Cambium · a working model

A metamodel of organizational flow

This is the model I am iterating on — a working theory of organizational flow, not a finished standard. It changes as I use it and learn from it, day by day. What follows is where it stands today.

Christoffer Råsten · TROi

What an organization can do, who is arranged against that today, what it runs on — and how it decides, who may act without asking, and what anybody has gone and measured. Twenty-two entities, 33 relations, and one loop that closes: from a capability, through the people and agents who hold the competence to perform it, through the work and what it teaches, back to a changed capability.

Structure

Three bands, read by how long they last. Every relation carries its multiplicity at both ends, in amber. The heavier lines are the spine: a capability speaks its contexts, and competence — held by a person or an agent — is what makes it theirs to perform.

DURABLE · SURVIVES THE REORGANIZATION ARRANGED · THIS YEAR’S ANSWER REALIZED · WHAT IT RUNS ON nests under 0..* : 0..1 speaks 1..* 1..* masters 1 0..* delivered through 0..* 1..* passes through 0..* 1..* operates in 0..* 1 is responsible for · owns · builds · uses 1 0..* works in 0..* 1..* holds 1..* 0..* staffs 1..* 1..* performs 0..* 0..* 1 person accountable for 0..* agents holds up 0..* 0..* realizes 1..* 1..* exposes 1 0..* carries 0..* 1..* runs on 0..* 1..* built with 0..* 0..* Offering audience · stage Legal entity country · form Flow value · returns to Capability core / supporting / generic Bounded context one meaning per word Information object a reading per context Decision gate authority · cadence Competence what somebody can do Actor person · agent · team Organizational unit mandate Technology ring · suited to System vendor · CIA · exit Interface pattern · queue · fields Infrastructure region · environment
A capability speaks one or more bounded contexts, and a context is spoken by one or more capabilities; the translation between two contexts lives inside the capability that speaks both. Competence staffs capabilities and is held by actors — people, agents and agent teams alike — which is how a capability comes to belong to whoever performs it, while responsibility stays with the organizational unit and accountability with one named person.

The loop, closed

The movement band is not a list of records beside the structure. It is what turns the structure round: every step hands to the next, and the last changes the first. The actor sits in the middle because it is in almost every hop.

staffed by held under acted on measured by where it sticks, raises answered as produces changes, and back to the start ↺ holds works under does raises decides H1 H3 H5 H6 H7 Review H8 Memory · Evals → policy H2 · H4 Fail safely 1 Capability must be performable 2 Competence held by a person or an agent 3 Guideline in force: act · prepare · ask 4 Activity the work actually done 5 Observation delivery + four indicators 6 Ask no rule reaches, or friction 7 Decision by an actor · a person answers 8 Agreement signed by the parties Actor person · agent · agent team Assessment bounds what may be automated Override a rule broken, with a why
Where a signed guideline reaches, the actor acts; where judgement remains, it prepares and stops; where nothing reaches, it asks. An answered ask becomes a decision — made by whichever actor may make it, a person or an agent the rules have delegated it to, and always answered for by one named person — the decision produces a rule the parties sign, and the rule changes what is staffed, owned and in force — so the next time round, the same actor may act. Autonomy is never set. Assessment bounds what may be automated at all; an override enters at the decision, because breaking a rule on purpose is itself something one person has to answer for.
  1. 1Capability

    Something the organization must be able to do.

    staffed by →
  2. 2Competence

    Held by a person or an agent, which is what makes the capability theirs to perform.

    held under →
  3. 3Guideline

    The rules in force where the actor works decide: act, prepare, or ask.

    acted on →
  4. 4Activity

    Commits, deploys, runs, incidents — what was actually done.

    measured by →
  5. 5Observation

    Delivery and the four indicators, read from the work.

    where it sticks, raises →
  6. 6Ask

    No rule reaches, or friction shows. Routed by mandate to the accountable person.

    answered as →
  7. 7Decision

    An actor chooses — a person, or an agent where a guideline delegates it — and one named person answers for it.

    produces →
  8. 8Agreement

    Signed by the parties. New rules, new meanings, a new owner, a competence needed.

    changes, and back to the start ↺ 1

The loop, run once: the work harness

The organization is the work harness — for people and agents alike. People and agents need the same thing: context, boundaries, authority and feedback to act with confidence.

The purpose of the work harness is to reduce the cost of navigating the organization — for people and agents alike.

So the question is not how much context can we give the agent? It is: how little context does someone need to make a good decision?

We build processes, governance, handoffs, coordination, meetings and controls to help people work. In the end the organization spends a significant share of its capacity navigating itself instead of creating value. AI only makes that cost much easier to see:

Humanextra handoff → meeting → waiting → question → coordination

Agentextra handoff → context → tool call → reasoning → tokens

Suddenly organizational friction almost has a meter. That is the other side of a work harness for people and agents: the point is not to build more harness.

People and agents do not need two organization models. Both need the same surrounding structure to act; the difference is in how each consumes it, not in what the organization has to define.

Both needStage · entityA personAn agent
A clear outcomeH1 · Capabilityknows what the work is for, and can argue with itis judged against it on every task
The right context and informationH3 · Competence · meaningslearns it, asks, and remembershas it only if it is handed over before the task
Clear boundariesH5 · Guideline · Assessmentmay go around a rule, and says whystops where a rule says so
Decision rightsH5 · Review · Mandate · Decision · Askdecides within the team’s mandate and escalates beyond itdecides only where a guideline delegates it — a person still answers
The right tools and capabilitiesH6 · System · Interfaceuses what the team can change, or asks for itcalls only what it may, through an interface somebody owns
Feedback on what actually happenedH7 · Evals · Activity · Observation · Agreementsees the heartbeat and the rings, and changes how the work is doneis changed by the rules the answers become

A work harness takes one task — by a person or an agent — from intent to a verified outcome. It is the inner loop: one actor, one task, fast. The loop above is the outer one: the whole organization, slowly changing what the harness reads next time. The tags in the figure mark where they meet.

Harness stageDoesEntityWhat
H1 intentreadsCapabilitythe outcome the task serves
H2 identityreadsActorwho acts, in which team, and the person who answers
H3 contextreadsCompetencewhat the actor can do, and what words mean where it works
H4 planreadsActorhow much the actor already carries, and who works beside it
H5 policyreadsGuidelineact, prepare or ask
H6 toolswritesActivitythe work actually done, by whom and with which agent
H7 verifywritesObservationwhat the result says about delivery and the four indicators
H8 outcomewritesDecisionwhat was chosen, and the person who answers for it
Review reviewwritesAskthe question no rule answers, routed by mandate
Fail safely failsafewritesOverridethe rule gone around, and why
Memory memoryreadsAgreementwhat the organization has already settled
Evals → policy observewritesAgreementthe policy update: a rule the parties sign

6 stages read the model and 6 write to it. Planning and routing a task is the runtime’s own job and has no entity; everything else the harness has to ask, the model answers — and what the harness writes back is how the model learns. A person is not stopped at the policy gate: they decide, and an override records why.

The entities

Grouped by how long they last, each with the question it lets the model answer and the relations it starts.

DurableStill true after replacing every system and reorganizing every team.
Legal entitycountry · form · parent
The company that signs things, and a boundary no mandate crosses. A decision binding one entity does not bind another.
Capabilityoutcome · core | supporting | generic · four levels
Something the organization is able to do. The classification makes every finding readable: neglect in a core capability is the advantage going, in a generic one it is something that should have been bought.0..* nests under 0..1 Capability1..* speaks 1..* Bounded context
Bounded contextowner · classification
The boundary inside which a word means one thing. A capability speaks one or more of them, and the translation between two lives inside the capability. It outlives the team that speaks it.1 masters 0..* Information object
Information objectagreed · a reading per context
A business concept, and what each context calls it and takes it to mean. Two teams can hold identical definitions and still misunderstand each other.
Offeringkind · audience · stage
What the organization actually hands somebody. Everything else is an input, and an organization can have its inputs in order and still not say what it delivers.0..* is delivered through 1..* Capability
Flowsteps · value per month · returns to
A piece of work end to end, through the capabilities it passes. Where it returns to is nullable, and null is the finding.0..* passes through 1..* Capability
ArrangedTrue this year. Expected to change, and the model expects it.
Organizational unitmandate: business · technical · spend
A team, and what it may settle without asking. Mandate decides whether work moves or travels, and it is never visible on an org chart.0..* operates in 1 Legal entity1 is responsible for 0..* Capability
Actorperson | agent | agent team · runs on · accountable to
Whoever does the work, which no longer means a person. An agent cannot sign, and answers to one named human: responsibility divides between people, accountability does not.0..* works in 1..* Organizational unit1..* holds 0..* Competence0..* performs 0..* Capability1 is accountable for 0..* Actor0..* amplifies 0..* Actor
Competenceheld by · staffs
What a person or an agent can do. Competence staffs a capability, and holding it is what makes the capability an actor's to perform. The capability belongs to the organization; the competence belongs to whoever holds it — people resign, agents get switched off.1..* staffs 1..* Capability
Decision gateauthority · cadence
Where work waits for somebody. A fortnightly gate on a daily flow is thirteen days of waiting, and the cadence makes that arithmetic rather than opinion.0..* holds up 0..* Flow
RealizedWhat the durable half is currently made of.
Systemvendor · cost · phase · CIA · exit
A system realizes a capability and is not one. Replacing it should not change what the organization can do — and its exit says when leaving was last proved.1..* realizes 1..* Capability1 exposes 0..* Interface0..* runs on 1..* Infrastructure0..* is built with 0..* Technology
Interfacepattern · rung · queue · fields
How something is reached. The pattern decides what a change costs: an API can be versioned, a nightly file cannot be changed without finding everybody who parses it. The queue is drawn, because to whoever stands in it that is not a detail.0..* carries 1..* Information object
Infrastructureprovider · region · environment
Where things run. Coarse on purpose: what earns a place is something whose failure would be an organizational event.
Technologyring · suited to · unsuited to
What you build with, including how you work. A ring says whether something new may start here; suitability says what for.
MovementNone of this can be read off a repository. All of it is why the rest moves or does not.
Agreementparties · signatures · bears
A statement about one thing, and who has put their name to it. The only honest evidence something is shared rather than asserted.0..* is signed by 1..* Organizational unit
Guidelinelevel · autonomy · check · derogates
A rule about a class of things, signed once and checked against everything new — the signature that scales. What an agent may do is read from these, never set.0..* governs 0..* Capability0..* sets what may be done by 0..* Actor
Decisionproduces · settles · needs · affects
What was decided, by which actor, and what it changed. An agent may decide where a signed guideline delegates it; a person still answers for every decision, and everything it creates arrives unsigned.0..* is made by 1 Actor0..* is answered for by 1 Actor0..1 answers 0..* Ask1 produces 0..* Guideline1 produces 0..* Agreement
Askkind · advancement · options · became a rule
An actor stopped and needs a person. An answer promoted to a rule is asked once; one that is not gets asked again next week in different words.0..* is raised by 1 Actor
Observationindicator · reading · who looked
What somebody went and measured: four organizational indicators, and delivery beside them. Append-only, and never summed.0..* reads 1 Capability
Assessmentrisk · compliance · security · continuity
The answers a repository cannot give. Unknown is a first-class answer — a compliance field defaulting to none is a claim nobody made.0..* bounds 1 Capability
Overridewhy · until · raised to
Going against a rule on purpose, in writing — or accepting friction knowingly. Cheap, and impossible without saying why.0..* breaks, on purpose, 1 Guideline
Activitycommit · deploy · run · incident · by · with
What was actually done, by whom, and with which agent beside them. The one thing that has to be written back by whatever did it.0..* is done by 1 Actor0..* is done with 0..1 Actor

Every relation

Read each row as a sentence. The last column is where the schema records it.

FromRelationToRecorded as
Durable
Capability0..*nests under0..1Capabilityparent · four levels at most
Capability1..*speaks1..*Bounded contextcontexts
Bounded context1masters0..*Information objectreading per context
Offering0..*is delivered through1..*Capabilityproducts · capabilities
Flow0..*passes through1..*Capabilitysteps · returns_to
Arranged
Organizational unit0..*operates in1Legal entityentity
Organizational unit1is responsible for0..*Capabilityowns · develops · uses
Actor0..*works in1..*Organizational unitteams · works_in
Actor1..*holds0..*Competenceholds
Competence1..*staffs1..*Capabilitystaffs
Actor0..*performs0..*Capabilityperforms · or held competence
Actor1is accountable for0..*Actorowner · a person, for each agent
Actor0..*amplifies0..*Actorassists · an agent beside a person, to build or to use, in a capability
Decision gate0..*holds up0..*Flowgates
Realized
System1..*realizes1..*Capabilityrealizes
System1exposes0..*Interfaceinterfaces
Interface0..*carries1..*Information objectcarries · fields
System0..*runs on1..*Infrastructurehosted_on
System0..*is built with0..*Technologytechnology
Movement
Guideline0..*governs0..*Capabilityapplies to a capability, context or technology
Guideline0..*sets what may be done by0..*Actorautonomy · in force where the actor works
Activity0..*is done by1Actorby
Activity0..*is done with0..1Actorwith · the agent beside the person who did it
Observation0..*reads1Capabilitysubject · indicator
Ask0..*is raised by1Actorby · routed to the accountable person
Decision0..*is made by1Actorby · a person, or an agent where a guideline delegates it
Decision0..*is answered for by1Actora person · the agent's owner when an agent decided
Decision0..1answers0..*Askbecame a rule
Decision1produces0..*Guidelineproduces
Decision1produces0..*Agreementproduces
Agreement0..*is signed by1..*Organizational unitsignatures
Assessment0..*bounds1Capabilityrisk · compliance · security
Override0..*breaks, on purpose,1Guidelinewhy · until · raised to

What the model asserts

Six rules, each true because of the model’s shape rather than attached to it as advice.

What you can do outlives how you are arranged to do it

Durable and arranged sit in separate bands, so the map does not go stale at every reorganization and "who owns this" is a relationship rather than a property.

Nothing is shared until somebody signs it

A statement carries its parties. Two groups both claiming something is expressible, and an unsigned statement stays visibly unsigned.

Autonomy is derived, never set

Act where a signed rule decided it, prepare where judgement remains, ask where no rule reaches. Giving agents more room and deciding more out loud are the same act.

Accountability does not divide

A team can be responsible. A thing that acts on its own needs one named person who explains it and decides to stop it.

Structure is read; movement is observed

Three bands can be derived from what an organization already keeps. The fourth cannot, and a model with no place for it asserts structure is enough.

Nothing is summed

Indicators, risks and delivery figures are reported apart. A single number acquires a target, and a measure with a bonus attached stops measuring.

How the model has moved

Every change to the model is a commit, so its learning has dates. Read from git when this page was generated — the entities, relations, loop and schema, newest first.

  • The organization is the work harness — for people and agents alike
  • Pilot kit: the pulse in CI, and what it cannot place said out loud
  • Decisions follow the lightweight ADR format
  • Signatures that are somebody; capabilities with their own pulse
  • People with AI: human owns, AI amplifies
  • Questions as files: the hook asks, Cambium answers, the answer goes back
  • Any actor may decide; a person answers for every decision
  • Close the metamodel's loop: relations, multiplicities, and a walkthrough
  • The model underneath, in the tool, and a guided tour for the demo
  • Legal entity: the boundary mandate cannot cross
  • Three ideas from the metamodel, and the twenty it does not need
  • The infrastructure layer, and three things it sees that nothing else could
  • Precedent, escalation that admits what it is, and metrics by capability
  • The radar goes back to technology, and information gets its own bridge
  • Information in and out, and the pattern carrying it
  • The whole estate, and responsible is not accountable
  • What we deliver, who executes, and a person answering for every agent
  • +7 more
  • A radar where a ring is a decision, and guardrails written to be read
  • Things that fire, rules that can be checked, and a page that says what this is
  • Coworkers who are not people, and decisions that change the map
  • Levels that compose, and the line an agent may not cross
  • Guidelines: the signature that scales, and drift from it
  • Agreements: the half of the tool that builds rather than reports
  • Accept friction, with the reason on the record
  • Containment, and what sharing costs
  • A connections graph, system attributes, and removal scenarios
  • Teams: Team Topologies types, cognitive load, mandate and leadership distance
  • Capability CRUD, four levels, team roles, system map and information model
  • v0.1 + v0.2 — the map, and the findings computed from it
  • Cambium — design specification and Vite scaffold

The model is YAML in git, not a database: diffs, history for free, code review on organizational change, and a map that survives the tool that drew it.

This page is generated from the same module the app renders and the schema is tested against. If the model changes, so does this — and nothing here is final. It is a model to argue with, and the history above is how it got here.