Give an engineering decision as much review as it needs to reverse—not the same process by default. Use a clear owner, a small review group and a time-box for decisions with a credible rollback path. Slow down, consult affected teams and document assumptions when a choice could be costly or impossible to undo, or could cause serious harm.
There is a naming trap: Bezos’s original shareholder-letter wording calls one-way doors Type 1 and two-way doors Type 2; a later Fast Company interview account reverses those numbers. The labels are inconsistent, so classify decisions by reversibility first and state which numbering convention you mean whenever you use Type 1 or Type 2.
What makes an engineering decision a one-way or two-way door?
A two-way door is a decision with limited consequences and a practical way back. A one-way door has significant consequences and is difficult, costly or impossible to reverse. AWS uses these descriptions in its executive guidance. The metaphor is useful because it asks what happens after the decision, rather than how impressive or complicated the proposal sounds.
Reversibility is not the same as whether a change can be reverted in source control. A code rollback may not undo a customer data loss, a contractual commitment, a safety incident or a migration that discarded the old format. Ask what it would actually take to restore the previous state: revert code, disable a feature flag, restore data, end a contract, reverse a migration or rebuild infrastructure.
#1 Best Overall
Do not treat the numeric labels as universal. Bezos’s original shareholder-letter terminology, as summarized by Axios, uses Type 1 for one-way and Type 2 for two-way decisions; the later Fast Company interview account calls one-way decisions Type 2 and two-way decisions Type 1. This article uses the door terms as the primary classification. If your organization uses numbers, record its chosen convention in the decision policy.
How much review does an architecture decision need?
Match the decision process to both reversibility and consequence. A choice may be technically reversible but still deserve senior review if a failure could expose sensitive data, endanger people or breach a regulatory obligation. Conversely, a significant-looking decision can move quickly if it is isolated, observable and easy to undo.
| Decision factor | More like a two-way door | More like a one-way door |
|---|---|---|
| Undo path | Rollback, feature flag or compatibility layer is available and executable. | Undo requires a major migration, data reconstruction, contract exit or rebuild. |
| Cost and time to undo | Small, bounded effort with little disruption. | High cost, long recovery or no credible route back. |
| Impact if wrong | Limited, observable effect on a small surface area. | Broad customer, team or business impact; safety, security or regulatory exposure. |
| Commitment | Little capital or long-term dependency is committed. | Substantial capital, external obligations or durable dependencies are involved. |
| Evidence and monitoring | Relevant metrics reveal failure quickly; a stop condition is defined. | Failure may be hard to detect, or rollback cannot be verified in advance. |
| Decision process | One accountable owner, a small review group and a short written rationale. | Alternatives and failure cases analyzed; affected teams consulted; assumptions recorded and senior approval assigned. |
This is a judgment aid, not a scoring formula. No universal numeric cutoff establishes when a decision becomes irreversible; teams should define local thresholds and explain the real exit path.
A practical process for calibrating decision ceremony
- Classify reversibility. Write down how the team would return to the prior state. Name the person or team able to execute that path, and distinguish a tested rollback from a theoretical one.
- Estimate consequences and blast radius. Consider customer harm, safety, security, regulatory exposure, data integrity, committed capital, dependencies and how many teams or users could be affected.
- Choose the review depth. For a bounded, reversible change, assign one owner, ask a small group for focused review and capture the context, decision and rollback or stop condition. For a hard-to-reverse change, compare alternatives, run a pre-mortem or failure analysis, consult affected teams, record assumptions and name an accountable senior approver. Stage validation where possible.
- Make reversibility operational. Instrument the change so monitoring can detect a problem quickly. Confirm that the rollback path is executable; where appropriate, rehearse it before rollout rather than relying on an untested promise.
- Time-box reversible decisions. Set a decision deadline and move with the evidence available when the downside is bounded and recovery is practical. Do not turn a two-way door into a committee process by waiting for certainty that will not change the decision.
How much information is enough before shipping?
For reversible decisions, waiting for complete information can cost more than learning from a controlled release. AWS’s 2022 guidance offers a rule of thumb: act with about 70% of the information desired, rather than waiting for 90% or more, when the decision is a two-way door. That is AWS guidance, not a measured universal threshold, and it does not mean shipping without safeguards.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Before acting, make sure the missing information is unlikely to change the risk category, the test has a bounded blast radius, and monitoring and rollback are in place. If the choice is hard to undo—or the downside involves safety, security, data integrity or regulatory exposure—use the time to resolve decision-critical unknowns and validate the exit plan. A percentage cannot substitute for that assessment.
Engineering examples: where the boundary changes
Feature-flag rollout
A feature flag with immediate rollback is usually a two-way door when the rollout is limited, metrics can reveal harm and an owner can disable it. AWS gives A/B testing a site-detail-page or mobile-app feature as an example of a reversible choice. Define the launch scope, success and stop conditions, and who can turn the change off.
Rank #4
API naming or an internal library
These choices are often reversible if a compatibility shim, migration plan and sunset date are part of the decision. A short decision record can capture the owner, trade-off and removal plan. Without a credible compatibility path, adoption across many teams can make a seemingly local choice expensive to undo.
Destructive database migration
A migration that destroys historical data may be a one-way door even if the application code can be redeployed. Validate backups, rehearse restoration, stage the migration and review the failure plan with an accountable senior approver before removing the old data.
Cloud region, data residency or long-term infrastructure contract
Treat these as one-way-door candidates when switching costs are high or external obligations constrain where workloads and data can move. Analyze alternatives and the exit path before committing; do not call a choice reversible merely because another provider or region exists in principle.
Safety-critical control logic or a security boundary
Elevate review when the consequences of failure are severe, even if a code revert is technically straightforward. Reversibility reduces some risk; it does not erase harm that can occur before rollback, nor does it replace domain-specific safety and security analysis.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to avoid both process failures
Do not put every decision through heavyweight governance
Applying the same extensive approval process to routine reversible choices slows action, encourages unthoughtful risk aversion and can reduce experimentation and invention. Amazon’s shareholder-letter discussion of the framework, summarized by Axios, warns about those effects. Keep the decision owner clear, limit review to people who can change the outcome and set a deadline when the downside is bounded.
Do not label a risky commitment an experiment
The opposite mistake is treating a hard-to-reverse architecture, data, safety or capital choice as though it were a harmless trial. A reversible interface change does not make an irreversible data deletion reversible; a rollback does not necessarily undo customer harm. If the exit path is vague, untested or dependent on another party, escalate the decision rather than assuming it is a two-way door.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Document enough to make the decision legible
For a low-ceremony choice, a brief record can state the problem, owner, chosen option, alternatives considered, rollback or stop condition and review date. For a high-ceremony choice, add material assumptions, affected teams, failure scenarios, validation evidence, approval and the conditions that would trigger a pause or reconsideration. The point is a usable record, not paperwork for its own sake.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




