The Eight-Stage Redesign Sequence
The reference version of Chapter 11’s sequence — the strategic roadmap from Chapter 9, in stage detail. Read it as one design deployed in stages, not as eight projects: the early stages are the whole-design work — the design gets drawn, tested for fit, and validated before serious money moves — and the later stages are the managed deployment, pieces of one design released in strategic priority order, gate by gate, around a business that keeps serving customers the whole way.
Lessons learned at a gate may re-order what comes next — in writing, owned, inside the design; the destination doesn’t move.
This is anatomy, not instructions — each stage names what has to happen, what lets you enter it, what lets you leave it, and the judgment call that no checklist makes for you. The sequence matters as much as the stages: most redesigns die in the transitions.
Stage 0 — Classify the door
Purpose: decide, before anything else, whether this redesign is reversible.
Entry condition: a specific redesign candidate that has passed the Five-Question Screen.
Exit condition: a written classification — two-way door (revertible without lasting damage) or one-way door (core process, brand promise, customer relationship, or a stage’s design assuming one vendor’s current roadmap, at stake) — and the rigor level that follows from it.
The judgment call: drifted companies walk through one-way doors at two-way speed. When in doubt, classify up.
Sources: Bezos, Amazon shareholder letter, 2015.
Stage 1 — Assemble the Three Sources
Purpose: put Depth (the people who hold your undocumented know-how), Distance (a genuine outsider), and Delivery (the AI doing the execution) in place before direction is set.
Entry condition: Stage 0 classification done.
Exit condition: named Depth individuals with extraction sessions scheduled (structured methods exist for surfacing what experts can’t put into words — Klein’s Critical Decision Method); a vetted Distance source under a time-boxed engagement (Appendix F); AI positioned only to execute and narrow down options, never to set direction.
The judgment call: resisting the pull to let the tool set the direction. Delivery is necessary just to keep up with competitors — parity, not advantage — and it’s never the source of the edge.
Sources: Polanyi (1966); Nonaka & Takeuchi’s SECI model; Klein, Calderwood & MacGregor (1989); Katz & Allen (1982) on the ~1.5-year decay of outsider perspective.
Stage 2 — Draft against the fit test
Purpose: design the redesign as a system, not a features list.
Entry condition: Depth extraction complete; Distance sessions run.
Exit condition: a draft that shows at least second-order fit — the new process reinforces other activities, and they reinforce it back (Appendix B, part three).
The judgment call: killing the draft that is merely a better single activity. First-order fit is the copyable kind.
Sources: Porter, “What Is Strategy?”, HBR 1996.
Stage 3 — Validate the delta
Purpose: prove the advantage is real to customers before scaling into it.
Entry condition: a fit-tested draft.
Exit condition: a pilot with a small, tolerant customer group has moved a perception or loyalty metric — not an internal efficiency metric — and the pilot was explicitly allowed to fail.
The judgment call: distinguishing validation from enthusiasm. This is a delta test — does the customer notice and value the difference? — against your existing baseline, not a discovery test; test for negative surprises, not the happy path.
Sources: Blank, The Four Steps to the Epiphany (Customer Validation, not Discovery); Cooper & Sommer, Journal of Product Innovation Management, 2016, on validated-learning loops inside gated stages.
Stage 4 — Stage the capital
Purpose: commit to the destination while capping the exposure.
Entry condition: validated delta.
Exit condition: gated tranches — money released in stages, each stage earned by the results of the last — funded one at a time: discovery, then proof, then production, each released only when the prior gate’s evidence clears. Budget multiples of the pilot, not increments; production reliably costs more than piloting. Each gate doubles as a scheduled moment to brief lenders or a board against pre-seen thresholds — for PE-owned firms, synced to the fund’s own reporting rhythm rather than competing with it.
The judgment call: holding the gate when the team is excited and the evidence is thin.
Sources: IBM’s stage-gating framework; Cooper’s Stage-Gate kill points (the mechanism, not any percentage).
Stage 5 — Pre-write the failure conditions
Purpose: write, before scaling, what result means “this failed” and what happens when it appears.
Entry condition: tranche structure agreed.
Exit condition: a complete IF/BY/THEN set on the model of Appendix D, with a named kill owner.
The judgment call: writing conditions sharp enough to trigger. A failure condition nobody could ever hit is a decoration.
Sources: Klein, “Performing a Project Premortem,” HBR 2007; the design principles in Appendix D.
Stage 6 — Lock in the protection
Purpose: make the validated advantage legally and contractually hard to take.
Entry condition: a redesign worth protecting — Appendix B says moat, not parity.
Exit condition: trade secrecy treated as the default approach to protecting your intellectual property, or IP (business processes generally aren’t patentable after Alice Corp. v. CLS Bank, 2014); NDAs and confidentiality agreements tightened rather than reliance on the collapsing non-compete; exclusivity formalized in contract for any data partnership the moat depends on; where the redesign streams client data through rented models, engagement-letter consent and the vendor’s data-use terms confirmed before any pilot touches live data; and a named plan for retaining the people who hold the Depth.
The judgment call: accepting that this stage decays. AI is lowering the cost of reverse-engineering, which erodes trade-secret defensibility itself — protection needs re-review on the Chapter 12 triggers, not a one-time filing.
A note that is not a formality: this stage describes strategy, not counsel. Nothing in it is legal advice. Engage qualified counsel before acting on any of it.
Sources: Defend Trade Secrets Act (2016); Alice Corp. v. CLS Bank (2014); USPTO 2024 AI subject-matter-eligibility guidance; FTC non-compete rule vacated, appeal withdrawn September 2025.
Stage 7 — Govern the risk tier
Purpose: apply governance proportional to what the system can break.
Entry condition: a scaled, protected redesign in production.
Exit condition: a written risk classification — light-touch for low-stakes, heavy for anything touching safety, compliance, or customer trust — with the bulk of the business kept in safe, proven operation — serving customers exactly as before — and the stages under active deployment capped and contained.
The judgment call: this stage never exits. It hands off to the Cadence: the calendar, signal, and decay-rate triggers in Chapter 12 are what re-open Stages 1–3 when the melt begins.
Sources: NIST AI Risk Management Framework; Taleb’s barbell — keep most of the business safe and boring, and let a small, capped slice take the real risk.
How to use it: This is anatomy, not instructions — each stage names what has to happen, what lets you enter it, what lets you leave it, and the judgment call that no checklist makes for you. The sequence matters as much as the stages: most redesigns die in the transitions. Print this page →