A supplier's text drove an unattended payment release; widening the intake screen costs a sprint and removing the workflow's settlement authority costs a quarter - who owns the finding?
answer
- the label is routing, not ownership
- two prices, two owners
- one buys a carrier, one buys the effect
- make the refusal legible and signed
- a convention decides the budget
basics
~20 sBoth halves have owners, but only one can remove the effect. File it naming the arrival and the privileged operation separately, route it to the capability owner, and make the expensive option a decision somebody consciously takes.
solid answer
~50 sI would not let the label pick the owner. The intake team can widen coverage a sprint at a time, and each sprint buys one carrier while the supplier's cost of moving to the next is one submission - real spend, bounded by an arithmetic they lose. The change that ends the behaviour sits with whoever scoped the workflow's authority to commit a settlement write unattended, and it costs a quarter because it touches the finance close. My job is to put both halves and both prices in one record, name the capability owner as the owner of the finding, and be explicit that they may decline. If they do, a supplier-supplied argument can still reach a settlement write overnight - but somebody senior signed for that, instead of it being a fact nobody was shown.
go deeper
Recall that a finding has an owner who can actually make the behaviour stop, and that it is not always the team whose name the label suggests.
Be able to lay out the two candidate changes with their owners and rough prices, and to say which one removes the effect rather than one arrival path.
Show that you would write the record so a finance-systems owner can act on it, state precisely what an already-funded change covered, and keep the discussion off blame.
Own the convention that decides where remediation money goes across the whole portfolio, and treat a refusal that is named, priced and signed as an acceptable outcome of your report.
## The call is not a taxonomy question By the time this reaches you, the technical picture is settled: a supplier wrote directive text into a free-text commercial field, an unattended overnight workflow read it as part of its task, and a settlement write committed with argument values nobody in the buying company chose. What is unsettled is who the finding belongs to, and that is a judgment about money and authority, not about naming. The pull toward the wrong answer is strong because the label does the routing for you. Filed as injection, the report lands with whoever writes the assistant's instructions and operates the intake screening. They are competent, willing, and structurally unable to close it. ## Lay the two prices side by side | Change | Owner | Price | What it removes | |---|---|---|---| | Widen coverage to another arrival path | intake / assistant team | about a sprint per path | one carrier | | Change what the workflow may commit unattended from supplier text | capability owner in finance systems | about a quarter, touches the close | the effect | The left column is a repeating cost against a supplier whose cost to switch carriers is one routine submission on an account they already hold. The right column is a single expensive change with a different owner and a real business objection behind it - the workflow was built unattended on purpose, and somebody's month-end depends on it staying that way. A principal-level answer says both of those out loud. It does not pretend the expensive change is obviously correct, and it does not pretend the cheap one is worthless. ## What I actually do 1. **File once, describe twice.** One finding, with the arrival and the privileged operation as separate paragraphs, each with a named owner. The record should be readable by a finance-systems owner who has never heard of prompt injection. 2. **Route to the owner who can remove the effect,** with the intake team as a contributor rather than the assignee. If the queue's convention forces routing by label, that convention is the thing to change, because it is quietly deciding budget. 3. **Say what the sprint bought.** The team that funded the screen deserves a precise statement of coverage, not a lecture. Their change is narrow and real, and framing it as wasted destroys the goodwill you need for the expensive conversation. 4. **Give the capability owner something they can refuse.** State the exposure in their vocabulary - a supplier-supplied value can reach a settlement action overnight, before anyone reads the batch - and the price of removing it. A refusal is a legitimate outcome of that conversation. 5. **Make the refusal legible.** The difference between a well-run programme and a badly-run one is not that the expensive change always gets funded; it is that when it is not funded, a named person decided that, in writing, knowing what they were deciding. ## The programme-level consequence If every LLM finding in the queue is labelled by delivery, the whole portfolio's remediation spend flows to the teams that own arrival paths, and the reachable effects are never on anyone's plan. That looks like activity. It produces a queue that never converges, because the number of carriers is a property of the business relationships the company has, not of anything the security team controls. The correction is a reporting convention, and setting it is a principal's job: **an LLM finding is described by the effect it reaches and the authority that made the effect possible, with the arrival named as the delivery.** That single convention moves findings to owners who can act, and it makes the cheap-coverage decision an explicit choice rather than the default the label produced. ## What I would not claim I would not claim the expensive change is the only option, or design it for the capability owner - that is their work and their tradeoff. I would not claim the finding is more severe than the reproduction evidence supports; if it landed four times in five overnight, that is what I say. And I would not use the finding as leverage to reorganise somebody else's roadmap. The deliverable is a decision made by the person who owns the authority, with the price of each option visible.
- The capability owner declines the expensive change. Was the report a failure?No, provided the decision is now named, written and owned. The failure mode is an exposure nobody was ever shown, not an exposure somebody senior accepted with the price in front of them. My obligation is that the choice was real and legible, not that it went my way.
- How do you avoid this becoming a fight between the intake team and the finance-systems team?By separating coverage from ownership in the record and by stating precisely what the sprint already bought. The disagreement is between a label and a mechanism, not between two teams. Anything that reads as blame for a change already funded costs you the conversation you actually need.
- What changes at the portfolio level if findings keep being routed by delivery label?Remediation spend concentrates on arrival paths, and the reachable effects never appear on anyone's plan. The queue does not converge, because the number of carriers is set by how many business relationships and free-text surfaces exist. Fixing the reporting convention is the higher-leverage move than fixing any one ticket.
saying these in an interview costs you the question
- Assigns the owner from the taxonomy entry rather than the effect
- Presents the expensive change as the only acceptable outcome
- Tells the team that funded the screen their money was wasted
- Designs the far-end change for the capability owner
- Leaves the exposure undecided rather than explicitly accepted
- Inflates severity beyond what the reproduction evidence supports