Skip to content

Estate completion control — production proof, consolidation, and retirement gates #1806

Description

Objective

Close the difference between a working public command demonstration and a durable, authenticated, observable production estate. No item is complete without source, deployment, and live evidence.

Landed or actively merging

  • Killinchu Defend plane merged as the sole Aegis/Sentra public runtime surface.
  • Vessels folded into Killinchu public topology.
  • A11oy publisher admits only Terra, Counsel, Finance, and Lyte as independent vertical front doors and records Sentra/Vessels as folded into Killinchu.
  • Vertical-services taxonomy change prepared to classify Sentra as a capability plane, Aegis as a portfolio label, and IMMUNE as migration-required.
  • Canonical public-estate manifest and fixed-origin live witness prepared with immutable receipts.

P0 — required before the word production

  • Exact merged source is live for A11oy, Killinchu, Lyte, Finance, Terra, and Counsel; every required route and Hugging Face revision matches its source receipt.
  • Killinchu Defend state is durable across rebuild, sleep, and rollback; backup and restore are exercised, timed, and receipted.
  • OIDC identity, tenant isolation, RBAC, requester/approver separation, session expiry, and audit-subject attribution are enforced outside public demonstration mode.
  • SLOs exist for availability, p95 latency, error rate, deployment freshness, connector freshness, and receipt-chain verification; alerts route to a named operator path.
  • All production secrets have metadata-only inventory, rotation owner, last-rotated timestamp, least-privilege scope, and a tested revocation path; values never enter receipts.
  • Public mode remains non-effecting. Any future effector requires a separately approved authority contract, target allowlist, two-person control, rollback, and live tripwire evidence.

P1 — estate completion

  • Snapshot SZLHOLDINGS/sentra, inventory secret key names without reading values, prove Killinchu /defend parity, record rollback window, then retire the duplicate Space.
  • Classify SZLHOLDINGS/aegis-assurance; retain only a distinct assurance contract that is not already served by A11oy or Killinchu.
  • Classify SZLHOLDINGS/david-leads; keep it outside the flagship estate unless it is an explicitly owned commercial workflow.
  • Inventory every remaining SZLHOLDINGS Space against the canonical manifest; no unclassified public Space remains.
  • Complete the IMMUNE migration gate: unique admission contract, signed-authority boundary, tripwire contract, rollback receipts, parity tests, and exact-source live witness.
  • Bind one governed inference route with model revision, tokenizer revision, benchmark suite, latency/cost envelope, fallback policy, PII boundary, and fail-closed behavior. Do not call an unbound plan inference.
  • Prove every official-source connector with fixed origin, schema contract, freshness budget, rate-limit behavior, attribution, degraded mode, and immutable observation receipt.

P2 — product and commercial readiness

  • Mobile and desktop journey tests at 320×568, 375×812, 768×1024, and 1440×900 for A11oy and all five public products; keyboard, reduced-motion, forced-colors, touch-target, overflow, and readable-table gates pass.
  • One developer quickstart, one operator runbook, one incident runbook, one backup/restore runbook, and one customer-facing trust page all match the exact deployed revision.
  • Tenant onboarding, usage metering, support boundaries, data retention, export/delete, licensing, and service ownership are explicit.
  • Investor metrics distinguish measured live usage from demonstrations, synthetic data, planned capacity, and projections.

Definition of done

A checkbox closes only with: protected-source SHA, green checks on that SHA, deployment revision, live route proof, rollback evidence where relevant, and an immutable receipt. A screenshot or README statement alone is not completion.

Signed-off-by: Stephen Lutar stephenlutar2@gmail.com

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    estate:p0Immediate security, data-integrity, or production-boundary defect

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions