Review

Who reviews the reviewer?

Independent review is only meaningful if the reviewer can actually disagree. Here is what independence has to mean structurally, not aspirationally.

By Fidelio

Adding a review step is easy. Adding a review step that can change an outcome is considerably harder, and the difference between the two is where most quality processes quietly die.

A reviewer that always approves is not a safeguard. It is a delay with a logo on it.

Independence is structural, not attitudinal

You cannot instruct a component to be objective about its own work. Independence has to come from the arrangement rather than the intent: the reviewer must not have produced the artifact, must not be scored on the artifact succeeding, and must be able to return a verdict that actually blocks something.

Remove any one of those and the review becomes theatre. A reviewer whose verdict is advisory is a reviewer whose verdict will be skipped on the day it matters, because the day it matters is also the day someone is in a hurry.

  • The reviewer did not write the artifact it is grading
  • The reviewer is not rewarded for the artifact passing
  • A negative verdict has a real consequence, not an advisory one
  • The verdict is recorded and visible at the point of decision
  • Overriding the verdict is possible, attributed, and logged

Why override must remain possible

It is tempting to make a failed review an absolute block. This is a mistake, and it fails in a predictable way: the first time the reviewer is wrong about something urgent, someone disables the reviewer. Now there is no review at all, and the disabling was done under pressure by whoever had the credentials.

A gate that can be overridden, where the override is attributed to a person and permanently recorded, survives contact with reality. A gate that cannot be overridden gets removed.

The recording is the load-bearing part. An override nobody can see later is the same as no gate; an override with a name and a timestamp attached is a decision someone owns.

Design for the override you will need at 2am, or you will get the deletion you cannot undo.

The reviewer is not the last line

None of this makes the reviewer authoritative. It makes it useful. The verdict is one input into a human decision at the deploy gate, and the human retains the accountability — that is not a limitation of the design, it is the design.

The failure mode to avoid is a team that stops reading verdicts because the verdicts are usually fine. That is the same trap as the green build: a signal that is almost always positive stops carrying information. The counter is to keep the gate a real decision, with a real person, who is expected to be able to say why they approved.

Put an intent in and see what comes back.

Every run produces a plan, a build, an independent review, and a gate you control.