Fractional CTO for healthcare and hospitality SMEs.
Home · Method · Healthcare · Hospitality · Engagement · About · Book a discovery call
Four weeks. A decision memo. The same decisions in two packets: a six-page paper for the board, and a shorter brief for engineering. Both use the same identifiers.
Assess hands over outcomes, evidence, proposed decisions, and an explicit list of limits. Strategy locks a small set of those decisions. It does not reopen the shadowing, and it does not become a roadmap. The roadmap is Translate.
The shape is Richard Rumelt’s kernel, from “The perils of bad strategy” (McKinsey Quarterly, June 2011, adapted from Good Strategy/Bad Strategy). A diagnosis: an explanation of the nature of the challenge, simplified to the critical parts. A guiding policy: the overall approach chosen to cope with those obstacles. Coherent actions: steps coordinated with each other to carry out the policy. His editing test for a bad strategy is four hallmarks: failure to face the challenge, mistaking goals for strategy, a long list of objectives that restate the desired state, and fluff.
Week 1. Write the diagnosis. Five conversations of 45 to 60 minutes: the owner, the operator of the workflow, finance, the engineering lead, and two people who touch the workflow every day. Bring back four baselines and no more: time through the workflow, where demand dies, regrettable attrition on that team, and how the related system is released today. Read the architecture only far enough to name constraints. Run Well-Architected questions against that one workload as a conversation. The framework’s introduction says the document is written for people who make architecture decisions, and a review is a conversation about those decisions. It is an input row. It is not the strategy.
Friday: a two-page diagnosis. The critical challenge, the evidence, and the challenges that were considered and set aside.
Week 2. Choose the policy and the order. Ninety minutes with organization leadership, ninety minutes with engineering, then sixty minutes together. Draft a guiding policy that a peer with a different constraint would be wrong to copy. Cap coherent actions at three, in the order they depend on each other. Attach a metric tree: one business result per action, plus delivery health on the single service that implements it.
An optional 90 minutes with engineering can draw one value chain of the workflow: the user need, the components required, and whether something custom-built is already a product. That is the useful slice of Simon Wardley’s introduction to value-chain mapping. If the hour does not change a build, buy, or integrate decision, leave the map out of both documents. A full Wardley workshop, with doctrine and climatic patterns, will consume the four weeks. An SME board will not sit through it.
Week 3. Write both artifacts from one decision log. Every bet gets an identifier. For each, write the cost of a month of delay in the unit finance already uses: missed visits, empty rooms, commission, denials, overtime. Record build, buy, or integrate; the data boundary; a funding band; and a candidate owner. Funding bands are coarse: inside the current team, needs a vendor, or needs a hire.
Week 4. Engineering first, then the board. Engineering reviews the brief. Change the paper only where they show a constraint the diagnosis missed. The board then accepts, accepts with one named change, or sends the diagnosis back. A send-back does not start the roadmap.
The engineering brief uses the same headings and the same identifiers. It adds design constraints and drops the narrative. No diagrams and no tool names in the board paper, except where a constraint forces one: the EHR or the PMS they already run.
Melissa Perri’s cascade sits under the kernel so the board sees order: a vision, the first challenge on the way, a measurable target, and today’s number. A feature list is a plan. A plan is what people ask for when they wanted a strategy.
Christina Wodtke’s rule is to set goals for the one mission-critical area, and to make the results outcomes rather than tasks. Rolling out a company OKR program inside these four weeks produces vanity goals: launch counts, model demos, “AI adopted.” The tree for this client has three business measures on the chosen workflow, and a separate delivery reading:
DORA’s current set is change lead time, deployment frequency, failed deployment recovery time, change fail rate, and deployment rework rate. Put two numbers in the board tree, one throughput and one stability, for the service that carries the bet. Keep the rest in the engineering brief. The metrics are for one application. Setting them as targets invites gaming. The 2025 DORA report’s public summary says AI amplifies the system the company already has, so “adopt AI” cannot be the guiding policy.
These are the shape of a kernel. They are not a client’s findings.
One intake stream. Referred patients for one service line do not become attended visits, and staff type the same demographics into the schedule and the record. Policy: close conversion on that stream before adding a channel or a model. Order: count the drop-off and name the handoff owner; stop the double entry using the EHR’s existing API; only then automate the slowest step inside the current HIPAA boundary. Declined: EHR replacement, a data platform, an AI front door.
If the bet calls a certified EHR’s patient-access API, the adopted standard is HL7 FHIR Release 4.0.1 (45 CFR 170.215). That is a reason to integrate with the record. The HIPAA Security Rule’s safeguards for electronic protected health information are a constraint on the data boundary (HHS Security Rule).
One arrival path. A small hotel group confirms direct bookings the desk cannot honor because housekeeping never sees the arrival. Policy: make one property’s arrival path executable by the desk and the floor, and keep card numbers in the processor they already use. Order: one arrival record from booking to a ready room; connect that time to the housekeeping turn; any guest-facing automation only for requests staff already handle. Declined: PMS replacement, a guest-data platform, a concierge bot.
A new path that stores, processes, or transmits cardholder data expands PCI DSS scope. Start from the PCI Security Standards Council and keep new card data out of the bet when a compliant processor already has it.
The board reads the six-page paper: the decision requested, the diagnosis, the policy, three bets in order, the metric tree, the funding bands, and the options declined.
Engineering reads the brief before that meeting. They check whether the actions can be staffed and whether the diagnosis missed a hard dependency. They are not being asked to approve the business goal. The options declined are in their packet so they are not rebuilt later as a “phase 0.”
A handoff block, and nothing else repeated: the guiding policy in one sentence, the bets in order with the metric each one moves, the refusals, and the questions still open (owner, budget band, dependency, appetite). The diagnosis, the evidence, and the argument stay on this page. Task lists, vendor names, and week-by-week delivery stay on the roadmap.
The call is to decide whether this engagement fits. The answer can be no.