skip to content

Which Threat Modeling Manifesto anti-pattern is a six-week, 200-element diagram with no threats enumerated yet?

level: middleimportance: nice to knowfreq 34%

answer

  1. One of the Manifesto's four anti-patterns
  2. About the artifact, not the discussion
  3. No single ideal view exists
  4. Several partial views beat one complete one
  5. A whiteboard drawing beats an unfinished masterpiece

basics

~20 s

Perfect Representation. The Manifesto's answer is that no single ideal view of a system exists, so several partial representations that each illuminate different problems beat one supposedly complete model — and the analysis should have started weeks ago.

solid answer

~50 s

That is **Perfect Representation**, one of the Manifesto's four anti-patterns. Its claim is not that the diagram is too detailed; it is that there is no single ideal view of a system, so it is better to create multiple representations, since additional views illuminate different problems. Six weeks on a 200-element diagram of an insurance broker portal before one threat is written down has bought precision in the one dimension that produces no findings. It also inverts the value pair `doing threat modeling over talking about it` — a rough drawing on a whiteboard that people argued over beats a beautiful model nobody finished. The practical move is to enumerate against the coarse view you already have, and let the analysis correct and extend the drawing as it goes, rather than treating completeness as the gate on starting.

go deeper

for a junior

Know that you can start finding threats from a rough sketch, and that no diagram has to be finished or approved before the first threat gets written down.

for a middle

Be ready to state the actual claim — there is no single ideal view, so multiple representations illuminate different problems — rather than the vaguer do not over-engineer paraphrase.

for a senior

Show which complementary views you would choose for a real system and what each is meant to surface, and explain how enumeration corrects the drawing as it goes.

for a principal

Own the milestone question: a programme whose first deliverable is a complete architecture model has planned for something unachievable. Be ready to redefine what the first deliverable is instead.

### What the anti-pattern actually says **Perfect Representation** is the fourth of the Threat Modeling Manifesto's anti-patterns. It is easy to misquote, so get its content exactly right: it is better to create *multiple* threat modeling representations, because **there is no single ideal view**, and additional representations may illuminate different problems. Notice what that is not. It is not a rule about how much detail belongs in a drawing, and it is not a claim that sloppy diagrams are fine. It is a claim about the **existence of an ideal**. If no one view is complete, then `finish the model first` is not a coherent plan, and any programme whose first milestone is a finished representation has planned for a milestone it cannot reach. ### How it shows up An insurance broker portal: a team spends six weeks growing a diagram to two hundred elements. Every queue is drawn, every sidecar, every configuration store. It is genuinely impressive. Not one threat has been written down. Three things have gone wrong: 1. **The effort bought precision in a dimension that yields nothing.** Findings come from asking what can go wrong at a boundary, not from the count of boxes. 2. **The value pair is inverted.** `Doing threat modeling over talking about it` — six weeks of drawing is preparation for the exercise, not the exercise. 3. **The diagram is stale on arrival.** A portal under active development moved during those six weeks, so the completeness the team was chasing was never achievable in the first place. ### Multiple views, not one better view The constructive half of the anti-pattern is the interesting half. Different representations surface different threat classes, so the answer to `which view is right` is `draw another one`: - A **coarse flow view** shows where data crosses a boundary between things with different levels of trust — where most tampering and disclosure threats live. - A **data-lifecycle view** follows one class of data from collection to deletion, which is what surfaces retention, copying and third-party sharing problems that a flow view hides. - A **privileged-path view** draws only the administrative and support routes into the system, which is where the paths nobody diagrams tend to be. - A **sequence view** of one important transaction exposes ordering and state problems — the double-submits and replays that no static box diagram shows. None of these is complete. Each is cheap. Together they find more than one perfected drawing does, which is precisely the Manifesto's argument. ### The objection worth answering `Surely an accurate diagram is a precondition for finding real threats?` The direction of causation is backwards. Enumerating threats is one of the most reliable ways to *discover* that the drawing is wrong — someone says `what about the support console` and a whole undrawn path appears. The drawing gets fixed by the analysis; waiting for it to be right first means waiting on something the analysis was supposed to produce. That said, the anti-pattern is not a licence for a misleading picture. A view that shows a boundary where none exists sends the analysis somewhere false. The failure being named is treating **completeness as the gate on starting**, not caring about accuracy in the parts you drew. ### How to say this in an interview The strong answer names the anti-pattern, states its actual claim (`no single ideal view`, so prefer several representations), and then makes the practical move: start enumerating against what exists now and let the analysis extend the drawing. A weak answer paraphrases it as `do not over-engineer your diagrams`, which sounds close and misses the point — it turns a claim about the plurality of views into a vague plea for moderation.

  • If no single view is ideal, which views would you actually draw for a broker portal?
    A coarse flow view to place the trust boundaries, a data-lifecycle view following one class of data from collection through deletion, and a privileged-path view showing only the admin and support routes in. Each is cheap and each surfaces a different class of threat — the lifecycle view finds retention and sharing problems the flow view hides, and the privileged-path view finds the routes nobody diagrams.
  • Isn't an accurate diagram a precondition for finding real threats?
    The causation runs the other way as often as not. Enumerating threats is one of the most reliable ways to discover the drawing is wrong — someone asks about the support console and an undrawn path appears. Waiting for the picture to be right first means waiting on something the analysis itself produces.
  • Does Perfect Representation mean diagram quality does not matter?
    No. A view that shows a boundary where none exists sends the whole analysis somewhere false, so accuracy in what you did draw still matters. The anti-pattern targets a specific belief: that one complete, canonical picture exists and must be finished before analysis can begin.

A city has no one correct map: the street map, the transit map and the elevation map each show what the others hide, and waiting for a single map that shows everything means never leaving the house.

saying these in an interview costs you the question

  • Believes one canonical diagram must exist before analysis starts
  • Paraphrases the anti-pattern as do not over-engineer your diagrams
  • Treats diagram polish as evidence of model quality
  • Says multiple views just duplicate maintenance, so pick one
  • Claims threats cannot be enumerated until the architecture is signed off

context