Beau-TieTools

Using Beau-Tie

Beau-Tie is a one-event-per-bow-tie editor. Open it at /bow-tie and on your first visit you land on the sample Customer data breach bow tie: the editor never starts empty, so you always have something to react to. After that it reopens your own work; the New menu brings the sample back any time. This guide walks the practical workflow from blank canvas to exportable artefact.

It assumes you already know what a bow tie is and what the vocabulary means. If you don't, start with the bow tie methodology page.

Starting a bow tie

Three ways to begin:

  • From the sample. The default, and useful when you're learning the tool or demonstrating the diagram shape to a workshop. Edit it in place; your changes are yours alone and never touch the sample for anyone else.
  • From a blank bow tie. Click New and choose Blank bow tie. You get an empty canvas and a fresh record header (Company pre-fills from your /account profile when you have one, and Date defaults to today). Start by setting the risk event statement, then add causes and consequences.
  • From a template.The same menu lists ten built-in templates covering common scenarios: cybersecurity data breach, supply chain disruption, key person dependency, regulatory non-compliance, major IT system outage, internal financial fraud, workplace safety, reputational damage from social media, climate and extreme weather, and M&A integration failure. Templates pre-populate causes, consequences and example controls, along with starter ratings and tags, so you can focus on tuning rather than scaffolding.

Switching to a blank bow tie or a template replaces what's on the canvas, so the editor asks before discarding unsaved changes.

The record header

Above the canvas sits a record bar with metadata fields:

  • Risk name: a short identifier (e.g. "Customer data breach"). It names the export files and appears on every export's title strip.
  • Risk owner: the role accountable for the risk. Use the role title, not a person's name, so the bow tie ages well.
  • Company, Business unit, Date: context for the export deliverable. Date defaults to today when a record is created; set it to the assessment date, because it appears alongside the risk name on the exported diagram's title strip and in the report header.
  • Tags: free-form labels (e.g. security, iso31000). They help organise a collection of bow ties and travel with the JSON envelope for filtering.

Building the canvas

The canvas has a fixed layout: causes on the left, the central event in the middle, consequences on the right. Connections between them are auto-routed; you don't position connectors manually.

The central event

Click the central event box to edit the event statement. Keep it short and noun-form. The description field below it is free-form context for the export reader; it isn't shown on the canvas.

Adding causes and consequences

Use the Add cause and Add consequence buttons in the side panel. Each gets a name and an optional description, and the canvas arranges them vertically in the order you add them.

Adding controls

Open a cause or consequence in the side panel and click Add in its Controls section. Each control has:

  • A name and optional description.
  • A type: Preventive (P), Detective (D), Corrective (C), Directive (Di) or Recovery (R). Most controls on the cause side are P or D; C and R sit on the consequence side; Di can sit anywhere it shapes behaviour. The methodology page covers how this taxonomy maps onto the standard's split between likelihood-modifying and reactive controls.
  • A status: existing or planned. Existing controls render as solid circles; planned controls render dashed.
  • For existing controls, an effectiveness on the platform's five-level scale (Not, Partially, Moderately, Substantially or Highly Effective). For planned controls, an implementation timeline (0–3, 3–6, 6–12 or 12+ months).

Controls position themselves automatically along the line connecting their cause or consequence to the central event. To reposition one, hold Shift, Ctrl or Cmd and drag the control circle along its line. The position saves with the bow tie.

Rating the risk

The Ratings panel at the bottom of the editor (the Ratings tab on mobile) is where you set residual, target and appetite. Each is a likelihood and consequence pair selected from the matrix's configured labels, and the mini-matrix alongside plots the positions as you set them.

Conventions worth following:

  • Set residual first: this is the truth on the ground. Don't anchor on what you wish it were.
  • Set target after costing the planned controls. A target that requires multiple high-effort treatments is fine if the treatments are named and tracked; a target that requires unspecified work is wishful thinking.
  • Appetite is policy, and setting it is an organisational decision rather than something an analyst does in isolation. If your organisation doesn't maintain explicit appetite statements, leave the marker off: better to omit than to invent.

Editing the matrix

Click Matrix in the toolbar to open the matrix editor. The grid is 5×5, and within that shape everything is editable:

  • Relabel the likelihood and consequence steps (e.g. switch likelihood labels from "Rare / Unlikely / Possible / Likely / Almost Certain" to "<5% / 5–25% / 25–50% / 50–75% / >75%").
  • Rename any cell's band and change its colour, cell by cell.
  • Reset to default restores the shipped matrix if an experiment goes wrong.

Saving applies the matrix to the current bow tie. Tick Also set as my default before saving to make new bow ties (and new PRQ registers) start from it as well; when you're signed in that default syncs through your account, so your other devices pick it up when they next open a tool.

The shipped matrix is a starting point, not a recommendation. The guidance position, covered on the risk matrix page, is that scales should always be customised to your organisation's objectives and the range of consequences it actually faces.

Exporting

The Export menu offers five formats:

  • JSON: the full platform envelope (montyco/v2), the format Beau-Tie itself reads. Use it for backup, version control, or handoff to another Beau-Tie user.
  • PNG image: the full 16:9 presentation slide on a white background, with the title strip, the diagram, the ratings strip with its mini matrix, and the legend, rendered at high resolution for slide decks and quick paste-ins.
  • Excel risk register: a register sheet with one row per risk, with causes, consequences, existing controls and planned controls as bulleted lists within the row. Built to drop into treatment-tracking workflows that already live in Excel, and to grow into a multi-risk register.
  • PDF report: an A4 landscape report. Page one is the diagram; the record detail follows, with the risk event and notes beside the matrix card, register tables for causes and consequences with their controls, then the planned-controls roadmap and a watch list of weak spots. Long bow ties paginate cleanly; a branch and its controls are never split across pages.
  • PowerPoint deck: a 16:9 deck with the diagram as a full-bleed slide plus title, overview, causes, consequences, existing controls, planned controls and ratings slides (and notes, when present), ready to reorder or restyle in your own template.

Where is your work saved?

Beau-Tie is local-first. Signed out, your in-progress bow tie lives in your browser's storage: close the tab and reopen it and you're exactly where you left off, but clearing browser storage deletes it, so export a JSON copy of anything that matters.

Signed in, the bow tie saves to your account instead and loads on any device you sign in on. The account holds one live bow tie per tool today, so use JSON export to keep a library of finished ones. If a cloud save ever fails, the editor falls back to saving locally and tells you so. Sign-in and cloud storage covers the full model, including what the operator can and cannot see.

What Beau-Tie doesn't model

The bow tie technique as described in the standards includes elements the editor does not yet draw. Knowing where the edges are is part of using the tool defensibly:

  • Escalation factors. Conditions that defeat a control, and the controls on those conditions, are part of the full technique. Beau-Tie doesn't model either; if a control's failure modes matter to your analysis, record them in the control's description for now.
  • Management functions. The supporting activities that keep controls working (training, inspection, maintenance) can be shown beneath a bow tie, linked to the controls they support. Beau-Tie has no surface for them.
  • Cascading bow ties. One event's consequence feeding the next bow tie's cause has to be managed as separate diagrams today.
  • Opportunity bow ties. The technique works for desirable consequences as well as undesirable ones, and the platform's data model carries a threat-or-opportunity field, but the editor doesn't yet expose it.
  • Quantification. Beau-Tie is deliberately qualitative. Putting numbers through a bow tie is only sound under independence assumptions that rarely hold, which is why the platform does quantification with PRQ and Event Risk instead.

The methodology page covers each of these in the context of the technique itself, with the sourcing.