Thesis

Specialize the capability, not the application.

Enterprise software specialized the application. Every capability a complex-product organisation needs — requirements, risk, verification, change, quality, compliance — arrived as its own product, with its own object model, its own permissions and its own idea of the truth. The result is not a toolchain. It is a set of partial representations of the same programme that no one can reconcile without human effort.

M Theory inverts that. The environment is general purpose — Sheet, Doc, Canvas, Deck, Plan — and the specialization lives underneath, in the objects, relationships, governance and evidence that every surface shares. One requirement is one object; the spreadsheet, the document and the diagram are views of it.

This page sets out the argument: what the systems-engineering literature reports about document-centric work, what practitioners describe, what the accident and assurance record shows about evidence going stale, how much is already spent holding the fragments together, and what changes if the capability rather than the application is the unit of specialization.

01

What the literature actually says.

Fragmentation is not a tooling preference; it is a documented condition of complex-product development. The findings below are the ones we build against.

Finding 1

Document-centric practice is the acknowledged baseline that systems engineering is trying to leave.

INCOSE's Systems Engineering Vision 2035 describes the discipline as still largely document-based and sets model-based practice, digital engineering environments and continuous, evidence-linked assurance as the target state rather than the current one.

INCOSESystems Engineering Vision 2035· 2021
Finding 2

The digital thread problem is an integration problem, not a modelling problem.

US Department of Defense digital-engineering strategy frames the objective as an authoritative source of truth connecting models and data across the lifecycle — an explicit acknowledgement that the data exists but is not connected across the tools that produce it.

U.S. Department of DefenseDigital Engineering Strategy· 2018
Finding 3

MBSE has been promoted for two decades and most organisations are still nearer document-based than model-based.

The SERC benchmarking study run with INCOSE and the NDIA Systems Engineering Division assessed organisations against the INCOSE Model-Based Enterprise Capability Matrix and found most sitting at low-to-moderate maturity, with document artifacts and manual traceability still dominant even where modelling tools are in place.

SERC / INCOSE / NDIABenchmarking the Benefits and Current Maturity of MBSE across the Enterprise· 2020
Finding 4

Defects introduced in requirements and design are cheapest to remove where they are created.

A NASA Johnson Space Center study measured relative error-correction cost across life-cycle phases using three independent costing methods and found errors found late cost many times more than the same error caught at requirements or design. The NIST-commissioned RTI study reaches the same conclusion economy-wide and put the annual cost of inadequate software testing infrastructure at $59.5 billion.

The popular 1:10:100 multiplier is disputed: investigative and peer-reviewed re-examinations have found the relationship far weaker and more project-dependent than the heuristic implies. We cite the direction of the effect, which is well evidenced, not a fixed ratio.

NASA Johnson Space CenterError Cost Escalation Through the Project Life Cycle (NTRS 20100036670)· 2010
Finding 7

Assurance evidence is required to stay connected to the design it describes.

NASA's software assurance and safety standard requires assurance activities, records and safety evidence to be maintained across the lifecycle as the software and its requirements change — a continuity obligation, not a one-time deliverable.

NASANASA-STD-8739.8, Software Assurance and Software Safety Standard· 2022
02

Signals from practice.

What the condition looks like from inside a programme, in the words teams use when they describe their week.

  • The spreadsheet is the integration layer

    The system of record for cross-tool truth is an export: a requirements dump joined by hand to a test log, reconciled in a review, and stale the moment it is circulated.

  • Traceability is produced, not observed

    Trace matrices are assembled for an audit rather than read off the work. The effort scales with the audit calendar, not with the engineering.

  • Change is announced, not propagated

    A severity changes in one tool; whether the verification that depended on it is still valid is a question answered by whoever remembers.

  • Compliance is a parallel project

    ASPICE, ISO 26262 or DO-178C work runs alongside development as its own effort, staffed separately, delivering documents that mirror engineering that has already moved on.

  • Tool sprawl outlives the programme

    Licences, schemas and permission models accumulate faster than they are retired, and each new one adds another partial view of the same object.

  • AI inherits the fragmentation

    An assistant is bounded by the context it can reach. Twenty disconnected systems means twenty schemas and no single grounded representation to reason over.

03

NASA's finding.

The most rigorous assurance organisation on the planet has repeatedly documented the same failure mode: the evidence and the engineering drift apart, and the drift is invisible until something breaks.

organizational barriers that prevented effective communication of critical safety information and stifled professional differences of opinion
Columbia Accident Investigation Board, on the organisational causes of the loss of STS-107
CAIBColumbia Accident Investigation Board Report, Volume I· 2003
The Board strongly believes that if these persistent, systemic flaws are not resolved, the scene is set for another accident.
Columbia Accident Investigation Board, Volume I
CAIBColumbia Accident Investigation Board Report, Volume I· 2003

Read as an information-architecture finding rather than a cultural one, the pattern is consistent: safety-critical knowledge existed inside the organisation, in analyses and in individual judgement, but it was not connected to the decisions that depended on it, and nothing in the system made the disconnection visible. Every assurance regime since — NASA's own software assurance standard, ISO 26262, DO-178C, ASPICE — encodes the same requirement, that evidence must remain demonstrably attached to the thing it certifies. What none of them supply is a substrate where that attachment is maintained automatically instead of reconstructed by people.

04

The market.

Organisations already spend heavily to hold this together. The spend buys more specialized applications, which is what produced the fragmentation in the first place.

$59.5BEstimated annual cost to the US economy of inadequate software testing infrastructure, of which roughly $22.2B was judged recoverable through better testing infrastructure and earlier defect detection.NIST / RTIThe Economic Impacts of Inadequate Infrastructure for Software Testing (NIST Planning Report 02-3)· 2002
$4.5BApplication lifecycle management software, 2024, projected to reach $11.7B by 2034 at 9.8% CAGR. Analyst estimates for this segment range from roughly $4.5B to $6.6B depending on scope.Research and MarketsApplication Lifecycle Management Software Market Outlook· 2024
$2.1BRequirements management software, 2024, projected to reach $4.1B at 11.8% CAGR. A second analyst puts the 2024 base at $1.24B — the spread is a fair indication of how loosely this category is bounded.Strategic Market ResearchRequirements Management Software Market Report· 2024
$9.8BQuality management software, 2024. Adjacent estimates for enterprise QMS sit nearer $7B; the categories overlap and are counted differently by each firm.Market Research FutureQuality Management Software Market· 2024
PLMProduct lifecycle management is the largest adjacent category. CIMdata is the recognised authority on its sizing; we do not quote a headline figure we cannot verify from a public source.CIMdataPLM Market Analysis Report Series· 2025
MandatedDefense and aerospace digital-engineering policy now requires an authoritative source of truth across the lifecycle, pulling spend toward connected environments rather than additional point tools.U.S. Department of DefenseDigital Engineering Strategy· 2018

We deliberately do not sum these into a single headline TAM. The categories overlap, each analyst bounds them differently, and adding them would imply a precision the underlying data does not support. The honest framing is that the addressable spend is the tooling an organisation buys to compensate for the absence of a shared substrate, plus the engineering time spent reconciling those tools — and the second number is usually larger than the first, and never appears on a licence invoice. We have also left out the widely repeated claim that engineers spend a fixed percentage of their week searching for information: it is quoted everywhere and traceable to nowhere.

05

A new level of work.

The answer to document-centric work is not eliminating documents. It is separating the document interface from the underlying work model, so structure, traceability and approval are properties of the work rather than deliverables produced after it.

Do the work

People work in the surfaces they already know: a sheet, a document, a diagram, a deck, a plan.

Objects, not files

What they create are addressable objects — a requirement, a hazard, a test, a decision — referenced with # from anywhere.

The graph records

Relationships, revisions, approvals and impact are captured as the work happens, not assembled afterwards.

Evidence follows

Compliance becomes a view over the graph. When something upstream changes, everything downstream of it knows.

Complexity does not disappear; it moves. The irreducible complexity of requirements, safety, compliance and configuration belongs in the platform rather than being imposed on every user through a different specialized application. The system carries more. The person carries less.

06

If this holds, what changes.

For engineersTraceability stops being an extra deliverable. The reference you make while writing is the trace link, so the matrix is a read, not a task.
For quality and safetyStaleness becomes observable. A change to a requirement or severity marks every dependent verification and approval, so audit readiness is a state rather than a project.
For programme leadershipStatus is derived from the work itself rather than reported on top of it, which removes the lag between what is true and what is known.
For platform and ITOne object model, one permission model, one audit trail. Domain specialization arrives as Packs on the same substrate instead of another application to integrate.
For AIA grounded, governed graph is the context an assistant needs to be useful in a regulated environment — and the same graph is what makes its output auditable.

The future of enterprise software may be fewer applications, not more — one connected environment with thousands of specialized capabilities.