HY-06

Security Classification Widened After Work Started

Hygiene

Default severity: medium
ProcessMetricsQuality

What it detects

Jira security level widened while issue in active delivery; tests; catalogue.

Detection formula

No published identification formula is available yet for this rule.

Examples in practice

  • Baseline fields or story data are edited outside agreed roles or left incomplete.
  • Changelog sparsity makes it hard to trust historical metrics.
  • A team shows jira security level widened while issue in active delivery; tests; catalogue during analysis.

Suggested response

Reduce silent edits—enforce who may change baselines and keep story data complete.

Coaching playbook

Symptom

The "Security Classification Widened After Work Started" signal shows a repeatable delivery anti-pattern on the cited issues.

Why it matters

When "Security Classification Widened After Work Started" keeps appearing, the team is signalling a repeatable process gap. Left unexamined, the pattern hides where work really stalls and makes improvement metrics harder to trust.

What you can achieve

Reduce silent edits—enforce who may change baselines and keep story data complete.

Facilitation questions

  • What system change would stop "Security Classification Widened After Work Started" from firing again?
  • What do the cited issues have in common — same root cause or same workaround?
  • Who owns the two-week experiment and how will we verify on the next import?

Run this rule against your own tracker data with Flow Analyzer.

Product tourSign in
HY-06: Security Classification Widened After Work Started — FlowAnalyzer