Nothing Is as Permanent as a Temporary Fix
Architecture, in the end, is just the set of decisions nobody got around to revisiting.
The Weekend the Stopgap Became the System
Somewhere in your organisation there is a piece of infrastructure that was assembled in a single weekend in March and is now load-bearing.
Perhaps it is the remote-access gateway that was resized, over a frantic seventy-two hours, for four times the concurrent users it had ever carried — because on the Monday the entire workforce would be dialling in from kitchen tables and spare bedrooms. Perhaps it is the month-end close, normally run from a controlled environment inside the building, now being coaxed to completion on a finance manager’s home laptop with a spreadsheet emailed round for sign-off. Perhaps it is the customer process that quietly assumed a human being would always be sitting at a particular desk, and now runs on a manual workaround and a shared mailbox that three people watch in shifts.
None of these things was designed. They accreted. Nobody held a review, weighed the options, or signed a decision that this was the architecture the organisation would run on. They happened because the alternative was that nothing happened at all, and in March the alternative was unthinkable.
The instinct now, ten weeks in, is relief. The lights stayed on. The work got out. The organisation that many of us privately feared would seize up under the strain has instead proved unexpectedly elastic. That relief is earned, and I do not want to take it away. But it is also the beginning of a particular kind of danger, and it is worth naming while the memory of March is still fresh enough to act on.
The danger is this. In the space of a few weeks we made an enormous number of technology decisions at emergency speed, and we recorded almost none of them as decisions. We logged the fix. We did not log the debt. And nothing is as permanent as a temporary fix that works.
Every emergency shortcut is two things at once: a solution to today’s problem and a liability on tomorrow’s balance sheet. We have been diligent about the first and almost silent about the second.
What the Scramble Actually Bought
It is worth being concrete about the scale of what happened, because the abstraction “we adapted quickly” hides it.
Consider a mid-sized organisation that, in the second half of March, stood up secure remote working for eleven thousand staff in nine days. Costed as a programme eighteen months earlier, that same capability had carried a nine-month timeline, a steering committee, and a business case that never quite cleared the investment board. In nine days it was simply done — because the choice was no longer whether to fund it but whether to have a business on Monday.
But the nine days bought more than remote access. They also generated, on one reckoning, more than three hundred security exceptions: firewall rules opened to get a system reachable from the outside, multi-factor requirements waived for a group that could not be enrolled in time, administrative rights granted to people who needed to fix their own machines because the service desk was drowning. Each exception was reasonable. Each was granted with the same three words attached, spoken or unspoken: just for now.
The trouble is that just for now is not a status anyone owns. A permanent system has a service owner, a lifecycle, a budget line, and a place on somebody’s risk register. A temporary one has none of these — which is precisely why it is never revisited. There is no review date, because reviewing it was never the plan. There is no owner, because owning it was never the plan. It exists in the one blind spot our governance cannot see: the space reserved for things that were never supposed to last.
“A permanent system has an owner. A temporary one has an alibi.”
Why the Temporary Hardens
If shortcuts simply dissolved once the crisis passed, none of this would matter. They do not. They set, and they set fast, for reasons that have nothing to do with anyone’s competence and everything to do with how organisations actually behave.
- It works well enough. The definition of a good stopgap is that it takes the pain away. But a stopgap that takes the pain away also takes away the urgency to replace it. The screaming problem of March becomes the quiet inconvenience of June, and quiet inconveniences do not command budget.
- The crisis suspended the friction that would have caught it. The change advisory board, the architecture review, the security sign-off — the whole apparatus that would normally have said “not like that” was deliberately stood down in the name of speed. That was the right call in March. But it means the shortcuts entered the estate without ever passing the checkpoint that exists to record what enters the estate.
- Dependence forms in weeks. People build habits, downstream spreadsheets, and muscle memory on top of the workaround almost immediately. Within a month it is not a workaround; it is how the team works. Unpicking it later means disrupting people who have only just absorbed more disruption than most of them will see in a decade.
- The people who understood it move on. The engineer who knew why the gateway was configured that particular way is back on their day job, or has been redeployed to the next fire, or has been furloughed. The reasoning was never written down, because writing it down was a luxury the weekend did not contain. What is left is a configuration nobody dares touch because nobody can quite remember why it is the way it is.
Put those four forces together and you have a mechanism, not an accident. The temporary hardens into the permanent not because anyone decides it should, but because at no point does anyone decide it should not. Architecture, in the end, is just the set of decisions nobody got around to revisiting.
In Defence of the Duct Tape
I want to take the strongest form of the opposing view seriously, because a version of it is circulating in every leadership team right now, and it is not foolish.
The argument runs like this. Speed was the entire point. An organisation that survived on improvisation has beaten one that would have governed itself into irrelevance while its people sat locked out of their own systems. Technical elegance is a peacetime virtue; in a crisis it is an indulgence. The businesses that hesitated to grant the exception are the businesses whose staff could not work, whose customers could not be served, whose March was a catastrophe rather than a scramble. Measured against that, a few hundred untidy exceptions are a rounding error. Would you really have preferred the alternative?
No. I would not, and that is not the claim. The shortcuts were correct. Taking them was an act of competence, not a lapse in it, and anyone now sniffing at the untidiness of what was built under fire has forgotten what the fire felt like.
But notice what the defence quietly does: it treats “make the shortcut” and “hide the shortcut” as the same act, and they are not. Making the fix was right. Failing to record it as debt — with an owner, a reason, and a date to look at it again — was not required by the emergency; it was merely the path of least resistance once the emergency was in full flow. The failure mode I am describing is not moving fast. It is moving fast and then, once the adrenaline drains away, allowing ourselves to believe that what we built in a panic is what we would have chosen in daylight. The duct tape was right. Forgetting it is duct tape is the mistake.
“The shortcut and the debt are the same act. We have only been recording one of them.”
The Register We Should Have Started in March
So what does a practitioner do now, in May, with the scramble behind us and the shape of the rest of the year still unknown? Not a transformation programme — the appetite for one is rightly zero, and the point of this argument is emphatically not “unpick everything you just built.” The response is smaller, cheaper, and almost entirely a matter of discipline rather than technology.
- Write the debt down while the memory survives. Somewhere there needs to be a single register of the consequential things that were done at speed: what was changed, why, what was traded away, and — the field that matters most — who now owns it. This is a fortnight’s work by people who were in the room, and its value decays by the week as those people scatter and forget. The most expensive sentence of 2021 will be “nobody remembers why that was set up that way.”
- Give every “temporary” a name and a date. The rule is simple and can be applied retrospectively in an afternoon: no exception, no workaround, no stopgap is allowed to exist without a named owner and a date on which it must be looked at again. Not resolved — merely looked at. An item with a review date can be extended deliberately. An item without one is simply invisible, and invisible risk is the only kind that surprises you.
- Sort the reversible from the irreversible. This is the distinction that turns an unmanageable list into a manageable one. Some shortcuts are cheap to unwind whenever it suits — a waived control re-enabled, a manual step re-automated. Others are quietly foreclosing options: data now flowing in a shape that will be painful to change, a supplier arrangement hardening into lock-in, a security posture eroding by increments. Reversibility, not tidiness, is what should set the order of the queue. Spend the scarce attention where the door is closing, not where it merely looks untidy.
- Then decide, in daylight, what to keep. Here is the part that the debt framing can obscure: some of what we built under fire is genuinely better than what it replaced. Processes were simplified because the elaborate version could not survive contact with a dispersed workforce. Approvals that existed only through habit quietly vanished and were not missed. The exercise is not to restore March’s architecture but to choose — consciously, with the option in front of us — which of these accidental improvements to adopt on purpose and which of the accidental liabilities to retire.
None of this is heroic. It will not feature in anyone’s end-of-year narrative. But it is the difference between an organisation that emerges from this period having learned its own systems and one that emerges having merely inherited them.
What We Choose to Inherit
The crisis will pass — later than we hope, in some form we cannot yet see, but it will pass. When it does, every organisation will be running on an estate that is part deliberate and part sediment, and almost none of them will be able to say with confidence which part is which.
That is the real transformation risk of this moment, and it is a quieter one than the risk we spent March fearing. We were braced for systems that would fall over. Instead we should be watching for systems that held — and that, precisely because they held, are now being canonised without anyone ever having chosen them. The question a year from now will not be whether we took shortcuts. We did, and we were right to. The question will be whether we can still tell the difference between the things we decided to keep and the things we simply never got around to removing.
The most expensive words in the building over the coming year will not be spoken in anger or panic. They will be spoken with a shrug, in a meeting about something else entirely, when someone asks why a critical process depends on a mailbox that three people watch in shifts, and the only answer anyone can give is: oh, that — that was only ever meant to be temporary.