Write policies as tests using OPA and Conftest, starting in warn-only mode. Developers see exact failures with examples and remediation notes. When noise settles, flip to blocking. Hosting policy code beside services encouraged contributions, peer reviews, and small experiments that evolved rules without stalling feature work.
Protect main branches with required checks, minimal reviewers, and size limits that encourage focused changes. CODEOWNERS clarifies responsibility without endless pings. By encouraging small pull requests and labeling security-sensitive files, we cut review delays dramatically while raising quality and accountability in the parts that truly matter.