Q4: Decision rights that should move closer to execution
- Daily task sequencing within an approved iteration must sit with delivery teams, because it is fully reversible, has zero blast radius, and produces only approval-queue latency when centralisedDORA (2024)Pais (2019)Mitchell (2026)
- Minor sprint-level scope adjustment (swapping items within the same priority band without changing external commitments) must sit with delivery teams; escalation is triggered only when the adjustment changes an external stakeholder commitment or exceeds the team's priority-band boundaryDORA (2024)Company (2022)
- Reliability decisions within an already-approved Service Level Objective must sit with delivery teams, because the SLO approval itself constitutes pre-authorised governance; decisions that change the SLO or accept reliability trade-offs with measurable external customer impact require escalationSRE (2016)SRE (2016)
- Technical debt prioritisation within a pre-authorised capacity band must sit with delivery teams, because deferring this decision through central approval compounds the future cost of the debt faster than the governance cost of per-decision review adds risk-reduction valueSRE (2018)CISR (2023)DORA (2024)
- Local environment spend below a defined cost ceiling must sit with delivery teams, because the cost ceiling itself is the risk control; central pre-approval of spend below the ceiling produces approval latency without providing additional risk reduction beyond what the ceiling already providesAmazon (2025)Mitchell (2026)
- Live incident response decisions must sit with delivery teams under the Incident Command System authority structure, because external approval latency during an active incident is structurally incompatible with the five-minute response time required for services targeting four nines of availability (99.99%)SRE (2018)SRE (2016)
- DORA research shows that teams authorised to make large-scale changes without external permission achieve higher software delivery performance across throughput and stability metrics simultaneously, indicating that team autonomy over execution decisions correlates positively with delivery outcomesDORA (2024)DORA (2024)
- The Bain RAPID framework places the Decide role as close to implementation as possible and restricts the Agree role to mandatory legal or regulatory requirements, providing a practitioner-validated design principle for moving decision authority toward execution rather than upwardCompany (2022)Company (2011)
Research Question
Which decisions about sequencing, scope, reliability, technical debt, local spend, and incident response must sit with delivery teams to reduce delay without losing control?
Findings
Executive Summary
Delivery teams must own all six categories of execution decision (daily sequencing, minor scope adjustment, reliability choices within an approved Service Level Objective, technical debt prioritisation within a pre-authorised capacity band, local environment spend below a cost ceiling, and live incident response) when those decisions are high-frequency, reversible, and bounded in blast radius. Centralising these decisions generates approval-queue latency with no proportionate governance value and, in the incident-response case, is structurally incompatible with the response times required to meet availability targets. The appropriate governance mechanism is bounded delegation: three pre-defined parameters (cost ceiling, blast radius limit, approved technology catalog) and four binary escalation triggers (catalog deviation, ceiling breach, blast radius overflow, external commitment) replace per-decision approval while preserving central oversight for genuinely high-consequence choices. DORA, Bain RAPID, MIT CISR, and the Incident Command System all independently converge on the same design principle: the Decide role should sit as close to implementation as possible, and the Agree role should be used only for mandatory legal or regulatory requirements.
Key Findings
-
Daily task sequencing within an approved iteration must sit with delivery teams, because it is fully reversible, has zero blast radius, and produces only approval-queue latency when centralised.
-
Minor sprint-level scope adjustment (swapping items within the same priority band without changing external commitments) must sit with delivery teams; escalation is triggered only when the adjustment changes an external stakeholder commitment or exceeds the team's priority-band boundary.
-
Reliability decisions within an already-approved Service Level Objective must sit with delivery teams, because the SLO approval itself constitutes pre-authorised governance; decisions that change the SLO or accept reliability trade-offs with measurable external customer impact require escalation.
-
Technical debt prioritisation within a pre-authorised capacity band must sit with delivery teams, because deferring this decision through central approval compounds the future cost of the debt faster than the governance cost of per-decision review adds risk-reduction value.
-
Local environment spend below a defined cost ceiling must sit with delivery teams, because the cost ceiling itself is the risk control; central pre-approval of spend below the ceiling produces approval latency without providing additional risk reduction beyond what the ceiling already provides.
-
Live incident response decisions must sit with delivery teams under the Incident Command System authority structure, because external approval latency during an active incident is structurally incompatible with the five-minute response time required for services targeting four nines of availability (99.99%).
-
DORA research shows that teams authorised to make large-scale changes without external permission achieve higher software delivery performance across throughput and stability metrics simultaneously, indicating that team autonomy over execution decisions correlates positively with delivery outcomes.
-
The Bain RAPID framework places the Decide role as close to implementation as possible and restricts the Agree role to mandatory legal or regulatory requirements, providing a practitioner-validated design principle for moving decision authority toward execution rather than upward.
-
MIT CISR research distinguishes what decisions (owned by business leaders) from how decisions (owned by delivery teams); daily sequencing, technical approach within an approved architecture, and technical debt prioritisation are all how decisions that belong with delivery teams, not with central approval functions.
-
A bounded delegation boundary defined by three parameters (cost ceiling, blast radius limit, approved technology catalog) and four escalation triggers (catalog deviation, ceiling breach, blast radius overflow, external commitment) preserves governance outcomes for high-consequence decisions while eliminating per-decision approval overhead for all six routine execution decision categories.
Assumptions
-
Delivery team competence: The delivery team has the technical competence to make reliable execution decisions within each category. If capability gaps exist, the bounded delegation model requires capability-building before delegation, not permanent centralisation.
-
Parameter maintenance: Governance parameters (cost ceilings, blast radius limits, approved catalogs) are maintained and updated on a regular cadence by the central function; stale parameters are a governance risk in the bounded delegation model.
-
Binary escalation trigger clarity: Escalation triggers are objective and binary; if trigger conditions are ambiguous, teams will either over-escalate (recreating approval latency) or under-escalate (creating governance gaps). The bounded delegation model is only as good as the precision of its trigger definitions.
Analysis
The six decision types in scope share a structural property: their governance risk is bounded before the decision is made, not during it. Daily sequencing risk is bounded by the iteration boundary. Scope adjustment risk is bounded by the priority-band definition. Reliability risk is bounded by the SLO. Technical debt risk is bounded by the capacity allocation. Spend risk is bounded by the cost ceiling. Incident response risk is bounded by the incident-scope definition. When governance parameters pre-bound the risk, the residual governance value of per-decision approval falls to near zero, while the coordination cost of that approval remains proportional to the decision frequency.
The four independent evidence sources (DORA, ICS, RAPID, MIT CISR) converge on this same structural conclusion from different starting points. DORA reaches it from empirical measurement of delivery outcomes. ICS reaches it from operational analysis of time-critical coordination failures. RAPID reaches it from practitioner case studies of decision quality and speed. MIT CISR reaches it from strategic governance research in digital transformation. This convergence from independent sources is the primary reason the key findings are held at medium rather than low confidence, despite the absence of controlled experimental evidence.
The behavioural dimension reinforces the structural argument. Adler and Borys (1996) show that controls perceived as coercive generate workaround behaviour; the bounded delegation model shifts formalisation from coercive (centrally approved per-decision) to enabling (team-owned within pre-agreed bounds). The governance failure mechanisms item in this corpus documents that the workaround patterns (shadow workflows, deliberate mis-classification, informal approval channels) emerge specifically when controls are applied uniformly to all work regardless of transaction hazard. The bounded delegation model disrupts this pattern by differentiating control intensity by risk category.
The one rival remedy worth noting is adding central approval capacity rather than delegating. This approach preserves the central-control model while attempting to reduce its latency by adding reviewers. Evidence from queueing theory (Little's Law) and the Theory of Constraints shows that adding capacity to a non-bottleneck position does not reduce system lead time: if the constraint is the serial nature of the approval gate, adding reviewers does not remove the serial dependency. Delegation removes the dependency; capacity addition does not.
Risks, Gaps, and Uncertainties
- Competence prerequisite: The bounded delegation model assumes delivery team competence in each decision category. No primary evidence was gathered in this item on how competence gaps manifest in practice or how to diagnose them before delegation. This is an evidence gap.
- Parameter calibration: The three governance parameters (cost ceiling, blast radius limit, approved catalog) require calibration for each organisation and each team. No empirical evidence on typical calibration values or calibration failure modes was gathered. This is an evidence gap.
- DORA causal direction: DORA data is observational. The correlation between team autonomy and delivery performance could reflect reverse causation (high-performing teams are granted more autonomy) rather than autonomy driving performance. The item treats DORA as corroborative evidence rather than proof of causation.
- Regulated sectors: The BCBS 328 analysis in §5 is an inference from the regulatory text, not a confirmed interpretation by a regulator. Application in highly regulated sectors (banking, healthcare) requires legal review of whether pre-approved blueprint governance satisfies applicable independent-review requirements.
Open Questions
- How should cost ceilings and blast radius limits be calibrated for teams at different maturity levels? (Potential backlog item for Q5 or a standalone item.)
- What monitoring design detects under-escalation before it becomes a governance failure, without recreating approval-queue latency through surveillance overhead?
- At what organisation scale does the parameter-maintenance cost of bounded delegation exceed its throughput benefit compared to alternative control models?
Output
- Type: knowledge
- Description: A bounded delegation map for six execution decision categories, with three governance parameters and four escalation triggers, synthesised from DORA, ICS, RAPID, MIT CISR, and AWS governance evidence.
- Key sources:
sources
- [x] Little (1961) A Proof of the Queuing Formula L = λW, Operations Research -- queueing theorem: average items in system equals throughput rate times average time in system; foundational basis for WIP-to-lead-time relationship
- [x] DORA (2024) Loosely Coupled Teams Capability -- empirical research on team autonomy and delivery performance
- [x] DORA (2024) DORA Metrics and Four Keys -- change lead time, deployment frequency, and change failure rate
- [x] Skelton and Pais (2019) Team Topologies Key Concepts -- stream-aligned teams, cognitive load limits, and inter-team interaction modes
- [x] Bain and Company (2022) RAPID Decision Making -- Recommend, Agree, Perform, Input, and Decide framework role definitions
- [x] Bain and Company (2011) Decisions: Who Does What? -- single decision owner, decision placement close to implementation
- [x] Massachusetts Institute of Technology Center for Information Systems Research (MIT CISR) (n.d.) Classic Topics: Decision Rights -- governance as allocation of decision rights and accountabilities
- [x] MIT CISR (2023) Simplifying Decision Rights for Growth -- what vs. how decisions, investment prioritisation, exception handling
- [x] Google SRE (2018) Workbook: Incident Response -- Incident Command System (ICS) authority structure during live incidents
- [x] Google SRE (2016) Site Reliability Engineering: Being On-Call -- on-call decision authority, escalation tiers, response-time constraints
- [x] Google SRE (2018) Workbook: Eliminating Toil -- toil characteristics and the operational cost of repetitive manual decisions
- [x] Google SRE (2016) Site Reliability Engineering: Embracing Risk -- risk continuum and cost-benefit trade-offs in reliability decisions
- [x] Amazon Web Services (AWS) (2025) Empower Your Teams with Modern Architecture Governance -- preapproved blueprints, distributed governance, automated controls
- [x] Mitchell (2026) Operating Model Synthesis for Split-Authority Delivery Systems -- five design principles including bounded delegation
- [x] Mitchell (2026) Q2: Demand Segmentation for Fast-Path vs Controlled-Path Flow -- three demand classes and boundary tests this item builds on
- [x] Mitchell (2026) Q3: Routing Design that Isolates Exceptions from Routine Flow -- physical lane separation and escalation thresholds
- [x] Mitchell (2026) Governance Designs where Explicit Integrator Rights Substitute for Co-location -- integrator authority bundle and boundary conditions
- [x] Mitchell (2026) Internal Governance Controls: Effectiveness Conditions in Regulated Enterprises -- control proportionality to transaction hazard
- [x] Adler and Borys (1996) Two Types of Bureaucracy: Enabling and Coercive -- enabling vs. coercive formalisation and team behavioural responses
- [x] Basel Committee on Banking Supervision (BCBS) (2015) Corporate Governance Principles for Banks -- independent risk challenge and second-line-of-defence role
- [x] Williamson (1991) Comparative Economic Organization, working paper version -- transaction cost economics and governance choice
| version | date | commit | summary |
|---|---|---|---|
| 1.0 | 2026-05-31 | dbdf8e8 | Initial completion |