I Hate Governance
Well, I used to think I hated governance. Then I understood: what I hate is bad governance.
The gut reaction is easy to explain. Governance shows up as red tape in the machine, forms, approvals, a committee sitting between you and the thing you’re trying to ship. To most engineers it looks like overhead invented by people who never have to do the actual work. I felt exactly that for years.
Everyone in this field has the same scar: a change so trivial it’s barely a change, a few minutes of real work, that somehow takes the better part of a year to clear. Not because anything was unsafe. Not because there was a real risk to weigh. Pure process: a queue, a form, a sign-off, another queue, a meeting to schedule the meeting. By the time it’s approved, half the people who asked for it have forgotten why they wanted it, or the opportunity has gone somewhere else.
That is the experience that makes people hate governance. But look at what actually went wrong, because it matters. That wasn’t too much governance, and it wasn’t too little. It was bad governance. The process treated a trivial, low-blast-radius change like a load-bearing wall, the same gauntlet you’d run to re-architect the core. Good governance would have had a fast lane: low risk, expedite, move on. The control wasn’t the problem. The lack of proportion was.
Because some things genuinely are load-bearing walls, and those do not bend. Every program has its handful: the controls that actually stop an intrusion, or contain the blast when one gets through. I hold the line on those every time, because it only takes one gap in the wrong place to undo everything else. And when people push back on one of them, it’s almost never about the control itself. It’s about how it showed up: imposed from the top, no context, no conversation. The control is right. The delivery is wrong.
The genuinely hard part is rightsizing all of this. The bigger and more varied the organization, the more every corner of it runs on its own reality, its own pressures, its own idea of normal. Try to hold all of that to one rule and you get no appetite and a wall of resistance. One-size-fits-all is the fastest way to lose the room, and you cannot mandate your way to buy-in.
The department of no doesn’t fly anymore. What works is “yes, and.” Surface the risk in plain terms and in numbers, hand the call to someone senior enough to own it, and let the size of the downside set the response. People aren’t reckless. They’re focused on the thing in front of them, not the thing that breaks later. Show them the whole picture and let them decide. That’s governance when it works: a translation layer between business intent and security reality.
Which brings me to the part nobody likes to say out loud. You don’t protect everything equally, because everything isn’t equally valuable. The data that would genuinely hurt people or the business if it leaked is not the same as a file nobody would miss. Call it the give-a-shit factor: does the business actually care, and does it hurt if it gets out? If the answer is no, don’t be the one who grinds the work to a halt to protect it anyway. That isn’t diligence. It’s how you become the team everyone routes around, and the day you need a real control taken seriously, you’ve already burned your credit on a file nobody cared about.
Done right, governance is efficient, effective, and meets the needs of the business. People work through it, not around it: fast lanes where the risk is low, hard stops where it’s real, and a clear, quick path to a decision everywhere in between. You feel it. It’s working for you, not against you.
Built badly, it’s the opposite: inefficient, ineffective, blind to what the business needs. A hassle. A headache. Friction, and morale quietly bleeding out of every team that has to fight the process to do basic work. And that’s bad for business.
Good governance means good business.
Comments (0)
Leave a Comment
No Comments Yet
Be the first to share your thoughts on this article!