The fastest way to lose an engineering organization is to fail every build on day one of a security rollout. The second fastest is to fail none of them and call the dashboard 'visibility.' Sustainable enforcement lives between those poles, and getting there is a policy-design problem, not a tooling problem.

The two dials that matter

Threshold: the minimum severity that triggers action — critical only, high and above, and so on. Mode: what the action is — fail the build, or monitor and record. Every pipeline needs an explicit setting for both, and the setting needs one authoritative home.

A rollout sequence that works

  • Start everywhere in monitor mode: build the posture baseline without blocking anyone.
  • Turn on fail-the-build for critical severity on a pilot group with engaged owners.
  • Expand scope before tightening threshold — organization-wide at critical beats one team at low.
  • Tighten to high-and-above once the finding backlog at critical is under control.
  • Keep exceptions possible but expiring, recorded, and visible.

Why the threshold must live in the backend

If teams can edit their own threshold in YAML, the rollout sequence above is fiction. Kangl evaluates thresholds centrally against normalized posture and returns an authoritative decision to the pipeline — FAIL BUILD or monitor — with the policy, the evaluation, and every change in the audit history. Teams see exactly why a build failed; they just cannot silently re-decide it.

KEEP READING