Skip to content

risks and threats.md

Muhammad Umer Nadeem edited this page May 17, 2026 · 2 revisions

Risks and Threats

Graveyard's biggest risk is AI commoditizing basic checks by 2029-2030. The mitigation is pivoting to policy + governance.

Last updated: 2026-04-30


Risk Matrix

Risk Severity Probability Timeline Mitigation
AI makes check-running commodity πŸ”΄ HIGH πŸ”΄ High 2028-2030 Pivot to policy engine β€” AI can't define org-specific policy
Big player builds this as a feature πŸ”΄ HIGH 🟠 Medium 2028-2031 Move fast, build community, get acquired OR own the niche
GitHub/GitLab adds deployment readiness 🟠 MEDIUM 🟠 Medium 2027-2029 Deeper policy + compliance features they won't build
3-person team can't evolve fast enough 🟠 MEDIUM 🟑 Low-Med Ongoing Open-source community helps; raise funding if traction exists
K8s abstracted away, checks change 🟑 LOW 🟑 Low 2028-2031 Build abstraction-agnostic policy engine
Market never materializes 🟑 LOW 🟑 Low β€” Regulatory pressure almost guarantees market existence
Nobody pays for free tool 🟠 MEDIUM 🟑 Low-Med Year 1-2 Team/enterprise features create clear paid value

Detailed Threat Analysis

Threat 1: AI Commoditizes Checks (πŸ”΄ CRITICAL)

The scenario: By 2029-2030, AI can automatically run security scans, verify tests, check K8s configs, and estimate costs β€” all without Graveyard.

Why this is serious: If Graveyard's value is "we run these checks for you," AI removes that value.

Why this is survivable: AI can run checks but cannot:

  • Define what "safe" means for a specific organization
  • Encode organizational deployment culture into rules
  • Take accountability for deployment decisions
  • Generate regulatory compliance evidence

Mitigation: Evolve to policy engine by 2028-2029. See Evolution Roadmap.

Threat 2: Datadog / Palo Alto Enters (πŸ”΄ HIGH)

The scenario: A major observability or security company adds pre-deployment verification.

Why this is serious: They have massive distribution, brand trust, and existing customer base.

Why this is survivable: Big companies are slow to build new categories. They're post-deployment focused. Graveyard has 2-3 year head start if we move fast.

Mitigation: Build community loyalty, integrate deeply with workflows, become the standard before they enter.

Threat 3: GitHub/GitLab Builds It In (🟠 MEDIUM)

The scenario: GitHub Actions or GitLab CI adds a "deployment readiness" dashboard.

Why this is serious: They're already in the CI/CD workflow.

Why this is survivable: They'll build basic features, not deep policy + compliance. Graveyard's depth in governance will differentiate.

Mitigation: Focus on policy engine + compliance features that platform vendors won't build.

Backup Plans

If This Happens... Then We...
SaaS fails to get traction Pivot to consulting: "We'll audit your deployment pipeline" ($3-5K/engagement)
CLI gets no adoption The knowledge/tools still build team's reputation for job market
Big player enters Seek acquisition OR double down on niche (regulated industries)
Team member leaves Open-source community can sustain development

See also

Clone this wiki locally