Summary of the Key Points
The core argument of this article is that companies often regard approval processes, permission management, and post-event audits as "safety barriers," but these are merely remedial measures (and thus costly) after a disaster has occurred. The true barrier should be able to prevent risks before they are executed, rather than simply holding someone accountable afterward. By analyzing the reasons why these barriers are often ignored, the difference between approval processes and actual safety barriers, and the urgency of having effective barriers in the age of AI, the article emphasizes that mature companies need to establish "independent controls before execution" to ensure that even if all procedures are followed, irreversible mistakes can still be prevented at the last moment.
Detailed Interpretation
1. Why do we often perceive barriers as a waste? – Because their value lies in preventing disasters that never happen
Barriers are most effective when they are least noticeable. For example, no one thinks a fire door is useful unless a fire breaks out; no one praises a circuit breaker for not tripping. The same applies to corporate safety measures: the extra confirmation steps that slow down processes or the stricter permission controls that inconvenience employees are easily visible every day. However, the mistakes they prevent—such as misdirecting large sums of money or deleting important data—are not recognized because they never happen. As a result, companies often weaken these barriers for the sake of efficiency: eliminating confirmation steps, expanding permission scopes, or creating "fast-track" options for administrators. Each of these actions seems reasonable on its own, but they ultimately concentrate risk on the "one-click execution" buttons. Only when a disaster occurs do people ask, "Why wasn't anyone stopped?"
2. More approvals do not equal having effective barriers – Processes manage how things are done; barriers manage situations where things cannot be done
Many companies mistake multiple rounds of approval for a form of security, but processes and barriers serve different purposes. Processes determine who should approve something, while barriers ensure that certain actions cannot be carried out, even with everyone's consent. For instance, in a payment process, if the initiator, supervisor, and finance department all approve, it doesn't matter if the receiving account is later replaced by a scammer’s account or if the system misclassifies the transaction as legitimate; the previous approvals become meaningless. The problem lies not in who is responsible but in the discrepancy between the "approved plan" and the actual actions taken by the system.
3. In the age of AI, barriers are the ultimate brakes – AI can directly change reality, making mistakes a real issue
In the past, software provided suggestions (e.g., "It’s time to transfer the funds"), but humans made the final decisions. Now, AI agents can directly perform actions—changing code, transferring money, or deleting data, turning potential errors into actual losses. For example, if AI misinterprets a customer's request and transfers millions to an unknown party, it can happen in seconds without anyone having time to react. While many focus on making AI more intelligent, even smart AI can make mistakes (e.g., due to corrupted data). True security does not mean that AI is always correct; it means that there are mechanisms in place to stop it when it does. For instance, if AI is about to transfer a large amount of money, an independent barrier system would check: "Is the recipient a predefined supplier? Has the amount exceeded the limit?" If the checks fail, the transaction cannot proceed.
4. Barriers are not about doubting people; they are about preventing failures – Even good people can make mistakes, and systems can malfunction
Some argue that restricting administrators’ permissions shows a lack of trust in employees, but barriers are designed to guard against potential failures, not personal integrity. Good people might still make mistakes (e.g., clicking the wrong button or allowing a hacker to manipulate processes). For example, a super administrator responsible for system maintenance should not be allowed to delete production data directly; another person must confirm the action. The logic of barriers is to prevent the mistake of any single individual or system from causing a disaster.
5. The real purpose of barriers: to give you a chance to regret – Not to stop actions, but to slow them down for confirmation
Barriers are not walls; they act as buffers. They slow down high-risk operations, asking questions like "Are you sure? Will the service be interrupted if you delete this data?" or requiring additional verification for ambiguous requests (e.g., before sending sensitive information to an unknown customer). The faster automation becomes, the more crucial these barriers are. Machines will not slow down just because the consequences are severe; they will execute as long as the conditions are met. The value of barriers is to give organizations a chance to change their course before irreversible damage is done—not to prevent actions altogether, but to encourage careful consideration.
Final Reminder
Companies used to focus on connecting everything for efficiency, but now they need to consider where mistakes can be prevented. True safety lies in independent controls before execution, not in post-event logs or audits. If all procedures are followed and no one can say "No" at the last moment, what you have is just a series of processes, not real security. The cost savings from streamlining processes may eventually turn into the price of a disaster. The ultimate question for companies should be: "When all the signals are green and the mistake still seems possible, who can stop it?" Without an answer to that question, there are no true barriers in place.