The Process Flow Visibility Manifesto
on where the time actually goes
Every organisation can tell you what it spends. Almost none can tell you where its time goes.
We ask for headcount and tooling because those have line items. We report utilisation, ticket counts, mean time to respond — numbers that describe how hard people are working, and say nothing about how long the work waits. So the delay grows in the dark, and every year the number that matters doesn't move.
This is a method for finding out. It is free, it is arithmetic, and it belongs to whoever uses it.
What we believe
1. The work is fast. The waiting is what costs you. In most recurring processes, between one and five percent of elapsed time is somebody working. The rest is the thing sitting in a queue. This is not a failure of effort and it is not unusual — it is normal, unmeasured, and enormous.
2. Busy people, idle work. Nobody in the building is slacking. The item spends its life between people, not with them. You could double everyone's speed and barely move the number.
3. You cannot fix what nobody counts. A pile you can point at gets argued about. A pile nobody measures grows quietly and forever. Measuring the waiting is the whole intervention; most of the fix follows from being able to see it.
4. Ask how you found out before you ask how long it took. If a stranger reported your problem, your queues explain none of the delay, and any chart you show about them is theatre. The first question is always the discovery path.
5. Split the number before you fix anything. Some delay is a queue — measurable, owned, yours. Some is an absence: nothing was looking, nothing had started, there was no station on that line. You find the second only by subtraction, and you must say so out loud. Two numbers, two owners, two different asks.
6. A wait can manufacture a defect. When a step takes three weeks, competent people skip it and guess. The rework that shows up two steps later is not carelessness — it is the queue, arriving late and wearing a different coat. Fix the wait and you fix both.
7. Shorter is not more. Cutting queues makes each item finish sooner and cuts what is in flight. It does not create capacity. Only eliminating rework — work being paid for twice — honestly raises how much you finish in a year. Anyone who tells you otherwise is selling something.
8. Inventory is not coverage. Nine hundred rules is a count of rules. Coverage is a measured share of what you decided matters. The same distinction applies to controls, tests, runbooks, and dashboards.
9. Say which numbers you know. Observed, Hypothesized, Verified. Write the prediction down and date it before you pull the logs. A number whose provenance is stated survives a room that a confident number does not.
10. The pile moves. Fix the biggest wait and a new one becomes the biggest. This is the process working, not a failure. So count again — next month, and the month after. A measurement you take once is a project. A measurement you repeat is a practice.
11. Maturity is what the process does without being pushed. Not a certificate. Not an appraisal. The line improves itself because the machinery generates the improvements: defects trigger their own reviews, telemetry opens its own tickets, and retirement is a real option with evidence behind it.
12. Waiting is not sin, and rest is not waste. Applied to a life, this method measures commitments you chose to make — not your worth, and not the hours you spend sleeping, eating, or with people you love. A life is not a production line. The unmeasured parts are usually the ones that matter.
What we refuse to claim
We will not price your improvement. The dollars in these tools are what the process costs to run — labour, at your rate, at your volume. Not the cost of measuring it. Not the cost of improving it. Not a fee. When a diagnostic quietly includes the cost of the diagnostician, the arithmetic stops being trustworthy.
We will not fold estimates into facts. Cost of delay, quality-escape multipliers, breach exposure — these are modelled, they rest on published research rather than your ledger, and they are shown separately and never added to the run cost.
We will not claim your delay is all flow. Sometimes most of it isn't. Saying which part the method cannot explain is what makes the part it can explain believable.
We will not tell you the answer is always to keep the work. A map that can only ever conclude "do this yourself" is not a diagnostic. Sometimes the honest read is that a partner does it better.
We will not hide the misses. Results get published whichever way they land. A method that only reports its successes has told you nothing about itself.
What we ask
Run it on one real process. Not a portfolio — one thing with a ticket trail and a timestamp.
Then tell us what happened, including if it didn't work. The evidence is the point. Everything else is a well-designed opinion.
The two questions
**How many are open right now?
How many finish in a week?**
Divide the first by the second. That's how long each one really takes.
Does that cycle time work for your business?
Fifteen seconds. No tool, no licence, no consultant.
If the answer bothers you, the rest of the method is waiting, and it's free.
Process Flow Visibility · Don Woodward · CISSP · C|EH · ITIL Expert · don.woodward@dewood.org
Standing on: Little's Law; Reinertsen on cost of delay and batch size; George on process cycle efficiency; Hubbard on calibrated estimation; Deming, Ohno and Goldratt on everything else. None of it is new. Almost none of it has been pointed at security operations.
The napkin does the arithmetic for you: PFV on a Napkin →