---
# === IDENTITY ===
id: consulting/recipes/oia-engagement-playbook/2026
canonical_question: "How do you run a full OIA engagement from scoping to monitoring retainer setup?"
aliases:
  - "OIA engagement lifecycle end to end"
  - "Organizational Immune System Audit project plan"
  - "How to scope and deliver an OIA consulting engagement"
entity_type: execution_recipe
domain: consulting > recipes > OIA Engagement Playbook
region: global
jurisdiction: global
temporal_scope: 2026-2027

# === VERIFICATION ===
last_verified: 2026-03-29
confidence: 0.85
version: 1.0
first_published: 2026-03-29

# === TEMPORAL VALIDITY ===
temporal_validity:
  status: evolving
  last_breaking_change: "Initial release — OIA methodology v1.0"
  next_review: 2026-09-25
  change_sensitivity: high

# === CONSTRAINTS ===
constraints:
  - "GDPR/privacy — anonymize personal data, use metadata only for network mapping"
  - "Data access requires legal sign-off before any system integration"
  - "Client must designate executive sponsor with authority over all departments in scope"
  - "Minimum engagement: 3 weeks — shorter timelines produce unreliable health scores"
  - "Monitoring retainer requires Slack or email integration — no monitoring without ambient data feed"

# === SKIP CONDITIONS ===
skip_this_unit_if:
  - condition: "User needs OIA theory, not execution"
    use_instead: "consulting/oia/organizational-immune-system-theory/2026"
  - condition: "User only needs network analysis, not full OIA"
    use_instead: "consulting/recipes/oia-network-analysis-execution/2026"
  - condition: "User needs pricing model, not delivery process"
    use_instead: "consulting/oia/metabolic-recovery-pricing/2026"

# === AGENT HINTS ===
inputs_needed:
  - key: engagement_scope
    question: "Which departments are in scope?"
    type: choice
    options: ["single department", "cross-functional (2-3 departments)", "organization-wide", "not yet defined"]
  - key: data_access
    question: "What communication platforms does the organization use?"
    type: choice
    options: ["Slack + Google Workspace", "Slack + Microsoft 365", "Microsoft Teams + Microsoft 365", "mixed/unknown"]
  - key: org_size
    question: "How many employees are in scope?"
    type: choice
    options: ["50-200", "200-1000", "1000-5000", "5000+"]
  - key: budget
    question: "What is the engagement budget?"
    type: choice
    options: ["$15K-$25K (focused)", "$25K-$50K (comprehensive)", "$50K+ (enterprise)", "not yet defined"]

# === EXECUTION METADATA ===
execution:
  required_inputs:
    - name: "Signed scope document"
      source: "client/engagement-lead"
      format: "document"
    - name: "IT system inventory"
      source: "client/IT-department"
      format: "spreadsheet"
    - name: "Org chart"
      source: "client/HR"
      format: "document"

  outputs:
    - name: "OIA Health Score Report"
      format: "PDF + structured JSON"
      description: "Composite organizational health score with network topology, autoimmune patterns, resilience gaps, and remediation roadmap"
    - name: "WBC Architecture Specification"
      format: "document"
      description: "Monitoring agent design: what to watch, alert thresholds, escalation paths"
    - name: "Monitoring Retainer Agreement"
      format: "document"
      description: "Ongoing monitoring scope, SLA, and pricing"

  tools_required:
    - name: "Microsoft Viva Insights"
      purpose: "Organizational network analysis from communication metadata"
      tier: "enterprise"
      cost: "$5K-$10K/engagement"
      alternatives: ["Custom Python NetworkX analysis", "Gephi"]
    - name: "Slack Admin Export"
      purpose: "Communication metadata extraction"
      tier: "paid"
      cost: "$0 (included in Slack Enterprise)"
      alternatives: ["Slack API (slack_sdk)", "Microsoft Graph API"]
    - name: "Survey Tool"
      purpose: "Shadow workaround interviews and security fatigue surveys"
      tier: "free"
      cost: "$0"
      alternatives: ["Typeform", "Google Forms", "SurveyMonkey"]

  credentials_needed:
    - service: "Slack"
      type: "Admin API token"
      where_to_get: "https://api.slack.com/apps"
      free_tier_limits: "N/A — requires Slack Business+ or Enterprise"
    - service: "Microsoft Graph"
      type: "OAuth token"
      where_to_get: "https://portal.azure.com"
      free_tier_limits: "N/A — requires Azure AD admin consent"

  estimated_duration: "3-6 weeks"
  estimated_cost: "$15K-$50K (consulting) + $2K-$5K/month (monitoring retainer)"

# === DISTRIBUTION ===
canonical_source: "https://knowledgelib.io/consulting/recipes/oia-engagement-playbook/2026"
suggested_citation: "Source: knowledgelib.io — AI Knowledge Library (verified 2026-03-29)"

# === RELATED UNITS ===
related_kos:
  depends_on:
    - id: "consulting/oia/organizational-immune-system-theory/2026"
      label: "OIA theoretical framework this engagement executes"
  feeds_into:
    - id: "consulting/oia/metabolic-recovery-pricing/2026"
      label: "Pricing model for OIA engagements"
  related_to:
    - id: "consulting/recipes/oia-data-collection/2026"
      label: "Data collection sub-recipe (Step 2-3)"
    - id: "consulting/recipes/oia-network-analysis-execution/2026"
      label: "Network analysis sub-recipe (Step 3)"
    - id: "consulting/recipes/oia-autoimmune-scan-execution/2026"
      label: "Autoimmune scan sub-recipe (Step 4)"
    - id: "consulting/recipes/oia-stress-test-execution/2026"
      label: "Stress test sub-recipe (Step 5)"

# === SOURCES ===
sources:
  - id: src1
    title: "The Knowing-Doing Gap"
    author: Pfeffer, J. & Sutton, R.I.
    url: https://www.hbs.edu/faculty/Pages/item.aspx?num=139
    type: academic_paper
    published: 2000-01-01
    reliability: authoritative
  - id: src2
    title: "Driving Results Through Social Networks"
    author: Cross, R. & Thomas, R.
    url: https://www.wiley.com/en-us/Driving+Results+Through+Social+Networks-p-9780470392492
    type: academic_paper
    published: 2009-01-01
    reliability: high
  - id: src3
    title: "Performance-based contracting"
    author: Hypko, P. et al.
    url: https://www.sciencedirect.com/science/article/pii/S0019850109001679
    type: academic_paper
    published: 2010-01-01
    reliability: high
  - id: src4
    title: "The New Science of Building Great Teams"
    author: Pentland, A.
    url: https://hbr.org/2012/04/the-new-science-of-building-great-teams
    type: primary_research
    published: 2012-04-01
    reliability: authoritative
---

# OIA Engagement Playbook

## Purpose

This recipe executes a full Organizational Immune System Audit engagement from initial scoping through monitoring retainer setup. It produces a composite health score report covering network topology, autoimmune patterns, and resilience gaps — plus a deployed monitoring architecture (WBC agents) that provides ongoing organizational health signals. [src1, src4]

## Prerequisites
<!-- Agents: verify ALL prerequisites before executing. Missing prerequisites = failed execution. -->

- [ ] **Executive sponsor** identified with authority across all in-scope departments
- [ ] **IT system inventory** available — list of communication platforms (Slack, email, Jira, Git, calendar, HRIS)
- [ ] **Org chart** available from HR with reporting lines and department boundaries
- [ ] **Legal/privacy sign-off** — data processing agreement drafted for metadata access
- [ ] **Slack Admin or Microsoft Graph credentials** — admin-level API access confirmed

## Constraints
<!-- Hard rules. Agents: enforce throughout execution. Violating these = broken output or legal risk. -->

- GDPR: use communication metadata only (timestamps, sender/receiver pairs, channel names) — never message content without explicit consent. [src4]
- Data access requires legal sign-off before any system integration begins.
- Client must designate a single executive sponsor with cross-departmental authority.
- Minimum engagement duration: 3 weeks. Shorter timelines produce unreliable health scores. [src1]
- Monitoring retainer requires ambient data feed (Slack or email integration) — no monitoring without it.

## Tool Selection Decision

```
Which path?
├── Client has Microsoft 365 enterprise
│   └── PATH A: Viva Insights — automated ONA, built-in dashboards
├── Client has Slack Enterprise + any email
│   └── PATH B: Slack Export + Custom Python — full control, lower cost
├── Client has mixed/smaller platforms
│   └── PATH C: API Integration + NetworkX — flexible, requires developer
└── Client has no API access (privacy-restricted)
    └── PATH D: Survey-Only — limited but compliant
```

| Path | Tools | Cost | Speed | Output Quality |
|------|-------|------|-------|---------------|
| A: Viva Insights | Microsoft Viva Insights | $5K-$10K | 3-4 weeks | Excellent — automated, validated |
| B: Slack + Python | Slack Admin Export, NetworkX, Gephi | $0-$500 | 4-5 weeks | Good — manual but thorough |
| C: API + NetworkX | Custom API scripts, NetworkX | $0-$1K | 4-6 weeks | Good — flexible but time-intensive |
| D: Survey-Only | Surveys, interviews, manual mapping | $0-$200 | 3-4 weeks | Adequate — limited network depth |

## Execution Flow

### Step 1: Scoping Call

**Duration**: 1 hour
**Tool**: Video call + structured intake form

Conduct initial scoping call with executive sponsor and key stakeholders. Define: engagement scope (which departments), specific concerns (turnover, communication silos, compliance fatigue), timeline, and success criteria.

Deliver structured intake form covering:
- Departments in scope (list all, mark priority)
- Communication platforms in use
- Known pain points
- Previous organizational assessments
- Budget and timeline constraints

**Verify**: Signed scope document with departments, timeline, and budget confirmed.
**If failed**: Reschedule within 3 business days. Do not proceed to data access without signed scope.

### Step 2: Data Access Negotiation

**Duration**: 2-5 days
**Tool**: Legal/IT coordination

Negotiate access to communication metadata across all platforms: Slack (channel activity, message timestamps), email (sender/receiver pairs, volume), Jira (ticket velocity, assignment patterns), calendar (meeting density, cross-team meetings), HRIS (org chart, tenure, role data).

Draft data processing agreement specifying:
- Metadata only — no message content
- Anonymization protocol for individual-level data
- Data retention period (engagement duration + 30 days)
- Access restricted to engagement team

**Verify**: All data feeds confirmed — admin credentials or export schedules in place for each system.
**If failed**: Identify blocking system, escalate to executive sponsor. If specific system is blocked, proceed with available data and document coverage gaps.

### Step 3: Network Mapping

**Duration**: 3-5 days
**Tool**: Microsoft Viva Insights or custom Python graph analysis (NetworkX)

Execute organizational network analysis from communication metadata. See [OIA Network Analysis Execution](/consulting/recipes/oia-network-analysis-execution/2026) for detailed sub-recipe.

Build directed weighted graph: nodes = people, edges = communication frequency. Calculate betweenness centrality (bottlenecks), degree centrality (hubs), eigenvector centrality (influence). Overlay formal org chart to identify formal-vs-informal gaps. [src2, src4]

**Verify**: Network topology validated with client — top 10 bottlenecks identified, formal-vs-informal gap report generated.
**If failed**: If data coverage is < 70% of in-scope employees, expand data sources or extend collection period.

### Step 4: Autoimmune Scan

**Duration**: 3-5 days
**Tool**: Log analysis + survey + structured interviews

Execute organizational autoimmune scan. See [OIA Autoimmune Scan Execution](/consulting/recipes/oia-autoimmune-scan-execution/2026) for detailed sub-recipe.

Detect compliance bypass patterns, shadow workarounds, and security fatigue indicators. Classify each friction point as protective (necessary) or paralyzing (serving hierarchy over function). [src1]

**Verify**: Pattern severity scored — each autoimmune pattern classified as low/medium/high/critical.
**If failed**: If survey response rate < 60%, extend survey window and add interview slots.

### Step 5: Resilience Assessment

**Duration**: 2-3 days
**Tool**: Network centrality analysis + stress test scenarios

Execute resilience assessment using stress test methodology. See [OIA Stress Test Execution](/consulting/recipes/oia-stress-test-execution/2026) for detailed sub-recipe.

Identify single points of failure (SPOFs), hero dependencies (individuals whose departure would halt operations), and recovery capacity gaps. Design and execute tabletop stress test scenarios. [src2]

**Verify**: Stress test scenarios completed, resilience score calculated per department.
**If failed**: If leadership team unavailable for tabletop exercise, run async scenario assessment via structured questionnaire.

### Step 6: WBC Architecture Design

**Duration**: 3-5 days
**Tool**: Architecture specification document

Design the White Blood Cell monitoring architecture based on findings from Steps 3-5:
- Define monitoring signals: communication pattern changes, bottleneck score drift, compliance bypass frequency
- Set alert thresholds: what level of change triggers notification
- Design escalation paths: who gets notified, in what order
- Specify integration points: Slack bot, email digest, dashboard

**Verify**: Client reviews and approves monitoring scope and alert thresholds.
**If failed**: Iterate on scope — common issue is client wanting too broad monitoring. Narrow to top 5 signals initially.

### Step 7: Report Delivery

**Duration**: 1-2 days
**Tool**: Presentation + structured report (PDF + JSON)

Produce and present the OIA Health Score Report:
- Composite health score (0-100) with breakdown by dimension
- Network topology visualization with annotated bottlenecks
- Autoimmune pattern inventory with severity scoring
- Resilience gap analysis with stress test results
- Prioritized remediation roadmap (quick wins + structural changes)
- WBC architecture specification

**Verify**: Client acceptance of findings. Schedule follow-up Q&A if needed.
**If failed**: If client disputes findings, offer to re-run specific analyses with additional data or different department scope.

### Step 8: Monitoring Retainer Setup

**Duration**: 2-3 days
**Tool**: Slack/email integration + monitoring dashboard

Deploy initial WBC monitoring agents:
- Install Slack bot or email integration
- Configure baseline metrics from engagement data
- Set initial alert thresholds (calibrate during first 30 days)
- Establish monthly reporting cadence
- Define retainer scope and SLA [src3]

**Verify**: Agents operational — first test alerts triggered and verified by client team.
**If failed**: If integration blocked by IT security, fall back to manual monthly check-in with data export.

## Output Schema

```json
{
  "output_type": "oia_health_report",
  "format": "PDF + JSON",
  "sections": [
    {"name": "health_score", "type": "number", "description": "Composite 0-100 organizational health score", "required": true},
    {"name": "network_topology", "type": "object", "description": "Graph data with centrality scores per node", "required": true},
    {"name": "autoimmune_patterns", "type": "array", "description": "Identified bypass/workaround patterns with severity", "required": true},
    {"name": "resilience_gaps", "type": "array", "description": "SPOFs, hero dependencies, recovery capacity gaps", "required": true},
    {"name": "remediation_roadmap", "type": "array", "description": "Prioritized actions: quick wins + structural changes", "required": true},
    {"name": "wbc_architecture", "type": "object", "description": "Monitoring agent specification", "required": true}
  ],
  "expected_sections": "6",
  "sort_order": "severity descending within each section"
}
```

## Quality Benchmarks

| Quality Metric | Minimum Acceptable | Good | Excellent |
|---------------|-------------------|------|-----------|
| Data coverage (% of in-scope employees) | > 70% | > 85% | > 95% |
| Network analysis accuracy (validated by client) | > 60% of key findings confirmed | > 80% confirmed | > 90% confirmed |
| Autoimmune pattern detection rate | > 5 patterns identified | > 10 patterns | > 15 patterns |
| Stress test scenario coverage | 3 scenarios | 4 scenarios | 5+ scenarios |
| Client satisfaction (post-engagement survey) | > 3.5/5 | > 4.0/5 | > 4.5/5 |

**If below minimum**: Extend engagement by 1 week, add additional data sources, or narrow scope to achieve depth over breadth.

## Error Handling

| Error | Likely Cause | Recovery Action |
|-------|-------------|----------------|
| Data access blocked by IT | Security policy or legal review pending | Escalate to executive sponsor, offer to proceed with available data and document gaps |
| Low survey response rate (< 60%) | Survey fatigue or lack of executive communication | Have sponsor send personal message, extend deadline, add interview option |
| Network analysis shows disconnected graph | Incomplete data or departmental silos | Verify data completeness, add missing communication channels, or document silos as finding |
| Client disputes findings | Findings challenge leadership assumptions | Present raw data supporting conclusions, offer to re-run with different parameters |
| Monitoring agent integration fails | IT security blocking bot installation | Fall back to manual monthly data export and analysis |

## Cost Breakdown

| Component | Focused ($15K-$25K) | Comprehensive ($25K-$50K) | Enterprise ($50K+) |
|-----------|---------------------|---------------------------|-------------------|
| Scoping + data access | $2K-$3K | $3K-$5K | $5K-$8K |
| Network analysis | $3K-$5K | $5K-$10K | $10K-$15K |
| Autoimmune scan | $2K-$4K | $4K-$8K | $8K-$12K |
| Resilience assessment | $2K-$3K | $3K-$6K | $6K-$10K |
| Report + WBC design | $3K-$5K | $5K-$10K | $10K-$15K |
| Monitoring setup | $2K-$3K | $3K-$5K | $5K-$8K |
| **Total engagement** | **$15K-$25K** | **$25K-$50K** | **$50K-$70K** |
| **Monthly retainer** | **$2K/month** | **$3K-$4K/month** | **$5K+/month** |

## Anti-Patterns

### Wrong: Skipping data access negotiation
Jumping straight into network mapping without proper legal sign-off and data processing agreements. Result: engagement halted mid-execution when legal or IT discovers unauthorized data access, damaging client trust permanently. [src1]

### Correct: Front-load legal and data access
Spend 2-5 days upfront negotiating data access with legal and IT. Document everything. This prevents mid-engagement stalls and establishes professional credibility.

### Wrong: Presenting findings without validation
Delivering the OIA report without first validating key findings with the client team. Result: report contains false positives (misidentified bottlenecks due to data gaps), client loses confidence in methodology. [src2]

### Correct: Validate findings before formal delivery
Share preliminary findings with 2-3 client stakeholders before formal report delivery. Use their feedback to calibrate accuracy and add context the data cannot capture.

### Wrong: Over-scoping the monitoring retainer
Setting up WBC monitoring for every possible signal across the entire organization. Result: alert fatigue within 30 days, client ignores all monitoring alerts. [src3]

### Correct: Start narrow, expand based on value
Begin monitoring with top 5 signals only. Calibrate thresholds during first 30 days. Expand scope only after demonstrating value from initial signals.

## When This Matters

Use when an agent needs to plan or execute a full OIA consulting engagement. This is the master recipe — it orchestrates the sub-recipes for data collection, network analysis, autoimmune scanning, and stress testing into a cohesive engagement lifecycle. Requires executive sponsor access and communication platform admin credentials as prerequisites.

## Related Units

- [OIA Theory — Organizational Immune System](/consulting/oia/organizational-immune-system-theory/2026)
- [OIA Data Collection](/consulting/recipes/oia-data-collection/2026)
- [OIA Network Analysis Execution](/consulting/recipes/oia-network-analysis-execution/2026)
- [OIA Autoimmune Scan Execution](/consulting/recipes/oia-autoimmune-scan-execution/2026)
- [OIA Stress Test Execution](/consulting/recipes/oia-stress-test-execution/2026)
- [Metabolic Recovery Pricing](/consulting/oia/metabolic-recovery-pricing/2026)
