# Certify Before You Rationalize

> Rationalization is only as good as the records under it. Have owners certify the fields a disposition depends on before anyone decides keep or kill.

Canonical: https://mikereams.com/writing/certify-before-you-rationalize

Published: August 21, 2026  
Author: Mike Reams (https://mikereams.com/about)  
Topics: [Application Portfolio Management](https://mikereams.com/writing/topics/apm), [Architecture](https://mikereams.com/writing/topics/architecture)  
Tags: APM, Governance, Data Quality  
Project: [Application Portfolio Rationalization](https://mikereams.com/work/application-portfolio-rationalization)

![Diagram: five record fields — owners, lifecycle, capabilities, criticality and deployments — pass through an owner attestation gate; certified applications proceed to a TIME disposition, uncertified ones go to a needs-data lane.](https://mikereams.com/writing/certify-before-you-rationalize.png)

Rationalization workshops tend to start the same way. Someone shares the application list, the room starts sorting it into keep, fix, move and retire, and within twenty minutes someone says, "That one isn't ours," or "We turned that off last year," or, my favorite, "What is that?"

The decisions are only as good as the records under them. If the owner is wrong, the lifecycle is stale and the capability mapping is a guess, then a [disposition](https://mikereams.com/writing/a-disposition-is-a-decision-not-a-field) is a confident opinion about a rumor. So certify first, then rationalize.

## What certification means

Certification is an owner attesting, by name and date, that a defined set of facts about their application is true. Not "the record looks fine." Specific fields, specific answers, an expiry date. It turns a database row into a statement somebody stands behind.

## The fields that carry a disposition

- **Owners.** Business owner and IT owner, as named people or roles that still exist. Ownership is the keystone: a missing owner predicts a missing everything else.
- **Lifecycle.** Operational, being retired, retired. A disposition on something already retired is just paperwork with ambition.
- **Capabilities.** At least one business and [one technical capability](https://mikereams.com/writing/every-app-needs-two-capabilities). Without them you cannot find overlap, and overlap is what consolidation is made of.
- **Criticality.** The recovery tier or business impact. Retiring a critical system and a convenience tool are not the same conversation.
- **Deployments.** The [application services](https://mikereams.com/writing/the-missing-middle-why-business-apps-shouldnt-point-at-servers) that run it. They carry the blast radius, and the cost.

> Uncertified data isn't wrong, exactly. It just hasn't been asked to testify.

## Run it as a campaign, not a cleanup

1. **Scope.** Certify the applications in this rationalization wave, not the whole portfolio. A finite list gets finished.
2. **Pre-fill.** Send owners the current values and ask them to confirm or correct. Editing is faster than authoring, and people are far more motivated to fix something wrong with their name on it.
3. **Time-box.** Two weeks, one reminder, then escalate through the owner's leader. Silence is an answer: uncertified means not ready for a decision.
4. **Expire.** Certification lasts until the next review cycle, typically a year, or until a material change — new owner, new platform, new contract.
5. **Gate.** No disposition is recorded on an uncertified application. It goes to a "needs data" lane instead, which is itself a useful finding.

## What you get back

A rationalization built on certified records survives the meeting where someone challenges it, because the evidence has a name and a date on it. And the gaps the campaign surfaces — no owner, no capability, [no traceable cost](https://mikereams.com/writing/why-you-cant-answer-what-does-this-app-cost) — are often the most valuable output. They tell you where the portfolio is flying blind.

## Copy this: the certification record

```
CERTIFICATION - <application> | wave <n> | due <date>
Attested by: <owner name/role>   Date: <date>   Expires: <date +12 months>
[ ] Business owner:   <value>   confirm / correct: <...>
[ ] IT owner:         <value>   confirm / correct: <...>
[ ] Lifecycle:        <operational / retiring / retired>
[ ] Business capability:  <lowest level>
[ ] Technical capability: <one primary class>
[ ] Criticality:      <recovery tier / business impact>
[ ] Deployments:      <application services: prod / test / region>
Status: certified | corrected | not certified (-> "needs data" lane)
Rule: no disposition on an uncertified application.
Re-certify on: owner change, platform change, contract change, or expiry.
```
