Post-Pilot Lock-In Audit¶
Test / assessment — instantiates Malleability Window Governance
Checks whether a pilot has already created dependency, expectation, political commitment, or infrastructure that makes non-continuation unrealistic.
The Post-Pilot Lock-In Audit is a point-in-time assessment run at the end of a pilot, asking one retrospective question: has this "temporary" trial already manufactured dependency, expectation, political commitment, or infrastructure that makes not-continuing unrealistic — and did the pilot stay inside the containment boundary it declared? It measures lock-in that has already accrued, and checks the boundary that was supposed to hold. It does not forecast future reversibility; it takes a reading of the present. Its whole reason to exist is that pilots are the archetype's classic Trojan horse: a bounded trial that quietly becomes permanent before the review meant to judge it ever convenes.
Example¶
A regional grid operator has just finished a twelve-month battery-storage demand-response pilot with three aggregators, and a renewal decision is on the agenda. The audit works backward through the lock-in pathways and finds three problems. Two aggregators re-architected their control systems around the pilot's proprietary API — technical dependency now runs deep. The operator publicly credited the pilot with averting a summer blackout — a political commitment that makes cancellation embarrassing. And a five-year interconnection agreement was quietly signed at month four — a breach of the pilot's declared scope boundary, which capped commitments at the pilot term. The audit's verdict is blunt: non-continuation is already unrealistic. The "pilot" locked itself in before the review, which is precisely the failure the archetype warns against.
How it works¶
- Retrospective checklist across pathways. Technical, financial, legal, political, and social lock-in are each scored for what has already formed, not what might.
- Boundary reconstruction. The audit recovers the pilot's declared containment — caps on scale, duration, and reliance — and checks whether the trial actually stayed inside it.
- Present-state switching cost. It scores what leaving would cost today, in dependency and reversal effort, rather than projecting a future.
- Timed before renewal. The output is a verdict delivered before the renewal vote, so lock-in cannot be ratified by default.
Tuning parameters¶
- Pathway coverage — technical only, or the full technical/financial/legal/political/social set. Broader coverage catches non-obvious lock-in but costs investigative effort.
- Evidence standard — self-reported versus artifact-audited. Harder evidence is more trustworthy but slower and more intrusive.
- Boundary strictness — how tightly the declared sandbox terms are read. Strict reading catches quiet breaches but can flag benign overruns.
- Lock-in threshold — how much accrued dependency counts as "already locked in." A low bar is cautious but noisy.
When it helps, and when it misleads¶
Its strength is catching "the pilot became permanent" before a renewal meeting rubber-stamps it — turning a suspicion into a documented reading of accrued dependency. Its failure mode is running too late, after lock-in has already set, or scoping only to technical dependency and missing the political and social lock-in that are often decisive; path dependence[n1] is the reason small early commitments cascade into a de facto standard nobody chose. A classic misuse is an audit that certifies "no lock-in" merely because a cancellation clause exists on paper, ignoring the dependency that makes exercising it impossible. The guarding discipline is to run the audit before the renewal decision and to cover the non-technical pathways where real lock-in usually hides.
How it implements the components¶
lock_in_cost_monitor— reads and scores the dependency and switching cost that have accrued over the pilot, across all lock-in pathways.sandbox_boundary— reconstructs the pilot's declared containment (scale, duration, reliance caps) and checks whether it actually held.
It measures lock-in that has already formed, not the future point where reversing gets harder than continuing — projecting that horizon reversibility_horizon_marker and testing whether the exit route works rollback_and_redesign_pathway both belong to its hazard-twin Reversibility Horizon Review.
Related¶
- Instantiates: Malleability Window Governance — the audit is the guard against the archetype's "pilots silently become permanent" symptom.
- Consumes: Regulatory or Operational Sandbox sets the boundary this audit reconstructs and checks.
- Sibling mechanisms: Adaptive Stage-Gate Protocol · Collingridge Curve Workshop · Deployment Impact Dashboard · Exit and Interoperability Rule · Pause or Moratorium Trigger Protocol · Regulatory or Operational Sandbox · Reversibility Horizon Review · Stakeholder Harm Reporting Channel · Sunset Clause with Renewal Hearing
Editorial Notes¶
Form Classification¶
Form family: Assessment, Review & Assurance
Rationale: Post-Pilot Lock-In Audit operates as a bounded evaluation of existing evidence or work that produces a finding or disposition because it checks whether a pilot has already created dependency, expectation, political commitment, or infrastructure that makes non-continuation unrealistic.
Independent corroboration: The frozen evidence defines Post-Pilot Lock-In Audit as 'Checks whether a pilot has already created dependency, expectation, political commitment, or infrastructure that makes non-continuation unrealistic', so its operative form is Assessment, Review & Assurance.
Review outcome: Independent reviewer agreement; high confidence.
Origin Attribution¶
Primary origin: Public Administration & Policy
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Multi-domain
Rationale: Auditing whether a nominal pilot has generated irreversible commitments is a policy-governance concern.
Related originating lineages:
- Economics & Finance — Economics contributes sunk costs, switching costs, and option-value analysis.
- Organizational & Management Science — Organizational management contributes infrastructure and expectation lock-in.
- Political Science — Path-dependence and policy-feedback theory materially explain political lock-in before formal continuation.
Review resolution: Both blind reviewers agree that public administration policy is the primary origin. Reconciliation resolves alternate origin disagreement, domain reach disagreement. Formative alternate lineages are retained as economics_finance, organizational_management, political_science; later breadth of use is recorded separately as domain_reach=multi_domain, while origin_mode=cross_disciplinary_synthesis describes the relationship among origin lineages.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Reconciled after independent review; medium confidence.
Notes¶
[n1] Path dependence / lock-in — the tendency for early, sometimes minor commitments to constrain later choices as dependencies, standards, and sunk investment accumulate (the persistence of the QWERTY keyboard layout is the stock example, per economist Paul David). It is why a "temporary" pilot can become a de facto standard, and why this audit reads the non-technical pathways where such lock-in quietly forms. ↩