Most scanner rollouts stall in one of two ways: they stay a pilot forever because expansion is manual, or they go organization-wide in one announcement and drown in false-positive complaints. The successful pattern is boringly incremental — and it depends on infrastructure that makes each increment cheap.
Phase 0 — Inventory before intentions
Enumerate organizations, projects, repositories, and every build pipeline, YAML and classic. Classify eligibility. You cannot phase a rollout over an estate you have not counted.
Phases 1–4 — The expansion ladder
- Pilot: one engaged team, scanning on, monitor-only. Tune noise here.
- Coverage: expand enrollment broadly, still monitor-only. The goal is a truthful posture baseline.
- Enforcement, narrow: fail builds on critical severity for the pilot group; publish the policy and the exception path.
- Enforcement, wide: extend blocking to the estate; tighten thresholds only after the critical backlog trends down.
What makes each phase cheap
Each rung of the ladder is a state change over many pipelines: enroll these fifty, switch that group to blocking, exclude these three with reasons. With Kangl, those are bulk operations against centrally-held state — with drift detection ensuring the estate stays where you put it, and audit history recording who moved which rung when. Without that, every phase is a ticket queue.

