The decision system for material enterprise change.
Approve with defensible confidence.
Material enterprise change crosses boundaries no single function sees across. boardlevel gives the accountable change authority one evidenced assessment of impact, unknowns, knowledge holders and residual risk.
People, not software, hold change authority. boardlevel supports their mandate, approval and risk acceptance.
Source-backed does not mean certain. Missing, stale and conflicting knowledge stays visible, not replaced by a fluent explanation.
The executive problem
The most material changes. The most fragmented assessment.
- 01
Executive decisions connect strategy, processes and people with applications, data, integrations, infrastructure, networks, security, suppliers and physical sites.
- 02
CAB, architecture, security, risk, legal/privacy, procurement, facilities, project governance and business owners use separate tools, records and approval forums.
- 03
Stale diagrams, repositories, tickets, documents and key individuals hold the links. No single view reliably shows the whole.
- 04
Impact is assessed in parts; accountability diffuses. After failure, what was known, missing or inferred (and who accepted the remaining risk) can be hard to establish.
The intended boardlevel model
One living enterprise relationship model.
Intended model. Illustrative layers, not observed proof.
- Strategy and capabilities
- Processes
- People and rolesunknown
- Applications
- Integrations and data
- Cloud and on-prem infrastructure
- Networksunknown
- Security controls and trust boundaries
- Suppliers
- Sites and buildingsunknown
An enterprise context graph connects strategy and business capabilities, processes/operational dependencies, people, teams, roles and ownership, applications, integrations and data, cloud/on-prem infrastructure, networks, security controls and trust boundaries, suppliers/outsourced dependencies and physical sites/buildings. Executive and enterprise, application, cloud, network and security architecture views share this source-backed model, not static diagrams.
Proposal
Edit the proposal as the sponsor would submit it. It is yours to change.
Impact Map
Technical and organisational blast radius, unknowns, knowledge holders, stakeholder communications and readiness. AI assists extraction, reconciliation, relationship proposals, impact reasoning and visualisation; observed, supplied, inferred and verified relationships stay distinct until validated.
Trace
Provenance, freshness, versions, evidence, actions, permissions and independent verification history, not an agent’s self-explanation.
The Boardroom
Independent assessment, challenge and specialist escalation. Dissent stays visible.
Challenges
Deliberation keeps objections on the record. Corrections and changed evidence trigger mandatory re-review. Recurring defects remain inspectable.
Mainboard
Authorised goal, scope, mandate and decision rights. Reviews bind to a version; drift invalidates authority.
Resolution
Final decision, conditions, explicit residual-risk acceptance and accountable approver, linked to Trace.
Separation of duties
Six roles, never one hand.
Submits the change and its intended benefit. Cannot assess or approve it.
Red Team and domain roles contest assumptions. Dissent is preserved, not merged.
Classifies impact and checks what the goal, scope and policy actually permit.
A named human approves the reviewed version or returns it for correction.
Acts only within current authority and verified pre-start controls. A2 cannot execute.
Separately records verifier, source and result. A condition owner cannot verify their own control.
Autonomy ladder
Five levels, one rule: capability is not authority.
Policy sets the ceiling per class of change. The sample decision is high-impact, so it stops at A2.
A1AI gathers, summarises and drafts. A human decides everything and does the work.
A2AI proposes a course of action with rationale. A human decides and acts.
A3Capability: carry out a change. Authority: a named human must approve that specific version, scope and action.
A4Capability: execute routine actions. Authority: prior human policy delegation for defined low-risk actions, limits, logging and rollback, not a new approval for each action.
A5Capability: adapt actions. Authority: stay within a human-owned policy envelope; outside it, stop and seek specific approval. Humans remain accountable.
Policy restriction: material, hard-to-reverse changes affecting all employees cannot be executed by AI. A3 applies only after a specific human approval exists, and even then not to this proposal at this scope.
Policy restriction: A4 is reserved for low-risk, pre-approved change types. This is a high-impact, first-of-kind proposal, so it does not qualify.
Policy restriction: A5 requires a mature policy envelope and a track record. None exists for this change. Selecting it does not bypass the human gate.
Capability is not authority. Every level operates within permissions a named human has granted.
Governance principles
Six commitments the product is built to keep.
What an agent can do is not what it may do. Permission comes from policy and a named human.
An agent’s explanation is a claim to inspect, not proof that its account is accurate.
Requested benefit and authorised goal are distinct. Source, owner and version stay attached.
Missing or unverified sources constrain confidence. A fluent answer cannot fill a gap.
Conditions need separate verification against recorded results, not just an owner’s assurance.
What changed, why and with what evidence remains visible when the proposal returns.
Resolution / sample decision record
A record structured for scrutiny.
Read the fields, not just the conclusion: identity, reviewed scope, dissent, conditions and limits. Trace supplies the checkable support. This excerpt is fictional; pricing is hypothetical.
CDR-DEMO-0001
Deploy Microsoft 365 Copilot enterprise-wide
Record structure
A decision is more than its rationale.
Reviewed proposal → named decision → verified conditions. This baseline excerpt has no human approval.
- Scope
- Requested: 12,400 users in a single wave. Recommended: about 4.8% of seats, HR, legal and M&A excluded.
- Evidence
- E1 to E7. Output-quality testing (E7) does not yet exist. Permissions scan covered 1.3% of sites.
- Assumptions
- Hypothetical price of AUD 30 per user per month; benefit from opt-in survey only.
- Unresolved dissent
- CISO, CFO, Legal/Privacy and Red Team, preserved verbatim.
- Conditions and limits
- C1 to C6, each with an owner. None verified. AI limited to recommend-only; pilot scope only.
- Identity and version
- Proposal v1; approver not yet recorded. A later edit cannot inherit approval.
boardlevel and the CAB
Complements the change advisory board.
boardlevel complements existing change governance with a source-backed picture of material organisational impact, independent challenge and accountable decision records. It does not replace your CAB.
The intended architecture reads and reconciles (not replaces) CMDBs, architecture repositories, cloud inventories, identity/security platforms, network sources, HR/organisation data, facilities/site registers, risk/legal records, procurement/supplier data and project/change systems. Source-backed, change-specific views support the Executive Change Board. This mockup connects to none of them.
Connect existing systems. Preserve decision rights.
- CMDB
- Architecture repository
- Cloud inventory
- Identity and security
- Network
- HR and organisation
- Facilities and sites
- Risk and legal
- Procurement and suppliers
- Project and change
Design partners
Bring one material decision to The Boardroom.
We are looking for design partners with a live decision and the appetite to document how it was made. Draft a brief to share with your sponsor. It stays on your device.
