Resources · Framework
Pilot-to-Production Checklist
A pilot that works is not the same as a system that can run the business. These are the six gates between the two, in the order they bite — with the specific failure each one exists to catch. Tick them as you go; nothing is saved, and the printed copy is the point.

The gates
UNIT 01Every gate has to be cleared, not scored. A gate half met is a gate not met — that is the whole discipline of it, and it is why this is a checklist rather than another weighted model.
The pilot answered a question
GATE 01Did the pilot test what was uncertain, or demonstrate what was already known?
What this gate catches: The demonstration pilot. It runs on the newest asset with clean data, everybody is pleased, and none of the risk has been touched. Scaling one of these is how a project discovers its real problems at ten times the cost.
The exception path exists
GATE 02What happens to the cases the system cannot handle, and who does it?
What this gate catches: The saving that never arrives. Exceptions turn out to be a quarter of volume, they land on the same people as before, and the business case quietly stops being true while everyone congratulates the build.
It survives the things that will happen
GATE 03Has it been tested against failure, not only against success?
What this gate catches: Silent failure. The system stops updating on a Friday, the dashboard shows the last known values, and nobody notices until Tuesday because a stale number looks exactly like a current one.
It is owned
GATE 04Who runs this on the Monday after handover?
What this gate catches: The most common failure in this list, and the least technical. The system works, the project closes, and eighteen months later it has been worked around because nobody was funded to keep it.
It can be changed
GATE 05When the process changes next year, what does it take?
What this gate catches: The frozen system. It works and nobody dares touch it, so the process grows around it instead, and within two years the workarounds cost more than the system saves.
The benefit is being measured
GATE 06How will you know in six months whether this was worth doing?
What this gate catches: The unprovable win. Everyone believes it helped, nobody can demonstrate it, and the next project has to be justified from scratch against a finance function that has learnt to discount the claims.
Where you are
UNIT 02Not ready
0/6Gates cleared
6 gates still open
0 of 21 criteria met, clearing 0 of 6 gates. Still open: the pilot answered a question; the exception path exists; it survives the things that will happen; it is owned; it can be changed; the benefit is being measured.
A gate half met is a gate not met. That is not pedantry — every one of these describes a way a technically sound project fails after go-live, when it is far more expensive to correct and when the people who could have corrected it have moved on.
Take it with you
↓The result as plain text. Paste it into an email, a board paper, or a request for quotation — no address needed, and it stays readable when it is forwarded to somebody who was not in the room.
Technical references
UNIT 03What the reasoning on this page is drawn from. Where a standard costs money to read it is marked, and where a free document covers the same ground better it is listed first.
- SAE JA1011Paid standardSAE InternationalThe evaluation criteria for reliability-centred maintenance. The discipline behind asking which failure mode before buying any sensor.
- NIST SP 800-82 Rev. 3NISTGuide to Operational Technology Security. Free, several hundred pages, and the most useful single document in this field. The segmentation logic in our planner follows its zone and conduit reasoning.
- ISO 42001 explainedISOISO's own free summary. The right first read if you are deciding whether certification is relevant before buying the standard.
Links open in a new tab so anything you have entered above survives. Every one was checked at build time; if one has rotted since, tell us and it comes out rather than getting patched from memory.
Every one of these tools is a compressed version of a conversation. If yours turned up something you would rather talk through than read about, that is what the scoping call is for — bring your result with you.
Get a pilot reviewed before it goes liveAlso on the shelf
- Framework
The Readiness Model
The five dimensions behind the readiness assessment, written out in full: what each one measures, how it fails, and what it costs to fix before a build rather than during one.
- Framework
Spec template
The sections an integration brief needs before it goes out to vendors, so that three quotes come back describing the same job.
- Framework
Vendor scorecard
How to compare integration vendors on what will actually determine the outcome, weighted and scored — including the questions we would rather you asked us.