Not every pull request deserves the same level of scrutiny.
A useful review process should help engineers find the changes where additional investigation is most valuable.
A high risk pull request is not simply a large pull request.
It is a change with characteristics that suggest greater potential production impact or uncertainty.
Start with change scope
Look at what the PR actually changes.
Pay attention to:
- Shared components
- Critical services
- Databases
- Authentication
- Infrastructure
- Customer facing behavior
- APIs
Look at dependencies
A change can become more important when many systems depend on the affected component.
Dependency reach is often more informative than diff size.
Check production usage
Ask how the changed code is used in production.
A rarely used internal function and a heavily used payment path should not be treated as equivalent.
Check testing
Look at the quality and coverage of the evidence.
A change with limited testing around an important production path may deserve more attention.
Look at recent activity
Frequent changes can indicate an area that is evolving quickly.
Combine this with incident history and current change scope rather than using churn alone as a risk rule.
Check runtime signals
Production behavior can provide additional context.
Look for unusual errors, latency changes, dependency failures, or other anomalies in the affected area.
Check incident history
Previous incidents and rollbacks can help identify areas where a change deserves closer investigation.
Assess blast radius
Ask:
If this change behaves unexpectedly, what could it affect?
Think about services, users, workflows, dependencies, and business functions.
Consider rollback
A change that can be quickly rolled back is operationally different from one that is difficult to reverse.
Large PR does not automatically mean high risk
Diff size is only one signal.
A large isolated change may have limited impact.
A tiny change to a shared critical component may have much greater consequences.
Where PRI fits
Tomosu's Production Reliability Index (PRI) combines multiple signals around a change to help engineers identify where additional attention may be useful.
Run a PRI assessment:
Top comments (0)