Concept and mechanism
Change approval does not remove the need to confirm conditions at execution time. Available people, access, dependencies, service state, and artifacts may have changed since review. A go/no-go decision should use explicit criteria, current evidence, and identified owners. Define signals allowing progress between phases, conditions requiring a stop, and who coordinates recovery. Gradual exposure can limit impact but requires representative observation. A canary without relevant traffic does not demonstrate critical-transaction behavior. Include time for important effects to be observed while respecting service context and the authorized plan.
Guided application
In a fictional weekend scenario, deployment is ready, but the specialist required for rollback has not confirmed coverage. Do not infer availability from a name on a contact list. Confirm coverage or present a plan change to the competent authority. During the first phase, errors in an important transaction exceed the agreed threshold although the overall average remains normal. Apply the affected function’s criterion and pause expansion under the plan; an aggregate average can hide segment impact. Before resuming, require appropriate evidence and an acknowledged decision. Scheduling and launch pressure do not replace agreed readiness conditions.
A green overall signal can coexist with a material failure in a critical flow.
Common pitfalls
Old approval treated as current readiness; contact treated as coverage; unrepresentative canary; average treated as everyone’s health.
Related topics: Mandate, models, and authorization · Impact, dependencies, and calendar · Evidence, artifacts, and controls
Confirm current conditions and decide using signals representing service outcomes.
Reference: Safe deployment practices · NIST SP 800-128 updated October 2019; DORA five-metric model and change approval guidance; vendor documentation inspected 2026-10-01