Protected Allocation
also called Ring-Fenced Capacity, Non-Negotiated Investment
A fixed share of capacity reserved for a category of work that loses every individual comparison against features - because the aggregate outcome would otherwise be nobody's decision.
Work that removes future cost — paying down a constraint, replacing a throughput-limiting system, automating a manual process, improving reliability — has real value that is diffuse, delayed and unattributed to a named customer.
It therefore loses every individual comparison against a feature with a sponsor, and it loses each one reasonably. The aggregate result is that none of it is done, and that aggregate was never decided by anyone.
Why it matters
The mechanism is structural rather than cultural. A team that genuinely values reliability and efficiency will still under-invest if every item is negotiated individually against work with clearer near-term value, because the comparison is always unfavourable at the item level.
A protected allocation removes the item-level comparison, which is the only intervention that changes the outcome.
Implementation patterns
- A fixed proportion of capacity, agreed in advance and not renegotiated per sprint. Commonly somewhere between 15% and 30% depending on the estate's maturity.
- Owned by the team, which decides what goes into it, since they hold the information about where the cost actually is.
- Reported like any other work, so it is visible and its results are attributable — an allocation with no reporting becomes slack and loses its legitimacy.
- Linked to an outcome measure where possible: deployment lead time, incident rate, unit cost, on-call load. That converts an act of faith into an investment with evidence.
- Distinct from the error budget mechanism, which is a reactive control triggered by reliability failure; the allocation is proactive and continuous.
- Not used for feature work in disguise, which is the failure mode that destroys the arrangement's credibility within two quarters.
Industry example
Fast-growing commerce platforms such as Myntra and Nykaa accumulate constraints at exactly the rate they accumulate customers, and the seasonal peak is where the accumulated constraint becomes visible. The organisations that manage it protect capacity year-round rather than attempting remediation in the weeks before a sale — which is both the most expensive time and the time when a change freeze applies.
Failure scenarios
- Negotiated per item, which loses every time.
- An allocation with no reporting, which becomes invisible and is then reclaimed.
- Used for features under another name, destroying trust in the arrangement.
- Set once and never reviewed, so it is either insufficient for a degraded estate or excessive for a healthy one.
- Owned centrally rather than by the team, which routes the decision away from the people with the information.
Trade-offs
A protected allocation is capacity not spent on customer-visible work, and in a genuinely existential period — a funding round, a competitive response, a compliance deadline — suspending it is the right call.
The discipline is that suspension is explicit, time-bounded and recorded, rather than an indefinite drift. An allocation suspended without a resumption date has been cancelled, and the estate's condition will make that visible within a year.
Interview question
"Your team has a 20% allocation for reliability and efficiency work. A major customer commitment means you need every engineer for a quarter. What do you do, and what do you insist on before agreeing?"