How to turn visibility into decisions, risk into product leverage, and security into a routine, without falling into the trap of beautiful yet useless dashboards.

mansplainer
João Brito

If there's one temptation that haunts us in platform and security teams, it's the urge to "see everything." Caroline Assunção, with over 14 years in the field, helps us separate illumination from spotlights: observability and security only generate value when they guide action. We provoke, she responds with methodology, and a bunch of field stories, so that the conversation leaves the chart and enters the backlog.
On one side, alerts crying out for attention; on the other, a product that needs to keep delivering. Between these poles lies the discipline of explicitly stating risk appetite, choosing metrics that matter, and creating rituals that keep security in the team's flow (and not in the queue). We talked about Kubernetes, threat modeling, Zero Trust as a philosophy, and even the role of data in decision-making.
Visibility without action becomes noise
Increasing telemetry is important, but not magical. When we measure without purpose, we create alert fatigue and a false sense of security. The antidote, as we discussed in the episode, involves:
Defining operational questions before tools (e.g., "what is our MTTR for critical fixes?");
Establishing thresholds and escalation paths that make sense for the context;
Periodically reviewing what is generating noise and what is driving fixes.
“Good visibility is the kind that moves the product needle.”
Risk appetite, ownership, and the power of the
Newsletter Getup.
Atualizações sobre Kubernetes e Software Supply Chain Security todos os meses.
Operating Kubernetes in production for more than 13 years. With Quor, this experience extends to software supply chain security as well.
GET UP
© Getup · 2026

