An approval gate admitting cases into a regression suite now receives ten times as many machine-drafted candidates. How do you design it so refusal stays real?
answer
- A gate that never refuses is decoration
- Refusal must cost less than approval
- Bound intake to review capacity
- Undecided should mean not admitted
- Tier depth by what a failure blocks
basics
~20 sBound intake to review capacity, default to refusal when a candidate is undecided, and make rejection cheap and reasoned. Tier review depth by what a case can stop, then watch the refusal rate: a gate that never refuses is decoration.
solid answer
~50 sStart from the property that makes a gate real: **saying no must be cheaper than saying yes.** Under a tenfold intake, uniform per-item approval fails quietly — the queue outgrows capacity and approval decays into acknowledgement. I would tier admission by consequence. A candidate that can stop a release faces a named approver and a default of refusal: undecided means not admitted, and an untouched candidate expires. Everything else enters a provisional tier whose failures block nothing and whose cases are removed unless someone claims them. Bound intake to review capacity rather than to drafting capacity, so the gate cannot be flooded into compliance. Make refusal produce something — a reason routed back so the same shape stops arriving. Then instrument it: refusal rate, age of the oldest undecided candidate, and the share of admitted cases removed again soon after.
code
pseudocode · 14 linesadmit_per_week = min(review_capacity, arrivals) # capacity, not drafting, sets intake
when candidate arrives at gate:
if candidate.failure_can_stop_a_release:
assign(candidate, named_approver)
if no decision within 5 days:
refuse(candidate, reason = "undecided") # default is refusal
else:
admit(candidate, tier = "provisional") # failures annotate, never block
if unclaimed after 30 days:
remove(candidate)
on refuse(candidate, reason):
send(reason, to = drafting_configuration_owner) # refusal has a destinationgo deeper
Know what an approval gate is for: nothing that can stop a release enters the suite until a person agrees it should. Expect to be on the receiving end of a refusal, and to be told the reason.
Explain the mechanics you would build: refusal as the default for undecided candidates, an expiry on stale ones, a provisional tier whose failures block nothing, and a reason attached to every rejection.
Show you can operate the gate: which numbers you watch, what a near-total approval rate really tells you, and how you discovered that admitted cases were being removed again weeks later.
Own the trade-off between uniform per-item approval and tiered admission, and name the conditions that decide it — what a failing case can stop, how well aimed the drafting is, and how much review the team can honestly sustain.
## What makes a gate a gate A gate is not a stage in a pipeline; it is a place where "no" is a realistic outcome. Three properties decide whether it is real: 1. **Refusal is affordable.** Saying no must cost the reviewer less than saying yes. If refusing means writing a justification, attending a meeting and absorbing someone's disappointment while approving means clicking once, the gate approves. 2. **Refusal is decidable.** The reviewer must be able to state the criterion out loud. "Does this case protect a behaviour someone can name, and does its assertion follow from a stated rule?" is decidable. "Is this a good case?" is not. 3. **Refusal has a destination.** A rejected candidate must go somewhere with a reason, and the reason must reach whoever or whatever produced it. A gate that only deletes is a gate people learn to route around. At ten times the arrival rate, these stop being philosophy. Approval capacity is fixed by the number of people and the hours they have; arrivals are now fixed by nothing at all. Something has to give, and the design decides what. ## Two designs, and what picks between them | | Uniform per-item approval | Tiered admission | |---|---|---| | Behaviour at ten times intake | Queue grows without bound; depth per item collapses; approval becomes acknowledgement | Depth preserved where it matters; breadth handled by a weaker mechanism | | What it protects | Every case in the suite has an owner | Only blocking cases have a named owner | | What it costs | Throughput; and eventually honesty, because the ritual survives the review | Complexity, plus a provisional tier that must be pruned or it rots | | When it is right | Small suites, or where every failure blocks something and an obligation requires per-item review | Large suites where a case's consequence varies widely and results can be advisory | Tiered admission is usually the answer at this volume, but the honest version of the answer names what the tier costs. You are trading uniform ownership for preserved depth, and accepting that the provisional tier will accumulate cases nobody claims unless it expires them. ## The conditions that decide - **What a failing case can block.** If a failure stops a release, the case needs a named approver; if it only annotates a run, it does not. - **How well aimed the drafting is.** Well-targeted candidates justify sampling; scattershot ones need the default of refusal, because most of them should be refused. - **Whether advisory results are possible.** A tier that "does not block" only exists if the surrounding process can tolerate a red mark that means nothing. If every red mark stops work, there is no provisional tier and you are back to uniform approval with a hard intake cap. - **What review the team can honestly sustain.** Design to the capacity you have, not the one you would like; a gate calibrated to imaginary capacity fails as acknowledgement. ## Properties any workable version has 1. **The default is refusal.** An undecided candidate is not in the suite, and it expires. Silence must never mean admission. 2. **Intake is bounded by review capacity, not by drafting capacity.** If arrivals can exceed what can be decided, the backlog will eventually be cleared by lowering the bar. 3. **Whoever admits a case inherits it.** The approver's name is on the case when it later fails at three in the morning. Nothing concentrates judgement like that. 4. **Two levels of authority, not one.** Blocking membership is scarce and explicitly granted; provisional membership is cheap, advisory, and time-limited. 5. **Refusal produces a signal.** The reason travels back to whoever configured the drafting, so the same shape stops arriving. ## Instrumenting it - **Refusal rate.** A gate approving nearly everything is decoration. Investigate before you celebrate. - **Time to decision, and age of the oldest undecided candidate.** A growing tail is the queue winning. - **Share of admitted cases removed again soon after.** This is the gate's false-accept rate, and it is the number that tells you the reviews were not real. - **Share of blocking cases whose protected claim nobody can state.** These entered without a decision, whatever the record says. ## How it fails - **The ritual survives the review.** Approvals continue at the same rate with a fraction of the attention. The refusal rate exposes this; nothing else does. - **The bypass appears.** Cases reach the suite through a path that does not pass the gate. A gate holds only while the legitimate route is also the fastest one. - **The provisional tier becomes a graveyard.** Cases enter advisory, nobody claims them, and their failures become background noise that trains everyone to ignore red. Expiry, not discipline, is the fix. - **The gate becomes a person.** One reviewer holds it, goes on leave, and the queue is emptied in an afternoon by someone with no context. Write the criterion down so the gate is a policy that people staff, rather than a person other people wait for.
- Your gate's refusal rate is under two percent. Is that good news?Almost never. Either the candidates arriving are unusually well aimed, which you verify by sampling admitted cases and asking whether each protects a claim someone can state, or the gate has decayed into acknowledgement. The decisive number is what happens next: if a meaningful share of admitted cases are removed again within a quarter, the gate approved things it should have refused.
- What breaks first if you make the gate stricter than the team's real capacity?People route around it. Cases reach the suite through a path that does not pass the gate, or the provisional tier becomes permanent because nothing is ever claimed out of it. A gate holds only while the legitimate route is also the fastest one, so extra strictness has to buy something visible — fewer failing cases nobody owns — or it gets bypassed.
- How do you stop the provisional tier from becoming a graveyard of ignored red marks?Expire its members. Provisional entry is time-limited: a case that nobody claims within a set window is removed rather than left failing quietly. Keep its failures out of anything that gates work, and report the tier's size and claim rate every cycle, so a tier growing faster than it is claimed is visible as a drafting problem rather than absorbed as noise.
A door that has never once been locked is not a security measure; it is a doorway. A gate that has never refused anything is the same thing with paperwork attached.
saying these in an interview costs you the question
- Treats a high approval rate as evidence of a healthy gate
- Leaves undecided candidates admitted by default
- Assumes any queue can be approved away given time
- Refuses candidates without a reason or a destination
- Reviews every candidate at the same depth regardless of consequence
- Judges the gate only by how fast it clears