Governance by Risk Level
| Risk Level | Approval Required | Deployment |
|---|---|---|
| β | β | β |
| β | β | β |
| β | β | β |
Governance Policy Template
1. All prompt changes require test results
2. Production changes need approval from role
3. Rollback available for 30 days
4. Monitor accuracy post-change
5. Communicate changes to users
Change Control Process
- 1Author proposes change with rationale
- 2Reviewer checks: tests, examples, risks
- 3Approve or request changes
- 4Deploy to staging first
- 5Monitor for 24 hours
- 6Deploy to production (staged rollout if high-risk)
- 7Rollback plan documented
Monitor Post-Change
- Accuracy metrics: Did quality degrade?
- Error rates: More failures?
- User feedback: Are users complaining?
- Cost impact: Did per-prompt cost change?
Rollback Decision Tree
Accuracy drop > 5%? Rollback immediately.
Error rate spike? Rollback immediately.
User complaints? Investigate, consider rollback.
Otherwise, monitor for 48 hours.
Sources
- OpenAI. Production practices
- Google. Change management
- Anthropic. Deployment safety
Common Mistakes
- No approval process (cowboy changes)
- No rollback plan (stuck if bad change)
- Deploying to 100% immediately (max blast radius)
- Not monitoring post-deploy
- Removing old version too soon