<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Rakesh Randeria</title>
    <description>The latest articles on DEV Community by Rakesh Randeria (@rakeshranderia).</description>
    <link>https://dev.to/rakeshranderia</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4110382%2Fe5a6be54-eb61-4b80-a524-84349cea8d48.png</url>
      <title>DEV Community: Rakesh Randeria</title>
      <link>https://dev.to/rakeshranderia</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/rakeshranderia"/>
    <language>en</language>
    <item>
      <title>DMAIC for Technology Delivery: From Business Problem to Operational Outcome</title>
      <dc:creator>Rakesh Randeria</dc:creator>
      <pubDate>Wed, 23 Sep 2026 03:55:37 +0000</pubDate>
      <link>https://dev.to/rakeshranderia/dmaic-for-technology-delivery-from-business-problem-to-operational-outcome-3job</link>
      <guid>https://dev.to/rakeshranderia/dmaic-for-technology-delivery-from-business-problem-to-operational-outcome-3job</guid>
      <description>&lt;p&gt;Technology projects are usually very good at describing &lt;strong&gt;what will be delivered&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;They are often less disciplined about describing:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;the condition that needs to improve;&lt;/li&gt;
&lt;li&gt;the evidence showing that the problem exists;&lt;/li&gt;
&lt;li&gt;the causes behind the current state;&lt;/li&gt;
&lt;li&gt;the baseline against which success will be measured;&lt;/li&gt;
&lt;li&gt;and how the organisation will know the improvement lasted after the project closes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That is where I find the overlap between &lt;strong&gt;Lean Six Sigma and technology delivery&lt;/strong&gt; particularly useful.&lt;/p&gt;

&lt;p&gt;DMAIC — &lt;strong&gt;Define, Measure, Analyse, Improve, Control&lt;/strong&gt; — is not a replacement for Agile, PRINCE2, PMBOK, product delivery or an organisation's project-management framework.&lt;/p&gt;

&lt;p&gt;It answers a different set of questions.&lt;/p&gt;

&lt;p&gt;A delivery method helps organise &lt;strong&gt;how the change will be delivered&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;DMAIC helps maintain the evidence chain between &lt;strong&gt;the original problem and the operational outcome&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;That matters because a project can be delivered on time, within budget and to its agreed scope while still failing to improve the condition that justified the investment.&lt;/p&gt;

&lt;h2&gt;
  
  
  The overlap in one view
&lt;/h2&gt;

&lt;p&gt;A typical technology delivery lifecycle might look like:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Initiate → Plan → Design → Build → Test → Deploy → Transition → Close&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;DMAIC can sit around that lifecycle: &lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqbwrfor8unxfw6ahz3fe.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqbwrfor8unxfw6ahz3fe.png" alt=" " width="798" height="197"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Define → Measure → Analyse → Improve [delivery] → Control&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The overlap is not exact, and it should not be forced to be.&lt;/p&gt;

&lt;p&gt;The practical value is that DMAIC adds a persistent set of questions:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;What problem are we solving?&lt;br&gt;&lt;br&gt;
How do we know?&lt;br&gt;&lt;br&gt;
What is causing it?&lt;br&gt;&lt;br&gt;
Does the proposed change address the cause?&lt;br&gt;&lt;br&gt;
How will we prove and sustain the improvement?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Those questions work at project level, but they also scale up into programs, portfolios and strategic roadmaps.&lt;/p&gt;




&lt;h2&gt;
  
  
  Define: make the problem clearer than the solution
&lt;/h2&gt;

&lt;p&gt;A common technology project begins with a solution statement.&lt;/p&gt;

&lt;p&gt;Examples:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Replace the CRM.&lt;/p&gt;

&lt;p&gt;Move the platform to the cloud.&lt;/p&gt;

&lt;p&gt;Implement a new service-management tool.&lt;/p&gt;

&lt;p&gt;Automate the onboarding process.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Those may all turn out to be appropriate interventions, but none is a problem statement.&lt;/p&gt;

&lt;p&gt;A stronger starting point is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Customer interactions are fragmented across sales, service and marketing platforms, making it difficult to maintain a reliable customer view.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Or:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Manual onboarding requires multiple hand-offs and re-entry of the same information, resulting in long cycle times and avoidable errors.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Or:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The current technology estate has duplicated capability, inconsistent ownership and increasing support cost.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The distinction matters because once the solution has been embedded in the problem statement, analysis tends to become justification for the chosen answer.&lt;/p&gt;

&lt;h3&gt;
  
  
  In technology delivery, Define can include
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;business outcome;&lt;/li&gt;
&lt;li&gt;problem or opportunity statement;&lt;/li&gt;
&lt;li&gt;scope and boundaries;&lt;/li&gt;
&lt;li&gt;stakeholders;&lt;/li&gt;
&lt;li&gt;users/customers;&lt;/li&gt;
&lt;li&gt;critical outcomes;&lt;/li&gt;
&lt;li&gt;high-level acceptance criteria;&lt;/li&gt;
&lt;li&gt;benefit owner;&lt;/li&gt;
&lt;li&gt;constraints;&lt;/li&gt;
&lt;li&gt;initial assumptions.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This overlaps significantly with a project charter.&lt;/p&gt;

&lt;p&gt;The difference is emphasis.&lt;/p&gt;

&lt;p&gt;A project charter may quite reasonably describe the delivery initiative.&lt;/p&gt;

&lt;p&gt;The DMAIC lens asks whether the charter also explains &lt;strong&gt;what measurable condition should be different when the initiative succeeds&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  Measure: establish the current state before claiming improvement
&lt;/h2&gt;

&lt;p&gt;If a project is intended to improve something, there should be a baseline.&lt;/p&gt;

&lt;p&gt;That sounds obvious, but it is easy to lose once delivery gains momentum.&lt;/p&gt;

&lt;p&gt;A baseline might include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;transaction cycle time;&lt;/li&gt;
&lt;li&gt;application count;&lt;/li&gt;
&lt;li&gt;vendor count;&lt;/li&gt;
&lt;li&gt;run cost;&lt;/li&gt;
&lt;li&gt;incident volume;&lt;/li&gt;
&lt;li&gt;mean time to restore;&lt;/li&gt;
&lt;li&gt;failed change rate;&lt;/li&gt;
&lt;li&gt;manual effort;&lt;/li&gt;
&lt;li&gt;error rate;&lt;/li&gt;
&lt;li&gt;service availability;&lt;/li&gt;
&lt;li&gt;customer satisfaction;&lt;/li&gt;
&lt;li&gt;adoption;&lt;/li&gt;
&lt;li&gt;licence utilisation;&lt;/li&gt;
&lt;li&gt;security exceptions;&lt;/li&gt;
&lt;li&gt;end-of-support exposure.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The measure does not have to be statistically sophisticated to be useful.&lt;/p&gt;

&lt;p&gt;The important point is that the team knows &lt;strong&gt;what the current state actually looks like&lt;/strong&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Example: service desk improvement
&lt;/h3&gt;

&lt;p&gt;Suppose the proposed project is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Introduce workflow automation to improve the service desk.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Before building anything, useful measures might include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;average resolution time;&lt;/li&gt;
&lt;li&gt;queue time before assignment;&lt;/li&gt;
&lt;li&gt;number of manual hand-offs;&lt;/li&gt;
&lt;li&gt;percentage of tickets requiring rework;&lt;/li&gt;
&lt;li&gt;top incident/request categories;&lt;/li&gt;
&lt;li&gt;first-contact resolution;&lt;/li&gt;
&lt;li&gt;automation rate;&lt;/li&gt;
&lt;li&gt;user satisfaction.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Those measures may reveal that automation is useful.&lt;/p&gt;

&lt;p&gt;They may also reveal that the largest delay is not the service desk at all — perhaps requests are waiting for approvals, identity verification or a specialist team.&lt;/p&gt;

&lt;p&gt;Measurement prevents the project from optimising the wrong part of the process.&lt;/p&gt;




&lt;h2&gt;
  
  
  Analyse: resist the urge to jump from symptom to implementation
&lt;/h2&gt;

&lt;p&gt;This is where DMAIC can add a lot to technology planning.&lt;/p&gt;

&lt;p&gt;Technology teams are trained to solve problems. That is useful, but it can also mean solution design begins before the cause is well understood.&lt;/p&gt;

&lt;p&gt;Analyse asks:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Which symptoms are being mistaken for causes?&lt;/li&gt;
&lt;li&gt;Which issues create most of the impact?&lt;/li&gt;
&lt;li&gt;Where does delay occur?&lt;/li&gt;
&lt;li&gt;Which dependencies create failure?&lt;/li&gt;
&lt;li&gt;Is the problem technology, process, data, ownership, capability or some combination?&lt;/li&gt;
&lt;li&gt;What would happen if nothing changed?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Tools can be simple:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;5 Whys;&lt;/li&gt;
&lt;li&gt;Pareto analysis;&lt;/li&gt;
&lt;li&gt;fishbone / cause-and-effect analysis;&lt;/li&gt;
&lt;li&gt;process mapping;&lt;/li&gt;
&lt;li&gt;value-stream mapping;&lt;/li&gt;
&lt;li&gt;FMEA;&lt;/li&gt;
&lt;li&gt;dependency analysis;&lt;/li&gt;
&lt;li&gt;data analysis;&lt;/li&gt;
&lt;li&gt;capability-gap analysis.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Example: fragmented technology estate
&lt;/h3&gt;

&lt;p&gt;Imagine the visible problem is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;We have too many applications.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A quick response is an application-rationalisation project.&lt;/p&gt;

&lt;p&gt;Analysis may show the deeper causes are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;decentralised procurement;&lt;/li&gt;
&lt;li&gt;no consistent application ownership;&lt;/li&gt;
&lt;li&gt;weak retirement gates;&lt;/li&gt;
&lt;li&gt;project success measured at go-live rather than decommissioning;&lt;/li&gt;
&lt;li&gt;duplicated business capability;&lt;/li&gt;
&lt;li&gt;inconsistent architecture standards;&lt;/li&gt;
&lt;li&gt;poor visibility of licences and contracts.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That changes the improvement.&lt;/p&gt;

&lt;p&gt;The answer is no longer simply:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Remove applications.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It becomes:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Rationalise the estate &lt;strong&gt;and&lt;/strong&gt; improve the controls that allowed the duplication to accumulate.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That distinction is the difference between reducing the problem once and reducing the likelihood that it returns.&lt;/p&gt;




&lt;h2&gt;
  
  
  Improve: this is where delivery methods do their best work
&lt;/h2&gt;

&lt;p&gt;Improve is where the intervention is designed, tested and implemented.&lt;/p&gt;

&lt;p&gt;For a technology initiative, that may include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;process redesign;&lt;/li&gt;
&lt;li&gt;automation;&lt;/li&gt;
&lt;li&gt;system configuration;&lt;/li&gt;
&lt;li&gt;application consolidation;&lt;/li&gt;
&lt;li&gt;migration;&lt;/li&gt;
&lt;li&gt;architecture changes;&lt;/li&gt;
&lt;li&gt;integration;&lt;/li&gt;
&lt;li&gt;security controls;&lt;/li&gt;
&lt;li&gt;vendor changes;&lt;/li&gt;
&lt;li&gt;operating-model changes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is also where Agile, waterfall, hybrid or product delivery can sit naturally.&lt;/p&gt;

&lt;p&gt;DMAIC does not prescribe how software must be developed or how project governance must be run.&lt;/p&gt;

&lt;p&gt;A team could use:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Define → Measure → Analyse&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;to establish the problem and evidence, then deliver the Improve stage through:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Backlog → Sprint → Test → Release → Measure → Adapt&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The improvement can be incremental.&lt;/p&gt;

&lt;p&gt;In fact, iterative delivery can strengthen DMAIC because the team can test whether a proposed change actually improves the measure before committing to wider scale.&lt;/p&gt;

&lt;h3&gt;
  
  
  Improvement should connect to cause
&lt;/h3&gt;

&lt;p&gt;The important test is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Which identified cause does this change address?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;If the project team cannot answer that clearly, there is a risk that delivery activity has become disconnected from analysis.&lt;/p&gt;




&lt;h2&gt;
  
  
  Control: project close is not the same as improvement sustained
&lt;/h2&gt;

&lt;p&gt;Control is the stage that maps particularly well to operational readiness, BAU transition and benefits realisation.&lt;/p&gt;

&lt;p&gt;A project may finish when:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;scope is delivered;&lt;/li&gt;
&lt;li&gt;testing is complete;&lt;/li&gt;
&lt;li&gt;production deployment succeeds;&lt;/li&gt;
&lt;li&gt;documentation is handed over;&lt;/li&gt;
&lt;li&gt;the project board accepts closure.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The improvement is sustained when:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;service ownership is clear;&lt;/li&gt;
&lt;li&gt;performance is monitored;&lt;/li&gt;
&lt;li&gt;benefits are measured;&lt;/li&gt;
&lt;li&gt;operational thresholds exist;&lt;/li&gt;
&lt;li&gt;drift can be detected;&lt;/li&gt;
&lt;li&gt;changes are incorporated into normal governance;&lt;/li&gt;
&lt;li&gt;the organisation does not quietly recreate the original problem.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Technology controls can include
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;service KPIs;&lt;/li&gt;
&lt;li&gt;monitoring and alerting;&lt;/li&gt;
&lt;li&gt;architecture standards;&lt;/li&gt;
&lt;li&gt;automated validation;&lt;/li&gt;
&lt;li&gt;runbooks;&lt;/li&gt;
&lt;li&gt;lifecycle reviews;&lt;/li&gt;
&lt;li&gt;licence utilisation reviews;&lt;/li&gt;
&lt;li&gt;vendor scorecards;&lt;/li&gt;
&lt;li&gt;access reviews;&lt;/li&gt;
&lt;li&gt;post-implementation reviews;&lt;/li&gt;
&lt;li&gt;benefits dashboards;&lt;/li&gt;
&lt;li&gt;named operational ownership.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The useful question is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What mechanism will tell us if we are drifting back toward the original condition?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is a different question from:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Has the project been closed?&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  DMAIC does not need to become bureaucracy
&lt;/h2&gt;

&lt;p&gt;There is an obvious risk with frameworks: turning them into more forms, gates and meetings.&lt;/p&gt;

&lt;p&gt;That is not the intention.&lt;/p&gt;

&lt;p&gt;A small initiative might capture the whole DMAIC evidence chain on a few pages.&lt;/p&gt;

&lt;p&gt;A major transformation may require much more.&lt;/p&gt;

&lt;p&gt;The level of method should be proportionate to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;business impact;&lt;/li&gt;
&lt;li&gt;risk;&lt;/li&gt;
&lt;li&gt;investment;&lt;/li&gt;
&lt;li&gt;uncertainty;&lt;/li&gt;
&lt;li&gt;reversibility;&lt;/li&gt;
&lt;li&gt;regulatory exposure;&lt;/li&gt;
&lt;li&gt;customer impact.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The point is not to make every project look like a Six Sigma certification exercise.&lt;/p&gt;

&lt;p&gt;The point is to preserve enough evidence to make the decision and outcome credible.&lt;/p&gt;




&lt;h2&gt;
  
  
  Where the overlap becomes broader than a project
&lt;/h2&gt;

&lt;p&gt;The same model scales upward.&lt;/p&gt;

&lt;h3&gt;
  
  
  Strategy
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Define:&lt;/strong&gt; What business or capability problem matters?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Measure:&lt;/strong&gt; What does the current state look like?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Analyse:&lt;/strong&gt; What strategic gaps, constraints or systemic causes exist?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Improve:&lt;/strong&gt; What target state and strategic options are appropriate?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Control:&lt;/strong&gt; How will strategy outcomes be reviewed?&lt;/p&gt;

&lt;h3&gt;
  
  
  Roadmap
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Define:&lt;/strong&gt; What planning horizon and outcome are in scope?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Measure:&lt;/strong&gt; What is the current technology/capability estate?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Analyse:&lt;/strong&gt; What gaps and dependencies constrain the path?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Improve:&lt;/strong&gt; What sequence of initiatives moves toward the target state?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Control:&lt;/strong&gt; How will the roadmap be refreshed as evidence changes?&lt;/p&gt;

&lt;h3&gt;
  
  
  Portfolio
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Define:&lt;/strong&gt; What investment themes and decision criteria apply?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Measure:&lt;/strong&gt; What are we already spending and delivering?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Analyse:&lt;/strong&gt; Where is there duplication, imbalance or concentration?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Improve:&lt;/strong&gt; What should be funded, deferred, stopped or rebalanced?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Control:&lt;/strong&gt; Are benefits and capacity reviewed after approval?&lt;/p&gt;

&lt;h3&gt;
  
  
  Program
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Define:&lt;/strong&gt; What outcome requires coordinated change?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Measure:&lt;/strong&gt; What is the cross-project benefit baseline?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Analyse:&lt;/strong&gt; Which causes and dependencies span multiple projects?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Improve:&lt;/strong&gt; How should coordinated initiatives deliver the outcome?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Control:&lt;/strong&gt; Are benefits realised after individual projects finish?&lt;/p&gt;

&lt;p&gt;This is why I see Lean Six Sigma as a useful &lt;strong&gt;decision discipline across technology management&lt;/strong&gt;, not simply an operational process-improvement method.&lt;/p&gt;




&lt;h2&gt;
  
  
  A practical example: from problem to roadmap
&lt;/h2&gt;

&lt;p&gt;A useful roadmap sequence is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Problem → Current State → Evidence → Root Cause → Capability Gap → Options → Prioritisation → Roadmap → Delivery → Benefits&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That sequence is materially different from:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Requests → Projects → Budget → Delivery&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The second can still produce a portfolio of good projects.&lt;/p&gt;

&lt;p&gt;The first makes it easier to explain &lt;strong&gt;why those projects deserve to exist&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Consider a technology-estate rationalisation scenario.&lt;/p&gt;

&lt;p&gt;The visible problems are high run cost, duplicated platforms and support complexity.&lt;/p&gt;

&lt;p&gt;A DMAIC-led path could be:&lt;/p&gt;

&lt;h3&gt;
  
  
  Define
&lt;/h3&gt;

&lt;p&gt;The estate has become fragmented and expensive to operate.&lt;/p&gt;

&lt;h3&gt;
  
  
  Measure
&lt;/h3&gt;

&lt;p&gt;Baseline:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;applications;&lt;/li&gt;
&lt;li&gt;vendors;&lt;/li&gt;
&lt;li&gt;support cost;&lt;/li&gt;
&lt;li&gt;licence utilisation;&lt;/li&gt;
&lt;li&gt;incidents;&lt;/li&gt;
&lt;li&gt;integration count;&lt;/li&gt;
&lt;li&gt;end-of-support exposure;&lt;/li&gt;
&lt;li&gt;ownership gaps.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Analyse
&lt;/h3&gt;

&lt;p&gt;Identify:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;duplicated capabilities;&lt;/li&gt;
&lt;li&gt;decentralised procurement;&lt;/li&gt;
&lt;li&gt;weak architecture standards;&lt;/li&gt;
&lt;li&gt;no retirement gate;&lt;/li&gt;
&lt;li&gt;unclear ownership;&lt;/li&gt;
&lt;li&gt;poor contract/utilisation visibility.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Improve
&lt;/h3&gt;

&lt;p&gt;Create a roadmap:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Stabilise → Simplify → Modernise → Optimise&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This may result in multiple programs and projects.&lt;/p&gt;

&lt;h3&gt;
  
  
  Control
&lt;/h3&gt;

&lt;p&gt;Introduce:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;application ownership;&lt;/li&gt;
&lt;li&gt;lifecycle governance;&lt;/li&gt;
&lt;li&gt;architecture review;&lt;/li&gt;
&lt;li&gt;licence utilisation monitoring;&lt;/li&gt;
&lt;li&gt;benefit tracking.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Now the roadmap is not just a list of consolidation projects.&lt;/p&gt;

&lt;p&gt;It also addresses the mechanisms that created the problem.&lt;/p&gt;




&lt;h2&gt;
  
  
  The distinction I find most useful
&lt;/h2&gt;

&lt;p&gt;For technology delivery, I reduce the idea to this:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The delivery method organises the work. DMAIC protects the evidence chain between the problem and the outcome.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;They overlap, but they are not competitors.&lt;/p&gt;

&lt;p&gt;Agile can still be Agile.&lt;/p&gt;

&lt;p&gt;A project manager can still use the organisation's existing framework.&lt;/p&gt;

&lt;p&gt;Architects can still use established architecture practices.&lt;/p&gt;

&lt;p&gt;Service teams can still use ITSM.&lt;/p&gt;

&lt;p&gt;The Lean Six Sigma lens simply keeps asking:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What are we improving? How do we know? Why will this intervention help? Did it work? Did it last?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Those are useful questions regardless of the delivery method.&lt;/p&gt;




&lt;p&gt;I have published the broader framework, diagrams, templates and a worked technology-estate example here:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lean Six Sigma for Technology Strategy &amp;amp; Delivery&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;a href="https://github.com/rakeshranderia/lean-six-sigma-technology-strategy-delivery" rel="noopener noreferrer"&gt;https://github.com/rakeshranderia/lean-six-sigma-technology-strategy-delivery&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The repository maps DMAIC across technology strategy, roadmaps, portfolios, programs, projects, operations and benefits realisation.&lt;/p&gt;

</description>
      <category>agile</category>
      <category>leadership</category>
      <category>productivity</category>
      <category>management</category>
    </item>
    <item>
      <title>File Share Access Reviews: Why Ownership Matters More Than Another ACL Export</title>
      <dc:creator>Rakesh Randeria</dc:creator>
      <pubDate>Mon, 21 Sep 2026 03:14:28 +0000</pubDate>
      <link>https://dev.to/rakeshranderia/file-share-access-reviews-why-ownership-matters-more-than-another-acl-export-31d4</link>
      <guid>https://dev.to/rakeshranderia/file-share-access-reviews-why-ownership-matters-more-than-another-acl-export-31d4</guid>
      <description>&lt;h1&gt;
  
  
  File Share Access Reviews: Why Ownership Matters More Than Another ACL Export
&lt;/h1&gt;

&lt;p&gt;Traditional Windows file shares are easy to underestimate.&lt;/p&gt;

&lt;p&gt;The permissions are visible. Active Directory groups exist. NTFS ACLs can be exported. On paper, that can look like access governance.&lt;/p&gt;

&lt;p&gt;In practice, the difficult question is usually not:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Who has access?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Who is accountable for deciding whether that access should still exist?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That distinction is what turns a permissions report into an access-governance process.&lt;/p&gt;

&lt;h2&gt;
  
  
  The problem with ACL-only reviews
&lt;/h2&gt;

&lt;p&gt;A typical file-share review starts with an export of directories, groups and users.&lt;/p&gt;

&lt;p&gt;That is useful, but it quickly runs into familiar problems:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;groups have no clear owner;&lt;/li&gt;
&lt;li&gt;the listed owner has left the organisation;&lt;/li&gt;
&lt;li&gt;permissions are inherited through several layers;&lt;/li&gt;
&lt;li&gt;users appear directly on ACLs rather than through governed groups;&lt;/li&gt;
&lt;li&gt;IT understands the technical permissions but not whether the access is still appropriate;&lt;/li&gt;
&lt;li&gt;review spreadsheets are produced, emailed and then quietly become evidence of activity rather than evidence of a decision.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The technical visibility is there. The accountability often is not.&lt;/p&gt;

&lt;h2&gt;
  
  
  Treat ownership as a control
&lt;/h2&gt;

&lt;p&gt;The approach I prefer is to treat ownership as a first-class control.&lt;/p&gt;

&lt;p&gt;IT or IAM should operate the technical process: discover permissions, resolve identities, validate ownership records, package reviews and implement approved changes.&lt;/p&gt;

&lt;p&gt;But the access decision should sit with a verified business or data owner.&lt;/p&gt;

&lt;p&gt;That creates a much cleaner separation:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;IT discovers and operates the control.&lt;br&gt;&lt;br&gt;
Owners decide whether access remains appropriate.&lt;br&gt;&lt;br&gt;
IAM/IT implements approved remediation.&lt;br&gt;&lt;br&gt;
Evidence records what happened.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This avoids turning a quarterly access review into an IT-owned exercise where the people with the least business context are effectively deciding who should retain access.&lt;/p&gt;

&lt;h2&gt;
  
  
  A practical operating model
&lt;/h2&gt;

&lt;p&gt;For traditional Windows file shares, I use the following pattern:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Discover → Resolve → Validate Ownership → Monitor → Certify → Remediate → Evidence&lt;/strong&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Discover
&lt;/h3&gt;

&lt;p&gt;Enumerate the file-share scope and collect the relevant NTFS ACLs.&lt;/p&gt;

&lt;p&gt;The aim is not to scan everything forever. It is to establish a reliable access register that can be refreshed when needed.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Resolve
&lt;/h3&gt;

&lt;p&gt;Translate ACL principals into meaningful Active Directory identities.&lt;/p&gt;

&lt;p&gt;That includes handling security groups, users, unresolved SIDs, nested group relationships where required, and direct permissions that fall outside the preferred model.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Validate ownership
&lt;/h3&gt;

&lt;p&gt;Do not assume that an owner reference is valid just because a field is populated.&lt;/p&gt;

&lt;p&gt;A useful ownership check verifies that the referenced object exists, is the expected object type, is enabled, has a usable identity, and has enough information to participate in the review workflow.&lt;/p&gt;

&lt;p&gt;For Active Directory groups, &lt;code&gt;managedBy&lt;/code&gt; is a good authoritative starting point when it is maintained properly. An extension attribute can provide an organisational fallback. A structured value in the group description can support legacy environments, but I would treat that as a fallback rather than the target state.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Monitor
&lt;/h3&gt;

&lt;p&gt;Ownership should not only be checked during the quarterly review.&lt;/p&gt;

&lt;p&gt;A lightweight daily or overnight validation can detect missing owners, disabled owners, deleted accounts, groups that no longer resolve, and ownership conflicts.&lt;/p&gt;

&lt;p&gt;This turns ownership hygiene into an ongoing control rather than a quarterly surprise.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Certify
&lt;/h3&gt;

&lt;p&gt;Verified owners receive only the access within their scope.&lt;/p&gt;

&lt;p&gt;Their decision should be simple:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Keep&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Remove&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Investigate&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The review does not need to become a large GRC workflow to be useful. It needs clear ownership, understandable data and an auditable decision.&lt;/p&gt;

&lt;h3&gt;
  
  
  6. Remediate
&lt;/h3&gt;

&lt;p&gt;Approved changes should flow back to IAM or IT for controlled implementation.&lt;/p&gt;

&lt;p&gt;I deliberately prefer the discovery/review process to remain read-only against permissions. Automatic removal sounds efficient, but separating the business decision from the technical change gives better control over mistakes, exceptions and evidence.&lt;/p&gt;

&lt;h3&gt;
  
  
  7. Evidence
&lt;/h3&gt;

&lt;p&gt;The final control is not the spreadsheet.&lt;/p&gt;

&lt;p&gt;The evidence is the chain:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;what was discovered → who owned the decision → what they decided → what was changed → when it was completed&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is much more useful operationally and from an assurance perspective.&lt;/p&gt;

&lt;h2&gt;
  
  
  The useful boundary
&lt;/h2&gt;

&lt;p&gt;This pattern is specifically useful for traditional Windows file shares using NTFS permissions and Active Directory identities.&lt;/p&gt;

&lt;p&gt;It does not govern SharePoint Online, Teams, OneDrive or every modern repository. Those platforms need their own discovery and control models.&lt;/p&gt;

&lt;p&gt;That boundary matters. A governance tool becomes less trustworthy when it claims broader coverage than it actually has.&lt;/p&gt;

&lt;h2&gt;
  
  
  The broader lesson
&lt;/h2&gt;

&lt;p&gt;The same idea applies beyond file shares:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;access visibility is not access governance.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A list of permissions becomes governance when the organisation can answer:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Who owns this resource?&lt;/li&gt;
&lt;li&gt;Is that owner still valid?&lt;/li&gt;
&lt;li&gt;Who decides whether access is appropriate?&lt;/li&gt;
&lt;li&gt;How often is that decision revisited?&lt;/li&gt;
&lt;li&gt;How are changes implemented?&lt;/li&gt;
&lt;li&gt;What evidence remains afterwards?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If those questions do not have clear answers, another ACL export probably will not solve the problem.&lt;/p&gt;

&lt;p&gt;I have published the Windows file-share implementation pattern, PowerShell baseline, review model and sample evidence structures here:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/rakeshranderia/FileShare-Access-Governance" rel="noopener noreferrer"&gt;https://github.com/rakeshranderia/FileShare-Access-Governance&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The project is intentionally scoped to Windows file shares and is designed as a safe baseline to test in a representative environment before enterprise deployment.&lt;/p&gt;

</description>
      <category>powershell</category>
      <category>cybersecurity</category>
      <category>iam</category>
      <category>windows</category>
    </item>
    <item>
      <title>Data Classification Without Turning It Into Bureaucracy</title>
      <dc:creator>Rakesh Randeria</dc:creator>
      <pubDate>Sun, 13 Sep 2026 03:41:43 +0000</pubDate>
      <link>https://dev.to/rakeshranderia/data-classification-without-turning-it-into-bureaucracy-4ko6</link>
      <guid>https://dev.to/rakeshranderia/data-classification-without-turning-it-into-bureaucracy-4ko6</guid>
      <description>&lt;h1&gt;
  
  
  Data Classification Without Turning It Into Bureaucracy
&lt;/h1&gt;

&lt;p&gt;Data classification is easy to make complicated. A more useful question is: &lt;strong&gt;what decision should this classification change?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A classification should affect access, sharing, storage, encryption, retention, monitoring, third-party handling and AI use.&lt;/p&gt;

&lt;h2&gt;
  
  
  Start with impact, not the label
&lt;/h2&gt;

&lt;p&gt;Classification should be risk-based rather than driven only by content type. Ask what happens if the data is disclosed, changed incorrectly, unavailable or used outside its intended purpose.&lt;/p&gt;

&lt;p&gt;A simple model may be enough: Public, Internal, Confidential and Restricted. The exact labels matter less than the decisions behind them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Classification sets the minimum baseline
&lt;/h2&gt;

&lt;p&gt;The label should define the &lt;strong&gt;minimum handling expectation&lt;/strong&gt;, not the full risk decision. Regulation, contracts, system criticality, external sharing or AI use may require stronger controls.&lt;/p&gt;

&lt;h2&gt;
  
  
  The important part: propagation
&lt;/h2&gt;

&lt;p&gt;Consider:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CRM → API → Data Platform → Report → AI Retrieval Store&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;My default position is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Downstream data should inherit the source classification unless there is a documented reason to change it.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That reason might be verified aggregation, masking, tokenisation, de-identification or removal of sensitive fields.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Classification tells us the control requirement.&lt;br&gt;&lt;br&gt;
Lineage tells us everywhere that requirement has to follow.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  A practical decision record
&lt;/h2&gt;

&lt;p&gt;Rather than ending with only "Classification: Confidential", capture owner, primary drivers, minimum controls, lineage status, AI implications and review triggers.&lt;/p&gt;

&lt;h2&gt;
  
  
  Operating flow
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Identify → Assess Impact → Classify → Apply Controls → Propagate → Review&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That is the difference between classification as a label and classification as an operating control.&lt;/p&gt;

&lt;h2&gt;
  
  
  Related resources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://rakeshranderia.com.au/data-classification-governance-readiness.html" rel="noopener noreferrer"&gt;Data Classification &amp;amp; Governance Readiness&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://huggingface.co/spaces/rakeshranderia/data-governance-toolkit" rel="noopener noreferrer"&gt;Interactive Data Governance Toolkit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/rakeshranderia/data-governance-toolkit" rel="noopener noreferrer"&gt;Data Governance Toolkit source on GitHub&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>datagovernance</category>
      <category>security</category>
      <category>data</category>
      <category>ai</category>
    </item>
    <item>
      <title>12 Questions to Ask Before You Call an AI Use Case Ready</title>
      <dc:creator>Rakesh Randeria</dc:creator>
      <pubDate>Mon, 07 Sep 2026 21:51:19 +0000</pubDate>
      <link>https://dev.to/rakeshranderia/12-questions-to-ask-before-you-call-an-ai-use-case-ready-28al</link>
      <guid>https://dev.to/rakeshranderia/12-questions-to-ask-before-you-call-an-ai-use-case-ready-28al</guid>
      <description>&lt;p&gt;A practical readiness check covering data, controls, human oversight and ongoing operations.&lt;/p&gt;

&lt;p&gt;Responsible AI can become abstract very quickly. Policies and principles matter, but at some point a project team needs to answer a more practical question: are the foundations actually strong enough to proceed?&lt;/p&gt;

&lt;p&gt;I have been using a simple 12-question readiness check to make that discussion more concrete. It is not a certification or compliance assessment. The aim is to expose obvious gaps before a use case moves from experimentation into operational use.&lt;/p&gt;

&lt;h2&gt;
  
  
  The 12 questions
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Data ownership&lt;br&gt;
Is there a clearly accountable owner for the data used by the AI use case?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Data classification&lt;br&gt;
Is the information classified, and is its use permitted in the proposed AI platform?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Data quality&lt;br&gt;
Is the data sufficiently accurate, complete, timely and fit for the intended purpose?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Access control&lt;br&gt;
Are permissions limited to the people, systems and services that genuinely need access?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Data lineage&lt;br&gt;
Can you reasonably explain the main source, movement and downstream use of the data?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Purpose and value&lt;br&gt;
Is the business problem clear, and is there a measurable reason to use AI?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Risk assessment&lt;br&gt;
Has the use case been assessed for privacy, security, legal, ethical and operational impact?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Approved platform&lt;br&gt;
Is the AI platform approved, and are supplier, data handling and retention arrangements understood?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Human oversight&lt;br&gt;
Is meaningful human review defined for consequential or material outputs?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Testing and evaluation&lt;br&gt;
Have quality, failure modes, hallucination or bias risk and acceptance criteria been considered?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Monitoring&lt;br&gt;
Are owners, metrics, incident paths and review triggers defined for ongoing use?&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Shadow AI controls&lt;br&gt;
Are users given clear guidance on approved tools, prohibited data and escalation paths?&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Looking beyond one overall score
&lt;/h2&gt;

&lt;p&gt;An overall readiness score is useful, but it can hide where the real weakness sits. I have therefore grouped the same questions into four dimensions:&lt;/p&gt;

&lt;p&gt;Data Foundations&lt;/p&gt;

&lt;p&gt;Risk &amp;amp; Controls&lt;/p&gt;

&lt;p&gt;Human Oversight&lt;/p&gt;

&lt;p&gt;Monitoring &amp;amp; Operations&lt;/p&gt;

&lt;p&gt;This makes the result more useful in practice. Two organisations can have the same overall score while having very different problems: one may have weak data foundations, while another may have reasonable data controls but little monitoring or human oversight.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happens next?
&lt;/h2&gt;

&lt;p&gt;The assessment deliberately produces only three overall outcomes: Ready, Ready with Controls, or Further Assessment Required. The useful part is not the label itself; it is identifying which dimensions and individual questions need attention before scaling the use case.&lt;/p&gt;

&lt;p&gt;As business impact increases, the strength of the assessment, evidence and oversight should increase with it. A low-impact internal productivity use case does not need the same governance treatment as an automated decision affecting customers.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try the live assessment
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://huggingface.co/spaces/rakeshranderia/responsible-ai-readiness" rel="noopener noreferrer"&gt;https://huggingface.co/spaces/rakeshranderia/responsible-ai-readiness&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  View the source
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://github.com/rakeshranderia/responsible-ai-readiness" rel="noopener noreferrer"&gt;https://github.com/rakeshranderia/responsible-ai-readiness&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Related framework
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://github.com/rakeshranderia/data-governance-framework" rel="noopener noreferrer"&gt;https://github.com/rakeshranderia/data-governance-framework&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The broader model behind the work remains: Data Governance → Trusted Data → AI Readiness → Responsible AI → Measurement → Scale.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>governance</category>
      <category>leadership</category>
    </item>
    <item>
      <title>Making Windows 11 Feel a Little More Familiar with PowerShell</title>
      <dc:creator>Rakesh Randeria</dc:creator>
      <pubDate>Sun, 06 Sep 2026 21:26:33 +0000</pubDate>
      <link>https://dev.to/rakeshranderia/making-windows-11-feel-a-little-more-familiar-with-powershell-190h</link>
      <guid>https://dev.to/rakeshranderia/making-windows-11-feel-a-little-more-familiar-with-powershell-190h</guid>
      <description>&lt;p&gt;Change is good, but sometimes a little familiarity is good too.&lt;/p&gt;

&lt;p&gt;Windows 11 introduces a cleaner interface and a number of useful changes, but some long-time Windows users still prefer a few parts of the Windows 10 experience.&lt;/p&gt;

&lt;p&gt;Rather than replacing the Windows shell or using a large “debloat” script, I wanted to see how far I could get with a small, conservative PowerShell toolkit focused on three things:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;restore classic Notepad&lt;/li&gt;
&lt;li&gt;show existing notification-area icons&lt;/li&gt;
&lt;li&gt;make Start cleaner and more familiar&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The result is a small project called &lt;strong&gt;Win11 Classic Experience&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Restoring classic Notepad
&lt;/h2&gt;

&lt;p&gt;The first objective was simple: keep the lightweight classic Notepad experience.&lt;/p&gt;

&lt;p&gt;The script:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;verifies that the classic Windows Notepad capability is installed&lt;/li&gt;
&lt;li&gt;installs it if required&lt;/li&gt;
&lt;li&gt;removes the modern &lt;code&gt;Microsoft.WindowsNotepad&lt;/code&gt; package&lt;/li&gt;
&lt;li&gt;removes the provisioned package where present&lt;/li&gt;
&lt;li&gt;suppresses the classic Notepad upgrade banner&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There is also a safety gate: the modern package is not removed unless classic Notepad is confirmed as installed first.&lt;/p&gt;

&lt;p&gt;One thing I deliberately avoided was creating a watchdog or scheduled task that constantly fights Windows servicing. If a future Windows update reintroduces the modern app, the script can simply be rerun.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Showing existing tray icons
&lt;/h2&gt;

&lt;p&gt;Windows 11 tends to place many notification icons into the overflow area.&lt;/p&gt;

&lt;p&gt;The approach here is straightforward:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="nv"&gt;$RegistryPath&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;'HKCU:\Control Panel\NotifyIconSettings'&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="nv"&gt;$Name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;'IsPromoted'&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="nv"&gt;$Value&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;'1'&lt;/span&gt;&lt;span class="w"&gt;

&lt;/span&gt;&lt;span class="n"&gt;Get-ChildItem&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Path&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$RegistryPath&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-Recurse&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ForEach-Object&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="n"&gt;New-ItemProperty&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;`
&lt;/span&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="nt"&gt;-Path&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="bp"&gt;$_&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;PSPath&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;`
&lt;/span&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="nt"&gt;-Name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$Name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;`
&lt;/span&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="nt"&gt;-Value&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$Value&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;`
&lt;/span&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="nt"&gt;-PropertyType&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;DWORD&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="se"&gt;`
&lt;/span&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="nt"&gt;-Force&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This promotes the notification icons already known to the current Windows profile.&lt;/p&gt;

&lt;p&gt;The important limitation is that new applications may create new tray entries later, so the feature may need to be rerun after additional applications are installed.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Making Start a little more familiar
&lt;/h2&gt;

&lt;p&gt;Windows 11 cannot genuinely be turned back into the Windows 10 Start menu without replacing or extending the shell.&lt;/p&gt;

&lt;p&gt;That was outside the scope of this project.&lt;/p&gt;

&lt;p&gt;Instead, I used native Windows settings to make Start more application-focused:&lt;/p&gt;

&lt;p&gt;Start_Layout = 1&lt;br&gt;&lt;br&gt;
ShowAllPinsList = 1&lt;br&gt;&lt;br&gt;
Start_IrisRecommendations = 0&lt;/p&gt;

&lt;p&gt;In practical terms, this means:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;use &lt;strong&gt;More pins&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;show all pins by default where supported&lt;/li&gt;
&lt;li&gt;reduce recommendation content&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It is still Windows 11 Start, just a little cleaner and less recommendation-heavy.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conservative by design
&lt;/h2&gt;

&lt;p&gt;The important part of this project is probably what it &lt;strong&gt;doesn't&lt;/strong&gt; do.&lt;/p&gt;

&lt;p&gt;It does not:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;disable Microsoft Defender&lt;/li&gt;
&lt;li&gt;disable Windows Update&lt;/li&gt;
&lt;li&gt;weaken UAC&lt;/li&gt;
&lt;li&gt;remove Microsoft Store&lt;/li&gt;
&lt;li&gt;remove Edge&lt;/li&gt;
&lt;li&gt;mass-remove inbox applications&lt;/li&gt;
&lt;li&gt;install third-party shell replacements&lt;/li&gt;
&lt;li&gt;apply dozens of undocumented registry tweaks&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal is not to produce an unsupported or heavily modified Windows build.&lt;/p&gt;

&lt;p&gt;The goal is simply to restore a few familiar behaviours.&lt;/p&gt;

&lt;h2&gt;
  
  
  Audit before apply
&lt;/h2&gt;

&lt;p&gt;The toolkit includes both audit and apply modes.&lt;/p&gt;

&lt;p&gt;To review the current state:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;.\Win11-Classic-Experience.ps1 -Mode Audit&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;To apply the changes:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;.\Win11-Classic-Experience.ps1 -Mode Apply -RestartExplorer&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Individual features can also be applied independently.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why build this?
&lt;/h2&gt;

&lt;p&gt;For me, this is less about resisting change and more about removing small pieces of friction.&lt;/p&gt;

&lt;p&gt;A familiar desktop can be useful, particularly for people who spend a lot of time administering systems and want the operating system itself to stay predictable.&lt;/p&gt;

&lt;p&gt;The project is available on GitHub:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Win11 Classic Experience&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;a href="https://github.com/rakeshranderia/win11-classic-experience" rel="noopener noreferrer"&gt;https://github.com/rakeshranderia/win11-classic-experience&lt;/a&gt;&lt;/p&gt;

</description>
      <category>windows11</category>
      <category>powershell</category>
      <category>sysadmin</category>
      <category>windows</category>
    </item>
  </channel>
</rss>
