Sensor placement determines what the security team can see. The architect designs a sensor coverage map: network taps and SPAN ports at perimeter ingress/egress points, inline sensors at inter-segment boundaries (east-west), host-based EDR on all endpoints, and API-based collection from cloud platforms.
Coverage gaps are more dangerous than known weaknesses — you cannot detect what you cannot see. The architect performs a gap analysis comparing the organization's actual sensor coverage against the ATT&CK techniques relevant to the threat model, then prioritizes sensor additions by the risk reduction each provides.