Your Approval Chain Is Guarding a Grave

Corporate Archaeology

Your Approval Chain Is Guarding a Grave

How we spend $10,000 in productivity to prevent a $200 mistake that hasn’t happened in a decade.

August V. is a food stylist who understands the precise architecture of a lie. He spends his Tuesday mornings in a windowless studio in Long Island City, using a jeweler’s syringe to inject mashed potatoes into the cavity of a raw turkey. He then paints the skin with a mixture of dish soap and industrial browning sauce to give it that “just-out-of-the-oven” glow that real heat can never actually achieve. I watched him do this for three hours once, mesmerized by the sheer labor required to make something look natural.

He told me, while dabbing a bead of condensation onto a soda can with a toothpick, that he once spent an entire workday-ten billable hours-ensuring that a bowl of cereal didn’t look “soggy” in the background of a shot where the cereal wasn’t even the product being sold. He did this because, in , a client had a meltdown over a stray flake of bran that had wilted under the studio lights.

That client’s company folded during the Great Recession. The brand manager who threw the fit probably doesn’t even eat cereal anymore. But August’s workflow still includes a dedicated “soggy-flake prevention protocol” that costs the agency three grand per shoot. He is guarding against a ghost. He is following a rule written by a man who no longer exists, to solve a problem that hasn’t happened in fifteen years.

The Archaeology of IT

We do this in IT every single day. We call it “governance,” but it is actually archaeology.

I recently sat through the birth of a purchase order for 50 Microsoft Remote Desktop Services licenses. The price was fixed. The vendor was known. The need was urgent-a new wing of a call center was going live, and without those licenses, fifty people would be sitting at desks staring at expensive, inert glass.

The total cost was somewhere in the neighborhood of a few thousand dollars. In the grand scheme of a ninety-million-dollar annual budget, it was a rounding error. It was the equivalent of buying a pack of gum at the checkout counter of a grocery store.

Yet, this purchase had to travel through five distinct human checkpoints.

License Cost

$3,000

Wasted Wages

$10,000+

We were so afraid of a $200 mistake that we spent $10,000 in productivity to prevent it.

The First Scar: Sarah Step

First, there was the requester-me. I knew exactly what was needed because I’d spent the morning using a CAL calculator to ensure we weren’t over-provisioning. Then it went to my team lead, Sarah. Sarah knows I’m competent, but she has to click “approve” because, in , a junior admin accidentally ordered 500 licenses instead of 50.

Sarah wasn’t even at the company then, and neither was the admin. But the “Sarah Step” remains, a permanent scar on the workflow left by a long-gone mistake.

The Second Layer: Shadow Governance

From Sarah, it went to IT Governance. This is a department that exists to ensure “alignment.” They held the request for forty-eight hours. They weren’t checking the price; they were checking if the software was on the “Approved Standard List.”

Microsoft Windows Server licenses are, by definition, the standard for a Windows shop, but the Governance team has to verify this every single time because of the “Shadow IT Crisis of ,” when a marketing intern bought a subscription to a cloud-based project management tool that didn’t have SSO.

“Every signature in the chain is a shovel used to bury a mistake that died a decade ago.”

The Finance and Director Wall

Then came Finance. Finance doesn’t know what an RDS CAL is. To them, it is a string of alphanumeric characters associated with a cost center. They held the request because they needed to verify that the “Software” line item hadn’t been exceeded for Q3. They do this because of a tax audit that happened in a business unit that was sold off to a private equity firm in .

Finally, it reached the Director. The Director is a busy woman. She manages a hundred people and a budget that could buy a small island. She had to take three minutes out of her day to look at a $3,000 request for server licenses.

She has no context for the purchase, but she has to sign it because the “Signatory Authority Policy” dictates that anything over $2,500 requires a Director’s digital ink. This policy was enacted in after an executive’s assistant was found to be embezzling money through a series of small, unmonitored office supply orders.

By the time the final “Approve” button was clicked, had passed. Fifty call center employees had spent those six days playing Solitaire on their phones. The cost of their wasted wages was triple the cost of the licenses themselves.

The irony is that the actual transaction is the fastest part of the entire ordeal. If you go to a specialist like the RDS CAL Store, you get the license keys in about . The technology has evolved to be instantaneous.

The vendor has optimized for a world where speed is a competitive advantage. They offer PayPal protection and money-back guarantees to mitigate the “risk” that our five-step approval chain is supposedly guarding against.

We add friction reactively, but we never remove it. It is the one-way valve of corporate bureaucracy. Every time there is a “flare-up”-a botched audit, a rogue purchase, a misconfigured server-we add a new signature to the chain. We call it “strengthening the process.”

But we never go back and ask if the strength is still required. We never ask if the “Assistant Embezzlement Incident of ” is still a relevant threat in a world of automated spend management and real-time ledger tracking.

It’s like my ex’s Instagram photo. I was scrolling late last night, a glass of wine too deep into my own head, and I accidentally liked a picture of her from ago. It was a photo of a beach in Maine. I wasn’t even there. I was just looking at the past, trying to understand where the friction started. That “like” was a ghost of a dead relationship, a momentary interaction with a reality that no longer exists.

That is what your approval chain is doing. It is an accidental “like” on a decade-old mistake.

The Red Flag for Your Ferrari

In the late , the British Parliament passed the Locomotive Act, better known as the Red Flag Act. It was a response to the “terrifying” new technology of the automobile. The law dictated that any self-propelled vehicle had to be preceded by a man walking at least sixty yards ahead, waving a red flag to warn pedestrians and horse-drawn carriages.

The Locomotive Act of 1865

Legally required internal combustion engines to move slower than a brisk walk for .

It effectively capped the speed of every car in the British Empire at four miles per hour. The law stayed on the books for . For three decades, the most advanced internal combustion engines on the planet were legally required to move slower than a brisk walk because the government was afraid of a “mistake” (a horse being spooked) that the technology was already quickly making irrelevant.

We laugh at the Red Flag Act, but we are currently doing the exact same thing to our IT infrastructure. We hire brilliant architects and sysadmins. We pay them six-figure salaries to design high-availability clusters and secure remote-access environments. Then we force them to wait six days for a Director to sign off on a pack of 20 User CALs.

The danger of this “archaeology of fear” isn’t just the delay; it’s the dilution of responsibility. When five people sign off on a purchase, nobody actually feels responsible for it. The requester assumes the Lead checked it. The Lead assumes Governance checked it. Governance assumes Finance checked it. Finance assumes the Director wouldn’t sign it if it wasn’t right.

The Responsibility Loop

  • × “The Lead checked the technical specs.”

  • × “Governance verified the vendor standards.”

  • × “Finance checked the budget line.”

  • RESULT: It is a chain made of tissue paper, designed to look like iron.

If we actually cared about preventing mistakes, we wouldn’t add signatures; we would add data. We would use the built-in CAL calculators and the pre-sales guidance offered by specialists to ensure the order is right the first time.

We would trust the 60-day money-back guarantees and the buyer protections that are already built into the modern procurement landscape. We would realize that a “perpetual” license means the risk of “buying the wrong thing” is a one-time, reversible event, not a catastrophic failure.

But we don’t. We keep the signatures. We keep the “Sarah Step.” We keep the “Governance Check.” We are terrified of the “Soggy Flake.” We are terrified that if we don’t have five people looking at every license purchase, the whole enterprise will crumble. We ignore the fact that the enterprise is already crumbling under the weight of its own hesitation.

The next time you’re waiting for that fourth signature to appear in your inbox, ask yourself: Who are we protecting? Are we protecting the budget? Or are we just honoring the memory of a guy named Gary who accidentally bought the wrong version of SQL Server in ?

“If the answer is Gary, it might be time to put down the red flag and let the car actually drive. The keys are already waiting for you.”

The keys have been ready for . The only thing standing in the way of your infrastructure’s future is your organization’s obsession with its own past mistakes.

Stop shellacking the turkey. Stop guarding the patch of grass where a flower once grew. Just buy the licenses and get back to work. The ghosts don’t need your signatures, and neither does your server.

!

Stop guarding graves. Focus on the flow of the future, not the ghosts of mistakes past.

Related Posts