Executives read a mandate for what it forbids and miss what it permits, and the delivery strategy almost always lives in the permissions.
Hand a demanding mandate to a capable executive team and watch where the attention goes. Within an hour there is a list of the dates that cannot move, the outcomes that cannot be compromised, the thresholds that cannot be breached. This is competent work on the wrong half of the document. The constraints define the shape of the box; the permissions define how much of it the enterprise may actually use, and it is remarkable how often that half is skimmed.
The counterintuitive observation is this: in most difficult programmes, the clause that decides whether the thing is deliverable is not a prohibition. It is a permission granted, recorded and never exercised. A sentence in the authorising instrument allows part of the operation to move before the whole does, or a facility to run at partial capacity while the rest is built, or an obligation to be met by a different route than everybody assumed. That sentence relaxes the binding constraint. Nothing enforces its use, so it sits there.
This matters because the enterprise's own analysis will not surface it. Prohibitions generate work: registers, controls, assurance, reporting. Permissions generate nothing unless somebody builds on them. A permission no one uses leaves no trace in any management system, produces no exception, triggers no review and costs nobody their position. It is the only element of a mandate that can be ignored without consequence, until the schedule fails and someone reads the document again.
The strategic question is therefore simple to ask and uncomfortable to answer: what has this enterprise been authorised to do that nobody has used?
The Strategic Context
There is a pattern visible in the way the discipline teaches this, and it is more instructive than any assertion about practice. Take a teaching brief built around a demanding transition: hard dates, an absolute welfare constraint, a financial target, a reuse instruction, and, in one sentence, a pre-authorisation to move the operation in stages, relocating parts of it before the whole shuts down. That sentence removes the largest single constraint on the schedule, because it converts a cutover into a migration.
Watch what the material does with it. In the initial decomposition, the prohibitions and dates are classified as constraints and success criteria, each with a downstream obligation attached. The staging permission is classified as a hint, listed near the bottom, and the work of turning it into a delivery approach does not appear until several instalments later, after the charter, the stakeholder plan, the breakdown structure and the control framework have all been organised around what must not happen and by when. A subsequent dissection of the same brief then identifies that clause as the most consequential sentence in it.
That is the shape of the failure in miniature. The permission is not hidden and it is not missed. It is correctly identified, eventually, and it is structurally demoted at the point where it would have changed the shape of the work. This is a discipline that reads mandates competently and still sequences its own attention prohibition-first.
Whether an approval to proceed is the same thing as a permission to act is a distinct question, and one already held elsewhere in the ERANORTH catalogue by articles 12 and 14. The concern here is narrower: an enterprise that is unambiguously permitted, and does not use it.
What Leaders Commonly Misread
The first misreading is to treat a permission as a concession rather than an instrument. When a regulator, a board or a counterparty grants flexibility, executives file it as goodwill: pleasant, non-binding, to be drawn on if things go badly. A permission is not a favour held in reserve. It is a change in the feasible set, and should be assessed as an option to acquire land or capacity would be: what does it allow, what is it worth, and what would we build to use it?
The second is the assumption that a permission needs no plan. It needs more plan than a prohibition does. Permission to stage a transition is worth nothing without stage definitions, gate criteria, dual-operation protocols and a designed rollback at each step. Enterprises that discover a permission late usually cannot use it, not because it lapsed, but because using it requires a delivery architecture they did not build and no longer have time to build.
The third is the belief that permissions are stable. They are held by people who move on, granted under conditions that change, and expressed in instruments that get reissued. An unexercised permission tends to be renegotiated more tightly at renewal, because nobody can point to a use that would be lost. Permissions do decay, and how an enterprise's broader stock of reversal capacity depletes without anyone keeping a balance is the subject of [Related article: Reversibility Is an Asset That Decays]; that is not the failure examined here. This article deals with the permission that remains fully available and is simply never taken up.
Reframing the Issue
A mandate is a two-sided document. One side states obligations and limits. The other states the latitude within which the enterprise may choose its method. Most organisations are structurally equipped to read only the first side, because compliance functions, assurance functions and audit functions all exist to test conformance with limits, and none exists to test whether available latitude has been used.
The reframing is to treat unexercised permission as unused capital. It was granted, it has value, and it is generating no return. A board that would notice an idle asset within a quarter can carry an idle permission for a decade.
Consider a port expansion under an existing approval as a hypothetical. The enterprise assumes it must complete the works before any new capacity operates, and plans accordingly: a long build, one commissioning event, a revenue step at the end. Read carefully, the approval already permits sections to be brought into service progressively, subject to conditions the enterprise can meet. Exercising that permission changes the funding profile, brings revenue forward, reduces peak exposure and removes the single-point commissioning risk. Nothing was blocking it. The plan was built from the conditions, because the conditions were all anybody read.
Why the Permissions Go Unread
Prohibitions have enforcers, permissions have none
Every limit in a mandate is attached to a party with an interest in its observance: a regulator, a funder, a counterparty, a control owner. Every permission is attached to nobody. No external party is disadvantaged when a permission goes unused, so none raises it, and internal assurance is calibrated to detect breach rather than underuse. An organisation can fail entirely to use its own authority and pass every audit it faces.
Using a permission is personally risky and institutionally cheap
Complying with a prohibition is defensible by construction: the executive who did what the mandate required cannot be criticised for the outcome. Exercising a permission is a choice, and choices carry authorship. If a staged approach produces a difficult overlap, the person who chose staging owns it; if a conventional approach fails, the mandate owns it. The asymmetry is rational and rarely acknowledged, and it biases the enterprise toward the most constrained reading of any document.
A regional broadcasting licensee illustrates the effect, again hypothetically. Its licence sets minimum obligations for local content and hours, and also permits some of those obligations to be met through shared or aggregated arrangements. The compliance team builds precisely to the minimums, year after year, because that position requires no authorisation and no defence. The permission that would change the cost base is never taken up, not because it was judged and rejected, but because using it would require a named person to depart from a settled practice that has never once produced a finding.
The permission arrives in the wrong document at the wrong moment
Permissions appear in authorising instruments (charters, consents, licences, delegations) read most closely at the beginning, by the people writing the initiation documents, then archived. Delivery decisions are taken months or years later by people working from the plan, not the instrument. By then the permission exists only in a document nobody consults, and the plan built without it has become the definition of the work.
One caution belongs here. Some permissions rest on variables the enterprise does not control, held by parties it has no contract with; how those external variables set and later reset the specification of a physical asset is the subject of [Related article: The Specification Was Set Outside Your Fence], and lies outside this article, which stops at the enterprise's own failure to read and use the authority it holds.
Decision Framework: The Permissions Reading
The instrument is a structured re-reading of the enterprise's authorising documents, repeated on a cycle. It takes two people two days for most programmes.
Step one — assemble the instruments. The mandate or charter, the licence or consent, the delegation schedule, the funding agreement, the head contract. Not the plan and not the summaries: the documents that grant authority.
Step two — classify every clause. Obligation, prohibition or permission. Anything containing may, is permitted, at the discretion of, or accepts that goes into the third category, which most organisations find larger than expected and documented nowhere else.
Step three — test each permission against the current plan.
| Test | What to record |
|---|---|
| Use | Does the approved plan rely on this permission — yes or no? |
| Value | What would change if it were used: schedule, funding profile, peak exposure, scope? |
| Build | What capability, protocol or governance would have to exist first, and how long would that take? |
| Grantor | Who granted it, do they still hold that role, and when is the instrument next reissued? |
| Decline | If the enterprise chooses not to use it, the recorded reason |
Step four — apply the governance rule. No delivery strategy is approved without a page listing the permissions relied on and those declined, each declination carrying a reason and a name. A strategy paper that does not mention permissions has not considered them; it has inherited the most constrained reading available.
Step five — set the review point. Re-run the reading whenever the sponsor changes, the instrument is reissued or the schedule comes under pressure. Schedule pressure is when enterprises finally reach for the document, and the reading is worth far more before that moment than during it.
From Strategy to Execution
Immediate. Run the reading on the enterprise's largest current commitment. The question to put to the team is not whether the plan is compliant, but whether any permission in the instruments would change it. Expect at least one, and expect it to have been visible from the start.
Medium-term. Change what a strategy paper must contain. Add the permissions page as a standing requirement, and give one named role, in commercial, legal or strategy, accountability for maintaining a live register of granted authority. Where a permission enables staged or phased delivery, plan the overlap explicitly, because staged delivery creates a period in which two operating states run at once and that period has a cost of its own; who funds the double-running, and why it is systematically unbudgeted, is the subject of [Related article: Nobody Funds the Overlap] and is not addressed here, where the argument stops at the decision to use the permission at all.
Long-term. Negotiate for permissions as deliberately as for price and dates. In consent processes, licence renewals and head contracts, flexibility clauses are usually available and rarely requested, because the negotiating team is optimising the obligations. Keep granted permissions alive across leadership changes, and treat an expiring unexercised permission as a loss worth reporting.
Signals to Monitor
The most reliable signal is a delivery plan shaped exactly as it would have been had the mandate contained no discretionary language at all. If the plan can be reconstructed entirely from the dates and the prohibitions, the permissions were not used.
Watch also for a strategy paper that quotes the mandate's constraints and never its latitude; for "we are not allowed to" surviving in discussion without anyone producing the clause; for licence renewals negotiated without a review of unused provisions; for authorising instruments not opened since initiation, which is easily checked; and for a grantor whose successor has never been briefed on what their predecessor allowed.
Questions for the Leadership Team
- In our largest current commitment, which clauses of the authorising instrument grant discretion, and which of them does the approved plan use?
- What would our delivery approach look like if we were required to use every permission available to us — and what would that be worth?
- When did anyone last open the founding instrument of a programme already in execution, and what were they looking for?
- Which permissions granted to this enterprise expire, lapse or come up for reissue in the next two years, and have any of them ever been exercised?
- Who is accountable for knowing what we are allowed to do, as distinct from what we are required to do?
- In the last three consent, licence or contract negotiations, what flexibility did we ask for, and what did we accept without asking?
Closing Perspective
The habit described here is not carelessness. It is the predictable output of an organisation built to be defensible, in which reading a document narrowly is always safe and reading it fully requires someone to take authorship of a choice. Every incentive points the same way, which is why the pattern survives in capable enterprises with strong governance, and why it will not correct itself.
What follows is a responsibility that cannot be delegated to assurance, because assurance is not designed to detect it. Someone senior has to ask, deliberately and on a schedule, what the enterprise is already allowed to do and is not doing. The permissions in an existing mandate are the cheapest strategic latitude available to any organisation: already granted, already negotiated, requiring no new approval and no new money. An enterprise that leaves them unread is not being prudent. It is declining an asset it has already paid for.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
