Purpose and scope
This policy defines the core working practices applied to software products and technology services developed or materially changed by Hosted Technology.
The methods and level of control applied are determined by the size and technical risk of the project, the data it processes, and the scope agreed with the customer.
Defining the need and scope
Before work begins, we consider the problem to be solved, target users, existing systems, technical dependencies, and success criteria. Assumptions and unresolved matters are stated clearly in the project record.
- Deliverables and out-of-scope matters are documented.
- Responsibilities, decision-makers, and acceptance criteria are defined.
- Data, integration, security, and operational risks are assessed before development.
- The effect of scope changes on the schedule and cost is considered separately.
Design and technical decisions
User flows, information architecture, and technical architecture are designed with the intended use, maintenance requirements, and compatibility with existing systems in mind. The rationale and known constraints of critical decisions are recorded.
- A prototype or technical proof of concept is prepared where appropriate.
- Technology choices consider not only how current a technology is, but also the team’s capabilities and the responsibility for operating it.
- Access, data flows, error handling, and the release method are treated as part of the design.
Development and quality assurance
Code changes are maintained in version control and undergo review and testing proportionate to the project’s risk. Test coverage is not identical for every project; it is planned according to the potential impact of the change.
- Functionality, accessibility, performance, security, and platform compatibility are checked to the extent required.
- Defects are prioritised according to severity and user impact.
- Test results and acceptance criteria are assessed before a release decision is made.
- If live data must be used in a test environment, masking and access rules are defined separately.
Release and change management
The release plan covers scope, responsibilities, dependencies, the rollback method, and post-release checks. A staged release or maintenance window may be used depending on the impact of the change.
- Required backup and recovery steps are verified before release.
- Relevant parties are notified in advance of critical changes.
- Core functions, error records, and service health are checked after release.
Live operation and maintenance
Error records, performance data, and user feedback from live operation are reviewed. Improvements considered appropriate are added to the product plan or maintenance scope.
Maintenance, monitoring, and support responsibilities are defined before project handover. Work that is not included in the service is quoted separately.
Security and data responsibility
Access is limited according to role requirements. Personal, commercial, or operational data is processed in accordance with project contracts, relevant policies, and applicable law.
No individual test or control is presented as a guarantee that a service will be error-free or uninterrupted. Identified risks, measures taken, and residual risks are shared with the relevant parties.
Review
This policy is reviewed when there is a material change to the relevant service, process, organisational structure, or applicable law. After any necessary revisions, the current text and revision date are published on this page.
