A rule survives being wrong for a long time, because nobody has to convince anyone to delete it — they just have to convince one person to make an exception this once.

That’s the cheaper move. Repealing a rule means arguing, in the abstract, that the incident it was written for either can’t happen again or wasn’t worth this much prevention. That argument has to win in a room, on the record, against a downside that would land on whoever made the case. Getting an exception means finding the one person with the authority to say “fine, for this case” and asking quietly. No debate, no record most people will ever see, no one on the hook for the general principle — just a specific yes for a specific ask. So the rule stays on the books at full strength, and the actual behavior of the organization routes around it, case by case, waiver by waiver.

This works fine right up until the waivers stop being the exception and start being the norm. The deploy freeze holds for teams that don’t know who to ask. The second-approver rule binds everyone except the three people who’ve learned that pinging the platform lead on a specific channel gets it lifted in ten minutes. The rule, as written, describes what happens to people without the relationship. The waiver process describes what happens to everyone else. And the second one is the real policy — it’s just not the one anybody could show you if you asked what the policy is.

The person granting the waivers becomes the actual decision-maker for the thing the rule was supposed to govern, without ever having written a policy, been asked to own one, or being visible in an org chart as the person who decides. They didn’t choose this. They just answered the same private message often enough that saying yes became their job. Nobody scoped it, nobody’s tracking it, and when they’re out sick or move teams, the organization discovers all at once that a whole category of work has no path forward — because the actual approval mechanism was a person, not a process, and the written rule it was quietly replacing was never designed to be usable on its own.

This is worse than a bad rule, because a bad rule is at least visible enough to argue with. A shadow approver is invisible until they’re a bottleneck or a single point of failure, and by then the informal system has been running long enough that formalizing it feels like more disruption than leaving it alone. The fix costs nothing at the moment it’s needed and everything once it’s overdue.

The cheap intervention is the same one that works for undocumented rules: write down what’s actually happening while it’s still small. Not a new rule — a log. Every time someone grants an exception, one line: who asked, what the rule would have blocked, why this case was different. That line does two things a policy document can’t. It shows you, after twenty entries, whether the rule is being waived for one genuinely recurring reason — in which case the rule is wrong and should change — or for twenty unrelated reasons, in which case the rule is probably fine and the process for asking is what’s broken. And it means the waiver path has an owner other than one person’s memory, so when that person leaves, the org loses a record instead of losing the entire mechanism.

The test isn’t whether your rules have exceptions — every rule that survives contact with reality does. It’s whether you can produce the list of exceptions granted this quarter without asking one specific person to remember. If you can’t, the rule in the handbook isn’t your policy. The unwritten judgment of whoever answers that private message is, and you don’t actually know what it says.