Earlier quoted context omitted.
I guess there's someone who orders the marketing department to say "1 million", while telling the operational side "10k", because his bonus rides on it.
That's not how it works. Bug bounties work like this. Somebody sets up a bounty program and defines a framework for deciding how much to pay out. Security is complicated as hell and you cannot possibly devise a framework that accounts for all possible things so this framework is necessarily brittle. For example, you might reasonably decide that the highest payouts require very minimal attacker capabilities (fully rem…
One would imagine that this would have been escalated to some pretty senior security folks at Google before the payout was decided. That would mean that there would be some amount of discretion on Google's end as to the payout, since there would (presumably) be someone senior enough to look at this closely and authorize a higher amount even if there was some rubric that might seem to award a lower amount. Obviously this is ultimately what happened, as they eventually did increase the payout. It's a little strange to me though that this wasn't done sooner.