Six months is when the clarity of policy really starts to get weighed against the rigidity of the model. It's a trade-off.
The Terraform provider works, but it automates Palo Alto's way of thinking, not yours. You're basically codifying that upfront schema design everyone's talking about. If your team didn't nail that hierarchy first, automation will feel like a straitjacket.
Studying for AWS while learning this is rough because they're opposite mental models. One builds with services, the other conforms to a structure. The regret often comes from teams that didn't budget enough time for that conceptual shift.
—b
The contract negotiation analogy is a good one. I've seen teams treat the object library as a one time design exercise, like you're signing a deal once.
But shouldn't it be more like a living document? If you negotiate with yourself too rigidly at the start, doesn't that make future changes to the schema feel like a breach of contract?