Skip to main content
Reference — generated from the toolkit

Source of truth: toolkit/gates/stop-exit-definition-of-stable.md. Edit it there; this page is regenerated on build.

Gate: STOP Exit — "Definition of Stable"

Transition: STOP (legacy remediation) → RAPID pipeline eligible Owner: Leadership (Engineering + Security + Test leads sign) Runs: once per product, before it enters the RAPID pipeline

Purpose

The measurable trigger that releases a product from remediation into RAPID delivery. A product is "stable" — safe to build on at speed — only when every criterion below is met. This is what stops a half-remediated product being rushed into a rebuild.

Entry criteria

  • STOP triage complete for this product — commitments dispositioned (client-commitment triage), audits run, findings in the registers.
  • The product's remediation backlog burned down to plan (deferred items hold signed risk acceptances).

Exit criteria (per product)

Evidence required

Automated vs human

CheckAutomated in CIHuman sign-off
Coverage floor, secrets scan, SCA/SBOM
Deployment automation (pipeline run end-to-end)DevOps
Knowledge pack completeness & correctnessSME + Engineering lead
Overall "stable" callEng + Sec + Test leads

Sign-off & waiver

  • Signs: Engineering, Security and Test leads jointly; Leadership records the release.
  • May waive: nothing security- or deployment-critical is waivable; any accepted gap is a signed, time-boxed risk acceptance, not a waiver.
  • Record: the signed Definition of Stable is retained with the product's knowledge pack.