Analysis tools / Defending the answer
SWOT
“Where are we strong, and where are we exposed?”
SWOT has a poor reputation, and mostly it has earned it. Run as a whiteboard exercise it produces four lists of adjectives that everyone agrees with and nobody acts on. Run against an actual model of the system, it becomes something else: a structured read of where the thing is solid and where it is exposed.
The discipline
The frame is fine. The problem is the evidence. A strength should be something you can point at, not something the room believes. A weakness should be a place where the evidence runs out, which is a fact about your knowledge rather than an opinion about your organisation. An opportunity should be a point where a small intervention has outsized effect. A threat should be a dependency you cannot control.
Read that way, the four quadrants stop being personality traits and start being properties of a system.
How SOSX runs it
SOSX derives each quadrant from the model. Strengths come from well-established feedback loops, high-confidence nodes and validated connections. Weaknesses come from high-uncertainty areas, coverage gaps and low-confidence elements, which is to say the analysis will tell you where your own model is thin. Opportunities come from leverage points, unexplored connections and emerging patterns. Threats come from critical dependencies, single points of failure and the risk of cascade.
You choose the depth, from a shallow pass to a deep one, and run it across the whole network or focused on a domain, a set of nodes or a theme you describe in your own words. Each run gets its own session folder, so a SWOT from three months ago is still there to compare against.
What you get
A strategic report with the four quadrants, each item traced back to what in the network produced it, plus recommendations. It exports to PDF or Word. The most useful part, in practice, is the weaknesses quadrant: it is the only version of this exercise that reliably tells you what you do not yet know.
The others in this group
Someone will ask how you know. These are the analyses that answer them.
Risk register
“What could go wrong, and how badly?”
Severity, occurrence and detection in the FMEA style, scored before and after the mitigations you propose.
Governance analysis
“Who decides this, and who has to be told?”
Decision rights, accountability and escalation paths, as a RACI matrix and the approval chains behind it.
Compliance analysis
“What does the audit trail show, framework by framework?”
SOSX's own audit evidence for a network, scored control by control against the governance frameworks it aligns with. Alignment, not certification.
Network quality critique
“How much should we trust this model?”
Centrality, single points of failure, orphans and coverage gaps, scored, with the fixes ranked by what they buy you.
Or see all the analysis tools. If you would rather we built the model and ran them for you, that is our system research, build and analysis service.