Cassie Kozyrkov’s question is a good one: if machines now do the doing, what is left for leadership?
Her answer is attention. Leadership becomes the design of what machines notice, optimise and repeat. That is a useful shift. It becomes more interesting if Ashby’s law and Lewin’s field theory are read a little more literally than the familiar management versions allow, and then held against what one organisation did with its attention over a year.
Ashby’s law does not say that a controller has to be as complex as the system it governs. It says that the regulator’s variety has to cover the variety of disturbances, relative to the outcomes that have to remain within limits. That difference gives two ways of closing the gap: increase the variety available to the regulator, or reduce the variety arriving at it.
Attention can be the second move, but only if what is filtered out is genuinely outside the control problem. Otherwise the filtering has reduced the variety the regulator can see and left the variety of the disturbance where it was. Either way it puts another operation inside the system: deciding what counts as a distinction worth surfacing.
Sixty-four positions, or thirty-six
Ashby’s two-armed semaphore offers sixty-four positions to an observer close enough to tell the arms apart, and thirty-six to one who cannot. The semaphore has not changed. The observer’s variety has. Ashby draws the moral that a set’s variety is not an intrinsic property of the set. The observer and their powers of discrimination have to be specified before the variety is well-defined. The number moves when the distinctions move.
The reorganisation was announced in October. Four directorates became three, the data team moved out of IT into a function called Information and Insight, two roles went and three were created. The intranet A to Z was updated inside a fortnight. In its first week the new function asked how many suppliers the company has. Procurement said 400, the ones on its approved list. Finance said 1,900, every entity it had paid. Legal said 250, the ones with a negotiated contract rather than standard purchase order terms. The reflex is to hunt for the wrong one, and there is none. A supplier is an obvious thing, obvious enough that no definition had ever been written down, and three teams had settled it three different ways without noticing. That week three definitions that had been in use for years surfaced as arithmetic.
Each of the three made sense where it was minted. The trouble starts when a word travels, carrying the confidence of home into a place where a different definition quietly holds. The same travelling has long kept business and ICT talking past one another.
A familiar ritual follows trouble of this kind. A decision goes wrong, a risk materialises that a team had documented, and the retrospective concludes that the information was not good enough. The remedy writes itself: another dashboard, a new report, a data lake properly governed this time, an AI pilot to surface insights. The ritual is comfortable because it frames the problem as scarcity, and scarcity has an obvious cure. A walk through almost any large organisation suggests no shortage at all. Dashboards refresh nightly and go unwatched. The same metric appears in three decks with three values. Reports run on schedules set years ago, for audiences that may no longer exist. Meetings re-litigate facts that were settled in other meetings. The organisation is standing in a warehouse of maps, unsure which one describes the territory outside. What is more often scarce is confidence that the information means what it is taken to mean.
An organisation in this condition can add information indefinitely without settling a single definition. Each new report is a new message, written in the local dialect of the team that built it, and each one raises a reconciliation bill for the reader. The bill is never itemised. It is paid in pre-meetings and corroborating phone calls.
Stored data is “a message, a communication, to people in the future”. Ronald Ross has spent a career on business rules, and that is his compact description of it. A message implies a sender with an intent, a receiver who was not in the room when the intent formed, and a gap the message crosses alone. Distance in time behaves like distance in space. The analyst who named the column has moved teams. The assumptions behind the metric were obvious to everyone in the room in 2019, and the room has dispersed. The report still arrives every Monday, fluent and confident, from senders who can no longer be asked what they meant, and each reader supplies a plausible meaning of their own.
Organisations rarely notice, because the compensating works well enough to stay invisible. An analyst in Finance knows which version of a figure to believe. A pre-meeting reconciles the figures before the real meeting sees them. These compensations are genuine competence. They live in particular people, and they go when those people do. The information stays neatly in the databases. What walks out the door is the knowledge of which number to trust, and why.
A message that has to survive its sender needs custody. The information life cycle in Metier, Jaap Karman’s framework, has a landing zone for the unverified, a staging area for what has been checked, a semantic stage where an intermediate form is shaped, and only then a product fit for delivery. The stages read less like storage tiers than like a chain of custody. Data lineage traces the same chain backwards: where a piece of information came from, and what has been done to it along the way. At each stage, someone vouches: still what it claims to be, still meaning what it was minted to mean. A reliable message is one that complies with the rules of the context that produced it. Verification is what keeps the message decodable after the sender has gone. As plumbing, such a pipeline is easy to dismiss as ceremony, the boring part of ICT, keeping the lights on. As custody, it is the difference between a warehouse of maps and a map that can be trusted at the moment of stepping outside. A figure can be trusted only as far as its meaning is maintained, and maintaining meaning is work, with owners, stages and failure modes of its own. Organisations often fund the production of information more visibly than the custody of its meaning.
“What information was missing” almost always has an answer, which is part of its appeal. Something can always be named, and a report commissioned to supply it. A different count is seldom taken: of everything already held, how much gets acted on without a corroborating phone call. Where most of it would be acted on, even a thin report goes a long way. Where little of it would be, no amount of additional reporting is likely to help. The appetite for one more dashboard rests on a scarcity that, in most organisations, ended years ago.
In Ashby’s terms, another report adds variety arriving at the regulator. It changes nothing about the distinctions the regulator draws. Three teams drawing three different lines through the same entities will go on producing three counts. Information and Insight commissioned a supplier dashboard in November.
Words outlive the distinctions they were cut from
The same November, four people left a meeting agreed about the risk of moving payroll to a new provider in January. The minute said so, and none of them had reason to doubt it. In the room, the payroll manager meant the chance that the first run would come out wrong. Finance meant what it would cost to put right. Legal meant who would answer for wages paid late. The programme lead meant the three months of roadmap a parallel run would eat. All four said risk, all four heard risk, and nothing in the hour gave any of them cause to check.
The four readings are not four points on one line. A botched run is an event, the cost of putting it right is a quantity, answering for late wages is a relation between people, and giving up three months of roadmap is a decision. Two people using one word for a quantity and for a decision have nothing to disagree about until something forces both into the same sentence. A disagreement about a number announces itself, because the two numbers sit on the same slide. A disagreement about a word can leave the room in four heads and carry on working. In December a contingency line arrived in the budget, sized to cover corrections and a month of overtime. The payroll manager read it and could not say what was wrong with it, only that money set aside to repair a bad run is not the same as a run that comes out right. By then the agreement was minuted, the budget was allocated, and reopening it would have looked like obstruction. Agreement of that kind is common, and not a failure of intelligence.
A word is durable. It gets repeated in meetings, printed on templates, written into job titles, and it survives without anyone attending to it. A distinction has no such life of its own. It exists while a person is making it, and the making leaves no trace: nothing is minuted on the day a team stops separating a rule from the procedure that carries it out. Rule and procedure tend to collapse first. A rule says what has to hold. A procedure says what gets done about it. A credit limit that once sat in a policy ends up in step four of the onboarding script, and from then on it is whatever step four says. It moves when the script’s owner edits step four. No decision is recorded. A procedure, a step in a procedure, or an action is not a business rule, which Metier says at length and the onboarding script does not say at all.
Functioning and functionality go the same way, two words most organisations use interchangeably and Metier does not. A report saying the payroll system is functioning can mean that it ran, or that it paid people the right amount, and nothing in the report says which.
Two weeks after the contingency line went into the budget, the programme lead proposed a reconciliation tool. It would run the old system’s output against the new one, line by line, and flag every difference. It went through without objection. Line by line, it would find every difference between the two systems and settle none of them.
In Metier, business becomes functional, because business reads as a cost centre and the work in question is implementing the organisation’s goals. Technology becomes technical, because technology carries the suggestion that buying some would solve the problem. Information communication becomes compliancy, because the communication an organisation actually runs on, the expectations and the instructions, is not the communication its cables carry.
The organisation already had a glossary. It was accurate. It had been reviewed, circulated and signed off. The entry for risk was broad enough that each of the four people would have read it and found their own reading sitting inside it. That is why it was approved. An entry narrow enough to exclude three of them would not have survived the review.
A glossary records the words an organisation uses. What held the chance of a bad run apart from the cost of one was never a word. It was a habit of keeping two things separate, maintained by people who had some reason to keep them separate, and it went when the reason did. The entry stayed on the intranet, accurate and undisturbed, and by then it described a distinction nobody was making.
Something stricter would be a term, synonyms included, pointing at a single concept within a stated context. That needs a business vocabulary with a concept model underneath. The glossary took an afternoon. Nothing was ever started on the concept model underneath it.
Whoever decides what an attention system surfaces is working from a stock of distinctions, and the stock is mostly borrowed. Not every import pays for itself. A hidden attractor has a precise definition: its basin of attraction does not touch any neighbourhood of an equilibrium, so looking at where a system comes to rest will not find it. The Cassini family of curves gives a sharper example still: a parameter crosses a threshold, and the curve changes from two regions to one. Once the parameter, threshold and organisational referents are specified, the analogy can be wrong. A distinction that can fail is the whole of what an import has to bring.
The glossary entry for risk cannot fail. It contains all four readings, so no reading contradicts it, so it makes no distinction. None of the four was working from a definition. They were working from a word, and the word was working perfectly.
The lifespace of an assistant
In Lewin’s B = ƒ(P, E), E is the lifespace, the situation as the person actually reads it. What lies outside that field has no purchase on the behaviour, however real it may be from somewhere else.
An attention system working from outside the situation can surface distinctions the person can recognise and make some things harder to miss. It can also institutionalise a blind spot.
Information and Insight’s assistant went live on a Tuesday in January. It indexed the intranet and was asked by an engineer about to resign what notice period applies. It answered three months, quoting a policy page from 2019. The answer has been one month since the 2022 handbook. The pilot review recorded a hallucination. The model had not hallucinated. It had read the intranet.
Nobody had taken the 2019 page down. There was never a reason to. The people reading it were checking a rule that applied to them, and they knew to go past it to the handbook. The ones who did not know asked a colleague who did. The page does not link to the handbook, and the handbook does not link to the page. That page is superseded. That report double counts anyone who transferred mid-year. The Friday pack runs a month behind. The regional totals still stop at the pre-merger boundaries. None of it was written down, because none of it looked like work. It was what reading the intranet consisted of. There was no villain in that. A written correction is a second document describing the errors in the first, which is an odd thing to propose in a meeting and an easy thing to decline. It would also have needed an owner, and the pages had none. Their author left years ago, from a team reorganised twice since, the second time in October. A ticket raised about the page in 2021 was closed as no action required, because the handbook was correct. Anyone who knew all this got the right answer. Anyone who did not asked a colleague who did, and got the right answer a little later. The documents stayed as they were, wrong in the same places for years, and the wrongness stayed a private arrangement between the staff and the pages. The page was corrected every time it was read, and never once changed. The intranet had been wrong since 2022, and it had cost nothing. The assistant was the first to take it at its word.
The staff had a lifespace that contained the page, the handbook and the knowledge that one superseded the other. The assistant had a lifespace that contained the intranet. Nothing in its field said that a page could be current and wrong. From where it stood there was no distinction to make. An assistant that reads the intranet as written institutionalises whatever the intranet has been wrong about. Procurement found the same thing from the other side. Policy says anything over ten thousand euro needs three quotes. It has said so for years, and it is accurate in the sense that it was written and signed. Renewals had not been put through it, because there is nothing to get three quotes for when the question is whether to carry on with a supplier already installed. The policy had been incomplete for as long as anyone could remember, and it had made no difference, because nothing had ever applied it exactly. By the end of January every renewal in the queue was blocked, three buyers were raising exceptions by hand, and one of them was writing down, for the first time, which purchases the rule had never really covered. A workflow was found too rigid, and a project opened to make it configurable.
The pilot review came back in February with three recommendations: better retrieval, a fine-tuning pass, and a policy on where the assistant may be used. None of those recommendations are new. An algorithm is one transformation among several in Metier’s account of information processing, and it arrives with a requirement older than any pilot: no data insight is worth taking seriously until it has been tested on new data. When something goes wrong, an explanation usually goes in one of two places. One is a specific local cause: this operator, this batch, this machine, on this morning. The other is the system, whatever would still be there tomorrow if the person were swapped out. W. Edwards Deming argued for the second, away from blaming a person for a mistake. A tool is new, it is external, it has a vendor attached, and it cannot object. The retrieval was improved. In March a second engineer, also about to resign, read the 2019 page themselves.
The filter and what it acts on
An attention scaffold is not outside the control problem. Its designer decides what it surfaces, what it suppresses and what counts as a useful distinction. The decision is made from somewhere, by an observer with a lifespace, a channel and a finite variety of their own. The problem has moved up one level, to the designer’s position.
What does the system distinguish? What does the filter act on? What disappears before it can be surfaced? Who can tell that something has disappeared? A queue that suppresses everything below a severity threshold has answers to the first two printed in its configuration. Forty low-severity events from one supplier and forty from forty different suppliers come out of it as the same silence. Those four questions are part of the system being designed.
The assessors came for three days in March. The evidence pack ran to 412 documents, 61 of them written that fortnight. The verdict was level three of five, with a roadmap to level four. The certificate hangs by the lift. In April a release went out without a rollback plan, the way releases had always gone out.
The score for each process came from six questions on a five-point scale: whether the thing exists, whether it is written down, whether it is reviewed, whether the review is scheduled, whether the schedule is met, and whether the whole is signed off. That is the filter’s configuration. What it acts on is documents and interviews. The pack held policies, process descriptions, minutes, review schedules and screenshots of the pipeline configuration. The assessors held nine interviews. None of it was untrue. Nothing in the three days watched a decision being made. The assessors asked nine people to describe the change process. Seven described the process as written. Two described what they do. The difference was recorded as inconsistent adoption, and the score for that process came down half a point.
The highest-scoring evidence in the pack was the rollback procedure of a team that had never used it. Current, reviewed on schedule, signed off, one version, never handled. Another team had used its rollback procedure three times and simplified it after each one. It could produce three versions, and approval records for one of them. It scored lower. Evidence keeps better when nothing touches it. This procedure carried the marks of three uses.
The record then grows to fit the filter. The second assessment, the following spring, took three weeks instead of six, because a coordinator had been appointed for three days a fortnight and knew which document answered which question. Two of the templates were reused unchanged. Before the second assessment the people due to be interviewed were sent a briefing note on how the change process is documented. At the first assessment the question was how deployment approval works. At the third it was where the deployment approval document is. The certificate by the lift was replaced with the new one. The old one is in the pack. The evidence request had 140 items. The pack answered 130 of them without anyone opening a system. Two findings were raised, one closed by adding a paragraph to the change policy and one by scheduling a quarterly review of it. The report recorded a mature and well-documented control environment. The quarterly review produces minutes, and the minutes are evidence for the next assessment. The pack ran to 412 documents in March and stands at 470. The steering meeting asked whether finding 17 was closed. Whether a release could be rolled back was not raised.
Everything the assessment had to work with was an interview or a document. Both return something simpler than the process, on Metier’s reckoning, and in most situations nobody has an overview of the real one. There are no verified independent maturity levels, which does not make the measuring pointless: without metrics any change is disputable. The work of producing evidence now has a description, a schedule, an owner and a signature. At the next assessment it will score well.
What did the assessment distinguish? Documented from undocumented, reviewed from unreviewed. What did it act on? The pack and nine interviews. What disappeared before it could be surfaced? A release without a rollback plan. No document described it and no question asked about it. Who could tell? The two interviewees who described what they do. Their difference was scored as inconsistent adoption.
Which distinctions can reach the position
What the occupant of a position can tell apart is finite, and the count moves with the position. Their channels determine which distinctions can reach them.
The week the assessors were in the building, a new starter sat for a week without a login. Six people met four times and recommended a pre-start checklist. The checklist was adopted in April. In September a new starter sat for a week without a login.
In January, the month the assistant went live, IT had consolidated identity management onto one platform. The licence cost fell, and provisioning moved from on request to a nightly run. In February HR added an e-signature step to contracts, closing an audit finding. It added two days. The working group was convened by the service desk, and looked at the service desk. Each decision was correct on its own terms, and each was taken by people who had been told what their part was for. The platform team’s representative sat on the working group. The group had been asked about onboarding delays. The January consolidation did not come up.
Time to productivity is on the quarterly scorecard. There is a monthly service review, an escalation path with three tiers, a target of five days, and an owner for each of the four onboarding sub-processes. There is also a process map. Eleven steps, three swimlanes, accurate. Nothing on it shows which of the eleven steps anyone in the room can change. The map is owned by the process improvement team, which owns none of the steps. The delays appear as item four on the monthly service review. The instruction that comes back is to review the onboarding process. The March delay was escalated twice, both times up the service desk’s line. The report has gone up every month for eleven years. The instruction has come back in some form for most of them. Nothing in that traffic has ever gone across, to the platform owner or to HR.
The service desk lead can change a ticket’s priority. Changing the provisioning schedule needs the platform owner. Changing the signing step needs HR and legal. One level down, a team lead can chase a ticket and cannot change the nightly run it waits for. One level up, the director who could change the schedule and the signing step does not see a new starter waiting. The service desk holds its own weekly review. Ticket ageing is item two. The instruction that comes back from it is to review ticket ageing.
A regulator needs a model of what it regulates. The result predates every one of these meetings, and it sits in Metier beside two things that share an abbreviation and are not the same: viable systems and value streams. Stafford Beer called the first of those the Viable System Model, and built it around the question of how a system stays able to sense, decide and act.
The working group had a model of the service desk, the position it was convened from. The disturbance arrived from two positions its channels did not reach. The September report named unclear ownership of onboarding, a communication gap between IT and HR, and a need for better forecasting of start dates. It recommended a pre-start checklist. The working group reconvenes in March. The nightly run and the signing step are where they were, one level up.
The occupant of the position
What is left is narrower than a claim about the value of human judgement. The comparison between a model and a situation has to happen somewhere, and that somewhere has an occupant. Even the mechanism intended to decide what reaches that occupant has to be held against a situation by an occupant of its own.
By April the new structure was being asked what the old one had been asked: who owns this, why it broke at the handover, why it was found so late, and why nobody had the whole picture.
In 2019 third-party access sat with the security team, which wrote a policy. In 2021 it moved to a vendor risk function under procurement, which built a questionnaire. In 2023 vendor risk was folded into Data and Trust, which commissioned a dashboard. The October reorganisation left it there. The policy, the questionnaire and the dashboard are all current, all owned and all reviewed. Third-party access touches the joiner and leaver process, the contract register, four identity systems, the people who approve exceptions at month end, and whoever happens to notice that an account is still open. The security team held the joiner and leaver process and the identity systems. Vendor risk held the contract register. Data and Trust holds the dashboard. In each of those three years, and again in April, the same thing turned up: a supplier account still open after the contract ended.
The 2021 reorganisation, the one that moved third-party access to vendor risk, also divided resilience. Infrastructure took the platforms, operations took the runbooks, business continuity took the plans. Each of the three tests its part twice a year. The dependency between the payments platform and the notification service has not been tested, because it sits in none of the three parts. In November the payments platform failed over correctly. Nobody could tell customers, because the notification service had gone with it.
Data protection readiness was a programme. It ran for two years, delivered forty-one workstreams and closed in 2019 with a completion report. The record of processing activities the programme produced has not been updated since it closed. Answering the audit committee takes about a fortnight, and starts by asking three teams what they hold. The question it was set up to answer, whether the organisation can say what personal data it holds and why, comes back twice a year and is answered by whoever is free that week.
A fourth reorganisation is scheduled for next year. Third-party access will be given its fourth owner. Reorganisations change who answers the door. They do not change who keeps knocking. Metier has an index built on concern, asking what, where, when, who, how and which. An index by department says where people sit, one by project what they are doing, one by technology what they are using. A concern is what keeps coming back. It is what the occupant of a position holds a policy, a questionnaire or a dashboard against. Under pressure, their stance changes what they can recognise. And when a construction meets the work and does not fit, the resulting gap is not necessarily a failure of the person or the model. It can be the evidence that the position has discovered a distinction it did not previously have. An open supplier account, three years running, is that kind of evidence. Three owners in turn filed it under the instrument they had built.
The organisation did not have an information problem. By November it had a supplier dashboard, a reconciliation tool, an improved retrieval, a certificate by the lift and a pre-start checklist, one remedy per scene. It had no position from which any of them could be held against what was happening. What it lacked was an occupant with the channels to receive the distinction, the stock to recognise it, and the position to act on it.
That makes attention part of the control problem itself, and whoever designs it is inside that problem too. The design of what the machines notice is made from a position, through channels, with a borrowed stock of distinctions, by an observer whose own variety is finite. Each remedy in that year was a design of what the organisation would notice, made by the function that could see its own part.
Data and information are kept apart in Metier, and so is most of what everyday language runs together: rule and procedure, functioning and functionality, viable system and value stream. The distinctions are filed by concern. Holding pairs like those apart is one way of keeping a stock of distinctions that can fail.
The machines can do the doing, and an extraordinary amount of the noticing. A distinction becomes useful only when somebody, somewhere, holds it against a situation.