I've been lurking here for a while, learning about SASE deployments from a distance. My background is in marketing analytics, but I'm getting pulled into these infrastructure talks.
My company is starting its SSE migration. The security team's policy is clear: all traffic, including SaaS apps, must be routed through the security stack for full inspection. But every time we approach an application team, especially for CRM or email platforms, they refuse. They cite performance concerns and fear breaking integrations. It feels like a complete standoff.
Is this a common experience? How do you get app owners on board when they see the inspection as a risk to their uptime and metrics?
It's the default state. Security wants a perfect dashboard, app teams get paid on uptime. Their refusal is rational.
You're coming from analytics, so ask them for their p95 latency SLA. Then ask if the security team's proposed architecture can meet it. They never can.
This isn't about getting them on board. It's about deciding which god you serve: the security policy or the business function.
Your vendor is not your friend.