Write a policy and train people
The org’s first instinct, and the cheapest. But policies decay, new hires miss the training. And these errors were silent: nobody knew they had undone a colleague’s work.
No rule catches what nobody notices.
In Sugar, everyone could edit everything. So work got silently undone, and nothing had an owner. This is the companion to the architecture rebuild: the layer no screenshot shows, where five teams stopped colliding and started running a relay.
CONTEXT
Owned
Partnered on
Constraint
My job was turning the org chart into a system that enforces itself.
PROBLEM
The incident that made it undeniable
A case manager spent a morning rebuilding a packet a colleague had “corrected” overnight — who was fixing what a third person changed the day before. Three people, one record, zero owners. Multiply by five teams and eighteen statuses: submissions dropping was arithmetic, not mystery.
The first design act was subtraction. Team-lead interviews mapped the workflow: two of six roles did their real work in a third-party platform, and screens for them would be screens for an audience that was not there. Scoped out, the system got simpler before anything changed. The four roles that remained:
01
Brings leads in
Lead Conversion Specialist
02
Runs initial review
Case Manager
03
Checks the documents
Underwriter
04
Signs off
Case Review Specialist
Claim pipeline · 18 statuses, four owners
Dotted = handled outside Sugar
01
Lead intake
02
Review
03
Packet
04
Submit & close
Lead Conversion Specialist
Case Manager
Underwriter
Case Review Specialist
Outside Sugar
Network Support · Mail Clerk
Closing states
Closed paid in full Charge off Close account settled Send to collections Marked as RECON ClosedStrategy
When everyone can edit everything, there are three classic responses:
The org’s first instinct, and the cheapest. But policies decay, new hires miss the training. And these errors were silent: nobody knew they had undone a colleague’s work.
No rule catches what nobody notices.
Role-filtered views without hard locks. Less friction, faster to ship — but the worst incidents came from people confidently “fixing” records they should not touch.
Filters suggest; they do not prevent.
Hard role-based access, sequenced handoffs, signed checkpoints. Highest build cost, and one real risk: blocking legitimate cross-role work.
Makes the failure impossible.
Solution
Every fix below follows one principle: make the system’s rules legible in the interface itself. Not a policy document, not training — the screen you are looking at should tell you what is yours, what is next, and what your name is about to go on.
Solution 01
The failure mode was work leaking downstream unverified — so every phase ends in a checkpoint, and every dashboard shows one role’s work only, because anything else on screen was a chance to break someone else’s.
Drawing those boundaries meant settling where one role’s ownership ended and the next began — the hardest lines to draw were the records two roles both had reason to touch, and getting them right took working through the real cases with the leads.
Solution 02
Forcing one flow on both kinds of work would have broken one of them: intake is sequential, review is not.
Solution 03
A reviewer’s real unit of work is the queue, not the row, so state had to read across a full screen at a glance, and progress had to survive interruption.
Solution 04
Accountability only sticks when someone chooses to put their name on it — so completion is a deliberate act, not an automatic flip, backed by an immutable record. Careless errors dropped measurably.
Shipped
Impact · Outcome
2×
claim submissions within one month of launch
Fewer errors
accidental changes by the wrong teams ended once access followed roles
Clear owners
every task and review gained a named, traceable owner: less confusion, less rework
Reflection
The fixes that mattered most were small: organizing tasks in the order people do them, and asking for one deliberate confirmation. Turning a messy free-for-all into a smooth, owned process was the win that counted.
Next case study
The Two-Minute Deal →