Engineering metrics
DORA metrics without gaming them
By the CodPal team · Engineering intelligence
The four DORA metrics — deployment frequency, lead time for changes, change-failure rate, and time to restore service — are the closest thing our industry has to a shared language for delivery. They're also dangerously easy to game. The moment a number becomes a target on someone's review, people optimize the number instead of the outcome. That's Goodhart's law, and it quietly ruins most metrics programs. Here's how to get the value of DORA without the theater.
How DORA gets gamed
Every DORA metric has an obvious exploit. Reward deployment frequency and people split one change into ten trivial deploys. Reward short lead time and PRs get sliced so thin that review becomes meaningless. Punish change-failure rate and incidents stop getting logged. Chase restore time and teams close incidents before they're actually fixed. In every case the dashboard turns green while delivery gets worse.
Measure the four together, never one alone
DORA works because the metrics are in tension. Throughput (frequency, lead time) is balanced by stability (change-failure, restore time) — you can't safely juice one without the others moving. Looked at as a set, gaming shows up as a contradiction: deploy frequency spikes while change-failure climbs. That's why Deckgauge's engineering intelligence dashboards show all four side by side with Elite/High/Medium/Low tiers, not a single vanity score.
Keep it at the team level
DORA was designed to measure systems and teams, not individuals. Tie it to a person's performance review and you've built an incentive to game it. Keep it at the team level, use it to find where the delivery system is slow, and you remove the reason to cheat. (More on that in measuring engineers without surveillance.)
Be honest about proxies
Most tools quietly fudge the metrics they can't truly measure. If you haven't connected a deployment or incident source, "deployment frequency" and "restore time" are estimates — Deckgauge labels them as proxies rather than overstating precision. Honest numbers are the whole point; a metric you don't trust is worse than no metric.
Use it as a conversation, not a scoreboard
The healthiest teams treat DORA as a prompt: "lead time jumped last sprint — what changed?" rather than "you're Medium, fix it." Trends and questions beat rankings and targets every time.
Deckgauge is open source and runs in your own stack, so you can read exactly how each metric is calculated — no black box to game against. Deploy it free, or if you want help reading your numbers, book a Deckgauge Engineering Health Check.