PSOF v1.0
Approach
Observe everything. Authorize deliberately. Automate safely. Prove outcomes.
Controlled operational outcomes — not certification theater, not unbounded AI in production.
Operating principles
Business service first
Every system maps to a service, owner, and value metric.
Evidence over assertion
A control exists only when evidence shows it works and has an owner.
Least authority
Minimum access for the approved action and period.
Observability before autonomy
Visible and recoverable — then AI action authority.
Reversible by default
Staged writes, canaries, backups, defined rollback.
Human accountability
AI may act within policy; a named human remains accountable.
One operational truth
Services, incidents, changes, and controls share canonical records.
Continuity is proven
Restore tests prove recovery. Backups alone do not.
Maturity model
You cannot skip to agentic autonomy because a demo works. Each level requires proof of the levels below.
Unknown
Undocumented systems and owners
Visible
Critical services, assets, owners identified
Controlled
Access, change, backup, security controls in use
Reliable
SLOs, monitoring, tested recovery
Predictive
Correlation, proactive cost and problem management
Governed autonomous
Bounded agents with eval, audit, kill switch
Delivery lifecycle
Speed
T0 in minutes. A1 fixed price. B packages with acceptance.
Safety
Observability first. Authority classes. Kill switches. Human accountability.
Scale
Same spine from one workflow to multi-service. Labs productizes proven installs.
- No production write access before design and change gates.
- No autonomous production action before maturity and authority-class gates.
- No managed transition without docs, boundaries, and billing authorization.