§9.6 · BUILDING · 3 MIN READ · EDITION 1.0
Sunsetting a capability responsibly
Stopping a capability needs the same discipline as starting one: a decision record, a communication to affected users, a transition plan for the manual process it replaced, and retained evidence of why it was stopped.
A quietly abandoned tool that users still occasionally invoke is worse than a formally retired one; ambiguity about whether a capability is still supported is itself a control gap.
Retain the qualification history and incident record even after sunset — a later, similar use case can learn from why the earlier one was stopped.
PUT THIS INTO PRACTICE
- 01Communicate sunset decisions to all affected users.
- 02Restore or confirm the manual process before switching off the capability.
- 03Retain qualification and incident history after sunset.
RELATED INSTRUMENTS
CITE THIS SECTION
§9.6 · Edition 1.0 · Sunsetting a capability responsibly