When I started, I had a thesis, a platform, and 18+ years of conviction that the timing was finally right. Then the largest grant-rule rewrite in a generation landed mid-cycle and made the case better than I could.
Six weeks of posting and the operators who showed up turned the thesis into something sharper and the platform into something more honest.
What's next: I'm taking everything this first beta round taught me and building it in. The seams operators found, the questions I'd never been asked, the gaps between how compliance should work and how it actually breaks. That's the roadmap now, written by the people who live this, not just the person who built it.
The bigger arc hasn't changed. Federal oversight is moving from periodic to continuous, and the organizations that hold up will be the ones whose structure was ready. I'm building the structure. I'd rather build it with you than for you.
To everyone who tested, commented, and pushed back, thank you. The next chapter is the real one.
Structure determines outcome. Let's continue building it.
Governance that depends on heroes isn't governance. It's luck with good intentions.
In a lot of grants operations, compliance works because of a person. The one who knows where everything is, remembers why each decision was made, holds the whole picture in their head, and pulls off the audit every year through sheer competence and long hours.
That person is real, and invaluable. They're also a single point of failure.
Heroic governance has a structural flaw: it doesn't survive the hero leaving, getting sick, or being overwhelmed when oversight goes continuous. You can't scale a hero, and you can't audit a memory. The knowledge in one person's head is, by definition, not on the record.
Structural governance is the opposite. Defensibility lives in the system, not the person. Anyone can answer the question because the answer is captured, not remembered. The operation holds whether or not the hero is in the building.
The shift from heroic to structural governance is the shift from luck to leverage. One depends on a person. The other depends on architecture and architecture doesn't quit.
The proposed rules will test which one you've actually built.
The most expensive part of your compliance program might be living in email threads and shared drives.
Here's the hidden cost. When the record of why a decision was made lives in someone's inbox, you don't actually have that record. You have a person who might remember where it is, who might still work there, in a thread that might still exist.
That's not documentation. It's distributed memory with no index. And distributed memory is exactly what fails under continuous oversight, because the questions come faster than the reconstruction can keep up.
The cost shows up in three places: the staff time spent hunting for justifications that should be one click away; the risk carried in the gap between "we decided this for a reason" and "here's the reason, on the record"; and the findings that surface when the reason can't be produced at all.
Email and shared drives feel free because you already pay for them. The real cost is in what they can't do: hold defensibility in a form you can retrieve on demand, which is exactly what the proposed rule will ask for.
How much of your compliance "system" is actually just email and folders nobody's organized?
Three questions every pass-through entity should be able to answer in 60 seconds.
If any of these takes longer than a minute, that's where your structure is thin:
1.) Which of your current subrecipients carries the highest risk right now, and on what basis? Not a gut feeling but a basis you could show someone.
2.) For your largest active subaward, when was the last substantive monitoring touch, and what did it find? Not the last email. The last real check.
3.) If a downstream entity misused funds tomorrow, how quickly would you know and could you show you'd been exercising oversight all along?
These aren't trick questions. They're the questions a reviewer is effectively asking, continuously, in the environment the proposed rule is bringing. The ability to answer them fast is a direct read on whether your monitoring is structural or improvised.
How many of the three could you answer in 60 seconds, honestly?
A monitoring failure, anonymized, because the pattern is more useful than the names.
A pass-through entity subawarded funds downstream. Onboarding was clean. Early reports came in fine. Everyone moved on.
Months passed with no real visibility, the relationship ran on quarterly reports and the assumption that no news was good news. Then a routine review surfaced that the subrecipient had been using funds in a way that didn't match the approved scope. Not fraud. Drift. The kind that accumulates quietly when nobody's watching closely.
The pass-through entity carried the finding. Not the subrecipient, the pass-through. Because the oversight obligation was theirs, and "we didn't have visibility" is not a defense. It's a description of the failure.
The structural lesson: monitoring that depends on periodic reports and good-faith assumptions isn't monitoring. It's hoping on a schedule. Real oversight is continuous by design, visibility that doesn't drop when the funds move. And the proposed determination rules make that obligation harder to wave off.
The seam between you and your subrecipients is where this lives. Worth closing before a review closes it for you.
"We've always done it this way" is the most expensive sentence in grants management. It's expensive because it was true for so long.
For decades, the way it had always been done actually worked. Periodic oversight rewarded stable process. Continuity was a virtue. The operations that didn't change much were often the ones that didn't get burned.
That's precisely what makes the sentence dangerous now. The environment underneath it is being rewritten. The methods that were safe because they were unchanging are now risky because they're unchanged. The ground is shifting; the habit isn't.
This is the trap of inherited process: it feels like prudence right up until it's exposure. The spreadsheet that always worked. The classification you never revisited. The reconstruction-at-audit rhythm that always got you through.
The question isn't whether your process is wrong. It's whether it was built for the environment you're about to operate in or the one that's ending.
What's one "we've always done it this way" in your operation that's overdue for a hard look?
"Audit-ready" means something specific at the transaction level. Most people define it too high. Ask a room what audit-ready means and you'll hear: organized files, clean reports, policies in place. All true. All insufficient.
Audit-ready, in the environment being proposed, means something more precise: for any single transaction, you can show what it was, why it was justified, who touched it, when it changed, and how it maps to a specific award activity....on demand, without reconstruction.
That's a transaction-level standard, not a file-level one. And it's a higher bar than most "audit-ready" operations actually meet, because file-level organization can sit on top of transaction-level gaps. The binder looks clean. The individual dollar, traced, falls apart.
The proposed payment-justification requirement is precisely a transaction-level standard. You become ready for it not by organizing what you have, but by capturing the right things at the moment they happen.
Audit-ready isn't a state of your files. It's a property of your transactions.
The difference between a subaward and a contract isn't paperwork. It's risk classification and the proposed rule makes misclassifying it a sharper exposure.
Quick refresher, because it matters more than it used to: a subaward passes through federal assistance to a subrecipient who carries out part of the program. A contract buys goods or services from a vendor. Different relationships, different oversight obligations.
The proposed direction tightens this specifically; pass-through entities would no longer treat transfers to affiliates or related entities as internal allocations exempt from determination. Every downstream transfer has to be classified and reported.
Why this is structural, not clerical: the classification determines what oversight you owe. Get it wrong, and you've either under-monitored a subrecipient (a finding) or mis-reported a relationship (also a finding). The misclassification is the exposure.
Operations that make this determination by habit, "we've always called this a contract", are carrying risk they can't see.
When's the last time you actually re-examined how your downstream relationships are classified?
The cheapest audit is the one your structure already passed.
Think about what an audit actually costs you. Not the finding, the preparation. Weeks of staff time pulled off mission to reconstruct a story that should have been captured as it happened. The scramble. The carried risk while you assemble proof you hope holds.
Almost all of that cost comes from structure that wasn't ready. If defensibility is built into how the work runs; every justification captured, every figure traceable, every subaward documented as it moves, the audit doesn't trigger a scramble. It triggers a query against a system that already has the answers.
That's the cheapest possible audit: the one where readiness was a byproduct of good structure, not a project run under pressure.
The proposed direction makes oversight effectively continuous, you're always being reviewed. The only sustainable answer is structural readiness.
If you want to see where your structure stands before October tests it, that's exactly what @uMorphos Grants is built to show. Comment or message me.
Six weeks of posting through the biggest grant-rule shift in a generation. Here's what the feed taught me.
I came in with a thesis: that operators feel the periodic-to-continuous shift even if they don't have language for it. The feed mostly confirmed it but not where I expected.
The posts that landed weren't the ones announcing what I built. They were the ones naming a problem people recognized but hadn't articulated...the quiet seam, the traceability gap, the "reduce burden" line that isn't actually relief. People don't engage with solutions. They engage with being seen.
The lesson for anyone building in public: lead with the problem you understand better than anyone, not the product you're proud of. The product earns attention only after the problem earns trust.
That's how I'll keep building this; problem first, in public, with the people who live it.
What's a problem in your world that nobody's naming well yet?
Last call for this round of beta access to @uMorphos Grants.
No false urgency...I'm capping this round because real feedback only works when I can act on each person's input. Small group, real access, honest trade.
The external timing is real, though: comments on the proposed overhaul close this week, and the final rule effective by October 1. The operations that get structurally ready now are the ones that won't be scrambling in the fall.
If you manage federal funds on the post-award side; financial control, subrecipient monitoring, indirect cost, audit readiness...this is built for you.
You get the platform free. I get your honest read on where it holds and where it doesn't.
The organizations that adapt to what's coming won't be the ones that worked harder. They'll be the ones whose structure was ready. This is a chance to help shape that structure and to have yours ready first.
Comment or message me. I'll open the next round when this one's done its work.
Structure determines outcome. Here's exactly what that means for federal funds. It's not a slogan. It's a claim about cause and effect.
The outcome of a federal award; clean audit or costly finding, recovered cost or returned cost, durable funding or terminated award, is not primarily determined by how hard your team works. It's determined by the structure they work inside.
A team working heroically inside periodic infrastructure will still struggle under continuous oversight, because the structure can't produce what the environment demands. A team working calmly inside the right structure will pass the same scrutiny without the heroics because defensibility is a property of the system, not a feat of the staff.
This is why "work harder" is the wrong prescription for the moment the proposed rules are creating. Effort applied to the wrong structure produces exhaustion, not defensibility. The leverage is in the architecture.
Change the structure, and the outcome changes with it. That's the whole thesis. Everything @uMorphos Grants does follows from it.
The comment window closes soon. Here's the through-line of everything OMB proposed.
Strip out the politics and the section numbers, and one principle runs through the entire proposed rule: every federal dollar should be traceable to actual, justified use, verifiable not at audit, but as it moves.
Watch how consistently it shows up. Payment justification at drawdown. Verification before disbursement. Elimination of fixed-amount awards that escaped monitoring. Explicit subrecipient determinations for every downstream transfer. Termination authority tied to ongoing alignment. Different sections, one logic: move the control to the moment of action, and make traceability the default state of federal money.
That's not a collection of rule tweaks. It's an architecture. And architecture doesn't reverse, even if specific provisions change in the final rule, the design philosophy is the direction of the whole system.
Comments close July 13; the final rule effective by October 1. Whether or not you comment, read the through-line. It's the clearest picture you'll get of the environment you'll be operating in.
What I learned the first time a tester broke something I was proud of.
You build a thing carefully. You're proud of how it handles the cases you imagined. Then an operator uses it for ten minutes and hits a case you didn't imagine because they live in a reality you were only advising on.
The instinct is to defend the design. The discipline is to be grateful. Every break a tester finds now is a break a customer doesn't find later and a finding an auditor doesn't find after that.
This is why I'd rather build with operators than for them. Advisory expertise tells you how things should work. Operators tell you how they actually break. The platform that holds up is built at the intersection of both.
Builders: what's the most useful thing a user ever broke for you?
We don't sell grants software. We install a compliance control layer. The distinction matters, and it's not semantics.
"Grants software" is a category of tools that help you administer awards; track tasks, store documents, manage workflows. Useful work. But it sits inside your operation as another application among many.
A compliance control layer sits above your financial systems and does a different job: it holds traceability, monitoring, and defensibility continuously, across whatever tools you already run. It doesn't replace your ERP or your existing systems. It governs the compliance logic they were never built to carry.
One is an app you adopt. The other is infrastructure you install, a structural addition to how your operation holds itself accountable.
That's why "another grants tool" is the wrong frame for the moment the proposed rules are creating. The new environment isn't asking for better administration. It's asking for continuous oversight. Those require different architecture.
We're not in the software category. We're in the infrastructure category. The difference is the whole point.
Reimbursement visibility sounds boring. It's where cash flow and compliance collide.
Here's the unglamorous reality of post-award life: you spend first, then get reimbursed (typically). Which means your cash position and your compliance posture are the same problem wearing two hats.
When reimbursement visibility is poor, two things break at once. Financially, you're carrying costs without a clear line of sight to recovery, a cash-flow strain. From a compliance standpoint, the same gap that obscures your reimbursement status usually obscures the documentation that justifies it. The drawdown you can't clearly track is often the drawdown you can't cleanly defend.
Most operations treat these as separate problems; finance handles cash, compliance handles defensibility. Structurally, they're one problem. And under a proposed rule that wants payment justification at drawdown, they collapse into one even more tightly.
Solve it once, structurally, and you fix both. Solve it twice, in two systems, and you've built the gap in.
Do your finance and compliance views of a drawdown come from the same source of truth, or two systems you reconcile by hand?
Termination authority is quietly expanding. Read ยง 200.340 before you assume your award is settled. Among the proposed changes, this one gets less attention than the payment rules and it shouldn't.
The proposal would clarify and reinforce the reasons a federal agency can terminate an award, including where it no longer aligns with program goals or agency priorities, and would require those termination provisions to appear in every award. Set the policy debate aside and look at the operational reality: an award is not a fixed, settled thing. It's a continuing relationship subject to continuing judgment.
That changes how you should think about defensibility. It's not enough to have been compliant at the point of award. The expectation is that you can demonstrate ongoing alignment and accountability throughout the life of the award because the basis for continuing it is, increasingly, under continuous review.
An award you can't continuously defend is an award you're holding on borrowed confidence.
Proposed, not final. But ยง200.340 is worth reading closely while the window's open, it tells you how durable the relationship really is.
Early testers are giving me SO much feedback๐๐ฝ
The trade I offered was simple: free access in exchange for honest feedback. What I underestimated is how much the feedback would sharpen the thing. Operators see seams an advisor never could, because they're inside the daily reality, not consulting on it.
This is why the beta exists. Not to validate what I built but to find where it bends under real weight, and fix it before the proposed rules make the weight heavier.
I'm opening a few more spots in this round. If you manage federal funds on the post-award side and want your operation's reality built into the platform, comment or message me.
The best version of this gets built with operators, not for them.
Where does your subrecipient monitoring actually live today?
Not where the policy says it lives. Where it actually happens, day to day, when someone needs to check on a downstream entity.
Be honest, this is one of the most consequential questions in grants management, and the proposed rule is raising the bar on exactly it:
1.) Spreadsheets we maintain by hand
2.) Email + shared drives, pieced together
3.) A real system built for it
4.) Informally โ no single place
There's no wrong answer to admit. But knowing where you actually stand is the first structural move.
19 months ago I had my daughter. In the last month, I built the platform I'd wanted to build for 18 years. ๐ซ The gap between those two facts is the whole story.
I've known what public funds management needed for almost two decades. In 2022 I drafted a framework to reshape the Uniform Guidance and was in early conversations with a congressional office. Then I paused. The timing told me to wait...adoption wasn't ready, and neither, honestly, was I.
So I waited. I had my daughter. I kept advising. And the environment kept moving in exactly the direction I'd been describing.
Recently, the OMB proposed the largest rewrite of the Uniform Guidance since it was created. The direction is the one I sketched eight years ago. Turns out my intuition was right. It just took eight years and a regulatory shift to reveal itself.
That's the thing about being early: it feels identical to being wrong, right up until it doesn't.
@uMorphos Grants is what I waited to build. Structure determines outcome, including the timing.