Concept and mechanism
Before the first stage, define signals, population, observation period, and stop criteria. A small canary may limit exposure, but only informs about operations it actually performed. Compare the new version and reference under relevant conditions: route, load profile, region, and dependencies. Ten read requests do not establish that month-end close works. Avoid attributing all degradation to the release without investigating whether the reference also worsened. Observation should help distinguish a change regression from a shared failure.
Guided application
During execution, keep a timeline of steps, evidence, and decisions. If significant impact appears, activate incident coordination under the applicable process and link the incident to the change. Designate execution, observation, and communication roles. Avoid multiple teams changing the same component without coordination. Pressure to find the cause does not remove the recovery deadline. Exposure may need containment or recovery before causal analysis finishes, while preserving useful evidence.
The canary shows 4% errors and the reference 0.2% for equivalent requests. The approved limit is 1% over five minutes. Evidence calls for applying the stop criterion, not expanding to obtain more traffic.
Common pitfalls
Confusing no traffic with success; continuing past the limit to finish the plan.
Related topics: Validation, closure, and improvement · Request, risk, and authorization
The next stage depends on evidence, not only on completion of the previous step.
Reference: Canarying releases · DR Change Management 2026.1; independent technical curriculum