The line I keep coming back to: each control assumes the others exist, and each one fails when built alone. A registry without mTLS is an honor system, and ephemeral creds with no registry have nothing to check against. It's the same reason I push clients to put the decision outside the model: governance is a system property, not a row in a spreadsheet. The hard part isn't naming the controls, it's getting one team to own the seams between them. Who actually owns those seams in the orgs you work with?
The line I keep coming back to: each control assumes the others exist, and each one fails when built alone. A registry without mTLS is an honor system, and ephemeral creds with no registry have nothing to check against. It's the same reason I push clients to put the decision outside the model: governance is a system property, not a row in a spreadsheet. The hard part isn't naming the controls, it's getting one team to own the seams between them. Who actually owns those seams in the orgs you work with?
Orgs always want things packaged up so management can act as though they are competent.
Hi.