To stop the risk function writing policies nobody can implement, a company embeds two risk engineers inside the platform team to build and operate the policy gate themselves. Time from policy publication to enforcement drops from two quarters to days. What has the company given up, and when does that bill arrive?
Show the full answer Hide the answer
What is gained
Rules that actually run. A policy author who can test a rule against the real estate writes rules with far fewer false positives, and a gate with a low false-positive rate is one engineers stop trying to bypass. Enforcement lead time falling from roughly six months to days is a real and large improvement, and it is usually worth doing.
What is paid
Independence, and specifically the independence that made the gate's output worth something as evidence. The control still runs in production and still blocks things; what it stops being is testimony about the team that built it.
The second line's value is not that it writes good policies. It is that its assessment of first-line work was produced by someone who does not carry first-line delivery pressure. Once the same two people own the rule, the exemption list and the log, the third line can no longer treat gate output as independent evidence, because a single group controls what the rule says, who is excused from it and what the record shows.
The mechanism is ordinary and has nothing to do with bad faith. A release is blocked at 18:00 on a Thursday. The people who can change the rule are sitting in the same room, under the same deadline, and changing the rule is faster than fixing the finding.
When the bill arrives
Two moments, and they are both predictable.
The first is the first assessment that tests the control rather than the estate. An assessor who asks "who can change this rule, and what is the record of changes" gets an answer that undermines every clean run the gate has produced, and the finding is a design failure rather than an operating one, which costs a remediation programme rather than a fix.
The second is visible earlier if you look for it. Count rule changes and exemption additions made within 48 hours of a blocked release, as a share of all rule changes. In a healthy setup it is near zero. Above roughly 10% the gate has become negotiable, and the number is available from the repository's history without asking anyone.
How to keep the option to reverse
Split the artefacts rather than the people, so embedding buys implementability without surrendering the property that makes the evidence worth having.
- Rule definitions live in their own repository with second-line owners in CODEOWNERS and signed commits. The embedded engineers write them; approval sits with the risk function, remotely.
- The engine and its pipeline integration belong to the platform team, because that is engineering work.
- The exemption register is a third location that delivery teams cannot merge to, with expiry enforced by the gate rather than by a reminder.
- The gate's output is an append-only stream the third line reads with its own credentials and no write access anywhere.
When not to bother
At 40 engineers and one risk person, embedding is the only option available and the splitting above is ceremony. The right answer there is to state the independence gap explicitly, record it as an accepted risk with an owner, and buy periodic external testing of the control. That is honest and cheap. Pretending a one-person function is independent of itself is neither.