Skip to main content

Development standards

Source changes that are understandable and reviewable.

Baseline development practices for source control, review, testing, dependencies, documentation, configuration, and release evidence.

What this means

Every important change should leave a useful trail.

The standard is scaled to the risk and engagement, but the intent stays constant: a competent engineer should be able to understand why a change exists, evaluate it, verify it, and operate it without relying on hidden context.

  • Small, purposeful changes
  • Peer or independent review where required
  • Automated checks at useful boundaries
  • No secrets committed to source

Baseline practice areas

01

Source control

Protected history, purposeful branches or change sets, meaningful messages, and traceability to work and decisions.

02

Code review

Review correctness, clarity, security, data impact, failure modes, tests, compatibility, and maintainability.

03

Testing

Use an appropriate mix of unit, integration, contract, system, accessibility, performance, security, and user validation.

04

Dependencies

Use supported dependencies, minimise unnecessary packages, monitor risk, control versions, and plan updates.

05

Configuration and secrets

Separate configuration from code, protect secrets, limit access, and make environment differences visible.

06

Documentation

Keep setup, interfaces, important decisions, runbooks, known limits, and ownership information close to the work.

07

Build and release

Prefer repeatable builds, automated checks, controlled promotion, release evidence, and an understood rollback route.

08

Observability

Build useful health, logs, metrics, traces, alerts, and diagnostic context without exposing sensitive information.

09

Maintenance

Plan dependency, defect, security, performance, documentation, and platform maintenance as ongoing work.

Evidence standard

A standard may have a documented exception when the context justifies it. The exception should identify the reason, risk, compensating control, owner, and review point rather than silently lowering the bar.

Bring the requirement and its constraints.

Algoza will clarify the evidence, controls, decisions, and delivery route appropriate to the engagement.

Discuss a requirement