When Agents Rule

NEAREST DEADLINE: 21 September 2026, FIPS 140-2 sunsets and only 140-3 validated modules may be used for new federal procurement. Twenty eight things have moved since this book went to press.

See What Changed
When Agents Rule by Steven Oppenheim, book cover
Second Edition // 2026 An Executive Playbook

When Agents Rule

The Executive Playbook to Govern Autonomous AI, Defeat the Quantum Threat, and Lead Through Regulatory Fragmentation

You think you are in control. You are not. The crisis will come. The question is whether you have already built the answer.

For the CIO who carries accountability for outcomes that no governance framework yet covers. For the CISO calculating how many years of encrypted data adversaries already hold. For the board member who wants to ask better questions before a crisis makes them irrelevant.

Second Edition 2026. Oppenheim Publishing. Hardcover, softcover and eBook. 356 pages.
Research current through 2026, sourced from Gartner, McKinsey, Deloitte, IBM, MIT, Okta, Netskope and the FinOps Foundation.
Book two of the Sovereign CIO series, following When Clouds Fail.

17Chapters
5Proprietary Frameworks
4Clock Quadrants
8Sovereign Commitments
22Free Instruments
28Tracked Updates
Since Publication // Reviewed 15 September 2026

Twenty Eight Things Have Moved Since This Book Went to Press

Four of them correct a figure printed in the book, and those are published in their own table rather than buried. Thirteen did not exist when the manuscript closed. Below are the four with the nearest consequences. The full log is a separate page, because a playbook is only useful if the calendar behind it stays current.

21 September 2026 // Nearest

FIPS 140-2 sunsets in six days

All remaining FIPS 140-2 certificates move to Historical status. From that date only FIPS 140-3 validated modules may be used for new United States federal procurement, so validation status determines market access. It is also the cheapest test of whether your cryptographic inventory is real: if you cannot say today which modules are on 140-3, you have a list rather than an inventory.

New since publication. Extends Chapters 6 and 13.

22 June 2026 // Correction

The federal quantum date is 2030, not 2035

Executive Order 14412 sets 31 December 2030 for key establishment and 31 December 2031 for signatures on federal high value assets, and directs the Federal Acquisition Regulatory Council to require contractor compliance by 2030. The book uses 2035 as the anchor. It remains the outer horizon but it is no longer the planning date, and a plan built to 2035 in a federal supply chain has five fewer years than it assumes.

Corrects Chapters 2, 6 and 13. Re run the Quantum Shelf Life Calculator at 2030.

27 July 2026 // EU

Four dates moved, and Article 50 was not one

The Digital Omnibus was adopted as Regulation (EU) 2026/1744 and moved exactly four dates: Annex III to December 2027, Annex I to August 2028, national sandboxes to August 2027, and content marking for systems already on the market to December 2026. Article 50 transparency applied on schedule in August 2026 and is enforceable now. Chapter 7 predicted the outcome; the log sharpens the Article 50 wording.

Confirms and corrects Chapter 7. Test one system with the Deadline Checker.

26 May 2026 // Gartner

The autonomy ladder is now the analyst position

Gartner predicts that by 2027 forty percent of enterprises will demote or decommission autonomous agents because of governance gaps found only after production incidents, and recommends classifying agents by autonomy level with different controls at each level. Its stated root cause is treating governance as binary, either locked down or fully trusted. That is the argument this book makes, reached independently.

Confirms Chapters 4, 5 and 12. A second citation to place alongside the first.

Read the Full Log, Twenty Eight Entries

The log carries every entry by strand, a corrections table naming what the book now gets wrong, a section on what has not changed, and the method used to maintain it. Every entry is dated and sourced, survey figures are labelled as survey figures, and enacted law is never blurred with forecast. Treat all of it as a pointer to primary sources rather than a substitute for them, and not as legal advice.

Three Crises, One Convergence

These crises do not announce themselves. They accumulate. By the time most organizations recognize the pattern, the gap between their posture and what is required has grown into something that cannot be closed quickly.

01 Crisis One

AI Agents Without Governance

Agents are making consequential decisions across your enterprise without governance, audit trails, or accountability. The illusion of control breaks the moment a board asks who approved what. The eighth commitment exists because most of what is operating was never authorized.

Chapters 1, 4, 5, 10, 12

02 Crisis Two

The Quantum Countdown

Adversaries are harvesting encrypted data today, waiting for quantum computers to decrypt it tomorrow. If your data must stay confidential for longer than your migration will take, the exposure already exists and no future effort closes it retroactively.

Chapters 2, 6, 11, 13

03 Crisis Three

The Fractured World

Regulatory frameworks are fragmenting across more than 140 jurisdictions in ways that turn today’s compliance into tomorrow’s liability. What works in one geography triggers a violation in another, and the dates move in both directions.

Chapters 3, 7, 8, 14

The Sovereignty Clock

One diagnostic measures four dimensions of organizational vulnerability. The question is not whether the clock is running. It is. The question is what time it shows for your enterprise.

12 to 3Agent Governance
3 to 6Quantum Countdown
6 to 9Regulatory Compliance
9 to 12Sovereignty Erosion
Sovereign CIO Read the
Clock

Four Quadrants. One Honest Reading.

Most enterprises have at least one quadrant approaching midnight. The Sovereignty Clock is the headline diagnostic of the book: the single instrument a reader should leave carrying. Four quadrants, one question each.

  • Agent Governance: Inventory, classify, govern, escalate
  • Quantum Countdown: Census, prioritize, migrate, validate
  • Regulatory Compliance: Map, classify, document, monitor
  • Sovereignty Erosion: Identify, diversify, exit, rebuild
Read Your Clock Now

Five Frameworks, Read in This Order

The frameworks in this book are not coequal. Read them in order of priority and the architecture becomes clear.

The Framework Hierarchy

  1. The Sovereignty Clock is the headline diagnostic. Four quadrants, one question per quadrant. It frames every other framework in the book.
  2. The L0 to L5 Autonomy Ladder is the classification instrument. Every AI system sits on the ladder, and every governance decision starts there.
  3. The PLACE Framework is the placement discipline. Every workload answers its five questions before it gets infrastructure.
  4. Cost Per Compliant Decision is the financial metric. The single number that translates governance discipline into language a CFO will fund and a board will track.
  5. The A.R.T. Framework, the Eight Commitments and the Friday Afternoon Test are the supporting instruments. Each has its place. None carries the headline.
L
Framework One

The L0 to L5 Agent Autonomy Ladder

Six levels of autonomy, from rule based automation to fully autonomous operation. A common language for technical and non technical stakeholders that maps directly to governance intensity. The step from L2 to L3 is the one that matters, because that is where the human stops seeing the work.

P
Framework Two

The PLACE Framework

Placement, Latency, Accountability, Compliance, Economics. Five questions answered before any workload is assigned infrastructure, so placement decisions become auditable, defensible and reversible rather than architectural folklore.

$
Framework Three

Cost Per Compliant Decision

Everything spent making an autonomous decision defensible, divided by the decisions that clear the bar. It behaves like cost per transaction, which means a finance function already knows what to do with it. Governance stops being a cost line and becomes unit economics.

A
Framework Four

The A.R.T. Framework

Agility, Risk Readiness, Tenacity. The three organizational capabilities that separate the technology leaders who navigate convergent crises from those caught between them. Operational rather than aspirational, and diagnosable.

8
Framework Five

The Eight Commitments of the Sovereign CIO 2.0

A leadership covenant designed to endure beyond any single technology cycle, from agent visibility to institutional legacy. The constitution of the technology executive who refuses to be replaced by their own systems.

F
Supporting Instrument

The Friday Afternoon Test

The diligence model that separates governance documentation from governance enforcement, paired in Chapter 16 with the board companion framework and the five questions a director should put to a CIO.

The organizations that win the next decade will not be those with the most advanced AI. They will be those with the most disciplined governance. Sovereignty is not a constraint on innovation. It is the foundation that makes innovation durable.

When Agents Rule, Executive Overview

The Eight Commitments of the Sovereign CIO 2.0

Chapter 16 turns the frameworks into a covenant. Eight statements a technology executive should be willing to sign and be measured against.

1

I will know what AI agents operate in my enterprise.

2

I will govern AI commensurate with its autonomy.

3

I will prepare for quantum threats before they arrive.

4

I will design for regulatory evolution, not regulatory stasis.

5

I will maintain sovereignty over critical capabilities.

6

I will translate technical necessity into business language.

7

I will build capabilities that persist beyond my tenure.

8

I will find the AI I did not authorize.

The eighth commitment is the one the book argues matters most. A commitment to govern what you can see is worthless if most of what is operating is invisible. Discovery is the precondition for every other commitment on the list, which is why the toolkit below opens with an inventory instrument and a shadow AI discovery log rather than with a policy.

Four Ways to Read Seventeen Chapters

The book is built to be entered at the point where your crisis already is. Pick the path that matches the time you actually have.

The Time Pressed Executive

15 to 30 minutes

Start with the Executive Brief, which distils the whole book into its frameworks, figures and action items. Then run the Monday Morning Checklist at the end of it, which gives you five moves for five days.

Executive Brief, then the checklist

The CIO or Technology Leader

2 to 3 hours

Introduction, then Chapters 1 to 3 for the threat landscape, then Chapter 15 for the operating model and Chapter 16 for the commitments. Return to Chapters 4 to 8 and 9 to 13 as implementation demands.

1 to 3, then 15, 16, 17

The Architect or Program Lead

Full read

Sequential, Introduction through Chapter 17. The three strands alternate by design, because agents, quantum and fragmentation do not arrive in sequence in a real enterprise. They arrive together, on one desk, in one quarter.

Introduction to Chapter 17

Board and Non Technical Executives

Selected chapters

Executive Brief, Chapter 10 on the return on governance investment, Chapter 11 on quantum economics, Chapter 16 for the commitments and the board companion framework, and Chapter 17 for the identity the work requires.

Brief, 10, 11, 16, 17

Reading by topic instead? Agent governance is Chapters 1, 4, 5, 10 and 12. Quantum readiness is 2, 6, 11 and 13. Regulatory compliance is 3, 7, 8 and 14. Business case development is 10 and 11.

Diagnostic Tools for the Sovereign CIO

Eight interactive instruments, all of them live. Read your clock, classify your agents, price your governance, score your bill of materials, and find out whether your governance would survive somebody asking to see it. Nothing is transmitted or stored by any of them.

Flagship All Four Quadrants

Sovereignty Clock Reader

Score your enterprise across all four quadrants. Find out which clock hand sits closest to midnight and where to move first.

7 minutes Read the Clock
. Quadrant One // Agents

L0 to L5 Agent Classifier

Classify any AI system by operational autonomy. Get the matched governance tier, oversight controls and escalation rules for that level.

4 minutes Classify an Agent
. Framework Three // Finance

Cost Per Compliant Decision Calculator

Price your governance as unit economics. Produces the do nothing trajectory, the governed trajectory, and the present value cost of waiting a year.

6 minutes Price the Decision
. Quadrant Two // Quantum

Quantum Shelf Life Calculator

Enter how long your data must stay confidential and how long your migration will take. Returns your protection margin in years, and whether the exposure already exists.

3 minutes Calculate Exposure
. Framework Four // Capability

A.R.T. Capability Assessment

Score your organization on Agility, Risk Readiness and Tenacity. Identify which capability is the binding constraint and what to invest in next.

6 minutes Assess Capability
. Quadrant Three // Regulatory

EU AI Act Deadline Checker

Six questions about one system, plus a short context block, and you get the dates that actually apply to it after the 2026 amendments, with what was deferred separated from what was not. Includes your penalty ceiling in euro.

4 minutes Check The Dates
New Quadrant One // Diligence

The Friday Afternoon Test

Five dimensions, each scored twice: is the control designed, and could you evidence that it operated this afternoon. The gap between those two numbers is the answer, because a control that is designed and not operating reports green.

3 minutes Take the Test
New Quadrant Three // Supply Chain

AIBOM Readiness Scorer

Twenty two checks across the six categories, plus format, signing and generation. Returns the weakest category rather than the average, the time to produce an Annex IV file on request, and whether you would clear a vendor qualification.

8 minutes Score Your Readiness

The Free Companion Toolkit

Twenty two instruments in four groups, all live. Working registers, scored checklists, financial models, runbooks and board papers, built to be filled in rather than read. Three were added in September 2026 after an industry review found artefact requirements the original nine did not cover.

How the toolkit is designed. Every instrument is a blank working artefact: a register, a rubric, a model, a runbook or a template. None of them reproduce the book, because the reasoning is what the book is for and the instrument is what the work needs. Each one names the chapters that explain the thinking behind it, so the two are used together. Every workbook ships with an example row that you delete, a fill legend, and a stated set of assumptions you are expected to replace with your own.

Start with the Toolkit Index. Twenty two instruments is too many to begin with, and the index says so: the ninety day sequence starts four of them and deliberately produces no policy at all in the first thirty days, because a policy written before the inventory governs the systems you already knew about. The index also carries the reconciliation table that names which instrument is authoritative when two of them disagree about the same figure.

Free for internal use inside your own organization. Not legal, technical or financial advice.
AGT

Agent Governance

5 Live
XLS
Agent Inventory and Classification Workbook Five tabs. L0 to L5 register with automatic risk scoring and control gap detection, the autonomy ladder reference, a shadow AI discovery sweep log covering the seven places agents hide, and a calculated governance dashboard. Start here: every other instrument depends on it.
XLSX Download
DOC
Agent Governance Charter Template Fourteen sections. Council membership and quorum, four approval gates, mandatory control floors by governance tier, human oversight measures that detect approval by reflex, the discovery obligation, exceptions and risk acceptance, and an adoption checklist.
DOCX Download
DOC
Agent Containment and Kill Switch Procedure Four graduated containment levels, twelve prerequisites that determine whether containment will work at all, trigger criteria, a five step sequence with target times, reversal and reconciliation, a drill log, and the failure modes seen in practice.
DOCX Download
XLS
Agent Decision Log, Audit Trail and Identity Register Three sheets, 1,206 formulas. An evidence grade decision log for L3 and above that captures inputs, retrieved context, tools invoked, the human checkpoint and reversal status, plus an identity register that calculates effective privilege and finds the dangerous cell: modest autonomy paired with a broad credential. Extended with the identity sheet after NIST stated that agents are commonly treated as generic service accounts without dedicated identity or accountability controls.
XLSX Download
DOC
Agent Reliability Contract and Error Budget Charter The five agent service level indicators from Chapter 15 with a column for the evaluation method, because an indicator without a stated method cannot be enforced. Error Budget 2.0 stratified by autonomy level, three burn rate thresholds wired to automatic consequences, and the autonomy change clause that prevents an agent qualified at L2 being promoted to L4 without its reliability standard tightening. Four signatories.
DOCX Download
PQC

Quantum Readiness

5 Live
XLS
Cryptographic Census and Quantum Migration Workbook Six tabs. A census register that scores every cryptographic dependency and assigns it a migration wave, an algorithm status and replacement reference, a planning assumptions sheet that drives every score from four cells, the data shelf life test that quantifies your protection margin in years, and a migration dashboard.
XLSX Download
DOC
Vendor Post Quantum Readiness Questionnaire Request for proposal grade. Seven sections from current cryptographic position through roadmap commitments, agility, key lifecycle, supply chain and standards to the contractual position, plus a weighted scoring rubric, a disposition table and the red flags that override the score.
DOCX Download
XLS
Five Year Quantum Migration Roadmap Five sheets. The four phase structure from Chapter 13 with its deliberate overlaps, nineteen milestones each carrying a gate criterion someone outside the programme can verify, six ordering constraints a schedule will not enforce for you, and a funding profile with calculated totals, contingency banding and the cost of a one year delay. Defaults to the 2030 Executive Order date rather than 2035.
XLSX Download
XLS
Cryptographic Bill of Materials and FIPS 140-3 Readiness NEW Added September 2026. A module inventory that answers the only question procurement asks after 21 September 2026, when FIPS 140-2 certificates move to Historical status and only 140-3 validated modules may be used for new federal procurement. Plus a twelve field readiness score against the machine readable cryptographic inventory that Executive Order 14412 directs CISA and NIST to specify by around March 2027.
XLSX Download
PPT
Quantum Readiness Board Brief Deck Twelve briefing slides plus a title, every one with speaker notes. Leads with the ask, shows the shelf life arithmetic rather than only the conclusion, defuses the timeline objection across five dates, states the Chapter 2 chief financial officer objection in its own words with the three reframes, and closes by handing the board the two questions worth its time.
PPTX Download
REG

Regulatory and Sovereignty

7 Live
XLS
Regulatory Obligation Register and Compliance Calendar Twenty nine obligations across AI and cryptographic regimes, twenty six carrying a hard effective date and three continuing or rolling, each with a confidence rating and a verification field, plus a per system obligation register with automatic risk rating and escalation flags, a jurisdiction map and a compliance dashboard. Rebuilt in September 2026 for the amended EU timeline.
XLSX Download
DOC
AIBOM Readiness Checklist Forty six scored checks across six domains: models, datasets, code and dependencies, hardware and infrastructure, data processing pipeline, and governance. Includes format selection guidance, readiness bands, procurement clause language to require a bill of materials from suppliers, and the gaps seen most often.
DOCX Download
XLS
Framework Crosswalk: EU AI Act, NIST AI RMF and ISO 42001 NEW Added September 2026, and the highest value gap the manuscript audit identified. Twenty three control areas, each mapped to its EU AI Act article, NIST AI RMF function and subcategory, ISO 42001 clause, book chapter and the toolkit instrument that produces the evidence. You record where your evidence lives and whether you could produce it in one working day, which is the column a buyer questionnaire actually tests.
XLSX Download
DOC
Sovereign Stack 2.0 and PLACE Assessment Worksheet The five PLACE questions answered before a workload gets infrastructure, each with a place to record the evidence and whether the answer was measured or assumed. Plus the five vendor sovereignty questions from Chapter 14: jurisdiction, weight openness, modification rights, infrastructure independence and exit readiness.
DOCX Download
DOC
Human Oversight Design Template Mostly about degradation rather than design, because an oversight control that has degraded does not fail safe, it reports green. Four checkpoint patterns with their failure modes, four tests of whether the reviewer can actually act including the seconds per decision calculation, six anti rubber stamp measures each producing a number, and a quarterly degradation review.
DOCX Download
DOC
Regulatory Evidence Pack Template The Annex IV structure, the records behind the documentation with the instrument that produces each one, and the one day test: pick a decision from last month at random and ask for the full record of it. If any of the five tests takes more than a working day, you have a filing structure rather than an evidence pack.
DOCX Download
DOC
Serious Incident and Post Market Monitoring Runbook NEW Added September 2026. Articles 72 and 73 carry a fifteen day reporting clock from awareness, sooner where fundamental rights are affected, and no other instrument addressed it. An hour by hour and day by day runbook, the post market monitoring plan that is supposed to find the incident first, and a rehearsal record. The reconstruction phase is the only one whose duration you control before the incident.
DOCX Download
EXE

Execution, Finance and Leadership

5 Live
XLS
Agent Governance Business Case and CpCD Model Six tabs. A five year investment case with a sourced assumptions sheet, the do nothing versus governed unit cost trajectory, hard cost reduction kept separate from expected loss avoided, a two way sensitivity grid, the present value cost of a one year delay, and a one page board summary that states plainly whether the case stands on cost reduction alone.
XLSX Download
XLS
Twelve Month Agent Governance Sprint Tracker Twenty four items across four quarterly gates, organised by gate rather than as a task list, because a programme reporting eighty percent completion and failing its gate has learned nothing from the eighty percent. Each quarter carries an exit test a person outside the programme must verify, and each item records change load on the receiving team, because a change a team cannot absorb is queue rather than progress.
XLSX Download
DOC
Quarterly Board AI Governance Report Template Five sections a board can compare quarter on quarter, with the same five measures every time, each one a minimum or a worst case rather than an average. Includes the row that matters most, thresholds crossed without the consequence following, a section on what you would not be able to answer, the Chapter 16 board self assessment, and the five questions a director should put to a chief information officer.
DOCX Download
DOC
Book Club and Executive Reading Guide Six fortnightly sessions for a leadership team, each pairing a reading with an instrument run against a real system, and each ending in a decision the team records rather than a discussion. Session six asks each participant which of the Eight Commitments they could sign today, which is the useful outcome even when the answer is none of them.
DOCX Download
DOC
Toolkit Index and Implementation Sequence Rebuilt for twenty two instruments. Which instrument to use when and what kind of thing each one is, the ninety day sequence that deliberately produces no policy in the first thirty days, a reconciliation table naming which instrument is authoritative for each shared figure, and a one day version for a reader who has an afternoon.
DOCX Download

Be told when the calendar moves

Three dates in this book changed within seven months of publication. One of them changed six days before it was due to take effect. If you would rather not find that out from a regulator, subscribe and you will get the update and the revised register.

Placeholder Insert your email form shortcode here, or replace this whole div with the form embed. Suggested fields: email, role, and a single checkbox for which quadrant matters most to you, so the list can be segmented later.
Marked in the source as REPLACE_NEWSLETTER_FORM.
Steven Oppenheim

Steven Oppenheim

Enterprise Technology Executive and Author

Steven Oppenheim is a technology executive and published author with over twenty five years of global leadership experience driving enterprise scale digital transformations across Fortune 500 organizations. His engineering foundation informs a hands on approach to infrastructure challenges, from thermodynamics to network architecture.

When Agents Rule is the second book in the Sovereign CIO series, building on the cloud concentration risk frameworks introduced in When Clouds Fail. Where the first book asked how enterprises survive when their providers fail, this book asks how they remain in command when their own AI agents begin to rule.

MMBA, Cambridge University 2525 Plus Years Enterprise Tech CCIO Mastermind Senior Mentor AAuthor, Sovereign CIO Series
Also by Steven Oppenheim When Clouds Fail: Hybrid Sovereignty, Multi Cloud Resilience, and Agentic AI

Book one of the series. Four Pillars of Sovereignty, six interactive tools and forty four free templates, plus the live cloud outage tracker. Also available on Amazon.

Questions Readers Ask First

Short answers. The long answers are in the chapters named.

Do I need to read When Clouds Fail first?

No. When Agents Rule stands alone. Readers of the first book will recognize the sovereignty and financial discipline themes continuing, and the frameworks build on that foundation, but nothing here assumes you have read it.

Is this a technical book or an executive book?

Executive, with enough technical specificity to survive a conversation with an architect. The financial models in Chapters 10 and 11 are built for a CFO’s scrutiny, and the implementation roadmaps in Chapters 12 and 13 are built for organizational resistance rather than for a whiteboard.

The EU deferred its AI rules. Has the urgency gone?

No, and this is the most costly misreading available in 2026. The Digital Omnibus was adopted as Regulation (EU) 2026/1744 and moved exactly four dates: Annex III high risk to December 2027, Annex I to August 2028, national sandboxes to August 2027, and content marking for systems already on the market to December 2026. Everything else kept its date. Article 50 transparency applied in August 2026 and is enforceable now, the penalty regime has been live since August 2025, and the AI literacy duty has applied since February 2025. Two new prohibitions arrive in December 2026. Treating the whole regime as delayed means missing three live obligation sets while gaining time on one deferred set. The EU AI Act Deadline Checker runs this distinction against one of your own systems and tells you which of your dates have already passed.

The book was published in 2026. How current is it now?

The manuscript closed in mid 2026 and the Since Publication log tracks everything that has moved since, currently twenty eight dated entries. Four of them correct a figure printed in the book and they are listed in their own table rather than buried: the breach cost figure, the characterisation of Article 50, the federal post quantum planning date, and an additional Gartner prediction to cite alongside the existing one. The frameworks themselves have held, and in one case been independently arrived at by Gartner, which now recommends classifying agents by autonomy level and governing each level differently.

Are the composite executives in the book real people?

No. They are composite figures drawn from a quarter century of advisory work across industries and continents, and the book says so explicitly. Their situations are true in essence rather than in detail, and no character represents a single individual or organization.

Can I use the toolkit inside my company, and can I share it?

Yes to internal use, including adapting the templates for your own organization. All twenty two instruments are provided free for that purpose. For redistribution, training delivery or commercial use, see the usage policy linked below. None of it is legal, technical or financial advice, and the regulatory dates should be verified with your own counsel.

Twenty two instruments is a lot. Which ones actually matter?

Four, to begin with, and the Toolkit Index names them: the Agent Inventory, the Cryptographic Census, the FIPS 140-3 sheet in the Cryptographic Bill of Materials workbook, and the Regulatory Obligation Register. The first thirty days of the ninety day sequence deliberately produce no policy at all, because a policy written before the inventory governs the systems you already knew about rather than the ones that will cause the incident. The remaining eighteen instruments each answer a question you will not have until those four are populated.

Where do I start if I only have one hour?

Read the Executive Brief, run the Sovereignty Clock Reader above, and download the Agent Inventory workbook. That combination tells you which of the four quadrants is closest to midnight and gives you the register to start filling in. If you have a second hour, take the Friday Afternoon Test above. It scores five dimensions twice, once for what is designed and once for what you could evidence this afternoon, and the gap between those two numbers tells you whether what you have is governance or a document about governance.

The Clock Is Already Running

Get the book, read your clock, download the toolkit, or ask about an advisory engagement.

The eight diagnostics, in quadrant order