Feature Flag
also called Feature Toggle
A runtime switch that separates deploying code from releasing behaviour.
The core value is decoupling two events that are usually welded together. Deployment becomes a low-risk technical act; release becomes a business decision, reversible in seconds without a build. That reversibility is the reason flags reduce change failure rate: the remedy for a bad release stops being a redeploy under pressure.
Flags are not one thing, and conflating the kinds is where the mess starts. Release flags are short-lived and must be removed after rollout. Experiment flags live for the duration of a test. Operational flags — kill switches, load-shed levers — are permanent and belong to operations. Permission flags gate entitlements and are really product configuration.
The failure mode is accumulation. Every flag is a branch in the code, and n flags is 2^n theoretical paths, almost none of them tested. Untended flag debt produces genuinely bizarre incidents where a combination nobody imagined becomes reachable. Treat a release flag with an expiry date as non-negotiable, and fail the build on flags older than the limit.
Also: flags in the request path are a dependency. If the evaluation service is down, the default must be safe and local.