← Technical project management: from decision to production
11 / 12 · 50 MIN

Decide releases with demonstrated recovery

Prepare go/no-go decisions using representative evidence, explicit authority, and time to recover.

Define what proceeding means

A useful gate identifies the accepted outcome, evidence, threshold, owner, and consequence of failure. In a fictional fund service, application startup is insufficient: the file must arrive, be processed once, and reconcile before the agreed cutoff. If a mandatory condition fails, the PM does not make it optional because of schedule pressure. Establish who may authorize an exception and under which conditions, if exceptions are allowed. Distinguish funding authorization, change approval, and functional acceptance; one person may hold several roles, but that must be explicit.

Compare a representative population

A sample of read requests does not necessarily test writes, daily close, or large files. In the rollout plan, identify affected flows and what each stage can demonstrate. If the candidate receives only simple requests while the control receives heavy exports, comparing averages may attribute a traffic difference to code. Separate results by version and operation without hiding aggregate impact. Define required volume and observation period, stop signals, and interpretation ownership before execution. Absence of relevant traffic means missing evidence rather than automatic approval.

Reserve time to recover and validate

Work backward from the time the service must be accepted. In an exercise with no activity overlap, restoration takes 40 minutes, functional validation takes 20, and agreed margin is ten. If acceptance must finish by 03:00, starting recovery after 01:50 violates that plan. At 01:45 only five minutes remain for additional investigation before the limit. This calculation depends on demonstrated durations and task order. If rehearsal reveals slower restoration, recalculate before the window rather than retaining a boundary whose assumption is no longer true.

Rollback includes data too

Returning to the previous binary can fail if the release changed data incompatibly. Request compatibility analysis across old and new versions, schema, messages, and configuration. In an exercise, the new version deletes a column still required by the old one: changing routing recreates neither that column nor its contents. The plan must identify when reversal stops being simple, how writes are protected, and how transactions after a backup are reconciled. Roll forward also requires a known, authorized solution rather than a vague promise to fix things during an incident.

Controlled delivery and effective configuration

The pipeline is part of delivery and needs controls appropriate to the environment. In GitLab, serializing deployment jobs and preventing outdated jobs address different risks; confirm behavior for the installed version and configuration. For the PM’s decision, request evidence of the artifact, configuration, and environment actually active. A green job establishes only what its steps check. If execution completed but an instance retained prior configuration, a requirement may remain unmet. Record the deviation, limit exposure under the plan, and validate the correction before treating technical status as functional acceptance.

Decisions during an exception

During a window, maintain a timeline of observed facts, decisions, authority, and time. An urgent change still needs the applicable process even when approval is accelerated. Do not attribute approval to someone who did not respond. Use documented delegation where available; otherwise follow the escalation path and preserve recovery capability. Communication should state known impact, current action, requested decision, and next update. After execution, check that configuration matches approval and record deviations and outstanding tasks. Apparent success does not remove the need to review unanticipated effects.

IN PRACTICE

At 01:45 a functional check fails. The plan requires 40 minutes of restoration, 20 of validation, and ten of margin before 03:00. The boundary is 01:50. Investigating for 15 more minutes without revisiting the decision consumes reserved recovery time.

Common pitfalls

Promoting a sample without the affected flow; treating a green pipeline as acceptance; ignoring data during rollback; investigating past the boundary; treating silence as consent.

Related topics: Lead decisions and communicate what matters · Address risk, obsolescence, and recovery · Prepare the change and hand over autonomy

Take this idea with you

A release decision combines evidence, authority, and recovery that remains executable within available time.

Create account

Reference: Guide for Security-Focused Configuration Management · DR Technical Project Manager 2026.4; independent professional curriculum