-
Notifications
You must be signed in to change notification settings - Fork 0
risks and threats.md
Graveyard's biggest risk is AI commoditizing basic checks by 2029-2030. The mitigation is pivoting to policy + governance.
Last updated: 2026-04-30
| Risk | Severity | Probability | Timeline | Mitigation |
|---|---|---|---|---|
| AI makes check-running commodity | π΄ HIGH | π΄ High | 2028-2030 | Pivot to policy engine β AI can't define org-specific policy |
| Big player builds this as a feature | π΄ HIGH | π Medium | 2028-2031 | Move fast, build community, get acquired OR own the niche |
| GitHub/GitLab adds deployment readiness | π MEDIUM | π Medium | 2027-2029 | Deeper policy + compliance features they won't build |
| 3-person team can't evolve fast enough | π MEDIUM | π‘ Low-Med | Ongoing | Open-source community helps; raise funding if traction exists |
| K8s abstracted away, checks change | π‘ LOW | π‘ Low | 2028-2031 | Build abstraction-agnostic policy engine |
| Market never materializes | π‘ LOW | π‘ Low | β | Regulatory pressure almost guarantees market existence |
| Nobody pays for free tool | π MEDIUM | π‘ Low-Med | Year 1-2 | Team/enterprise features create clear paid value |
The scenario: By 2029-2030, AI can automatically run security scans, verify tests, check K8s configs, and estimate costs β all without Graveyard.
Why this is serious: If Graveyard's value is "we run these checks for you," AI removes that value.
Why this is survivable: AI can run checks but cannot:
- Define what "safe" means for a specific organization
- Encode organizational deployment culture into rules
- Take accountability for deployment decisions
- Generate regulatory compliance evidence
Mitigation: Evolve to policy engine by 2028-2029. See Evolution Roadmap.
The scenario: A major observability or security company adds pre-deployment verification.
Why this is serious: They have massive distribution, brand trust, and existing customer base.
Why this is survivable: Big companies are slow to build new categories. They're post-deployment focused. Graveyard has 2-3 year head start if we move fast.
Mitigation: Build community loyalty, integrate deeply with workflows, become the standard before they enter.
The scenario: GitHub Actions or GitLab CI adds a "deployment readiness" dashboard.
Why this is serious: They're already in the CI/CD workflow.
Why this is survivable: They'll build basic features, not deep policy + compliance. Graveyard's depth in governance will differentiate.
Mitigation: Focus on policy engine + compliance features that platform vendors won't build.
| If This Happens... | Then We... |
|---|---|
| SaaS fails to get traction | Pivot to consulting: "We'll audit your deployment pipeline" ($3-5K/engagement) |
| CLI gets no adoption | The knowledge/tools still build team's reputation for job market |
| Big player enters | Seek acquisition OR double down on niche (regulated industries) |
| Team member leaves | Open-source community can sustain development |
- Evolution Roadmap β How we mitigate the AI threat
- Competitive Landscape β Current competitor positions