Consolidation, Governance & Identity Stability
The year architecture stopped being a role and became a responsibility
If 2020 was the year architecture became urgent, 2021 was the year it became strategic. My position moved into Information Risk Management, and with it came a quiet but total shift: every design now needed to be risk-aware from the first sketch, every assessment carried security implications, every architectural call had to survive a governance lens before it survived anything else.
Identity became the year's real subject. Certificate lifecycle problems, authentication escalations, privileged-account controls, single sign-on risk alignment, domain-authentication hardening. And underneath all of it, I authored the organization's identity-management Service Level Agreement: service levels, responsibilities, the support model, change-management steps, a RACI matrix that finally answered who owned what. When an architect writes an SLA, something specific has happened: the job has moved from designing systems to defining how systems get governed. That document quietly laid the foundation for identity-lifecycle work that wouldn't land for years.
I also joined formal risk-impact analysis on planning and scheduling software, assessing unauthorized-access exposure and controls. Proof, if I'd needed it, that I'd stopped evaluating technology fit alone and started evaluating organizational risk.