20Plans get scanned by policy-as-code before merge. Which rules earn a hard block, and who can waive one?▼mediumNewJPMorgan ChaseGoldman SachsCloudflare○ sign inScan plan JSON on every pull request, run new rules advisory for two weeks, and block only what is law. Waivers live in version control with an owner and an expiry date, or the gate becomes noise within a quarter.Open full answer →
16Audit season starts in eight weeks. How do you turn compliance from a document scramble into code?▼hardNewJPMorgan ChaseGoldman SachsSalesforce○ sign inThe reframe that scores: many controls contain machine-checkable assertions; others require human evidence. Guardrails prevent, gates stop pipelines, drift detection watches live state, and evidence falls out as a byproduct.Open full answer →
24Our security exception list only grows. Design a risk-acceptance process that does not rot.▼hardNewSalesforceSAPAtlassian◆ premiumExceptions rot when they lack expiry dates, named owners and an aggregate view. Structured records where engineers work, auto-expiry with teeth, and a monthly portfolio review that treats growth as a control failure.Open full answer →
42Half your team's Terraform is now written by an assistant. What changes about how you run reviews and pipelines?▼hardNewHashiCorpGitLabGitHub2 replies◆ premiumGenerated infrastructure code is plausible, fluent and confidently wrong in specific ways. The volume goes up, the reviewer attention per line goes down, and the controls that used to be optional stop being optional.Open full answer →