Maintenance window policy: rules for the hours when change is allowed

A maintenance window is where scheduled risk is supposed to live — the hours when it is legal to break something on purpose. At small teams it usually decays into one of two lies: a calendar event so vague it means "whenever we get to it," or a rule so strict that admins quietly work around it. The patch cadence calendar decides when the window happens; this page is the policy for the hours themselves — the four rules every window runs on, when a window is actually required, how emergency work ratifies after the fact, and the one-line log that makes eleven consecutive windows look like the change process auditors and customers ask about.

1. The four rules every window runs on

2. When a window is required — and when it is theater

3. Freezes, holidays, and collisions

4. Staffing: the second awake human

5. The paper trail that makes the window real

Small-team honesty note: a five-person company does not need a change advisory board; it needs a recurring calendar event, a notice template, a written plan per window, and one log file. The trap this page exists to prevent is window theater — a recurring event that never has a plan, notices nobody sends, overruns nobody logs. If the notice for the next window is not drafted as you read this, the window is still a hope with a slot in the calendar. Send the notice, run the first window ugly, and let the log make it real.

Related: delegation of authority · patch cadence calendar · patch management checklist · change freeze window policy · change management checklist · severity matrix · deployment rollback checklist · status page template · vendor outage runbook · on-call rotation · on-call handoff · downtime budget · SLA/SLO definition · weekly status report · first 30 minutes