Boundary Mutation, Not Change Request
Change control for generative delivery

Boundary Mutation, Not Change Request

Typing the perimeter so surprise has to declare itself

AI broke the link between “the work got harder” and “the work got more expensive” — and your change-control clause is still keyed to the half that broke.

Implementation movement is not contract movement. The commercial object changes only when its perimeter does.

By the end of this book you can

  • ✓ Type eight perimeter fields with a recorded value and an observable trigger apiece
  • ✓ Classify any surprise as interior variation, typed surprise or boundary mutation
  • ✓ Settle a contested classification by comparison instead of argument
  • ✓ Run a reserve-exhaustion decision with a named owner, a window and a default
  • ✓ Say which variables actually predict your cost — and which stopped
  • ✓ Recognise the engagement where the honest answer is don’t fix this price
01
Part I: The Rule

The Change Request Nobody Should Have Written

Somewhere this week, a delivery lead is drafting a change request for work their own machine did while nobody was watching.

It is week three. The engagement was sold as a fixed commitment, and the estate has turned out to be messier than the sales conversation implied — which is to say, it has turned out to be an estate.

The agents that were meant to read three thousand pages have read fifteen thousand. An integration that was meant to take one pass took three. An entire approach was generated, tested, failed, discarded, and a second one was generated in its place. Somebody adds it up on a Thursday afternoon and it is unmistakably, visibly more work than the plan described.

Here is the part that should stop the room. None of it took a human noticeably longer. Most of it happened while the delivery lead was in a different meeting. The marginal cost of the whole episode — the extra reading, the failed approach, the two additional integration passes — would not buy lunch. But the statement of work has a clause about deviation from the agreed method, and this was a deviation from the agreed method.

So the change request gets written. And the client, who bought certainty, learns three things at once: that the fixed price was soft, that the supplier’s surprises are the buyer’s problem, and that “fixed” was a marketing word.

Key Insight

Nobody in that story behaved badly. The delivery lead followed the process. The process is what is wrong — it was designed for a world where a different method meant more expensive human hours, and it has not noticed that the world changed.

The rule, before the machinery

I am going to state the rule now, in the first few pages, and spend the rest of the book earning it. Books that build slowly toward their claim are usually hiding something about the claim.

Implementation movement is not contract movement.

A commercial change exists when a named perimeter field moves against a recorded starting value, or when a typed reserve exhausts. It does not exist otherwise. Everything else — the search, the retries, the regeneration, the ordinary discovery that reality is messier than the deck — belongs to the supplier, because that is precisely what the price already bought.

Definition

Boundary mutation

A boundary mutation does two things, and both are load-bearing. It names which agreed perimeter field changed, and it quantifies the delta against that field’s recorded starting value. A surprise that cannot do both is not a boundary mutation. It is the supplier’s own weather.

Notice what has been reversed. The old question was “was this in scope?” — an interpretive question, asked at the worst possible moment, answered by whoever argues better or has more to lose. The new question is “did field four move?” That is a comparison. You answer it by reading a table.

The belief underneath, stated plainly because it is the thing I actually care about: the buyer must never be billed for the supplier’s own search. Not because it would be ungenerous, but because the search is not a deliverable. It is the machinery. Charging for it is like a printer charging by the number of times it re-inked the roller.

Why this book exists at all

There is already an architecture for this kind of commitment, and it is published. A stable commercial perimeter around an adaptive, machine-scale production interior: rigid at the promise, fluid in the machine, rigid at proof. Scott’s own instinct for it was geometric — the old engagement shape was “an amorphous shape, many edges, many curves, difficult to explain”, and the AI-native one is a square. That book draws the square, and this one does not redraw it.

What that book did do, twice and in writing, is hand this particular test forward.

This is the treatment.

And because the credibility of everything downstream depends on it, let me be exact about what is borrowed. The reserve is not mine. Typed surprise, volume bands, the idea that unknowns become deliverables rather than labour — all of that is parent doctrine, already published, and this book references it rather than re-teaching it. What this book types is the trigger: the observable condition under which a field counts as having moved, agreed at signature, settled by comparison rather than by argument.

“If I promise to analyse your estate and one part turns out to require twenty agent-hours rather than two agent-hours, that’s my problem. The square absorbs it.”

What you will be holding at the end

Six things, all of them usable on Monday

  • Eight perimeter fields, each with a recorded starting value and an observable mutation trigger.
  • Three dispositions that replace the generic change request — and a default that means most surprises never reach anybody.
  • A complete engagement event log, classified — including four cases that were genuinely argued about, and the rule that settled each.
  • A reserve-exhaustion protocol with a named owner, a window, and a stated default for when nobody decides.
  • A sensitivity view of which variables actually predict what an engagement costs, and which have stopped predicting anything.
  • The conditions under which the honest answer is don’t fix this price — with a worked case where this rule refuses.

What this book is not

It does not re-teach the Fixed-Price Envelope, its census or its bands. It does not rebuild the service architecture. It treats acceptance as one perimeter field among eight — the semantics of acceptance evidence, what counts as proof and how a test earns the right to fail an engagement, deserve their own treatment and will get one. And it is not a clause library. Chapter 13 shows the shape of contract language and says so in a box you cannot miss.

Two objections are already forming, and both deserve one sentence here and a chapter later. Isn’t this just the supplier absorbing more and calling it doctrine? — no, because the same rule says when the supplier must reopen, fences six classes of variance it may never absorb, and contains a worked case where it refuses the fixed price outright. We already have a change-control clause — so does everyone, and yours specifies who may request, in what form and by when, and almost certainly never specifies what makes something a change in the first place.

That second objection is the more interesting one, and it is where the argument has to start. Because the clause we are replacing was not stupid. It was calibrated — a well-engineered instrument, pointed at a variable that used to track cost almost perfectly.

A rule stated is not a rule earned. So before the machinery: what that instrument was measuring, why it worked for thirty years, and the precise moment it stopped.

02
Part I: The Rule

The Proxy That Broke

The clause was not stupid. It was calibrated — and the thing it was calibrated against has moved.

Most people arguing about a change request believe they are arguing about scope. They are not. They are arguing about a plan of work, and the difference matters enormously.

Read the standard that most of the world’s delivery organisations were trained on. Integrated change control is described as the process of “reviewing all change requests, approving or rejecting changes, and managing changes to deliverables, project documents, and the project management plan”, and the entry rule is blunt: every change to a baseline requires approval, which is what “keeps scope, schedule, and cost under control and preserves traceability”.1 That is a description of PMBOK rather than PMI’s own wording, and it should be read as such — but it is how the discipline is taught and practised.

A baseline is a plan of work. So under the world’s most widely taught change-control standard, method movement and perimeter movement enter the same funnel — and once they are in the same funnel, nothing downstream can ever separate them again.

The commercial contract repeats the pattern with better manners. A change-control clause “aims to regulate change and exclude the possibility of informal, and perhaps inadvertent, variations being made to an agreement orally, or by conduct”, and a well-drafted one is procedurally complete: proforma request and response templates, “time limits for the steps in the change process and the consequences of non-compliance with those deadlines”, and a signed Change Control Note at the end.2

Read a dozen of these and the same thing is missing every time. They specify who may request, in what form, by when, and documented how. They almost never specify what makes something a change in the first place.

So how did that ever work?

Because the definition was doing its job somewhere else. Every change-control regime runs on an observable that stands in for the thing anyone actually cares about. Nobody can measure “cost has moved” at the moment a surprise arrives, so the clause measures something correlated and cheap to see.

Key Insight

Change control has a billing proxy. The proxy was deviation from the estimated method — and for thirty years it was an excellent one, because when production was made of expensive human hours, “we had to do it a different way” and “it cost more” were the same sentence.

That is why the missing definition was survivable. The proxy did the defining. Deviation was trivially observable, tightly correlated with cost, and cheap to adjudicate — three properties that make a gauge worth building a contract around.

What has happened since is not a moral failure and it is important not to write it as one. Nobody behaved badly. The gauge still moves. It no longer moves with the quantity it was calibrated against. This is an instrumentation failure, and instrumentation failures are silent by construction — the needle keeps twitching, so nobody checks the needle.

How far apart did they come?

Far enough to price. The cost of querying a model at a fixed level of capability collapsed from “$20.00 per million tokens in November 2022 to just $0.07 per million tokens by October 2024” — described by the people tracking it as “a more than 280-fold reduction in approximately 18 months”.3

What the interior actually costs now

280×

Fall in the cost of a fixed level of model capability, Nov 2022 to Oct 2024

$6.00

One full agentic session on a premium model — read the codebase, implement across files, run tests, debug the failures

$0.60

The same session on a cheaper model. Illustrative figures, not a rate card

At the level of an actual task, one current account of agentic coding describes “a single agentic task where the AI reads through a codebase, implements a feature across multiple files, runs tests, and iterates through failures” and puts it at roughly “$6.00 per session on Opus versus $0.60 on Composer 2 Standard”.4 Those are the author’s own illustrative figures based on representative usage, not measured client data, and they should be read as an order of magnitude rather than a price list.

The order of magnitude is the whole argument. Set six dollars beside one senior consultant’s morning. That gap is what your change-control clause has not been told about.

You will notice I have not told you what a change request costs to process. That is deliberate: there is no figure for it that survives checking. I looked. What can be said honestly is the shape — the cost of processing the request now routinely exceeds the cost of absorbing the work it describes, and once that is true the instrument is not merely imprecise, it is inverted.

Absorber, not hedge

Scott’s first formulation of this was that “AI is your hedge at doing all the runaround — turning the amorphous shapes and change requests and the inconsistencies and unexpected pieces, and reining them in.” The instinct is right. The word is wrong, and the correction happened in the same conversation, which is worth showing rather than smoothing over.

“Calling AI a hedge is intuitively right, but technically I think elastic capacity or variance absorber is stronger. A financial hedge offsets risk. AI does not guarantee your risk decreases. What it does is radically reduce the marginal cost of responding to many forms of variance.”

That distinction is not pedantry; it is the whole load-bearing structure of the argument. Risk did not fall. The cost of responding fell. Every over-claim in this territory comes from collapsing those two, and this book will be accused of the collapse whether or not it commits it. Our own earlier statement of the same idea is careful in the same way: AI “does not make the cost curve flat. It makes it flatter — and it changes which variable drives it.”

And here is the evidence against

A chapter that presents only the favourable half forfeits the right to be believed in Chapter 11, so take the counterweight now. The 2025 DORA research, drawing on survey responses from nearly five thousand technology professionals, reports that “AI adoption does continue to have a negative relationship with software delivery stability”, and frames it as a confirmation rather than a surprise: “AI accelerates software development, but that acceleration can expose weaknesses downstream.”5

Which gives us the sentence the rest of the book is built on:

Bottom Line

The marginal cost of another attempt collapsed. The marginal cost of verifying the attempt did not.

That is exactly why the topology is rigid at the promise, fluid in the machine, rigid at proof — and not a general presumption that the supplier absorbs whatever turns up. A free interior only works with hard boundaries at both ends of it.

The instrument that stopped working

There is a strange piece of corroboration for all of this, and it comes from the most rigorous attempt anyone has made to measure what AI does to developer productivity.

In July 2025, METR ran a randomised controlled trial on experienced open-source developers and found that “when developers are allowed to use AI tools, they take 19% longer to complete issues” — while believing they had been sped up by twenty per cent.6 The result travelled widely, including through our own writing.

But the reason METR changed the experiment is worth more than the number ever was. They could no longer make elapsed human time mean anything:

“Some developers reported it was challenging to report time-spent in completing tasks when they used agentic tools, because they would often work an unrelated task while waiting for the agent to complete its work.”
— METR, We are Changing our Developer Productivity Experiment Design, February 2026

Nor could they obtain the counterfactual. “30% to 50% of developers told us that they were choosing not to submit some tasks because they did not want to do them without AI.”7 The comparison condition — working the old way — had become something people would not agree to for money.

Read that as a commercial finding rather than a methodological one, because that is what it is. A research organisation with randomisation, screen recording and paid incentives could not keep human-hour accounting meaningful for AI-assisted work. A professional-services firm, holding none of those instruments, is billing against it.

A note on Agile, and then we move on

It is worth one paragraph, because it explains why the machinery exists at all. The management substrate — sprint capacity, story points, velocity, estimation, resource scheduling — grew up around a scarce and expensive resource. As Scott puts it: “It was born out of the idea that the engineer is the brilliant, expensive piece of the work… So we put all this stuff on top to manage the delicate genius. That model’s gone away.” The precise version of the claim is not that Agile dies — users still do not know what they want until they see something — but that the labour-management layer of Agile depreciates. And Scott’s own correction to himself is the sharpest form of it: “In the absence of Agile, I thought some sort of waterfall must prevail. But it’s the fixed price that prevails.”

That is the last this book will say about production cadence, which has its own treatment elsewhere. We are one level above it, at the commercial topology, and the two should not be confused.

The decision nobody made

Strip the professionalism off a time-and-materials engagement and the sentence underneath is: we don’t know exactly what reality will require, so you buy access to our people while we discover it. That is not a billing convention. It is a decision about who owns the supplier’s production variance — made once, decades ago, and inherited ever since.

“The customer effectively owns a significant portion of the supplier’s production variance.”

Nobody chose that this year. It was the only economically sane answer for as long as the middle of an engagement was made of expensive human hours. It is not the only answer now, which means the question who owns the production variance? has stopped being an inherited default and become a design decision — one that somebody in your firm is currently making by not making it.

So the old test is broken and the reason is precise. What replaces it is not a better change-request process. It is a classification that happens before any of this — with three outcomes, and no fourth.

03
Part I: The Rule

Three Dispositions

Three outcomes, three decision-makers, three speeds — and no fourth.

The instinct, when you are told your change-control clause is broken, is to reach for a better change-control process. Resist it. That instinct is the failure repeating itself one level up.

Every change-control regime ever written is a procedure for handling a surprise after it has arrived. That is the design flaw, and it is upstream of every detail. By the time the procedure runs, both parties have a financial interest in the answer, at least one of them is embarrassed, and the relationship is the loudest thing in the room. Under those conditions the answer is not determined; it is negotiated.

So move the decision to a point where nobody has an interest yet. Classify the possible surprises before the engagement starts, into three classes, and let each class carry its own consequence automatically. After this chapter, every surprise you meet has exactly one home, and arriving at that home is a lookup rather than an argument.

The three dispositions. Every surprise in a bounded engagement lands in exactly one of them.
Disposition What it means Commercial effect Who decides
Interior variation
the supplier absorbs
Method, prompt, model, code, sequencing, regeneration, analysis route, ordinary implementation surprise — while every perimeter field still holds its recorded value. None. No request, no note, no log entry against the buyer. The band was priced knowing these happen. Nobody. It is the default, and the default is silence.
Typed surprise
a named reserve absorbs
A pre-declared exception class occurs inside the perimeter: access delayed or narrowed after contract, an unsupported source the client still needs interpreted, exception density above the band’s assumption. The reserve draws down by a published rule, visibly, until its band is spent. Unconsumed reserve is not consumed. The delivery lead, against the published rule. Logged, not negotiated.
Boundary mutation
re-contract
A named perimeter field has moved against its recorded value — or the reserve has exhausted. Stop; name the field; quantify the delta; present four options — uplift the band, extend the reserve, narrow the boundary, or stop. A named commercial owner on each side, within a stated window.

Read those rows as three different Thursdays. In the first, nothing happens: the work is harder than expected, the team does more of it, and the buyer never learns. In the second, a line moves on a counter the buyer can already see, and somebody sends a one-paragraph note saying which trigger fired. In the third, a named person on each side has a scheduled conversation inside five days with a delta and four options in front of them. Three classes, three decision-makers, three speeds.

A taxonomy whose classes share a decision-maker is a relabelling. One whose classes have different decision rights is a governance design.

Why three, when the parent draws two?

The published architecture draws two categories — absorbed and crossing — and folds reserve exhaustion into the crossing list as one bullet among eight. As a description of what crosses a perimeter, that is exactly right. But a reserve draw is structurally unlike both of its neighbours, and not by degree.

Collapse it in either direction and you get a specific, predictable failure.

Collapse it into interior variation and the buyer never sees the meter until it has run out. Every earlier absorption was invisible, so when exhaustion finally arrives it arrives as a bill from a supplier who has never mentioned any of this before. The absorptions bought no credit, and the reopening reads as opportunism.

Collapse it into boundary mutation and you re-contract because an access approval was four days late. That is precisely the behaviour the whole rule exists to prevent, now wearing the rule’s own vocabulary — which is worse than not having the rule, because it is harder to argue with.

Which gives the test for whether a fourth class is ever warranted: a disposition earns its own class when its commercial consequence differs in kind from both neighbours. Reserve draw passes. Nothing else in this space does, which is why there are three.

What is inherited here, and what is not

The reserve is not mine. It is defined in the parent doctrine as “a named, priced absorption layer for typed surprise”, drawn against typed events, “visible to both sides”, and governed by the rule that “what is not drawn is not consumed”. The trigger classes and the exhaustion behaviour are equally established: exceptions consume reserve units by a published rule, and exhaustion “produces a commercial conversation with a census delta and a recommendation”.

So say it plainly rather than letting a reader infer generosity that is not there: this book adds the trigger, not the reserve. If you want the census, the bands and the six parts of the envelope, they are published and cited, and re-teaching them here would spend the chapters this book needs for its own contribution.

The default is the design

Here is the part that decides whether any of this survives contact with a delivery organisation, and it is not the taxonomy. It is which disposition is the default.

A classifier with no default produces a change request for everything — for the same reason an assistant with no threshold narrates every event and trains you to ignore it. Volume is not diligence. A hundred-row change log is not governance; it is a record of a hundred arguments, and its length is a symptom.

The structural fix is a null option that is always available and always compared against. In our own work on when a system should stay silent, that is stand-pat, and what makes it useful is precisely that it is structural rather than clever — it “works with zero domain knowledge, because all it does is compare the best available move against the value of doing nothing”.

The framing transfers exactly, and I will use it once and then leave it alone. Almost every event in a bounded engagement is a capture: available, tempting, and perfectly safe to leave alone. A very few are checks — real threats you are genuinely not allowed to ignore. The entire skill is telling those two apart, and defaulting to silence for everything that is not a check.

Key Insight

Interior variation is the default and requires no decision by anybody. A surprise becomes commercial only by earning its way out of the default — and it earns its way out by moving a named field.

There is a quiet commercial benefit in that arrangement which is easy to miss. It removes the delivery lead’s discretion in the direction where discretion is most expensive. Under the old clause, absorbing something is an act — someone chooses not to raise a request, and that choice is invisible, unrepeatable, and becomes an unacknowledged precedent. Under this rule, absorbing is what happens when nobody does anything. Nobody has to be brave.

“In conventional delivery, almost any newly discovered complexity can become a change request. In this model, ordinary implementation complexity should not.”

Who stops the supplier calling everything interior?

Two things, and both need their own chapter. First, interior is not a judgement — it is a residual. It is what remains when eight named fields have each failed to move, which means the supplier cannot classify something as interior by deciding to; it can only observe that nothing moved. Second, the fields carry recorded values that the buyer agreed to and in several cases supplied. Chapter 5 builds the fields; Chapter 6 makes the values real.

And the mirror objection — what if the reserve is never drawn? — has a published answer rather than a negotiated one: what is not drawn is not consumed. Chapter 10 makes that operational, including the case where it is never drawn at all, which is a pricing defect rather than a windfall.

The classification is now complete, and at this moment entirely unusable. Every row of it turns on the phrase while every perimeter field still holds its recorded value, and nothing so far says what those fields are. Before the fields, though, there is something the reader deserves to see: exactly how much the supplier has just agreed to own — and precisely where that agreement stops.

04
Part I: The Rule

The Interior, and Its Fences

What the supplier has just agreed to own — and the six things it must never promise to absorb.

Read the interior as a commitment being read aloud, because that is what it is. Not a principle, not a posture — an actual list of things the supplier has agreed never to charge for.

Say it that way and the list turns out to be longer and stranger than “a bit of rework, a couple of extra days”. The surprise is not the length. It is what is on it. So: one item at a time, with what each one costs and why it stays inside.

The interior, item by item

An approach fails its test and the system generates another. This is not rework in the old sense, because nothing is being repaired. A candidate died and a replacement was produced. If the buyer paid for candidate mortality, they would be funding the search they explicitly did not buy — and they would be funding it at exactly the moment it was working.

An integration needs three regeneration attempts rather than one. The retries are real money, and they are not linear: “when the agent hits a test failure, tries a fix, fails again, and tries another approach, each retry cycle is a full round-trip at the current (inflated) context size”.4 Still interior. The perimeter did not move; only the path did.

The evidence base is rebuilt because the first assembly was structurally wrong. This is the most galling one to absorb, because it is the supplier’s own error. It is also the clearest: rework of the supplier’s mistake has never been a customer change, and cheap machine labour does not make it one. A rule that quietly exempted the supplier’s own errors would deserve every accusation it got.

Fifteen thousand pages instead of three thousand. Volume within a declared source class. Hold that phrase, because it does a lot of work later: the class is a perimeter question, the volume is a band question with a published threshold, and the shape a source arrives in is neither.

Two authoritative sources disagree and reconciliation takes four passes. The machine runs the passes. What it cannot do is decide which source wins, and that decision is the first appearance in this book of the thing that actually costs money. The passes are nearly free. The disposition is not.

A source arrives in a form nobody anticipated and needs an adapter written on the spot. One line to carry: shape is method, class is perimeter. An adapter is a Tuesday. A new class of source is a conversation.

A declared constraint set turns out to have an internal dependency nobody mentioned, forcing the whole option space to be re-tested. The constraints were declared; their interaction was not understood. Understanding the constraints is the work, not a change to it.

Why it is supposed to look wasteful

Seen from outside, the interior of a good engagement is embarrassing. Eight framings built and six thrown away. The evidence base assembled twice, because the first assembly used a source that turned out not to be authoritative. A whole line of analysis dying on a constraint discovered in week three. As the parent architecture puts it: if a client watched that on a timesheet, they would ask why they were paying for the six.

“They are not. That is the entire commercial point of the square: the buyer bought a state, and the search that produced it is the supplier’s business.”
— the architecture this rule governs

There is something to add to that, which the parent does not say. The waste is not a tolerated side effect. It is the mechanism. Discarding six framings is how the seventh gets found. A supplier who optimises for not wasting machine work is optimising against its own product, and will produce narrower answers more cheaply than a competitor who lets the machine be profligate inside a boundary.

Regeneration beats patching

The canonical case, and the one most likely to be misfiled under the old clause. When code generation is cheap and code surgery is expensive, the economics invert: you want detailed specifications up front, ruthless evaluation harnesses, and “regeneration over patching — because fresh generation beats accumulated patches”. The delivery-side statement of the same rule is blunter: “prefer regeneration from improved intent over endless surgery on near-miss code”.

Why does a production rule belong in a book about contracts? Because under the old clause it is the most change-request-shaped event imaginable: work was thrown away and started again. Under this rule it is a production decision inside an unmoved perimeter, and the buyer never hears about it — which is correct, because the buyer is not qualified to have an opinion about it and should not be asked to fund one.

One honesty note, since this is a claim about cost. There is no external empirical study measuring regeneration against patching in production codebases. I looked for one. The argument rests on our own design reasoning plus the indirect evidence that retries at high context are superlinear — and the shape of that argument is what you should carry, not a number I have not got.

Where the absorption stops

Now the other half, and it deserves equal weight. A book that spent seven chapters on what the supplier absorbs and then quietly added exclusions at the back would be doing exactly what the statements of work it criticises do.

Important

Absorbing everything is not generosity. It is an unpriced promise — and an unpriced promise is what destroys suppliers, quietly, one engagement at a time.

Six fences. What the supplier does not absorb, why cheap cognition does not touch it, and where it belongs instead.
Fence Why cognition does not help Where it belongs
Physical work Trucks, stock, technicians, laboratories, buildings, working capital. Machine cognition improves the cognitive and coordination curve; it does not repeal physics. A separate commercial object, priced against real capacity — not a line inside the square.
Third-party decisions and timetables If the critical path runs through an organisation that is not a party to the contract, you are selling somebody else’s calendar. Explicit exclusion, with the state it produces typed as valid and deliverable — blocked pending third party.
Buyer delay Absorbing it teaches the buyer that dates are decorative, and it consumes calendar — which is where the supplier’s scarce humans are actually spent. The reserve first, then the perimeter. This is the fence most suppliers breach in the generous direction.
Unlimited exception tails A reserve with no band is not a reserve. It is a promise to absorb reality indefinitely, made by someone who has not met reality yet. A declared band with an exhaustion decision attached — Chapter 10.
Liability the supplier cannot control Better analysis lowers the probability of an error. It does nothing whatsoever to the cost of the one you make. A capped, closed-list liability clause — and its own perimeter field, argued in Chapter 5.
Open-ended intent If the declared intent has not survived two contacts with evidence without changing shape, there is no perimeter to draw around it. Sell the bounding as its own commitment — Chapter 12.

The first two are grounded in delivery physics rather than doctrine: every commitment in a commercial boundary has to map to “an operational pathway that exists or is funded to exist”, and physical scarcity belongs in the offer design rather than being “wished away by the AI narrative”. The failure they prevent has a name: a brochure the operations network cannot honour.

A rule only the supplier can invoke is not a rule

This is the first statement of a test that returns in Chapters 11 and 13, and the fences are where it gets paid. They are the buyer’s protection, and they are stated by the supplier, in the contract, before anyone needs them.

That sequencing is the whole credibility of the thing. A fence disclosed at the moment it is needed is not a fence; it is an excuse with a clause number. Which is also why they appear here, in Part I, rather than in some late chapter about limits — a book that hid its exclusions at the back would have reproduced the exact pathology it is trying to replace.

What is left, once all that is absorbed

Not machine work, and not calendar. What remains scarce is the number of consequential judgements a named human must own. That is the metered resource, it is what the band actually prices, and it is the reason the interior can be free without the engagement being free.

Scott’s version of the same observation is less formal and easier to remember: “AI’s just gobbling up all those middle bits to keep the project bounded in time and resources and how it operates in the real world.” The middle bits are gone. The judgements are not.

The arithmetic of that claim is Chapter 11, and it will be tested rather than asserted. But every distinction in this chapter was made by hand, in prose, by an author who agrees with himself. None of it would survive two people disagreeing at eleven o’clock on a Thursday. What is missing is the instrument: eight fields, each with a value written down, and a condition that says — without interpretation — whether it moved.

05
Part I: The Rule

The Boundary Mutation Matrix

Eight fields. A recorded starting value, an observable trigger, and a pre-agreed response for each.

Before the instrument, the test that makes it an instrument. Handing over a table without its test produces a longer list, not a rule.

The trigger test

A trigger that requires judgement at dispute time has failed.

Expand that precisely, because it is the sentence you will be applying to your own draft. If settling whether the field moved requires an argument, a partner’s memory of the negotiation, or a reading of anyone’s intent, the field is not typed. It has been named, which feels similar and is not the same thing at all.

There are exactly two permitted responses to a row that fails. Rewrite the trigger as a comparison against a recorded value — or say in the contract that this field is untyped, and price accordingly. The second is not a defeat. An untyped field that both parties know is untyped is manageable; one that looks typed is a trap that will spring at the worst possible moment.

And to be clear that this test is allowed to bite: the book applies it destructively to its own matrix in Chapter 9, and one row fails in practice. A design rule that never costs its author anything is decoration.

The matrix

The Boundary Mutation Matrix. Fields 4 and 6 are additions to the parent architecture’s perimeter, and the reason is argued below.
Perimeter field Recorded at signature Observable mutation trigger Commercial response
1. Promised state The bounded end state as one testable sentence, plus the valid terminal states — including the uncomfortable ones. The signed sentence would have to change to describe what is now being asked. Read it aloud: does the request fit inside it without adding a clause? Re-contract. The one field where latitude has no room at all.
2. Authoritative input estate Declared source classes, the named systems in each, who warrants each one, and access status at signature. A source class not on the declared list is required; or a declared source is withdrawn, replaced, or re-warranted to a different party. Re-contract, or type the new class as excluded from this phase.
3. Volume / band The census counts that assigned the band, each with its measured number, and the band’s upper threshold published. A census metric crosses its published threshold. Purely arithmetic: re-run the census, compare to the recorded number. Band uplift at the published rate. A re-configuration, not a negotiation.
4. Buyer-controlled dependencies Every input the buyer owes — access grants, environments, nominated people, decisions, third-party cooperation — each with an owner’s name and a date. A dated buyer obligation passes its date unmet, by the number of days stated in the schedule. Reserve draw first. Beyond the band, or where the critical path moves: re-contract with a revised time boundary.
5. Authority and access Who signs what on which side; which classes of action may be autonomous; the security and privilege model the work runs under. A new signatory or approving party is required; an approval class crosses the table; or the privilege model narrows after contract. Re-contract. An added approver changes the disposition path, and the disposition path is the meter.
6. Consequence / liability class The cap, the carve-outs as a closed list, the standard of care, and the intended use of the deliverable. Intended use changes; a regulator or a fitness-for-purpose obligation enters; a carve-out is requested outside the closed list; the cap is asked to move. Re-contract and re-underwrite. Never absorbed, never reserved.
7. Acceptance rule The observable event that closes the engagement, written so that it can fail, plus who runs it. A new acceptance condition is proposed; the agreed test is declared insufficient by the party that agreed it; or the named runner changes. Re-contract. A failed test under the agreed rule is not a mutation.
8. Fixed time boundary The end date, what the date means commercially, and whose clock each dependency runs on. Either party asks to move the date; or a field 4 obligation has pushed the critical path past it. Re-contract. Compression counts as much as extension.

A table read is worth more than a table printed, so take the rows that carry the most weight in practice — and the mistakes people make with each.

Field 1 fails when the promise is written as a deliverable. “A report” is a deliverable; “a decision the board can act on” is a state. A deliverable-shaped promise cannot detect its own mutation, because almost anything can be added to a report without changing the noun.

Field 2 is where three different complaints get confused, and the distinction is worth hammering: class is perimeter, volume within a class is field 3, and shape within a class is interior. Three different answers to what feels, in the room, like the same grievance.

Field 3 is not a price for volume, even though it looks like one. It prices volume because volume correlates with dispositions — and the strength of that correlation is a design assumption, not a law. Chapter 11 tests it, and Chapter 9 shows what happens when it fails.

Field 4 exists because buyer delay is the most commonly absorbed cost in professional services, and the one suppliers feel least able to raise. A field with a name and a date raises it automatically, which is precisely the point: nobody has to be the person who mentions it.

Field 7 has a distinction that saves it. A failed acceptance under the agreed test is not a mutation — it is “a defined state with a defined remedy, and the remedy is inside the band”. If a failed test created a commercial event, the test would not be a test. (What counts as acceptance evidence, and how a test earns the right to fail, is a subject in its own right and gets its own treatment; here acceptance is one field among eight.)

Field 8 catches people out in the direction they do not expect. Compression is a mutation as much as extension — a shortened boundary changes the disposition schedule, and usually costs more than an extension would.

Why field 6 has different physics

Seven of these rows can, in principle, be traded. A bigger band for a bigger fee. A later date for a narrower promise. Field 6 cannot, and the reason is insurance rather than commerce.

Without a contractual cap, professional liability is not large. It is unbounded: “without a contractual limitation, liability is unlimited and could exceed the level of cover maintained under your PI policy”. And some obligations are uninsurable at any price — “fitness-for-purpose obligations should be avoided as they are generally uninsurable under a PI policy provided to a professional services provider”.9

Caps hold, and they hold far below the loss — which is the point rather than a scandal. American engineering practice records a $50,000 limitation enforced even though it “accounted for only 8% of the designer’s fee”, and another that limited recovery “to only $550,000 out of a $9.5 million jury verdict”. The rationale is stated without embarrassment: design professionals’ “fees do not cover the potential that they can be liable for virtually unlimited financial exposure if there is a claim”.10

The gap between a fee and a consequence

8%

What a $50,000 liability cap had shrunk to, as a share of the fee, by the time it was enforced — because scope moved through addenda and nobody reopened the cap

$550k

Recovery permitted out of a $9.5 million jury verdict, under an enforced limitation-of-liability clause

That first case is the one this book exists to write about. The cap had been set as a percentage of the original fee. Scope was then added through a series of addenda. Nobody reopened the cap. By the end it was eight per cent of what the designer was being paid — and the court enforced it anyway, and said exactly why:

“The failure of (the contractor) to address or renegotiate the limitation of liability clause during the execution of each addendum has made the term of the contract more burdensome than previously anticipated… This court is unwilling to allow (the contractor) to avoid a term of the contract simply because it has become more burdensome due to its own failure to renegotiate.”
Zirkelbach Construction Inc. v. DOWL LLC, as reported in ASCE’s Civil Engineering

Two things follow, and the second matters more than the first.

One: that is a litigated example of a perimeter moving while the contract stood still. The exact failure this matrix is built to catch, from an industry with no interest in our argument.

Two: it cut toward the buyer. The party who wore the exposure was the one purchasing the services, who believed they had transferred a risk they had not. If you want evidence that this instrument is not a supplier’s convenience, it is here: the matrix protects whoever is paying attention, and in that case nobody was.

Hence field 6’s response is stated as an absolute rather than a default. Re-contract and re-underwrite. Never absorbed, never reserved.

Six inherited, two added

Say it out loud rather than smuggling it. Six of these rows are the parent architecture’s perimeter fields, re-cut for change control — a perimeter described there as needing to be “explicit enough that surprise has to speak the product’s language before it can reach the invoice”, with the warning that a service which cannot answer those eight questions “is not a square. It is a wish with an invoice schedule.”

Fields 4 and 6 are additions. The parent treats buyer dependencies and liability class only as reasons to decline an engagement, and the argument for promoting them is structural rather than preferential:

“Eight fields is too many for our SOW”

Then you do not have a bounded engagement. You have a price. Every one of the eight is already implicitly promised in any fixed commitment — the matrix does not add obligations, it makes existing ones legible.

“Our clients will negotiate every trigger.” Good. That negotiation is the product working. It happens once, before signature, rather than repeatedly during delivery under relationship pressure. “What about a field we cannot type?” The trigger test already answered that: say so in the contract and price it — and if enough fields are untyped, Chapter 12 has a stronger answer, which is to decline the fixed price entirely.

“So I’d replace a lot of change-request logic with boundary-mutation logic. That is a considerably cleaner distinction.”

It is cleaner. It is also, at this moment, a document. Every row above rests on the phrase recorded starting value, and nothing so far has said where those values come from or who is allowed to change one afterwards. Both answers are next — starting with what happens when the values were never recorded at all, which is not the exotic failure but the ordinary one.

06
Part I: The Rule

Typed at Signature, Not Argued at Dispute

Where recorded values come from, and who is allowed to change a trigger afterwards.

Here is how the ordinary failure runs. Not a cautionary tale about a bad supplier — a mechanism, in sequence, that good firms execute perfectly.

A firm sells a bounded engagement well. Competent team, fixed commitment, a buyer who is pleased. The band is assigned from a sales conversation rather than a measured input surface, because the buyer is in a hurry and running the preflight measurement “would have delayed the start by a week”.

Delivery begins. Interior variance happens, and is absorbed — correctly, and invisibly. Boundary movement also happens: two more sign-off parties appear; a source class nobody declared turns up in week three. Nothing distinguishes the two, because nothing was measured at the start. The supplier absorbs both, and privately congratulates itself on not raising a change request.

Margin erodes silently, then quickly. And then the supplier reopens the price anyway — later, worse, and with less evidence than it would have had in week three. The buyer experiences that reopening as the old change request in new clothes, and the trust the whole arrangement was supposed to buy is spent in a single meeting.

The diagnosis, in one sentence

No measurement, therefore no band drivers with values attached, therefore no delta available when reality arrived — therefore no language in which surprise could speak.

Same reality, two starts

✗ The unmeasured start
  • • Interior variance is real and gets absorbed — correctly, and invisibly
  • • Boundary movement is also real, and looks identical from the inside
  • • Nothing distinguishes them, because nothing was measured
  • • The supplier absorbs both and calls it good client service
  • • Margin erodes silently, then quickly
  • • The price is reopened anyway, at the worst possible moment

Outcome: the buyer sees the old change request wearing a new coat.

✓ The measured start
  • • The same two events occur — reality does not care about your process
  • • Both are recognised within a week, because a named field moved against a recorded value
  • • A delta is presented with evidence
  • • Four options: uplift the band, draw the reserve, narrow the boundary, or stop
  • • The buyer chooses, in possession of the facts, early

Outcome: same money at stake, entirely different relationship — because surprise had a language.

The predictable objection is that this is an execution mistake — a team that should have known better. The parent architecture answers it with a test worth keeping: an execution mistake is one a better team would not make, and both halves of this failure were made by good teams doing everything their process asked of them, because no step in the method said measure before quoting.

“A failure that survives competence is the definition of a missing structure rather than a missing effort.”

“You’ve moved the argument, not removed it”

Yes. Completely, and the concession should be made before the defence.

The matrix does not abolish disagreement about perimeters. It relocates it — from week three of delivery, when both parties have spent money, one of them is embarrassed and the relationship is the loudest thing in the room, to the week before signature, when neither has spent anything and both can still walk away.

And it changes the form of the argument, which matters more than the timing. Interpretation has no natural end; two competent people can interpret a scope paragraph in opposite directions indefinitely, and the winner is whoever has more stamina or more leverage. Comparison ends: you read two values and one of them either matches or does not.

There is an honest residue, and it is worth naming. The disagreement that remains at signature is real disagreement about what is being bought, and it is worth having — some of those conversations will end in no deal, correctly. What the matrix removes is the manufactured kind: the disputes produced entirely by an ambiguity that both parties quietly preferred at the time.

Where the recorded values come from

From the same machinery that will deliver the engagement, measuring the input surface before the promise is made — which is parent doctrine and is referenced rather than re-derived. The important property is that the measurement is “a free byproduct of the machinery, not a paid discovery phase”, which is what makes it possible to insist on it without asking the buyer to fund an extra stage.

Then publish the drivers, even if you never publish a price. A buyer who understands why they are in this band will accept a delta against it. A buyer who does not will hear any delta as a renegotiation. That is the cheapest trust purchase available in this entire scheme, and most firms skip it because they confuse driver transparency with cost transparency. They are not the same thing.

Be precise about what “recorded” means, because vagueness here quietly undoes everything above it. A recorded value is a number or a sentence, dated, in a schedule attached to the contract, with the method of measurement named. Not a paragraph in a proposal. Not a slide. Not “as discussed”.

Working exclusions, not decorative ones

There is a sentence in our own canon that belongs here more than anywhere else: exclusions that name systems, work types, time periods and decision rights “survive contact with a change request” — while decorative ones are “paragraphs that list what is out of scope without operational teeth”.

Tie that to specific rows or it becomes a general virtue nobody acts on. Field 2: an excluded source class must be a typed state, not a silence — the difference between “we did not look there and here is the state that produces” and a gap the buyer discovers later. Field 6: an excluded consequence class must name the use it excludes, because “not for external reliance” is a fence and “general limitations apply” is not.

The test to hand a delivery lead is simple enough to apply in a meeting: when a client asks whether something is in scope, the answer should be findable from the compiled objects, not from a partner’s memory of the negotiation.

Same words in three places

Write the typed catalogue into the contract schedule, not only into the playbook. If the types live only in a slide deck, delivery will invent synonyms under pressure and the commercial boundary will blur. Same words in contract, software and report.

That is a change-control point rather than a documentation point, and the reason is mechanical: a trigger is a comparison, and a comparison requires both sides to be naming the same object. Synonym drift is how a typed field silently becomes an untyped one — nobody decides to un-type it; the words just stop matching. The trigger column in your matrix, the status enum in your delivery tool, and the vocabulary in the report have to be one vocabulary in three places.

Who is allowed to change a trigger?

This is the section most treatments would skip, and it is the one that decides whether the matrix survives a sales cycle.

The failure to prevent is silent overrides by sales to win a logo. The parent doctrine is unsentimental about it: create a light monthly review board for threshold edits, using review-economics data, because “if anyone can redefine Band M in a proposal footnote, you are back to authored pricing with extra steps”.

Governing the matrix — five lines

  • Publish the drivers, even if you never publish a price.
  • Record the values in a schedule, dated, with the measurement method named.
  • A light monthly review board owns threshold and trigger edits.
  • Triggers are revised between engagements, never during one.
  • When an exception class recurs, promote it into a first-class state or a band driver.

The fourth line is an absolute and should be treated as one. A trigger edited mid-engagement is not governance; it is a renegotiation conducted unilaterally by whoever happens to hold the document.

The fifth is the constructive half, and it is how the instrument improves. When the same exception class keeps appearing, promote it into a first-class state or a band driver “rather than leaving it as endless Flex Reserve folklore”. The envelope is supposed to learn between engagements; the review board is where that learning is booked.

The sentence to keep

A perimeter you did not measure is a perimeter you cannot defend — and a supplier who cannot defend its perimeter will absorb things it never agreed to and then reopen the price anyway, which is strictly the worst of both worlds.

Which is why the phrase to distrust, wherever it appears in a proposal, is “we’ll clarify unknowns during delivery”. That is how fixed-price certainty products become ordinary projects with better marketing. If an unknown is material, it is a typed deliverable, a reserve item, or an explicit exclusion. It is never a smile in a steering committee.

A fixed price without a measured input surface is not a square. It is bravado with a schedule — and the schedule makes it worse, because it delays the moment of honesty until the money is already spent.

The rule is now complete as doctrine: three dispositions, eight fields, a trigger test, recorded values, and a governance regime that stops the instrument being edited by whoever wants the deal most. And so far, as far as any reader can tell, all of it is mine — which is the weakest possible position for a commercial rule to be in. Before the specimen, there is an accounting owed: what already exists, who has been doing parts of this for decades, and the one move none of them make. That accounting includes an admission, because typing a trigger has a price, and the insurance industry has already paid for the lesson.

07
Part I: The Rule

What Change Control Already Knows

Five families that already do parts of this, the one move none of them make, and the named price of making it.

Almost everything in the last four chapters has a precedent somewhere, and in three cases the precedent is older, better tested and considerably more litigated than anything in professional services.

That concession is not modesty. It is the argument. A rule presented as an invention invites a reader to hunt for the flaw; a rule presented as an adaptation invites them to look for the delta — and the delta is the only thing this book actually has. So the honest position is narrow: professional services is the outlier. Industries that sign ten-year, nine-figure commitments stopped treating every deviation as a commercial event a long time ago. We never adopted the discipline, because while production was human, we did not need to.

NEC: triggers that are enumerated and exhaustive

The closest external relative, and it is not close by accident. In NEC contracts a compensation event “means an event which can affect the cost to the Client of the work being carried out, the time when the works will be completed, or both”. Then the sentence that makes it a genuine ancestor:

“A compensation event is the only way in which these can be changed. There are no other ways in which a Contractor can claim additional payment for carrying out the works or be allowed additional time in which to complete them.”
— NEC Contracts, on clause 60

Clause 60.1 enumerates the events, and the list is exhaustive by construction — extended only through named options or additional entries in the Contract Data. Crucially for this book, it puts client-side failures inside the same typed list: “a failure by the Client, the Project Manager or Supervisor to take an action which the contract requires them to do”. Field 4 of the matrix is not an exotic idea. It is standard practice in an industry that has been doing it since the 1990s.11

NEC also shares the instinct to type things prospectively rather than retrospectively: unlike JCT, which primarily values variations after the fact, NEC “requires a prospective assessment of both the time and cost implications of a change at the time it is identified”, inside a tight response window with deemed acceptance if the assessor stays silent.12

What NEC does not do is the move this book makes. It still assesses each event’s cost and time effect individually, event by event, with a quotation for each. It prices the work. The matrix prices the boundary.

The World Bank already has three classes

The closest external thing to the three dispositions comes from infrastructure procurement, in guidance written for contracts that get audited for decades.

The first class has no procedure at all: “in circumstances where a proposed variation involves no additional costs for either party, no formal variation procedure is required”. The second is pre-rate-carded — the agreement “can require the private partner to provide a schedule of rates for a range of likely small works at the beginning of each year”. The third is a full re-contract with an assessment of technical, financial, contractual and timetable implications.13

That is interior, reserve and mutation, in a multilateral’s handbook. And the same guidance recommends typing at signature in almost these words: where variations “can be foreseen to a reasonable degree before the signing… the government should explore the feasibility of requiring the private partner to commit to pricing pre-specified variations as part of the” agreement. It even states the classification question outright — contract managers must “verify that a variation request is actually a change and not covered under the existing agreement and pricing structures”.

ITIL already pre-authorises a class out of the approval path

ITIL 4’s standard change is “a low-risk, repeatable, and pre-authorized change that follows a documented procedure” which “often require[s] little or no additional approval” and is “frequently automated”. Its Change Authority decentralises approval by risk, correcting the widespread misreading of earlier ITIL that every change had to reach a central board.14 The definitional material sits behind a subscription and is quoted here at one remove, as it is by the cloud vendors who teach it.15

What that retires is a specific objection: pre-classifying a change type out of the approval path is ordinary engineering practice, not a supplier land-grab. The delta is the axis. ITIL classifies by risk of the change; the matrix classifies by which commercial variable moved — and ITIL’s axis cannot answer a commercial question, because a low-risk change can be a boundary mutation and a terrifying one can be entirely interior.

PMI already has two reserves

The typed-reserve primitive is not new either. Contingency reserve is “time or money allocated in the schedule or cost baseline for known risks with active response strategies” — the known-unknowns, inside the baseline. Management reserve is “an amount of the project budget or project schedule held outside of the performance measurement baseline… reserved for unforeseen work that is within scope of the project” — the unknown-unknowns, outside it, and drawing on it “follows the change control process”.16

So the reserve, the split, and even the exhaustion behaviour are standard. What is missing is precisely what this book adds: typing by event class rather than by risk-register entry, a published consumption rule, and an exhaustion decision with an owner and a window.

Target cost already has a banded absorption layer

Under a target-cost contract, costs are reimbursed plus a fixed margin, assessed against a target agreed at the outset, with “any savings or cost overruns… shared between the owner and contractor based on an agreed formula”. The simplest form is a straight 50:50 split, “often altered to allow a sliding scale”, and — the part that matters here — “the owner may at a certain level allocate 100% percent of overspend and 0% of underspend to the contractor”.17

That is a banded absorption layer with an explicit exhaustion point — litigated, board-legible, and decades old. It also carries a counterweight this book has to accept: target cost is chosen precisely for projects “of higher risk, or where the scope of works cannot be clearly defined”. Which is this book’s own refusal condition, arrived at from the other side. Chapter 12 takes it up.

And parametric insurance already runs entirely on observable triggers

The strongest transferable analogue, and the one that also supplies the admission.

Parametric cover “insures a policyholder against the occurrence of a specific disaster event by paying a pre-agreed amount based on the magnitude of the event, as opposed to the size of losses”. A contract “typically specifies (1) the payment amount; (2) the trigger (a pre-determined parameter based on observable data); and (3) an impartial third party to verify that the trigger was met”.18

The contrast with traditional indemnity is exactly the contrast between a typed trigger and a change request: normally “the policyholder documents their losses and submits a claim after an event, the insurer reviews the claim, and an adjuster assesses and validates the claim before payment is made”. Removing that assessment step lets payment happen “in a matter of weeks with a parametric contract versus months or years with a standard indemnity contract” — and “the use of a clearly defined trigger may make it easier for the insured to understand the coverage provided and reduce policy disputes”.

Five families, and where each one stops.
Family What it types What it does not do
NEC compensation events An enumerated, exhaustive trigger list including client-side failures, assessed prospectively. Prices each event’s work individually rather than pricing the boundary.
World Bank / APMG PPP Three classes: no-cost (no procedure), small works (pre-rate-carded), government variation (re-contract). No default presumption that irregular delivery belongs to the supplier.
ITIL 4 change enablement Standard / normal / emergency classes, with pre-authorisation and a delegated Change Authority. Classifies by risk of the change, not by which commercial variable moved.
PMI contingency / management reserve Known-unknowns inside the baseline; unknown-unknowns outside it, released through change control. No event-class typing, no published consumption rule, no owned exhaustion decision.
Target cost / pain-gain A banded absorption layer with a sliding share and an explicit exhaustion point. Keys on cost overrun rather than on a named perimeter variable.
Parametric insurance Payment amount, observable trigger, impartial verifier — no claims assessment at all. Buys its speed with basis risk, which it names openly.

The price of typing: basis risk

Here is the admission, and it belongs in the chapter that establishes the lineage rather than buried somewhere later where it would look like a hedge.

“Compensation from parametric policies is not linked to actual losses, so the claim payment may be higher or lower than the losses incurred. This is known as basis risk.”

The worked failures are unsparing. A city insured on barometric pressure “might not be able to claim if the damage was due to storm surge rather than wind”. The New Orleans School District held parametric wind cover for 2024, and the winds from Hurricane Francine “did not meet the 100 mph trigger and the policy did not pay out despite damage to school facilities”.

The Boundary Mutation Matrix inherits exactly that exposure, and it must be said before the book’s own example of it turns up. A supplier who types a trigger badly will absorb variance it should have re-contracted. A buyer will occasionally face a re-contract for something that did not really hurt them. Typing does not make the world tidy; it makes the disagreement about the world happen at a better time, in a cheaper form.

The mitigations come from the same literature and translate directly: choose triggers “highly correlated” to the thing you actually care about; name the impartial verifier up front; and revise triggers between engagements rather than during one — which is Chapter 6’s governance rule, now with an external reason attached to it.

Bottom Line

A rule that claims to eliminate judgement is lying. A rule that concentrates judgement into the week before signature, where it can be exercised calmly by people who can still walk away, is the best available deal.

Part I is finished. The rule, the artefact, the discipline and the lineage are all on the table. What none of it has survived is contact with an actual engagement — and a framework that has only ever been applied to clean cases has demonstrated the author’s imagination and nothing else.

So here are the terms of the proof. One engagement. Every variation classified, including the ones that were argued about — and including at least one the matrix got wrong, in exactly the way this chapter has just named.

08
Part II: One Engagement, Carried Through

The Event Log

Nine weeks. Seventeen surprises. Every one of them classified, and none of them a judgement call.

The discipline is inherited rather than invented. Our own earlier work on fixed-price envelopes says it twice, and both formulations are worth holding: “where this book has no number… it gives the shape and refuses to invent the figure”; and “where I use illustrative counts, they are design structure… Copy the mechanism. Do not copy imaginary numbers as if they were market data.”

The specimen

A bounded board-decision product: a fixed commitment to produce an evidence-backed decision pack whose valid terminal states are proceed, reshape or stop.

That shape is chosen because it is the hardest case for the rule, not the easiest. There is no code to point at, no obvious build, and the deliverable is an argument — which means every dispute is about analysis rather than artefacts, and analysis is exactly where the old change-request instinct is strongest.

Stated assumptions

  • • A measured input surface at signature; all eight fields carry recorded values.
  • • Four declared authoritative source classes, each with a named warrantor.
  • • A band that includes twenty consequential human dispositions.
  • • A named reserve of five access exceptions, with a published consumption rule.
  • • A nine-week delivery window with a fixed decision date.

Twenty, five and nine are design structure — the shape of a band, not a rate card. A reader who copies the counts without measuring their own estate has copied the wrong thing.

The complete event log: eight interior, four reserve draws, five boundary mutations. Four rows are disputed and are settled in Chapter 9.
# Event Disposition Why — and the field, if one moved
1Week 1. The evidence base is assembled, then rebuilt: the first assembly leaned on a source that turned out not to be authoritative.InteriorNo field moved. The declared source list was unchanged; the supplier misread its own list. Rework of the supplier’s error is the clearest interior case there is.
2Week 1. Access to the second system is granted four days after the date in the schedule.Reserve 1/5Field 4 trigger fired: a dated buyer obligation passed its date. One access exception drawn. Critical path unaffected, so field 8 did not move.
3Week 2. An authoritative source arrives in a structure nobody anticipated; an adapter is written on the spot.InteriorThe source class was declared; only its shape surprised us. Shape is method. Class is perimeter.
4Week 2. Two declared sources disagree systematically on a material quantity. Reconciliation takes four passes; a senior spends most of a day establishing that the difference is a compilation artefact.InteriorNo field moved — but it consumed one of the twenty included dispositions, so it is metered without being commercial. It also had to leave a fossil behind.
5Week 3. The team concludes that regenerating the analysis pipeline from an improved specification beats patching it, and discards nine days of machine output.InteriorA production decision inside an unmoved perimeter. The buyer bought a state; the search that produced it is the supplier’s business.
6Week 3. A fifth source class appears that nobody declared: an operational system holding data material to two decision options.MutationField 2. A source class not on the declared list. Delta quantified within the week; four options presented. The buyer narrowed the boundary and the system was typed excluded from this phase.
7Week 4. Agent read volume runs to roughly five times the planning estimate: the declared documents were far denser than the census sample suggested.Interior — disputedField 3 was checked and did not move: the census counted documents in declared systems, and that count was accurate. Density is not a band driver. See dispute A.
8Week 4. Security review adds a two-week privilege-approval cycle before sensors can run in the second environment.Reserve 2/5A pre-declared exception class. Flagged as a field 8 watch item, because a repeat would move the critical path.
9Week 5. The buyer asks for a second business unit to be included. The requested interface, deliverable and decision look identical to the first.Mutation — disputedFields 2, 5 and 6 all moved: a different data authority warrants the estate, a different executive signs, a different regulator applies. Identical interface, different perimeter. See dispute B.
10Week 5. A candidate framing survives three tests and dies on the fourth; a replacement is generated.InteriorEight framings built, six discarded, none of it reaching the invoice. The interior is supposed to look wasteful from outside.
11Week 6. A named buyer decision-maker is unavailable for eleven days; two dispositions queue behind them.Reserve 3/5Field 4 again: a nominated person is a dated buyer obligation. The eleven days are visible in the log rather than absorbed silently.
12Week 6. An undeclared internal dependency in the constraint set forces the whole option space to be re-tested.InteriorThe constraints were declared; their interaction was not understood. Understanding constraints is the work.
13Week 7. The buyer’s legal team asks that the decision pack be able to be relied on by a lender in a financing process.Mutation — disputedField 6, and the only field whose answer never varies. Intended use changed, so the consequence tail changed, so the cap and carve-outs are being asked to move. See dispute D.
14Week 7. Access to a third environment is narrowed after contract; a workaround costs four machine-days.Reserve 4/5The workaround cost is irrelevant to the classification. The trigger is the access change, not the effort.
15Week 8. A sixth access exception: a fourth environment requires a privilege model the supplier does not hold.Reserve exhaustedException six against a five-exception band. Not a margin dispute — a scheduled decision. Chapter 10.
16Week 9. Acceptance is run and one option fails its evidence-coverage threshold; the remedy takes three days.InteriorA failed acceptance under the agreed test is a defined state with a defined remedy, and the remedy is inside the band.
17Week 9. The buyer asks whether the engagement can also “design and launch three new offers” once the classification work lands.Mutation — disputedField 1. Read the signed promise sentence aloud: it describes classifying a current estate. The promise moved; latitude cannot absorb it. See dispute C.

Weeks 1–2: the quiet weeks that are not quiet

Five events, four of them interior. The evidence base is built and rebuilt. A source arrives in an unanticipated shape. Two sources disagree and reconciliation takes four passes. In a conventional engagement, that fortnight has already generated two or three change requests — because every one of those events is visibly more work than the plan described, and a diligent project manager could justify raising all of them.

Here it generated one line in a log the buyer can see, and a set of absorbed costs the buyer never hears about. Nothing was negotiated. Nobody had a difficult conversation. That is not the absence of governance; it is governance doing what it is supposed to do, which is mostly nothing.

Event 4 does double duty and deserves its own beat. It consumed one of the twenty included dispositions — so it was metered without being commercial, which is a distinction most delivery organisations have no vocabulary for. And it had to leave something behind: a typed exception class with a detection condition, a deterministic test that flags the same signature automatically next time, a decision rule for which source wins, and a routing trigger naming who looks at it and at what seniority. Without those four, a day of senior time bought one answer. With them, it bought a class.

Weeks 3–4: the first mutation, and the first thing that felt like one

Event 5 is the emotionally difficult one. Nine days of machine output discarded, deliberately, because regenerating from an improved specification beats patching a near-miss. It looks exactly like waste, it was the right call, and under the old clause somebody would have felt obliged to explain it to the client. Here nobody does, because it is not the client’s business.

Event 6 is the first real crossing, and it shows the routine at full speed. A fifth source class appears in week three. Stop. Name the field — field 2, authoritative input estate. Quantify the delta against the recorded list: four declared classes at signature, a fifth now required, one of the four never contemplated this system. Present four options, in the same week, not accumulated to month end. The buyer chose to narrow the boundary; the system was typed excluded from this phase; the decision pack would later say so in plain language.

Event 7 arrives immediately afterwards and feels identical to a boundary event. It is not, and it was argued about for two days. Chapter 9 settles it.

Event 8 draws the second reserve unit and picks up a watch flag: a repeat of this class would move the critical path, which would make it a field 8 question rather than a field 4 one. Notice what the flag actually is — a delivery lead being asked to observe a trend in a field rather than an instance. That is a small act of governance, and it costs nothing.

Weeks 5–7: the middle, where most books stop paying attention

Event 9 is the second business unit, and it moved three fields at once while looking like a copy-paste. Disputed, and settled in the next chapter.

Event 10 is another dead framing. By this point in the engagement it does not require discussion at all, and the fact that it does not is itself evidence: the rule is learnable, and a team that has run it for five weeks stops asking.

Event 11 is the classification most suppliers get wrong in the generous direction. A named decision-maker is unavailable for eleven days and two dispositions queue behind them. Drawing the reserve for that is not aggression — it is what makes the counter mean something in week eight. A supplier who eats buyer delay silently has spent the evidence it will need later, and has taught the buyer that dates are decorative.

Event 14 is the cleanest illustration in the log of what the rule keys on. Access to a third environment is narrowed and the workaround costs four machine-days. Those four machine-days are irrelevant. The trigger is the access change; the effort is not part of the test. A rule that keyed on effort would be back to measuring the supplier’s pain, which is where this book started.

Weeks 8–9: exhaustion and close

Event 15 is exception six. The reserve is spent. This is not a dispute and does not belong in the next chapter — it is a scheduled decision with a counter that everyone has been watching for three weeks, and it gets a chapter of its own.

Event 16 is a failed acceptance. One option misses its evidence-coverage threshold and the remedy takes three days, inside the band. If a failed test created a commercial event, the test would not be a test — it would be a formality with a fee attached.

Event 17 is the promise-moved request, arriving in the last week as these things always do, framed as a small addition by a buyer who is genuinely pleased with the work.

The same nine weeks, under two regimes

8–13

Change requests a diligent project manager could defensibly have raised under a baseline-keyed clause

5

Boundary mutations — each with a named field, a recorded value and a five-day window

4

Reserve draws — one-line notifications against a published rule, not negotiations

Events 1, 3, 4, 5, 7, 10, 12 and 16 all involve visibly more work than the plan described. Under a clause whose entry test is the baseline, every one of them is arguable, and several are compelling.

Be careful about what that comparison proves. It is not a saving, and I am not going to convert it into one: there is no credible published figure for what a change request costs to raise, negotiate and settle, and inventing one would poison the whole log. What can be said exactly is this. The number of negotiations falls by roughly half. The number of unscheduled negotiations falls to zero, because all five mutations arrived through a named field with a recorded value and a stated window.

Takeaway

The saving is not in money changing hands. It is in the number of times two parties have to renegotiate their relationship in order to keep working.

Seventeen events, seventeen homes, and no row that says “judgement call”. Which is the least interesting thing about this chapter, because the clean rows prove nothing at all. Four of these were argued about by competent, informed, financially interested people. One was settled against the supplier. One exposed a defect in the design of the census itself. That is the chapter the argument stands or falls on.

09
Part II: One Engagement, Carried Through

The Four Disputes

Two went the supplier’s way. One went against it. One found a defect in the instrument itself.

A rule that has only ever been applied by the person who wrote it, to cases they chose, has demonstrated the author’s imagination. Nothing more. The parent architecture says the same thing about itself, and it is worth repeating here as a standard rather than a courtesy: a framework that only shows itself succeeding has proved nothing.

So the test is not whether seventeen events could be classified. It is whether the classification held when somebody competent, informed and financially interested argued the other way.

The scoreboard, before the arguments

2

Settled in the supplier’s favour — B and C

1

Settled against the supplier, which absorbed the cost — A

1

Design defect found in our own census — also A

Dispute A — five times the reading volume

The argument. Delivery’s position was not a stretch; it was the most natural reading available. The band exists to price volume. Volume ran to roughly five times the planning estimate. Therefore field 3 has moved and this is a band uplift.

Commercial disagreed on a technicality that turned out not to be a technicality. The band was assigned from a census, and the census counted documents in declared systems. That count was accurate. Nothing that had been recorded had changed.

The rule that settled it. A band driver is whatever the published census actually counts, and nothing else. Ours counted documents. It did not count pages, tokens or density. The recorded value did not move, so the event was interior, and the supplier absorbed it.

Everyone in that room knew the work was materially larger than the band had anticipated. The rule said absorb it anyway. It was the right answer arrived at for a wrong-feeling reason, and pretending otherwise would be dishonest about how these conversations actually go.

Key Insight

Two things were true at once: the classification stood, and the census was wrong. A supplier who cannot hold both simultaneously will either corrupt its classifications to fix its pricing, or leave its pricing broken to protect its classifications.

What it changed. The finding has a home, and it is not this engagement. Density went into the band-driver review as a candidate metric for the next contract — which is exactly the prescribed move: when the same exception class keeps appearing, promote it into a first-class state or a band driver rather than leaving it as folklore. There is even a named leading indicator in the parent doctrine worth borrowing here, since early ambiguity rate predicts disposition load better than raw counts do.

What you may not do, stated as a prohibition rather than a preference: retro-fit a band driver mid-engagement to recover margin. It destroys the band’s meaning for every future buyer and teaches your own sales system that drivers are negotiable — which reintroduces exactly the private-judgement pricing the whole apparatus was built to replace, now with a product’s name on it.

Dispute B — the second business unit that looked identical

The argument. The buyer’s position was sincere and entirely reasonable: same screens, same deliverable, same decision, a modest increment of work. Their own delivery counterpart agreed with them. Nobody was manoeuvring. Our commercial lead had to explain a “no” in a room where the intuitive case ran the other way.

The rule that settled it. Classification runs on fields, not on resemblance — and three fields moved at once:

  • Field 2 — a different party warrants the authoritative estate.
  • Field 5 — a different executive signs the dispositions.
  • Field 6 — a different regulator applies, therefore a different consequence class.

The user interface is not a perimeter field and never was. Neither is “how much work it feels like”.

Why the buyer accepted it is the part worth dwelling on, because it was not because we argued better. Both sides had an argument, and arguments do not settle this kind of disagreement.

They accepted it because the fields had recorded values with names against them, and one of the names was theirs. Field 2’s warrantor was a person the buyer had nominated at signature. Field 5’s signatory was in the schedule. Field 6’s consequence class had been agreed in writing eleven weeks earlier by their own general counsel.

The conversation was two people reading a table, rather than two people recalling a meeting.

That is the strongest practical argument for typing at signature anywhere in this book — stronger than any of the design reasoning in Part I, because it is about what happens in a room with money on the table. And there is a second-order benefit that gets missed: the buyer was not being told “no”. They were being told exactly which three things had changed, which was information they needed anyway for their own internal approvals.

Dispute C — “you have all the analysis anyway”

The argument. This is the sharpest challenge in the book, because it uses the rule’s own economics against it. The machine had already read everything needed to design the new offers. The marginal cost of doing the additional work was small. And this book spends four chapters arguing that the supplier absorbs what the machine can do cheaply. So why not absorb this?

The rule that settled it. Because absorption is bounded by the promise, not by the cost — and field 1 is the field where cheapness is irrelevant.

Apply the field 1 test in the room, out loud, which is what it is for. Read the signed promise sentence: it describes classifying a current estate and producing a decision on it. “Design and launch three new offers” does not fit inside that sentence without adding a clause. Three consequences follow, and each is independently sufficient: a different promised state, a different acceptance test, and a different consequence class if the work turns out to be wrong.

Remember

Cheap to produce is not the same as cheap to be wrong about.

The low marginal machine cost is precisely the trap. It makes an unbounded commitment feel affordable at the exact moment you are agreeing to it, and the affordability is real while the exposure is not accounted.

What made it easy to say. The answer was never “no”. It was “that is a second commercial object, and here is its shape” — a better outcome for the supplier than absorbing it, and a better outcome for the buyer than an argument at month end. Our own work on bounded promises is unambiguous about the alternative: sell an outcome you cannot control and you will “quietly rewrite the promise later through change requests and fine print”. Refusing to absorb here is what prevents that, and it prevents it in the buyer’s interest as much as the supplier’s.

Dispute D — lender reliance

The argument. Delivery saw a document-handling question: the pack already exists, so letting one more party read it costs nothing. That is true of the reading and false of everything else. The buyer’s legal team saw an administrative addition to something they had already paid for.

The rule that settled it. Reliance changes who can sue, for what, and under which standard. That is field 6, and field 6 is never absorbed and never reserved.

The asymmetry underneath is the one this book keeps returning to: better analysis lowers the probability of an error and does nothing at all to the cost of the one you make. Cheap cognition is silent on the consequence tail. And the external position is uncompromising — without a contractual limitation liability is unlimited and can exceed the cover maintained under a professional indemnity policy, and fitness-for-purpose obligations are “generally uninsurable” under such a policy at all.9

Outcome. Re-contract and re-underwrite: a named reliance party, a revised cap, and the carve-outs restated as a closed list. The last of those matters more than it sounds — a generous-looking cap “means little if that waiver strips out the losses you would actually claim”, and the supplier-side discipline is to “tie carve-outs to a closed list rather than open-ended categories”.20

And the counterfactual, because it is the credible half: had the buyer declined to re-contract, the correct answer was to decline the reliance and keep delivering the original engagement unchanged. Not to walk away. Not to quietly allow it and hope. A supplier who cannot say “no, and the work continues exactly as agreed” has only one lever, and will use it badly.

The settling protocol

Generalised from the four, and short enough to run in ten minutes with the schedule open:

How to settle a contested classification

  1. Name the candidate field. Not “is this a change?” — which field do you say moved? A dispute that cannot name a field is already resolved.
  2. Read its recorded value. Out loud, from the schedule.
  3. Compare, do not interpret. The question is whether the current state differs from the recorded one — not whether the difference feels significant.
  4. If the comparison needs an argument, the field was untyped. Record that as a defect for the next contract, and default to interior.
  5. Log the decision either way, with the field named and the comparison shown. The log is what makes the next dispute cheaper.

Step 4 carries the risk, so be explicit about it. It biases the untyped case toward the supplier absorbing, deliberately. The alternative bias — untyped means re-contract — would hand the supplier a standing incentive to leave fields vague, which is the disease this whole instrument was built to cure.

It also creates the feedback loop everything else depends on. Every untyped field costs the supplier exactly once, and is fixed before it can cost them twice. That is not a generous rule. It is a rule with a correction mechanism, which is a different and better thing.

Four disputes, four settlements. And one event from the log still unresolved: exception six. That one was left deliberately, because it is not a dispute at all. It is the most predictable event in the entire engagement — the only one with a counter on it — and it is the one most fixed-price engagements still manage to get wrong.

10
Part II: One Engagement, Carried Through

Exception Six

The only event in an engagement that arrives with a counter on it — and the one most fixed-price work still gets wrong.

Week eight. Four exceptions drawn, one unit left in the band, and a fourth environment turns out to require a privilege model the supplier does not hold. That is exception six.

Everything about this moment is known in advance. The band was five. The draws were logged at events 2, 8, 11 and 14, each against a named trigger. The counter has been on the buyer’s screen since week one. Nobody is surprised by the arithmetic, because the arithmetic has been public for two months.

Key Insight

Reserve exhaustion is the most predictable event in a bounded engagement. It has a counter on it. Everyone watched it approach for three weeks.

Which makes the way most engagements handle it genuinely strange. There are two standard failure modes, and they are opposites.

Silent absorption. The supplier quietly eats the sixth exception. Then the seventh. Margin erodes where nobody is looking. Nobody in the buyer’s organisation ever learns that the reserve meant anything, because its consumption was never visible. And when the supplier finally does raise it — because eventually it must — there are three weeks of precedent demonstrating that it did not need to.

The ambush. A change request lands in week nine with no warning, citing a clause the buyer has not read since signature. The commercial position may be entirely correct. The relationship damage happens anyway, because from the buyer’s side an unannounced invoice and an opportunistic one are indistinguishable.

Both are avoidable, and the fix is not goodwill or better relationship management. It is a protocol agreed at signature, when nobody is under pressure and neither party has a position to defend.

The exhaustion protocol

1. The counter is published from day one. On the same surface as disposition consumption, not in a supplier-side spreadsheet that gets shared when it becomes convenient. “Access exceptions: 4 of 5” is visible in week seven. This prevents the ambush structurally rather than behaviourally: a buyer who has watched the counter move cannot be surprised by exhaustion, and a supplier who has shown the counter cannot credibly be accused of manufacturing it. Our own doctrine already argues the general form of this for dispositions — showing the meter is “honest rather than awkward”, because the meter is the thing the band was priced against.

2. A named owner on each side. Written into the schedule at signature — roles rather than people, where the organisation allows it, because people leave and an unowned decision is worse than an unnamed one. What this prevents is the phrase “the parties will discuss”, which is not a decision procedure. Unowned decisions default to whoever is least able to refuse, and in a live engagement that is almost always the delivery lead at ten o’clock at night.

3. A stated window. Five business days from the draw that exhausts the band. The same week, not month end. Speed here is commercially load-bearing rather than merely polite: a delta presented in the week it occurs is information; the same delta presented a month later is a bill. The crossing routine in the parent doctrine insists on the same thing — options presented in the same week the crossing happened, not accumulated into a difficult conversation at month end.

4. A delta, with evidence. What was recorded, what is now true, how much of the band it consumed, and what the remaining schedule looks like under each option. This is what stops the reopening being heard as a renegotiation. A buyer who understands why they are in this band will accept a delta against it; a buyer who does not will hear any delta as an attempt to reprice them.

5. Four options, always the same four. Uplift the band. Extend the reserve at a published rate. Narrow the boundary. Or stop, with work to date delivered in its typed state. That set is inherited rather than invented: exhaustion “produces a commercial conversation with a census delta and a recommendation: uplift band, extend reserve, narrow boundary, or stop”. Fixing the option set prevents creative option-generation under pressure, which always favours whoever is more comfortable in the room. And “stop” has to be a real option offered without theatre — a menu where one item is unthinkable is a menu of three.

6. The stated default if nobody decides. Ours: work continues on everything not blocked by the exhausted class, and the blocked portion is typed inaccessible within boundary until the decision lands. This prevents the most expensive failure in the chapter — the supplier working on, unpaid and unremarked, because nobody said stop. A default is what protects the party with the least power to pause. And notice that it is not a new invention: it is an existing typed terminal state doing duty as a holding position.

The counter, week by week

1 / 5

Wk 1 — access four days late (event 2)

2 / 5

Wk 4 — two-week privilege review (event 8)

3 / 5

Wk 6 — decision-maker unavailable 11 days (event 11)

4 / 5

Wk 7 — access narrowed after contract (event 14)

Spent

Wk 8 — exception six (event 15)

What was inherited and what is added should be said plainly. The parent doctrine already had exhaustion producing a conversation with a delta and four options. This book adds the owner, the window and the default. Three additions, each of them one line in a schedule — and together they are the difference between a policy and a procedure.

What a draw has to leave behind

A draw that produces only an answer is an unpriced leak. Every one should deposit four things: a typed exception class with a detection condition; a deterministic test that flags the same signature automatically next time; a decision rule stating how it resolves; and a routing trigger naming who looks at it and at what seniority. Without those four, a day of senior time bought one answer. With them, it bought a class.

And this book adds the commercial consequence: a class can become a band driver in the next contract. That is how a reserve shrinks across engagements instead of being re-drawn forever. It is the same learning rule as the governance section in Chapter 6, now with a live example attached — and it is the difference between a firm that gets better at bounding work and one that simply gets more practised at absorbing it.

What happened

The buyer chose to narrow the boundary. The fourth environment was typed excluded from this phase, and the decision pack shipped saying exactly that, in the same vocabulary as everything else in it — because unknowns become typed deliverables rather than unbounded labour.

Two weeks later there is a detail worth noticing. The excluded environment appeared in the pack as a named gap with a named consequence for one of the three decision options: this option depends on data we did not see, and here is what would change if that data contradicted our assumption. That is more useful to a board than a silent omission, and considerably more useful than a confident answer built on an environment nobody checked.

Takeaway

The exclusion improved the deliverable. A decision pack that says what it could not see is a better instrument than one that implies it saw everything.

Why visible absorption beats silent absorption

Make this argument without any appeal to virtue, because the commercial version is stronger.

The buyer who watched the counter move from one to five experiences option four as governance. The buyer who sees the counter for the first time at exhaustion experiences it as a bill. Same money, same events, entirely different relationship — because surprise had a language and a schedule.

There is a second-order return that survives into the next deal, and it is the one most suppliers throw away. A supplier who can show four absorbed exceptions and one governed decision has evidence of absorption. Silent absorption produces no evidence, buys no credit, and cannot be sold. It is generosity with the receipt thrown away.

“Won’t clients demand the unconsumed reserve back?”

Answer with the published rule rather than a negotiation: what is not drawn is not consumed.

It survives contact because the reserve is not a contingency held against the buyer’s money. It is the priced home for an absorption obligation the supplier accepted, and its unconsumed portion is what the buyer paid for and did not need — in the same way an unclaimed insurance policy is not refunded at the end of the year.

But there is an honest limit on that answer, and a supplier who ignores it is being lazy rather than principled. If the reserve is never drawn across many engagements, it is mispriced. The correct response is to reduce it in the product definition, not to defend it deal by deal against buyers who have noticed.

This is worth setting beside the older commercial instruments from Chapter 7. PMI’s management reserve is already drawn through the change-control process; a target-cost pain share already has a point beyond which the contractor takes all of the overspend. The mechanism is not exotic. What is missing in most professional-services contracts is not the reserve — it is the counter, the owner, the window and the default.

The rule has now been shown classifying, arguing and deciding. What it has not been shown doing is paying. The whole scheme rests on an economic claim that has been asserted since Chapter 2 and never once tested: that implementation churn no longer deserves to be the billing proxy, because it no longer predicts cost. Time to put that on trial — and to find out whether the answer justifies the design or embarrasses it.

11
Part II: One Engagement, Carried Through

What Actually Costs You

The claim under test: implementation churn no longer deserves to be the billing proxy, because it no longer predicts cost.

If implementation churn does still predict what an engagement costs, then the old clause was right, this book is wrong, and the correct response to everything so far is a better change-request process rather than a different unit of change control. That is a real possibility and it deserves a real test.

So use a frame that is not this book’s invention. Our own offer-qualification work already sets out the contribution shape for a bounded commercial unit: willingness to pay, minus machine and infrastructure cost, minus human disposition cost (scarce experts only, costed honestly), minus sales and onboarding, minus physical delivery capacity, minus liability and commitment risk, minus exceptions and failure remediation.

What makes that a fair test rather than a rigged one is the last two lines. They were not added to make this argument work — they have been in the canon since before this book existed, and they happen to be exactly the two the matrix protects.

Sensitivity: which variables move the cost of a bounded engagement, and which of them deserve to be billing triggers.
Variable Who owns it Effect on engagement cost when it moves A billing trigger?
Implementation churn
retries, regenerations, discarded approaches
Supplier Real but small in absolute terms; superlinear in session length rather than linear; averages out across a portfolio. No. A portfolio property, not a per-engagement prediction — and it is the supplier’s own search.
Consequential dispositions Shared The dominant controllable cost. Each occupies scarce senior attention that does not parallelise and cannot be regenerated. Yes — this is the meter. Band it, publish the included count, show the counter.
Consequence / liability class Buyer’s use, supplier’s exposure A step function, not a slope. Adding a reliance party or a fitness-for-purpose obligation can exceed the entire fee — and may be uninsurable. Yes — and it is a re-underwrite, not a repricing.
Buyer-controlled dependencies Buyer Costs calendar rather than machine time — and calendar is where the supplier’s real capacity is consumed. Delay also idles the scarce humans. Yes — but as a reserve draw first. A few slipped dates are normal; re-contracting for them is absurd.
Authority and access Buyer An added approver adds dispositions and lengthens every loop that touches them; a narrowed privilege model can invalidate the production route entirely. Yes. It changes the metered resource directly.
Volume within a declared class Buyer’s estate Mostly absorbed by machine breadth — unless it pushes disposition count up, which is the real transmission channel. Only at a published threshold, and only because volume correlates with dispositions.
Exception density Nobody — reality The most under-costed line in every early product. Early economics look attractive precisely because exception tails have not appeared yet. Yes, via the reserve — and if it recurs, promote it into a band driver.

Two rows use real figures, and both were introduced earlier. Implementation churn is bounded by the token economics of an agentic session, and its shape is superlinear rather than linear: “a session that runs 2x as many turns might cost 3-4x as much”, because later turns carry accumulated context.4 Liability is a step function: caps enforced at eight per cent of a designer’s fee, and at $550,000 out of a $9.5 million verdict, describe a gap between fee and consequence that no amount of analysis narrows.10

Read down the “who owns it” column

The design falls out of that column, and it is worth presenting as a discovery rather than a justification, because that is how it arrived.

Key Insight

Every variable the supplier controls is absorbed. Every variable the buyer controls is typed. The one variable nobody controls — exception density — gets a reserve.

Which tells you what a reserve is for: shared exposure to reality, priced, banded and visible. Not a contingency fund. Not a negotiating buffer. Not margin held back in case the client is difficult.

And it means the three dispositions are not an arbitrary taxonomy that happened to come out at three. They are the three possible answers to a single question — who controls this variable? Supplier, buyer, nobody. A rule derived from control is defensible in a way that a rule derived from convenience is not, and it is defensible to the party that did not write it.

“Isn’t this just a supplier deciding what it feels like absorbing?”

The sharpest objection in the book, and the table is the answer to it. The supplier absorbs exactly the variables it controls, and gets no relief at all on the ones it does not.

Run the counterfactual out loud, because it is the fastest way to see the difference. A self-serving rule would absorb buyer delay as a gesture of goodwill — it is cheap to eat in any single instance and buys enormous relationship credit — and would quietly reprice volume, because volume is easy to measure and easy to invoice. This one does the exact opposite. It types buyer delay, which is awkward, and it absorbs volume up to a published threshold, which is expensive.

There is a harder-edged version of the same point. The rule commits the supplier to absorbing the one category where its own competence is most in question: rebuilding an evidence base because the first assembly was structurally wrong is the supplier’s error, and it is interior by construction. A rule written for the supplier’s benefit would have carved that out first.

Why early economics lie

Our own qualification work is unsparing about this: true contribution “collapses when disposition is costed and exception tails appear”, and “early pilots look fine while principals absorb exceptions unpaid”.

Which is why this sensitivity is the falsifier rather than a nice-to-have. A firm that has run two engagements profitably has learned almost nothing, because both of the lines that kill this model are back-loaded — the exception tail arrives late, and the liability event arrives later still, if ever, and catastrophically when it does.

The instruction that follows is uncomfortable and cheap: instrument disposition count and exception class from engagement one, especially when the engagement is going well. The measurement that would have warned you is precisely the one nobody builds while things are fine.

So: justified, or embarrassed?

Justified on the central claim. Implementation churn is the only variable in the table that is simultaneously supplier-controlled, small in absolute terms, and averaged across a portfolio. It is the worst available billing proxy — and it is the one the incumbent clause uses.

Embarrassed on one point, and the book should say so rather than wait to be caught. Volume within a declared class is not cleanly interior. It transmits to cost through disposition count, which means the honest treatment is a published threshold rather than a clean absorption — and dispute A in the previous chapter is exactly that weakness appearing in practice. The rule is not as tidy as its three-line summary.

Bottom Line

Own the variance you control. Meter the variance you share. Reserve the variance nobody controls. Re-contract the variance that changes your exposure.

The third and fourth of those are where the money actually is, which is worth saying because the first two are where all the attention goes.

The cross-engagement check

Whether any of this is working is not visible inside a single engagement. The metric that answers it is paid bounded units divided by scarce expert dispositions, with both halves disciplined — only paid bounded units in the numerator, only material authorised dispositions in the denominator. If that ratio does not improve across comparable engagements while quality holds, the matrix has been administered rather than used. That metric belongs to its own treatment and this book does no more than point at it.

One paragraph of market context, then, because it explains why the arithmetic is urgent rather than merely interesting. The same efficiency gain lands in opposite places depending on one line of the invoice: a tool that turns a four-hour task into a one-hour task “creates a revenue problem under hourly billing and a margin opportunity under fixed fees”. Same people, same clients, same quality — and opposite economics, decided by what the invoice counts.

The headline on the review interface is not “the machine found forty things.” It is “forty calls still need your name on them.”

That inversion is the honest face of the whole scheme. It makes the scarce resource visible to both sides at once, which is the only durable basis for a fixed commitment — and it is why the counter is a feature rather than an embarrassment.

Part II has now shown the rule classifying, arguing, deciding and paying, inside an engagement it was designed for. Which leaves the question every framework avoids: what does it say about the engagement it cannot handle? Walk the eight rows and ask, of each, whether you could write an observable trigger for it. For one perfectly real, well-funded, attractive opportunity, the answer is no.

12
Part III: Where It Refuses, and What You Do Monday

When the Rule Refuses the Price

Five of eight rows cannot carry a recorded value. Three of those five are outside both parties’ control. Do not fix this price.

The opportunity is a good one, which is what makes it dangerous. A well-funded group wants a fixed-price commitment to “get us to a decision on our regulatory posture”. There is a real relationship, a real problem and a real budget. Everything about it is attractive except the perimeter.

So run the self-test, row by row, before anybody writes a number.

Can I write an observable trigger for this field?

✗ 1. Promised state. The decision has been redefined twice in three meetings — first “are we compliant”, then “what should our posture be”, then “what should we tell the board”. There is no sentence to record, so there will be nothing to compare against later.
✗ 2. Authoritative input estate. Which entity’s records govern depends on a restructure that has not completed. Nobody can warrant the estate today, because the warrantor is one of the things being decided.
✓ 3. Volume / band. Measurable, as it happens. The document estate can be censused this week.
~ 4. Buyer-controlled dependencies. Nameable but not datable: the people who owe inputs are the people whose roles are being restructured.
✗ 5. Authority and access. The approving body will exist after the restructure. Its composition is unknown.
✗ 6. Consequence / liability class. The regulator that will apply is one of the things the restructure decides. The consequence tail cannot be described, so it cannot be capped.
✗ 7. Acceptance rule. Cannot be written, because it depends entirely on field 1.
✓ 8. Fixed time boundary. Available — and meaningless without the rest.

Five of eight rows cannot carry a recorded value, and three of those five sit outside both parties’ control. Note what that is and is not. This is not a hard engagement; hard engagements are the ones this book is written for. It is an unclassifiable one.

The chain is short and it terminates: no recorded value, therefore no delta; no delta, therefore no trigger; no trigger, therefore every surprise resolves into an argument. An instrument that cannot distinguish interior variation from boundary mutation is not an instrument, and a fixed price laid over it is not a commitment. It is a wager with a schedule attached.

Key Insight

The rule is not AI → fixed price. It is: AI expands the territory in which complexity can be bounded, configured and priced as a product — and the edge of that territory is a design output, not an act of courage.

So: do not fix this price. Not “price it carefully”. Not “add contingency”. The instrument this book has spent eleven chapters building says the instrument does not apply here.

And it is worth being concrete about what happens if you ignore that verdict, because the temptation is real and the failure is predictable. You would absorb the first two redefinitions as goodwill, because each one individually is small. You would discover in month two that the approving body has changed composition. You would reopen the price in month three — arriving at exactly the failure from Chapter 6, except that you would also have spent the credibility of a fixed-price promise on the way there.

The shrink, which is the actual answer

Refusal without a shrink is a lecture. And the shrink here is not a consolation prize — it is a better product than the one that was asked for.

Sell the bounding. A smaller fixed commitment whose entire deliverable is a stable, testable question and a recorded perimeter: which entity governs, which regulator applies, who approves, and what decision is actually being asked.

Notice what that product is. It is the missing rows, produced as a deliverable. Its output is a filled perimeter — and a filled perimeter is precisely what makes the larger engagement quotable afterwards, by us or by anyone else. The buyer is not being sold a smaller version of what they wanted; they are being sold the thing that has to exist before what they wanted can be bought at all.

The four-step shrink applies cleanly to this case, and applying it beats re-listing it:

  1. Identify which perimeter field is unstable. Fields 1, 2, 5 and 6 — and note that 7 is downstream of 1 rather than independently broken, which matters, because fixing one field repairs two rows.
  2. Remove the commitment that depends on it. Precisely those, not a defensive haircut across the whole proposal. The censusable estate work in field 3 stays exactly where it is.
  3. Re-home the removed part as one of three things: a client responsibility with a named owner (the restructure decisions), a separate commercial object (the posture decision, once bounded), or a typed terminal state.
  4. Re-check that what remains is still worth buying. The step people skip — and the one that decides whether this is a shrink or a decline wearing a shrink’s clothes. Here it passes: a group mid-restructure genuinely needs to know which entity governs before it can decide anything else.

If even the bounding cannot be sold, the alternatives are a staged engagement or non-fixed pricing — with the stability of the unit preserved even where the fee shape is not. Fixed price is a signal, not a law.

Why refusal is commercial, not moral

The moral version of this argument is easy and unpersuasive, and nobody with a pipeline has ever been moved by it. The commercial version is stronger.

Forcing out-of-band work into a fixed price does three expensive things. It destroys the band’s meaning for every future buyer, because the band no longer predicts anything. It teaches your own sales system that drivers are negotiable, which reintroduces private-judgement pricing under a product’s name. And it converts a product back into a bespoke project with a product’s price and a project’s cost — which is the worst combination available.

There is a fourth cost, quieter and worse: a lane full of forced exceptions cannot teach you anything. A population of half-comparable engagements produces numbers nobody can act on, and a firm that cannot measure its own product cannot improve it.

“Our competitors will just say yes.” Some will. Some of them will win the deal and lose the money, and that is a market you can wait out — particularly since a buyer who has been over-promised to is a buyer looking for someone credible in eighteen months. But answer it honestly rather than piously: refusing costs revenue now, and a firm without a pipeline cannot afford principles. Which is exactly why the realistic move is almost always the shrink rather than the walk-away, and why shrinking is the harder skill and the one nobody teaches.

Fixed price was never absolute

None of this is an AI-era discovery, and the book is safer for saying so. Construction lawyers have been saying the quiet part for decades. Lump-sum contractors “often include significant contingencies in their pricing”; they are “naturally incentivized to seek opportunities to reopen the fixed price” where those contingencies prove insufficient; and then the sentence worth carrying into every negotiation:

“In truth, there is no such thing as an absolute fixed price contract.”
— A&O Shearman, on lump-sum turnkey construction contracts, August 2025

The same source states this book’s refusal test from the other end: lump-sum contracts “may still be preferable for well-defined, low-risk projects where scope and owner requirements are clear from the outset”.21 Legal services arrives at the identical boundary by a different route — hourly billing persists in “complex, high-stakes, or open-ended” matters because “the scope keeps evolving… and the risk is asymmetric and dynamic”, so “pricing these engagements upfront requires embedding significant risk premiums, which often makes fixed-fee structures impractical”.22

So state the book’s own limit before anyone else does.

Bottom Line

The matrix does not abolish reopening. Nothing does. It makes reopening early, typed and evidenced instead of late, adversarial and improvised.

That is a considerably smaller claim than “AI makes fixed price safe”, and it is the only one that survives contact with a real engagement.

What survives a refusal

Not nothing. What is preserved when the fixed price is declined is the stable unit of commitment — which can be a per-project activation, a verified decision, an assessed estate, a protected period, a guaranteed response commitment, or a capacity tier. What it must increasingly not be is “however many hours our internal process happens to consume”.

Two sentences carry the whole boundary of this book, and both come from the source conversation. “AI can cheaply absorb cognitive variance. It cannot cheaply absorb all variance.” And the deeper invariant, which is what you are really protecting when you decline a fee shape: a stable unit of commitment.

Scott’s own hedge belongs here too, at the end rather than the beginning, because by now it reads as confidence rather than doubt: “I’m not saying this is the only pattern. I’m saying it’s probably a pretty good reusable construct for AI-native successor products and businesses — a pattern, or a template.” A rule that could not decline anything would not be a template. It would be a slogan.

The edge is drawn now, and drawn in the same vocabulary as the rule itself — which is the test a boundary has to pass to be part of a design rather than an apology for one. What has still never appeared, in twelve chapters, is the thing a reader would actually have to sign.

13
Part III: Where It Refuses, and What You Do Monday

Drafting the Perimeter

Five clause shapes, the buyer’s side of the same rule, and an honest answer about whether any of it can be coded.

The purpose of the demonstration is narrow: to show what an observable trigger reads like once it stops being a design principle and becomes a sentence somebody has to live with.

A rule that has never been rendered into contractual language has not been tested. Drafting is where vagueness dies — several of the rows in Chapter 5 only became precise when someone sat down and tried to write them as clauses, and one of them had to be rewritten twice. That is the argument for including this chapter. The argument for keeping it short is that a clause library dates instantly, and this is not one.

1. The classification clause

What it does. Names the three dispositions, states that interior variation is the default, and lists explicitly what is supplier-elected: method, model, tooling, sequencing, retries, regeneration and analysis route.

The shape. A definition of each disposition; a statement that no change request arises from any matter falling within interior variation; and a cross-reference to the recorded-values schedule for the definition of “perimeter field”.

What the buyer should understand it to mean

“We are not paying extra because they had to try three times — and they are not allowed to ask.”

This clause is where the supplier’s latitude finally gets a contractual home, and it has a lineage. Our own prompting doctrine already describes the same structure at a different scale: be tight on intent — purpose, audience, what success and failure look like — and loose on procedure, while staying prescriptive wherever the output feeds a machine or a constraint is correctness-critical. The perimeter fields are the “must be exactly X” layer; the interior is the “must be good” layer. This chapter is that doctrine handed a contract.

2. The recorded-values schedule

What it does. The most important artefact in the entire scheme and easily the least glamorous: a table appended at signature, one row per perimeter field, each with its measured value, the method of measurement, and the date.

The shape. A schedule, not prose. Values, not adjectives. If a cell contains the word “appropriate”, it is not finished.

What the buyer should understand it to mean

“Here is what both of us agreed was true on day one.”

Without this attachment every other clause in the chapter is unenforceable, because there is nothing to compare against. The whole of Chapter 6 reduces to it.

3. The trigger schedule

What it does. States, per field, the observable condition that constitutes movement.

The shape. Comparisons. “A source class not listed in Schedule 2.” “A census metric exceeding the threshold stated in Schedule 2.” “A dated obligation in Schedule 3 unmet by more than N business days.”

What the buyer should understand it to mean

“These are the only things that let either of us reopen the price.”

Apply the trigger test during drafting rather than afterwards. Any row that needs the words “material”, “significant” or “reasonable” in order to work has failed and should be rewritten or declared untyped. A clause that needs the word “material” to function is a clause that has not been written yet — it is a placeholder for an argument somebody is scheduling for later.

4. The reserve clause

What it does. Sets the band, the typed exception classes, the published consumption rule, the statement that unconsumed reserve is not consumed, and the exhaustion decision with its owner, window and default.

The shape. A list of typed classes; a consumption rule; a short procedure with two names and a number of days in it.

What the buyer should understand it to mean

“There is an allowance for a named set of problems, we can both watch it being used, and when it runs out there is a meeting with a date on it — not an invoice.”

The typed classes belong in the contract schedule rather than the delivery playbook. If the types live only in a slide deck, delivery will invent synonyms under pressure and the boundary will blur: same words in contract, software and report.

5. The liability interlock

What it does. Sets the cap, the carve-outs as a closed list, the standard of care and the intended use of the deliverable — and then adds the interlock itself: a change of intended use is a re-contract, not a variation.

The shape. A cap; a closed list; a named permitted use; and a cross-reference that makes field 6 movement structurally incapable of being processed as an ordinary change.

What the buyer should understand it to mean

“If we want to use this for something else, that is a new agreement — and we will be told so at the time, rather than discovering it in a dispute.”

Two drafting notes that matter more than they look. A generous-looking cap “means little if that waiver strips out the losses you would actually claim”, and supplier-side practice is to “tie carve-outs to a closed list rather than open-ended categories”.20 And keep the Zirkelbach lesson from Chapter 5 in the drafter’s mind: a cap that is never reopened while scope moves is a cap that shrinks in real terms, and it will be enforced at its shrunken size.

The buyer’s side of the same rule

The two-sided test in Chapter 4 was a claim. This is where it gets paid, and it needs to be substantial enough that a buyer-side reader would actually use it.

What a buyer should demand

  • Recorded values before signature — not “to be documented during mobilisation”.
  • Published band drivers, enough to see why you are in this band. A buyer who understands the drivers will accept a delta against them; one who does not will hear any delta as a renegotiation.
  • The reserve counter visible during delivery, on the surface you already read — not on request.
  • A named exhaustion owner and window on the supplier’s side, with a stated default if nobody decides.
  • Working exclusions that name systems, work types, time periods and decision rights — the kind that survive contact with a change request, rather than paragraphs without operational teeth.

And then the part that makes this a rule rather than a supplier’s script: the right to invoke the matrix in the other direction. A buyer can point at a field and require a re-contract when the supplier’s perimeter has moved — a changed sub-processor, a changed data location, a changed model or tooling class where the contract made that a declared input, a changed standard of care, or a change in who signs on the supplier’s side.

Anchor that in the litigated case rather than in fairness. In Zirkelbach the party who failed to reopen the clause as scope moved was the one who wore the consequence, and the court said so explicitly.10

The matrix protects whoever is paying attention.

One instruction for legal review, and it is counter-intuitive enough to be worth stating plainly: test the exclusions and acceptance objects first, before the liability paragraphs. If legal only polishes liability wording while the evidence spine is missing, you have professionalised the wrong layer — and the clause that will actually be argued about is the one nobody read.

Can any of this be coded?

Briefly, and then this book will decline to become a smart-contracts book.

The law is not the obstacle. The Law Commission of England and Wales concluded in 2021 that “the current legal framework in England and Wales is clearly able to facilitate and support the use of smart legal contracts, without the need for statutory law reform”, and that existing principles apply “in much the same way as they do to traditional contracts”.24 A smart contract is defined there as computer code “that, upon the occurrence of a specified condition or conditions, is capable of running automatically according to pre-specified functions”.25

A typed trigger is much closer to that shape than a scope narrative will ever be. “A census metric exceeding Schedule 2’s threshold” is machine-checkable; “a material change to the agreed scope” is not, and never will be.

But discretion and best-endeavours obligations do not code, and fields 1, 6 and 7 contain irreducible judgement at drafting time even where the test is mechanical at dispute time. Typing a trigger moves the judgement; it never eliminates it. Which is the same trade Chapter 7 named as basis risk, showing up again in legal dress.

So the useful ambition is not a contract that executes itself. It is a schedule a competent person can check in five minutes — and that is available today, in Word, with no technology at all.

The rule is now argued, tested, bounded and drafted. What is left is the smallest thing in the book and the only one that decides whether any of it happens: what you do on Monday, with the engagement you already have, without a new template and without asking anyone’s permission.

14
Part III: Where It Refuses, and What You Do Monday

Monday

Six moves. None of them requires a contract to be renegotiated, a client to agree to anything, or a budget to be approved.

Every one of the six below can be started unilaterally, this week, by one person, on an engagement that is already half-finished and was sold under the old clause.

That is not a concession to anybody’s laziness. It is a property of the design worth naming: the matrix is primarily an instrument of internal clarity and only secondarily a contractual one. A supplier who knows which field moved is better off immediately, even when the contract does not yet care. The order matters too — they run from cheapest-and-most-diagnostic to most-committing.

1. Run the classification backwards

Do: take your last completed engagement. List every surprise, from memory and from the change log. For each, ask which named perimeter field moved.

Costs: an hour, and nobody’s permission.

Surfaces: the count of surprises you cannot classify without an argument. That count — not the number of change requests you raised — is the honest measure of whether your perimeter was typed or merely written. And watch the distribution: if the unclassifiable ones cluster on one field, you have just found the row to fix first, which is worth more than the total.

2. Write the eight recorded values for your live engagement

Do: fill the schedule retrospectively, today. What was the promise sentence? What was the declared source list? What did the census count, if there was a census?

Costs: a morning.

Surfaces: at least one field you cannot answer — which is information you needed and did not have. A recorded value written in week four is worth enormously more than none, because from week four onwards there is something to compare against, and every subsequent surprise becomes decidable.

3. Write a trigger per field, then delete the ones that need judgement

Do: apply Chapter 5’s trigger test destructively to your own draft.

Costs: an afternoon, and some discomfort.

Surfaces: the deletions. The deletions are the finding. They are the fields that will be litigated, and they are precisely where your next contract needs work. A field you cannot type is not a failure of effort — it is a fact about your product, and you have just learned it before it cost you anything.

4. Publish one counter

Do: put reserve consumption on the surface the buyer already sees. One line. “Access exceptions: 2 of 5.”

Costs: nothing.

Surfaces: how much absorption you have been doing invisibly. Visible absorption is worth several times silent absorption and costs exactly the same to provide — silent absorption produces no evidence, buys no credit, and cannot be sold to the next buyer or defended to your own finance director.

5. Name the exhaustion owner and the window

Do: two names and five business days, in the schedule.

Costs: one email.

Surfaces: nothing at all, immediately — which is the point. It is insurance against the single most expensive failure in this book, and it is the cheapest clause in the whole scheme.

6. Shrink the next unclassifiable opportunity

Do: run Chapter 12’s row-by-row verdict on it, then sell the bounding instead of pricing the whole thing bravely.

Costs: revenue, sometimes. Nerve, always.

Surfaces: whether your firm can actually do this. Shrinking is the harder skill and the one nobody teaches — and a firm that can reliably convert an unboundable request into a smaller boundable one keeps the relationship, the revenue and the band’s integrity at the same time.

What the six have in common

They all move judgement earlier. That is the entire mechanism, and it is worth more than the taxonomy — not because three categories beat one, but because the categories force a set of decisions to be made while both parties are calm, informed and not yet committed. Every hour of judgement relocated from delivery to signature is an hour exercised without the relationship in the room.

And there is a compounding effect that is easy to miss and is probably the real prize. A firm that types its perimeter accumulates comparable engagements — and comparable engagements are the only population from which a band can ever be learned. A lane full of forced exceptions teaches you nothing, which means the firm that keeps saying yes to everything is also the firm that will never find out what its own product costs.

Three altitudes

Applying AI to writing change requests faster is one altitude. Recompiling the change-request pipeline is another. Replacing the change request with a boundary-mutation test is a third — it deletes the commercial object rather than accelerating it. The failure mode of the first two is named precisely in our own work: faster reconstruction is still reconstruction, and “the wrong friction gets greased” when a firm treats the maintained object as given, applies AI to the labour inside it, and never re-asks whether the object should exist.

The change request is a maintained object. It has been maintained for thirty years, it employs people, it has templates and a log and a board, and almost nobody has re-asked whether it should exist.

The invariant

Fixed price was never it. Fixed price is a strong signal — unusually good evidence that a supplier has made its own complexity legible enough to take responsibility for it — and a signal is not a religion. The invariant underneath is a stable unit of commitment. And what this rule protects is the stability: a promise that does not move when the method does, and that does move — promptly, with evidence, in front of the person who owns the consequence — when the boundary really has.

Here is the fullest statement of the whole doctrine, from the conversation this book came out of:

“An AI-native service product fixes the commercial boundary while leaving the production path generative. It sells a bounded customer state rather than labour, uses machine-scale cognition as elastic capacity to absorb ordinary complexity and iteration inside the boundary, meters the residual human or physical scarcity explicitly, and reopens the commercial contract only when reality changes the boundary rather than merely making the work messier.”

Those last twelve words were the seam. Everything in this book has been the work of filling them in — eight fields, three dispositions, a trigger apiece, an exhaustion protocol with a name and a date on it, and an honest account of where the whole thing refuses to apply.

The compact form

“Fixed outside. Generative inside. Verified at the edge.”

“Sell the transformation. Absorb the production variance. Meter what remains scarce.”

Stop writing change requests for work your machine should absorb. Start writing down which eight things, if they move, mean the deal has changed.

REF
Sources & Evidence

References & Sources

The evidence base behind every claim — primary research, industry analysis, and technical specifications

Research Methodology

This ebook draws on primary research from standards bodies, independent research firms, enterprise technology vendors, and consulting firms. Statistics cited throughout have been cross-referenced against primary sources.

Frameworks and interpretive analysis developed by Scott Farrell / LeverageAI are listed separately below — these represent the practitioner lens through which external research is interpreted, and are not cited inline to avoid self-promotional appearance.

LeverageAI / Scott Farrell — Practitioner Frameworks

The interpretive frameworks, architectural patterns, and practitioner analysis in this ebook were developed through enterprise AI transformation consulting. The articles below are the underlying thinking behind those frameworks. They are listed here for transparency and further exploration — not cited inline, as this is the author's own analytical voice.

Scott Farrell — AI-Native Service Architecture

The square as the object this rule governs; the eight perimeter fields; the deferred change-control seam

https://leverageai.com.au/wp-content/media/articles/226-ai-native-service-architecture.html

Scott Farrell — AI-Constituted Services

The Fixed-Price Envelope: census, bands, included finding counts and the Flex Reserve — parent doctrine, referenced not re-taught

https://leverageai.com.au/wp-content/media/articles/202-ai-constituted-services.html

Scott Farrell — Buy Certainty First

Typed uncertainty and the pricing envelope as parent doctrine

https://leverageai.com.au/wp-content/media/articles/204-buy-certainty-first.html

Scott Farrell — Waterfall Per Increment

The production cadence — specify, generate, verify, regenerate inside the increment — has its own treatment; this book operates at the commercial altitude

https://leverageai.com.au/wp-content/media/articles/44-waterfall-per-increment.html

Scott Farrell — Stand Pat

The structural null option: the default output is nothing, and only a genuine must-answer event earns an interruption; almost every event is a capture, a few are checks, and the entire skill is telling them apart

https://leverageai.com.au/wp-content/media/articles/101-stand-pat.html

Scott Farrell — FDE Delivery Looks Like Waterfall Per Increment

Loosen the leash on implementation after the pre-generation gate; prefer regeneration from improved intent over endless surgery on near-miss code

https://leverageai.com.au/wp-content/media/articles/171-fde-delivery-looks-like-waterfall-per-increment.html

Scott Farrell — AI-Native Successor Offer

Delivery physics: every commitment maps to an operational pathway that exists or is funded; physical scarcity is explicit in the offer design, not wished away by the AI narrative; authority is placed

https://leverageai.com.au/wp-content/media/articles/213-ai-native-successor-offer.html

Scott Farrell — Cheap Thinking Makes Strategy Harder

Same tool, opposite economics: a tool that turns a four-hour task into a one-hour task creates a revenue problem under hourly billing and a margin opportunity under fixed fees

https://leverageai.com.au/wp-content/media/articles/227-cheap-thinking-makes-strategy-harder.html

Scott Farrell — The North Star Prompt

Tight intent, loose method: be precise about purpose, audience, success and failure and the load-bearing constraints, and leave latitude over procedure — while staying prescriptive where output feeds a machine or a constraint is safety- or correctness-critical

https://leverageai.com.au/wp-content/media/articles/70-north-star-prompt.html

Scott Farrell — Compile the Bounded Object

Faster reconstruction is still reconstruction and the wrong friction gets greased; the failure is treating the maintained object as given, applying AI to the labour inside it, and never re-asking whether the object should exist

https://leverageai.com.au/wp-content/media/articles/222-compile-the-bounded-object.html

Primary Research & Standards Bodies

Project Management Knowledge (practitioner reference describing PMBOK) — Perform Integrated Change Control [1]

The entry test is every change to a baseline; each request assessed for impact on scope, schedule, cost, quality, resources and risk

https://project-management-knowledge.com/definitions/p/perform-integrated-change-control

Stanford HAI — Artificial Intelligence Index Report 2025, Chapter 1 [3]

Inference cost for GPT-3.5-level capability fell from $20.00 to $0.07 per million tokens, a more than 280-fold reduction in approximately 18 months

https://hai.stanford.edu/assets/files/hai_ai-index-report-2025_chapter1_final.pdf

Nathen Harvey and Derek DeBellis, Google Cloud / DORA — Announcing the 2025 DORA Report [5]

Nearly 5,000 respondents; AI adoption continues to have a negative relationship with software delivery stability; acceleration exposes downstream weaknesses

https://cloud.google.com/blog/products/ai-machine-learning/announcing-the-2025-dora-report

Joel Becker, Nate Rush, Beth Barnes and David Rein, METR — Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity [6]

Developers took 19% longer with AI tools while believing they were 20% faster; the page now carries a banner stating the results are out of date

https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study/

Joel Becker, Nate Rush, Tom Cunningham, David Rein and Khalid Mahamud, METR — We are Changing our Developer Productivity Experiment Design [7]

Developers could not report time-spent while agents ran; 30-50% declined to submit tasks they would not do without AI; the early-2025 slowdown estimate is superseded

https://metr.org/blog/2026-02-24-uplift-update/

Michael C. Loulakis and Lauren P. McLaughlin, ASCE Civil Engineering — Limitation of liability clauses are like kryptonite [10]

A $50,000 cap enforced at 8% of the designer's fee (Zirkelbach, 2017) and $550,000 of a $9.5m verdict (Taylor Morrison, 2017); fees do not cover potentially unlimited exposure; the court enforced a stale cap because the parties failed to renegotiate as scope moved

https://www.asce.org/publications-and-news/civil-engineering-source/civil-engineering-magazine/article/2021/12/limitation-of-liability-clauses-are-like-kryptonite

APMG / World Bank Group — PPP Certification Guide — Variation Management [13]

Four variation categories, the first requiring no formal procedure where there is no additional cost; pre-agreed schedules of rates for small works; pre-pricing foreseeable variations at signature; verify that a variation request is actually a change and not covered by existing pricing structures

https://ppp-certification.com/ppp-certification-guide/7-variation-management

Congressional Research Service — Parametric Insurance for Natural Disasters: Frequently Asked Questions (IN12670) [18]

A parametric contract specifies the payment amount, a trigger based on observable data, and an impartial third party to verify the trigger; payment in weeks rather than months or years; clearly defined triggers reduce policy disputes; basis risk means payment may be higher or lower than actual losses; the New Orleans School District policy did not pay because winds missed the 100 mph trigger

https://www.everycrsreport.com/reports/IN12670.html

The Law Commission of England and Wales — Smart contracts — advice to Government [24]

The current legal framework in England and Wales is clearly able to facilitate and support smart legal contracts without statutory reform; existing principles apply much as they do to traditional contracts

https://lawcom.gov.uk/project/smart-contracts

Industry Analysis & Vendor Research

Oracle Law Global — The benefits and pitfalls of a contract's 'change control' clause [2]

Regulates change and excludes informal variation; specifies templates, time limits and the consequences of missing them

https://oraclelawglobal.com/news/general/the-benefits-and-pitfalls-of-a-contracts-change-control-clause

Vantage — The Hidden Cost Driver in Agentic Coding Sessions in 2026 [4]

A full agentic session reading a codebase, implementing across files, running tests and iterating through failures costs roughly $6.00 on a premium model versus $0.60 on a cheaper one — the author's illustrative model, not measured client data

https://www.vantage.sh/blog/agentic-coding-costs

JMD Ross Insurance Brokers — Professional services contract clauses — Some key points [9]

Without a contractual limitation liability is unlimited and could exceed PI cover; fitness-for-purpose obligations are generally uninsurable; indemnity clauses can extend the scope and duration of liability

https://www.jmdross.com.au/wp-content/uploads/2018/02/Professional-services-contract-clauses.pdf

Peter Higgins, NEC Contracts — Clause 60 — compensation events [11]

A compensation event is the only way cost or time can be changed; clause 60.1 enumerates the events; the three categories include failures by the Client, Project Manager or Supervisor to take an action the contract requires

https://www.neccontract.com/news/clause-60-%E2%80%93-compensation-events

Tiah Weekes, Sharpe Pritchard — Changing Course: Navigating Variations Under JCT and NEC Contracts [12]

NEC requires prospective assessment of time and cost at the time a change is identified, with a tight response window and deemed acceptance; a variation is intended to modify the works, not the working relationship

https://www.sharpepritchard.co.uk/latest-news/changing-course-navigating-variations-under-jct-and-nec-contracts

Sophie Danby, ITSM.tools — Change Enablement in ITIL 4: Definition, Practice and Best Approaches [14]

Standard changes are low-risk, repeatable, pre-authorised and frequently automated; the Change Authority decentralises approval by risk rather than routing everything through a central board

https://itsm.tools/change-enablement

Amazon Web Services, Well-Architected (quoting the PeopleCert ITIL 4 Change Enablement Practice Guide) — Change enablement in ITIL 4 [15]

A service change is the addition, modification or removal of anything that could have a direct or indirect effect on services; the purpose is to maximise successful changes by assessing risk and authorising changes to proceed

https://docs.aws.amazon.com/wellarchitected/latest/change-enablement-in-the-cloud/change-enablement-in-itil4.html

MPUG, quoting PMI definitions — Contingency Reserve and Management Reserve [16]

Contingency reserve sits inside the baseline for known risks with active response strategies; management reserve sits outside the performance measurement baseline for unforeseen in-scope work and is drawn through the change-control process

https://mpug.com/contingency-reserve-management-reserve

Hong Kong Lawyer (Law Society of Hong Kong) — Getting to Know Target Cost Contracts and Pain/Gain Share Mechanism [17]

Costs reimbursed plus fixed margin against an agreed target with savings and overruns shared by formula; sliding-scale pain/gain share with a point beyond which the contractor takes 100% of overspend; target cost is preferred where scope cannot be clearly defined

https://www.hk-lawyer.org/content/getting-know-target-cost-contracts-and-%E2%80%9Cpain-gain%E2%80%9D-share-mechanism

GC AI — Limitation of Liability Clause: Caps, Carve-Outs, and Examples [20]

Two mechanisms read together — a cap on damages and a consequential-loss waiver; a generous cap means little if the waiver strips out the losses you would actually claim; tie carve-outs to a closed list rather than open-ended categories

https://gc.ai/clauses/limitation-of-liability

Troy Edwards and Peter Tolson, A&O Shearman — Cost reimbursable vs. lump sum turnkey construction contracts: the many routes to bankability [21]

In truth there is no such thing as an absolute fixed price contract; contractors price significant contingencies and are incentivised to reopen where those prove insufficient; lump sum may still be preferable for well-defined, low-risk projects where scope is clear at the outset

https://www.aoshearman.com/en/insights/cost-reimbursable-vs-lump-sum-turnkey-construction-contracts-the-many-routes-to-bankability

Aayush Sharma, SignalFire — Beyond the billable hour — How AI is reshaping margins and models at law firms [22]

Hourly billing persists in complex, high-stakes or open-ended matters because scope keeps evolving and risk is asymmetric and dynamic, making fixed-fee structures impractical without significant risk premiums

https://www.signalfire.com/blog/ai-is-redefining-billing-hours-at-law-firms

Osborne Clarke — Law Commission concludes English law supports smart contracts [25]

A smart contract is computer code that, upon the occurrence of specified conditions, runs automatically according to pre-specified functions; a smart legal contract is one where some or all terms are defined in or performed by a computer programme

https://www.osborneclarke.com/insights/law-commission-concludes-english-law-supports-smart-contracts

About This Reference List

Compiled August 2026. All URLs verified at time of compilation. Regulatory documents and standards specifications are subject to revision — check primary sources for the most current versions.

Some links to academic papers and vendor research may require free registration. Government and standards body publications are freely accessible.