An approval queue for credential reads has never denied a request — what does that tell you about the control?
answer
- denial rate alone proves nothing
- pair it with the response time
- modification is the everyday judgment
- same requester every day means routine
- moving work off the gate strengthens it
basics
~20 sBy itself, very little: most requests really are legitimate. Paired with a two-second median response it means nobody is reading them, and the usual cause is that the gate sits in front of routine work rather than exceptional access.
solid answer
~40 sA zero denial rate is not the tell on its own, because a healthy gate mostly sees honest requests. The tell is the denial rate together with the response time and the modification rate. If approvals land in two seconds and no approver has ever narrowed a scope or shortened a window, the second opinion exists on paper only. Two causes need different fixes: the gate is on routine reads, so approval has become a keystroke; or the approvers cannot judge, because the request does not show them the scope, the referenced work or this requester's recent history. Move routine reads onto a narrow standing grant with after-the-fact review, give the approver enough to judge, and make them set the duration rather than accept the requested one.
go deeper
Recall that an approval only counts if somebody actually looked; an instant approval on every request is a signal worth asking about.
Explain which numbers diagnose it — response time, how often scopes are narrowed, and how often the same person asks — rather than the approval rate alone.
Separate the two causes and pick the matching fix, including the unpopular one of moving routine reads off the gate onto a narrow standing grant.
Decide what the pool is measured on and published against, and resist both a denial quota and an automated approver as ways of making the numbers look healthy.
## One symptom, two causes An approval queue that has never refused anything is not automatically broken. Most requests in a functioning estate really are legitimate, and refusals are the rarest outcome of a control that mostly works by making people state what they are doing. The diagnosis needs a second number. The two causes worth separating: 1. **The gate is on the wrong reads.** It sits in front of work people do several times a day, so approving became a keystroke within a fortnight. Nothing about the approvers is wrong; the placement is. 2. **The approvers cannot judge.** The request does not show them what scope was asked for, what it reaches, whether the referenced work matches, or whether this requester asked three times this shift. A person approving from a two-line notification is not withholding judgment — they have nothing to apply it to. ## The measurements that tell them apart - **Response-time distribution.** A median of a couple of seconds means nothing was read, whatever the approval rate says. A median of a few minutes with a long tail looks like people actually opening requests. - **Modification rate.** How often does an approver narrow the scope or shorten the requested window before agreeing? This is the single best signal, because modification is the everyday form of judgment and refusal is the rare one. - **Requests per requester per week.** A gate on exceptional access sees a handful. The same person appearing daily means routine work is being dressed as an exception. - **Scope distribution.** If nearly every request asks for the widest scope the requester is eligible for, nobody is being made to think about scope — neither the requester nor the approver. - **Sent-back rate.** Has any request ever been returned for more detail? A queue where that has never happened is a queue nobody has ever found underspecified. ## What the gate still produces at a hundred per cent approval Even with no refusals ever, an approval step that is genuinely being performed still yields real output: a stated reason on every read, a second name attached at the time, a narrowed window on requests that asked for too long, and a record an external audit can follow. That is a large part of why the control exists, and it is why *approval rate* alone is a poor health metric. But all of it is contingent on somebody having looked; a two-second median says they did not, and then the output is a record of a decision nobody made. ## Fixes, including the honest one | finding | fix | |---|---| | routine reads behind the gate | move them to a narrow standing grant and review the reads afterwards | | approver has no context | show scope, referenced work, what it reaches, and this requester's recent requests | | durations never shortened | require the approver to set the duration instead of accepting the requested one | | nobody knows if it is decaying | sample-audit approvals and publish the modification rate to the pool | The first row is the one teams resist, and it is usually correct. A gate is worth its cost only on infrequent, high-blast-radius reads; routine access needs a narrow scope, not ceremony. Moving work off the gate is strengthening the control, because it restores the approvers' capacity to examine the requests that are left. ## What not to conclude Do not conclude that a denial quota is the answer. Manufacturing refusals to prove vigilance teaches requesters to pad their requests so that something can be cut, and it costs real work real time. Do not conclude that automating the approval preserves the control either: an approval nobody made is a record that will mislead whoever reads the trail later. If a class of read is routine enough to be approved automatically, the honest move is to say it is routine and control it with scope.
- Why is the modification rate a better health signal than the denial rate?Because refusal is rare even in a healthy gate, while narrowing a scope or shortening a window happens on ordinary, legitimate requests. A modification is direct evidence that somebody opened the request and acted on what it said, and it improves the outcome without the cost of a refusal.
- An approver says they approve instantly because they trust their team. What is the problem?The control was installed on the assumption that a second person looks at the specifics, not that a second person vouches for the first. Blanket trust returns the design to a standing grant with an extra click, and it removes the one defence against a compromised account belonging to a trusted colleague.
saying these in an interview costs you the question
- Treats a zero denial rate as proof on its own that the gate failed
- Sets a target denial rate so that approvers appear vigilant
- Approves from a notification without seeing the requested scope
- Keeps routine reads behind the gate to avoid appearing lax
- Automates the approval while still recording it as a decision