Skip to content
STOIntelligence

Scope Development & Challenge

STO·SDC

Lean where it can be.
Complete where it must be.

A facilitated challenge of every discretionary item in the scope, run live with your team and their own risk matrix on the screen. Each item is tested the same way, priced where risk alone does not decide it, and given a disposition with the reasoning recorded. What comes out is a scope your team can defend at the gate, item by item.

Why it usually fails

Most scope challenges are theater.

A thousand-line list goes up on a screen. A room works through it for two days. The person who argues hardest keeps their scope, the person who is not there loses theirs, and everyone leaves with a list that is slightly shorter and no more defensible than the one they walked in with.

Ask three months later why a particular job was in, and nobody can reconstruct the reasoning. That is the real failure. Not that the wrong calls were made, but that no record exists of why any call was made, so none of them can be defended at a gate or learned from afterwards.

The fix is not a longer meeting. It is giving every item the same test, in the same order, with the reasoning written down as you go.

The reliability case

More scope is not safer scope.

Scope challenge gets resisted because it sounds like cutting corners. It is the opposite, and the failure-rate curve is the reason.

Equipment failures cluster at the beginning of a life and again at the end: an early-life region where assembly errors, seal and gasket failures, and contamination shake out, then a long stable middle, then a rising wear-out slope. Opening healthy mid-life equipment does not move it along that curve. It puts it back at the start of it, with fresh early-life risk carried straight into startup.

Which is why the goal is optimal scope, not maximum scope. Work belongs in the event where there is evidence of an active mechanism, not where the equipment is simply accessible.

Failure rate across an equipment life
RESTARTS THE CURVEhealthy equipment openedEVIDENCE OF WEAR:scope belongs hereEARLY LIFEUSEFUL LIFEWEAR-OUTFAILURE RATE

Every added intrusion carries its own early-life failure risk into startup. That is a cost of scope, and it belongs in the decision alongside the hours and the window.

Illustrative

The method

Every discretionary item takes the same two-stage test.

Required work is required and skips the challenge, though it is still logged. Everything else has to earn its place the same way, which is what makes the outcome comparable and the reasoning reconstructable.

01

The risk screen

If we do not do this work, what is the risk?

Every discretionary item is scored on your own matrix for the risk of leaving it undone. Score high enough and it is included on risk, no economics required. That is the easy half, and most scope challenges stop there.

Where it gets sharper

The half most people skip: we also score the risk if the work IS done. Where an item scores high but the proposed work does not actually reduce the risk, it does not get included on risk. Doing work that does not change the risk is not a reason to do the work, and until you record both numbers you cannot see the difference.

02

The mitigation ratio

Does the exposure it removes justify what it costs?

Where risk alone does not force the decision, the item is priced. What the failure would actually cost, weighted by how much more likely it becomes if the work is deferred, against what the work costs to do here and now.

Where it gets sharper

The cost of failure includes the production it takes with it, and not only in a full shutdown. A failure that cuts rate for three weeks is priced as a rate loss against that unit's own margin, because that is how it will actually be felt. One ratio, comparable across every item in the scope, so the room argues about inputs rather than opinions.

Scored on your matrix, not ours

The risk scoring runs on your own corporate matrix, in your own wording, with your own thresholds. Send it in whatever form it exists today, a spreadsheet, a procedure, or a photograph of the one on the wall, and it is read into the tool for your review before the session. Matrices that do not score cells as a simple product are honored as they are written. A team will not accept a scope decision made on somebody else’s definition of high risk.

The expert panel

A reliability challenge on every item, not just the ones someone thought to question.

No room holds deep expertise in fixed equipment, rotating, electrical, instrumentation and safety systems, heat transfer, operations, and civil at the same time. A panel built across all of them challenges each item alongside your people, working from curated reference material drawn from public standards and inspection practice.

The boundary, stated plainly

It coaches and challenges. It does not certify. It will not issue an integrity verdict, a safety-integrity determination, or a fitness-for-service call, and it is never a substitute for your inspection and reliability program. It sharpens your team’s challenge; your engineers still decide.

On each item it will

  • Names the failure mechanism the scope has not accounted for, given the equipment, its material, its service, and its temperature
  • Questions whether the proposed inspection method would actually find the mechanism being claimed
  • Surfaces the assumption worth testing before the room prices anything
  • Cites the public standard behind every point it makes, so it can be checked rather than believed

And it is held to the numbers

Every figure it uses has to exist in the reference material or the item itself, and every finding it raises has to survive a challenge designed to refute it before anyone in the room sees it. A confident-sounding point that cannot be supported never reaches the screen.

The session

The whole room contributes. One person records.

We walk the register one item at a time, by unit and by discipline, on the screen everyone is looking at. The difference is what your team can do while that happens.

Everyone joins by scanning a code

No accounts to set up and nobody left out because the invite went to the wrong list. Each person is on their own phone, seeing the item under discussion.

Anyone can put something forward

A failure mechanism, a consequence, a cost, a correction, or the inspection record that settles the argument. The person who knows the equipment contributes directly instead of waiting to be asked.

Nothing lands until the facilitator accepts it

Every contribution queues for review and commits only when accepted, so the session stays a discussion with one clean record coming out of it rather than a free-for-all.

Evidence someone attaches is displayed to the room on the spot. Actions raised during the session get an owner and a date before anyone leaves. And because the register carries the time remaining to execution at the top of the screen, the room argues about scope with the window in front of it rather than in the abstract.

After freeze

The scope that ruins a window is the scope added after the argument was won.

A challenge that ends at freeze solves half the problem. Freeze snapshots the baseline and opens a change register, and from that point an addition has to clear a bar that rises as the event approaches and as the growth allowance is consumed.

Late work is not forbidden. It is priced against the disruption it now causes, which is a different conversation from the one held at freeze, and the right one to be having. Genuinely required work is exempt from the test but never from the record.

The bar rises as you get closer

  • Early after freeze

    An addition has to clear the standard justification, the same test everything else already passed.

  • As the allowance is consumed

    The bar steps up. Work that would have been comfortably justified at freeze no longer clears it.

  • Close to execution

    The bar steps up again and the decision leaves the working level entirely: an addition this late needs executive approval.

Deletions and changes are logged too, so scope churn is visible as a number at closeout rather than an argument about what happened.

What you get

A scope you can defend, item by item.

01

The challenged register

Every item with its risk scores, its ratio where one applies, its recorded disposition, and the reasoning behind it.

02

The frozen baseline

A snapshot of the scope at freeze: what was included, what was reduced, deferred, offloaded, or eliminated, and the risk basis for each.

03

The endorsement package

A workbook your team carries into planning and defends at the gate, including the risk acceptances recorded against anything removed.

04

The change register

Everything that arrives after freeze, what hurdle it had to clear, and who approved it. Scope churn stops being invisible.

And it does not stop when we leave

The register lives in STO·PATH, so your team keeps working it after the session: challenging the scope that arrives late, raising and deciding changes against the same rising bar, and carrying the record into the gate. The facilitated session is where the discipline is set. The platform is where it holds.

How it runs

Most of the work happens before the room sits down.

01

Send what you already have

Your scope register in whatever shape it is in, your risk matrix, the event premise, and any scope-management procedure you run. Columns are matched for you and confirmed before anything is imported.

02

We set the economics

What a day down is worth on each unit, and what a rate cut costs, so the pricing uses the right unit's numbers rather than a site average.

03

The session

By unit and discipline, item by item, with the whole team contributing and every disposition recorded as it is made.

04

Freeze and carry on

The baseline is snapshotted, the endorsement package comes out, and the change register opens for whatever arrives next.

Method per our scope development and challenge standard, built on public frameworks: AACE recommended practice for the cost and risk treatment, and public inspection and reliability practice (API, ASME, IEC, ISO) behind the panel.

Scope it right, once

How much of your scope could you defend today?

Bring your scope list and your matrix. We will show you what the two-stage test does to it, and what the reasoning looks like written down.

Start a conversation