name: tech-leadership
description: Use when advising, planning, reviewing, reporting, operating, or improving CTO and technology leadership work across strategy, cybersecurity management, SME/COE, functional and technical requirements, framework selection, people, organization, delivery, risk, KPI, roadmap, budgeting, governance, audit, R&D, stakeholder communication, culture, politics, and sector-specific leadership.
Tech Leadership
Core Rule
Treat technology leadership as an operating system, not a motivational role. Convert business context into explicit priorities, decision rights, capacity, risk appetite, financial trade-offs, technical strategy, cybersecurity posture, people systems, execution rhythm, and measurable outcomes.
First Pass
- Classify the request: daily operating review, strategy, roadmap, portfolio, cybersecurity strategy, SME/COE, functional/technical requirements, framework selection, audit/compliance, board/shareholder report, delivery recovery, incident management, organization design, hiring/retention, appraisal, budget, vendor/partner strategy, R&D, AI/data transformation, culture, political risk, or cross-functional advisory.
- Identify role level: CTO, VP Engineering, Head of Engineering, tech lead, engineering manager, platform leader, product/data/AI leader, non-executive tech leader, acting CTO, advisor, or founder-CTO.
- Capture context: sector, geography, company stage, regulation, risk appetite, operating model, budget authority, reporting line, decision rights, team size, vendor dependence, technology estate, and current constraints.
- Separate
Fact, Inference, Assumption, and Question. Do not invent headcount, budget, maturity, compliance obligations, breach history, board priorities, or culture dynamics. - Choose the smallest useful output: decision memo, roadmap, dashboard, board report, audit pack, risk register, org map, meeting brief, policy, operating cadence, performance calibration, incident review, or change plan.
- Define validation: stakeholder review, metric baseline, risk acceptance, financial model, delivery evidence, audit evidence, tabletop exercise, incident drill, pulse survey, architecture review, or post-implementation review.
Required Reads By Task
- Operating cadence, daily/weekly/monthly leadership work, decision rights, or CTO operating model:
references/leadership-operating-system.md. - Strategy, short/mid/long-term planning, roadmap, portfolio trade-offs, technology bets, technical debt, scalability, resilience, sustaining engineering, roadmap uncertainty, or over-engineering:
references/strategy-roadmap-portfolio.md. - Senior technology leadership role design, CTO vs VP Engineering, executive peer trust, senior leadership tasks, technical True North, role modeling, or business/technology executive alignment:
references/senior-technology-leadership.md. - KPI, KRA, OKR, CSF, scorecard, dashboard, performance reporting, root cause analysis, balanced scorecard, benchmarking, performance management system, or metric design:
references/metrics-kpi-dashboard.md. - Executive and managerial quantification, CTO metrics, technology value metrics, manager-system metrics, board metric synthesis, team diagnostic metrics, metric harm, or modern technology leadership blind spots:
references/executive-managerial-quantification.md. - Hiring, developing, retaining, mentoring, delegation, 1:1s, skip-level meetings, managing managers, manager accountability, calibration, appraisal, 360 feedback, incentives, team allocation, or succession:
references/people-org-talent-appraisal.md. - Enterprise risk, audit readiness, compliance, policy, controls, regulatory exposure, or governance:
references/governance-risk-compliance-audit.md. - SME, Subject Matter Expert, Center of Excellence, COE, community of practice, expert review, capability enablement, platform/service COE, governance COE, or reusable expert capability:
references/sme-coe-operating-model.md. - Functional requirements, technical requirements, product/engineering specs, non-functional requirements, acceptance criteria, traceability, launch readiness, migration requirements, or requirement review:
references/requirements-engineering-for-tech-leads.md. - Selecting or critiquing ITSM, ITIL, COBIT, TOGAF, ISO/IEC/IEEE, PCI DSS, PMBOK, CMMI, AICPA/SOC 2, CNCF, Gartner Magic Quadrant, HIPAA, GDPR, PDP, SAFe, Lean Six Sigma, DORA, MTTR, or deciding no framework:
references/framework-selection-and-critical-prompts.md. - Socio-technical risk, reliability management, hidden risk, near misses, barriers, redundancies, recoveries, just culture, burnout risk, human reliability, system reliability, organizational reliability, or predictive reliability:
references/risk-reliability-leadership.md. - Cybersecurity leadership, CISO/CTO boundary, cyber risk appetite, security roadmap, IAM, SOC, AppSec, cloud security, data security, third-party risk, incident/crisis leadership, or board cyber reporting:
references/cybersecurity-strategy-management.md. - Delivery predictability, unblocking, agile, incident/on-call, reliability, SLO, operational resilience, platform operations, or postmortem:
references/delivery-incident-reliability.md. - Budget, costing, ROI, value realization, business case, unit economics, vendor spend, cloud cost, or investment governance:
references/finance-roi-costing.md. - AI leadership, AI agents, agent autonomy, AI observability, AI security, AI ROI, data/product leadership, data value, R&D, technology research, innovation, experiments, hypotheses, evaluation, and adoption governance:
references/ai-data-rd-innovation.md. - Board, shareholder, executive, cross-functional, customer, vendor, and team communication; presentation, narrative, advisory, negotiation, and pushback:
references/stakeholder-board-communication.md. - Engineering culture, structure, career ladders, cross-functional pods, process-as-risk-management, code review, architecture review, learning reviews, Conway's Law, psychological safety, and scale-stage structure:
references/engineering-culture-structure-process.md. - Culture, incentives, organizational politics, power mapping, psychological safety, cross-cultural leadership, and office politics defense:
references/culture-politics-cross-cultural.md. - Sector-specific leadership forces across banking, energy, government, insurance, consulting, FMCG, healthcare, manufacturing, logistics, agriculture, defense, real estate, media, education, non-profit, vendor, and multinational contexts:
references/sector-contexts-and-operating-models.md. - Red flags, anti-patterns, failure modes, weak assumptions, and leadership smell checks:
references/leadership-antipatterns-red-flags.md.
Task Playbooks
- 30/60/90-day CTO or tech leadership diagnostic:
tasks/cto-90-day-diagnostic.md. - Build a technology strategy and roadmap:
tasks/build-technology-roadmap.md. - Build a cybersecurity strategy and management plan:
tasks/build-cybersecurity-strategy.md. - Build a performance management system, KPI cascade, dashboard, or scorecard:
tasks/build-performance-management-system.md. - Quantify executive and managerial technology leadership system:
tasks/quantify-technology-leadership-system.md. - Prepare board, shareholder, or executive report:
tasks/prepare-board-shareholder-report.md. - Run engineering organization review:
tasks/run-engineering-org-review.md. - Run skip-level and manager system review:
tasks/run-skip-level-manager-system-review.md. - Define senior technology leadership role boundaries and True North:
tasks/define-senior-tech-leadership-role.md. - Design engineering culture, structure, and process:
tasks/design-engineering-culture-structure.md. - Run risk and reliability review:
tasks/run-risk-reliability-review.md. - Handle audit, risk, and compliance readiness:
tasks/handle-audit-risk-compliance.md. - Design SME or COE operating model:
tasks/design-sme-coe-operating-model.md. - Write or review functional and technical requirements:
tasks/write-functional-technical-requirements.md. - Select governance, compliance, service-management, architecture, delivery, market, or metrics framework:
tasks/select-governance-compliance-delivery-framework.md. - Conduct performance appraisal and 360 calibration:
tasks/conduct-performance-calibration.md. - Recover delivery predictability and unblock execution:
tasks/recover-delivery-predictability.md. - Evaluate AI, data, R&D, or innovation initiative:
tasks/evaluate-ai-rd-initiative.md. - Navigate office politics and stakeholder conflict ethically:
tasks/navigate-office-politics.md.
Templates
- Board or shareholder report:
templates/board-report.md. - Technology roadmap:
templates/technology-roadmap.md. - Cybersecurity strategy brief:
templates/cybersecurity-strategy-brief.md. - KPI dashboard:
templates/kpi-dashboard.md. - Performance management system:
templates/performance-management-system.md. - Executive and managerial quantification map:
templates/executive-managerial-quantification-map.md. - AI/data/R&D evaluation:
templates/ai-data-rd-evaluation.md. - Organization and capacity map:
templates/org-capacity-map.md. - Skip-level signal map:
templates/skip-level-signal-map.md. - Senior technology leadership role map:
templates/senior-tech-leadership-role-map.md. - Technical True North:
templates/technical-true-north.md. - Engineering culture and structure map:
templates/engineering-culture-structure-map.md. - Risk register:
templates/risk-register.md. - Risk and reliability review:
templates/reliability-review.md. - SME / COE operating model:
templates/sme-coe-operating-model.md. - Functional and technical requirements:
templates/functional-technical-requirements.md. - Framework selection decision record:
templates/framework-selection-decision-record.md. - Cyber risk register:
templates/cyber-risk-register.md. - Technical debt register:
templates/technical-debt-register.md. - Decision memo:
templates/decision-memo.md. - Meeting brief:
templates/meeting-brief.md. - Appraisal and 360 calibration:
templates/appraisal-360.md. - Change or policy template:
templates/change-policy.md. - Leadership operating system diagram:
templates/mermaid-leadership-operating-system.mmd. - Performance management system diagram:
templates/mermaid-performance-management-system.mmd. - AI agent governance diagram:
templates/mermaid-ai-agent-governance.mmd. - Risk and reliability diagram:
templates/mermaid-risk-reliability-view.mmd. - Cyber governance diagram:
templates/mermaid-cyber-governance-view.mmd. - SME / COE operating model diagram:
templates/mermaid-sme-coe-operating-model.mmd. - Requirements engineering flow diagram:
templates/mermaid-requirements-flow.mmd. - Framework selection diagram:
templates/mermaid-framework-selection.mmd.
Decision Discipline
- If current laws, sector regulations, cybersecurity frameworks, privacy rules, audit standards, vendor claims, pricing, market data, or product capabilities matter, say exactly:
This needs verification. - Do not use ITIL, COBIT, TOGAF, ISO/IEC/IEEE, PCI DSS, PMBOK, CMMI, SOC 2, CNCF, Gartner Magic Quadrant, HIPAA, GDPR, PDP, SAFe, Lean Six Sigma, DORA, or MTTR as a brand list. State the problem driver, applicability, owner, evidence, minimum viable adoption, and misuse risk.
- Do not create SME or COE structures without decision rights, service catalog, adoption metrics, exception path, and a plan to avoid bottlenecks.
- Do not accept functional or technical requirements that lack actor, business objective, measurable NFRs, acceptance criteria, data lifecycle, IAM/security/privacy implications, rollout/rollback, and validation evidence.
- Keep skill guidance self-contained for production use. Do not require local reference PDFs, private folders, or book/page citations at runtime.
- Lead with the strongest concern when a proposed strategy is under-evidenced, politically naive, unaffordable, un-auditable, or operationally fragile.
- Do not turn every leadership problem into process. Check incentives, decision rights, capacity, trust, technical constraints, and business trade-offs first.
- Do not assume CTO, VP Engineering, Head of Engineering, CIO, CISO, Chief Architect, and technical founder mean the same thing. Map business strategy, technology strategy, organization, execution, external face, infrastructure, R&D, and management authority explicitly.
- Do not treat cybersecurity as a tool purchase or compliance checklist. Tie it to business risk, asset criticality, threat exposure, control ownership, incident readiness, evidence, and funding.
- Do not hide trade-offs: speed vs control, autonomy vs standardization, innovation vs operational resilience, centralization vs local ownership, cost reduction vs future optionality.
- Do not use generic cultural stereotypes. For Indonesia, Asia, Middle East, Western, Eurasian, or multinational settings, map decision norms, regulatory pressure, power distance, labor expectations, procurement, language, stakeholder hierarchy, and escalation paths from evidence.
Output Standard
Lead with the leadership judgment and the recommended path. State business objective, role accountability, constraints, stakeholders, current evidence, risks, trade-offs, operating model, roadmap, metrics, cybersecurity implications, financial impact, people impact, communication plan, validation, and next decision needed.
Script Helpers
- Run
scripts/generate_leadership_artifact.py --type <artifact> --output <file> to create a starter report, roadmap, risk register, cyber strategy, SME/COE model, requirements spec, framework decision, appraisal, or meeting brief. - Run
scripts/tech_leadership_static_audit.py <file-or-dir> to scan leadership docs for missing strategy, metrics, risk, cybersecurity, SME/COE, requirements, framework selection, people, finance, delivery, governance, stakeholder, and validation coverage.