The Workshop

The Workshop: Walking the Wall

August 08, 2026 · 33 min read

Event storming builds the model; this session is how the model survives contact with the people who know the domain. The wall on the screen is generated from a discovery ledger, every open question is a red card sitting beside its impact, and the session’s score is the red count going down.

Walking the Wall

Walking the Wall is a facilitated review of an existing event-storm model, run against a wall that is projected rather than papered: a portrait canvas generated from the model’s source table, scrolled top to bottom so the room reads the domain in timeline order. It sits after the storming sessions (Big Picture, then Process Level per flow) and between them, whenever enough has been folded into the model that the room should check it. You may hear the same idea called a wall walk, a model walkthrough, or a review storm; the distinguishing feature here is that the wall is generated and the session is driven by audits, mechanical checks that turn defects in the model into questions for the room.

It gets confused with two things it isn’t. It is not another storming session: the room isn’t discovering a flow from scratch, it’s attacking a model that already exists. And it is not a readout: the facilitator is not presenting findings for approval, they’re hunting for the places the model is wrong, and the session has failed if nothing changes.

What’s It For

Between storms, a discovery model accumulates edits nobody has walked: transcribed sessions, folded satellite documents, proposed cards inserted to satisfy the storm grammar, strawman sections sketched to cover flows no workshop has reached. Walking the Wall is how those edits get checked by the people who know, before anything gets built on them.

Use it when a model has grown beyond what any one session’s attendees have seen; when grammar enforcement has inserted (proposed) cards that need confirming, renaming, or striking; when a flow was strawmanned deliberately and needs the room to attack it; or when the open-question count has stopped falling and the questions need to be put in front of the right faces. It also works as the standing cadence of a discovery engagement: storm, fold, walk, repeat.

The deeper purpose is honesty. A model that has only ever been added to looks better than it is. A model that gets audited in front of domain experts, with every defect converted into a red card that someone must answer, stays honest, and the red count gives the whole engagement a progress number that can’t be gamed by writing more documentation.

What It’s Not For

Don’t use it to storm a flow nobody has mapped: there’s nothing on the wall to walk. Run a Process Level session first, even a rough one, and walk the result.

Don’t use it to make decisions. The session names problems and assigns owners; the moment the room starts designing the fix for a hotspot, the walk has stalled. Rules that need pinning down get an Example Mapping or a Decision Tables session of their own.

Don’t use it as a status meeting for stakeholders who can’t answer domain questions. The red count makes a fine one-line status report on its own; the session is for people who can take reds off the wall.

Definitions & Background

The wall being walked is a generated view of a single source table, the pattern described in The Discovery Ledger: one row per card, timeline top to bottom, every card carrying a global ID (🟧 E021, 🟪 P011). The projected canvas is portrait, one card per row, so scrolling down is reading the domain in time order. Nobody edits the canvas; a scribe edits the table and the wall regenerates.

Cards follow the storm grammar from the event storming playbooks: 🟨 actors issue 🟦 commands, commands cause 🟧 events (past tense, one per card), events trigger 🟪 policies, policies decide commands and consult 🟩 data. Unknowns are never blank: a bare 🟨 is an unknown actor, a bare 🟩 unknown data, a (proposed) 🟪 an inferred rule, and each carries a 🟥 row directly beneath the card it questions. The reds are the open-question register, held in place.

An audit is a mechanical pass over the model looking for one class of defect. The defect is never the finding; the question it implies is. An event with no cause isn’t an error to fix quietly, it’s the question “who or what makes this happen?”, and the room is where that question gets answered.

Inputs

  • The source table, current: all recent sessions transcribed and folded, IDs renumbered, references verified.
  • The generated wall, regenerated from that table the morning of the session, projected on the biggest screen available. A meeting-room TV works; a projector wall is better.
  • The audit results, run beforehand: the facilitator should walk in already knowing where the grammar violations, bare squares, and suspicious names are, so the session spends its time on answers rather than discovery of defects.
  • A scribe able to edit the table live, and to regenerate the wall at the break or at the close.
  • The current red count, written somewhere the room can see. It’s the score.

Outputs

  • Answered reds removed from the model, each leaving a dated note on the card it questioned.
  • New reds for everything the audits and the walk surfaced that the room couldn’t answer, each placed beneath its impact, each with a name against it: not an owner of the problem, an owner of finding the answer.
  • Renames blessed by the room, where a name failed the audit and the room agreed on better words. The room’s words win; nothing gets renamed over the room’s objection.
  • Confirmed or struck (proposed) cards.
  • A new red count, and the delta from the old one, which is the only status report the session needs to produce.

Who’s Needed

The facilitator. Content-neutral, same discipline as any storm: they name problems and never solve them. They drive the scroll, run the audits as questions, and hold the room to answering rather than designing.

The scribe. Edits the table as answers land. Can’t be the facilitator; the facilitator’s eyes have to stay on the room. A capable scribe keeps up in real time; if yours can’t, capture answers on the reds themselves and fold after the session, same-day.

Domain experts, chosen for the stretch of wall being walked. The people who can actually take reds off: the booking manager for the intake chapters, the field lead for the field day, whoever owns the relationship with the external licensing authority for the flows that touch it. Two to five of them.

A developer or two. They hear the answers that will become code, and they ask the questions domain experts have stopped noticing are questions.

Ninety minutes for a few chapters of a big domain, or one full flow. Do not attempt an entire large domain in one sitting; walking a dozen flows takes a series of these sessions, each scoped to the chapters its experts can answer for.

How To Run It

Phase Duration Key question
Frame, show the score 5 min “Here’s the wall, here’s the red count”
Audit passes 35 min “The model says X; is that true?”
Reverse-narrative walk 30 min “What had to be true for this to happen?”
Count the reds down 15 min “What came off? What went up? Who owns each?”
Buffer 5 min
Total 90 min  

Phase 1: Frame, show the score (5 min)

Scroll the wall once, fast, top to bottom, no commentary. The room should feel the size of what they collectively know. Then say what the session is:

“Everything on this wall came from you, from the sessions we’ve run. My job today is to show you the places where the model is suspicious and ask you what’s true. Every question we can’t answer goes up as a red card next to the thing it questions. The red count is [N]. The goal is to leave with it lower.”

Point at one red so everyone knows what they look like, and read it aloud.

Phase 2: Audit passes (35 min)

Five audits, run as question-generators. The facilitator has the hit-list from running them beforehand; in the room, each hit becomes a scroll-to, a read-aloud, and a question. Keep each finding to a minute or two: answer it, red it, or rename it, then move.

The grammar audit. Every violation of the storm grammar is a missing card, and every missing card is a question. An event that appears to cause an event means something in between hasn’t been named:

“The model says Order Packed leads straight to Label Printed. Nothing decides that? Nobody batches, nobody checks anything, no rule about carriers?”

If the room names the rule, the (proposed) policy card between them gets confirmed and named in the room’s words. If they can’t, the proposed card stays with a red beneath it. A command with no issuer gets “who does this?”; an event with no command gets “how does this come to happen?”

The green audit. A policy consulting no data is a decision with unexamined inputs. Scroll to each bare or missing green:

“The model says something decides whether a job is ready to schedule. Decides it from what? What does whoever decides actually look at?”

The answers become named greens, and the greens’ sources become entries in the data catalogue, and sometimes the answer is “a spreadsheet on the scheduling desk”, which is exactly the kind of true answer this session exists to capture.

The actor audit. Walk the yellow squares that say “the system”, and the bare ones. “The system” is rarely the issuer:

“The system pauses the account after three failures. Did anyone decide that, or did it ship that way and everyone adapted? Who would change it? Who notices when it’s wrong?”

Automated is a fine answer; it gets the automation marker and the name of the system. But most walls hide a person behind half their “the system” squares, and that person has knowledge the model needs.

The naming audit. Read suspect event names aloud, one at a time, and ask the wall’s own tests: Past tense? Specific enough to identify alone on a wall of a hundred events? One event, or two stapled together? Any consequences smuggled into the name?

“‘Payment Processed And Receipt Sent’. That’s two things. Do they always happen together? Can one succeed and the other fail?”

Splitting a card like that regularly uncovers a failure path nobody had mapped. One discipline point: if the name on the wall is the room’s own phrase, it only changes with the room’s blessing. The model serves the room’s language, not the other way round.

The fan-out audit. One event causing several commands with no policy between them is a hidden rule:

“When Stock Runs Out, the model shows three different things happening. Do all three always happen? Who or what picks?”

Sometimes all three genuinely always happen, and that’s the answer. More often there’s a decision in someone’s head, and it comes out here, as a policy card with the deciding data beside it.

Phase 3: The reverse-narrative walk (30 min)

Brandolini’s reverse narrative, run on the projector: start from the final event of the scoped stretch and walk backwards, asking of each card “what had to be true for this to happen?” Forwards, a room nods along with a plausible story. Backwards, nothing can hide; every gap is a card that isn’t there.

“Invoice Sent. What had to be true? The work was signed off. Says who? Where’s that on the wall?”

Stall deliberately on the strawman stretches, the parts sketched without a workshop and marked as such. They were written to be attacked, so invite the attack:

“This section is our guess. Nobody has walked it. Where is it wrong?”

The room correcting a strawman is the cheapest discovery you will ever do; the correction arrives with the energy of someone fixing an error rather than the hesitance of someone filling a blank page. Every correction lands as an edit the scribe makes live; everything the room can’t settle lands as a red.

Phase 4: Count the reds down (15 min)

Return to the score in front of the room. Read out each red that came off today and each that went up. Then the number:

“We started at 61. Twelve came off, seven went up. 56. The seven new ones: here’s who’s finding each answer.”

Every new red gets a name and, where possible, a date. Group them by who can answer, because that grouping becomes the follow-up plan: three reds only the operations manager can answer become a session with the operations manager; four about the licensing authority become the list for the next call with the authority.

Close on the number. The room should leave knowing the score moved and what moves it next.

What Can Go Wrong

The room starts solving. A red turns into a design discussion.   Recovery: “That’s the fix; we’re after the facts today. Who can confirm what actually happens?” Name it, red it, move.   Stop if: The same voices keep designing after three redirects. End the walk early and book the design session they clearly want; a walk that’s become a design meeting produces neither.

The expert defends instead of answers. Audit questions land as accusations and the answers get cagey.   Recovery: Re-aim the question at the model: “The model is what’s on trial here. If it’s wrong, you correcting it is the session working.”   Stop if: The defensiveness has a political root: the walk is exposing that someone’s area runs on improvisation. Break, and raise it privately; projecting it to a room makes it worse.

The rename war. Two factions argue about what a card should be called.   Recovery: Both names onto the card, red beneath, owner assigned, move on. Naming disputes are real findings; they mark a term the glossary work hasn’t reached.   Stop if: Every second card triggers one. The model’s language has drifted from the room’s; the fold has been paraphrasing instead of transcribing.

The audit becomes a style critique. Findings are about tidiness, not truth: cards that could merge, lanes that could align.   Recovery: Ask of each finding, “what question does this raise for the room?” No question, no finding; the scribe tidies it offline.   Stop if: You genuinely can’t get questions out of the audits, which means the model is cleaner than the room’s time deserves. Declare victory, end early, spend the saved hour on the reds that need a different room.

The scroll outruns the room. The facilitator, who knows the wall by heart, walks past the exact spot someone was about to question.   Recovery: Scroll slower than feels natural, and at each section band ask, “anything on this screen anyone doesn’t recognise?”   Stop if: People have stopped reading and started waiting for it to be over. The scope was too big; cut to the two chapters that matter and walk them properly.

The score becomes theatre. Reds get answered thinly, or quietly not raised, because the number has to go down.   Recovery: Say the rule out loud: a red that goes up today is the session working just as much as one that comes off. Praise the person who adds one.   Stop if: Someone with authority is pressuring the count. The metric is no longer true, and a false burndown is worse than none; take the count off the wall and report findings narratively until it’s safe to bring back.

Next Steps

Same day: the scribe finishes folding the session’s answers into the table, renumbers, verifies, regenerates the wall, and sends the room three lines: the new red count, what came off, what went up and who owns each.

The facilitator’s week: turn the surviving reds into per-audience agendas, grouped by who can answer, each a printable one-pager. A red that needs the operations manager, the licensing authority, or a director is a meeting to book, and the agenda writes itself off the wall. Reds that need a rules conversation become Example Mapping or Decision Tables sessions; reds that need a flow nobody has stormed become the next Process Level session.

Then hold the cadence: storm, fold, walk. The walk is the checkpoint that keeps the folds honest, and the red burndown across walks is the truest picture of a discovery engagement’s progress that I know how to produce.

Variants

The paper walk. No generated wall, just the physical stickies from a recent storm. The audits all still work; run them with a marker in hand. What’s lost is scale (you can only walk what fits in the room) and the live score, since reds on paper need counting by hand.

The standing audit. The grammar and reference checks run on every edit anyway; a lighter session variant skips Phase 2 entirely and spends the whole hour on the reverse-narrative walk, trusting the machine to have already carded the mechanical findings. Good once a model has been walked twice and the easy defects are gone.

The chapter walk. Fifteen minutes, one chapter, run at the start of an unrelated meeting with the one expert who owns that stretch. Less ceremony than a full session, and often the fastest way to clear reds that are blocked on a single busy person.

The exec walk. Chapters and pivotal events only, reds shown as counts per chapter rather than card by card, ten minutes. Not a working session; it’s how a sponsor sees the shape of the domain and the direction of the number without sitting through the audits. Resist making it prettier than the working wall; it’s the same generated view, zoomed out.

These posts are LLM-aided. Backbone, original writing, and structure by Craig. Research and editing by Craig + LLM. Proof-reading by Craig.