The Constraint Capture Matrix


Finding a bottleneck is not the same thing as capturing it.

Every technology cycle creates the same illusion. Leaders locate the friction point in their industry, buy software to address it, and expect market share to follow. The historical pattern says otherwise. Some companies convert that diagnosis into a multi year moat while others just automate their existing limitations.

In The Strategy Isn’t Wrong. The Clock Is., I argued value migrates to whichever constraint is binding at a given moment. In The Scarce Thing, we saw what happens when that constraint becomes permission. Diagnosing a bottleneck tells you where value is trapped. It tells you nothing about whether your organization can actually claim it.

Two independent variables decide that. Does the organization control the constraint, and has it built the authority to act on that control? Advantage doesn’t come from finding the next constraint, your competitors will see it too eventually. It comes from controlling the constraint and redesigning the permission structure to act on it. The final scarce resource is authorized action.

Control vs. Authority

Constraint control is the control surface. A company rarely owns a bottleneck outright, regulators own rules, payers own reimbursement, markets own capital costs. What a company can build is the specific point where it can influence the outcome without controlling the entire system. High control means the deciding variables sit inside your software, your balance sheet, your data, your infrastructure. Low control means clearing the bottleneck requires independent third parties, regulators, licensing boards, platform monopolies, to move together.

Execution authority is the permission structure, an organizational choice to delegate action without a human calendar queue. It requires runtime verification, pre audited risk bounds, and clearing the liability traps that make managers hoard sign off. Most AI transformations don’t stall for lack of use cases. They build intelligence systems inside organizations still running on human speed permission.

Four positions follow from these two axes. Quadrant 1, Default Capture, high control and high authority. Quadrant 2, the Sunk Cost Engine, high control and low authority. Quadrant 3, the Fragile Velocity Trap, low control and high authority. Quadrant 4, the Dependency Trap, low control and low authority. Companies move between them along recognizable paths: control without new authority takes you from Quadrant 4 to 2, authority without control takes you from 4 to 3, securing a control surface over your dependencies moves you from 3 to 1, and replacing manual queues with real permission architecture moves you from 2 to 1.

This matters now because AI compresses the cost of insight faster than organizations can redesign around it. The bottleneck is moving from generating answers to authorizing actions. The companies that win won’t necessarily have the best models. They’ll have the shortest path between machine insight and business execution.

The Four Quadrants

Quadrant 1 is the target state. Amazon Logistics is canonical. Delivery reliability, not inventory selection, became the real promise to the customer, and third party carriers were a bottleneck Amazon couldn’t dictate. By building its own fulfillment centers and last mile fleet, Amazon built the control surface itself, and every routing improvement compounded into its moat. Credit unions like FORUM, Centris, and Del-One did the same thing in lending. Underwriting guidelines and software sat inside their own walls, so they controlled the constraint, and granting execution authority to pre audited, bounded transactions turned that into a 70% jump in processing capacity, the case covered in The Scarce Thing.

Quadrant 2 is where most enterprise technology budgets die. In corporate procurement, AI can ingest contracts and draft renegotiated terms in seconds, fully within the company’s control. CFOs still refuse to delegate execution, a rational response until machine agency liability is settled in court. The system drafts faster. A human still signs everything.

Quadrant 3 is speed without ownership. Marcus by Goldman Sachs built genuine machine speed underwriting, real authority by any definition, on top of an economic foundation it didn’t control. A new accounting rule, CECL, forced far more aggressive loss reserving just as rates made the loan book more expensive to carry. Worth repeating the honest caveat here rather than dropping it: some of the loss likely traces to underwriting quality itself, Goldman’s card loss rate ran above peer issuers, which is an execution problem, not a control problem. Both can be true. Quadrant 3 doesn’t require a company to be blameless, only that part of the outcome trace to a constraint it never controlled, and here it does.

Pear Therapeutics belongs here too. Its software tracked and adapted treatment for substance use disorder without clinician micromanagement, real authority over the clinical action itself. What it never had was control over the constraint that decided its fate, CMS and commercial payers never assigned a reimbursement code that made the product viable at scale. Pear cleared the hard regulatory hurdle and still had no leverage over the variable that actually mattered.

Quadrant 4 is the default posture of most regulated industries, because it takes no decision to end up there. Traditional prior authorization is the clearest case. AMA surveys consistently find the overwhelming majority of physicians say it delays necessary care, and most of the industry still runs on fax and phone holds on both sides. No one owns the reimbursement rules, and no one built software to act quickly within them either. It’s the quadrant every other example in this chapter started from.

Cohere Health vs. Olive AI

Both companies attacked prior authorization from Quadrant 2. Olive AI raised over $900 million to a $4 billion valuation using robotic process automation to fill out payer web forms faster. It automated the paperwork, not the authority, hospital staff still verified and submitted every request, because Olive had no integration into payer decision engines. It shut down in October 2023, selling its prior authorization unit to Humata Health. In fairness, overexpansion and a burn rate above $100 million a year played a real part too, not every dollar of that failure is a pure Quadrant 2 story. But the core pattern holds.

Cohere Health partnered directly with Humana in 2021 to embed the payer’s own coverage policies into its platform at the point of care. Median approval time on musculoskeletal requests dropped to zero minutes, with 89% approved for immediate scheduling. The partnership is now nationwide, and Cohere reports real time approval on up to 85% of documented submissions. Olive optimized Quadrant 2. Cohere built a new control surface and moved to Quadrant 1.

Beyond AI

This move predates artificial intelligence. Apple built the App Store’s review and payment architecture into an unassailable control surface over mobile distribution. NVIDIA built CUDA into a software layer that binds developers to its silicon. Tesla built the Supercharger network to remove a constraint utilities weren’t going to solve for it. Medtronic used FDA’s Predetermined Change Control Plan to pre negotiate future updates to its LINQ II monitor, turning a recurring regulatory toll into its own iteration schedule. Every one of these firms treated the binding constraint as something to be redesigned, not accepted.

The Guardrail and the Audit

Control and authority are necessary, not sufficient. A company can execute flawlessly inside a domain it fully controls and still fail if it misdiagnosed where scarcity actually lives. The matrix starts only after that diagnosis is right.

Before allocating capital, ask three things. Which quadrant does this initiative occupy now? Do you control the constraint, or are you building a Fragile Velocity Trap? And what organizational cover is keeping you in Quadrant 2, what would it take to authorize the bounded action instead of routing the whole system through a human queue?

Diagnosing the bottleneck tells you where value is migrating. The matrix tells you whether you’re actually equipped to capture it.

Intelligence Is Cheap. Permission Still Has to Be Built by Hand.


Toyota did not win the manufacturing wars of the 1980s because it had a better factory. American plants ran comparable equipment, comparable tolerances, often the same suppliers. Toyota won because it redesigned who had permission to act.

In the 1970s, Toyota gave line workers something most manufacturers would have considered reckless: the authority to stop the entire production line. The worker who pulled the andon cord wasn’t the most senior person in the building. They weren’t in a meeting with the plant manager. They were usually just the person standing closest to the defect, the one with the least formal power and the most immediate information. The andon cord was never a productivity tool. It was an authority architecture, a decision about who gets to act on what they see, without waiting for someone above them to see it too.

American manufacturers spent the better part of a decade copying the visible parts, the kanban cards, the quality circles, and mostly failed, because what they were copying wasn’t the actual advantage. The advantage was the redesigned permission underneath it, and permission doesn’t show up on a factory tour.


A Second Proof, Twenty Years Later

I’ve written before about Desktop Underwriter, the automated mortgage underwriting system Fannie Mae shipped in 1995. The value didn’t come from software that could evaluate a loan file faster than a human. Every competitor could eventually buy comparable software. The value came from what Fannie Mae attached to the system’s output: a waiver, relief from having to re-verify certain judgments the system had already made, provided a lender’s own data and documentation held up. That’s not automation. That’s an institution redesigning who could decide, who carried the risk when the decision was wrong, and how exceptions got handled, around a machine’s output.

Same mechanism, different industry, twenty years apart. The technology was necessary in both cases. It was never what got captured. What got captured was the permission architecture built around it, and I’ve called that capture Default Capture before: the winner is never whoever owns the technology, it’s whoever owns the constraint the technology creates downstream of itself.

AI is about to run the same test a third time.


The Question That Actually Matters

Most of the AI conversation happening in boardrooms right now is stuck on one question: can the model reason well enough to be trusted?

That’s the easy question, and the mortgage industry answered its version of it in 1995. The harder question, the one that actually determines whether an enterprise can act on what its systems produce, is different:

Can the organization allow the model to act?

Every technology transition creates a new abundance somewhere. The winners are never the organizations with the most of the newly abundant thing. They’re the ones that redesign permission around whatever became the constraint instead, before the market redesigns it for them, on someone else’s timeline.

That’s not a technology question. It’s the same question Toyota answered on a factory floor and Fannie Mae answered in a rulebook. Most enterprises haven’t answered it at all. They’ve bought the equivalent of the andon cord and left it bolted to the wall, unconnected to anything.


The Pilot Trap

Walk into almost any large enterprise right now and you’ll find the same three things: an enterprise AI license, a dozen point-solution pilots, and a Center of Excellence generating slide decks about theoretical time savings.

The demos are genuinely good. That was never the problem. The problem is that the company is putting a new engine into an old transmission. Every output still moves through the same approval chain built when the model needed supervision to be trustworthy. Every exception still follows the same escalation path designed for a system that used to be wrong a lot more often than it is now.

The model got dramatically better. The org chart didn’t get the memo. That gap is where the money goes to die, not in model cost, in the friction of an organization still authorizing decisions the way it did when authorization was the only safety mechanism available.

I don’t think this is a technology adoption problem. It’s an Organizational Rewiring Latency problem, and it’s a particularly nasty one, because unlike most of the shifts I’ve written about, this one doesn’t announce itself as a crisis. Nothing breaks. The pilots keep running. The demos keep landing well in the quarterly review. The company just quietly stays exactly as slow as it was before, with a much more expensive engine attached to the front of it.


The Blast Radius Problem

I’ve written before about the Law of Migrating Scarcity: when technology makes something abundant, value doesn’t disappear, it moves to whatever the abundance can’t dissolve. For decades, enterprise intelligence was that scarce resource, so companies built permission systems that assumed it would stay that way, slow, expensive, routed through whoever in the hierarchy had the most of it. Permission itself was never the scarce thing. It didn’t have to be. It only had to keep pace with a world where a decision moved as fast as the human hierarchy that had to bless it.

That world is ending. Models are commoditizing on schedule, the same way the underlying intelligence is, and the permission system built around its old scarcity is what’s left standing as the constraint. Permission isn’t becoming scarce out of nowhere. It’s being exposed as the bottleneck it was always going to become, the moment the thing it was rationing stopped being rare.

The advantage now belongs to whoever builds the clearest architecture for what a system is allowed to do without a person in the loop, and what still requires one. Within the decision and operational layers of that architecture, most companies still have exactly one lever: human review, on or off, applied uniformly regardless of stakes or track record. A usable version isn’t a single switch. It’s three tiers.

Tier 1, human-in-the-loop. The system recommends, a person decides before anything executes. High-consequence, low-frequency, hard-to-reverse decisions belong here, regulatory filings, large pricing exceptions, anything with real legal exposure attached.

Tier 2, human-on-the-loop. The system decides and acts, a person monitors and can intervene inside a defined window before the consequences compound. Most operational workflows land here once you’ve actually built some track record with the system.

Tier 3, human-out-of-the-loop, bounded. The system acts autonomously inside an explicit blast radius, a capped dollar amount, a reversible action, a pre-cleared category. A person audits the pattern, not the transaction.

Toyota never gave a worker unlimited authority. They could stop the line. They couldn’t redesign the factory, renegotiate with a supplier, or change the product roadmap. The authority had a blast radius, which is exactly what these tiers are designing. They’re a tool for two of the five layers I’ve written about before, decision permission and operational permission, not a replacement for the other three. A perfectly bounded Tier 3 can still fail if whoever audits it shares the same blind spot the system does, or if the outside world, regulators, customers, counterparties, never extends the market trust the internal architecture assumed it would have.

The actual design work isn’t picking a tier once and moving on. It’s the mechanism that promotes a decision from Tier 1 toward Tier 3 as the system earns trust in that specific domain, and demotes it the moment it doesn’t, the same kind of circuit breaker I’ve argued multi-agent systems need for cost, applied here to authority instead of spend. Almost nobody has built that mechanism.

Toyota’s cord and Fannie Mae’s rulebook both had an advantage this version doesn’t. A violation was visible. A worker could see a defect. An underwriting file either met the rule or it didn’t. A model that’s slowly drifting in quality doesn’t trip a wire, it just gets quietly worse, and the same review process built to catch it can end up sharing its blind spot, the exact failure I’ve written about in automated underwriting’s own verification layer. The promotion and demotion mechanism above only works if an organization can actually detect drift in a probabilistic system, and that detection problem is harder here than it ever was on a factory floor. Building a Tier 3 that looks bounded on paper without solving that problem first is how the blast radius stops meaning anything.

The reason this becomes a durable advantage, and not just a nice-to-have, is that permission architectures are hard to copy. A competitor can buy the same model. They can license the same software. They can hire the same consultants who hired the same consultants. What they can’t buy off the shelf is the accumulated trust, the operating data, and the specific decision boundaries that let one organization move with confidence while another is still in a meeting arguing about who has the authority to approve the meeting’s outcome.


What Autonomy Actually Costs When You Get It Wrong

It would be dishonest to make this argument without naming what it costs when it’s done badly. Expanding autonomy without a real governance mechanism doesn’t remove risk, it just changes its shape, from slow and visible to fast and compounding. A bad approval chain produces one bad decision at a time, and someone downstream usually catches it. A badly bounded Tier 3 produces the same bad decision at machine speed, thousands of times, before anyone notices anything’s wrong.

That’s not an argument against building this. It’s the argument for building it on purpose instead of drifting into it. The companies that get hurt in this transition won’t be the ones that moved too slowly on autonomy. They’ll be the ones that expanded it without a defined blast radius, without an audit trail, and without a name attached to who owns it when it fails. Tiering, bounding, and auditing is the whole difference between deliberate autonomy and an accident waiting for a headline.


Three Questions Worth Asking This Quarter

If you’re the one accountable for this inside your company, the diagnostic isn’t how many pilots you’re running. It’s:

Where does a decision still require a human sign-off purely out of habit, not because the stakes or the risk actually call for it?

For your highest-volume automated processes, do you have a defined blast radius and an audit mechanism, or just an on/off switch?

Who owns the outcome when a system acts on its own and gets it wrong, and do they know yet that it’s their job?

Toyota moved authority from headquarters to the factory floor. Mortgage underwriting moved authority from individual judgment to an institutional system. AI is going to move authority from human execution to bounded autonomous systems. The technology changes each time. The pattern underneath it doesn’t.

Most companies can’t answer the second or third question today. That gap, not model capability, will separate the companies that become the default this decade from the ones that spend it running increasingly sophisticated pilots.

Where scarcity goes when it leaves


A few weeks ago I wrote that boards are treating AI intelligence as a permanently scarce, permanently expensive input, and that this assumption is already cracking. A few people asked me a fair follow up question. If intelligence stops being the scarce thing, where does the scarcity actually go. It doesn’t just vanish. Someone always ends up holding it.

I have watched this happen up close twice in my own career, and I know a third example only from history, but it is the cleanest one to start with because you can actually see the migration happen.

The first time was containers. Malcolm McLean did not invent a faster ship. He invented a standard box, and that box made loading and unloading cargo dramatically cheaper. Everyone assumed the story was over once ships stopped idling in port for a week at a time. It wasn’t. Ports suddenly needed acres of land to stack containers. Rail lines had to sync up with ship schedules. Crane operators and terminal planners became more valuable than the stevedores whose jobs the container had just eliminated. The scarcity did not disappear when loading got cheap. It walked a few hundred yards down the dock and set up shop in land, rail and coordination.

The second time was the shift from FTE pricing to outcome pricing in IT and BPO, which is a conversation I have had more times than I can count over the last two years. For a long time, the constraint looked like headcount. You needed bodies to run processes, so you priced by the body. As automation and now agentic AI made raw execution cheaper, everyone assumed the constraint would just dissolve along with the headcount. It didn’t, because the bottleneck was never just labor. It was the entire system built around buying, measuring and governing labor. Procurement teams that are set up to negotiate FTE contracts are, frankly, not set up to negotiate outcome contracts, and it isn’t only because procurement is slow. When a workflow runs through a mix of human teams, vendor agents and enterprise software, agreeing on who actually caused a given outcome is a genuinely messy problem, not just a paperwork one. Finance teams that know how to forecast a headcount ramp don’t automatically know how to forecast a variable outcome fee they can’t cleanly attribute in the first place. That system, not the labor it was built to manage, is the thing that is actually scarce right now. I said back in February that this is exactly why Khosla’s five year timeline for IT and BPO extinction won’t hold. Enterprises are slow to redesign the muscle that buys and governs work, and rebuilding that muscle takes a lot longer than swapping the underlying technology.

The third time is AI, and we are living through the early innings of it.

The public conversation is entirely about model capability. Whose benchmark is better this month, whose inference is cheaper, whose context window is longer. That is the visible layer, and it is genuinely moving fast. But if you sit in enough steering committee meetings, as I do, you notice the real conversation has already shifted somewhere else. Nobody is asking whether the model is good enough anymore. They are asking who is accountable when an agent acts on its own, how you audit a decision a model made six tool calls deep, and whether legal and risk can sign off before the business quarter ends. Legal, risk and compliance are quietly becoming the functions that decide how fast AI actually ships, not engineering. And this isn’t only a soft, organizational story either. I wrote back in February that Jevons paradox is still very much alive in AI, cheap intelligence doesn’t shrink total demand, it multiplies the number of things people try to do with it. That multiplication is what’s straining power grids and chip supply right now, and it will keep straining them. The bottleneck isn’t only moving into legal’s inbox. It’s splitting, part of it lands on governance, part of it lands on the physical world’s ability to keep up.

That is the pattern, and it holds across all three examples. When something that used to be the bottleneck becomes cheap, the constraint does not evaporate. It relocates to whatever has to absorb the new abundance. Land and rail after containers. Contracts and procurement after outcome based pricing. Governance and organizational readiness after intelligence.

I want to be honest about where this framework is weaker than it sounds. It is easy to find three examples that fit a pattern after the fact. The real test is whether it predicts anything, and whether there are cases where it breaks. It does break sometimes. The cloud is actually the interesting counterexample here, not the confirming one. When compute got cheap, the constraint should have moved to independent architecture and security specialists. Instead, the hyperscalers largely built and sold that layer themselves. AWS didn’t watch a market of third party cloud governance firms spring up and capture the value, it built Control Tower and Security Hub and kept the margin in house. The incumbents who already controlled the abundant layer often reach up and grab the scarce layer too, they just do it slower than a scrappy new entrant would. Call it the adjacent ownership problem if you want a name for it.

But I don’t think AI plays out quite the same way, and it’s worth being precise about why. AWS could absorb cloud security because cloud security is still fundamentally tooling, dashboards, policies, audit logs, things a vendor can build and sell. Frontier labs can absorb model guardrails the same way, and several of them are trying to. What they cannot absorb is the thing sitting underneath the tooling: whose name is on the regulatory filing, who eats the liability when an agent makes a bad call, who signs the indemnity clause. That layer doesn’t move to the vendor no matter how good their safety tooling gets. It stays inside the enterprise. So the AI version of this migration may actually be more durable than the cloud version, the technical guardrails can be commoditized by whoever owns the model, but the accountability cannot be outsourced the same way. Though I’d bet even that has a shelf life. The moment someone figures out how to price and package agentic risk the way insurers price everything else, that liability becomes securitizable too, and the scarce resource quietly becomes actuarial expertise instead. Scarcity doesn’t stop migrating just because it hit an enterprise’s balance sheet. And I should be honest that this bottleneck doesn’t always slow things down the tidy way a land shortage slows down a port. Sometimes a business unit just routes around legal entirely, the way shadow IT always found a way around IT, and what looks like delay from the boardroom is actually unowned risk quietly accumulating somewhere nobody is tracking it yet.

So if you are trying to figure out where value is actually migrating in your own AI strategy, the technology roadmap is the least useful thing to stare at. Watch where the friction is showing up instead. Watch which meetings in your company have gotten longer, not shorter, since AI arrived. Watch which job titles didn’t exist eighteen months ago and are now impossible to hire for fast enough. Watch whether your procurement team can even write a contract for an outcome nobody has priced before.

The technology tells you what just became possible. The friction tells you where value is about to accumulate. And the companies that win the next few years will not be the ones who called the breakthrough early. They will be the ones who noticed where the scarcity went after it left.