When the enterprise starts behaving in ways nobody intended, who knows, who decides, and what stops?

MOM-305 is the Micro Operating Model for operating risk. It gives an enterprise the architecture to detect trouble, see what can spread, contain it, decide with settled authority, and recover the way it operates, not only the systems it runs on. A kill switch is one action inside it.

MOM-305 is in design. The demonstration uses a fictional company and illustrative data.
NORMAL→ELEVATED→CRITICAL→CONTAINMENT→RECOVERY
THE SHIFT

Intelligence is becoming abundant. Interactions multiply faster than components.

Enterprises will soon run thousands of models, agents and AI-enabled applications, on top of the applications, infrastructure, data, vendors and people already there. All of it will interact continuously.

Nobody adds interactions on purpose. They arrive with every new component, and they grow much faster than the components do.

Every complex system eventually reaches a point past which it cannot be understood, predicted or steered in time. Monitoring, committees and human supervision still exist beyond it, but they no longer see enough, fast enough. BlueHour calls this the Complexity Ceiling.

Nobody can say exactly where that point is for a given enterprise, and we do not pretend to. What can be measured is the direction of travel, process by process. Complexity Ceiling Management, MOM-304, helps determine when the system is approaching its operating limits. MOM-305 determines what the enterprise does about it.

4 components · 6 interactions 8 components · 28 interactions 16 components · 120 interactions
Each line is a possible interaction. Doubling the components roughly quadruples the ways they can affect each other.
FAILURES PROPAGATE

A local event becomes an enterprise event

The danger is not that a model gives a bad answer. It is that a small action travels. It reaches a system nobody had mapped as connected, other agents act on what it changed, and an hour later the problem is somewhere else entirely.

It works like debris in orbit, where each collision makes the fragments for the next. Sometimes the cause is an interaction nobody designed, anticipated or can easily explain afterwards. We call that a Black Pterodactyl.

By the time anyone sees it, the question is no longer which system failed. It is what the enterprise should stop, what it must keep running, and who decides.

That is an operating model problem, not a technology problem. It needs an operating model answer.

Small disturbanceOne action outsideits boundaryPropagationIt reaches a systemnobody mapped as connectedAmplificationOther agents act onwhat it changedCascadeThe cause isno longer obviousEnterprise impactCustomers, cash, theledger, the regulator
THE ENGINEERING PROBLEM

Stopping AI is easy. Knowing what to stop is the engineering problem.

Any vendor can sell you an off switch. The hard part is knowing what to stop, what must continue, who has the authority to decide, and how the enterprise safely recovers. That is the problem MOM-305 is engineered to solve, and it cannot be solved during the event. It has to be designed before it.

OPERATING STATES OF THE ENTERPRISE

MOM-305 runs the enterprise in five operating states. They are states of the whole enterprise, not AI risk levels. In each one, the architecture and the decision rights change.

STATEWHO DECIDESWHAT THE ARCHITECTURE DOES
NORMALEach class owner, for their own agentsBoundaries enforced automatically, one action at a time
ELEVATEDClass owner, with the risk owner informedThe affected class is narrowed. Everything else runs.
CRITICALA named incident owner, usually the COOFreezes and payment holds become available. Exposure goes to the CFO.
CONTAINMENTThe incident ownerThe problem is isolated. Named critical operations keep running.
RECOVERYThe incident owner, handing back to class ownersComponents restored, then the operating model verified before sign-off

The demonstration lets you move a fictional insurer through all five and watch the exposure, the authority and the allowed actions change. Open the operating states →

Know what can spreadEvery agent class, what it may do, what it touches, and which dependencies carry a problem from one place to another.
Name what must keep runningCritical operations named in advance, so containment isolates the problem and leaves claims, customers and cash flowing.
Intervene in proportionCorrect one action, constrain a class, freeze it with an expiry, or disable it. Stopping a class is one intervention among several.
ACCOUNTABILITY IN THE LOOP

A human watching is not governance

HUMAN IN THE LOOP

Puts a person in the process.

ACCOUNTABILITY IN THE LOOP

Gives someone the authority, the information and the responsibility to act.

MOM-305 names that person for every agent class and every operating state, before the event. During it, the CEO and the Board get straight answers to eight questions.

What happened?
What is happening now?
What could it cost us?
What can propagate?
Who has authority?
What can we stop?
What must we protect?
What is the safest path back to controlled operation?
CAPITAL GLASSES

Risk decisions are also capital allocation decisions

THE CONVENTIONAL QUESTION

How do we stop the dangerous thing?

THE BLUEHOUR QUESTION

What intervention produces the lowest total enterprise harm?

Sometimes the answer is to stop an agent. Sometimes it is to isolate a workflow, or to hold 212 transactions while 4,100 legitimate payments proceed. Sometimes the greater risk is the shutdown itself.

In the demonstration, a procurement agent edits 212 payee records it should never have touched. $1.9M of payments are tied to them. The next payment batch runs in 34 minutes.

STOP ALL PAYMENT RELEASE
$6.1M delayed

4,300 claimants paid late to protect 212. Claims, cash and customers all take the hit.

MOM-305 CONTAINMENT
$1.9M held

The 212 payments are held. $4.2M is paid on time to about 4,100 claimants. Total cost: about $18K in late-payment interest.

The safest system is not the system that can stop everything. It is the system that knows what not to stop.

The objective is not maximum shutdown. It is minimum total enterprise harm while preserving controlled operation. So MOM-305 reports every state the way a CFO reads it: revenue and capital exposure, business interruption, customer and regulatory impact, reputation, time to recovery, and whether you still have the option to deploy the next model.

The purpose is not risk management for its own sake. It is to let an enterprise capture the economics of abundant intelligence without accepting operating risk it cannot see or control.

THE THREE CLOCKS

Every minute changes the economics

OBSERVE
How long until we know?
HALT
How long until it stops spreading?
RESTORE
How long until we operate as intended again?
THE DEMONSTRATION EVENT, MINUTE BY MINUTE OBSERVE18 m to knowHALT23 m to stop itRESTORE2 h 9 m to operate as intended again Payment batch runs T+018 m41 m60 m2 h2 h 50 m $1.9M at risk, still recoverable If not halted by now: $1.9M paid out, no longer recoverable

Halted at 41 minutes, the $1.9M is held. Halted after the batch at 60 minutes, it is gone and recovery becomes a legal matter. Delay does not add exposure in a straight line. It compounds.

Each clock is measured in drills, for every agent class, against what that process can absorb. The method is proposed rather than validated.

RECOVERY

Restore the components. Recover the operating model.

Systems back online is not recovery. Every component can come back and the enterprise still not work the way it did. We call that the Humpty Dumpty outage.

MOM-305 signs off recovery only when each of these is verified to be back within its intended boundaries:

AUTHORITY
Every class is back with its named owner, under any new conditions.
DEPENDENCIES
What talks to what is re-verified, not assumed.
WORKFLOWS
Held work is released in the right order.
ECONOMICS
The ledger reconciles and the actual cost is known.
BEHAVIOR
Each class operates inside its boundaries again, and the architecture changes so the event cannot recur the same way.
WHERE IT SITS

The agent is not the system

MOM-305 is one of sixty Micro Operating Models in the BlueHour60. It does not solve enterprise AI governance on its own, and nothing should. More intelligence requires more architecture, not less.

It starts after Capital Discipline, never before it, and it leans on the models around it.

See MOM-001, Capital Discipline →

MOM-001
Capital Discipline decides what you keep, and can place an uncontrollable class on HOLD.
MOM-304
Complexity Ceiling Management tells you when the system is approaching its limits.
MOM-305
Operating Risk decides what the enterprise does about it.
MOM-405
Truth Preservation keeps the record of what happened trustworthy.
MOM-303
Upboarding & Workflow decides which work agents take on, and how people move up.
MOM-508
Board Decisioning brings the exposure to the Board in terms it can act on.
WHAT IT TAKES TO START

Named owners, not a programme

MOM-305 is activated on top of MOM-001. From your side it needs standing roles, not a project team.

INCIDENT OWNER
Usually the COO. Holds authority once the enterprise reaches a critical state.
RISK OWNER
Sets the operating boundaries, the thresholds between states, and each process’s tolerance.
CLASS OWNERS
One named person per agent class, who can stop it and who decides when it resumes.
IT OWNER
Provides the credential and revocation paths, so stopping a class never depends on a vendor.

What you receive first: the inventory of every agent class and what it can reach, the decision rights for each operating state, and the first drill, which measures how long it really takes to observe, halt and restore. Scope and price are set at activation, from what MOM-001’s ledger shows you run.

PUT MOM-305 ON YOUR ROADMAP

MOM-305 is activated after MOM-001, Capital Discipline. Authority is designed before the event, not negotiated during it. See what could propagate in your enterprise.

A note on where we are: MOM-305 is in design. The demonstration is built on a fictional company with illustrative data, because we will not show you another client’s numbers, and because we will not show you measurements we have not yet taken. The architecture and the method are ours.