Resilience Planning Workshop¶
Facilitated workshop — instantiates Resilience Capacity Building
Gathers the people who run and depend on a system into one room to map which functions must survive a shock, what could threaten them, and where the hidden dependencies lie.
A resilience program cannot protect what it has never named. Resilience Planning Workshop is the front-of-pipeline diagnostic session that turns a diffuse sense of fragility into three explicit, shared artifacts: a ranked map of the functions that must survive, a shortlist of the shocks that could threaten them, and a diagram of the dependencies that would break together. Its defining move is that it produces the maps — it does not test decisions, rehearse an evacuation, or write the standing plan. It exists because the knowledge needed to see a system's fragility is scattered across silos: the facilities lead knows the building, the IT lead knows the servers, dispatch knows the phones, and no single one of them can see that all three ride the same fiber path. Put them in a room and that hidden coupling becomes visible before a storm makes it visible for them.
Example¶
A mid-sized city convenes department heads — public works, the utility liaison, 911 dispatch, IT, and communications — for a one-day workshop ahead of hurricane season. They start by listing lifeline functions and ranking them by consequence of loss: emergency dispatch and water treatment are must continue; permit processing can go dark for a week. Then they generate shock scenarios not to predict the future but to stress assumptions — a 72-hour grid outage compounded by street flooding, and a separate "loss of the primary data center" case. Tracing dependencies, they discover that 911 dispatch and the flood-prone data center share a single fiber run through a low underpass. Nobody had ever drawn that line.
The output is small and consequential: a ranked critical-function map, three scenarios, a dependency diagram with two single points of failure circled in red, and a gap list. None of it is a plan yet — it is the raw material the continuity and recovery plans will be built from, and the fiber single-point-of-failure is already on the capital-works list by the end of the day.
How it works¶
- Convene across the silos. Bring the people who each hold one slice of the system's fragility, plus a facilitator whose only job is to make the tacit explicit.
- Name and rank the functions. List what the system does and sort by consequence of loss — must-continue, may-degrade, can-wait — so later effort is spent where loss actually threatens viability.
- Generate shocks, don't forecast them. Produce a handful of plausible disruptions chosen to reveal hidden assumptions about scope, duration, and correlated failure, not to guess the next headline.
- Trace the dependency web. Follow each critical function down to what it silently relies on, hunting specifically for shared and hidden couplings.
- Capture durable artifacts. Leave with the map, the scenarios, the dependency diagram, and a gap list owners can act on — not a memory of a good discussion.
Tuning parameters¶
- Participant breadth — the core operators only, or the full cross-functional set including outside dependencies. Wider rooms surface more hidden coupling but cost more calendars and can dilute focus.
- Scenario ambition — a few deep scenarios or many shallow ones. Depth exposes second-order effects; breadth covers more of the possibility space but skims each.
- Facilitation mode — divergent (brainstorm every function and threat) versus convergent (ruthlessly rank and prune). Too divergent and you drown in a wish-list; too convergent and you miss the odd shock that matters.
- Output fidelity — a whiteboard photo or a maintained, versioned artifact. Higher fidelity feeds the downstream plans cleanly but takes real authoring effort.
- Refresh cadence — one-off or a standing seasonal review. A map is a perishable good; dependencies change quietly between sessions.
When it helps, and when it misleads¶
Its strength is that it makes invisible, cross-silo fragility explicit and shared — the coupling no single owner can see becomes a line on a diagram everyone now agrees on. It is the cheapest possible way to stop protecting the wrong things.
Its central distortion is the availability heuristic: the room maps the disaster it remembers most vividly — usually the last one — and under-weights the shock it has never lived through, so the scenario list quietly re-fights the last war.[n1] Its other failure is subtler and is the archetype's signature trap: a workshop that produces a handsome binder and no downstream capacity is resilience theater, a map with no territory behind it. The discipline that guards against both is to force at least one unfamiliar or deliberately correlated shock onto the list, and to treat the workshop as the opening of the pipeline — every artifact it produces must be handed to a mechanism that acts on it, or the session was decoration.
How it implements the components¶
Resilience Planning Workshop fills the mapping side of the archetype — the diagnostic artifacts everything downstream consumes:
critical_function_map— its central output: the list of functions ranked by consequence of loss, so protection is aimed at what actually threatens viability.shock_scenario— the shortlist of plausible disruptions, chosen to surface assumptions about scope, duration, and correlated failure rather than to forecast.dependency_map— the traced web of what each critical function silently relies on, with shared and hidden couplings flagged.
It draws the maps but does not act on them: it does not set the minimum service to hold or the trigger to invoke a response (continuity_threshold, activation_rule, communication_channel_plan — the Business Continuity Plan), does not stage the resources to restore function (recovery_resource — the Disaster Recovery Plan), and does not build or own capacity (adaptive_capacity, resilience_governance_owner, incident_learning_loop — the Emergency Preparedness Drill and Community Resilience Program). A tabletop pressure-tests decisions against a scenario; this workshop produces the scenario and the map in the first place.
Related¶
- Instantiates: Resilience Capacity Building — the workshop opens the pipeline, producing the maps the plans, drills, and programs are built on.
- Sibling mechanisms: Business Continuity Plan · Disaster Recovery Plan · Emergency Preparedness Drill · Community Resilience Program · Tabletop Exercise · After-Action Review
Editorial Notes¶
Form Classification¶
Form family: Communication, Facilitation & Learning
Rationale: Resilience Planning Workshop operates as a designed message, facilitated interaction, ritual, or learning activity that changes shared understanding because it gathers the people who run and depend on a system into one room to map which functions must survive a shock, what could threaten them, and where the hidden dependencies lie.
Independent corroboration: The frozen evidence defines Resilience Planning Workshop as 'Gathers the people who run and depend on a system into one room to map which functions must survive a shock, what could threaten them, and where the hidden dependencies lie', so its operative form is Communication, Facilitation & Learning.
Review outcome: Independent reviewer agreement; high confidence.
Origin Attribution¶
Primary origin: Disaster Management & Risk Reduction
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Multi-domain
Rationale: Facilitated mapping of critical functions, threats, and hidden dependencies is a business-continuity and disaster-planning practice.
Related originating lineages:
- Organizational & Management Science — Cross-functional facilitation materially supports ownership and operational planning.
- Systems Thinking & Cybernetics — Systems mapping supplies dependency and survivability analysis.
Review resolution: Both blind reviewers agree that disaster_management is the primary historical origin. Explicit reconciliation of alternate origin disagreement, origin mode disagreement adopts reviewer_a's evidence: Facilitated mapping of critical functions, threats, and hidden dependencies is a business-continuity and disaster-planning practice. The selected record uses alternates=organizational_management, systems_cybernetics, origin_mode=cross_disciplinary_synthesis, and domain_reach=multi_domain; the other review proposed alternates=military_strategic_studies, organizational_management, public_administration_policy, systems_cybernetics, origin_mode=convergent, and domain_reach=multi_domain. The selected combination better preserves the mechanism-specific formative lineages and calibrated scope; broader present-day use is not treated as proof of additional historical origin.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Reconciled after independent review; high confidence.
Notes¶
[n1] The availability heuristic (Tversky & Kahneman) — the tendency to judge an event's likelihood by how easily an instance comes to mind. In resilience planning it biases the scenario list toward vivid, recently-experienced shocks and away from the novel ones a map most needs to consider. ↩