{"id":1947,"date":"2026-09-06T05:08:16","date_gmt":"2026-09-06T05:08:16","guid":{"rendered":"https:\/\/voicecabling.com\/?p=1947"},"modified":"2026-09-06T05:08:16","modified_gmt":"2026-09-06T05:08:16","slug":"beyond-the-silos-how-new-relic-reimagined-enterprise-governance-with-star","status":"publish","type":"post","link":"https:\/\/voicecabling.com\/?p=1947","title":{"rendered":"Beyond the Silos: How New Relic Reimagined Enterprise Governance with STAR"},"content":{"rendered":"<p>In the high-stakes world of enterprise software, trust is the primary currency. For vendors, that trust is tested daily by a complex web of regulatory requirements, security protocols, and legal frameworks. However, the traditional corporate approach to managing these mandates\u2014fragmented, siloed departments operating in isolation\u2014often creates a disjointed experience for the very customers they aim to protect. <\/p>\n<p>New Relic, the observability powerhouse, recognized that the industry-standard &quot;waterfall&quot; model of review was no longer tenable. In response, they engineered STAR (System, Tooling, and Architecture Review), a unified governance ecosystem designed to collapse the distance between internal operations and customer trust. By replacing five distinct departmental queues with a single, integrated intake system, New Relic has fundamentally shifted how security, legal, and compliance teams collaborate, proving that operational efficiency and rigorous oversight are not mutually exclusive.<\/p>\n<h2>The Anatomy of a Broken Process: Why Enterprise Governance Fails<\/h2>\n<p>Every enterprise software company has navigated the frustration of the &quot;staggered review.&quot; A product team ships a feature, only to have it stalled by a cascade of sequential approvals. Security inspects the architecture; Legal reviews the contracts; Compliance validates the certifications; IT verifies infrastructure compatibility; and Procurement audits the vendor status.<\/p>\n<p>In the traditional model, these functions operate as independent fiefdoms. Each possesses its own intake form, ticket queue, and specialized vocabulary. When these teams work in isolation, the seams become visible. A compliance requirement may conflict with a security protocol, or a legal concern might necessitate an architectural change that was already &quot;approved&quot; by IT. This creates a cycle of repetitive meetings, redundant questionnaires, and significant project delays. <\/p>\n<p>More critically, this siloed approach treats compliance as a series of boxes to check rather than a unified discipline. From the customer\u2019s perspective, a security gap or a legal oversight is a singular failure of trust. By treating these functions as separate entities, companies often deliver fragmented, inconsistent answers to customer audits, eroding confidence and stalling procurement cycles.<\/p>\n<h2>The Genesis of STAR: A Chronology of Change<\/h2>\n<p>The shift toward a unified review system at New Relic did not begin with a directive from the C-suite to reorganize the org chart; it began with a customer-centric design philosophy. <\/p>\n<h3>Phase 1: The &quot;Customer-First&quot; Realization<\/h3>\n<p>New Relic recognized that their customers\u2014engineers, SREs, and security officers\u2014operate under a heavy burden of regulatory frameworks, including HIPAA, FedRAMP, SOC 2, ISO 27001, GDPR, and CCPA. These frameworks do not view security, privacy, and legal as distinct entities; they view them as a holistic posture. New Relic realized that if they wanted to provide a seamless, authoritative answer to these customers, they had to mirror that unity internally.<\/p>\n<h3>Phase 2: Forming the SLC Review Team<\/h3>\n<p>The company moved to establish the SLC (Security, Legal, and Compliance) review team. Unlike a traditional committee that merely meets to sign off on projects, this team was empowered to act as a single, accountable entity. The objective was clear: ensure that questions from customers and regulators are addressed in concert, not in sequence. This structure, which mirrors the governance requirements of a Change Advisory Board, transformed &quot;check-the-box&quot; compliance into a collaborative, strategic partnership.<\/p>\n<h3>Phase 3: Designing the &quot;One Door&quot; Portal<\/h3>\n<p>The final piece of the puzzle was the creation of STAR. By moving from a multi-portal submission system to a single JSM (Jira Service Management) portal, New Relic eliminated the administrative friction that plagues most product launches. Whether the request involves a new third-party tool, a product feature, or a change to existing infrastructure, it enters through the same door. The system uses automated routing to pull in the necessary stakeholders, ensuring that parallel tracks begin simultaneously on a single parent record.<\/p>\n<h2>Engineering Governance: The Power of the Native Toolchain<\/h2>\n<p>One of the most radical design choices in the development of STAR was the decision to build it entirely within Jira. Many organizations default to dedicated GRC (Governance, Risk, and Compliance) platforms. While these systems offer robust reporting, they often exist in a vacuum, forcing engineers to step out of their native development environment to participate in governance.<\/p>\n<p>By embedding STAR into the existing engineering toolchain, New Relic achieved two critical outcomes:<\/p>\n<ol>\n<li><strong>Contextual Transparency:<\/strong> When a reviewer opens a STAR ticket, they see the entire history of the project\u2014the design documents, the threat models, the data flow diagrams, and the linked code repositories. There is no need to hunt through disconnected email threads or wait for a meeting to understand the technical architecture.<\/li>\n<li><strong>Cultural Integration:<\/strong> Governance is no longer a &quot;gate&quot; at the end of the development cycle. Because the review team is active within the same Jira instances as the engineers, they can provide guidance during the design phase. This shift moves governance from a reactive, punitive function to a proactive, consultative one. A comment from a security reviewer now lands in the engineer\u2019s workflow in real time, allowing for rapid iteration rather than late-stage rejection.<\/li>\n<\/ol>\n<h2>Supporting Data: Efficiency and Accuracy<\/h2>\n<p>While the primary driver of STAR was the improvement of the customer trust experience, the operational gains have been significant. By eliminating redundant intake forms, New Relic has drastically reduced the &quot;context switching&quot; that previously hampered both product managers and reviewers. <\/p>\n<p>The unified dashboard provides a single source of truth for the status of any request. When a blocker emerges, it is visible across all tracks simultaneously. This allows the SLC team to identify patterns\u2014such as recurring architectural weaknesses or common vendor risks\u2014that might otherwise go unnoticed in a siloed environment. <\/p>\n<p>Furthermore, the &quot;Tuesday meetings,&quot; where the SLC team reviews escalations, have evolved from status updates into strategic working sessions. By analyzing the data housed within the STAR system, the team can align on complex, cross-functional problems, ensuring that the guidance provided to product teams is consistent and informed by the latest regulatory shifts.<\/p>\n<h2>Official Perspective: Governance as a Strategic Asset<\/h2>\n<p>Joseph Jang, legal counsel for New Relic, emphasizes that the goal of STAR is to &quot;meet teams where they are.&quot; In his role, providing guidance on emerging technologies like generative AI requires a deep understanding of both the legal landscape and the underlying engineering architecture. <\/p>\n<p>&quot;The goal is to provide practical solutions,&quot; Jang notes. By having access to the same Jira tickets as the developers, he can offer legal and compliance guidance that is actually applicable to the specific technical architecture being built. This level of granular visibility ensures that the advice provided is not just a high-level legal theory, but a actionable roadmap for safe, compliant deployment. <\/p>\n<p>The company acknowledges that these solutions are highly environment-specific and tailored to their unique product landscape. However, the principle remains universal: governance should be a frictionless extension of the development process, not an external barrier to innovation.<\/p>\n<h2>Implications: Preparing for an Unstable Regulatory Future<\/h2>\n<p>The regulatory landscape for enterprise software is in a constant state of flux. With the implementation of the EU AI Act, the proliferation of state-level privacy laws, and the increasing complexity of FedRAMP requirements, the old model of &quot;siloed expertise&quot; is increasingly fragile. <\/p>\n<p>If a company\u2019s security team doesn&#8217;t know what the compliance team is promising, or if the legal team is unaware of how a new AI agent processes customer data, they cannot hope to survive the next generation of audits. STAR provides a blueprint for scalability. As new frameworks emerge\u2014such as those surrounding AI safety and prompt injection risks\u2014the system can accommodate new tracks without requiring a fundamental redesign of the process.<\/p>\n<h2>Conclusion: A New Standard for Trust<\/h2>\n<p>New Relic\u2019s journey with STAR is a testament to the power of designing for the customer experience first. By acknowledging that customers view security, legal, and compliance as a single, indivisible promise, the company was able to work backward to build an operating model that delivers on that promise. <\/p>\n<p>The &quot;One Intake, Five Disciplines&quot; approach is more than just a software implementation; it is a cultural shift. It acknowledges that in the modern enterprise, the wall between &quot;building&quot; and &quot;governing&quot; must be dismantled. For customers, the result is a transparent, cohesive, and professional engagement. For New Relic, it is the ability to navigate an increasingly complex world with the confidence that they are not just checking boxes, but building a foundation of enduring trust.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the high-stakes world of enterprise software, trust is the primary currency. For vendors, that trust is tested daily by a complex web of regulatory&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1946,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[615,5,560,307,4,1454,20,2014,1455,3],"class_list":["post-1947","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-network-testing-and-monitoring","tag-beyond","tag-diagnostic","tag-enterprise","tag-governance","tag-monitoring","tag-reimagined","tag-relic","tag-silos","tag-star","tag-testing"],"_links":{"self":[{"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/posts\/1947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1947"}],"version-history":[{"count":0,"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/posts\/1947\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=\/wp\/v2\/media\/1946"}],"wp:attachment":[{"href":"https:\/\/voicecabling.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/voicecabling.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}