Every estate has a boundary where the controls get serious. Production sits inside it. Access is brokered, changes are reviewed, reads are logged, and somebody owns the log.

Test environments sit outside it. Not by decision — by accretion. Someone needed a realistic dataset for a migration in 2019, took a snapshot, and the snapshot became the fixture. It got copied into a second environment for load testing, then into a third so a contractor could reproduce a bug. Nobody signed anything, because nobody was doing anything that felt like it needed signing.

That is how the least-governed part of an estate ends up holding the most production-shaped data in it.

Why the data has to be production-shaped

The obvious answer is "then don't use real data", and it is worth being honest about why teams do it anyway.