Your change board rubber-stamps 200 microsegmentation approvals a month - what do you ask the funder to buy or give up?
answer
- review capacity is the ceiling, not rule count
- signatures are not reviews
- grain or budget - pick one
- changing the control changes the claim
- a named owner accepts the residual
basics
~20 sAn intruder's path is assembled from individually approved changes, so rubber-stamping is the failed control. Name the real ceiling - review capacity, not rule count - and make the funder choose: pay for reachability testing, or accept a coarser grain.
solid answer
~50 sI would put the choice, not the complaint, in front of the risk owner. The ceiling on how fine a policy can be is not the platform's rule capacity but the organisation's capacity to state what the rules permit, and at 200 changes a month that is already exceeded. Three options, each with a price somebody must accept. Fund reviewers: buys throughput, not assurance, because the extra reviewer still cannot state the aggregate. Fund a reachability service and move review to invariant violations plus sampled deep review: costs standing headcount and changes the control we claim, which the risk owner must accept in writing. Coarsen the policy to the grain we can state: cheapest, and hands back isolation the business already paid for, so the business owner signs. Whichever they pick, the claim that every segmentation change is reviewed must be corrected first: it is false.
go deeper
Know that an approval is only a control if someone could actually verify the change, and that signing 200 changes a month with minutes each is not verification.
Be able to explain why extra reviewers do not fix this: each still sees one defensible change, and the risk lives in the composition nobody computes.
Show you can convert the problem into numbers a decision-maker acts on - arrival rate against verified capacity, no-comment approval share, time to answer what reaches a named system.
Own the trade: set the grain from review capacity, get a named owner to accept whatever isolation you hand back or fund the reachability capability instead, and correct any control statement you cannot substantiate.
## Name the failed control first Two hundred changes a month, two reviewers, minutes each. The approvals are real signatures on real tickets, and none of them is a review. If an intruder later walks a path composed of those approved changes, the control that failed is not the firewall, the platform or any rule - it is review. Say that plainly, because every option below follows from it and none of them makes sense if the conversation stays on rule quality. ## The measurement that reframes the argument Stop reporting rule count and coverage percentage. Report: - **change arrival rate against verified-review capacity** - how many changes arrive, and how many a reviewer can actually verify rather than sign; - **share of changes approved with no comment**, which is the rubber-stamping rate stated as a number; - **time to answer "what can reach the actuarial data store"** - if that is days, the policy has passed the grain the organisation can hold; - **invariant coverage** - how many of the pairs we say must never be reachable are actually tested. Those four turn an engineer's unease into a governance fact, which is what gets funded. ## The three options, with their prices **Fund more reviewers.** Honest assessment: it buys throughput and almost no assurance. The marginal reviewer sees the same defensible single change and still cannot state the aggregate, because the aggregate is a computation no human performs. Present it, price it, and say why it is the weakest option - offering it strengthens the other two. **Fund the reachability service and change what review means.** Review becomes: every change automatically evaluated against a stated invariant set, blocked if it breaks one, plus a sampled deep review of a percentage of changes. This is the strongest technical answer and it has a governance cost people miss: **the control you claim changes**. "Every change is reviewed by a person" becomes "every change is tested against stated invariants, and a sample is reviewed by a person". That is a better control and a different one, and the risk owner - and often the external auditor - must accept it explicitly before you operate it, not after. **Coarsen the policy.** Set the grain from review capacity rather than from what the platform can express, and collapse distinctions that do not correspond to trust boundaries. Cheapest and fastest. Its price is real: some isolation the business already paid for goes back, and the blast radius of a compromised workload grows. That is a decision a named risk owner takes with the numbers in front of them, not one an engineer makes quietly in a consolidation ticket. A fourth, usually combined with the second: **push approval to workload owners behind automated guardrails**. It distributes the burden and moves accountability closer to the people who understand the application, but it only works if the invariants exist first - otherwise you have distributed rubber-stamping. ## The uncomfortable part: withdraw the claim If the audit committee, a customer contract or a regulatory submission says every segmentation change is reviewed, that statement is currently untrue and you know it. Correcting it before an assessor or an incident does is the principal-level move, and it is the part candidates skip. It also, usefully, creates the pressure that funds the fix: a control you cannot substantiate is a finding whether or not anything bad has happened. ## How to leave the room With a decision, not a paper. Concretely: an agreed target grain justified by review capacity; a named owner for the residual risk of whatever is coarsened; a funded owner for the reachability computation if that is the route; a corrected control statement; and one tripwire number reported monthly, so the same conversation does not have to be reconstructed from scratch next year. ## What a weak principal answer sounds like "We need more headcount in the change process." It names no ceiling, offers the funder no choice, and would leave the estate in exactly the state that let the path be built - finer than anyone can state, with signatures standing in for knowledge.
- The audit committee has been told every segmentation change is reviewed. What do you do about that?Correct it before an assessor or an incident does. Restate the control as it actually operates, with the rubber-stamping rate as evidence, and pair the correction with the proposal that fixes it. A withdrawn claim plus a funded plan lands very differently from a claim discovered to be false during an investigation.
- The business owner refuses a coarser grain. What then?Then they are funding the reachability service and its standing owner, because those are the only two ways to hold fine policy honestly. The choice is grain or budget. What is not on the table is keeping the fine grain, refusing the funding, and continuing to describe rubber-stamping as review.
- Which single number would you report monthly after the decision?Time to answer 'what can reach this destination' for a named high-value system, with the share of changes approved without comment beside it. The first says whether the policy is still statable; the second says whether review is still real. Rule count and coverage percentage say neither.
saying these in an interview costs you the question
- Asks for more reviewers without saying what they would then be able to state
- Reports rule count or coverage percentage as the health metric
- Continues to claim every change is reviewed when it is not
- Decides the policy grain without a named risk owner accepting the residual
- Assumes finer segmentation is always safer regardless of who can review it
- Treats coarsening as a purely technical change needing no business consent