Readiness position · Trial 1
NO-GO for live lender assignments. Stated by the platform, not about it.
Connecting the custom domain must not be read as the moment the system becomes live. Four prerequisites are unmet: MFA, malware scanning with a licensed engine, a rehearsed backup and restore drill, and database-level protection of the audit tables.
Build under review
The numbers the verdict rests on
Production-class records
00
no real lender file has ever run
Assignments
0184
130 synthetic · 54 trial
Audit entries
09,204
linkage intact, 0 breaks
Automated tests
0191
23 files · 7 explicitly outstanding
Unattended sweeps
0119
scheduler HEALTHY
TypeScript errors
00
pnpm check
Grading rules
Three rules stop this sheet degrading into a formality
UNKNOWN counts as RED
An unverified control is not a passing control. “The feature exists” is not evidence.
No self-certification
The person who built a control does not sign it off. Owner fields stay UNASSIGNED until a second party takes them.
No silent closure
A row moves to GREEN only with the stated evidence attached. Waivers are named, dated and reasoned in writing.
Gate console
Model the launch decision without touching the record
Launch gate console · projection only
Clear gates to see what the verdict would become. The record does not move.
Blocking gates
All ten must be GREEN before the first live assignment
| # | Gate | Verdict | Evidence required to turn GREEN | Owner |
|---|---|---|---|---|
| B-1 | MFA enforced for all internal staff | RED | Screenshot of enforced policy + one login refused without a second factor | UNASSIGNED |
| B-2 | Backup and restore drill completed | RED | Restore into a separate environment + audit chain verifies clean against the restored copy + measured RPO/RTO | UNASSIGNED |
| B-3 | Licensed AV engine behind the quarantine gate | RED | A known-malicious test file (EICAR) quarantined and blocked from certification | UNASSIGNED |
| B-4 | INSERT-only grants on audit tables | RED | SHOW GRANTS output + a direct UPDATE attempt refused by the database | UNASSIGNED |
| B-5 | Company controls all assets | RED | Hosting, repo, DB, domains, secrets, billing under company account, ≥2 admins | UNASSIGNED |
| B-6 | Off-platform backup exists | RED | Database + files export held outside the host platform, dated | UNASSIGNED |
| B-7 | Tenant isolation with live accounts | CONDITIONAL | Two live authenticated non-admin accounts; cross-tenant access attempted and refused on the deployed site | UNASSIGNED |
| B-8 | Named owner receiving scheduler alerts | RED | Monitor wired to a paging destination + one test alert acknowledged by a person | UNASSIGNED |
| B-9 | Baseline methodology agreed | RED | Operations sign-off on the baseline methodology proposal | UNASSIGNED |
| B-10 | External adversarial review | RED | Written findings from a reviewer who did not build the platform | UNASSIGNED |
Owner fields are deliberately unassigned. Filling them in from the build side would be the exact failure the no-self-certification rule prevents.
Gate matrix
Fifteen gates, graded in the environment they must work in
09
Exercised in the environment where it must work, with reproducible evidence
014
Implemented and tested, but bounded by a dependency or unexercised in production
011
Missing, or not evidenceable without access this environment does not have
03
Deliberately out of Trial 1 scope, prevented from becoming an accidental dependency
Controlled state integrity
Single write path, 42 guards, optimistic concurrency and hash-chained audit pass 142 automated tests; never exercised against concurrent real users
Scheduler durability
Persisted heartbeat, four states, external monitor and post-deploy probe are live and caught a real stall in production; the deploy-stall defect itself remains unresolved
Stop-work propagation
Cancellation is a declared transition requiring a named human approver; cure, bankruptcy, recall and legal hold are not yet distinct gated events
External isolation
No two real external accounts exist to attack. Cross-tenant isolation is unproven, and unproven is RED
Authentication and privilege
MFA is not configured; step-up authentication for critical actions does not exist
Document safety and integrity
Quarantine gate and hashing exist, but no malware engine is wired in; the previous hardcoded CLEAN status was a defect found and fixed this cycle
Audit immutability
Application layer verified clean by automated scan, 5,000+ entry chain verified unbroken; database-level INSERT-only grants not applied
Backup and restore
Procedure written; no restore has been performed and no RTO/RPO has been measured
AI authority
L0–L4 ladder with L4 prohibited, confidence-never-expands-authority enforced by invariant, kill switch admin-only; no external adversarial review performed
Security readiness
No vulnerability scan or penetration test has been run against this build
Trial observability
Scheduler health, incident module and audit integrity are observable; no alert routing to a named on-call human exists
Baseline and cohort integrity
Four-way record classification and versioned metric envelope enforced in code; pre-Trial baseline not agreed with Operations
Operations readiness
No named users trained; no rehearsal of pause/resume with real staff
Ownership and recovery access
Single-operator dependency; no documented company-level recovery of code, DNS, secrets and observability
Scope boundary
No money movement exists in code; finance is validation and routing only, and the AI decision recorder refuses any record claiming a protected-state change
Launch position: NO-GO. Four non-waivable gates are not GREEN and six P0 gates are RED.
Verified controls
What is genuinely done, with the evidence attached
Lifecycle kernel is the single write path
28 states, 38 transitions, 42 guards; illegal transitions refused with a named rule
Audit chain append-only and tamper-evident
9,204 entries, linkage intact, atomic chain-head allocation
AI cannot write state
Authority middleware; 15 tests including L4-prohibited and confidence-cannot-expand-authority
AI decision record on every AI execution
Written from the same function as the action log; 41 records
Compliance hard gates with immutable snapshots
Eligibility snapshots canonically hashed; 0 tampered
Stop-work gates enforced in the write path
7 named conditions; 11 tests; retention never blocked under legal hold
Durable scheduling monitored externally
119 unattended production sweeps; 503 on failure; post-deploy probe
Deadline provenance
Rule version, explicit UTC, pause history stamped at creation
Escalation requires verified delivery
A failed notification does not satisfy escalation; 6 tests
Measurement integrity
Every KPI carries numerator, denominator, n, cohort and a server-derived claim class
Synthetic vs real separation
130 synthetic / 54 trial / 0 production, stated on screen
RBAC and account deactivation
13 tests; revoked account refused on next request; history retained
Analytics suppressed on sensitive routes
8 route families; persisted global switch; 5 tests
Non-admin end-to-end workflow
7 steps, LENDER / OPERATIONS / VENDOR only, no admin
Structured error contract
Failed rule + current state + required action on every refusal
Accepted constraints
Documented, not hidden — each with the reason it is not being papered over
Redeploy stalls cron delivery
Why accepted
Host platform behaviour, not an application defect
Mitigation
Runbook remedy; Mission Control staleness banner; post-deploy probe
6 legacy audit entries content-unverifiable
Why accepted
Rewriting stored hashes to turn an indicator green is what the chain exists to detect
Mitigation
Documented permanently; linkage still intact; a test bounds the count so it can only shrink
437/438 timers lack deadline provenance
Why accepted
Backfilling would fabricate a rule version those deadlines never ran under
Mitigation
Resolves through natural turnover
5/12 AI contracts unexercised
Why accepted
Defined but not yet run against live models
Mitigation
Labelled “defined, not yet exercised” on screen
Cycle times not earned
Why accepted
Compressed sandbox clock
Mitigation
Labelled “not earned” by server-derived claim class
Ownership and recovery
Key-person risk is a governance finding, not a technical one
| Asset | Current control | Required before live trial |
|---|---|---|
| Hosting account | Individual | Company-owned account, ≥2 administrators |
| Source repository | Individual, in-sandbox git | Company GitHub organisation |
| Production database | Via hosting account | Company-controlled credentials, documented rotation |
| Domains | Individual account | Company registrar account |
| Credentials and secrets | Environment-injected | Company secret store with named custodians |
| Backups | None exist | Company-held, off-platform, tested |
| Logs | Platform-managed | Retention policy and named owner |
| Billing | Individual | Company payment instrument |
Sign-off
No signature is valid while any blocking gate is RED
Engineering
Operations
Compliance
Executive sponsor
Waivers require a named approver, a dated written reason and a compensating control. There are currently none, and B-1 through B-4 should not be waived under any circumstances for real consumer debt files.