1) devops/sre start to provide some guides on top of some cloud, nowdays it's k8s. Like default service templates.
2) service templates transforms into custom DSL with side configuration and k8s abstraction things.
3) Abstraction/libraries on top of secrets management.
4) Service configuration per enviroment.
At with point it's all good. But startup grows, and needs a secops team to get some internal audit. Or it could be a platform team initiative.
5) Audit shows critical issues with permissions and platform team starts to think about how to restrict access.
Mismatch with "old freedom" could be quite high for unprepared product teams. Platform becomes "inconvenient". It takes huge amount of resources to make it actually usable.
I definitely agree that as any small start-up grows, the security controls become very painful, especially for those folks who felt "the freedom" before the controls were established. That said, would the picture look better without platform teams? The security controls would need to be there anyway, and I'd personally prefer to use some self-serve, platform-ish solution built by a team of software engineers that would do call auditing, verification, etc., rather than raising a JIRA ticket with some ops folks who'd do the security-sensitive thing for you.
Ahah. 100%.
Honestly I am in a great conflict right now. My current role is in a platform team (first time here, previously it was only product positions). And I'm responsible for implementing unified company wide authorization including client libraries and integration with all web frameworks in use. I feel vast empathy for product engineers having to migrate and integrate the new system. It has artificial intended bumps I have to enforce and doesn't like personally.