Skip to contentThe Observability LayerSearch

Enterprise handbook · Section 17 of 30

15. A 90-day implementation sequence

This is a proposed sequence for a first controlled workflow, not a claim that every enterprise can complete the work with existing staffing. Select a process with a clear success oracle, a named resource owner, and bounded consequences. Schedule depends on access, integrations, procurement, reviewer capacity, and the maturity of existing controls.

Evidence table: Phase, Work, Accountable first-line role, Exit evidence
PhaseWorkAccountable first-line roleExit evidence
Days 1-30: authority and inventoryChoose workflow; register manifest and mandate; inventory effect routes; implement identities, least privilege, limits, and exact-scope approval.Business process owner, with platform/resource ownersE01/E02/E04 artifacts; successful denial, revocation, budget, and bypass tests.
Days 31-60: evaluation and evidenceBuild external outcome oracles; add paired normal/harmful cases; evaluate timing, monitor thresholds, delayed influence, interactions, and recovery.Platform lead and workflow ownerLocked test set; configuration-linked results; evidence reconciliation; residual-failure register.
Days 61-90: bounded operation and challengeRun shadow then bounded canary; verify reviewer staffing; compare customer stages where relevant; exercise incident response; obtain independent release challenge.Business process ownerProduction evidence, completed drill, stage outcomes, challenge record, and bounded operating authorization.

15.1 Responsibilities across the three lines

Evidence table: Decision or activity, First line, Second line, Third line
Decision or activityFirst lineSecond lineThird line
Mandate and autonomyBusiness proposes and owns use; platform implements.Risk approves the framework and challenges proposed scope.Tests governance and exception discipline.
Evaluation designSupplies business scenarios and system access.Validation challenges construct validity and owns independent conclusions.Re-performs selected methods and tests.
Runtime enforcementPlatform and resource owners operate controls.Security/risk defines control standards and reviews residual risk.Tests operating effectiveness and bypass coverage.
Customer outcomesBusiness owns service and remediation.Compliance/fairness reviews lawful scope, analysis, and rights.Audits end-to-end decision and remedy evidence.
Incident handlingOperations contains, reconciles, and restores.Legal/compliance determines reporting duties; risk challenges restart.Assesses control failure and corrective-action closure.
Release and promotionBusiness accepts responsibility within approved policy.Independent validation/risk challenges evidence and exceptions.Reviews authorization and the evidence chain.

Assign one accountable role per deliverable in the local RACI. Internal audit should retain independence from designing or approving the controls it will later audit. Legal review should establish applicable duties and exemptions without substituting for technical enforcement tests.

15.2 What the governing body needs

The operating pack should contain the permitted business mandate; maximum autonomy by action class; system configuration and material dependencies; evidence for the critical control claims; unresolved misses and coverage gaps; customer impacts; exception owners and expiry; incident/recovery results; and the basis for the next operating decision.

Keep detection performance separate from prevention. Identify any claim that relies on an untested vendor assertion, unavailable reasoning trace, missing effect oracle, or unresolved legal applicability. A governed exception should be explicit, time-limited, attributable, and accompanied by a containment plan. It should not silently become evidence that the control works.

15.3 A reusable incident drill

Evidence table: Drill step, Required action, Proof of completion
Drill stepRequired actionProof of completion
Detect and classifyIdentify the observable effect, implicated configuration, severity, and affected workflow.Incident record and preserved source events.
Stop new authorityPause commits and revoke relevant credentials or grants.Post-revocation attempts fail on every covered route.
Contain descendantsStop child agents, jobs, queues, and continuing network paths.Delegation-tree reconciliation and effective halt times.
Establish effectsQuery independently for completed, partial, and pending actions.Resource receipts and reconciled state.
Preserve and protect evidenceApply custody/access rules and prevent agent edits to authoritative records.Integrity record and evidence-access log.
Assess duties and customer remedyDetermine applicable reporting clocks and remediation.Legal/compliance determination with jurisdiction and trigger.
Repair and restartCorrect configuration or data; replay retained failures and restoration cases.Fresh gate decision and bounded restart authorization.