19 December 2024 / Applied AI / 8 chapters

Tie the release evidence to the actual configuration

From Production readiness for applied AI

A production approval should point at a specific configuration: the application version, model identifier, prompt version, tool and permission configuration, source index version, evaluation set and operating procedures. If any of those change materially after approval, you may need to refresh the evidence.

Run the release evaluation through the full configured path. Include ordinary tasks, missing information, conflicting sources, unauthorised requests, invalid output, tool failure and recovery. Report results by task family and by critical failure type, because a combined pass percentage can't tell you whether a dangerous path is still open.

Check the operating arrangements alongside the test results. Name the reviewer group, the expected queue, the support owner, the incident contact, the source owner and the person who's allowed to pause the feature. Make sure those people actually have access before launch. If the runbook lives somewhere they can't get to during an incident, it isn't finished.

For a practical readiness review, I'd ask for evidence that:

  • Supported users, tasks and exclusions are enforceable.
  • Permissions match the task and have been checked in the target systems.
  • Sources have owners, provenance and visible ingestion state.
  • Critical output and tool failures have containment tests.
  • External actions are idempotent or reconcilable.
  • Monitoring shows incomplete and unknown work.
  • Support can investigate and recover a prepared failure.
  • The approved configuration can be identified and rolled back.

Record any accepted limitations with an owner and a review date. I'd push back on phrases like "monitor closely" unless someone has specified the monitoring signal, threshold and response. If a control depends on manual review, check that the interface shows the reviewer enough evidence and that they've got time to use it.

Where it reduces risk and gives you useful operating evidence, roll out to a limited group or volume first. Keep a configuration switch that stops new work without wiping current state, so that pausing still leaves submitted and unknown actions available for reconciliation.

All articles