H.8 Policy

A repository-wide standard is neither a slogan nor a permanent boolean. It is a decision with an authority boundary, a supported path, evidence, rollout, exceptions, reversal, and retirement.

Record The Decision Before Enforcing It

H.8.1 Decision Rights separates proposer, decision owner, affected constituencies, implementers, exception authority, and retirement authority. Central authority fits true organization-wide invariants; federated and domain-owned decisions preserve expertise or local context where uniformity is not worth its coordination cost.

These rights establish or revise a standard. H.4.4 Review Authority answers the narrower question of who must approve one concrete change under the current standard.

H.8.2 Paved Roads turns a decision into a supported internal product: capabilities, compatibility, documentation, examples, service expectations, and owned escape hatches. Repeated escapes are product evidence, not merely noncompliance.

Operate The Policy Record

H.8.3 Policy Lifecycle carries a proposed standard through testing, canary, adoption, enforcement, measurement, revision, reversal, and retirement. A useful record includes the problem, alternatives, owner, affected cohorts, compatibility, rollout, diagnostics, support load, and the evidence that would change the decision.1

H.8.4 Policy Exceptions represents a bounded alternate state with owner, exact scope, reason, compensating control, approval, expiry, and review date. At review, it must expire, renew with fresh evidence, become a supported variant, or disappear. A growing cluster of similar exceptions is evidence that the standard or platform capability needs repair.

key takeaway

Govern the full lifecycle of a standard: who decides, what path is supported, how adoption is tested and measured, how an exception is bounded, and what evidence reverses or retires the policy.

Footnotes

  1. The DevOps Handbook (First Edition) — evidence-driven rollout and revision of operational practices