Slug: move-fast-reversible-decisions-review-gates
Tags: Opinion, Risk Management, decision making, Innovation
Meta description: Speed and safety are not opposites. Move quickly on reversible experiments, but add proportionate review gates before decisions that can cause lasting harm.
“Move fast” is useful advice when a decision is cheap to reverse, tightly contained and easy to observe. It becomes reckless when the same philosophy is applied to payments, personal data, public releases, safety-critical systems or decisions that materially affect another person.
The mistake is not speed itself. The mistake is using one speed for every kind of decision. A team that sends a colour experiment through the same approval process as a payroll change will become painfully slow. A team that treats a payroll change like a colour experiment may become painfully sorry.
My argument is simple: move fast inside reversible boundaries, and put explicit gates around irreversible or high-impact actions. This is an opinion and a practical synthesis, not an official standard. It is, however, consistent with a broader pattern in authoritative risk, privacy, AI and cybersecurity guidance: understand context, assess impact, assign responsibility, build safeguards early and keep the ability to respond when reality differs from the plan.
Reversibility is more useful than the vague label “risky”
People often describe an idea as low-risk or high-risk without explaining what the risk consists of. Reversibility gives the conversation a sharper starting point. Ask: if this decision is wrong, can we return affected people, money, data and systems to roughly where they were before?
A draft shown to five colleagues is normally reversible. A public statement copied across the internet is less so. Testing a new button with anonymous traffic may be reversible. Uploading a customer database to an unapproved service is not made harmless by calling it a pilot. A small financial transfer can still be irreversible; a large technical experiment can be reversible if it runs in an isolated environment with no real users.
Reversibility is therefore not the same as size. It depends on exposure, recoverability, rights, dependencies and the cost of restoring the prior state.
What official frameworks contribute
HM Treasury’s Orange Book presents risk management as part of governance, decision-making and the achievement of objectives—not as an activity designed merely to prevent action. That distinction matters. Mature risk management should help an organisation take appropriate risks deliberately, with ownership and information, rather than replacing every decision with caution.
The US National Institute of Standards and Technology’s AI Risk Management Framework organises AI risk work around four functions: govern, map, measure and manage. Its companion resource also calls for identifying AI features and contexts that require human oversight. The framework does not say that every use of AI needs the same controls. It asks organisations to connect controls to context and risk.
The UK Information Commissioner’s Office says data protection by design and by default means integrating safeguards into processing and limiting personal-information use to what is necessary for a specific purpose. The US Cybersecurity and Infrastructure Security Agency’s Secure by Design guidance similarly argues that manufacturers should take ownership of customer security outcomes rather than pushing the burden downstream.
Evidence: these frameworks emphasise governance, context, ownership, safeguards and continuous management. Interpretation: a practical team can translate that pattern into decision gates that become stricter as reversibility decreases and potential harm increases.
The two-lane operating model
Lane one: the rapid reversible loop
This lane is for experiments whose failure is contained and recoverable. Work moves quickly because the environment supplies the safety: limited users, synthetic or anonymised data, capped spending, temporary access, clear monitoring and a rollback switch.
- Use a small, defined test population.
- Set a time limit and a spending limit.
- Use the minimum data required.
- Record the hypothesis and success measure before launch.
- Make stopping easier than continuing.
- Restore the previous version without depending on heroic manual work.
The point is not to produce paperwork around a tiny test. It is to make learning cheap. A reversible experiment should answer one useful question without quietly acquiring permanent consequences.
Lane two: the high-impact review gate
This lane applies when an action can move real money, disclose sensitive information, publish to a large audience, change a person’s access or eligibility, create a legal commitment, weaken security or affect health and safety. The gate should pause execution—not curiosity—until named checks are complete.
- Authority: Who is permitted and accountable for this decision?
- Impact: Who could benefit, lose, be excluded or be exposed?
- Evidence: What information supports the action, and how uncertain is it?
- Controls: What limits, approvals and monitoring reduce foreseeable harm?
- Recovery: Can the action be reversed, compensated or contained?
- Record: What must be logged so the decision can later be understood?
A review gate is not automatically a committee meeting. It may be a second authorised person confirming a payment, a privacy impact assessment before new data processing, a security test before deployment or an editor checking a serious allegation before publication. The gate should match the consequence.
Five signals that a decision needs a stronger gate
1. The affected person cannot easily opt out
An internal volunteer testing a tool has more agency than a customer whose service silently changes. Power asymmetry raises the control requirement, especially when the decision concerns employment, credit, education, housing, health or access to essential services.
2. Data can escape its original purpose
Personal information is easy to copy and difficult to retrieve. Before a fast experiment uses real data, ask whether synthetic, aggregated or minimised data could answer the same question. “We will delete it later” is weaker than never collecting or sharing unnecessary information.
3. An automated action can compound itself
A single draft may be harmless; an agent that can repeatedly send, buy, delete or publish can turn a small error into a sequence. Rate limits, spending caps, permission boundaries and human approval points are not signs that the automation failed. They are part of its design.
4. The decision creates a public or legal commitment
Once a promise is public, a contract is signed or a statement names another person, correction may not restore trust or remove liability. The cost of a short pre-publication check is often far lower than the cost of explaining why nobody paused.
5. Recovery depends on memory rather than a mechanism
If rollback means “we will remember how the old system worked”, the experiment is less reversible than it appears. Keep backups, version history, exportable records, tested restoration steps and a named owner. A theoretical undo button is not a recovery plan.
Avoid the two symmetrical failures
Failure one is control theatre: every decision requires approval, but reviewers lack time, context or real authority. Work queues grow while responsibility becomes blurry. Teams learn to describe ordinary choices as emergencies so they can bypass the process.
Failure two is innovation theatre: leaders praise speed while other people absorb the consequences. “Experiment” becomes a word used to avoid defining consent, ownership, security or compensation. The organisation learns quickly because users are forced to learn painfully.
The cure for both is proportionality. Remove gates that do not change a decision. Strengthen gates where a mistake can persist, spread or transfer costs to people who did not choose the risk.
A practical decision card
Before acting, write six lines:
- Action: What exactly will happen?
- Exposure: Which people, systems, money or data are involved?
- Reversibility: What would restoration require?
- Limit: What caps the blast radius?
- Gate: What evidence or approval is required before execution?
- Stop signal: What observation triggers pause or rollback?
If the action is genuinely reversible, this card should take minutes and help the team move. If the answers reveal lasting effects, the pause has already delivered value: the decision was never as lightweight as it first appeared.
Speed is a resource; spend it where learning is recoverable
Good builders do not choose between innovation and responsibility. They design a system in which each supports the other. Fast reversible tests generate evidence. Evidence improves high-impact decisions. Clear gates protect attention by preventing every small choice from becoming a debate.
The mature version of “move fast” is therefore not “move slowly”. It is: move fast where you can learn without trapping other people inside your mistake; slow down where action changes rights, money, safety, privacy or trust. That is not fear of innovation. It is how innovation earns permission to scale.
Featured image disclosure: The featured visual is an original conceptual AI illustration. It does not depict a real organisation, meeting or deployment.
Primary sources
- HM Treasury: The Orange Book—Management of Risk
- NIST: AI Risk Management Framework
- NIST AI Resource Center: AI RMF Core
- ICO: Data protection by design and by default
- CISA: Secure by Design
Discover more from Marychuks.com AI, Psychology, Business & CreativeVerse
Subscribe to get the latest posts sent to your email.