Kullanım senaryolarıUse cases
Dördü de aynı kökten gelir: karar veriliyor, kayıt kalmıyor. All four come from the same root: decisions are made, no record remains.
Bir müşteri şikâyeti geliyor. Kayıt bulunacak, sebep anlaşılacak. Birisi üretime bağlanıyor ve bakıyor. Bu doğru bir davranıştır; iş öyle çözülür.
A customer complaint arrives. A record has to be found, a cause understood. Someone connects to production and looks. This is the right behaviour; that is how the work gets done.
Erişim izleme aracınız bu bağlantıyı görür. Gördüğü şey bir bağlantıdır. Neden bakıldığını, kimin uygun bulduğunu, ekrana hangi verinin geldiğini görmez.
Your activity monitoring tool sees that connection. What it sees is a connection. It does not see why the person looked, who found it acceptable, or which data reached the screen.
Altı ay sonra "bu müşterinin verisine kim, neden erişti" sorusu geldiğinde elinizde bir bağlantı kaydı vardır, bir karar kaydı yoktur.
Six months later, when someone asks who accessed this customer's data and why, you have a connection log but no decision record.
Kurumların çoğunda tek bir değişiklik süreci vardır. Bir kolon açıklaması da, milyonlarca satırı etkileyen bir işlem de aynı sırada bekler.
Most organisations run a single change process. A column description and an operation touching millions of rows wait in the same queue.
Sonuç iki yönlü zarardır. Küçük iş gereksiz yere yavaşlar, büyük iş ise küçük işlerin arasında hak ettiği dikkati görmez.
The damage runs both ways. Small work is slowed for no reason, and large work does not get the attention it deserves among the small items.
Ekip bunu bilir ve telafi eder. Deneyimli kişiler riskli olanı sezip yavaşlar. Bu bir kontrol değil, bir alışkanlıktır ve o kişiyle birlikte gider.
The team knows this and compensates. Experienced people sense the risky one and slow down. That is a habit, not a control, and it leaves with the person.
Denetçi bir tarih aralığı verir ve o dönemdeki değişiklikleri ister. Ekip bilet sisteminden, sürüm notlarından, log platformundan ve kişilerin hafızasından bir tablo derler.
The auditor gives a date range and asks for the changes in that period. The team assembles a table from the ticketing system, release notes, the log platform and people's memory.
Bu tablo doğrudur. Ama sonradan derlenmiştir ve derleyen kişinin yorumunu taşır. Denetçinin sorduğu asıl soru şudur: bunu siz mi hazırladınız, sistem mi üretti?
The table is accurate. But it was assembled after the fact and carries the interpretation of whoever assembled it. The auditor's real question is this: did you prepare it, or did the system produce it?
Denetime hazırlık bir dönem işi değildir. Kayıt olayla birlikte oluşuyorsa hazırlık diye bir aşama kalmaz.
Audit readiness is not a seasonal exercise. If the record forms at the moment of the event, there is no preparation stage left.
Politika metninde yazar: talebi yazan onaylamaz, onaylayan çalıştırmaz. Kurum buna inanır ve genellikle de böyle işler.
The policy says it plainly: the person who writes a request does not approve it, and the approver does not run it. The organisation believes this, and usually it does work that way.
Gece yarısı, üç kişilik bir ekipte, kritik bir olayda ne olduğunu ise kimse gösteremez. O gece kuralın uygulandığına inanılır. İnanmak ile göstermek arasındaki fark denetimde ortaya çıkar.
What happened at midnight, in a team of three, during a critical incident, nobody can show. It is believed the rule held that night. The difference between believing and showing surfaces during an audit.
Bir kural ancak sistem tarafından uygulanıyorsa kuraldır. Aksi halde iyi niyettir.
A rule is only a rule if the system enforces it. Otherwise it is good intent.