Technology
| Field | Detail |
|---|---|
| Owner | Saqlain Raza, CTO |
| CDO Oversight | Daniel O'Reilly, Chief Digital Officer |
| Effective Date | 14 April 2026 |
| Review Date | 14 July 2026 |
| Status | Active |
Executive Summary¶
This plan sets out the Technology group's priorities for the first 90 days under the new CDO leadership structure. It covers three sub-teams - Solution Engineering, Platform Engineering, and Production Engineering - and is organised around three interlocking themes: shipping discipline, platform maturity, and engineering quality.
The immediate priority is landing SDLC v2.0 across all seven tribes. This replaces two-week sprints, a separate QA gate, and manual CAB releases with a Kanban continuous delivery model in which engineers own quality end to end and deployments to production are gated by automated pipelines rather than committee approval. By the end of the 90-day period the group is expected to demonstrate daily deployment capability, a live DORA metric baseline, and the first deliverable of the Transaction Lifecycle Architecture programme.
Progress will be tracked against four DORA metrics - deployment frequency, lead time for change, mean time to restore (MTTR), and change failure rate - none of which are currently measured. Establishing that baseline is the single most important analytical task in the first 60 days.
Team Overview¶
The Technology group comprises three sub-teams. All operate within the SDLC v2.0 framework published April 2026.
| Sub-team | Head | Headcount scope | Primary mandate |
|---|---|---|---|
| Solution Engineering | Saqlain Raza (CTO) | 7 tribes (Portal, Pay-Ins, Pay-Outs, and merged cross-functional squads) | Feature delivery, product engineering, tribe-level quality ownership |
| Platform Engineering | Muhammad Mohsin | CI/CD, infrastructure, databases, developer tooling | Build and maintain the delivery platform that tribes ship through |
| Production Engineering | Muhammad Owais Khalid | On-call, monitoring, incident response, SRE practices | Production reliability, incident lifecycle, uptime and latency SLOs |
The previous fragmentation of Solution Engineering into isolated Portal, Pay-Ins, and Pay-Outs silos is being resolved through the tribe model. Each tribe is a self-contained, cross-functional unit responsible for its own test coverage, deployment cadence, and incident ownership.
30-Day Plan: 14 April - 14 May 2026¶
Theme: Foundation — SDLC v2.0 Adoption and Pipeline Audit
The first 30 days are about establishing the operational baseline. Every tribe must be on Kanban boards, the CI/CD pipeline must be audited for gaps, and the transition away from sprint ceremonies must be underway.
| # | Deliverable | Owner | Success Metric |
|---|---|---|---|
| 1 | SDLC v2.0 kickoff workshops completed for all 7 tribes | Saqlain Raza | All tribe leads sign off on transition plan by 30 April |
| 2 | Kanban boards live in Jira for all tribes, replacing sprint backlogs | Saqlain Raza + tribe leads | Zero active sprints remaining by 14 May |
| 3 | CI/CD pipeline audit completed across all repositories | Muhammad Mohsin | Audit report delivered; gaps classified by severity |
| 4 | DORA metric instrumentation plan finalised | Muhammad Mohsin + Muhammad Owais Khalid | Tooling selected, data sources identified, instrumentation timeline agreed |
| 5 | CAB process formally retired; deployment authority delegated to tribes | Saqlain Raza | Final CAB meeting held; new approval matrix published |
| 6 | Threat modelling gate added to SDLC template (pre-development mandatory) | Saqlain Raza | Template updated; tribes trained; first threat model produced by one tribe |
CI/CD Target Pipeline Architecture¶
The audit in this period will validate that every repository's pipeline conforms to the following stage sequence. Any stage missing or manual must be flagged for remediation in the 60-day period.
flowchart LR
A[Commit] --> B[Build]
B --> C[Unit Tests]
C --> D[Security Scan\nSnyk]
D --> E[Integration Tests]
E --> F[Staging Deploy]
F --> G[Prod Deploy]
style A fill:#4A90D9,color:#fff
style D fill:#E8733A,color:#fff
style G fill:#27AE60,color:#fff
Key constraints for pipeline compliance: - Security scan (Snyk) must run before integration tests - no promotion without a passing scan - Staging deploy must be automated and environment parity with production is required - Prod deploy requires automated smoke tests post-deploy; rollback must be scripted
60-Day Plan: 15 May - 13 June 2026¶
Theme: Quality and Reliability — DORA Baseline, TLA Phase 1, Security Shift-Left
With the SDLC transition underway, the second period focuses on measuring what we now have and delivering the first major engineering programme milestone.
| # | Deliverable | Owner | Success Metric |
|---|---|---|---|
| 1 | DORA baseline published (all four metrics, all tribes) | Muhammad Mohsin + Muhammad Owais Khalid | Dashboard live; baseline numbers documented in engineering wiki |
| 2 | Transaction Lifecycle Architecture Phase 1 shipped (state machine + audit log) | Saqlain Raza | Feature deployed to production by 31 May 2026; audit log queryable |
| 3 | Snyk integrated into all tribe CI/CD pipelines | Muhammad Mohsin | 100% of repositories scanning on every PR; critical CVEs blocked from merge |
| 4 | Integration Pattern Library v1 published (4 archetypes: aggregator-led, direct bank, wallet-first, hybrid) | Saqlain Raza | Library published to engineering wiki; adopted by at least 2 tribes in active work |
| 5 | Production on-call runbooks reviewed and updated for all critical services | Muhammad Owais Khalid | Runbooks cover all P1 services; on-call rotation confirmed with no single points of failure |
| 6 | ADR governance process operationalised (79 ADRs already documented) | Saqlain Raza | New ADR review cadence in place; at least 3 new ADRs raised and approved in the period |
90-Day Plan: 14 June - 13 July 2026¶
Theme: Maturity — Daily Deployment, Architecture Standards, DORA Targets
The final period is about demonstrating that the delivery system works at the standard the business requires. Daily deployment capability is the headline target; DORA metric improvement against the baseline confirms whether the SDLC change is delivering value.
| # | Deliverable | Owner | Success Metric |
|---|---|---|---|
| 1 | Daily deployment capability demonstrated across at least 4 tribes | Saqlain Raza | Deployment frequency greater than or equal to 1 per day per tribe over a 2-week period |
| 2 | DORA targets hit or trajectory confirmed | Muhammad Mohsin + Muhammad Owais Khalid | Lead time for change under 24 hours; MTTR under 1 hour; change failure rate under 5% |
| 3 | Architecture Standards document published and adopted | Saqlain Raza | Standards ratified by CDO; all new work referenced against standards from July onwards |
| 4 | Security shift-left fully embedded: threat modelling completed for all active features | Saqlain Raza | No feature enters development without a threat model on record |
| 5 | Platform Engineering roadmap for H2 2026 presented to CDO | Muhammad Mohsin | Roadmap covers database scaling, observability, and developer experience improvements |
| 6 | Production Engineering SLO targets set for all critical payment corridors | Muhammad Owais Khalid | SLO targets agreed with product; error budget policy documented |
Programme Gantt¶
gantt
title Technology Group — 30/60/90-Day Plan
dateFormat YYYY-MM-DD
axisFormat %d %b
section 30-Day (Foundation)
SDLC v2.0 tribe kickoffs :done, sdlc, 2026-04-14, 2026-04-30
Kanban boards live (all tribes) :active, kanban, 2026-04-14, 2026-05-14
CI/CD pipeline audit :active, audit, 2026-04-14, 2026-05-07
CAB retirement and delegation : cab, 2026-04-21, 2026-05-14
Threat modelling gate added : threat, 2026-04-21, 2026-05-14
DORA instrumentation plan : dora1, 2026-04-28, 2026-05-14
section 60-Day (Quality)
DORA baseline published : dora2, 2026-05-15, 2026-06-07
TLA Phase 1 shipped :crit, tla, 2026-05-15, 2026-05-31
Snyk in all pipelines : snyk, 2026-05-15, 2026-06-07
Integration Pattern Library v1 : ipl, 2026-05-15, 2026-06-13
On-call runbooks reviewed : oncall, 2026-05-15, 2026-05-31
ADR governance operationalised : adr, 2026-05-15, 2026-06-13
section 90-Day (Maturity)
Daily deployment demonstrated :crit, deploy, 2026-06-14, 2026-07-13
DORA targets hit :crit, dorat, 2026-06-14, 2026-07-13
Architecture Standards published : arch, 2026-06-14, 2026-06-30
Security shift-left embedded : sec, 2026-06-14, 2026-07-13
Platform H2 roadmap presented : plat, 2026-06-28, 2026-07-13
SLO targets set (corridors) : slo, 2026-06-14, 2026-07-07
Success Metrics¶
All four DORA metrics are currently unmeasured. The table below sets out the baseline expectation after 90 days.
| Metric | Current State | 90-Day Target | Notes |
|---|---|---|---|
| Deployment Frequency | Unknown (sprint-based, ~fortnightly) | Daily per tribe (at least 4 tribes) | Measured per tribe, not per monolith |
| Lead Time for Change | Unknown | Under 24 hours | From commit merge to production |
| Mean Time to Restore (MTTR) | Unknown | Under 1 hour for P1 incidents | Requires runbooks and on-call maturity |
| Change Failure Rate | Unknown | Under 5% | Snyk and automated tests are the primary controls |
Baseline numbers will be published at the end of the 60-day period. Targets above will be revised if the baseline reveals a significantly different starting point.
Dependencies and Risks¶
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| Tribe resistance to Kanban transition | Medium | High | Executive sponsorship from CDO; tribe lead involvement in kickoff design |
| TLA Phase 1 scope creep delays May delivery | Medium | High | Scope locked to state machine and audit log only; no additional features in Phase 1 |
| Snyk integration blocked by legacy pipeline tooling | Low | Medium | Pipeline audit in 30-day period will surface this; remediation time built into 60-day window |
| DORA instrumentation requires tooling procurement | Low | Medium | Instrumentation plan agreed in 30-day period; procurement fast-tracked if needed |
| On-call single points of failure | Medium | High | Rotation audit in 60-day period; cross-training plan if gaps found |
This document is reviewed monthly by the CTO and CDO. It is a living plan and will be updated as context changes.