A PR gate is a required check on a pull request that must pass before merge. In Azure DevOps, branch policies on protected branches enforce this: required reviewers, linked work items, build validation, and external status checks that services post against the PR. Security scanners use the status-check surface to gate merges on the diff's findings.
Why the PR is a powerful surface
- Feedback lands while the developer still has context — the cheapest moment to fix.
- The insecure change never enters the protected branch, so nothing downstream inherits it.
- Statuses are visible in review, making security part of the code conversation.
PR gates vs build gates
PR gates evaluate the diff before merge; build gates evaluate the assembled artifact before shipping. Each catches what the other misses — post-merge interactions on one side, late feedback on the other. The failure mode to avoid is two gates with two policies producing contradictory verdicts.

