Principal-led architecture for critical systems

Review worksheet

Long-Term Capability Review

A non-certifying worksheet for reviewing business behavior, system knowledge, evidence, human authority, learning, ownership, and continuity before a major modernization or AI decision.

Decision resourceUse the artifact with a named owner
Resource type
Review worksheet
Version
1.48.0
Decision
Which capability gaps must be addressed before the organization proceeds, narrows, or expands a high-risk system change?

Purpose and use

A non-certifying worksheet for reviewing business behavior, system knowledge, evidence, human authority, learning, ownership, and continuity before a major modernization or AI decision.

Decision supported: Which capability gaps must be addressed before the organization proceeds, narrows, or expands a high-risk system change?

Select Yes, Partly, No, Unknown, or Not applicable. Record an owner, evidence or source, and the next action. The worksheet stays in the browser page and is not transmitted.

1. Business behavior and continuity

PromptResponseOwnerEvidence or sourceNext action
Have the calculations, approvals, permissions, reports, exceptions, and manual workarounds that matter been identified?
Is observed system behavior separated from intended policy or requirement?
Are known, unknown, disputed, intentional, and accidental behaviors classified?
Are representative high-consequence scenarios documented?
Is the operational fallback known if the new or AI-assisted path is unavailable?
Are cutover and rollback conditions explicit?
Are service, support, and recovery owners named?

2. System state and knowledge durability

PromptResponseOwnerEvidence or sourceNext action
Is there a current inventory of applications, data stores, integrations, jobs, models, prompts, tools, and vendors?
Are important decisions recorded with date, owner, rationale, and supersession status?
Can another qualified person reproduce the relevant system state?
Are source, authority, time, scope, trust state, and retention visible for reusable knowledge?
Is stale or superseded information kept out of active instruction paths?
Can the organization continue if a key maintainer, contractor, or vendor leaves?
Are dependencies and replacement options documented?

3. Evaluation and evidence

PromptResponseOwnerEvidence or sourceNext action
Are golden, edge, adversarial, refusal, access, and operational cases defined where relevant?
Are datasets, fixtures, prompts, models, tools, and configurations versioned?
Can results be traced to the exact source and system state examined?
Are failure categories separated rather than grouped under a vague label?
Are automated evaluators calibrated against human-reviewed cases where used?
Are access-control and unauthorized-source cases included?
Are release, rollback, exception, and stop criteria explicit?
Are unknowns retained with an owner and next action?

4. Human authority and escalation

PromptResponseOwnerEvidence or sourceNext action
Are proposer, reviewer, approver, executor, escalation owner, policy owner, and system owner roles named?
Is AI output clearly labeled as proposed work before approval?
Can reviewers approve, edit, reject, request evidence, refuse, or escalate?
Does the interface show source evidence, limitations, and downstream consequence?
Is approval separated from execution where consequence warrants it?
Is execution bound to the exact approved action and parameters?
Are duplicate execution, expired approval, and unavailable-reviewer cases handled?
Are overrides and disagreements retained and reviewed?

5. Feedback and learning

PromptResponseOwnerEvidence or sourceNext action
Does the team review failures, disagreements, overrides, and blocked actions for system improvement?
Are users taught how to verify AI-assisted work rather than only accept it?
Are assistance levels appropriate to user expertise, consequence, urgency, and accessibility?
Is independent performance measured when long-term human capability matters?
Are operational signals connected to ownership and remediation?
Does each pilot improve a reusable dataset, architecture pattern, review process, or evidence method?
Are lessons promoted into maintained documentation instead of remaining in meeting notes?

6. Ownership, handoff, and vendor exit

PromptResponseOwnerEvidence or sourceNext action
Does the client own client-specific deliverables and evidence?
Are pre-existing provider methods and client-specific outputs distinguished?
Are artifacts available in exportable, readable formats?
Are repository, environment, account, and vendor dependencies known?
Is knowledge transfer included in scope?
Is there a practical replacement or exit path for models, platforms, or vendors?
Are retained data, logs, prompts, and documents addressed at exit?
Can the organization operate and change the system without manufactured lock-in?

7. Infrastructure and time-horizon constraints

PromptResponseOwnerEvidence or sourceNext action
Are expected volume, latency, cost, availability, and recovery needs documented?
Are rate limits, quotas, model availability, and vendor-change risks understood?
Are near-term decisions separated from medium-term capability building?
Is infrastructure work sequenced before use cases that depend on it?
Are current constraints accepted explicitly rather than hidden in assumptions?
Is there a review date for fast-changing model, vendor, security, or procurement facts?

8. Decision and next-step register

PromptResponseOwnerEvidence or sourceNext action
Gap or unknown
Consequence if unresolved
Owner
Evidence needed
Action
Due date
Decision affected
Status
Proceed within the reviewed boundary
Proceed with named conditions
Narrow the use case or system scope
Remediate before proceeding
Keep the work in pilot
Stop or defer with the reason recorded
Usage boundary: This worksheet does not produce a score, certification, compliance conclusion, or universal maturity rating. Record unknown and not-applicable results rather than forcing a positive answer.

Next action

Bring the system, the trigger, and what cannot fail.

Start with public-safe context. Sensitive evidence moves only after fit, responsibility, scope, and an approved channel are clear.

Private local search

Find a service, capability, evidence record, resource, or insight

Press / to open search when focus is not in a form field.

Search runs locally against the public site index.