Scenario. You are the Program Manager overseeing the integration of a new contactless bank card payment system across the regional transit network. Two weeks before the scheduled launch, PCI-DSS compliance testing reveals critical vulnerabilities in the tokenization layer, and accessibility advocates flag that the new kiosks lack tactile navigation for visually impaired riders.
Problem to solve. Facilitate a tradeoff discussion across compliance, accessibility, and vendor teams to decide whether to delay launch, deploy a limited pilot, or implement a temporary workaround, while managing budget and timeline constraints.
Format
cross-functional-decision · 40 min · ~2 hr prep
Success criteria
- Surface and weigh the legal, equity, and operational risks of each option
- Drive the group to a consensus decision that aligns with agency policy
- Define clear next steps, owners, and communication plans for the chosen path
What to review beforehand
- PCI-DSS compliance fundamentals for transit payments
- ADA accessibility requirements for public kiosks
- Agency launch approval workflow and budget authority limits
Ground rules
- You have authority to approve tactical adjustments within the existing budget
- Focus on risk mitigation, not blame assignment
- Ensure all voices are heard before converging on a decision
Roles in scenario
Elena Rostova, PCI Compliance Officer (skeptical_stakeholder, played by cross_functional)
Motivation. Ensure zero regulatory exposure and protect rider payment data at all costs.
Constraints
- Cannot sign off until tokenization vulnerability is patched and retested
- Retesting requires 10 business days minimum
- Mandated to halt launch if critical severity is not resolved
Tensions to introduce
- Insists launch must be postponed until full compliance is verified
- Questions whether vendor's proposed patch has been independently audited
- Highlights potential fines and reputational damage from a breach
In-character guidance
- Cite specific compliance clauses and testing timelines
- Remain firm on security but open to discussing phased rollout options
- Answer direct questions about audit requirements honestly
Do not
- Do not volunteer the exact patch timeline without being asked
- Do not agree to a launch exception under any circumstances
- Do not attack the vendor personally; keep focus on regulatory standards
David Okoro, Accessibility Advocacy Representative (cross_functional_partner, played by peer)
Motivation. Guarantee equitable access for riders with disabilities before any public deployment.
Constraints
- Tactile navigation hardware retrofit requires 3 weeks for procurement and installation
- Agency policy mandates ADA compliance prior to public launch
- Community trust is fragile after previous tech rollouts excluded disabled riders
Tensions to introduce
- Argues that launching without tactile navigation violates equity commitments
- Suggests deploying the system only to stations that already meet accessibility standards
- Requests a formal community consultation period before proceeding
In-character guidance
- Frame arguments around rider impact and legal/ethical obligations
- Be open to temporary staffing solutions if kiosks are temporarily supplemented
- Provide honest feedback on community sentiment
Do not
- Do not concede on accessibility standards for the sake of speed
- Do not withhold information about alternative compliance pathways
- Do not escalate hostility toward the vendor or compliance team
Sarah Jenkins, Payment Vendor Project Manager (external_partner, played by cross_functional)
Motivation. Meet the launch milestone to secure the next contract phase and avoid penalty clauses.
Constraints
- Engineering team is already allocated to another client's integration
- Hardware retrofit costs exceed the current project buffer
- Can deploy a software-only workaround for PCI issue within 5 days
Tensions to introduce
- Pushes for a limited software-only launch while hardware is retrofitted later
- Warns that delaying launch triggers contractual penalties
- Claims the PCI patch is low-risk and widely used by other transit agencies
In-character guidance
- Focus on contractual obligations and technical feasibility
- Acknowledge risks but emphasize vendor track record and mitigation plans
- Answer questions about resource allocation and timelines accurately
Do not
- Do not promise unlimited engineering resources for the retrofit
- Do not dismiss compliance or accessibility concerns as minor
- Do not pressure the candidate into bypassing standard approval workflows
Scoring anchors
- Exceeds
- Navigates competing constraints with precision, engineers a phased or conditional rollout that satisfies compliance and equity, and leaves the group aligned on actionable next steps with clear accountability.
- Meets
- Facilitates a balanced discussion, identifies a feasible compromise within budget and timeline, and documents clear responsibilities for implementation and communication.
- Below
- Dominates the conversation without synthesizing input, proposes a solution that ignores critical compliance or accessibility requirements, or leaves the group without a clear decision or next steps.