{
  "object_name": "Platform Map",
  "object_slug": "platform-map",
  "version": "1.0",
  "last_reviewed": "2026-06-24",
  "owner": "LPM / Lapemo",
  "object_type": "LPM Knowledge Object",
  "primary_lpm_layers": [
    "Platform Structure",
    "Information Ecology",
    "Governance Architecture",
    "AI Amplification"
  ],
  "connected_lpm_layers": [
    "Ownership Map",
    "Decision Architecture",
    "Communication Architecture",
    "Source-of-Truth Map",
    "Data Lineage Map"
  ],
  "purpose": "Map enterprise platforms, systems of record, integration paths, ownership, controls, data flows, and AI usage boundaries under one operating model.",
  "intended_audience": [
    "Executives",
    "Transformation Leaders",
    "Enterprise Architects",
    "Platform Owners",
    "Data Leaders",
    "AI Governance Teams",
    "Risk and Compliance",
    "Product and Operations Leaders"
  ],
  "required_fields": [
    {
      "name": "Platform ID",
      "definition": "Unique identifier for the platform, system, application, data product, integration, or AI tool",
      "required": "Yes"
    },
    {
      "name": "Platform name",
      "definition": "Common business and technical name of the platform",
      "required": "Yes"
    },
    {
      "name": "Platform category",
      "definition": "Work, people, customer, finance, data/BI, governance/risk, knowledge, AI, integration, identity, or infrastructure",
      "required": "Yes"
    },
    {
      "name": "Business capability",
      "definition": "The capability, process, decision, or operating need this platform supports",
      "required": "Yes"
    },
    {
      "name": "Primary users",
      "definition": "Functions, roles, teams, agents, vendors, or customers who use the platform",
      "required": "Yes"
    },
    {
      "name": "Business owner",
      "definition": "Accountable owner for purpose, value, adoption, operating rules, and approved use",
      "required": "Yes"
    },
    {
      "name": "Technical owner",
      "definition": "Accountable owner for reliability, configuration, integrations, access, and support",
      "required": "Yes"
    },
    {
      "name": "Data owner / steward",
      "definition": "Owner of the critical data objects, definitions, freshness, and quality rules in the platform",
      "required": "Required when data-critical"
    },
    {
      "name": "System of record status",
      "definition": "Authoritative, consuming, reference, temporary, duplicate, shadow, retired, or disputed",
      "required": "Yes"
    },
    {
      "name": "Critical objects",
      "definition": "Core records, entities, metrics, artifacts, documents, or workflows managed by the platform",
      "required": "Yes"
    },
    {
      "name": "Source-of-truth relationship",
      "definition": "Whether the platform creates, masters, consumes, transforms, reports, indexes, or archives the object",
      "required": "Yes"
    },
    {
      "name": "Integration path",
      "definition": "APIs, webhooks, ETL/ELT, events, file transfers, RPA, workflow automation, native connector, or manual handoff",
      "required": "Yes"
    },
    {
      "name": "Upstream dependencies",
      "definition": "Systems, sources, teams, vendors, or data products required for the platform to work",
      "required": "Yes"
    },
    {
      "name": "Downstream consumers",
      "definition": "Systems, reports, AI tools, workflows, controls, teams, or external parties that depend on this platform",
      "required": "Yes"
    },
    {
      "name": "Control requirements",
      "definition": "Access, audit, retention, approvals, segregation, evidence, policy, compliance, or model risk requirements",
      "required": "Yes"
    },
    {
      "name": "AI usage boundary",
      "definition": "Whether AI can retrieve, summarize, update, classify, recommend, create, approve, or act through the platform",
      "required": "Yes"
    },
    {
      "name": "Human review rule",
      "definition": "When a human must approve a platform change, AI action, workflow step, or data update",
      "required": "Required when material"
    },
    {
      "name": "Adoption / value metric",
      "definition": "Usage, cycle time, quality, cost, revenue, risk, experience, or automation metric used to assess value",
      "required": "Yes"
    },
    {
      "name": "Health signal",
      "definition": "Reliability, support burden, duplicate usage, stale data, manual workaround, integration failure, or control exception",
      "required": "Yes"
    },
    {
      "name": "Lifecycle state",
      "definition": "Explore, pilot, active, governed, constrained, consolidate, replace, retire, or exception",
      "required": "Yes"
    },
    {
      "name": "Known gaps",
      "definition": "Missing owner, duplicate platform, weak integration, stale data, ungoverned AI access, or shadow usage",
      "required": "Yes"
    },
    {
      "name": "Review date",
      "definition": "Next date to review ownership, usage, value, controls, integrations, and AI boundaries",
      "required": "Yes"
    },
    {
      "name": "Version",
      "definition": "Object version, owner, last reviewed date, and change history",
      "required": "Yes"
    }
  ],
  "platform_categories": [
    {
      "category": "Work systems",
      "examples": "Jira, Asana, Monday, Azure DevOps, ServiceNow, Linear",
      "operating_role": "Intake, planning, delivery, dependencies, blockers, outcomes",
      "primary_owners": "Product / PMO owner, work system owner",
      "common_risk": "Hidden work, status theater, duplicate backlogs"
    },
    {
      "category": "People systems",
      "examples": "Workday, SuccessFactors, ADP, Greenhouse, Lattice",
      "operating_role": "Org structure, roles, skills, capacity, performance, incentives",
      "primary_owners": "People owner, HRIS owner, identity owner",
      "common_risk": "Bad org data, unclear roles, AI workforce routing errors"
    },
    {
      "category": "Customer / revenue systems",
      "examples": "Salesforce, HubSpot, Gainsight, Zendesk, Intercom",
      "operating_role": "Customer records, pipeline, support, success, renewal, experience",
      "primary_owners": "Revenue owner, CX owner, CRM owner",
      "common_risk": "Duplicate customer truth, weak handoffs, AI outreach risk"
    },
    {
      "category": "Finance / resource systems",
      "examples": "ERP, FP&A, procurement, billing, planning tools",
      "operating_role": "Budget, cost, vendor spend, resource allocation, benefits tracking",
      "primary_owners": "Finance owner, ERP owner, budget owner",
      "common_risk": "Untracked AI cost, benefit leakage, vendor sprawl"
    },
    {
      "category": "Data and BI systems",
      "examples": "Snowflake, Databricks, Power BI, Tableau, Looker, dbt",
      "operating_role": "Metrics, analytics, data products, semantic models, dashboards",
      "primary_owners": "Data owner, analytics owner, BI owner",
      "common_risk": "Competing dashboards, stale metrics, weak lineage"
    },
    {
      "category": "Knowledge systems",
      "examples": "Confluence, SharePoint, Notion, Google Drive, wikis",
      "operating_role": "Policies, SOPs, playbooks, templates, decisions, knowledge objects",
      "primary_owners": "Knowledge owner, content steward, platform owner",
      "common_risk": "Stale content becomes AI memory"
    },
    {
      "category": "Governance and risk systems",
      "examples": "GRC, IAM, legal, privacy, audit, policy platforms",
      "operating_role": "Controls, policies, exceptions, access, risk, compliance evidence",
      "primary_owners": "Risk owner, control owner, GRC owner",
      "common_risk": "Controls disconnected from work and AI actions"
    },
    {
      "category": "Integration and automation systems",
      "examples": "Mulesoft, Workato, Zapier, n8n, APIs, event streams, RPA",
      "operating_role": "Data movement, workflow automation, handoffs, system actions",
      "primary_owners": "Integration owner, platform owner, automation owner",
      "common_risk": "Brittle automations, no failure path, no audit trail"
    },
    {
      "category": "AI systems",
      "examples": "Copilot, ChatGPT Enterprise, Claude, agent platforms, vector DBs, model registry",
      "operating_role": "Retrieval, summarization, recommendation, generation, automation, agents",
      "primary_owners": "AI owner, model owner, data owner, governance owner",
      "common_risk": "Agents act without authority, source, or review"
    }
  ],
  "map_stages": [
    {
      "stage": "1. Identify",
      "what_happens": "Catalog the platform, category, users, owner, capability, and lifecycle state.",
      "evidence": "Platform register, app inventory, owner list",
      "key_fields": "Platform ID, business owner, technical owner",
      "common_risk": "No named owner or unknown usage"
    },
    {
      "stage": "2. Classify",
      "what_happens": "Determine whether the platform creates, masters, consumes, reports, indexes, or automates enterprise objects.",
      "evidence": "Source-of-truth map, data catalog, process map",
      "key_fields": "System-of-record status, critical objects",
      "common_risk": "Duplicate truth or disputed source"
    },
    {
      "stage": "3. Connect",
      "what_happens": "Map integrations, upstream dependencies, downstream consumers, workflows, and AI access paths.",
      "evidence": "Integration catalog, API list, data lineage map",
      "key_fields": "Integration path, dependencies, consumers",
      "common_risk": "Manual handoffs or invisible automation"
    },
    {
      "stage": "4. Govern",
      "what_happens": "Attach access, control, retention, evidence, review, and escalation rules.",
      "evidence": "GRC records, access model, audit logs",
      "key_fields": "Control requirements, review rule, evidence link",
      "common_risk": "Platform action without policy or control"
    },
    {
      "stage": "5. Measure",
      "what_happens": "Track adoption, value, reliability, risk, cost, and support burden.",
      "evidence": "Usage metrics, cost data, tickets, SLA, value score",
      "key_fields": "Adoption metric, health signal, value metric",
      "common_risk": "Shelfware, redundant spend, low-trust system"
    },
    {
      "stage": "6. Optimize",
      "what_happens": "Decide whether to standardize, consolidate, integrate, replace, constrain, or retire.",
      "evidence": "Rationalization plan, roadmap, exception list",
      "key_fields": "Lifecycle state, known gaps, next action",
      "common_risk": "Tool sprawl and unmanaged shadow systems"
    },
    {
      "stage": "7. AI-enable safely",
      "what_happens": "Define whether AI can retrieve, summarize, recommend, update, approve, or act through the platform.",
      "evidence": "AI policy, model registry, agent logs, permission model",
      "key_fields": "AI boundary, human review, audit trail",
      "common_risk": "AI reaches into systems without authority"
    }
  ],
  "platform_archetypes": [
    {
      "archetype": "System of record",
      "definition": "Authoritative platform where a critical object is created or mastered",
      "examples": "HRIS for employee record, CRM for account record",
      "governance_requirement": "Must have business owner, data steward, access rule, lineage, and evidence standard"
    },
    {
      "archetype": "System of work",
      "definition": "Platform where teams plan, execute, track, or coordinate work",
      "examples": "Jira, ServiceNow, Azure DevOps, Asana",
      "governance_requirement": "Must connect to decision logs, ownership, delivery metrics, and escalation path"
    },
    {
      "archetype": "System of intelligence",
      "definition": "Platform that analyzes, reports, predicts, or recommends",
      "examples": "BI tools, analytics layers, AI assistants, model platforms",
      "governance_requirement": "Must reference approved sources, confidence, freshness, and review rules"
    },
    {
      "archetype": "System of control",
      "definition": "Platform that enforces risk, access, policy, approvals, or compliance",
      "examples": "IAM, GRC, policy, audit, legal, privacy platforms",
      "governance_requirement": "Must connect to evidence, exceptions, ownership, and automated control checks"
    },
    {
      "archetype": "System of integration",
      "definition": "Platform that moves data or executes workflow across systems",
      "examples": "API gateway, iPaaS, event platform, RPA, workflow automation",
      "governance_requirement": "Must have failure handling, ownership, observability, and audit trail"
    },
    {
      "archetype": "Knowledge system",
      "definition": "Platform that stores reusable human and AI-readable knowledge",
      "examples": "SharePoint, Confluence, Notion, knowledge bases, prompt libraries",
      "governance_requirement": "Must have content ownership, freshness review, versioning, and AI retrieval boundary"
    },
    {
      "archetype": "Shadow system",
      "definition": "Unapproved or unmanaged tool used because official systems do not meet the need",
      "examples": "Spreadsheets, local databases, rogue SaaS, personal AI tools",
      "governance_requirement": "Must be evaluated for unmet need, risk, value, and replacement path"
    }
  ],
  "company_versions": {
    "500_plus": [
      {
        "dimension": "Design intent",
        "recommended_pattern": "Create basic platform visibility before systems, spreadsheets, AI tools, and ownerless workflows multiply."
      },
      {
        "dimension": "Minimum scope",
        "recommended_pattern": "Map the top 20 to 40 platforms across work, people, customer, finance, data, knowledge, governance, integration, and AI."
      },
      {
        "dimension": "Operating pattern",
        "recommended_pattern": "Monthly platform review led by technology, transformation, and business owners with a simple lifecycle status."
      },
      {
        "dimension": "AI focus",
        "recommended_pattern": "Block AI access to unowned or disputed systems. Allow summary and retrieval only from named sources with human review."
      },
      {
        "dimension": "Governance need",
        "recommended_pattern": "Name owners, define source-of-truth status, list integrations, and identify shadow tools before rationalizing."
      },
      {
        "dimension": "Red flags",
        "recommended_pattern": "No platform owner, duplicate customer or employee truth, manual exports, AI pilots using local files, and unclear usage metrics."
      }
    ],
    "5000_plus": [
      {
        "dimension": "Design intent",
        "recommended_pattern": "Move from tool inventory to capability-owned platform architecture that supports cross-functional execution and governed AI."
      },
      {
        "dimension": "Minimum scope",
        "recommended_pattern": "Map enterprise platforms, critical integrations, domain systems of record, BI layers, GRC systems, and AI platforms."
      },
      {
        "dimension": "Operating pattern",
        "recommended_pattern": "Quarterly platform governance by domain with lifecycle decisions, adoption metrics, control status, and integration health."
      },
      {
        "dimension": "AI focus",
        "recommended_pattern": "Define AI usage boundaries by platform: retrieve, summarize, recommend, update, create, approve, or act."
      },
      {
        "dimension": "Governance need",
        "recommended_pattern": "Connect each platform to owners, data objects, access rules, evidence standards, lineage, and escalation paths."
      },
      {
        "dimension": "Red flags",
        "recommended_pattern": "Business units buying duplicate SaaS, integration debt, BI sprawl, ungoverned copilots, and automation without audit trail."
      }
    ],
    "10000_plus": [
      {
        "dimension": "Design intent",
        "recommended_pattern": "Create enterprise platform control across business units, shared services, data domains, AI agents, risk, and regulatory obligations."
      },
      {
        "dimension": "Minimum scope",
        "recommended_pattern": "Map Tier 1 and Tier 2 platforms, systems of record, high-risk integrations, AI-critical data paths, control systems, and external data sharing."
      },
      {
        "dimension": "Operating pattern",
        "recommended_pattern": "Enterprise platform council, domain architecture boards, automated dependency tracking, evidence packs, and lifecycle governance."
      },
      {
        "dimension": "AI focus",
        "recommended_pattern": "AI agents require platform permission boundaries, tool-use logs, source lineage, model risk tiering, human review, and kill-switch rules."
      },
      {
        "dimension": "Governance need",
        "recommended_pattern": "Connect platform changes to access, data, risk, policy, architecture, procurement, security, and audit review."
      },
      {
        "dimension": "Red flags",
        "recommended_pattern": "Federated sprawl, business-unit-specific truth, unmanaged vendor platforms, silent API dependencies, and AI acting across systems without decision rights."
      }
    ]
  },
  "scoring_logic": [
    {
      "dimension": "Ownership clarity",
      "score_range": "0-5",
      "good_state": "Business, technical, data, control, and AI owners are named for critical platforms."
    },
    {
      "dimension": "Purpose clarity",
      "score_range": "0-5",
      "good_state": "Each platform has a clear capability, user group, value metric, and lifecycle state."
    },
    {
      "dimension": "Source-of-truth clarity",
      "score_range": "0-5",
      "good_state": "Critical objects have authoritative system status and known consumers."
    },
    {
      "dimension": "Integration visibility",
      "score_range": "0-5",
      "good_state": "Upstream and downstream dependencies are mapped with owners and failure paths."
    },
    {
      "dimension": "Governance strength",
      "score_range": "0-5",
      "good_state": "Access, retention, controls, evidence, policy, and escalation rules are defined."
    },
    {
      "dimension": "AI boundary clarity",
      "score_range": "0-5",
      "good_state": "AI retrieval, recommendation, update, action, and review boundaries are explicit."
    },
    {
      "dimension": "Health visibility",
      "score_range": "0-5",
      "good_state": "Usage, reliability, support burden, cost, adoption, and risk signals are monitored."
    },
    {
      "dimension": "Lifecycle discipline",
      "score_range": "0-5",
      "good_state": "Platforms are actively governed as pilot, active, consolidate, replace, retire, or exception."
    }
  ],
  "readiness_formula": "Average the eight dimension scores. 0-1.9 Fragmented, 2.0-3.4 Mapped, 3.5-4.4 Governed, 4.5-5.0 AI-ready.",
  "ai_prompts": [
    "Given this platform inventory, classify each system by category, lifecycle state, source-of-truth status, and AI usage boundary.",
    "Identify duplicate platforms, shadow tools, weak ownership, risky integrations, stale data paths, and ungoverned AI access.",
    "Score each platform from 0 to 5 across ownership clarity, purpose clarity, source-of-truth clarity, integration visibility, governance strength, AI boundary clarity, health visibility, and lifecycle discipline.",
    "Generate a platform dependency map showing upstream systems, downstream consumers, critical objects, integrations, AI consumers, and control evidence.",
    "Recommend whether each platform should be standardized, integrated, governed harder, consolidated, replaced, retired, or accepted as an exception.",
    "Create a Lapemo ingestion plan that converts this platform map into platform objects, ownership objects, integration objects, data objects, control objects, and AI boundary rules."
  ],
  "validation_rules": [
    "Every critical platform must have a business owner and technical owner.",
    "Every system of record must identify the critical objects it masters and the downstream systems that consume them.",
    "Every integration must have an owner, purpose, failure path, observability signal, and review date.",
    "Every platform used by AI must have an approved AI usage boundary and human review rule.",
    "No AI tool should retrieve, update, approve, or act through a platform unless access, source, lineage, and decision rights are defined.",
    "Shadow systems must be flagged as unmet-need signals, not ignored or instantly removed.",
    "A platform cannot be classified as authoritative if ownership, freshness, access rules, and evidence links are missing.",
    "Status must never be encoded only by color; use labels such as authoritative, consuming, duplicate, shadow, disputed, active, governed, constrained, retire, or exception."
  ],
  "lapemo_mapping": [
    {
      "lapemo_object": "Knowledge object",
      "fields_or_entities": "Platform Map",
      "use": "Canonical reusable artifact for platform control and AI-safe system access."
    },
    {
      "lapemo_object": "Platform object",
      "fields_or_entities": "Platform ID, category, lifecycle, capability, source-of-truth status",
      "use": "Creates the enterprise platform inventory and control layer."
    },
    {
      "lapemo_object": "Ownership object",
      "fields_or_entities": "Business owner, technical owner, data owner, control owner, AI owner",
      "use": "Connects systems to accountable humans."
    },
    {
      "lapemo_object": "Integration object",
      "fields_or_entities": "Upstream dependencies, downstream consumers, API/event/file/RPA/workflow paths",
      "use": "Shows how systems connect and where risk travels."
    },
    {
      "lapemo_object": "Information object",
      "fields_or_entities": "Critical objects, source-of-truth relationship, lineage, freshness, evidence",
      "use": "Links platform structure to enterprise truth."
    },
    {
      "lapemo_object": "Governance object",
      "fields_or_entities": "Access, control, retention, policy, exception, review date",
      "use": "Links systems to operating controls and auditability."
    },
    {
      "lapemo_object": "AI object",
      "fields_or_entities": "AI usage boundary, permissions, review rule, logs, agent tool use",
      "use": "Defines what AI can safely do across platforms."
    }
  ],
  "render_targets": [
    "DOCX template",
    "PDF guide",
    "Website Markdown",
    "JSON skill schema",
    "Interactive form",
    "Lapemo onboarding workflow",
    "Platform control dashboard",
    "Integration dependency graph",
    "AI access boundary review"
  ],
  "automation_policy": {
    "auto_update": false,
    "recommended_mode": "Flag missing platform owners, duplicate systems, stale integrations, ungoverned AI access, shadow tools, and dependency changes for human approval.",
    "human_approval_required_for": [
      "source-of-truth status changes",
      "AI usage boundary changes",
      "system owner changes",
      "critical integration changes",
      "platform retirement",
      "external data sharing",
      "control requirement changes"
    ]
  }
}