World Congress 2026 North America

Earning the Right to Deploy: Netflix's Approach to Deployment Safety at Scale

September 25, 2026 15:30 – 16:00 · 30 min Stage 3

What this session covers

At some point, all organizations will hit a similar point. A high-risk time frame exists for each org when a single poor deployment can lead to disaster (holiday peak periods, new product launch times, etc.) In many cases, the first response to such situations is to call for a complete deployment lockdown. Freeze everything. Just wait until things are safer. Unfortunately, such freezes cause problems of their own: emergency patches get blocked, panic releases occur prior to the lockdown, engineers begin treating safety gateways like bureaucratic hurdles they need to find ways around.

We posed the question differently. How can we set up our systems so deployments automatically pause at the correct time, and how can we make bypassing eligibility a team-earned privilege rather than simply available to all? This talk is a technical dive into Quiet Period Automatic Protection, the system Netflix developed to replace raw trigger suppression with intelligent, stage-level deployment safety. We will go over how we moved from ‘stop the pipeline’ to ‘pause the right stage at the right time with surgical accuracy’. The presentational topics include how the system determines production impact without requiring manual setup, how it dynamically adds protection to already running deployments, how it will handle multiple-region deployments that may last hours, and how every override is treated as an auditable learning opportunity rather than just a liability.

This architectural shift transforms the mechanism of safety. By mandating a justification for every override, we convert raw bypasses into high-fidelity, auditable learning signals. Monitoring these patterns allows the system to act as a barometer for organizational strain, surfacing latent risks before they manifest as outages. Furthermore, we linked bypass eligibility to proven deployment health metrics, ensuring high-velocity teams maintain autonomy while others remain shielded. This “safety by default, freedom by merit” philosophy was battle-tested during our 2025 peak holiday window. I will detail our findings from this high-pressure period, examining where our logic proved resilient and where we recalibrated, demonstrating why designing for dynamic adaptation is superior to static lockdowns.

Related talks at this congress

Open session

World Congress 2026 North America

September 24, 2026 · 13:40–13:50

Outdoor Stage

The Autonomous Performance Agent: A Netflix Production Story

Rajat Shah

Staff Software Engineer, AI Platform, Netflix

Rajat Shah
Open session

World Congress 2026 North America

September 24, 2026 · 14:10–14:40

Stage 3

Real-Time Data Platforms at Trillion-Event Scale

Diptamay Sanyal

Principal Engineer | Data, AI & Cybersecurity Platforms

Diptamay Sanyal
Open session

World Congress 2026 North America

September 25, 2026 · 15:45–15:55

Outdoor Stage

Closing the Visibility Gap: Lessons from Safety Critical Agentic Systems

Vivek Pandit

Frontier AI Lead at Turing

Vivek Pandit
Open session

World Congress 2026 North America

September 25, 2026 · 11:00–11:30

Mainstage

Govern the Runtime, Not the Agent: One Control Plane for Every Model, Every Harness

Tushar Jain

Chief Technology Officer, Docker

Tushar Jain
All sessions at this congress