TIME tells you what to do with an application. It doesn’t tell you how fast to do it. That’s a different question, and it’s the one that actually keeps CIOs up at night.
You already know which apps to modernize and which to retire. What you don’t know is which of those decisions can wait until next year, and which one is a live wire right now. That’s the gap the PAID framework closes.
What PAID Actually Is
PAID stands for Plan, Address, Ignore, Delay. Where TIME plots business fit against technical health, PAID plots two narrower, sharper questions: business criticality and technical risk.
Business criticality isn’t the same as business fit. Fit asks whether people like the app. Criticality asks how much damage happens if it fails. An app nobody loves can still be the one thing holding the business together.
Technical risk works the same way. It’s not overall technical health across every factor - it’s a tight focus on the handful most likely to actually break something: platform currency, security controls, disaster recovery, vendor support, and architectural soundness. An app can look fine on paper and still be one bad patch cycle away from an outage.
Score those two, plot them, and every application lands in one of four quadrants.
- Plan: Critical to the business, technically healthy. Keep it that way with scheduled maintenance and planned upgrades.
- Address: Critical to the business AND carrying serious technical risk. This is the fire alarm. Fund it now.
- Ignore: Low criticality, low risk. Check in occasionally, don’t spend a dollar on it.
- Delay: Real technical debt, but low business impact if it fails. Document the risk, accept it formally, revisit later.
Why This Matters More Than People Think
Every IT team has a list of things they know need fixing. The problem is never the list. It’s the ordering. Without a forcing function, the loudest voice in the room wins the budget - not the actual risk.
PAID replaces gut-feel triage with a number. It’s the difference between “we should probably look at that eventually” and “this is business-critical with a broken security posture, it goes first.”
How to Actually Use It
Pair PAID with a TIME assessment you’ve already run. The same applications, the same underlying scores, just recalculated through a narrower lens. Pull your Address quadrant first: those are business-critical apps sitting on real technical risk. Fund them this quarter. Everything in Delay goes to the backlog with a documented risk acceptance - not a shrug.
Why It’s Built Into GetInSync From Day One
PAID isn’t a separate exercise from TIME inside GetInSync - it’s the same assessment viewed through a different lens. On the App Health tab, one toggle switches between TIME and PAID views of the same applications. TIME gives you direction. PAID gives you urgency. Together, they turn a long list of “we should fix that” into a funded, sequenced roadmap.
The Bigger Point
Knowing what to fix is only half the job. Knowing what to fix first is what actually protects the business. PAID is how you turn a pile of known risk into a plan with a real order to it - instead of whatever got escalated loudest this week.