Article chapter 07 of 08
Assemble release evidence around the actual configuration
A production approval should point to a specific configuration. Record the application version, model identifier, prompt version, tool and permission configuration, source index version, evaluation set and operating procedures. If one of these changes materially after approval, the evidence may need to be refreshed.
The release evaluation should run through the full configured path. Include ordinary tasks, missing information, conflicting sources, unauthorised requests, invalid output, tool failure and recovery. Report results by task family and critical failure type. A combined pass percentage cannot explain whether a dangerous path remains open.
Confirm the operating arrangements beside the test results. Name the reviewer group, expected queue, support owner, incident contact, source owner and person authorised to pause the feature. Check that these people have access before launch. A runbook stored somewhere they cannot reach during an incident is unfinished.
A practical readiness review asks for evidence in these areas:
- supported users, tasks and exclusions are enforceable;
- permissions match the task and have been checked in the target systems;
- sources have owners, provenance and visible ingestion state;
- critical output and tool failures have containment tests;
- external actions are idempotent or reconcilable;
- monitoring exposes incomplete and unknown work;
- support can investigate and recover a prepared failure;
- the approved configuration can be identified and rolled back.
Record accepted limitations with an owner and review date. Avoid phrases such as "monitor closely" unless the monitoring signal, threshold and response are specified. If a control depends on manual review, confirm the interface shows enough evidence and that the reviewer has time to use it.
Roll out to a bounded group or volume where that boundary reduces risk and creates useful operating evidence. Keep a configuration switch that stops new work without destroying current state. Pausing should leave submitted and unknown actions available for reconciliation.