STO·PATH · The STO Management Platform + STO·CORE · The STO Management System
STO·PATH is the software your shutdown, turnaround, and outage program runs on, from the ten-year plan down to the person who owns one deliverable this week. The work process is its spine. Around that spine it carries the plan’s economics, the governance forums and their decisions, the risk register, every open action, and the lessons that make the next event better. STO·CORE is the best-practice standard it deploys.
Own the standard. Run it in software.
The problem
Sites run forty-day events on ten-year cycles with tools that see neither end: the long-range plan lives in a spreadsheet, the work process lives in a binder, the decisions live in minutes nobody reopens, and the lessons live in whoever happened to be there. Four failures hide in that gap.
The ten-year plan is a spreadsheet with dates in it. Nobody can say what a five-year cycle does to annual cost, where the inspection ceiling stops the stretch, or what the board approved and when.
A binder and a countdown spreadsheet do not assign the activity, date it from T0, or hold a gate until the accountable person decides on the record. The process and the event drift apart.
Steering meets, decides, and moves on. Six weeks later nobody can say what was agreed, who agreed it, or whether it was ever meant to be revisited, so the same argument runs twice and the risk register quietly ages out.
Preparation runs one to two years; a lessons meeting at the end reconstructs it from fading memory. Actions get minuted, filed, and rediscovered as the same surprise next event.
Plan the decade · before any of this
Every unit and event across every site on one timeline, and underneath it a real model: what the cycle costs per year in real terms, what a longer interval would cost once scope growth and reliability are priced in, and which constraint actually binds. Scenarios end in a recorded decision, not a new spreadsheet tab.
Fiscal-year cashflow, replacement-value and complexity-adjusted benchmarks, and a board report ride the same engine · a dedicated long-range planning one-pager covers this in depth
What it does
It governs what happens, when, who owns it, and what gets approved, then carries the decisions, risks, actions, and lessons that grow around it. Detailed scope-level scheduling stays with your planners.
The work process, deployed to a real event with a real team on it, and held to.
Your work process is a versioned template your company controls, not a vendor’s black box. Start from the STO·CORE master, import the process you already run, or build one, then edit every activity, role, gate, and date. No change request to alter your own standard.
A built-in complexity calculator recommends the tier, then the whole countdown calendarizes from your execution start date. A small event gets a compressed front end, a mega event the full runway. Each deployment is an editable copy the site team adjusts without touching the company standard.
Every activity has a named owner. One with a key deliverable cannot be submitted without evidence, cannot close without the accountable person’s approval, and a gate closes only through a recorded decision. Nothing is silently changed; it all lands in an append-only audit trail.
The Drift report shows exactly how a running event diverged from its template. When a change is worth keeping, promote it into a new version of the company standard in one step. One event’s experience becomes the next event’s starting point.
Roll up compliance by role, person, and phase with gate status and pending approvals, and export the whole board to Excel for the meeting. Event-driven email keeps owners and approvers moving without anyone chasing them.
The three forums that actually steer an event, run as a system rather than a calendar invite.
Each forum is a recurring series with a question-form agenda and a context dashboard built from live data: what moved, what is escalated, what is owed. Every meeting opens on the same ritual. Approve the last minutes, walk their still-open actions, and revisit the decisions past their revisit-by date.
Record the room if you want to, disclosed and started by the facilitator, and the transcript drafts the minutes. Decisions, actions, and risks are proposed, never assumed: the facilitator accepts, edits, or dismisses each one. Approval freezes the minutes, turns proposed decisions into agreed ones, and sends them out.
Every decision carries who agreed it, when, in which forum, and when it should be looked at again. Superseding one requires naming its replacement, so the register can never quietly contradict itself. Decisions due a revisit come back onto the agenda by themselves.
An evergreen register with the heartbeat enforced, and contingency that comes off it.
Scoring runs on your own risk matrix, uploaded in whatever form it exists today and read into the tool, including matrices that do not score a cell as a simple product. Risks are written as cause, uncertain event, and effect, and the coach helps shape a vague one rather than refusing to save it.
Every risk has one named owner and a review-by date keyed to its severity, tightened once the execution window opens. Mitigations are real actions in the same spine, not prose in a cell. A risk that reaches its date untreated forces an explicit, recorded acceptance rather than quietly aging out, and gates hold for a register pass.
Quantified risks size the event’s contingency two ways, both stated: expected value per AACE 44R-08, and a simulated band on the risk-driver method of AACE 57R-09, the practice GAO-16-89G describes. Remove-one analysis ranks which risk is buying the most contingency, so the number is arguable rather than asserted.
The decision register, the risk heartbeat, and register-driven contingency are covered in depth on the governance, decisions and risk one-pager.
The half of lessons learned that everybody skips: capture during, not after.
One box, on the activity you are standing on, typed or spoken. The event, phase, and category fill themselves in. Attributed by default, anonymous when it needs to be. A register opened at closeout is reconstruction; this one is a record.
A lesson resurfaces on the next event’s copy of the same work-process activity, in front of the person about to do that job. When a lesson echoes one from a previous event that was never actioned, the platform says so, which is the finding that actually changes behaviour.
One action spine for the whole organization: gate conditions, meeting commitments, lessons actions, preparation tasks. One named owner, never a committee. Re-dating after the first due date requires a recorded reason, verified is its own state, and the owner cannot verify their own action. A next-event action lands as a real activity in that event’s plan.
Run · the deployed event
The complexity calculator scores the event and recommends the tier. PATH copies your template, calendarizes every activity from your execution start, and opens the board: named owners, ready-to-start flags, out-of-sequence warnings. The site team owns its copy, and improvements promote back into the company standard. No vendor change requests.
The accountability rail
Learn · the evergreen loop
Capture is attributed or anonymous, takes half a minute, and never waits for closeout: a gate cannot close until the phase’s lessons pass is confirmed. At closeout the register flows into the STO·LEARN workshop; what comes back is themes and owned actions. And the actions do not go to a binder: they land as activities in the next deployed event, resurface on the same activity that taught them, and systemic fixes promote into the standard itself.
Ask the platform
A standard nobody reads is a binder with a login. Every person on the event can ask the platform what a deliverable has to contain, why a gate exists, or what their own role owns this month, and get an answer grounded in two things only: your governing standard and your deployed plan.
It is the fastest way a new team member gets useful, and the reason your standard stops being a document people mean to read.
Where the boundary sits
Keeping it alive
A process only survives if people are reminded of it at the right frequency, and gets abandoned if they are reminded too often. Everyone gets one brief a week: what moved across the event, and what is theirs in the week ahead. Only the genuinely time-critical items, approvals waiting and anything overdue, interrupt the day.
The standard it runs on · STO·CORE
STO·CORE is the documented best-practice STO management system PATH deploys: a 43-document family from governance to closeout, companion working tools (scope challenge, probabilistic cost, contracting and packages, basis of schedule), and a 180-activity complexity-tiered work process, built on public-framework rigor and tailored to how your site actually works. The master ships in the tool; copy it, adapt it, and make it yours. Or import the process you already run and keep your house standard, now live and enforced.
License the management system and its complexity-tiered work process and countdown, tailored to your facility’s units, nomenclature, and event sizes. A documented program your team can run, not a binder that sits on a shelf.
A hands-on engagement to stand the system up and make it stick: deploy the work process, set the countdown and gates, assign accountability, and coach your people to run it without us.
At a glance
Built on public frameworks (DCMA, GAO, AACE, PMI) · tailored to your facility, never a shrink-wrapped download
Why us
STO·PATH runs on the same event spine as our assurance reviews, so the state of the work process and an independent read of the plan sit on the same event, not in two disconnected systems. That is the seam no closed tool can offer.
What you get
Named accountability on every activity, evidence-backed key deliverables, recorded gate decisions, a decision register with revisit dates, a risk register with a review heartbeat and register-driven contingency, one action spine, and an append-only audit trail. The levelized long-range plan with scenarios, a board-ready report, event and portfolio reporting, Excel export, the coach, and one weekly brief keep the whole program moving. Your team works in the STO·PATH client portal; we work beside you in the same system.
Deployable now, consultant-led. STO·CORE is delivered as a tailored engagement; STO·PATH runs it as the software you own.
What changes
Show us how you run turnarounds today. We will stand up your standard in STO·PATH, load your event history into the long-range plan, and walk your team through their first deployed event.