Understand risk grades
Read the risk grade on a change, its supporting evidence, and the difference between no risk and not assessed.
ArchDev helps you decide where to spend review time. A grade is a prompt to inspect the change and its evidence, not a guarantee that the code is correct or that tests and approvals can be skipped.
What the grade means
A risk assessment considers two questions:
- Uncertainty: How much remains unproven about whether the change will work? Relevant tests and established patterns reduce uncertainty; missing integration coverage can increase it.
- Consequence: If the change goes wrong, what can happen to users, data, access, or development? A change can be well tested and still have serious consequences if it fails.
Each question is assessed as low, medium, or high. When both have been assessed, ArchDev combines them with a fixed rule:
| Uncertainty ↓ / Consequence → | Low | Medium | High |
|---|---|---|---|
| Low | Low | Low | Medium |
| Medium | Low | Medium | High |
| High | Low | High | Critical |
For example, a well-tested change to a critical access path can still be medium because its consequence is high. Critical requires both high uncertainty and high consequence. The grade does not come from the number of files changed. Read the reasons, test boundaries, and limitations alongside it.
Grades in a review
- Low: Nothing in the assessed change calls for extra attention beyond normal review. Still read the diff and check the tests.
- Medium: Look closely at the indicated files or hunks and the assumptions behind them.
- High: Review the failure path and its safeguards carefully before proceeding.
- Critical: Both important behavior and serious potential harm remain uncertain; resolve the gaps or make a deliberate decision with the right reviewers.
The review may also show risk labels on individual changed ranges and a short Start here list of the most important places to read. A range label points to a concrete concern in that part of the diff; it is not a separate assessment of the entire pull request. You can leave feedback on the relevant lines for your agent.
No risk means a reviewed change has no notable risk flagged in that view. Not assessed (or a missing grade) means there is not enough assessment to assign one. Not assessed is not low risk. Analysis can also be pending, skipped, or unavailable; review the change yourself rather than treating an absent badge as approval.
Grades and annotations refer to a particular change or pull-request head. After new commits, inspect the latest revision rather than relying on the previous grade.