How to find out where your knowledge concentration risk sits
You find knowledge concentration risk by looking at traffic, not org charts: track for a month who gets interrupted with which questions, run the three-months-absent thought experiment per name, spot-check whether the written material could actually replace them, and score what remains by criticality times horizon. Most SMEs can run this diagnostic in four weeks with no outside help.
Before you start
No prerequisites beyond honesty. Useful framing for the team: this is an audit of the company's exposure, not of anyone's replaceability — the people who score highest are by definition the most valuable.
The steps
Step 1 — Run the interruption audit
For one month, have a handful of people log every 'let me ask X' moment: who was asked, what about, what would have happened without an answer. No tooling needed — a shared note suffices. The pattern is usually visible within two weeks and concentrated on fewer names than expected.
Pitfall: Asking people to self-report being the bottleneck. The askers see the pattern; the asked normalize it ('that's just my job').
Step 2 — Run the absence experiment per name
For each frequently-asked name: assume three months of unreachable absence, starting tomorrow. Walk through concretely: which decisions stall, which clients notice, which failures take days instead of hours. Write the answers down — vagueness here is the risk hiding.
Pitfall: Testing with two weeks instead of three months. Short absences are bridged by delay; the real exposure only shows when delay stops being an option.
Step 3 — Spot-check the paper trail
For the top domains from steps 1–2, test the documentation: could a competent newcomer act on what is written, without calling anyone? Pick three real recent cases and try to answer them from documents alone. The usual finding: procedures exist, judgment doesn't.
Pitfall: Auditing whether documentation exists rather than whether it suffices. Shelf-meters of ISO binders can coexist with total dependency — see SOPs vs a living knowledge base.
Step 4 — Score and rank the exposure
Per person-domain pair, score three factors 1–5: criticality (damage if unavailable), concentration (how exclusively it sits with this person), and horizon (how soon departure is plausible — age, tenure, market demand). Multiply. Everything above ~48 is a live risk; sort descending.
Pitfall: Leaving horizon out because 'nobody is leaving'. Departures announce themselves late; horizon is about plausibility, not announcements.
Step 5 — Decide per risk: spread, capture, or accept
For each top risk choose deliberately: spread it (duplicate the knowledge across people — slow but structural), capture it (build the knowledge base — fast and durable), or accept it (defensible for low-criticality items; indefensible for the top of the list). Put an owner and a date on each decision.
Pitfall: Producing the ranking and stopping. An unactioned risk register is a mood, not a mitigation.
How MentX compresses this
MentX is a personality-aware knowledge base: it captures the knowledge of a company's key person — from meetings and a guided intake track — into a living, temporal knowledge graph with full source attribution. MentX is the 'capture' branch of step 5, industrialized: the interruption audit's question list becomes the intake agenda, meeting ingest starts on the highest-scoring person, and the knowledge base — living, temporal, fully sourced — converts the top of your risk register into an asset. The diagnostic above is also, unchanged, the scoping conversation of the Founding Partner Program.
Checklist
- One month of interruption logging by the askers
- Three-months-absent experiment written out per top name
- Paper-trail spot-check on three real cases per domain
- Exposure scored: criticality × concentration × horizon
- Every top risk assigned: spread, capture, or accept — with owner and date