"That's Not SOC 2 Compliant": The Compliance Excuse That Blocks Real Engineering
A recent essay from the team behind Amp, Sourcegraph's AI coding agent, pushes back on a common workplace phrase: "that's not SOC 2 compliant." The author argues this line often gets used as a conversation-ending veto against perfectly reasonable requests - like giving an AI coding assistant broader access to logs or infrastructure - even when SOC 2 itself doesn't actually forbid the thing being blocked.
The piece resonated with Hacker News commenters, many of whom have experienced compliance being invoked less as a technical constraint and more as organizational cover: an easy way for teams to avoid explaining their real risk tolerance, or to dodge doing the work of a proper security review.
The underlying point: SOC 2 is an audit framework, not a fixed rulebook, and blaming it obscures who's actually making the decision and why.