Collaboration cycle

Engineering and Security Staging Review

Last updated: September 9, 2026

Waiver available: No

Recommended timing: Schedule once your product is production-ready and all required artifacts are complete

How this touchpoint helps you, VA, and Veterans

An Engineering and Security Staging Review is your last checkpoint before launch. Use it to confirm your product meets the Platform QA Standards, and Engineering and Security Standards — before Veterans use it. This gives you one more chance to catch issues before Veterans use your product, so you can launch with confidence.

This touchpoint is required for any product that does not result in visible changes to the Veteran experience or is built for Organizations.

This isn’t the right review for you if:

  • You're making changes Veterans can notice. Instead, complete a Staging Review.

Not sure which applies? Review the touchpoint flowchart or tag @platform-governance-team-members in your team's Slack channel.

No GitHub ticket yet? Start with a Collab Cycle kickoff first.

What you need to bring

Complete these artifacts before you schedule your Staging Review meeting. They’ll need to be complete and unchanged while the Platform conducts their review (4 working days before your meeting).

Engineering and Security Staging Review artifacts

Artifact

Required?

What to include

Engineering and Security Checklist

Required

Update the Engineering and Security Checklist based on this feedback provided at Architecture Intent. If you’ve updated this document, mark with the word “UPDATE” in bold, all-caps as well as the time and date of the update.

Pull Requests for this work

Required

List all PRs created for this work

Scoped code links

Required

Provide links to relevant code changes

System / Backend flow diagrams

Required

Link diagrams showing backend logic, data flow, or system interactions

Incident response plan

Required

Link or description of your Incident response plan

Functional monitoring dashboards

Required

Provide links to monitoring dashboards

QA Artifacts

Required

Artifacts that correspond to each of the QA Standards

Updated release plan

Required

Link to your updated release plan with all sections complete

Product access instructions

If applicable

Direct link or instructions for accessing your product in staging. Required if FE surfaces are impacted by engineering changes (e.g., API changes, FE error handling)

Link to production, if this work is already released and the staging environment includes unreleased work.

Test users

If applicable

Only required if FE surfaces are impacted by engineering changes

Figma mockups

If applicable

Only required if FE surfaces are impacted by engineering changes

You’re ready for this touchpoint when

  • You’ve completed an Architecture Intent touchpoint

  • All test scenarios can be successfully navigated

  • All required artifacts (listed above) are complete

How to schedule your review

  1. Create a ticket
    Click "Initiate an Engineering and Security Staging Review" in your Main Collab Cycle ticket to generate an Engineering and Security Staging Review GitHub ticket

  2. Add your artifacts
    Add links to your artifacts in your Engineering and Security Staging Review GitHub ticket before scheduling your meeting

  3. Book a time
    Click the Calendly Engineering and Security Staging Review calendar link in your GitHub ticket when you’re ready to schedule

Anyone on your team can do this — no specific role is required.

How to prepare for your review

  • Test your scenarios first — an untestable scenario may cancel your review

  • Do not merge changes to VA.gov or test users for 4 working days before your meeting while Platform conducts its review

  • Confirm your product is live on an approved staging environment

What happens during the meeting

Format: 30-minute Microsoft Teams meeting, hosted by the Platform Engineering Team and recorded

Who should attend: Your product manager, Gov Lead, and anyone who contributed to the artifacts

Who else attends: Relevant Platform participants and Gov Leads, invited by the Governance Team

Agenda:

  1. Welcome and team updates

  2. Platform Engineering and Security findings

  3. Launch-blocking tickets, if any

  4. Non-launch-blocking tickets, time permitting

  5. Your questions

What to expect: Top findings are shared live.

Two types of findings:

  • Launch-blocking — must fix before launch. Examples: QA standards issues, imposter components, severe accessibility defects (a11y-defect-0/1), major deviations from Experience Standards.

  • Non-launch-blocking — worth fixing, doesn't stop launch. Examples: typos, inconsistent link behavior.

Too many findings? At 25+ total or 10+ launch-blocking, we'll pause, share what we found, and ask you to schedule a second Staging Review.

What happens after the meeting

  • A link to the recording will be in your Staging Review ticket.

  • Engineering and Security feedback will be added as a comment on your GitHub ticket by the end of the day.

  • Fix all launch-blocking findings before you launch.

  • If a second review is required, resolve as much as you can and retest thoroughly before rebooking.

  • A Post–Staging Review Checklist ticket with your remaining pre- and post-launch tasks, including a VA 508 Office Audit Request after launch, will be created. Complete everything that applies.

Waiver process

A waiver is not available for Engineering and Security Staging Reviews. Every team whose work does not result in visible changes to the Veteran experience or is building for Organizations must complete this touchpoint before launch.