Reversibility and Decision Speed
One-way and two-way doors: [Amazon — Andy Jassy on asking “why”](https://www.aboutamazon.com/news/workplace/amazon-ceo-andy-jassy-on-asking-why) • Decision-quality framework: [Decision Education Foundation — The Decision Chain](https://www.decisioneducation.org/learn/decision-chain) • Practical guidance: [Tony Robbins — Four Rules for Decision Making](https://www.tonyrobbins.com/blog/the-four-rules-for-decision-making)
Match decision effort to the cost of being wrong
Decision speed should depend on the choice’s reversibility, downside, scale, and cost of delay. Treating every choice as equally consequential creates either recklessness or bureaucracy.
A logo test for ten customers, a three-year factory lease, and emergency surgery should not use the same process. The first can be reversed cheaply, the second locks capital and location, and the third is urgent with profound consequences.
The useful question is not “Is this important?” Almost every owner believes a decision is important. Ask: If this choice is wrong, how quickly, cheaply, and safely can we detect and undo it?
Distinguish one-way and two-way doors
Amazon’s shareholder letter describes some decisions as one-way doors—consequential and difficult to reverse—and most as two-way doors, which can be changed when they prove wrong. The metaphor helps allocate attention without claiming any choice is literally irreversible.
| Test | Two-way door | One-way door |
|---|---|---|
| Exit cost | Low and planned | High, uncertain, or prohibitive |
| Recovery time | Days or weeks | Months, years, or impossible |
| Harm radius | Limited users, money, or operations | Broad legal, safety, financial, or reputational effect |
| Learning | Feedback arrives before major exposure | Feedback may arrive after commitment |
| Typical process | Local owner, threshold, monitor | Senior owner, scenarios, independent review, mitigation |
Examples depend on context. A price change may be reversible for a small online store but difficult for a regulated utility. A database migration can be a two-way door with tested rollback and dual writes, or a one-way door after destructive conversion.
Classify the implemented design, not the label. “Pilot” is not reversible if it exposes every customer’s private data. “Long contract” may have an affordable termination clause.
Write the exit route before entry: owner, rollback steps, maximum loss, and time required.
Measure the cost of delay
The cost of delay is the value lost or risk accumulated while a decision remains open. More analysis is not free: opportunities expire, problems compound, attention stays occupied, and teams improvise around missing direction.
Estimate a rough weekly cost:
| Delay effect | Estimate |
|---|---|
| Deferred gross margin from launch | £18,000 |
| Manual work while system remains unchanged | £4,000 |
| Expected incident exposure | £3,000 |
| Decision meetings and rework | £1,500 |
| Approximate weekly cost | £26,500 |
The estimate need not be exact to challenge a month of unstructured analysis. If another week of research costs roughly £26,500, that research should have a plausible chance of improving the decision by more.
Delay can also create value by preserving flexibility or buying information. Compare net delay value: expected learning and option preservation minus deferred benefit, ongoing harm, and effort.
Convert irreversible commitments into experiments
An experiment is a limited action designed to produce decision-relevant evidence before full commitment. It makes a choice more reversible by restricting scope, time, money, or exposure.
Design an experiment backward from the next decision:
- Name the commitment you are trying to avoid making blindly.
- Identify the uncertain claim most likely to change that commitment.
- Define the smallest action that tests the claim in a representative setting.
- Set success, failure, and ambiguous-result thresholds before running it.
- Cap exposure and preserve a rollback.
- Decide what each result will trigger.
“Try it with some users” is not enough. A useful pilot says: “Offer the new onboarding to 500 randomly selected new customers for four weeks; scale only if activation rises at least 8 percentage points, refund requests do not rise more than 1 point, and severe support cases remain below five.”
A pilot can mislead when participants, timing, or conditions are unrepresentative. Record how the experiment differs from full scale and which risks it cannot test.
Set stop rules before escalation
A stop rule is a predefined condition that ends, pauses, or changes an action. It protects against sunk cost, gradual risk expansion, and the tendency to reinterpret failure after investment.
Use four parts:
| Part | Example |
|---|---|
| Metric | Weekly retained use |
| Threshold | Below 25% |
| Duration | For three consecutive cohorts |
| Action and owner | Product director stops paid acquisition and reviews the product |
Include safety and budget thresholds: “Stop immediately after any unauthorized data exposure,” “Pause when cumulative spend reaches £80,000 without milestone B,” or “Rollback if error rate exceeds 2% for ten minutes.”
Predefine scale rules too. Otherwise a modest positive signal can justify uncontrolled expansion. “Scale from 5% to 20% only after two weeks above all thresholds” preserves staged learning.
Stop rules should not be so noisy that normal variation triggers chaos. Use sustained thresholds, confidence intervals, or human review for ambiguous signals. Safety limits remain immediate when harm cannot be tolerated.
Use deadlines and default actions
A decision deadline is the time after which delay costs more than the expected value of further analysis. Pair it with a default action so the deadline cannot pass without consequence.
Weak deadline: “We should decide soon.” Strong deadline: “The chief operating officer decides by 16:00 Friday. If supplier security evidence is missing, the default is a four-week extension of the current contract, not automatic approval of the new supplier.”
Define one extension rule: extend only if a named piece of evidence could reverse the choice, has a credible delivery date, and its value exceeds delay cost. An extension cannot merely reflect discomfort or lack of unanimity.
Time-box meetings as well as the overall process. A reversible choice may need a one-page proposal and 30 minutes, not five committees. A consequential choice may need a week of scenarios and review, not an indefinite calendar.
Set a minimum evidence threshold
A minimum evidence threshold states what must be known before action is responsible. It prevents both premature commitment and impossible demands for certainty.
Calibrate the threshold to exposure:
| Decision type | Minimum useful evidence |
|---|---|
| Reversible UI change to 5% of users | Instrumentation works; rollback tested; harm metric defined |
| Six-month supplier trial | Security and legal constraints met; references checked; exit terms clear |
| Multi-year capital project | Independent cost range; demand base rate; adverse scenario; financing and exit analysis |
| Safety-critical change | Applicable standards met; hazard analysis; qualified approval; emergency recovery tested |
Separate must-know from nice-to-know. Must-know evidence protects hard constraints or could change the choice. Nice-to-know evidence improves comfort but would not alter action.
Use a decision threshold: “Approve only if estimated on-time probability is above 65% and loss in the adverse case remains below £200,000.” Research should focus on whether those conditions hold, not on producing a universally complete report.
When evidence remains ambiguous at the deadline, choose the option that preserves survival and learning. Uncertainty does not justify violating a hard safety or legal boundary.
Work a build-or-buy example
A worked example shows how reversibility and speed change a technical decision. A company needs customer-notification software within three months. The team can build internally, sign a three-year platform contract, or run a paid six-week trial with one region.
Classification: a full internal build consumes scarce engineers but can be stopped; a three-year contract has termination fees and data migration, making it closer to a one-way door; a limited trial is a two-way door if data deletion and export are verified.
Cost of delay: manual notification work costs £12,000 per week and creates an estimated £5,000 weekly compliance exposure. A month of indecision therefore costs roughly £68,000 before lost product work.
Experiment: the team chooses a £15,000 trial in one region. It tests delivery rate, operator time, data export, and support responsiveness under realistic load. Hard constraints—security review, consent handling, and deletion—must pass before any customer data enters.
Thresholds: sign a one-year contract only if delivery exceeds 99%, operator work falls by at least 50%, critical support response stays below two hours, and full data export succeeds. Stop after any unresolved privacy breach or if cumulative trial spend exceeds £20,000.
The team decides the trial in two days because it is bounded and reversible. The contract decision receives deeper review after evidence arrives. Speed is not uniform; it follows the door.
Install a decision-speed policy
A decision-speed policy gives teams default levels of process so every choice does not begin with a negotiation about governance. The levels should reflect local risks rather than job titles alone.
| Level | Typical choice | Owner | Process | Target time |
|---|---|---|---|---|
| 1: bounded and reversible | Small experiment within limits | Closest informed operator | Record action, metric, rollback | Hours to two days |
| 2: meaningful but recoverable | Supplier pilot, team process change | Functional owner | Options, consequences, threshold, review | Days to two weeks |
| 3: difficult to reverse | Large contract, major platform, public commitment | Accountable executive | Scenarios, independent challenge, mitigation, approval | Time-boxed weeks |
| 4: safety, legal, or existential | Hazardous or survival-level exposure | Qualified authority | Required standards, expert review, tested recovery | As urgent as safety allows |
Final checklist:
- [ ] Reversibility is assessed by exit cost, recovery time, and harm radius.
- [ ] A written exit route exists before commitment.
- [ ] Delay cost includes forgone benefit, ongoing harm, and process effort.
- [ ] Experiments test the uncertainty most likely to change the full choice.
- [ ] Pilot population and conditions resemble the intended scale.
- [ ] Success, stop, and scale rules are set before results arrive.
- [ ] Every open decision has an owner, deadline, and default action.
- [ ] Extensions require named high-value evidence.
- [ ] Minimum evidence protects hard constraints without demanding certainty.
- [ ] Process depth matches the implemented door, not the importance rhetoric.
Fast and careful are not opposites. A strong decision system is fast where error is cheap, deliberate where commitment is deep, and always explicit about how it will learn or recover.