Most supply planning advice describes one posture: be lean, or be resilient. A distributor needs both, at different times, on different SKUs. This framework names four states a SKU at a location can be in, what moves it between them, and what a planner should be able to say in each.

LEAN

The default. Replenishment is short and reliable, alternatives are real, uncertainty is within its normal range, and the customers served do not need more than the stock on hand and inbound. Protection is small and the plan should be able to explain why: "two independent sources within one period, spread within calibration".

PROTECT

Entered when uncertainty becomes economically dangerous: the supplier's observed lead-time tail widens, partial deliveries rise, a route signal appears, demand shifts up and the new level is not yet confirmed, or a high-commitment customer's exposure grows. Protection is bought early and specifically: order earlier, split the source, hold more of this SKU, not every SKU. The size of the protection follows from the spread of plausible futures and the probability given to the adverse ones, so it is larger for a credible, expensive stress and smaller for a remote one. Page's CUSUM and its descendants are the workhorse for detecting the demand part of this without reacting to one abnormal week.

ALLOCATE

Entered when the requested service targets are not jointly achievable with the stock and supply that exist. The question changes from "how do we meet every target" to "which customers do we serve first, and by how much do we miss the rest". Priority and contractual targets decide; a plan that raises a lower-priority customer at the expense of a higher one is rejected; and the miss is classified as unavoidable, avoidable, an economic trade-off, a model failure or insufficient data. Cheapness is not a reason to prefer a plan in this state.

RECOVER

Entered when supply is coming back: open orders are arriving, the supplier's record is normalising, the route signal has cleared. The plan works off the emergency actions, restores the customers that were rationed in priority order, and stops buying protection for a risk that is passing. Time to recover, in Simchi-Levi's sense, is measured here.

Back to LEAN

The test of the whole framework is the return. If protection built during a disruption is still there a year later, the business has not become resilient, it has become expensive. Protection should disappear when the risk disappears, and the plan should be able to show that it did.

Why states, not a dial

A single "risk appetite" dial applies the same posture to every SKU and customer. States are per SKU and per location, they are entered on evidence, and each has its own reporting: what triggered it, what it cost, what it protected. That is what lets an operator approve a plan, rather than trust it.