---
# /blocks/resilience/ - stamped from block-map-canon-v0.5 (entry 10) and the
# block-page template. Confidentiality: shape yes, implementation no; moments
# are illustrative composites; no client names, thresholds or gated figures.
title: 'The resilience block'
slug: 'resilience'
object: 'The important business service and its incidents - from normal operation through disruption to recovery.'
pain: 'When something breaks the regulatory clock starts before we have understood what happened.'
description: 'Every important service run as one loop - the blast radius mapped and the notification clock managed before the scramble, governed to a named human.'
metaTitle: 'The resilience block: incidents, mapped and governed'
related:
  - 'obligations'
  - 'third-party'
order: 11
noindex: false # launched 2026-07-24
---

# The resilience block

**Every important service, run as one loop** - the blast radius mapped and
the clock managed before the scramble.

---

## The pain

*"When something breaks we scramble - no one can see the blast radius, and the
regulatory clock starts before we have understood what happened."*

An incident is the moment the firm's dependencies all matter at once, and it is
exactly the moment no one can see them. The error rate ticks up in monitoring,
a complaint spike forms in service, a supplier's failure lands in ops - each in
its own place, none joined into "which important service is now at risk, and
what does it touch." So the response is a manual scramble to reconstruct the map
while the impact tolerance erodes and the notification clock, which started the
moment the service breached, runs unmanaged. In regulated firms this is the
important business service and its impact tolerances; in distribution, platform
and logistics uptime; in legal, matter-critical systems.

## What the block is

The object is the important business service and its incidents - one continuous
picture per service, from normal operation through disruption, response,
recovery and control update. Everything it produces feeds one live record:
service health and incidents, impact tolerances, dependencies, notifications
and control changes. A model reads it permanently. Your monitoring,
service-management and incident systems stay exactly where they are - the block
reads from them, it does not replace them.

## The loop in action

[MOMENT: styled quote panel]
An error rate and latency drift on an important service, ahead of any outage.
The block opens a pre-incident investigation before customers feel a thing:
*"this service is degrading toward its impact tolerance; here is what depends on
it and what is likely failing."* The scramble that would have started after the
outage starts before it - with the map already drawn. - *the dial: recommend*

[MOMENT: styled quote panel]
The catch. A security event is logged, and a containment step would help - but
containment touches production and customers. The block prepares the playbook
and holds it at the gate: *"a containment step is ready; it runs on a named
human's word, not on its own."* The fast action is available and the
irreversible one is never taken unsupervised - the whole point of governing the
muscle. - *the dial: draft, human-gated*

[MOMENT: styled quote panel]
An important service crosses toward breaching its impact tolerance. The block
escalates with the regulatory clock started and managed ⇄ the obligations loop -
the notification deadline tracked from the moment it began, not discovered
after it has passed. The clock is handled rather than missed. - *the dial:
recommend*

Each output states what it saw, why it matters, what it recommends, and how
confident it is - every fact linked back to its source, in an order an
operations lead can read and a regulator can examine.

## You set the dial

Every capability has four positions: **observe** - it reads silently and
measures its own accuracy; **recommend** - it surfaces the case and a proposed
action to a named owner; **draft** - it prepares the action for a human
signature; **act** - it executes within agreed bounds and logs everything.

Everything starts at observe. Promotion is earned on the measured record and
reversed instantly if it doesn't hold. Customer and regulatory notifications,
and any containment that touches production, stay behind a named human -
permanently, if that is your policy. The mechanics are the immune gate described
in [our framework](/ai-native-company/).

## How it lands

It starts narrow: one important business service, the block at observe against
your own past outcomes. Nothing is replaced, nothing is migrated - the first
signals flow from the monitoring and incident systems you already run. From
there it is a bounded engagement - blueprint, build, handover - and your team owns
the result outright: the signal map, the judgement rules, the dial settings,
the working loop.

## The backtest

Take three past incidents: one contained within tolerance, one that surprised
you, and one where the regulatory clock started before you understood what had
happened. What did your own systems know, and when?

That is the first question the diagnostic answers. Take
[the ten-minute diagnostic](https://benchmark.somai.studio), or write
to [hello@somai.studio](mailto:hello@somai.studio?subject=The%20resilience%20block).

---

<small>Runs on [our framework](/ai-native-company/) · related reading:
[Most AI spend never reaches the P&L](/thinking/most-ai-spend-never-reaches-the-pnl/)</small>
