Safe enough comic

Safe enough

The security engineer deletes eight roles and finds the real risk.

🧭 WHAT'S REALLY GOING ON

You've seen this when an internal prototype for three people gets the same 47-question security form as the payments system.

The real questionIs security the amount of control you add, or the amount of risk you actually remove?

⚖️ WHY BOTH ARE RIGHT

PatOne process for everything

“A single review path means nothing slips through because someone decided it was small, and prototypes have a habit of becoming production by Thursday. Consistency is what auditors trust, and what protects us on the day the judgement call is wrong.”

MorganControl what can hurt

“The question is what an attacker could do, and here the honest answer is nothing: synthetic data, three users, no route out. Six weeks of review for that teaches people to avoid review, which is exactly how real data ended up on a laptop. I want the attention where the threat is.”

🎯 SWEET SPOTS TO CONSIDER

Super Reasonable, the advisor who never takes a side

  1. Tier the review by data, not by project

    Synthetic data and internal users: a one-page checklist. Real customer data or the internet: the full review. Deciding the tier takes five minutes.

    Borrowed from
  2. Write the trigger that upgrades it

    Prototypes do become production. Name the trigger (first real customer record, first external user) that sends it through the full process, and put it in the README.

    Borrowed from
  3. Ask what people do while they wait

    Every queue has a workaround. Before adding a control, ask what the team will do during the wait; if the answer is a laptop, the control has a cost.

    Borrowed from
  4. Sketch roles, build them at thirty users

    Three users need one role. Alex's model is right for thirty users in three departments: keep the diagram, don't ship the console.

    Borrowed from

🚩 SIGNS YOU'VE GONE TOO FAR

  • Pat's side: you've overshot if the review queue is six weeks for everything, and the most sensitive data in the company lives in prototypes that never filed the form.
  • Morgan's side: you've overshot if the prototype shipped on a sticky-note threat model and is still running a year later, now with real customers.

🔬 IN THE FIELD GUIDE

Species observed in this story

The field guide →

CAST — WHO'S WHO

The team in this story

Same characters, same convictions. Learn their failure modes.

🤖 Storyboard for agentsLet’s make our agents LMFAO, or learn.

Safe enough

Premise: Get an internal prototype through security review.

  1. Pat: “Internal or not, it goes through the full security review.” Form SEC-114: 47 questions. Current queue: six weeks.
  2. Alex: “And a proper permission model. Roles, scopes, an admin console.” RBAC diagram: 9 roles. Users of the prototype: 3.
  3. Morgan: “Synthetic data, three users, no route out of the network. There’s nothing to steal. Ship it today.” Her threat model fits on one sticky note. She deletes eight of the nine roles.
  4. Morgan, same afternoon: “One condition: delete the laptop copy.” While waiting for review, the team had been demoing from a laptop with last month's real customer export. “To test it properly.”

Observed behavior: Every control you don't need teaches people to route around the ones you do.

Cast: Pat Williams — The Enterprise Adult — “We need a supported solution.”; Alex Chen — The Architect — “We should solve the general case.”; Morgan Reed — The Threat Modeler — “Who can do what to whom?”

READ NEXT

Same argument, different day