How the Discovery sub-phase works

Where this fits

Understand the problem from the people living with it. Decide whether to reuse, buy, or build. Stopping here is a good outcome.

The official checkpoints of a digital service shows where Discovery comes in the whole journey, checkpoint by checkpoint.

Before you start Discovery

A discovery goes badly when the basics are not in place first. These are the things to have before you begin:

THE MAKE-OR-BREAK QUESTION

Reuse, buy, or build

The needs behind most existing Government of Canada services were met by something that already existed:

  • bought from a vendor
  • reused from another department
  • configured from a platform the government already runs

Before any solution is named, Discovery weighs those options and makes sure the service will not duplicate one that already exists. Three public registries make the scan concrete: the GC Service Inventory lists existing services, the Open Resource Exchange lists open-source solutions other teams have released, and the Open Government Portal holds the government's published data.

Sometimes the answer is not a service at all. Clearer information, or a change to a form, can be enough on its own.

See how to weigh the options →

What to find out in Discovery

The team you need

Discovery needs a small, multidisciplinary team, dedicated to it. The minimum roles (one person can hold more than one):

  • User researcher runs the research and interviews.
  • Designer maps the journey and shapes early thinking.
  • Business and policy lead knows the program, the rules, and the constraints.
  • Business owner steers the work and owns the decision to go on or stop.

In the Government of Canada the team is usually assembled from a mix of public servants and vendors. A discovery is short: four to eight weeks is typical.

CAUTION

When Discovery goes wrong

  • The team runs with the solution it was handed and never asks what the real problem is.

  • No goal was set, so the work drifts and never finishes.

  • The people who actually live with the problem are never spoken to.

  • Someone starts building, or picks a vendor, before the problem is understood.

  • A constraint that would kill the idea surfaces late, after months of work.

A REAL EXAMPLE

Three thousand mailboxes, of five hundred thousand

In 2011, Shared Services Canada took over email, data centres, and networks for 43 departments, and set out to fold the departmental email systems into one. The plan: more than 500,000 mailboxes moved to the new service by March 2015.

By that date, about 3,000 had moved. The Auditor General found that clear, concrete expectations with the departments were never set, and that progress and savings could not be properly measured or tracked: the commitment came before the understanding. Counting what exists, agreeing what good looks like, and asking whether the thing can be done at all: that is Discovery's work, and no later phase can do it retroactively.

How you know Discovery is finished

Discovery is finished when you have decided whether or not to move on to Alpha. That decision weighs two things: whether there is a viable service worth building, and whether it is cost-effective to pursue.

  • Forward to Alpha,

    when the problem is real and worth solving.

  • Stop or pause,

    when the evidence says it is not worth building. Stopping here is a success, and it saves the money a wrong build would have cost.

Everything Discovery makes is knowledge, and all of it crosses over. Before you move to Alpha, have ready:

The official instruments in Discovery

Everything official that has something happening to it during Discovery, and what that something is. The tag says what stage the instrument reaches here, not that it is finished.

Placing an instrument in a sub-phase is this guide's own editorial choice, anchored where possible on a real deadline in the instrument itself. The full detail, including who does the work and what the business owner personally does, is in the table on the home page.

Every service

  • Security categorizationAssessmentGathersource

    A rating of how much injury would result if the service's information leaked, if someone altered it, or if the service became unavailable.

    Name what information the service will hold and how bad each kind of loss would be. Anchored on the categorization sitting in the concept phase, before requirements and design.

  • Security assessment and authorization, ending in the Authority to Operate (SA&A, ATO)AuthorizationGatherSign or acceptsource

    The formal permission for the service to run.

    Get the standing conditions for authorization out of the departmental security plan, or from the authorizer directly, and put them in the project charter. The authorizer signs the charter.

  • Service in both official languagesStanding dutyCheck

    The duty to offer and deliver the service in English and French, equally and at the same time.

    Confirm the service is available across Canada, which is what makes it bilingual by rule rather than by choice.

Only if it applies

  • Privacy checklist and privacy impact assessment (PIA)AssessmentChecksource

    A structured look at what personal information the service collects, why it is allowed to, where it flows, how long it is kept, and what happens to people if it goes wrong.

    Complete the privacy checklist. It is a documented step in its own right, and the answer can be no.

    Applies when: Triggers are broad. A new or substantially modified program that creates, collects, uses, discloses, retains or disposes of personal information brings it into scope. So does using it for an administrative purpose, contracting the program out or transferring it, bringing in a third party, changing the technology that processes it, or automating a decision. No dollar or user-count threshold.

  • Concept caseSubmissionCheckFillSubmitsource

    A short, early write-up of the problem, the rough size of the investment, and the direction being considered, produced before a business case and before any solution is chosen.

    Work out whether the threshold is crossed, write it, get assistant deputy minister approval, and send it. It precedes the architecture review board submission and any Treasury Board submission.

    Applies when: Mandatory for digitally enabled projects where the department is willing to invest at least: $2.5 million with no approved capacity class or class 1; $5 million at class 2; $10 million at class 3; $15 million for National Defence; $25 million at class 4.

  • Project complexity and risk assessment (PCRA)AssessmentCheckGatherFillsource

    A 64-question scoring tool that rates a project from level 1, sustaining, to level 4, transformational.

    The business risks section comes from the client or project sponsor, including how ready the organization is to adopt the thing.

    Applies when: Required at: $2.5 million with no approved capacity class or class 0; $5 million at class 1; $10 million at class 2; $25 million at class 3; $50 million at class 4, all tax included. Note this ladder differs from the architecture review board ladder as written.

  • Treasury Board submissionSubmissionChecksource

    The formal request to the Treasury Board for authority and money when the project is beyond what the minister can approve alone.

    Whether one is needed follows from the complexity level and the department's capacity class, so it is knowable early.

    Applies when: When the project's complexity level exceeds the department's approved capacity class, or the department has no class and the project is over $2.5 million. Plus all programmes. Plus procurement or real property above their own approval limits.

  • Benefits realization plan and project close-out reportSubmissionFillsource

    The written statement of what good this project is supposed to do, and the later report confirming what was actually delivered and whether the promised benefits arrived.

    The benefits are named when the funding is sought, not afterwards.

    Applies when: Universal for anything that counts as a project under the projects and programmes directive, with no dollar trigger. Baseline reporting to the Office of the Comptroller General starts at $25 million.

  • Security Requirements Check List (SRCL, form TBS/SCT 350-103)SubmissionCheck

    A short form that states, for one specific contract, exactly what security the supplier and its people need: what level of information they will touch, what screening each role needs, and whether the company may hold government information at its own offices.

    Work out whether a supplier will be involved at all, and whether they would have access to protected information. Editorial placement.

    Applies when: Only where the supplier or its people will access Protected or Classified information or assets, enter restricted sites, or connect electronically to departmental systems, which includes any access to personal information the department holds. Where there are no security requirements, no check list is produced and the department certifies that instead.

  • Identity and credential assurance levelsAssessmentCheck

    Two ratings, from one to four, of how sure the service has to be about who someone is, and how strong the sign-in has to be.

    Establish whether the service identifies people at all.

    Applies when: Any service where people or businesses have accounts, sign in, or are identified. A worksheet under the authentication requirements guideline produces the level. At level three and above, multi-factor authentication follows.

Create, Live, and Sunset, with Create split into Discovery, Alpha, and Beta, and Live split into Stabilization, Growth, and Maturity.Discovery, Alpha, and Beta: the three sub-phases of Create, from understanding the problem to a real service ready to launch.

Assumptions this page makes

You are already working to the Government of Canada Digital Standards, design with users, iterate and improve frequently, work in the open, use open standards, address security and privacy, build in accessibility, empower staff, be good data stewards, design ethical services, and collaborate widely, and to the law on privacy, security, official languages, and accessibility. The standards say how the government works in the digital world. The six Government of Canada digital competencies say what every public servant has to be able to do to work that way, and the team page covers them. This guide builds on those.