CALIPER
Impact tolerance calibrator: derived, challenged, board-ready tolerances per important business service.
The problem
Every operational resilience regime asks the same deceptively simple question: how much disruption to this service is too much? Most banks answer with a round number. Two hours for payments, one day for lending, chosen in a workshop, anchored on the first figure someone said aloud, and defended ever after because changing it would mean admitting it was never derived. Impact tolerance is the load-bearing promise of the resilience framework, and in practice it is usually the least evidenced number in the building.
What it does
CALIPER treats an impact tolerance as a conclusion, not an input. For each important business service it works across the harm dimensions that regulators actually name: customer harm, market integrity, safety and soundness, and reputational damage. Harm curves describe how each dimension deteriorates as an outage extends; the tolerance falls out of the curves, and the binding dimension is the one that breaks first.
The build carries three working instruments. A derivation workbench turns harm assumptions into tolerance candidates per service, with every assumption inspectable and every curve editable. An elicitation copilot structures the conversation with service owners, pressing on the assumptions that drive the answer instead of collecting opinions. A board translator renders the result in the language a board can approve: what the number is, which harm binds it, and what evidence stands behind it.
The demonstration beat is the inversion: a service whose tolerance everyone believed was bound by customer harm turns out, once the curves are drawn, to be bound by market integrity. The round number survives the workshop. It does not survive the derivation.
Why it matters
Supervisory frameworks from the UK operational resilience regime to DORA and OSFI E-21 expect impact tolerances that are set, evidenced, and tested. A tolerance with no derivation behind it fails the second expectation quietly and the third one publicly, when a scenario test breaches a number nobody can defend. Deriving tolerances from harm curves makes the promise auditable, and makes the annual review a recalibration instead of a re-vote.
Honest framing
CALIPER is a working prototype and a blueprint, not a product. It runs in the browser on a synthetic demo tenant with deterministic demo data, reads service inventories shaped like ORBIT exports, and produces tolerance candidates shaped for the same workbench. Open it, walk the derivation, and challenge the curves. That is what it is for.