Reference — generated from the toolkit
Source of truth: toolkit/gates/stop-exit-definition-of-stable.md. Edit it there; this page is regenerated on build.
Gate: STOP Exit — "Definition of Stable"
Transition: STOP (legacy remediation) → RAPID pipeline eligible Owner: Leadership (Engineering + Security + Test leads sign) Runs: once per product, before it enters the RAPID pipeline
Purpose
The measurable trigger that releases a product from remediation into RAPID delivery. A product is "stable" — safe to build on at speed — only when every criterion below is met. This is what stops a half-remediated product being rushed into a rebuild.
Exit criteria (per product)
- Deployment automated — no manual steps to production (DORA baseline captured).
- Zero unremediated critical/high security findings (security-gap assessment) — or each has a signed risk acceptance.
- No EOL component without a signed risk acceptance (EOL inventory).
- Test coverage at the agreed floor (test-debt baseline).
- Secrets vaulted (secrets management); scanning gate live.
- Knowledge pack complete (legacy-knowledge-pack), SME-validated.
- Cost baseline set (FinOps review).
Sign-off & waiver
- Signs: Engineering, Security and Test leads jointly; Leadership records the release.
- May waive: nothing security- or deployment-critical is waivable; any accepted gap is a signed, time-boxed risk acceptance, not a waiver.
- Record: the signed Definition of Stable is retained with the product's knowledge pack.