Skip to content

Code Review Policy Update - Risk-Based Approach

Proposer: Bomee Jung

Our work practices have changed recently with the advent of AI tools. These changes to our policy bring our documents up to date and solidify the day-to-day practices that have evolved over retros and dialogs.

  1. Implement risk-based review requirements that reflect actual change impact rather than simplistic metrics
  2. Formalize our AI-assisted development practices and tooling (Claude Code, CodeRabbit, Korbit)
  3. Establish clear post-merge review tracking for AI-only reviewed changes
  4. Maintain development velocity while ensuring code quality and security
  5. Document practices for SOC2 compliance and responsible AI governance
  1. Approve and publish the Risk-Based PR Review Policy (risk-based-pr-review-policy.md)

    • Defines four risk levels (Zero, Low, Medium, High) with appropriate review requirements
    • Emphasizes developer judgment over rigid rules
    • Includes contextual examples and risk modifiers
  2. Update the Software Development Lifecycle (software-development-lifecycle.md)

    • Add risk-based code review section
    • Document PR review states including post-merge review
    • Include AI-assisted development practices and tool requirements
    • Reference the detailed risk-based policy
  3. Finalize the AI Code Generation Practices (20250609-ai-code-gen.md)

    • Update to reflect current implementation status
    • Document our AI tooling stack and policies
    • Add values and intent section
    • Include future expansion toward Model Specification
  • Publish updated documents to handbook
  • Update PR templates to include risk self-assessment
  • Set up automation for post-merge review tracking in Momentum project
  • Schedule reviews of risk categorization accuracy
  • <5% of high-risk PRs merged without human review
  • 100% of AI-only medium-risk PRs tracked for post-merge review
  • Maintain or improve current deployment velocity
  • Zero security incidents from inadequate review

Steps:

  1. Discovery: Ask questions to understand the proposal.
  2. Debate: Explore risks, concerns, alternatives, and identify critical questions related to the actions proposed.
  3. Decision: Finalize a “safe to try” approach with consent from all stakeholders.

Please start by adding your comments in the PR.

To be summarized and filled in.

To be summarized and filled in.

Please situate yourself in a stakeholder category.

  • Fill in
  • Fill in