The service-desk manager says per-host admin passwords will wreck handle time - how do you land the change?
answer
- his charter is a design constraint
- the security budget pays the friction
- invisible removals first
- a measured threshold and a written rollback
- offer break-glass before he asks
basics
~20 sTreat the objection as a cost to fund, not a blocker to overrule. Pay for password retrieval inside the console his engineers already use, sequence the invisible removals first, and commit to a measured handle-time threshold with a real rollback.
solid answer
~50 sHe is not wrong: the shared secret is fast, and his charter is handle time and first-contact resolution. So price each removal against his workflow. Per-host unique rotated secrets cost him seconds per call **if** retrieval is one click inside his existing console - so fund that integration from the security budget, because it is your requirement. A workstation-only support account costs him nothing at the desk; it costs you the account provisioning and group management. Approval-gated elevation is the expensive one, so keep it off routine laptop support entirely and spend it on rare, high-consequence rights. Sequence invisible changes first, agree a measurable handle-time threshold and a written commitment to roll back a named step if you cross it, and give him a sealed break-glass path with an owner. If he still refuses, escalate with the trade stated honestly: one owned laptop equals administrator on four thousand, and here is what that costs the business he supports.
go deeper
Understand that a security change with a real workflow cost needs the owning team's agreement, and that the fastest way to get a control ignored is to impose it.
Be able to explain which part of a support workflow each removal touches, and why retrieval friction is an engineering problem rather than a discipline problem.
Show you can sequence the rollout, keep support functioning throughout, and design a break-glass path that does not quietly restore the shared secret.
Own the negotiation: fund the friction from your budget, commit to a measured threshold with a real rollback, and frame the escalation as a business trade rather than a compliance finding.
## Start by conceding the true part The manager's objection is grounded. His team is measured on average handle time, first-contact resolution and abandonment rate; those are the numbers his own performance is judged on, and a memorised shared password is genuinely the fastest way for an engineer to get administrator on a machine at 09:00 on a Monday. If you open with a policy citation, you will win the meeting and lose the change - it will be adopted nominally, then worked around with an exception list, a spreadsheet of retrieved passwords, or a quietly re-created shared account. So the frame is: **his charter is a constraint on your design, and the friction your change creates is a cost your budget should absorb.** ## Price the three removals separately, in his units **Per-host unique, rotated secrets.** Cost to him: an engineer can no longer type a password from memory; he has to retrieve it for the specific host. That is seconds if retrieval is a control inside the ticketing or remote-support console he already has open, and a minute or more with a context switch if it is not. The difference between those two numbers is the entire objection, and it is an engineering task, not a policy question. Fund it. Add retrieval that is scoped to the ticket's host and available to the support role by default, so nobody has to raise a request to do their job. **A workstation-only support account.** Cost to him: essentially nothing after rollout - the engineer signs in as before, with a different account. Cost to you: provisioning, group management, and the awkward conversations with the two or three tools that expected a domain-wide administrator. Also cost to him at rollout: retraining muscle memory, which is real for a few weeks and should be planned into staffing, not sprung on a Monday. **Approval-gated elevation.** Cost to him: potentially minutes of wait per call, which is the one change that can genuinely wreck his numbers. So do not put it in front of routine laptop support at all. Reserve it for rights that reach servers or identity infrastructure, where requests are rare and the wait is proportionate. Saying this explicitly, unprompted, is what convinces him you have read his job description. ## The commitments that make it land **Sequence invisible first.** Per-host secrets with good retrieval, then the tier-2 support account, then gating for the rare high-privilege rights. Each step should be independently valuable so a stall does not strand the programme half-done. **Agree a number and a rollback.** "We will measure average handle time for the four weeks before and the four weeks after. If it rises by more than the agreed threshold and the cause is retrieval, we revert this step and fix the tooling first." A falsifiable commitment converts a security demand into a joint experiment, and it costs you little because the failure mode it insures against is one you can fix. **Give him the break-glass path, before he asks.** Machines go offline, retrieval systems fail, and at 02:00 someone will need in. A sealed emergency credential with a named owner and mandatory rotation after use is the honest answer. Refusing to provide one guarantees an unofficial one appears. **Do not let the escrow become the new shared secret.** If retrieval is clumsy, engineers will store what they retrieve. Watch for the workaround, and treat its appearance as evidence the tooling is inadequate rather than as a discipline problem. ## If he still refuses Escalate, but escalate with the trade stated in business terms rather than as a compliance finding. One laptop compromise currently equals administrator on the entire fleet - including the machines used by the people who approve payments - and the crew most likely to use that path is paid a share of the proceeds and works in days. Against that, the cost is a tooling integration and some seconds per call, both of which you are offering to fund and to measure. Put the decision, so framed, to the manager you and he share, and accept a phased plan over a perfect one: unique secrets on the highest-value hosts this quarter beats a fleet-wide design that never ships. ## What a weak answer looks like Mandating from a policy document. Running it as a security project with no service-desk owner. Skipping the integration spend and calling the resulting friction a training issue. Promising "no impact" - which is untrue, will be disproved in week one, and costs you every subsequent conversation with that team.
- He offers to accept the change if the service desk keeps one shared account for emergencies. Do you take it?Not as stated - a routinely available shared administrator account rebuilds the precondition you are removing. Counter with a sealed break-glass credential: a named owner, retrieval that is deliberate rather than convenient, mandatory rotation after each use, and a review of every use. The emergency capability is legitimate; its availability as a shortcut is what you refuse.
- Handle time does rise past the agreed threshold after rollout. What do you do?Honour the commitment. Determine whether the cause is retrieval friction or rollout learning curve, and if it is retrieval, revert that step, fix the integration and return. Keeping the promise is what buys you the next three changes; overriding it once means every future proposal from your team starts a level lower.
- Which of the three removals would you drop entirely if you could only fund two?Approval-gated elevation for routine support. It costs the most per use, buys the least against an adversary working in hours, and its value concentrates on rare high-privilege operations you can gate separately later. Unique per-host secrets and a workstation-only support account remove the cheap hops and cost the desk almost nothing once tooled.
saying these in an interview costs you the question
- Overrules the objection with a policy mandate
- Promises the change will have no operational impact
- Leaves the retrieval tooling unfunded and calls friction a training issue
- Runs the programme with no service-desk owner
- Gates routine laptop support behind approvals