Product Management Craft · 18 min · 130 XP

Staged launches and the kill switch

Release in stages behind a flag, watch the guardrails, and know in advance what would make you turn it off.

Shipping to everyone at once is the riskiest possible way to learn whether something works. A staged rollout spreads that risk out: first the team itself, then a small share of real users, then more, watching the numbers at each step. Most teams do this with a feature flag, a switch in configuration that turns the feature on for chosen users without a new deploy, and off again in seconds.

A rollout plan, written before launch day
Stage 1  Internal team only            3 days
Stage 2  5% of team-plan accounts      1 week
Stage 3  50%                           1 week
Stage 4  Everyone

Watch      approved-invoice share (primary)
           time-to-send, error rate, support tickets (guardrails)
Roll back  if error rate > 1% or time-to-send rises > 2 min
Owner      Priya (on call during each stage change)

Decide the rollback rule before you start. On launch day, with the team proud of the work, every bad number looks like noise. Writing down beforehand “if the error rate goes above 1%, we turn it off” turns a judgement made under pressure into a check. The kill switch only helps if someone is watching and allowed to use it.

Some decisions are easy to reverse and some aren't. A UI change behind a flag can be turned off in seconds. A database migration that deletes a column, a pricing change customers have been emailed about, or a public API others have built on can't be undone cleanly. Move fast on reversible decisions and slowly on irreversible ones: the latter need more review, a longer rollout and a plan for the people affected.

Launch is not just the code. Before the flag reaches real users: support knows what's changing and has answers ready, help pages are updated, sales knows what they can promise, and the people who'll see a change in their workflow have been told. A feature that surprises the support team becomes a pile of tickets.

Do it this week: for the next thing you ship, write a rollout plan like the one above: stages, what you'll watch, the rollback rule and who owns it. Share it with support before stage two.

Loading your workspace…