← Change Manager: risk, authorization, and coordination
09 / 10 · 60 MIN

Decide, recover, and transfer responsibility

Coordinate conditional decisions, recovery alternatives, and effective coverage during RUN handover.

Make the decision request specific

A supplier's technical confirmation may establish availability to install without representing acceptance of customer impact. In a fictional meeting, separate those questions: can the team execute, and who can accept downtime for each affected function? The position-query owner may not represent the team depending on exports. Explain known impact, functions still needing analysis, and the required decision. If the record permits proceeding only after partner confirmation, a sent message does not satisfy that condition. Retain the pending item and route any change in the condition to the applicable authority. A useful note includes the requested decision, scope, evidence, uncertainty, deadline, and consequence of not deciding. This supports international discussion in English without turning Change Manager coordination into unlimited authority. Confirm that participants share the same understanding of what is being accepted.

Protect time for the alternative

At 03:20 UTC, a fictional export remains unconfirmed. The commitment requires validated recovery by 04:00. The estimate has eighteen minutes of recovery followed by eight of validation: the latest start without slack is 03:34. Investigating for another twenty minutes moves the decision to 03:40, six minutes beyond that boundary. Requesting more time requires exposing the alternative that no longer fits. This does not mean automatically rolling back: if the recipient already applied effects, recovery may need reconciliation. Request priority evidence about state and effects, a checkpoint before the boundary, and a decision by responsible owners. Times are exercise estimates without a production guarantee. Recalculate when data or stages change. Do not remove validation to preserve the appearance of meeting the communicated deadline. State which options remain feasible under the assumptions currently available.

Complete handover with observable capability

A window extended until 04:15 does not automatically extend coverage by the team leaving at 03:30. Forty-five minutes remain unresolved. The next shift received slides but has read-only access and has not demonstrated recovery. Record responsibility not yet transferred and agree capable coverage or a revised plan. Google SRE transition guidance supports preparation, training, and progressive transfer; the actual organizational model remains local. Define tasks, required access, temporary support, acceptance, and criteria for completing handover. Attending a session is not equivalent to executing a procedure. An authorized demonstration in an appropriate environment can expose gaps before autonomy. If service stabilizes but an export still needs confirmation, assign accepted follow-up and a checkpoint. Technical closure does not erase this residual work. The receiving team needs enough context to act when the expected outcome does not arrive.

Reproduce calculations and challenge inputs

Save the code below as change-assurance.py and run python3 change-assurance.py. It requires no additional packages. It was executed using CPython 3.13.1 and produces eleven groups of checks. It calculates boundaries and gaps using minutes within one UTC day, distinguishes events from deployments, and compares median with maximum. It performs no timezone conversion, duration-uncertainty modeling, or general input validation. In the handover object, acceptance, access, and demonstration fields are supplied values: the program neither authenticates people nor observes recovery. Change coverage end time and predict the gap before execution. Then change only attendedTraining: the list of missing conditions should remain unchanged. Write a decision note with the calculation and actual evidence still needed. An empty list in the model neither authorizes production nor establishes human competence. Discuss the assumptions separately from the arithmetic result.

"""Original DR arithmetic and evidence exercise, using fictional inputs only."""
from fractions import Fraction
from statistics import median
import hashlib
import json
import platform
from pathlib import Path


def latest_recovery_start(deadline, recovery, validation):
 return deadline - recovery - validation


def uncovered_after(coverage_end, window_end):
 return max(0, window_end - coverage_end)


def handover_gaps(record):
 # Supplied booleans are not authenticated observations or authorization.
 required = ["accepted", "recoveryAccess", "demonstratedRecovery"]
 return [key for key in required if not record.get(key, False)]


def run:
 checks = []

 def check(name, actual, expected):
 if actual!= expected:
 raise AssertionError((name, actual, expected))
 checks.append({"name": name, "actual": actual, "passed": True})

 latest = latest_recovery_start(240, 18, 8)
 check("recovery_start_reserves_validation", latest, 214) # 03:34 UTC
 check("twenty_minute_investigation_loses_six_minutes", 200 + 20 - latest, 6)
 check("twenty_five_minute_investigation_loses_eleven_minutes", 200 + 25 - latest, 11)
 check("handover_extension_exposes_forty_five_minutes", uncovered_after(210, 255), 45)
 check("longer_coverage_does_not_create_negative_gap", uncovered_after(270, 255), 0)
 partial = {"accepted": False, "recoveryAccess": False, "demonstratedRecovery": False, "attendedTraining": True}
 check("attendance_does_not_fill_handover_conditions", handover_gaps(partial),
 ["accepted", "recoveryAccess", "demonstratedRecovery"])
 check("supplied_handover_fields_only", handover_gaps({key: True for key in partial}), [])
 events = [{"deployment": f"D{i:02}", "state": state}
 for i in range(1, 51) for state in ["start", "technical-completion", "validation"]]
 deployments = {event["deployment"] for event in events}
 check("three_events_are_not_three_deployments", {"events": len(events), "deployments": len(deployments)},
 {"events": 150, "deployments": 50})
 check("rework_and_failure_numerators_remain_distinct",
 {"rework": str(Fraction(5, len(deployments))), "failure": str(Fraction(2, len(deployments)))},
 {"rework": "1/10", "failure": "1/25"})
 waits = [2, 2, 3, 3, 40]
 check("median_does_not_exclude_long_wait", {"medianHours": median(waits), "maximumHours": max(waits)},
 {"medianHours": 3, "maximumHours": 40})
 monthly_event_day, observed_until_day = 30, 20
 check("declared_monthly_event_is_outside_observation", monthly_event_day > observed_until_day, True)
 return {"scope": "Fictional same-day UTC arithmetic, supplied handover fields and synthetic metric events only. No identity, authority, actual access, recovery, service dependencies or human competence is verified. Empty gaps prove only supplied model fields. Estimates do not guarantee production completion.",
 "python": platform.python_version, "scriptSha256": hashlib.sha256(Path(__file__).read_bytes).hexdigest,
 "groups": len(checks), "checks": checks}


if __name__ == "__main__":
 print(json.dumps(run, ensure_ascii=False, indent=2))
IN PRACTICE

“Recovery needs 26 minutes including validation. Waiting until 03:40 would exceed the 03:34 boundary. We need a decision or an accepted alternative before that point.”

Common pitfalls

Technical confirmation treated as business acceptance; extending investigation without showing lost alternatives; attendance treated as capability; shift change without acceptance.

Related topics: Decision mandate · Recovery and reconciliation · RUN autonomy

Take this idea with you

Completed handover needs accepted ownership and capability appropriate to the work remaining.

Create account

Reference: The Evolving SRE Engagement Model · NIST SP 800-128 updated October 2019; DORA five-metric model and change approval guidance; vendor documentation inspected 2026-10-01