← Thinking

The Broken Laptop Clause

Your organisation has a guaranteed response time for a broken laptop and none for a broken business model. The most disciplined response machinery in the enterprise lives at the bottom of the building, and the principle it runs on has never once climbed the stairs.

A server room at night, where the fifteen minute clock is always armed

Somewhere in your organisation there is a contract that guarantees what happens when a laptop breaks. It names a severity. It starts a clock. If a server dies at three in the morning, a fifteen minute countdown begins and a specific person’s phone makes a specific noise. The response is owned, timed, escalated before breach, and graded afterwards.

Now go looking for the clause that covers a broken business model. A competitor quietly rewriting your category. A regulation redrawing your margins. A customer behaviour that stopped meaning what your strategy assumes it means.

There is no clause. There is no severity rating, so no clock ever starts. The signal arrives, and instead of a P1, it gets a steering committee.

I have spent most of my career one floor below the strategy discussion, in the rooms where the laptop clause is enforced. What follows is an attempt to explain something that took me twenty years to see clearly: the most disciplined response machinery in the modern enterprise lives at the bottom of the building, and the principle it runs on has never once climbed the stairs.

The import that built the machine

Here is the part IT people know and strategy people mostly do not. IT did not fix its delivery problem with an IT idea.

Through the nineties and two thousands, enterprise IT was a byword for late, over budget and broken. The fix came from a car factory. Flow, batch size, work in progress limits, constraint management: the Toyota ideas that Goldratt had already translated for manufacturing in The Goal were translated again for technology, most famously in The Phoenix Project, which is The Goal rewritten with servers. It became the most successful cross pollination artefact in modern management, and it rebuilt how software reaches production.

Look closely at what actually got imported. Not a framework. Not a reference architecture. Not a maturity model. A set of clocks. Lead time. Cycle time. Time to restore. Deployment frequency. The metrics that came to define delivery performance are four measurements, and three of them are durations.

The transfer succeeded because what transferred was a way of timing work, not a way of describing it.

What an SLA actually is

The service level agreement gets dismissed as bureaucracy by people who have never watched one operate. It is not a promise. It is a machine with five parts.

A severity taxonomy: this event is a P1, that one is a P3, and the classification is decided in advance, not negotiated during the incident. A clock per severity, and the clock starts at detection, not at convenience. A named owner per clock: one person, not a committee. An escalation path that fires before the breach, not after it. And a review loop that grades the response afterwards, so the next response starts from what the last one learned.

Five parts, one effect: the enterprise, through its IT function, contractually guarantees response times. Modern operations tooling is just the newest compression of the same machine, shrinking detection to seconds and sometimes remediating without a human. The machine is so normal that nobody inside it considers it remarkable.

One floor up, none of it exists.

Four reasons the principle never climbed

It is tempting to call this neglect and move on. The truth is more interesting. There are four specific reasons the response clock never walked upstairs, and each one says something about how enterprises are actually wired.

The market never files a breach claim. An SLA exists where a counterparty can invoke a breach. IT’s customers hold contracts with penalties. Strategy’s counterparty is the market, and the market does not send a breach notice. It just leaves. The notice arrives eighteen months later as a revenue line, unattributed, long after anyone could connect it to the signal that went unanswered. A clock with no one to enforce it never gets built.

No severity category exists for a rewritten category. Severity classification requires the event type to exist in advance. And here is the proof that the ladder is unclimbed rather than unclimbable: wherever something forced a category into existence, the clock appeared. Cyber breach notification is regulated to seventy two hours, and enterprises found a way to run that clock within a budget cycle of the regulation landing. Crisis communications has clocks. Safety has clocks. A competitor rewriting your business model has no severity rating, so the event arrives unclassified, and unclassified events do not start countdowns.

The socket arrived late. IT could run response clocks decades ago because its events were born timestamped. Every ticket, every alert, every deployment carries the moment of its own creation. The strategic layer only recently became readable in the same way, as the systems of record that could timestamp a market signal became connected enough to ask. The upward transfer was not only neglected. It was early.

Nobody owns the clock. A clock needs one named owner, and strategic response crosses every silo in the building. Sales sees the signal, product owns the answer, finance owns the funding, operations owns the delivery. In most organisations that intersection reports to nobody, which means the clock, if it existed, would ring in an empty room.

The honest caveat

There is a real objection to all of this, and it deserves to be stated plainly rather than managed.

A P1 incident has an unambiguous detection moment and an unambiguous resolution state. The server is down; the server is back. A strategic signal has neither by default. When did the change become knowable? What counts as the response being complete? Those are not administrative details. Deciding where the clock starts and what stops it is real intellectual work, and it is the reason the upward transfer is genuinely harder than the sideways one, not just less fashionable.

But notice what kind of objection that is. It is not an argument that the clock cannot exist. It is a description of the work required to build one. The seventy two hour breach clock faced the same objection once: what counts as a breach, and when did you know? Regulation forced the definitions, and the definitions turned out to be buildable.

That work is what my own research and practice has gone into: defining where the strategic clock starts, what counts as response complete, and measuring the distance between them from the enterprise’s own systems of record. I call that distance the Signal-Response Distance. An SLA is what the strategic layer gets when someone does that work. Severity taxonomy, clock, owner, escalation before the window closes, graded review: incident management for strategy.

The clause that is coming

The pattern of the last import suggests the shape of the next one. The Toyota ideas sat in manufacturing for forty years while IT burned money, and the transfer happened only when the pain got a budget line and the events got timestamps. Both conditions are now arriving one floor up. AI has made the world’s signals cheaper to detect than ever, which makes the undetected response gap more visible, and more expensive, every quarter.

Your organisation has a guaranteed response time for a broken laptop and none for a broken business model. That sentence will sound absurd to someone reading it in fifteen years, the way an unmeasured deployment pipeline sounds absurd now.

Nobody has written strategy’s Phoenix Project yet. The machine it would describe is already overdue.

© 2026 AJ Olivier Escape velocity for enterprise transformation