustness. When boundary tests produce ambiguous results, conservative classification (assigning to a higher-control class) is the correct default because the governance failure cost of under-classifying a high-risk item exceeds the throughput cost of over-classifying a low-risk item.

Key Findings

  1. Three classification axes (risk level, reversibility, and standardisation) appear independently across ITIL 4, SRE, Reinertsen's product development flow, and healthcare triage as the operative criteria for segmenting fast-path from controlled-path demand.

  2. ITIL 4 Change Enablement defines three change types (standard, normal, and emergency) where standard changes are pre-authorised because they are low-risk, documented, and repeatable, and normal changes require per-instance risk and impact assessment with Change Advisory Board approval.

  3. Reinertsen's four classes of service (expedite, fixed-date, standard, and intangible) are defined by cost of delay profile and each implies a handling policy that cannot be derived from organisational status or requester seniority.

  4. DORA research shows that elite technology delivery teams achieve high deployment frequency and low change failure rate simultaneously, a result consistent with demand segmentation that routes low-risk standard work through automated pre-approved lanes and high-risk novel work through controlled review lanes.

  5. Three observable boundary tests (template test: a pre-approved documented pattern exists; recovery test: the failure mode has been tested with a validated rollback procedure; blast radius test: potential impact is contained within a defined boundary) operationalise class assignment without requiring specialist risk knowledge at intake time.

  6. The healthcare triage principle that under-triage (routing a high-acuity patient to the fast track) is a patient safety failure while over-triage (routing a low-acuity patient to the main track) is only a capacity waste translates directly to work intake design, establishing conservative boundary classification as a safety property.

  7. Two-class segmentation (fast and controlled only) is insufficient in a split-authority delivery system because it collapses routine assessed work and genuinely exceptional high-consequence items onto the same controlled path, intensifying the bottleneck and reproducing the queue fragmentation failure mode identified in the organisational failure modes evidence.

  8. Applying full pre-approval controls to Class 1 (fast-path) work converts an enabling governance control into a coercive one, generating queue congestion without proportionate risk reduction because the control intensity no longer matches the transaction hazard.

  9. Delivery-operations demand (BAU change, minor enhancement, incident response) and build-mode demand (novel capability delivery) accumulate independently, and a segmentation scheme that ignores this distinction risks misclassifying high-volume BAU work as exception-path simply because no pre-approved template exists yet, rather than because the work is genuinely novel or high-consequence.

Assumptions

  1. Four or more demand classes add classification overhead without operationally distinct control actions. Justification: no evidence identifies a fourth mandatory class with a distinct control form; Reinertsen's four types and ITIL 4's three types both reduce to three distinct control policies when mapped by action rather than demand characteristic.

  2. The three boundary condition tests can be administered reliably without specialist risk knowledge, given a maintained template catalogue and blast radius tooling. Justification: ITIL 4 requires standard change classification to be operable without per-instance specialist review; SRE toil criteria are designed to be self-evident from change documentation.

Analysis

The weight of evidence supports the three-class demand model, but the model is grounded in cross-domain inference rather than a published empirical study of split-authority delivery segmentation. Each individual source provides primary evidence for a specific domain (ITIL 4, SRE, Reinertsen, clinical triage); the inference that they converge on the same classification structure is the substantive synthesis claim.

The principal alternative model is a single-axis risk score. This analysis rejects the single-axis risk score model on the grounds that risk level alone does not determine the correct control action: a high-risk but fully reversible item with a tested rollback procedure should travel the standard path, not the exception path. Reversibility is an independent axis that modifies the risk interpretation.

This analysis rejects a four-class model (splitting Class 2 into bounded-low and bounded-high sub-classes) on the grounds that the control actions for both sub-classes are assessed pre-approval; the difference would be in approval authority level, not control form. Routing to different approval authority levels is a decision rights placement question (Q4), not a segmentation question. A four-class model adds classification overhead without a corresponding distinct control action at the new boundary.

ITIL 4 Change Enablement endorses automated pre-approval for low-risk changes in the same framework that defines controlled paths for high-risk ones, removing the apparent incompatibility between ITIL and DevOps segmentation approaches.

The completed item on AI and low-code risk tier classification found that risk tiers for AI-generated and low-code work use the same axes (risk level, reversibility, and standardisation) as the three-class model proposed here, confirming that the classification structure generalises beyond IT service change management to software delivery work items. The completed item on human-in-the-loop AI automated workflows found that the boundary between automated handling and mandatory human review is determined by reversibility and blast radius of the automated action, which maps directly to the Class 1 versus Class 2/3 boundary tests defined in this item.

Risks, Gaps, and Uncertainties

Open Questions

Output

sources


cites
cites Operating model synthesis for split-authority delivery systems
cites Conditions under which internal governance controls minimise coordination costs in regulated enterprises
cites Variance Control Comparison Across Delivery Modes
cites Customer-Segment Demand Prioritisation Against Domain-Based IT Teams: Empirically Observed Organisational Failure Modes
cites Project-Based Demand Governance With Product-Structured IT Teams: Empirically Observed Organisational Failure Modes
cites Temporary Automation Demand Persistence and Core Capability Investment Displacement
cites Backpressure Infrastructure and the Theory of Constraints
related (frontmatter)
related Automated governance assurance and change control verification patterns for AI-assisted delivery
related How should Artificial Intelligence (AI) and low-code use cases be classified into risk tiers, and how should governance controls vary across those tiers?
related When and how should human intervention be incorporated into Artificial Intelligence (AI)-driven and automated workflows?
version history
versiondatecommitsummary
1.02026-05-30a525c3dInitial completion

Connected items

Loading…

View full knowledge graph →