Assurance · Workforce Capacity · Soft Exhaust
Green by Heroics: The Safety Margin Your Dashboard Can't See
A control can report green while people silently subsidise it. Measure the obligation-to-capacity ratio — and treat amber as a resource contract, not a performance verdict.
The short version
- Green by Heroics is status sustained by silent overtime, tacit knowledge, compressed reviews and a few load-bearing specialists — not by a designed operating model with enough capacity.
- Human Reserve Margin is the sustainable capacity left after expected work, normal variation and incident contingency. The lights can stay on while reserve approaches zero.
- Instrument the obligation-to-capacity ratio. When it crosses amber, unlock people, facilitation, redesign or authority change — do not demand amber-level scrutiny on green-level resources.
There is a pattern I keep seeing in regulated environments. A control family is green. Patches are closed. Reviews are signed. Service levels are met. The board pack is clean. And the people who produce that green are working longer hours, carrying more systems, compressing every review, and not turning up to the meetings that used to make the assurance real.
Nobody is lying on the dashboard. The obligation was met. What the dashboard cannot say is the more important sentence: the designed operating model still has sufficient capacity.
Those are not the same claim. They only share a colour.
The wrong response to the soft signal underneath — after-hours coordination, shortened review notes, the same two specialists on every critical thread — is staff surveillance: measure the people harder. That is the anti-human read of AI and operational telemetry. The pro-human read is simpler, and harder to staff for:
The exhaust shows that the organisation's declared level of assurance is being sustained by hidden human effort. The process needs more capacity, assistance or redesign — not a closer performance score.
I call the failure mode Green by Heroics. I call the missing instrument Human Reserve Margin. Together they force a companion rule onto the Workforce AI Compact: when obligation intensity rises, capacity must be reviewed — whether the intensity came from AI throughput or from a threat and regulatory cycle that simply will not wait.1
The pressure pattern: obligation up, headcount flat
Start with Australian banking infrastructure as a sector-level shape, not a named-bank indictment. Public reporting already describes the squeeze. Attack paths that begin with exploitation of public-facing applications rose sharply year-on-year in IBM's 2026 X-Force work, with financial services among the most targeted industries and continuous vulnerability hunting and patch governance recommended over purely periodic security review.2
Then frontier models changed the defender's clock. ASD has reported that advanced models can chain multi-step simulated corporate intrusions and sharply accelerate vulnerability discovery. Its advice is not only "patch faster." It is that the response cannot be left to cyber defenders alone — process and organisational change are required.3 ASIC called for an urgent cyber uplift across financial services as AI accelerates threats.4 APRA has said governance, assurance, information-security and operational-resilience practices are not keeping pace, and that frontier models require a step-change in cyber practice.5
On 22 June 2026, Five Eyes cyber agencies put a calendar under the rhetoric: the timeline for transformation is "not years, it is months," and leaders should empower cyber leaders with authority and resources.6 That second word is load-bearing. Authority without resources is a speech. Resources without authority is a budget line that cannot change the work.
Meanwhile the maturity models tighten the window. ASD's Essential Eight expects critical or actively exploited vulnerabilities on exposed systems to be patched or mitigated within forty-eight hours, with scanning cadence measured in days and weeks rather than quarters.7 ASD's 2024–25 threat report recorded financial and insurance services among the most frequently reporting non-government sectors, with incident response and malicious-activity notifications rising sharply year-on-year.8
Put the sequence in one line:
Attack velocity rises. Vulnerability discovery accelerates. Regulatory expectation rises. Patching windows contract. Headcount assumptions stay where they were when the threat was slower.
That is the pattern I have watched play out in banking IT and support teams: more tests, more patches, cycle times compressed from months toward weeks or days — without a corresponding increase in people. Everyone works more hours. Shifts stretch. Behaviour changes. Disagreement and quiet panic rise in the operational channels. And the formal status stays green, because the obligation is still being met by people spending themselves as reserve.
Public sources will not give you a neat table of overtime at any particular Australian bank. That local operational detail is ordinarily invisible. That invisibility is the argument. The global workforce picture is at least consistent with the shape: ISC2's 2025 study found large shares of organisations without budget for adequate cyber staffing, respondents overworked or exhausted by threat pace, and process oversights attributed to skills shortages.9 Attack intensity and constrained capacity can coexist for a long time before the dashboard admits it.
Green by Heroics
Green by Heroics is when a process, control or service reports green because employees are silently contributing unsustainable additional labour, attention and personal resilience.
The formal report records what institutions know how to count:
- patches completed
- incidents closed
- service levels met
- controls performed
- milestones achieved
- reviews signed off
The soft layer — the emails, threads, meeting notes, handover friction and review artefacts that BI for Soft Data treats as organisational source code — can reveal something else entirely:10
- nights and weekends becoming normal
- more people pulled into each issue
- repeated emergency coordination
- review notes getting shorter
- unresolved questions carried forward
- temporary workarounds accumulating
- fatigue and competing-priorities language rising
- experienced staff covering several roles
- approvals arriving at the end of shifts or just before deadlines
- fewer independent reviewers
- growing reliance on one or two load-bearing specialists
- staff saying "we got it done" rather than "the control is working"
The dashboard sees compliance. The soft layer sees the human subsidy underneath compliance.
This is adjacent to — not a rehash of — the green-formation work in Elastic Assurance. One of those formation modes is compensated green: status produced by people filling gaps the design did not fund.11 Green by Heroics is that mode made operational for capacity leaders. It is also what the Institutional Failure Radar is designed to sense without scoring people — behavioural telemetry around a control, not a performance ranking of the humans holding it up.12
Designed green vs compensated green
Before you instrument anything, lock the distinction. Two greens can look identical on a status board and mean opposite things about the operating model.
| Dimension | Designed green | Compensated green (Green by Heroics) |
|---|---|---|
| What the light means | The operating model has capacity for this obligation under expected variation. | The obligation was met this cycle by discretionary human effort. |
| How work finishes | Within designed hours, roles and review depth. | After-hours, multi-role coverage, shortened or deferred review. |
| Where knowledge lives | In procedures, backups and cross-trained capacity. | In a few load-bearing specialists and tacit workarounds. |
| What independent review looks like | Present, argumentative, evidenced. | Boilerplate, late, missing, or the same people checking themselves. |
| What happens next week | Repeatable without consuming reserve. | Repeatable only if the same people keep spending themselves. |
| Correct management move | Maintain and improve the design. | Resource, redesign, or reduce obligation — do not celebrate the KPI. |
If your governance system cannot tell these apart, it will keep rewarding the people who are quietly becoming the institution's unreported safety margin — until they leave, get sick, or make the first mistake that exhaustion was always going to buy.
Human Reserve Margin
For critical-infrastructure operators, the cleanest metaphor is already trusted on the engineering side of the house.
Human Reserve Margin is the sustainable capacity remaining after a team has delivered its expected workload, maintained quality, handled normal variation, and preserved enough contingency for an incident.
A power system can supply every megawatt of current demand and still be unsafe if it has no reserve for the next contingency. The lights are on. That does not mean the system has adequate margin. Human capacity works the same way. A team can meet every KPI while its reserve approaches zero.
| Reported state | Human reserve state | Actual condition |
|---|---|---|
| Green | Healthy reserve | Genuinely green |
| Green | Falling reserve | Green, trending amber |
| Green | Overtime and deferred work | Green by Heroics |
| Green | No backup expertise or recovery time | Structurally red, operationally concealed |
| Amber | Additional resources deployed | Managed amber |
| Amber | Same resources, more scrutiny | Exhaustion spiral |
The last row is the managerial failure mode that looks like governance: status goes amber, so leadership adds reporting, reviews and oversight — without adding people, time or authority. That is how you get amber-level scrutiny on green-level resources. It guarantees hidden work and shallow assurance.
What to sense: obligation-to-capacity, not "who is slow"
The system should not ask who is working too slowly. It should ask:
Where has the obligation-to-capacity ratio changed without a corresponding change in resources?
Signals fall into four families. None of them is a person score. Together they support a capacity hypothesis at team or function level — privacy-preserving, aggregated, aimed at the control environment.
Work expansion
- higher frequency of security, safety or assurance requests
- shorter required completion windows
- more systems and assets in scope
- increased testing depth
- more regulatory or executive reporting
- increased third-party coordination
Effort expansion
- activity moving outside normal hours
- growing meeting and messaging volume around routine controls
- more handoffs and escalations
- repeated calls for assistance
- the same specialists appearing across unrelated incidents
- increasing interruption of planned work
Quality compression
- shorter review comments
- repeated boilerplate approvals
- fewer counterarguments
- declining evidence depth
- deferred remediation
- temporary exceptions renewed rather than closed
- formal reports getting cleaner while operational conversation gets more anxious
Human-capacity deterioration
- sustained overtime at team level
- leave cancelled or deferred
- vacancies unfilled
- increased contractor dependence
- key-person concentration
- training and preventative work displaced by urgent work
Hard boundary. These signals produce a hypothesis about the control and the operating model. They must not produce a ranking of individuals, a loyalty score, or a covert performance case. The moment capacity sensing becomes personal surveillance, you have abandoned the pro-human purpose and invited the Extraction Reflex in through a side door.1 Stay on the low end of the Surveillance Gradient: aggregate and team-level, transparent purpose, no individual behavioural scoring.
That fence is the same moral geometry as the Institutional Failure Radar: signals generate questions about systems, not accusations about people.12 The Institutional Linter can still ask whether the codified procedures contradict each other; the radar can still ask whether deliberation is deforming; this instrument asks whether the people are being spent as free contingency.13
Worked example: obligation-to-capacity and the amber contract
Here is the artefact in the shape a responsible owner can actually use. The numbers are illustrative for a mid-sized OT or infrastructure-adjacent security control family — not a claim about any real team's headcount. The structure is what matters.
| Factor | Baseline (designed) | Last 8 weeks (observed) |
|---|---|---|
| Critical patch / urgent change window | 10 business days typical | 48-hour class for exposed / actively exploited |
| In-scope systems under active patch governance | 120 | 165 (+38%) |
| Urgent patch events / month | ~8 | ~22 |
| Funded FTE on the control (ex contractors) | 4.0 | 4.0 (flat) |
| After-hours coordination threads / week | 1–2 | 9–12 |
| Median independent review comment length | substantive (paragraphs) | boilerplate (lines) |
| Preventative / hardening backlog items deferred | 0–1 / month | 2 consecutive months deferred |
| Specialists appearing on >70% of critical decisions | distributed | 2 named roles (concentration) |
| Formal control status | Green | Green |
A crude obligation-to-capacity index for the period:
Relative obligation load ≈ scope growth × event frequency × inverse window
≈ 1.38 × (22/8) × (10/2) ≈ 19× the designed intensity on the dimensions that moved — while funded capacity stayed at 1.0×.
You do not need a precise scalar to act. You need a threshold rule the organisation pre-commits to. Example rule set:
- Watch: any two effort-expansion or quality-compression signals sustained for four weeks while formal status remains green.
- Amber (resource contract): funded FTE unchanged while either (a) in-scope systems rise >20% and urgent events double, or (b) after-hours volume stays >4× baseline for six weeks with review-depth collapse and key-person concentration.
- Red (concealed): green formal status with no backup for critical specialists and preventative work deferred twice — structurally red even if the light is green.
Under that rule, the table above is amber — while the dashboard is still congratulating itself.
Capacity intervention packet — OT Security Patch Management
Formal status: Green.
Capacity hypothesis: Over the past eight weeks the team has sustained a sharp increase in urgent patch activity, after-hours coordination and cross-team escalation. Review artefacts have shortened, preventative work has been deferred twice, and two specialists now appear across most critical decisions. Funded headcount is unchanged. Interpretation: compliance is being maintained through discretionary effort rather than designed capacity. Human Reserve Margin is likely near zero.
This is not a performance finding about the team. It is a finding about the operating model under a new threat and regulatory cadence.
Amber resource contract — unlock one or more automatically:
- temporarily augment the team (surge FTE or seconded specialists)
- bring in independent facilitation or review capacity so the load-bearing two are not also the only checkers
- separate urgent patching from normal operations (dedicated lane, protected windows)
- reassess staffing assumptions against Essential Eight / regulator cadence, not last year's volume
- defer or renegotiate lower-priority obligations with an explicit owner
- automate evidence assembly and testing where it reduces toil without faking depth
- review whether the current procedure is still workable under the new threat cadence
- temporary change in decision authority so blockers clear without heroic escalation chains
Forbidden response: add weekly status meetings, demand longer reports, and leave the roster unchanged.
That packet is pro-human and pro-safety at the same time. It treats amber as a resource contract:
The operating conditions have moved outside the assumptions under which this team was staffed.
Most organisations still treat amber as a performance judgement — "the team is falling behind." That reading produces scrutiny without capacity. The contract reading produces help, redesign or explicit de-scoping. Only one of those preserves assurance quality under sustained pressure.
Where Green by Heroics hides in critical infrastructure
Generalise beyond banking. A critical-infrastructure operator running a more complex grid, an expanded capital programme, tighter cyber expectations and scarce specialist labour will generate the same shape wherever obligation outruns the staffing model. Likely human-reserve hotspots include:
- control-room and power-system operations
- protection engineering
- operational technology cybersecurity
- outage planning
- commissioning and testing
- field maintenance and emergency response
- system-strength modelling
- project safety assurance
- contractor oversight
- regulatory and technical submissions
The dangerous condition is not that these teams fail to deliver. It is that they continue to deliver while complexity, cyber threat, capital delivery and assurance demand all rise — and the staffing assumptions from a simpler era stay on the books. That is exactly where Green by Heroics forms: green lights, thinning reserve, nobody officially aware until the resignation letters or the incident.
Companion principle for the Workforce AI Compact
I have argued elsewhere that AI is anti-staff by default because organisations automatically convert new cognitive capability into higher throughput, flat headcount and tighter monitoring — the Extraction Reflex — unless a Workforce AI Compact intercepts it with enforceable triggers.1 The Compact's north star is still right: AI should buy time before it buys headcount.
Green by Heroics extends that doctrine past AI deployment itself. The same extraction mechanism fires when an external obligation intensifies:
threat or regulatory intensity ↑ → scrutiny ↑ → cadence ↑ → headcount flat → human reserve consumed
So add a companion principle:
Obligation increases must trigger capacity review.
Not only: "AI-generated throughput rises by 15%, therefore review workforce impact." Also: "Required assurance intensity, frequency or scope rises materially, therefore revalidate the staffing and capability model."
A pro-human assurance system therefore monitors three things together:
- Obligation load — what the organisation is demanding of a control family.
- Assurance quality — how deeply and independently the work is still being done.
- Human reserve margin — how much sustainable capability remains.
A green control with collapsing human reserve becomes amber for capacity purposes even before the control fails on the formal board. That is the sensing the dashboards were never built to do — and the reason soft exhaust, read at machine scale, earns its keep as safety infrastructure rather than as a people-analytics product.14
Later work in this series will take governance design further — including a governance barbell for where to put weight, an intent compiler for turning policy into executable checks, and a cognition scarcity audit for where attention itself is the scarce resource. Those pieces are not yet live; the point here is narrower and actionable now: instrument reserve, and wire amber to help.
What to do on Monday
A first pass that does not require a platform programme
1. Pick one control family already under cadence pressure (patch management, outage planning, protection settings, contractor safety assurance).
2. Write the designed obligation assumptions: windows, scope, FTE, review depth, backup expertise.
3. For the last six to eight weeks, collect only team-level signals from the four families above — no individual scorecards.
4. Classify the green: designed, falling reserve, or Green by Heroics.
5. Pre-commit the amber contract before you need it: which resource unlocks fire automatically when the threshold is crossed.
6. Issue a capacity intervention packet to the control owner and the capacity owner together — not to HR as a performance case.
If you do nothing else, stop congratulating green that was purchased with unpaid reserve. The employee is not the safety system. The employee is what you are burning when the safety system was never sized for the obligation you now demand.
Send help before auditors
BI for soft data can show where an organisation is spending human resilience as though it were free capacity. That is not surveillance. It is making invisible labour, invisible strain and invisible organisational risk visible so the institution can support its people before the hidden safety margin is gone.
If you want to scope a first obligation-to-capacity pass on one control family, start a conversation: scott@leverageai.com.au.
References
- Scott Farrell, LeverageAI. "AI Is Anti-Staff by Default — and Staff Are Anti-AI by Default." — Workforce AI Compact; Extraction Reflex; AI should buy time before headcount. leverageai.com.au/wp-content/media/articles/52-ai-anti-staff.html
- IBM. "IBM X-Force Threat Intelligence Index 2026." — rising attacks via public-facing applications; financial services highly targeted; continuous vulnerability hunting and patch governance. ibm.com/think/x-force/threat-intelligence-index-2026-securing-identities-ai-detection-risk-management
- Australian Signals Directorate. "Frontier models and their impact on cyber security — update." — multi-step intrusion chaining; accelerated vulnerability discovery; organisational change required. cyber.gov.au/.../frontier-models-and-their-impact-on-cyber-security-update
- ASIC. "26-092MR: ASIC calls for urgent cyber uplift as AI accelerates cyber threats." — urgent uplift across financial services. asic.gov.au/.../26-092mr-...
- APRA. "APRA calls for step-change in AI-related risk management and governance." — practices not keeping pace; step-change required. apra.gov.au/.../apra-calls-step-change-ai-related-risk-management-and-governance
- ASD / Five Eyes. "Five Eyes cyber security agencies statement." — timeline months not years; authority and resources for cyber leaders. cyber.gov.au/.../five-eyes-cyber-security-agencies-statement
- Australian Signals Directorate. "Essential Eight Maturity Model." — critical/actively exploited vulnerabilities mitigated within 48 hours. cyber.gov.au/.../essential-eight-maturity-model
- Australian Signals Directorate. "Annual Cyber Threat Report 2024–2025." — financial/insurance among most reporting non-government sectors; elevated incident and notification volumes. cyber.gov.au/.../annual-cyber-threat-report-2024-2025
- ISC2. "2025 ISC2 Cybersecurity Workforce Study." — staffing budget and skills gaps; overwork and exhaustion under threat pace. isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
- Scott Farrell, LeverageAI. "Your Organization Has Source Code (And You Can Finally Read It)." — soft exhaust as organisational source code; as-designed vs as-operated. leverageai.com.au/wp-content/media/articles/86-your-organization-has-source-code.html
- Scott Farrell, LeverageAI. "Elastic Assurance: Compute Broadly, Disclose Narrowly." — green-formation modes; how green was produced. leverageai.com.au/wp-content/media/articles/136-elastic-assurance.html
- Scott Farrell, LeverageAI. "The Institutional Failure Radar: Failure Changes Shape Before It Changes the Numbers." — behavioural sensing; systems not people. leverageai.com.au/wp-content/media/articles/138-institutional-failure-radar.html
- Scott Farrell, LeverageAI. "The Institutional Linter: Static Analysis for Your Organisation." — codified-org lint plane complementary to capacity sensing. leverageai.com.au/wp-content/media/articles/137-institutional-linter.html
- Scott Farrell, LeverageAI. "BI Tells You Where, the Wiki Tells You Why." — structured locate; soft layers explain. leverageai.com.au/wp-content/media/articles/106-bi-where-wiki-why.html