A project may encounter a condition that does not match an organization's established security requirements. That situation needs the responsible security authority's review, rather than an informal agreement that the team will fix it later.
Describe the specific condition
Record the affected service, the requirement in question, the proposed arrangement, and why the issue has arisen. Keep sensitive details in the approved system and involve the owners authorized to assess the risk. Project staff can coordinate the question, but they should not assume the authority to accept it merely because the installation deadline is close.
Track the decision and follow-up
If an exception is approved through the organization's process, record its conditions, owner, review point, and any required corrective work. Keep temporary approval distinguishable from a permanent operating standard. Make relevant dependencies visible in the project schedule without exposing the full security record to every participant. If approval is not granted, update the plan around the authorized decision. Keep the approved review date visible to the owner responsible for completing the corrective work.
Practical takeaway
A security exception should have a clear record and an authorized owner. Keeping that process visible prevents a temporary project assumption from quietly becoming the long-term arrangement.