Decisioning Tools

Frameworks I use to evaluate, prioritize & decide

When every project claims to be a priority, the Effort/Reward matrix cuts through the noise. Score each candidate initiative on two axes — effort (cost, time, complexity, risk) and reward (savings, revenue, risk reduction, strategic value) — and plot it. Where it lands tells you what to do with it:

  • Quick Wins (high reward, low effort) — do these first. They build momentum and fund credibility for bigger bets.
  • Major Projects (high reward, high effort) — worth doing, but plan them properly: phased roadmaps, executive sponsorship, and clear milestones.
  • Fill-Ins (low reward, low effort) — do them when capacity allows; never let them crowd out the top half.
  • Money Pits (low reward, high effort) — decline or defer. Saying no here is where prioritization earns its keep.

I've used this with stakeholders to sequence everything from datacenter exits to platform roadmap investments — it turns "everything is urgent" conversations into a shared, visual decision.

Reward
Quick WinsDo first
Major ProjectsPlan & invest
Fill-InsWhen capacity allows
Money PitsAvoid
Effort
LowHigh

ITIL gives technology operations a common language and a connected set of processes — so incidents don't just get fixed, they feed permanent improvement. The flow I've run teams on:

  • Incident Management — restore service fast. Every incident is matched against known errors and existing solutions before reinventing the fix.
  • Problem Management — find the root cause behind recurring incidents and log it as a defect / known error so the same fire never gets fought twice.
  • Change Management & Approvals — fixes and improvements enter production through controlled, approved changes — protecting stability while still moving fast.
  • Asset Management & CMDB — the backbone. Knowing exactly what you have and how it connects is what made sequencing 12,000+ server migrations possible.

Service Level Management wraps around all of it, tying every process back to what the business was promised. I've applied this running payment platform operations at Wells Fargo and in building WGU's disaster recovery and platform reliability programs.

Service Level Management Service Request Management Incident Management Problem Management Defect Known Error Change Management Approvals Solution Asset Management CMDB

A Cloud Center of Excellence (CCOE) is how an organization moves to the cloud deliberately instead of accidentally — a cross-functional framework that puts standards, guardrails, and shared expertise around every workload. I developed CCOE frameworks for clients as a cloud architect, organized around nine pillars that all serve the company at the center: its customers, team members, vendors, and government obligations.

Company

Customers · Team Members · Vendors · Government

Cost Optimization

  • Financial management
  • Licensing
  • AWS Budgets
  • Cost & usage reports

Information Security

  • Cybersecurity & intrusion prevention
  • Patching
  • Zero trust architecture
  • Encryption & IAM
  • Fraud detection

Reliability

  • High availability
  • Scalability
  • Business continuity (BCP)
  • Backups
  • Logging (Splunk)

Operational Excellence

  • Ops as code
  • CloudWatch
  • ITIL
  • SecDevOps

Agility

  • IaC templates
  • App code deployment
  • Environment framework
  • Cloud migration
  • Current-environment KPIs

Risk Management & Auditing

  • Artifacts
  • Regulatory compliance
  • Control frameworks

Data

  • ERP & BI
  • Big data (Hadoop)
  • AI / ML
  • Archiving & caching
  • ETL

App Digital Transformation

  • Microservices & containerization
  • Container orchestration
  • MQ / data bus / streaming
  • FaaS / serverless & EDA
  • APIs

Workforce Management

  • VPN & email
  • Office tools
  • Document management
  • Teams / Slack

The risk assessment matrix turns gut-feel risk conversations into a shared picture. Score every identified risk on likelihood (rare to almost certain) and impact (negligible to severe); the product places it in one of four bands:

  • Extreme (16–25) — stop-the-line risks. Escalate to leadership; work doesn't proceed without a mitigation plan.
  • High (10–15) — actively mitigate with named owners and dates; review at every program checkpoint.
  • Medium (5–9) — mitigate where economical; monitor for movement.
  • Low (1–4) — accept and note. Not every risk deserves budget.

In datacenter migrations, every application cutover got scored this way — it's what let us defend sequencing decisions to risk partners and auditors with a straight face.

NegligibleMinorModerateMajorSevere
Almost Certain510152025
Likely48121620
Possible3691215
Unlikely246810
Rare12345

Likelihood (rows) × Impact (columns) = risk score

The matrix scores risks; the register manages them. It's the living log of every identified risk — its score, its response strategy (mitigate, transfer, accept, or avoid), who owns it, and where it stands. Reviewed on a cadence, it keeps risk from being a one-time workshop and turns it into an operating discipline. A representative sample from a migration program:

IDRiskLikelihoodImpactScoreResponseStatus
R-01 Tier-1 application has no vendor support on target platform LikelyMajor 16 · Extreme Mitigate — containerize, full regression test, vendor engagement before wave assignment Mitigating
R-02 Network cutover has a single point of failure PossibleMajor 12 · High Mitigate — redundant links, tested rollback plan, cutover in low-traffic window Open
R-03 Cloud spend exceeds business case after migration PossibleModerate 9 · Medium Mitigate — FinOps budgets, alerts, and monthly cost & usage reviews Monitoring
R-04 Restore procedure untested for Tier-1 database UnlikelySevere 10 · Medium Mitigate — quarterly DR restore tests with documented RTO/RPO results Closed
R-05 Legacy reporting tool loses one nightly batch feature LikelyNegligible 4 · Low Accept — documented with business sign-off Accepted

SWOT is the fastest way to pressure-test a strategy, product, or major investment: two internal lenses (what we control) and two external ones (what the market controls). The discipline is in the pairing — a strategy is only as good as how its strengths address threats and its weaknesses block opportunities. Example below: evaluating a move from a self-managed datacenter to a cloud platform.

Helpful
Harmful
Internal

Strengths

  • Deep in-house infrastructure and migration expertise
  • Well-documented application portfolio (CMDB)
  • Executive sponsorship and funded business case

Weaknesses

  • Limited cloud-native skills on current team
  • Legacy apps with hard-coded dependencies
  • Immature FinOps practice — cost visibility gaps
External

Opportunities

  • Exit datacenter leases — step-change cost reduction
  • Elastic capacity unlocks faster product delivery
  • Managed AI/ML services enable new capabilities

Threats

  • Vendor lock-in and cloud price increases
  • Evolving regulatory and data-residency demands
  • Competitors already operating cloud-native

When the roadmap has more good ideas than capacity, RICE replaces the loudest-voice-wins meeting with arithmetic. Score each initiative on Reach (how many users/events per quarter), Impact (0.25 = minimal, 1 = medium, 2 = high, 3 = massive), Confidence (how sure are you about those estimates), and Effort (person-months) — then rank by the result.

RICE = (Reach × Impact × Confidence) ÷ Effort

InitiativeReachImpactConfidenceEffortRICE Score
Modernize platform status dashboard 500 / qtr1100%2 pm250
AI agent for CI/CD troubleshooting 400 / qtr280%3 pm213
Self-service environment provisioning 250 / qtr370%5 pm105
Replace legacy job scheduler 60 / qtr290%4 pm27

The value isn't the decimal precision — it's that every assumption (reach, impact, confidence) is now written down and debatable.

For choosing between options — platforms, vendors, architectures — a weighted decision matrix forces two honest conversations: what actually matters (the weights) and how each option really performs (the scores, 1–5). Multiply and sum; the discussion shifts from opinions about options to evidence per criterion. Example: selecting a container platform.

CriterionWeightAWS EKSECS FargateSelf-Managed K8s
Cost efficiency25%344
Security & compliance25%443
Scalability & flexibility20%534
Team skills fit15%342
Portability / lock-in risk15%435
Weighted total3.803.653.60

Set the weights with stakeholders before scoring options — otherwise weights get reverse-engineered to justify a favorite.

Sticker price is never the price. TCO compares options across their full lifecycle — typically 3–5 years — including the costs that hide in facilities, labor, refresh cycles, and one-time migration work. It's the backbone of every credible infrastructure business case. Illustrative 5-year comparison for a datacenter-to-cloud move:

Cost Category (5-year)On-PremisesCloud
Hardware purchase & refresh$4.5M
Facilities — power, cooling, space$2.8M
Software licensing$2.4M$1.6M
Operations labor$4.5M$2.9M
Cloud services — compute, storage, network$4.1M
Migration (one-time)$1.2M
Total 5-year TCO$14.2M$9.8M

Pair with sensitivity analysis (growth rates, egress, reserved-instance discounts) — TCO models are only as honest as their assumptions. This discipline underpinned business cases behind $114M in annual savings.

TOGAF's ADM is the discipline behind sound architecture decisions: a repeatable cycle that moves from vision to business, information systems, and technology architectures — then into planning, governed implementation, and managed change. Two things make it powerful in practice:

  • Requirements sit at the center — every phase checks back against what the business actually needs, so architecture never drifts into art for its own sake.
  • It's a cycle, not a project — Phase H feeds the next iteration, which is how architecture keeps pace with change instead of becoming shelfware.
  • Governance is built in — Phase G ensures what gets built matches what was designed, closing the gap where most architecture efforts fail.

I used this structure for enterprise architecture planning and cloud migration assessments — Phases E and F (opportunities, solutions, and migration planning) are where datacenter exit sequencing and wave planning live.

Preliminary Requirements Management A Architecture Vision B Business Architecture C Info Systems Architectures D Technology Architecture E Opportunities & Solutions F Migration Planning G Implementation Governance H Change Management