Every recommendation is traceable to specific asset owner responses. Every score can be explained in plain English. No politics, no gut calls.
Does this asset earn its keep? NORA asks the owner what the asset actually delivers — and whether the business would feel it if it disappeared.
What NORA Asks
What measurable benefit does this asset deliver?
Would a core business process stop if it vanished tomorrow?
Can you quantify the value — revenue, time saved, cost avoided?
Is there a manual workaround, or is it truly load-bearing?
Is it used at the scale that justifies keeping it? Low adoption often signals wasted spend — or a shadow alternative people actually prefer.
What NORA Asks
Who uses it, and how often?
How many people depend on it day to day?
Does its output feed work other teams rely on?
How many people actually have expertise in it?
Does it do something no sanctioned tool already does? Redundant tools multiply cost and attack surface for no real gain.
What NORA Asks
Is there an approved or existing tool that does the same or similar?
What specifically does this do that the alternative doesn't?
Could an existing tool be configured to cover it?
Is the uniqueness essential, or merely a convenience?
Is there an accountable owner willing to fund and maintain it — including security oversight? An unowned asset is an ungoverned asset.
What NORA Asks
Who is the named owner?
Do they have budget allocated, or just informal responsibility?
Is there a succession plan if that owner leaves?
If the deployment doesn't match company standard, is the owner willing to fund the extra security and maintenance?
Can the security team actually secure it? An asset security can't see or control is a standing liability — no matter how useful it is.
What NORA Asks
Does it support SSO or centralized identity?
Audit logging and role-based access control?
Encryption of data at rest and in transit?
Has it undergone a security review by our organization?
Can the security team get the visibility and control they need, or is it a black box?
Each dimension is scored 1–5 on its own merits. NORA combines them into a weighted Justification Index from 1.0 to 5.0 — and maps that index to a clear, defensible recommendation.
One override protects against false positives: an asset with no real owner, little adoption, and no uniqueness is flagged for Retire regardless of its other scores — because a tool nobody owns, nobody uses, and nobody needs isn't worth securing.
Inside NORA
The same model inside NORA: each asset scored across the five dimensions and resolved to one defensible recommendation — sanction, consolidate, or retire.
A recommendation to retire or keep a business-critical tool has to withstand scrutiny. NORA builds that defensibility into the method itself.
Business Value, Adoption, Uniqueness, Ownership, and Security Capabilities are each scored on their own evidence. A strong answer on one never inflates another — a discipline a human reviewer can't reliably self-impose.
Each dimension score is derived from the owner's own answers in the guided conversation, not a gut call or office politics.
The owner answers in business language; NORA produces a scored recommendation with a rationale that can be explained to a CFO or an auditor.
Business Justification uses the same guided-conversation approach as NORA's risk assessment — consistent, repeatable, traceable.