Fasil PM logoFasil PMProject & IT ConsultancyBook a call

A Lesson Without a Changed Behavior Is Just a Memory With Formatting.

Fourteen candidate lessons faced one rule: no dated artifact, no lesson. The AI flagged a blind spot, prevention leaves no evidence, and ownership became a funded fight.

Programme
Project Falcon
Organisation
Atlas Bank
Phase
Closing
Template
Lessons Register
Post 21 of 22 following Project Falcon at Atlas Bank. Full program context is in Post 01. Previously, Post 20 ran the 24-hour go-live window: a dead load balancer, an 84-minute hold decided by a sentence written in June, and a transition certificate signed at 21:55. This post is the discipline that comes after the champagne nobody actually drank: deciding what was learned, proving it, and making someone own it.

Thirty Days After the Mountain, You Map the Route

The program is in Phase 5, Closure, and closure is mostly lists: contracts winding down, the hypercare desk demobilizing on schedule, the legacy decommission underway since 1 August, the closure report targeted for 30 September. Inside that list sits the one activity that determines whether Atlas Bank bought a platform or bought a capability: the lessons workshop. Most organizations run it as a ritual, two hours of adjectives, a slide titled “Key Learnings,” an appendix nobody reopens. Falcon decided in June to run it as an evidence exercise instead, and the difference starts before the room fills: every candidate lesson must trace to a dated artifact, and every lesson that survives the workshop must leave with a disposition and an owner. No artifact, no lesson. No owner, no lesson. The register is allowed to be short. It is not allowed to be decorative.

The preparation ran for a week. The program's archive, twenty months of charters, registers, ADRs, change requests, quarterly reviews, incident packs, and gate records, was mined for candidate lessons, circulated on 6 August, and challenged in writing before anyone sat down. The workshop on the 13th is therefore not a brainstorm; it is a tribunal. Fourteen candidates enter. Each is read against three questions, and the second one is the post's reason to exist. One: what is the evidence? Two: was the outcome structure or luck, would this have worked with different people on a different night? Three: if it is structure, who owns it after 30 September, when the program that learned it stops existing?

The third question is where lessons registers go to die, and everyone in the room knows it. A lesson addressed “to the organization” is addressed to nobody. A lesson that institutionalizes carries cost: tooling, on-call rotations, policy maintenance, training, a line in someone's permanent budget. Which means the lessons workshop, properly run, is not a reflective exercise at all. It is the program's final negotiation, and the currency is ownership.

The most dangerous lessons are the ones from things that went right.

Raman Defends the Rejection of Her Own Proposal

The brief's standout agenda item is the one the architecture community has been waiting for: the formal revisit of both ADRs, on the record, with hindsight finally available. ADR-002 first, because its verdict is quick. gRPC on the internal mesh did what its spike test promised: the screening path peaked at 174 milliseconds on go-live day against a 200 millisecond SLA, and the headroom Benali demanded held through every Monday since. More telling is the boundary. In May, a squad proposed extending gRPC to an external partner API, citing ADR-002 as precedent; the proposal died in one meeting, killed not by an architect but by a sentence, the non-goal clause stating external APIs remain REST in the program's lifetime. The yes held its edges for nine months including one direct attempt to stretch them. Verdict: working as intended, boundary intact, lesson L-09 drafted on the spot.

ADR-001, the Pulsar rejection from Post 12, is where the room gets interesting, because Jin-ho Park arrives with a motion.

Jin-ho Park: “Market B design starts in Q1. Multi-region, geo-replication, exactly the future ADR-001 said Pulsar was built for and we did not need yet. We were right to reject it in month nine of one market. We would be wrong to carry the rejection into three. I move we flip ADR-001 to accepted for the Market B architecture now, while we still have the people who understood the original analysis.”

And the person who stands up to oppose him is Priya Raman, which silences the room, because ADR-001 was her proposal. She has carried the rejection of her own technically correct idea for ten months, and she is now defending it.

Priya Raman: “No. The rejection was never ‘Pulsar is wrong.’ It was ‘Pulsar is unjustified by current evidence,’ and that is still exactly true today, because Market B has produced no evidence yet; it has produced a kickoff date. If we flip the verdict on anticipation, we are doing in reverse what I was stopped from doing in November: deciding ahead of the data and calling it foresight. The ADR has a revisit trigger. The trigger is the Market B scaling design producing measured requirements. Let it fire properly, and if the numbers say Pulsar, I will be the happiest rejected proposer in this bank. The process gave my idea a fair trial once. Give it a second fair trial, not a pardon.”

The motion fails, correctly, and the moment becomes lesson L-09's evidence in real time. A decision culture has matured when the proposer defends the rejection of her own proposal because the process that rejected it is worth more to her than the vindication. ADR-001 remains REJECTED, revisit trigger formally scheduled against the Market B scaling design in Q1 2027, and the register records the workshop's quiet consensus: vindication of the process is worth more than vindication of the position.

Vindication of the process is worth more than vindication of the position.

The Lesson Everyone Praises and Nobody Wants

Lesson L-02 is the program's most externally validated learning: wire risk-register trigger conditions into live alerts, the practice that caught R04 in shadow, gave the January incident its four-minute detection, and earned supervisory observation OBS-2, in which the regulator itself recommended Atlas Bank formalize it into standing policy. Nobody disputes the lesson. Then Fasil Alemeye Abate asks who owns it bank-wide, and the temperature drops, because the answer carries a permanent budget line and a permanent on-call burden, across every program the bank will ever run.

Nadia Benali: “It is monitoring infrastructure. Alerts, dashboards, instrumentation: that is a technology control. It lands in Abebe's organization.”
Abebe Alemu: “It is a risk-management practice; my teams wire whatever the risk policy mandates, but a mandate has to exist first, and policy is the CRO's pen. If I institutionalize tooling without her policy, I have built a fire alarm no regulation requires anyone to answer.”

Both deflections are technically correct, which is how good lessons die: not rejected, just unfunded, orphaned between two executives who each genuinely believe the other is the natural parent. This is the inverse of Post 11's territory war, where two leads each claimed ownership; maturity, it turns out, produces the mirror-image dispute, where ownership means cost and everyone's arms are suddenly full. The deadlock holds for ten minutes until Fatima Idris ends it the only way these deadlocks end: with money.

Fatima Idris: “The program proved it, a regulator endorsed it, and I am not closing Falcon by orphaning its best lesson. Split it. Nadia writes the policy, due 30 September with the closure report. Abebe delivers the tooling standard against that policy by 30 November. The first-year operating cost comes out of the CDO budget; after that it is baseline. The lesson now has two owners, two dates, and a sponsor. Next item.”
From Flag to Institution · Three Chains the Register Preserves
The pattern the workshop kept finding: a machine surfaces a gap, humans encode a rule, reality tests the rule once, and the lesson's only remaining question is who owns it forever.
AI flag, Dec 25:triggers unwired Rule: wire all8 triggers (9 Jan) Tested: INC-0014-min detection L-02 + OBS-2endorsement Bank policyBenali + Alemu AI flag, Jun 26:masked failures Rule: N+1 atgate time (30 Jun) Tested: 02:03,84-min hold L-04: gates aredecisions Validated once;revalidate Mkt B AI flag, Jan 26:no prevention Rule: CA-3 freeze+ 48h notice Tested: go-livefreeze, no recur L-07: detection≠ prevention Std vendorclause (Marquez)

Mining the Archive with CARES, Defined Inline

The lessons-mining prompt uses CARES: Context, Action, Result, Evaluation, Sustainment, and it comes with the bluntest adoption note in this series. CARES circulates in practitioner material with unstable, conflicting definitions; it is not a cited method, and anyone who tells you otherwise is quoting a different blog than the last person who told you. The honest way to use a framework in that condition is the way shown below: pin your own definition inside the prompt itself, so the structure is explicit rather than assumed. That practice is itself one of this series' quieter lessons about working with AI: a framework's value is the structure it enforces, not the authority of its name, and an inline definition enforces structure while borrowing no authority. The fit, once pinned, is exact for lessons work. Context and Action anchor the lesson to its dated artifact. Result states what happened, measurably. Evaluation asks the workshop's central question, structure or luck. Sustainment names the owner, the cost, and the date, which is the field that separates a register from a scrapbook.

Prompt · Lessons Mining · 4 August 2026
You are mining a completed banking program's archive to draft candidate lessons for a lessons register. Use CARES, defined for this task as follows (definitions in circulation vary; these bind): CONTEXT: the situation and the dated artifact it lives in. ACTION: what the program did, with the artifact that did it. RESULT: what happened, measurable, with evidence citation. EVALUATION: structure or luck. Would this outcome survive different people, a different night, a different program? State the evidence count: how many times was this tested? SUSTAINMENT: what must exist permanently for this lesson to keep paying (policy, tooling, clause, budget), the natural owning function, and the recurring cost order-of-magnitude. ARCHIVE INDEX PROVIDED: charter + tolerances (Feb 25); risk register + instrumentation audit (Apr 25, Jan 26); PMO-CC-001/ 002/003 (Jun-Jul 25); benefits plan (Aug 25); status Red (Aug 25); RACI decomposition (Sep 25); ADR-001 REJECTED (Nov 25 per revisit file; orig. Post 12); CR-001 + T4 trace (Sep-Oct 25); QR-2025-Q3 + PMB v2.0 (Oct 25); ADR-002 + boundary (Nov 25); RR-R04 (Dec 25); INC-001 + CA-1..4 (Jan 26); GOV-001 v2.0 incl. termination protocol (Feb 26); RA-001 conditional go (Mar 26); TP-001 as executed (Jul 26). TASK: draft 12-16 candidate lessons in CARES. Hard rules: every lesson cites at least one dated artifact; no lesson may use the words "communication," "alignment," or "stakeholder engagement" as its subject (lessons must name mechanisms, not virtues); EVALUATION must commit to structure / luck / insufficient evidence, with the test count. Flag systematic gaps in the candidate set itself: classes of lesson this mining method will under-produce.

The Flag About the Dogs That Did Not Bark

AI Draft · Candidate Lessons · L-04 Evaluation (Extract) and Method Flag

L-04 (extract), EVALUATION. The N+1 gate criterion produced the correct hold decision under genuine pressure on 14 July. Test count: one. A single successful firing cannot statistically separate structure from luck; the counterfactual (would the room have held without the written criterion?) is untestable. Classification: structure by design, validated once. Recommended disposition: institutionalize the pattern (gates written as decisions with named criteria), but tag the specific criterion “validated once,” with revalidation scheduled at the next major cutover (Market B). Three other candidates carry the same single-occurrence profile and the same tag.

AI flagged (method gap): “This mining method reads artifacts, and artifacts are overwhelmingly produced by events. The candidate set therefore over-represents lessons from things that happened and systematically under-produces lessons from things that were prevented. Example found by inversion: ADR-002's migration rule (feature-complete services migrate only at natural touch points) generated no incident, no escalation, and no artifact beyond its own clause, which is precisely the evidence that it worked: eleven services crossed a protocol migration era with zero migration-induced defects. The register currently has no mechanism for capturing the absence of failure. Recommend an explicit non-events review: for each major restraint decision in the archive, ask what did not happen and whether that silence is attributable. Otherwise the bank will institutionalize its saves and forget its prevention, and prevention is the cheaper of the two.”

The flag names the deepest bias in organizational learning: evidence follows noise, and prevention is silent. The workshop adopted the non-events review on the spot and harvested two lessons the mining had missed: L-10, the migration restraint that produced eleven quiet services, and L-11, the cross-party change freeze that produced a go-live week in which the January incident structurally could not recur, an absence nobody had thought to log as an outcome. The “validated once” tag survived too, over mild resistance from people who wanted their best night labeled proven. One firing is one firing. The register says so, in writing, next to its proudest entries, because a lessons register that flatters its own program is just a yearbook.

LL-001 Lessons Register, as Ratified (Extract)

Lessons RegisterLL-001 · v1.0
Project Falcon: Lessons, Dispositions, and Owners
Project Falcon · Atlas Bank · Workshop 13 Aug 2026 · Compiled by Fasil Alemeye Abate
Status Ratified Ratified 27 Aug 2026 · 14 lessons: 9 institutionalize · 2 validated-once · 3 archive · Into closure report 30 Sep
IDLesson (mechanism, with source artifact)DispositionOwner · Date
L-01Charters enumerate tolerances; tolerances are cited by clause when used (T4, CR-001). A tolerance you never cite is one you never had.InstitutionalizeBank PMO · charter template v3, 30 Sep
L-02Risk-register trigger conditions are wired as live alerts, not prose (RR-R04; INC-001 4-min detection; OBS-2 endorsement).InstitutionalizePolicy: N. Benali 30 Sep · Tooling: A. Alemu 30 Nov · Year-1 cost: CDO
L-03One unified change log across all parties, vendor included; in incident, the log is read end-to-end before any rollback (INC-001: 9-minute diagnosis).InstitutionalizeVendor mgmt office · std clause, 31 Oct
L-04Cutover gates are written as decisions (SCQA), with hold ceilings and rollback defaults; the N+1 criterion held the 14 Jul PONR (TP-001).Validated onceBank PMO · revalidate at Market B cutover
L-05Threshold breaches trigger decomposition before recovery plans (PMO-FIN-002 amendment; Q3 SPI 0.964 with green critical path).InstitutionalizeFinance PMO (T. Richter) · done, Oct 25
L-06Pre-approved communications libraries, incl. contingency variants; embargo moved at 03:25 on go-live night in 20 minutes (Post 07 library; TP-001).InstitutionalizeCorporate comms (L. Marquez) · 31 Oct
L-07Detection is not prevention: cross-party change governance (freeze windows, 48h shared-resource notice) is contractual, not customary (INC-001 CA-3).InstitutionalizeVendor mgmt · std contract schedule, 31 Oct
L-08Three-role service ownership (service / operations / escalation) by name, set before incidents (R06; 18-minute OTP failover on day one).InstitutionalizeTechnology operating model (A. Alemu) · 30 Nov
L-09ADRs record both verdicts with reasoning and revisit triggers; ADR-001 remains REJECTED (revisit: Market B design, Q1 2027), ADR-002's boundary survived a direct extension attempt (May 26).InstitutionalizeArchitecture board · ADR standard, 30 Nov
L-10Non-event lesson: the migration restraint rule produced eleven services that crossed a protocol era with zero migration-induced defects; restraint is an outcome and is logged as one (ADR-002; non-events review).Validated onceArchitecture board · with L-09

Extract: 10 of 14 entries shown. L-11 (change-freeze non-event), L-12 (sponsor exit protocol), L-13 (cost instrumentation receipts), L-14 (termination protocol, GOV s.8) in the full register. Three workshop candidates were archived as program-specific; one candidate (“the team showed great resilience”) was struck under the no-virtues rule, with affection.

What the Human Changed

What the Human Changed (AI Candidates to Ratified LL-001)
  1. Adopted the non-events review and ran it in the room. The flag's point, that artifact mining over-produces saves and under-produces prevention, became a standing agenda step, and it harvested the two lessons (L-10, L-11) the register would otherwise have missed. The cheapest lessons a bank owns are the disasters that never generated a document.
  2. Kept the “validated once” tag against the room's pride. Several owners wanted L-04 marked proven; one firing is one firing, and the tag plus a named revalidation event (Market B cutover) is what makes the register honest enough to survive its own program's affection for itself.
  3. Converted Sustainment from a field into a negotiation. The AI drafted natural owning functions; Fasil refused to ratify any institutionalize lesson until a named human accepted it with a date and a funding line, which produced the L-02 deadlock and Idris's split-and-fund resolution. Eleven of fourteen lessons changed hands in the room, on the record.
  4. Enforced the no-virtues rule to the letter. Two AI candidates and one human candidate arrived with mechanisms missing and adjectives doing the work. All three were rewritten or struck. A lesson that cannot name its mechanism cannot transfer; it can only be admired.
  5. Recorded the Raman moment as evidence, not anecdote. The draft of L-09 cited the two ADR verdicts. Fasil added the 13 August revisit itself, proposer defending her own rejection, motion to flip on anticipation defeated, as the lesson's third evidence point, because a decision culture is proven by how it behaves when reversing would feel like generosity.
The Future Payoff

LL-001 files into the closure report on 30 September, but its real payoffs are dated past the program's death: Benali's policy and Alemu's tooling standard land in the autumn, the vendor clauses enter the bank's standard schedules in October, and the ADR-001 revisit trigger waits for the Market B design in Q1 2027, where Raman gets her second fair trial. One payoff lands sooner and closes this series: the register's final page cross-references every benefit claim the lessons rest on to the measurement that will test them, the twelve-month value review of Post 22, because a program's lessons and its benefits are the same question asked in two tenses.

The workshop ended at 17:40 with fourteen lessons, eleven new owners, one funded deadlock, and a struck candidate about resilience that everyone privately agreed with. One artifact remains, and it is the one the entire series has been walking toward since the business case of Post 01: standing in front of the benefits plan, twelve months after launch, and answering the only question a sponsor's signature ever really asks. Was it worth it? That is Post 22, and the series ends there.

The Takeaway
A lesson without an owner is a memory. A lesson without evidence is an opinion.
Most lessons-learned exercises fail twice: first by harvesting adjectives instead of mechanisms, then by addressing the harvest to an organization, which is to say, to nobody. Falcon's register survived both failures by treating the workshop as the program's last negotiation. Every lesson traced to a dated artifact or died. Every win answered the question structure-or-luck, with its test count printed beside it, and one firing was never allowed to call itself proof. Every surviving lesson left the room with a human owner, a date, and a budget line, because institutionalizing a lesson is not an act of documentation; it is an act of funding. And the machine's best contribution was pointing at the silence: the prevented incidents, the restrained migrations, the disasters that never produced an artifact, which are the lessons organizations forget precisely because nothing happened. Write those down too. Nothing happening was the plan.

A fictional case study for teaching purposes. Atlas Bank, Project Falcon and all named individuals are invented. Technologies are industry-standard and publicly available.