I Don't Simplify Things. I Build Ladders.
Most people think "clarity" is a communication skill. I think it's a product.

Most people think "clarity" is a communication skill. I think it's a product. Because confusion, in tech, usually isn't a personality flaw—it's a design flaw at the system level.
Let's illustrate with a real-world mess: ContentSquare had just acquired Heap. Heap (US) focused on SOC2 compliance. ContentSquare (France) cared deeply about ISO 27001. Why?
- ISO 27001 is Europe's defacto proof your company does privacy and security right.
- Why does that matter? European customers watched giants—like Google—get massive GDPR fines. They want to know who they can trust, fast.
- But there's more: each acquired company's products were built under different rules. That meant contracts ballooned, MSAs got messy, and every deal turned into a technical therapy session—explaining the nuances of every control.

Our mandate wasn't just "get compliant." It was: standardize the trust story, make contracts simple, and unlock cross-sell between both customer bases.
That's where the real complexity (and opportunity) started.
Understanding the Real Intent

Before you chase checklists, stack rank, or decide on tech fixes, you need to dig until you hit the why behind the why.
Why do these controls exist? Who cares, and what risk or goal are they really protecting? Sometimes it's auditors. Sometimes, it's a scared customer success team. Sometimes—it's the markets, or a ticking acquisition requirement.
I call this phase mind-melding. Get privacy, legal, compliance, and eng in a (virtual) room. Go through each control—not just what it says, but what it's there to block, enable, or prove.

The Real Ladder: Outcome-Backwards
This is what shifts teams from consensus theatre to actual progress:
1. Name the true outcome. (e.g., "Close deals with one trust story and no contract escalations.")
2. Stack rank by biggest risk/offender. We admitted up front: we can't do it all this quarter. But we can tackle the highest risk—the issues blocking most revenue or trust.
3. Get creative: best-bang-for-buck solutions. Only when everyone truly understood what each control was meant to protect could we get creative with engineering. (Not every control needs a gold-plated fix—just something auditor-ready.)
4. Negotiate, iterate, sell it internally. Each team had to be comfortable selling this compromise—tradeoffs, intent, plan to iterate—when the auditors showed up. No one left in the dark or out of the loop.
5. Artifact: Ship an artifact (checklist, implementation log, FAQ) that captures not just what you did, but why—so the story, not just the compliance, is easy to pass down the line.
Before & After: The "Compliance Sprint"
Before:
- "Get us ISO 27001 in 6 months."
- 2 companies, 2 compliance cultures, zero shared intent.
- Legal, eng, privacy in endless meetings, nobody clear where to start.
After:
- Stack-ranked risks by contract slowdowns and customer fears.
- <20 controls flagged as "must-fix this year." (down from >150 suggestions from the compliance, legal, privacy and security teams)
- Each team helped craft and sell the implementation story for auditors.
- Artifact: one-page cross-org FAQ and controls registry shared with every customer team.
Reader Exercise
Think of a system you're struggling to "align" on.
- Why does this REALLY matter (the deepest why)?
- Who feels this pain (and how does it hit them)?
- Where can you stack rank for biggest impact right now?
- Build a ladder—outcome at the top, small creative actions, guardrails, artifact.
If your work feels heavy, ask yourself this: Are you carrying the whole puzzle... or are you building a ladder others can climb (and explain) with you?
"I don't simplify because I hate complexity. I simplify because I respect what it costs."