Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Draft status

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Governance, Ownership & Risk

Draft status marks a pull request as not yet ready for human approval. It keeps the machine in the loop while it validates its own changes, which is important when CI feedback or follow-up edits are still needed before review.

What Draft Status Means in a Pull Request

Draft status is a workflow state that tells reviewers the change is not yet ready for approval. It keeps the review loop open while the author is still validating code, gathering CI signal, or making follow-up edits that would make a formal review premature.

Why Draft Status Exists

The main purpose of draft status is to separate work in progress from a change that is being actively approved for merge. That distinction matters because reviewers can focus on completeness and risk only when the author has signalled that the pull request is stable enough to assess seriously. In practice, draft status reduces review churn and helps prevent partial implementation details from being treated as final.

Draft status is also a coordination signal. It tells collaborators that comments may be premature, that checks may still be failing for known reasons, and that the request is still being shaped rather than accepted as a finished candidate for integration.

How Draft Status Changes Review Behaviour

When a pull request is marked draft, the platform usually withholds or de-emphasises approval workflows until the author converts it to a ready state. That changes the social and operational meaning of the request: the team can still inspect it, discuss it, or run automation against it, but the branch is not being presented as ready for final human sign-off.

This matters most when CI is still noisy or when the author expects another iteration after feedback. A draft request creates a cleaner handoff between building and reviewing, which helps keep review comments focused on substance rather than on obvious incomplete work.

Draft Status in Secure Delivery Workflows

Draft status is especially useful in security-sensitive delivery pipelines because it helps ensure that control checks happen before approval is requested. If the change touches authentication, authorization, secrets, or other sensitive components, the draft state gives the author room to verify behaviour before asking a reviewer to bless the result. For related control thinking, teams often map the review stage to broader NIST Cybersecurity Framework 2.0 governance and assurance practices.

It also aligns well with change discipline in secure software delivery, where the goal is to avoid treating unfinished code as production-ready simply because it has been opened in a collaboration tool. The draft flag is not a security control by itself, but it is a useful guardrail against premature approval and accidental merge readiness.

Common Misunderstandings About Draft Status

Draft status does not mean the work is low quality, and it does not mean the change is invisible. It means the author is explicitly signalling that the request is incomplete or still under validation. Reviewers can still inspect it for awareness, but they should understand that comments may need to be revisited once the request becomes ready.

Another common mistake is assuming draft status replaces CI or policy enforcement. It does not. Automated checks, branch protections, and approval rules still do the actual gating; draft status simply helps the team apply those gates at the right moment in the review lifecycle.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, OWASP SAMM and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-03 — Cybersecurity Supply Chain Risk ManagementDraft status supports staged control of change readiness before review and merge.
Recommendation — Use draft status to delay approval requests until change validation and review prerequisites are met.
OWASP SAMMSAMM Governance — GovernanceDraft status reflects a controlled transition from work in progress to review-ready software delivery.
Recommendation — Define when pull requests may move from draft to ready so review gates are applied consistently.
NIST SP 800-53 Rev 5CM-3 — Configuration Change ControlDraft status helps distinguish incomplete change sets from approved configuration changes.
Recommendation — Require readiness review before converting draft code into an approvable change.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org