Maturity Matrix
Capability 02 of 04 · Delivery Management

Merge & Deploy

How PRs flow from creation to production - throughput, automation, and conflict handling.

5
maturity levels
15
practices
15
guides
L1 · Stage 01Ad-hoc
L2 · Stage 02Guided
Criteria - what to measure
  1. 01Merge queue is implemented (GitHub merge queue, Mergify, or equivalent)
  2. 02Auto-rebase is enabled for PRs targeting main branch
  3. 03CD pipeline includes at least one gate (tests pass, security scan, approval)
  4. 04Merge conflicts are detected and flagged before review is requested
  5. 05Deploy frequency is at least daily
L3 · Stage 03Systematic
Criteria - what to measure
  1. 01Policy-based merge rules are enforced (OPA, branch protection, or equivalent)
  2. 02Deterministic merge ordering with conflict detection prevents concurrent merge failures
  3. 03PRs require a maximum of 2 CI rounds before merge (Stripe benchmark)
  4. 04Merge rules are versioned as code and reviewed when changed
  5. 05PRs exceeding 2 CI rounds are flagged for investigation
L5 · Stage 05Autonomous
Criteria - what to measure
  1. 01Merge throughput sustains 1,000+ merges per week
  2. 02Full autonomous pipeline: agent produces PR, CI passes, merge, deploy, observe - no human in the loop
  3. 03Rollback is agent-driven (agent detects regression, reverts, and opens fix PR)
  4. 04Mean time to rollback is under 5 minutes from anomaly detection
  5. 05Agent-driven rollbacks succeed without human intervention 95%+ of the time

Which level is your team at in Merge & Deploy?

The criteria above are what we check in a facilitated assessment. Run it yourself to place this capability, see which gates you have passed, and compare it against the other 3 in Delivery Management.

Start the assessment →

Other capabilities in Delivery Management