Azure DevOps gives you two natural places to enforce security: the pull request — via branch policies and status checks — and the build pipeline. Teams often frame this as a choice. It is not; the two gates catch different failure modes, and the real design question is keeping their decisions consistent.
What each gate is good at
- PR gates: fast feedback on the diff, before insecure code merges; the developer is present and context is fresh.
- Build gates: authoritative verdict on the whole artifact, including dependencies resolved at build time; nothing ships around them.
- PR-only programs miss what appears after merge; build-only programs give feedback at the most expensive moment.
The consistency trap
When the PR check and the build gate run different tools with different thresholds, developers get contradictory verdicts — green PR, red build — and conclude the system is arbitrary. Every exception then has to be granted twice, in two configuration surfaces, by two owners.
One policy brain, two enforcement points
The sustainable design evaluates policy centrally and projects the same decision into both gates. Kangl manages PR-level controls and pipeline-level enforcement as delivery mechanisms of the same backend-authoritative policy: same normalized posture, same thresholds, same audit trail — whether the verdict lands as a PR status or a failed build.

