Skip to content

Practitioner Counterfactual Walkthrough

Method — instantiates Workaround Governance

A case-based, step-by-step comparison of the official path against the workaround, walked with the practitioner, to reveal the demand the deviation answers and the function it supplies.

Why does the workaround keep winning? A Practitioner Counterfactual Walkthrough answers that by walking a single real case twice, side by side: here is what the official procedure requires at each step, and here is what actually happened. Its defining instrument is the counterfactual — at the point where the two paths diverge, the practitioner is asked what would have happened had they followed the official route (the treatment delayed, the record lost, the customer dropped), and what the deviation actually delivered instead. The method's product is a precise diagnosis of the demand — the specific latency, gap, or exception the official path fails to meet — together with the legitimate function the workaround preserves. It is a magnifying glass, not a courtroom: one case, closely read, that turns "people are non-compliant" into "the official path takes forty minutes the situation does not have."

Example

In a security operations center, an analyst used a shared administrator credential to contain a ransomware outbreak instead of requesting individually approved access. Rather than write it up as a policy violation, a governance analyst runs a Practitioner Counterfactual Walkthrough on that exact incident. Step by step, they lay the official path — open an access request, wait for a manager and a security approver, receive scoped credentials — against what happened: the analyst grabbed the shared account and isolated the infected segment in ninety seconds. At the divergence point they ask the counterfactual: had you followed the official path, what happens? The answer is concrete — the approval chain averaged twenty-two minutes in the last quarter's incidents, and the ransomware spreads laterally in under five. The walkthrough surfaces the demand (containment latency the approval process cannot meet) and names the function to preserve (sub-five-minute privileged action during an active incident). It does not decide what to do — but it hands the disposition a sharp, evidenced statement of exactly what any acceptable route must deliver, so nobody proposes "just ban the shared account" without a replacement that hits the latency target.

How it works

  • Anchor on one real case. The method works a specific, recent instance in detail rather than debating the workaround in the abstract — the concrete case carries evidence the general argument cannot.
  • Lay the two paths in parallel. Official procedure and actual practice are written step for step, so the exact divergence point is visible rather than assumed.
  • Ask the counterfactual at the fork. "Had you followed the rule here, what would have happened?" — the answer names the harm the deviation averted and the demand the official path missed.
  • Extract demand and function separately. The output distinguishes why the official path lost (the causal demand, e.g. latency) from what must be kept (the legitimate function, e.g. fast containment), because a disposition needs both.
  • Predict, don't just describe. A good diagnosis says when the workaround will reappear and what a fix must achieve to remove the pressure — a testable claim, not a story.

Tuning parameters

  • Case selection — a typical instance versus an extreme one. Typical cases characterize the routine demand; extreme cases expose the exception the rule never anticipated. Choosing only flattering cases biases the diagnosis.
  • Counterfactual depth — stopping at the first divergence versus tracing downstream consequences. Deeper tracing catches second-order harms but costs time and invites speculation.
  • Practitioner framing — collaborative reconstruction versus interrogation. Collaboration yields candid detail; an accusatory tone yields defensive rationalization.
  • Number of cases — one deep walkthrough versus several. More cases distinguish a stable demand from a one-off, at proportional effort.
  • Function-abstraction level — naming the function narrowly ("this shared account") versus generally ("fast privileged action"). Too narrow blocks better replacements; too general loses the real constraint.

When it helps, and when it misleads

Its strength is that it produces the evidenced constraint every downstream disposition needs: a specific demand and a named function, grounded in a real case, so replacement and redesign aim at the actual pressure instead of at the symptom. It reliably converts a compliance framing into a design problem.

Its central failure mode is mistaking the practitioner's rationalization for a safety case — a workaround can be entirely rational from the operator's seat and still be unacceptable in its downstream or aggregate risk, and a walkthrough that only elicits the user's view will make the deviation look justified because, locally, it is. This is the gap between work-as-imagined and work-as-done[n1]: the method is superb at recovering work-as-done, but "it makes sense from here" is a diagnosis of demand, not a verdict on acceptability. The classic misuse is treating a compelling walkthrough as authorization to continue. The guarding discipline is to hand the diagnosis out — to distributed benefit-risk classification and failure-mode review, which weigh the harms the practitioner's vantage cannot see — and to keep the walkthrough's job to explaining the demand, not blessing the practice.

How it implements the components

This method fills the diagnostic front of governance — understanding the deviation before anyone disposes of it:

  • causal_demand_diagnosis — the parallel walk with a counterfactual at the fork is the diagnosis: it isolates the specific latency, gap, or exception that makes the official path lose, and predicts when the workaround will recur.
  • benefit_preservation_requirement — by asking what the official path would have cost, the walkthrough names the legitimate function the deviation supplies, stated as a requirement any acceptable replacement must meet.

It does not protect the disclosure or assign the decision owner (nonretaliation_and_learning_boundary, disposition_owner_and_contestability_path — those belong to the Nonpunitive Workaround Review); the walkthrough is a diagnostic method, not the protected decision forum.

Editorial Notes

Form Classification

Form family: Communication, Facilitation & Learning

Rationale: The mechanism walks official and actual paths step by step with the practitioner and elicits the counterfactual harm and function at the divergence.

Nearest alternative: Assessment, Review & Assurance — The case yields diagnostic evidence, but direct facilitated inquiry with the practitioner is primary.

Review outcome: Adjudicated after independent review; high confidence.

Origin Attribution

Primary origin: Ethnography & Qualitative Methods

Origin pattern: Cross-disciplinary synthesis

Present-day reach: Multi-domain

Rationale: Walking an official process and workaround with the practitioner is grounded in contextual inquiry and qualitative fieldwork.

Related originating lineages:

Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.

Review outcome: Independent reviewer agreement; medium confidence.

Notes

[n1] Work-as-imagined versus work-as-done — Erik Hollnagel's distinction (central to Safety-II) between how procedures assume work happens and how it actually unfolds under real constraints. Workarounds live in the gap between the two; a counterfactual walkthrough is a disciplined way to recover work-as-done without treating the gap as automatic proof the deviation is safe.