Blast Radius Classifier in CD

Classify changes; gate accordingly.

Classify every deploy

Every deploy gets a blast radius tag: low, medium, high. The author classifies, review validates, and unclassified deploys block merge. The classifier is a forcing function for the author to think about impact before shipping.

Low blast radius treatment

Low-tier deploys auto-deploy on merge. No human approval, no canary; safety comes from feature flags and observability rather than process gates.

High blast radius treatment

High-tier deploys go through full ceremony. Two-person review, pre-deploy SLO check, 1% canary with 30+ minute soak, off-hours requires named incident commander.

Automate the classifier

Automation reduces author friction. File-path rules catch obvious cases, change-size heuristics flag large PRs, database migrations auto-tag high regardless of code-line size.

How to roll this out

Roll out with three tiers, visible labels in PRs, quarterly audit. Do not add more tiers until a real gap shows up; three tiers cover most patterns and adding more produces decision fatigue.