Code review

Approval policy

Also known as Review approval policy, Pull request approval rules

By WeavePublished 2 min read

Definition

An approval policy states who must review which changes and what evidence is needed before integration.

What the measure captures

An approval policy states who must review which changes and what evidence is needed before integration. It is most useful when the team states the unit of analysis, the start event, the completion event, and the population being measured. A review request, a pull request, and a merge are related events, but they are not interchangeable. Keeping those boundaries visible prevents a dashboard from turning an operational signal into an unexplained score.

A practical example

A service can require an owner approval for interface changes, a passing test suite, and a second reviewer for sensitive configuration. Start with a small sample and inspect the underlying requests before creating a target. Record the repository, change type, reviewer path, and relevant policy state. That makes it possible to explain an unusual result instead of simply celebrating or escalating a number. Compare similar work over time and annotate major changes in ownership, branch rules, or automation.

How to use it carefully

Policies are only useful when they are discoverable and maintained. A complex policy can create bypass behavior or approvals that are merely ceremonial. Review metrics work best as prompts for team-level investigation. Combine them with review samples, author and reviewer feedback, escaped defects, rework, and delivery outcomes. Avoid ranking individuals from a single measure because review difficulty, system familiarity, and assignment patterns vary. A healthy process makes useful feedback available at an appropriate time while preserving accountability for the final change.

How this relates to Weave

Weave can connect review events with change context and delivery signals so teams can inspect approval policy alongside review time, pull request size, and flow. That context helps teams investigate queues and quality patterns without treating one review number as a verdict on an engineer.

How this relates to Weave

Weave can connect review events with change context and delivery signals so teams can inspect approval policy alongside review time, pull request size, and flow. That context helps teams investigate queues and quality patterns without treating one review number as a verdict on an engineer.

Explore Engineering intelligence

Sources and further reading

  1. Managing protected branches, GitHub Docs