Cloud Sentry
Compliance

Teams are shrinking. Separation of duties is holding still.

Compliance assumes enough people to keep the maker and the checker apart. AI is compressing headcount while that assumption stays exactly where it was, and small companies are the ones caught in the middle.

Every compliance framework in use today was written for a company with enough people to keep the person doing the work apart from the person checking it. That assumption is quietly becoming the hardest one to satisfy.

Teams are getting smaller. A company that would have hired thirty people two years ago now runs on eight and a stack of AI tooling, and it is winning on speed. The frameworks it will be measured against have held exactly still.

So the interesting question stops being how a small team gets compliant and becomes how a shrinking team keeps its checks and balances meaningful.

Two hats is a fact of small companies

In a fifteen-person company the person who provisions accounts is often the person who approves provisioning. The person who ships the change reviews the change. The person who owns the risk register is the person who decides what goes on it.

Auditors see this constantly and it is survivable. Somebody wearing two hats is a design constraint to be handled. A process around those two hats is what keeps it survivable. Where that process is missing, the one person who holds both hats can step over the control at will and the record stays silent.

The control that matters, then, has less to do with headcount than with whether a rule holds when the person it constrains is the same person who could remove it.

Where a third party fits

This is the structural reason an operator helps, beyond the labour. When we run the environment, the approval step sits with somebody who has no stake in the request going through.

  • Changes to a tenant run through change control, so the record exists whether or not anyone remembers to write it down.
  • Our own access is granted just in time and expires, so the standing administrative account that defeats every access review stops existing.
  • Approvals route to a named role on your side, and a request reaches somebody who is at their desk.
  • Our own actions in your accounts are logged in your accounts, so the checker is auditable too.

The effect is that a two-person company can satisfy a control that reads as though it needs six people, because the separation is real. It lives across an organisational boundary, which is where the room is.

What this gets harder at, and where it holds

The honest scope limit: this addresses separation and evidence. Its reach stops at a control that genuinely requires a specialist you have yet to hire, and at a founder who wants the process removed. Both of those are decisions, and we will tell you which one you are making.

What it does hold up for is the long middle: the weekly, monthly and quarterly work that carries most of a framework, executed on a date, with a record, by somebody whose job it is.

The direction this is heading

Trust used to be extended to a team and verified occasionally. As teams compress and more of the work is done by tooling that runs unattended, verification becomes the whole of it. That shift arrives faster for a company of ten than for a company of ten thousand, because the small company has fewer people to absorb it.

If your headcount is falling while your obligations are climbing, which of your controls still works when the one person who could bypass it is the one being asked to follow it?

See the access and lifecycle workflow

Book a Discovery Call

More in Compliance

Compliance

Evidence your auditor can pull on their own

When the policy library is current and the activity log is filterable, the auditor stops asking you for proof and starts retrieving it.

Read more
Compliance

HIPAA for Growing Healthcare Companies: Where the Real Risk Lives

HIPAA at 10 people looks nothing like HIPAA at 10,000. The real risks for small and mid-market healthcare are specific and practical, and most companies find them the hard way.

Read more
Compliance

Making the buyer security review painless

When a buyer's security review lands, the proof is either already sitting there or it is not; here is how to make it a self-serve pull, not a fire drill.

Read more

Runs on the platform

This is the work behind the writing.

These posts come out of environments we operate every day. Cloud Sentry runs your security, compliance, and IT on one platform, with a human one click away and the proof on demand. See what your team would get.