{"id":1655,"date":"2026-08-29T22:08:14","date_gmt":"2026-08-29T22:08:14","guid":{"rendered":"https:\/\/voicecabling.com\/?p=1655"},"modified":"2026-08-29T22:08:14","modified_gmt":"2026-08-29T22:08:14","slug":"one-intake-five-disciplines-how-new-relic-re-engineered-governance-for-the-trust-era","status":"publish","type":"post","link":"https:\/\/voicecabling.com\/?p=1655","title":{"rendered":"One Intake, Five Disciplines: How New Relic Re-Engineered Governance for the Trust Era"},"content":{"rendered":"<p>In the high-stakes world of enterprise software, a &quot;trust gap&quot; often emerges between a vendor and its customers. It begins with a simple, common scenario: a product team launches an innovative feature, but a customer\u2019s security officer flags a discrepancy during an audit. Suddenly, the vendor is scrambling. Legal teams draft hurried responses, security experts perform retrospective architecture reviews, and compliance officers scramble to map the new feature against evolving frameworks like SOC 2, HIPAA, or the EU AI Act. <\/p>\n<p>For the customer, the experience is disjointed. They receive fragmented, often contradictory answers assembled under intense time pressure. The seams of the organization are exposed.<\/p>\n<p>New Relic, a leader in observability, decided that the industry-standard approach to these workflows\u2014siloed, sequential, and reactive\u2014was no longer sustainable. Their solution is <strong>STAR (System, Tooling, and Architecture Review)<\/strong>, a unified internal ecosystem designed to treat security, legal, compliance, privacy, and IT not as a series of hurdles, but as a single, cohesive discipline.<\/p>\n<h2>The Architecture of Trust: A Chronology of Change<\/h2>\n<p>The genesis of STAR was not a desire for internal optimization, but a response to the shifting expectations of the enterprise customer. Modern regulatory landscapes are complex; customers are no longer asking if a vendor is &quot;compliant.&quot; They are asking if a vendor treats security, legal, and privacy as a unified philosophy.<\/p>\n<h3>From Silos to Systems<\/h3>\n<p>Historically, New Relic\u2014like most enterprise companies\u2014operated with departmental separation. Security owned the security queue, Legal owned the legal queue, and Compliance managed its own documentation. This &quot;waterfall&quot; approach to governance meant that if a compliance team flagged an issue late in the game, it could force a costly redesign of an architecture that security had already signed off on weeks prior.<\/p>\n<p>New Relic recognized that this model was fundamentally broken. By moving to an integrated <strong>SLC (Security, Legal, and Compliance)<\/strong> review function, the company shifted from a &quot;sign-off chain&quot; to a collaborative team. <\/p>\n<p>The transition followed a clear logic:<\/p>\n<ol>\n<li><strong>Consolidation of Intake:<\/strong> Moving from five separate forms to one &quot;front door&quot; via Jira Service Management.<\/li>\n<li><strong>Contextual Integration:<\/strong> Bringing reviewers into the same digital space where engineers work, rather than forcing engineers into disparate GRC (Governance, Risk, and Compliance) tools.<\/li>\n<li><strong>Continuous Alignment:<\/strong> Replacing &quot;status report&quot; meetings with weekly working sessions that focus on strategy and pathfinding.<\/li>\n<\/ol>\n<h2>The Design Philosophy: Why STAR Lives in Jira<\/h2>\n<p>One of the most radical aspects of the STAR initiative is its refusal to adopt a standalone GRC platform. While GRC software is standard for most firms, these tools often create a &quot;governance island&quot;\u2014a place that engineers visit only when they have to, leading to friction and delayed compliance reporting.<\/p>\n<p>New Relic chose to build STAR entirely within Jira. By embedding governance into the existing engineering toolchain, the company achieved a collapse of distance between the &quot;gatekeepers&quot; and the &quot;builders.&quot;<\/p>\n<h3>The &quot;One Door&quot; Advantage<\/h3>\n<p>Under the STAR model, every material change\u2014whether a new product feature, a third-party vendor integration, or a local software exception\u2014enters through a single portal. <\/p>\n<ul>\n<li><strong>Automated Routing:<\/strong> The system identifies the nature of the request. If it involves procurement, IT and the Vendor Management Office are tagged. If it involves architecture, the SLC review team is notified. <\/li>\n<li><strong>Total Transparency:<\/strong> For the requester, there is one ticket and one dashboard. They no longer need to manage multiple email threads or chase down updates from three different departments. <\/li>\n<li><strong>Data-Rich Reviews:<\/strong> When the SLC team reviews a request, they have immediate access to the design documents, threat models, data flow diagrams, and the roadmap epic within the same Jira record.<\/li>\n<\/ul>\n<h2>Implications: Building for a Regulatory Future<\/h2>\n<p>The shift toward a unified review system has significant implications for how New Relic interacts with its customers. By treating governance as a unified discipline internally, the company can provide faster, more transparent, and more cohesive answers to customer inquiries.<\/p>\n<h3>Meeting the AI Challenge<\/h3>\n<p>The true test of any governance system is its ability to handle volatility. As AI adoption accelerates, regulatory frameworks like the EU AI Act and evolving state privacy laws are changing the game. Traditional, siloed review functions struggle to keep pace because these new requirements don&#8217;t respect departmental boundaries.<\/p>\n<p>For example, a request involving generative AI touches upon legal (copyright and contract law), security (prompt injection and data leakage), and compliance (data privacy). Under the old model, these might have been treated as three separate, potentially conflicting reviews. Under STAR, they are viewed as a single, multidimensional problem. <\/p>\n<h3>Cultural Transformation<\/h3>\n<p>Beyond the operational efficiency, the STAR system has fundamentally altered the culture at New Relic. Because review teams are now embedded in the engineering workflow, they are present at the beginning of the design phase. They move from being &quot;blockers&quot; who approve or reject at the finish line to &quot;consultants&quot; who help shape the architecture to be compliant by design. This early intervention significantly reduces the cost of course correction and fosters a culture of shared accountability.<\/p>\n<h2>Official Perspectives on the New Model<\/h2>\n<p>Joseph Jang, legal counsel at New Relic, emphasizes that the goal of this system is to meet teams where they are. By focusing on the engineering architecture and the specific product capabilities, the legal and compliance functions become proactive partners in innovation rather than just auditors of it.<\/p>\n<p>&quot;The SLC review team sees it together in the same Jira record,&quot; notes the internal team. &quot;When a question in the compliance lane has implications for the security assessment, the two reviewers are in the same conversation. This isn&#8217;t just about efficiency; it&#8217;s about building a foundation of trust that can scale as fast as the technology does.&quot;<\/p>\n<h2>Supporting Data and The Customer Experience<\/h2>\n<p>The customer-facing benefits of this internal re-engineering are measurable. When a customer&#8217;s security officer asks a complex question about data handling or architectural integrity, New Relic&#8217;s Customer Trust team does not have to hunt for answers across five different departments. They leverage the collective STAR data to provide a comprehensive, unified response.<\/p>\n<p>The effectiveness of this model is being validated by the increasing complexity of customer security questionnaires. As these questionnaires grow in length and specificity, the ability to synthesize information across security, legal, and compliance becomes a competitive advantage. <\/p>\n<h2>Conclusion: A Blueprint for Enterprise Governance<\/h2>\n<p>The STAR system serves as a case study for companies looking to bridge the gap between agility and governance. By rejecting the &quot;waterfall&quot; review process and embracing a &quot;one intake, five disciplines&quot; model, New Relic has demonstrated that governance does not have to be a drag on innovation.<\/p>\n<p>As the industry moves toward a future where AI and cloud-native infrastructure require constant, real-time compliance, the &quot;siloed&quot; model of the past is effectively obsolete. New Relic\u2019s approach suggests that the companies that win in the next decade will be those that view trust, security, and compliance not as secondary functions, but as core components of their engineering DNA.<\/p>\n<p>For New Relic, the journey of STAR is just beginning. As the remaining chapters of their series on this topic suggest, the framework is robust enough to handle everything from vendor procurement to the ethical complexities of artificial intelligence. One intake, five disciplines\u2014it is a simple, yet powerful, starting point for any organization striving for true, customer-centric trust.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the high-stakes world of enterprise software, a &quot;trust gap&quot; often emerges between a vendor and its customers. It begins with a simple, common scenario:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1654,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[5,1790,1791,1789,307,1788,4,20,3,675],"class_list":["post-1655","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-testing-and-monitoring","tag-diagnostic","tag-disciplines","tag-engineered","tag-five","tag-governance","tag-intake","tag-monitoring","tag-relic","tag-testing","tag-trust"],"_links":{"self":[{"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/posts\/1655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1655"}],"version-history":[{"count":0,"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/posts\/1655\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/media\/1654"}],"wp:attachment":[{"href":"https:\/\/voicecabling.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}