Requests to Refuse
The asks that arrive once a chain exists, why each should be declined, and what to offer instead.
What not to build · Reference
A connected estate makes things possible that were not before, and some of them should stay impossible.
"Push the schedule straight into payroll"
Why to refuse: the schedule is a plan. Paying it means paying for shifts that were covered by someone else, cut short or not worked.
Offer instead: the actual, with an exception process and a tolerance.
"Let the integration account write to payroll directly"
Why to refuse: it removes the approval step between an operational system and money, and the segregation question has no answer afterwards.
Offer instead: a file that requires a human release, with the release logged.
"Combine the four systems' data into a productivity score per person"
Why to refuse: it compounds the measurement error of every module at once — schedule variance, clock error, absence classification — and produces a confident number about a person that none of the sources supports.
Offer instead: analysis at site and period level, where the errors average rather than multiply.
"Give managers a live view of everything about their team"
Why to refuse: the chain assembled in one view is substantially more intrusive than any part of it, and most of it informs no decision a manager makes.
Offer instead: the exceptions that need a decision, which is what they actually use.
"Keep everything indefinitely so we can analyse it later"
Why to refuse: retention is per purpose, and "later" is not one. It also enlarges every access request and every breach.
Offer instead: aggregates kept, detail deleted on schedule.
"Skip the reconciliation this period, we are short-handed"
Why to refuse: it is the only control that detects a silent join failure, and the period you skip is the one that breaks.
Offer instead: a reduced version — headcount and hours only — which takes fifteen minutes.
"Let the vendor's consultant hold the admin credentials permanently"
Why to refuse: it is a third party with unlogged access to the payment chain.
Offer instead: a named, time-limited account with the access logged and reviewed.
Recording it
What was asked, by whom, when. What was declined and why. What was offered instead. Who decided.
Findable, so the second identical request is answered by reference.
Decide who decides
Before the first request arrives.
Name the person or forum that rules on exceptions.
Name what evidence an exception requires.
Agree it with whoever owns risk.
Publish it internally, so a requester meets a process rather than one person's judgement — and so the first decision does not silently become the precedent.
A practical configuration prompt
During configuration, use this record-transfer example to prompt questions about identifiers, ownership and output. Treat the page as a starting point and document each assumption.
More in this section