- Task
- Version · 6.0
- Govern
Retire controls that no longer earn their cost
Last updated: September 29, 2026
Spot a control that is costing more than it protects, confirm why, and retire it without deleting anything.
Before you begin
You have a control you suspect is costing more than it protects, and enough history in the Policy Checks dashboard to tell a long-standing rule that never fires from one that was only just added.
Procedure
Recognize the signals
Every check has a cost: Pipeline time, developer attention, and the credibility of governance as a whole. A control that only ever produces noise, or protects against a risk the platform no longer has, should be rescoped or retired. Improvement is not only adding rules.
It never fires. Either the risk is gone, the practice has fully absorbed the rule, or the check is not reaching what it should. Confirm which before celebrating.
It always fires and is always overridden. A rule everyone routes around is not a standard. It is friction. Fix its calibration or retire it.
It guards a platform you no longer run. Vendor-specific rules outlive migrations.
Confirm why before retiring anything
A check that never fires can mean the risk is gone, that the practice has absorbed the rule, or that the check is not reaching anything. Only the first two are good news. The risk may be gone, the practice may have fully absorbed the rule, or the check may simply not be reaching what it should. Confirm which before celebrating, using Review policy coverage to check that the rule is actually assigned to the assets you think it covers.
Retire it without deleting it
Disable the check in its package, or remove the package from the assignments that carry it. Do not delete anything. A disabled check can be turned back on, and an assignment can be re-scoped, but a deleted check takes its configuration and its history with it.
When a whole assignment has outlived its purpose, archive it from the Assignments page. The checks and packages it pointed at are left as they are, but confirm first that no pipeline still runs with its ID.

Communicate it like any governance change
Retirement changes what the pipeline enforces, so it is announced the same way an addition is. Teams that learned to work around a rule need to know it is gone, and teams relying on it need to know it no longer protects them. See Communicate the change to affected teams.
Verify on the next cycle
Retiring a control should not move the measures it was not protecting. If violation counts or the change failure rate climb after a retirement, the rule was doing more than it appeared to. See Verify the effect on the next measurement cycle.