Disrupting the purple team
The danger of prolonged, exclusive, purple teaming is real. If an organization solely depends on purple teaming internally, it is strongly advised to have an external red team assess the progress and work of the purple team on a regular basis.
Regardless, the offensive security team should periodically run red team operations that are covert to reevaluate end-to-end testing if the progress during the purple team operations is effectively in place. Look through Chapter 4, Progressive Red Teaming Operations, to get some ideas of how things can be mixed up to challenge stakeholders and think about new or modified objectives that an adversary might have.