War-game a WAF rule change before match criteria, false-positive budgets, and rollback steps harden into what every edge block will quote.
WAF changes fail when the runbook invents precision the matcher never had, when allowlists dual-count the same partner path as blocked and as exempt, when money routes still lack a named false-positive owner, and when ops cannot show who owns the decision after a partial rule misfire. A neat rule XML dump is not evidence.
Freeze the change
One sentence for why the rule exists, which hosts and paths it covers, who owns match criteria, logging, and rollback, and the abort trigger if false positives or latency past a named threshold. Attach the draft rule, sample request logs, allowlist map, and the measured path from detection to restored traffic. If security, network, and product disagree on which paths are truly covered, stop and reconcile first.
Name the decision you will make if the war game finds nothing new, and the delay criteria if any money path still lacks a named rollback owner or a verified canary.
Seats that matter
- Network ops. Where match criteria invent coverage or hide shared rules across apps.
- Security. Where bypasses still leave the queue and become standing exceptions.
- Product. Which customer decision breaks first when a legitimate request is blocked.
- Support. How status language trails the customer-visible error rate.
- Skeptic. The claim that looks strongest and is least evidenced by prior WAF drills.
Attach the same source pack to every seat. Secret allowlists for favorite partners only create fake calm.
Loop the review
Feed Pingpong the draft rule, canary notes, and open risk list. Early passes steelman the design. Later passes attack from network, security, product, support, and skeptic seats. End with a pass that turns surviving objections into clearer owners, a timed canary, or a hold. Delete invented "we already block cleanly" claims and dual-counted success rates.
Force a month-after narrative: what happens if a partner webhook is blocked, if a marketing landing page starts failing bot checks, or if an operator widens an allowlist under launch pressure. If those stories are stronger than your mitigation plan, fix the package before you ship the rule.
Pair with the network ops lead seat, a CDN edge config review, a security incident stress test, and the war-game decisions hub.