“A single review path means nothing slips through because someone decided it was small, and prototypes have a habit of becoming production by Thursday. Consistency is what auditors trust, and what protects us on the day the judgement call is wrong.”

Safe enough
The security engineer deletes eight roles and finds the real risk.
🧭 WHAT'S REALLY GOING ON
You've seen this when an internal prototype for three people gets the same 47-question security form as the payments system.
The real questionIs security the amount of control you add, or the amount of risk you actually remove?
⚖️ WHY BOTH ARE RIGHT
“The question is what an attacker could do, and here the honest answer is nothing: synthetic data, three users, no route out. Six weeks of review for that teaches people to avoid review, which is exactly how real data ended up on a laptop. I want the attention where the threat is.”
🎯 SWEET SPOTS TO CONSIDER
Super Reasonable, the advisor who never takes a side
Tier the review by data, not by project
Synthetic data and internal users: a one-page checklist. Real customer data or the internet: the full review. Deciding the tier takes five minutes.
Write the trigger that upgrades it
Prototypes do become production. Name the trigger (first real customer record, first external user) that sends it through the full process, and put it in the README.
Ask what people do while they wait
Every queue has a workaround. Before adding a control, ask what the team will do during the wait; if the answer is a laptop, the control has a cost.
Sketch roles, build them at thirty users
Three users need one role. Alex's model is right for thirty users in three departments: keep the diagram, don't ship the console.
🚩 SIGNS YOU'VE GONE TOO FAR
- Pat's side: you've overshot if the review queue is six weeks for everything, and the most sensitive data in the company lives in prototypes that never filed the form.
- Morgan's side: you've overshot if the prototype shipped on a sticky-note threat model and is still running a year later, now with real customers.
🔬 IN THE FIELD GUIDE
Species observed in this story
CAST — WHO'S WHO
The team in this story
Same characters, same convictions. Learn their failure modes.
🤖 Storyboard for agentsLet’s make our agents LMFAO, or learn.
Safe enough
Premise: Get an internal prototype through security review.
- Pat: “Internal or not, it goes through the full security review.” Form SEC-114: 47 questions. Current queue: six weeks.
- Alex: “And a proper permission model. Roles, scopes, an admin console.” RBAC diagram: 9 roles. Users of the prototype: 3.
- Morgan: “Synthetic data, three users, no route out of the network. There’s nothing to steal. Ship it today.” Her threat model fits on one sticky note. She deletes eight of the nine roles.
- Morgan, same afternoon: “One condition: delete the laptop copy.” While waiting for review, the team had been demoing from a laptop with last month's real customer export. “To test it properly.”
Observed behavior: Every control you don't need teaches people to route around the ones you do.
Cast: Pat Williams — The Enterprise Adult — “We need a supported solution.”; Alex Chen — The Architect — “We should solve the general case.”; Morgan Reed — The Threat Modeler — “Who can do what to whom?”
READ NEXT

