Evaluator guide

Cutover pre-mortem

What breaks at go-live, listed before it does

Every finding below is derived from a measured signature in the as-is model: re-keying becomes a data-quality defect, a shadow step has no home in the tenant, a normalized exception has no condition rule. Each carries a named mitigation and the Workday object that implements it.

45
findings
derived from the model
30
high severity
resolve before cutover
15
medium severity
design decisions
4
failure categories
No home in the tenant · Data-quality defect · Missing condition rule
highNo home in the tenantOnboarding

Failure mode

Position funding confirmed against the salary line

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Position Restrictions · Position Budget integration. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectOnboarding

Failure mode

Background investigation package initiated

"Investigation forms" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Onboarding BP · Background Check Service integration. Single capture point, downstream systems fed by integration.

highData-quality defectOnboarding

Failure mode

Workspace, badge and physical access requested

"Access request" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Onboarding BP · outbound provisioning integration. Single capture point, downstream systems fed by integration.

highData-quality defectOnboarding

Failure mode

IT account, equipment and system entitlements requested

"Provisioning ticket" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Onboarding BP · role-based provisioning by Job Profile. Single capture point, downstream systems fed by integration.

highNo home in the tenantOnboarding

Failure mode

Contractor-supported role checked against the contract vehicle

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Condition rule on Worker Type = Contingent Worker. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectOnboarding

Failure mode

New-hire record created in the HR system

"Employee record" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Hire BP · Worker record with Job Profile and Comp. Single capture point, downstream systems fed by integration.

highNo home in the tenantOnboarding

Failure mode

Orientation scheduled and mandatory training assigned

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Learning assignment rule on Hire event. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantOnboarding

Failure mode

Supervisor onboarding checklist issued and tracked

This step lives in email with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Onboarding BP · To Do steps on the manager's inbox. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantOnboarding

Failure mode

Day-one readiness confirmed across directorates

This step lives in email with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Onboarding BP · consolidated status report. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectOnboarding

Failure mode

Personnel action documented to the official file

"Personnel action" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Business process audit trail · eOPF integration. Single capture point, downstream systems fed by integration.

highNo home in the tenantPerformance management

Failure mode

Cycle opened and performance plans distributed

This step lives in email with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Performance Review BP · mass launch by Org. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantPerformance management

Failure mode

Mid-year progress review recorded

This step lives in email with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Performance Review BP · Check-In event. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectPerformance management

Failure mode

Training completion checked against the plan

"Completion export" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Learning Enrollment report feeding the review. Single capture point, downstream systems fed by integration.

highNo home in the tenantPerformance management

Failure mode

Training completion checked against the plan

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Learning Enrollment report feeding the review. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectPerformance management

Failure mode

Rating distribution reviewed for consistency

"Distribution sheet" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Delivered Performance analytics · calibration. Single capture point, downstream systems fed by integration.

highNo home in the tenantPerformance management

Failure mode

Rating distribution reviewed for consistency

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Delivered Performance analytics · calibration. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantPerformance management

Failure mode

Award funding confirmed against available budget

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: One-Time Payment BP · budget check integration. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantOffboarding

Failure mode

Clearance checklist issued to all directorates

This step lives in email with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Termination BP · parallel To Do steps by role. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantOffboarding

Failure mode

Contract or vehicle access closed for contingent staff

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Condition rule on Worker Type = Contingent Worker. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectOffboarding

Failure mode

Training obligations and tuition payback checked

"Obligation check" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Learning obligation report on Termination event. Single capture point, downstream systems fed by integration.

highNo home in the tenantOffboarding

Failure mode

Training obligations and tuition payback checked

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Learning obligation report on Termination event. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectOffboarding

Failure mode

Final leave balance, pay and debt reconciled

"Final pay record" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Termination BP · Payroll and Absence integration. Single capture point, downstream systems fed by integration.

highNo home in the tenantOffboarding

Failure mode

Exit interview offered and recorded

This step lives in email with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Termination BP · optional questionnaire step. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantTraining request to completion

Failure mode

Training office reviews for duplication and eligibility

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Delivered Learning eligibility rules and catalog check. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantTraining request to completion

Failure mode

Funding availability confirmed for the fiscal year

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Budget check integration on the Learning BP. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectTraining request to completion

Failure mode

Continued service agreement executed if required

"Service agreement" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Learning BP · document generation and e-signature. Single capture point, downstream systems fed by integration.

highData-quality defectTraining request to completion

Failure mode

Attendance and completion recorded

"Completion record" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Learning Enrollment completion · transcript. Single capture point, downstream systems fed by integration.

highNo home in the tenantTraining request to completion

Failure mode

Attendance and completion recorded

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Learning Enrollment completion · transcript. If it is deliberately out-of-system, name an owner and a reason in the design.

highNo home in the tenantTraining request to completion

Failure mode

Cost reconciled to the obligation and closed out

This step lives in spreadsheet tracker with no system of record. It is absent from any configuration workbook built from system inventories, so go-live silently drops it.

Mitigation

Give it an explicit home: Learning cost report to financial system. If it is deliberately out-of-system, name an owner and a reason in the design.

highData-quality defectTraining request to completion

Failure mode

Credit reflected against the employee development record

"Record update" is re-keyed by hand today. Migrated as-is, the same double entry runs against the new tenant and seeds divergent records from day one.

Mitigation

Resolve before cutover: Worker Learning transcript · single record. Single capture point, downstream systems fed by integration.

mediumMissing condition ruleOnboarding

Failure mode

Background investigation package initiated

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Onboarding BP · Background Check Service integration, or fix the upstream policy that produces it.

mediumRouting designOnboarding

Failure mode

IT account, equipment and system entitlements requested

Serial approvals with no mutual dependency. Reproduced as sequential BP steps, the new tenant inherits the old queue.

Mitigation

Parallel approval steps or a single consolidated approval in the business process definition.

mediumMissing condition ruleOnboarding

Failure mode

Supervisor onboarding checklist issued and tracked

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Onboarding BP · To Do steps on the manager's inbox, or fix the upstream policy that produces it.

mediumMissing condition ruleOnboarding

Failure mode

Day-one readiness confirmed across directorates

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Onboarding BP · consolidated status report, or fix the upstream policy that produces it.

mediumRouting designOnboarding

Failure mode

Personnel action documented to the official file

Serial approvals with no mutual dependency. Reproduced as sequential BP steps, the new tenant inherits the old queue.

Mitigation

Parallel approval steps or a single consolidated approval in the business process definition.

mediumMissing condition rulePerformance management

Failure mode

Supervisor drafts and issues the employee plan

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Performance Review BP · Manager Evaluation step, or fix the upstream policy that produces it.

mediumMissing condition rulePerformance management

Failure mode

Mid-year progress review recorded

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Performance Review BP · Check-In event, or fix the upstream policy that produces it.

mediumRouting designPerformance management

Failure mode

Rating drafted, reviewed by second-level official

Serial approvals with no mutual dependency. Reproduced as sequential BP steps, the new tenant inherits the old queue.

Mitigation

Parallel approval steps or a single consolidated approval in the business process definition.

mediumMissing condition ruleOffboarding

Failure mode

Separation type and effective date determined

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Termination BP · reason code with condition rules, or fix the upstream policy that produces it.

mediumMissing condition ruleOffboarding

Failure mode

Clearance checklist issued to all directorates

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Termination BP · parallel To Do steps by role, or fix the upstream policy that produces it.

mediumMissing condition ruleOffboarding

Failure mode

Exit interview offered and recorded

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Termination BP · optional questionnaire step, or fix the upstream policy that produces it.

mediumRouting designOffboarding

Failure mode

Clearance certified complete and action filed

Serial approvals with no mutual dependency. Reproduced as sequential BP steps, the new tenant inherits the old queue.

Mitigation

Parallel approval steps or a single consolidated approval in the business process definition.

mediumMissing condition ruleTraining request to completion

Failure mode

Vendor training procured where a purchase is required

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Condition rule routes to procurement sub-process, or fix the upstream policy that produces it.

mediumRouting designTraining request to completion

Failure mode

Vendor training procured where a purchase is required

Serial approvals with no mutual dependency. Reproduced as sequential BP steps, the new tenant inherits the old queue.

Mitigation

Parallel approval steps or a single consolidated approval in the business process definition.

mediumMissing condition ruleTraining request to completion

Failure mode

Continued service agreement executed if required

The exception path here runs in more than one case in five. A tenant configured to the documented happy path will throw this volume at manual workarounds immediately.

Mitigation

Model the exception as a condition rule inside Learning BP · document generation and e-signature, or fix the upstream policy that produces it.