---
alwaysApply: false
globs: ["**/*"]
description: "Ship new user-facing behavior dark behind a flag with owner, removal date and kill switch. Use when changing user-facing behavior."
---

# Feature Flag Delivery Gateway

- Decouple deploy from release: new user-facing behavior lands dark, behind a
  runtime flag, and activates by decision, not by merge.
- Every flag has one named owner and a removal date. A flag without both is
  technical debt the moment it merges.
- Ramp gradually: enable for a small cohort first, watch the health signals,
  then widen. Define the watch metric before the first ramp step.
- Keep a kill switch: turning the flag off must restore the previous behavior
  without a deploy and without data loss.
- State the rollback path before release. If off-switching cannot restore
  service, the change is not ready to release.
- Test both flag states. An untested off-path fails exactly when the kill
  switch is needed.
- Remove the flag once the behavior is fully released. Expired flags are
  dead branches that mislead every later reader.
- Never use one flag for two behaviors; independent risks need independent
  switches.
