What stages take a custom software project from approval to production?
Stages may be combined or repeated, but a custom project must leave inspectable evidence for scope, design, tested code, release, and handover. Wavesteam does not force every project through five waterfall steps. A small change can combine discovery and design; a complex system may cycle through prototypes and increments. At every gate, both sides know what is confirmed, what remains risky, who decides, and how the result can be inspected.
Begin with target user, business outcome, first-release scope, exclusions, and a client decision owner. Test the most dangerous process, data, interface, device, or compliance assumption. Develop runnable increments rather than waiting for every page before integration. Release readiness includes migration, accounts and qualifications, monitoring, backup, and rollback. Production observation closes residual work and leads to asset transfer or operations.
When planning milestones, resources, and acceptance, also compare Does Wavesteam continue supporting a system after it goes live? and How should the process and service scope of a large software project be defined?; the linked guidance adds context that should be considered in the same decision.
| Gate | Key question | Inspectable artifact | If not satisfied |
|---|---|---|---|
| Goal and scope | Who obtains what first-release value, and what is excluded? | Scenarios, scope, acceptance principle, dependencies, owners | Continue discovery; do not start on a vague total price |
| Solution and risk | Do workflow, data, interface, and route work? | Prototype or proof, fields, interfaces, risk, estimate baseline | Reduce scope, change route, or stop |
| Runnable increment | Can the core task complete end to end? | Version, source, environment, tests, changes | Fix or replan; do not hide a broken chain behind percentage |
| Release readiness | Are production and recovery ready? | Acceptance, migration reconciliation, alerts, recovery, release plan | Delay, stage, or explicitly accept residual risk |
| Operation and handover | Is it stable and does the client control the assets? | Running evidence, issues, accounts, documents, training, revoked access | Extend observation or complete transfer |
Prototype, UI, engineering, and testing need not finish sequentially. After the main path is understood, build a vertical slice. Testing begins with requirement examples, interface contracts, and automation. Security and operations enter the definition of done during design. The Scrum Guide supports usable increments and a definition of done without changing the need for contractual scope.
An artifact must be usable, not merely named. Requirements link roles, rules, and examples. Prototypes include core exceptions. Designs specify components and states. Source builds in the agreed environment. Interfaces contain request, response, and errors. Test reports name version, environment, scope, and failures. The receiving team rehearses deployment rather than accepting a file labelled “deployment guide.”
Acceptance is not one final signature. A phase review accepts its evidence without removing the right to report a real later defect. A new rule after a confirmed prototype is assessed as change; implementation that deviates from the accepted flow remains a delivery issue. Record version, comments, decision, and owner to avoid both “you signed, so nothing can be corrected” and “I mentioned it verbally, so it is free.”
Release gates cover core tasks, severe defects, migration reconciliation, access, security, performance baseline, monitoring, tested restoration, rollback, platform accounts, and response contacts. The depth differs by risk, but omitted controls need a reason. Observe business success, errors, latency, and support after release rather than declaring the project complete at deployment.
Wavesteam supplies a visible build and evidence index at every gate while the client controls code, accounts, and data. Final transfer includes assets, versions, build and deployment, architecture and data, suppliers, monitoring and backup, residual risk, and operations boundary. The same evidence becomes an operations baseline or reduces rediscovery for a new team.