Analysis tools / Defending the answer
Governance analysis
“Who decides this, and who has to be told?”
Ask a programme who signs off a particular decision and you will often get three different answers and a pause. Governance is usually documented somewhere, but it is documented as an organisation chart, and an organisation chart tells you who reports to whom rather than who decides what.
The discipline
Useful governance answers three questions for every decision that matters. Who is accountable, meaning exactly one name, because accountability shared is accountability absent. Who is responsible for doing the work, who must be consulted before, and who must be informed after. And what happens when it goes wrong, which is the escalation path and the thing most often left undefined until it is needed at speed.
The RACI frame is old and slightly unloved, and it remains the most reliable way to expose the two failure modes that actually hurt: a decision with nobody accountable, and a decision with three people who each think they are.
How SOSX runs it
Because the network already models actors as first-class nodes alongside the systems, governance is read out of the model rather than assembled separately. SOSX can auto-generate the RACI matrix, document the approval chains, or produce a full governance map covering both.
Every assignment comes with its rationale, which is the part that makes the output reviewable. A matrix somebody can argue with is worth more than one they have to accept, and the arguments it provokes are usually the point of running it.
What you get
A report carrying the summary, the RACI matrix, the approval chains, the rationale for each assignment, the assumptions and method, and an interpretation. It exports to PDF or Word. It pairs directly with the compliance analysis, which scores SOSX's own audit evidence for the network against the governance frameworks SOSX aligns with.
The others in this group
Someone will ask how you know. These are the analyses that answer them.
Risk register
“What could go wrong, and how badly?”
Severity, occurrence and detection in the FMEA style, scored before and after the mitigations you propose.
SWOT
“Where are we strong, and where are we exposed?”
The familiar four quadrants, but built out of the model's loops and confidence levels rather than a workshop's memory.
Compliance analysis
“What does the audit trail show, framework by framework?”
SOSX's own audit evidence for a network, scored control by control against the governance frameworks it aligns with. Alignment, not certification.
Network quality critique
“How much should we trust this model?”
Centrality, single points of failure, orphans and coverage gaps, scored, with the fixes ranked by what they buy you.
Or see all the analysis tools. If you would rather we built the model and ran them for you, that is our system research, build and analysis service.