Skip to content
framework

Scaled agile and governance, without slowing delivery

Governance slows delivery when it is expressed as approval, because an approval is a queue with a fixed service rate. Expressed as structure, the same controls that satisfy an auditor are the ones that let a portfolio roll up without a spreadsheet.

The usual argument treats governance and delivery speed as a trade. Add controls and delivery slows; remove them and risk rises. Teams then negotiate a point on that line, and both sides leave unhappy.

The trade is real only when governance is expressed as approval. When it is expressed as structure, the relationship inverts: the same controls that satisfy an auditor are the ones that let a portfolio roll up without a spreadsheet. This piece is about how to build the second kind.

Why approval-shaped governance slows things down

An approval is a queue. Queues have a service rate, and the service rate of a human approver is roughly constant regardless of how much delivery you put in front of it. Scale the delivery, and the queue lengthens.

Teams respond predictably. They batch changes to reduce the number of approvals, which makes each change larger and riskier. They route around the process for anything urgent, which means the record stops matching what happened. Or they get the approval delegated so widely that it stops being a control at all.

Only 16 percent of security leaders say they govern access to their core platforms effectively, and the rest are managing it by exception (2026 CISO AI Risk Report, 235 large-enterprise leaders). Management by exception is the end state of approval-shaped governance meeting real delivery volume.

What structural governance looks like instead

Structural governance answers the same questions without a person in the loop for the common case. Four mechanisms carry most of it.

Permission architecture. Who can do what is a property of a scheme mapped to directory groups, not a list of individuals maintained by hand. The control is that the wrong person cannot make the change, so nobody has to check whether they did.

Workflow gates. The states a work item must pass through, and the conditions on those transitions, encode the policy. A change that has not met its condition cannot reach the state that means done.

Evidence as a by-product. If the gate is in the workflow, passing it produces a record automatically. The audit artifact is the ordinary trail of work rather than a document assembled at quarter end.

Hierarchy that reflects reality. Work items roll up to the thing that funds them. When that structure is right, portfolio reporting is a query rather than a reconciliation.

The hierarchy is the part most teams get wrong

Scaled agile frameworks describe a hierarchy, and organizations usually implement it as a naming convention. Epics get named after initiatives, initiatives live in a slide deck, and the connection between them is maintained by whoever is preparing the quarterly review.

The result is a roll-up that is accurate on the day it is produced and stale immediately. Worse, it is expensive, because someone rebuilds it every cycle, and the cost is invisible because it sits in the calendar of people who were going to be busy anyway.

The fix is to make the hierarchy a property of the data. Every work item has a parent that exists as an object, and the parent is what the budget is attached to. Then a portfolio view is generated rather than assembled, and it is as current as the work.

This is less disruptive than it sounds, because most of the structure already exists informally. Teams know which initiative their work belongs to; they just express it in a label, a component, or a naming convention rather than in a link. Converting those conventions into real parents is a data exercise measured in weeks, and it is the single change that most reduces the cost of every reporting cycle afterwards.

Governance for a portfolio that includes agents

The pressure is new and it is not going away. Rovo passed five million monthly active users (Atlassian Q2 FY26 shareholder letter), and the connective tissue between tools has standardized, with the Model Context Protocol passing 97 million monthly SDK downloads before being donated to the Linux Foundation in December 2025 (Anthropic and the Linux Foundation, December 2025).

An agent inside a delivery portfolio raises exactly the governance questions a contractor raises, faster. Who authorized it, what can it touch, what did it do, and how does its output enter the same record as everyone else's.

Only 23 percent of organizations report having an identity strategy that covers agents at all (Cloud Security Alliance and Strata, 2026). The structural answer is the same as for people: the agent has an identity, that identity is in groups, those groups map to permission schemes, and its work passes the same gates. Nothing about the framework changes. The population it governs does.

Reporting that a finance team will accept

The test of a portfolio model is not whether delivery teams like it. It is whether the people allocating budget will use its numbers without asking for a reconciliation.

That requires three things to be true at once. The hierarchy has to be complete, so nothing significant sits outside it. The states have to mean the same thing across teams, so that in progress is not a local dialect. And the data has to be current by construction rather than by effort.

Where those hold, the reporting layer stops being a monthly project. Where they do not, no reporting tool will fix it, and buying one usually adds a second version of the truth for people to argue about.

The second condition is the one teams underestimate. Standardizing what a state means is a political exercise, not a technical one, because every team's definition encodes something they care about. It is worth doing anyway, and it is worth doing narrowly: agree the meaning of three states across the portfolio rather than fifteen states within each team. Three shared states produce a usable roll-up. Fifteen local ones produce a translation layer, and translation layers are where roll-ups go to become inaccurate.

Sequencing without stopping delivery

The objection to all of this is that it sounds like a re-platforming exercise, and delivery cannot pause for one. It does not have to.

Start with permission architecture, because it is invisible to delivery teams and it is what everything else rests on. Then standardize states for one value stream rather than all of them, and let the roll-up prove itself on that slice before it is imposed anywhere else. Then attach the hierarchy, which is mostly a data exercise once the states agree.

Nine in ten organizations had a successful identity-related breach in the last twelve months (Palo Alto Networks, 2026 Identity Security Landscape, 2,930 respondents), which is the reason the permission work cannot wait for the reporting work. It is also the reason to do them in this order rather than the reverse: the security case funds the foundation, and the portfolio case is what the foundation makes possible.

The thing to hold onto

Governance slows delivery when it is a person checking. It accelerates delivery when it is a structure that makes the wrong thing hard and the right thing automatic, because the evidence stops being work.

Every control on this list has a delivery benefit and an audit benefit, and they are the same benefit seen from two directions. That is the test to apply to any governance proposal: if it only helps the auditor, it will be routed around within two quarters.

Questions we get

Does structural governance mean no approvals at all?
No. It means approvals are reserved for the cases that genuinely need judgement, and the common case is handled by permission architecture and workflow gates, so the queue never becomes the bottleneck.
Where do most teams get the hierarchy wrong?
They implement it as a naming convention rather than as data. Epics named after initiatives that only exist in a slide deck produce a roll-up that is accurate on the day it is built and stale immediately.
Can this be done without pausing delivery?
Yes, and it should be. Start with permission architecture, which is invisible to delivery teams, then standardize states for one value stream and let the roll-up prove itself there before it goes anywhere else.

Get an agent readiness assessment

Fixed scope. You get a findings report across identity, platform, and governance, an ownership gap analysis, and a sequenced plan for closing it.