Approval & Sign-Off Workflow
Turns the Production Go/No-Go decision into named accountable approvals with conditions, evidence references, expiry dates, and an escalation path.
This workflow is internal sign-off evidence. An "Approved" state on this page never means regulatory approval, legal advice, an audit opinion, or authorization to launch — it means a named BLACKSWAN owner has accepted the linked evidence pack for the scope shown. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events.
Required sign-offs
29
across 7 scopes
Founder, CCO, Risk, CISO, COO, Legal, Board.
Approved · current
6
Approved
Confined to Internal & Founder/Admin Production.
Conditional · pending evidence
8
Conditional
Amber gates with named owner and review date.
Blocked · cannot proceed
15
No-Go
Counterparty Data Room, External Pilot, Full Launch.
Filter by stateApprovedConditionalRejected · No-GoPendingRisk-AcceptedExpiredEscalated
Approval states used on this workflow
Pending
Review in flight; evidence pack assigned to a named owner; no decision yet.
Approved
Owner has accepted the evidence pack and signed for the named scope.
Approved with Conditions
Owner has accepted with explicit limitation text, expiry, and monitoring control.
Rejected · No-Go
Owner has rejected the scope; evidence pack uplift required before re-submission.
Risk-Accepted
Residual risk accepted by approver for a tightly-scoped, monitored pilot.
Expired
Approval lapsed at its review date; treat as Pending until renewed with fresh evidence.
Escalated
Approver could not decide within SLA; routed to Founder Admin and Board observer.
Eight approval stages
Each stage names an owner and an evidence pack
No stage can be skipped. A stage is only complete when the linked evidence pack has been accepted by the named owner with an approver signature recorded on the Pack Registry. Stage state below reflects the current Production Go/No-Go posture.
Stage 1 · Draft DecisionApproved
Founder Admin drafts the launch decision per scope
Captures recommended state per scope, jurisdiction implications, and gates referenced. Output is the v1.0 Go/No-Go memo on the Pack Registry.
Owner
Founder Admin
Last reviewed
2026-05-15
Stage 2 · Evidence ReviewConditional
Compliance verifies linked evidence packs are current
Compliance Owner re-checks pack hashes, expiry dates, limitation text, and recipient ledger evidence. Conditional pending Data-Room MNPI policy-version binding and Control Testing operating-effectiveness samples.
Owner
Chief Compliance Officer
Last reviewed
2026-05-15
Stage 3 · Risk & Compliance ChallengeConditional
Risk Owner and CCO challenge residual risks per scope
Outsourcing concentration, settlement responsibility, MNPI policy binding, and partner-route assurance are challenged with reviewer trail. Risk-Accepted Pilot evidence captured where used.
Owner
Risk Owner · CCO · MLRO observer
Last reviewed
2026-05-14
Stage 4 · Security/Ops ReadinessRejected
CISO and COO confirm cutover/rollback readiness
Entra OIDC tenant application not registered; SIEM forwarding staging-only; cutover/rollback runbook draft. Rejected for any external scope until Gate 6 closes.
Owner
CISO · COO
Last reviewed
2026-05-12
Stage 5 · Legal/Regulatory Counsel ReviewPending
External counsel opinion on activity perimeter per jurisdiction
ADGM/FSRA perimeter draft circulated; UK FCA, MAS, MiFID/MiFID II perimeter opinions outstanding. No supervisor pre-engagement record on file for UK/MAS/EEA.
Owner
Legal / Regulatory Counsel
Last reviewed
2026-05-10
Stage 6 · Board/Founder ApprovalConditional
Board resolution for any external scope; Founder for internal scopes
Founder approval recorded for Internal Production and Founder/Admin Production scopes only. Board resolution outstanding for Counterparty Data Room, Controlled External Pilot, Full External Launch.
Owner
Founder/CEO · Board
Last reviewed
2026-05-15
Stage 7 · Release AuthorizationBlocked
Final release authorization for the named scope
Blocked for any external scope while P0 blockers remain open. Release authorization available only for Internal Production and Founder/Admin Production via the Release panel below.
Owner
Founder Admin
Last reviewed
2026-05-15
Stage 8 · Post-Launch ReviewPending
30-day post-launch evidence refresh and limitation revalidation
Triggered automatically 30 days after any GO or Risk-Accepted Pilot release. Includes incident retrospective, monitoring evidence, and limitation-text re-attestation.
Owner
Founder Admin · CCO
Last reviewed
—
Sign-off matrix · scope × role
Current state per approver, per launch scope
Cells show the current internal sign-off state. None of these states imply supervisor authorisation. Approvals required-but-pending block the scope from progressing past Stage 7.
Sign-offs linked to 21 evidence packs and six production gates
Every approval on this surface references a pack on the Pack Registry and a Launch Readiness gate. Stale or missing evidence appears in the right column and blocks the linked approval until refreshed.
Current evidence
Linked packs accepted by their named owner within the review window.
Auth · Gate 1 Foundation · CISO accepted 2026-05-15
Policy Attestation · Gate 1 Foundation · Compliance accepted 2026-05-15
Complaints · Gate 4 · written policy and intake route DOCUMENTED · risk-accepted to 2026-08-31
Conditional approval terms
Every conditional state names its limitation, expiry, owner, monitoring control, rollback trigger, and external-use restriction
A conditional or risk-accepted approval is only valid while every field below is current. If the review date passes, the approval auto-expires; if the monitoring control fires, the rollback trigger pulls the scope back to No-Go.
Internal ProductionConditional
Limitation
Founder Admin and named internal users only. No external surface, no regulator-shared bundle.
Blocked. Jurisdiction Readiness gate red across all four jurisdictions.
Expiry
n/a · no approval issued.
Owner
Board resolution required when re-submitted.
Monitoring
n/a until conditional approval reinstated.
Rollback
n/a.
External use
None. Reactivation requires at least one jurisdiction perimeter green and partner-route assurance attached.
Escalation queue
Items routed to Founder Admin and Board observer
An item enters the queue if a P0/P1 blocker is unresolved, an approval has expired, evidence has been challenged in a reviewer round, counsel review is missing, or the last-reviewed date has slipped past SLA.
P0P1ExpiredChallenged
Severity
Item
Owner
Aging
P0
Product Governance route not closed for external useBlocks Stage 2 Evidence Review for Counterparty Data Room and all external scopes.
Product Gov.
5d open
P0
Model Risk validation pack and monitoring thresholds incompleteBlocks Stage 3 Risk & Compliance Challenge for any quantitative-model-using scope.
Model Risk
7d open
P0
Outsourcing Concentration · service map and exit plans openBlocks Stage 4 Security/Ops Readiness for all scopes; supervisor outsourcing notice cannot be filed.
Risk Gov.
8d open
P0
Microsoft Entra OIDC cutover application not registeredBlocks Stage 4 Security/Ops Readiness and Stage 7 Release Authorization for any external scope.
CISO · IAM
4d open
Challenged
UK FCA / MAS / MiFID-II perimeter counsel opinion outstandingStage 5 Legal/Regulatory Counsel Review pending across three jurisdictions; routed to Founder Admin and Board observer.
Settlement Responsibility four-eye approval not closedExternal responsibility routes lack four-eye approval and partner SLA mapping.
Post-Trade Ops
6d open
Stale
FSRA exam-response rationale last reviewed beyond SLALast reviewer pass was inside SLA at 2026-05-15; will auto-expire on 2026-07-14 unless re-attested.
Reg. Affairs
SLA 60d
Audit trail · decision history
Every state change is timestamped, named, rationale-bound, and evidence-linked
Sample audit lines consistent with the current staging posture. Entries are simulated/staging evidence; production audit-event capture still requires SIEM-forwarded audit events under Microsoft Entra OIDC.
Timestamp
Approver
Action & rationale
Evidence ref
2026-05-15 06:14Z
Founder / CEO
Approved Internal Production; founder MFA evidence current; SIEM forwarding rule active on auth and MNPI access. Conditional on 60-day review.
pack/auth#hash:9a2c…
2026-05-15 06:32Z
CISO
Co-signed Internal Production; identity model documented; audit-event capture verified for sign-in, evidence release, approver actions.
pack/auth#hash:9a2c…
2026-05-15 09:01Z
CCO
Approved Founder/Admin Production with conditions; Entra cutover deferred to next review; rollback trigger registered.
pack/policy-attestation#hash:7e11…
2026-05-15 11:48Z
Board Liaison
Risk-Accepted Pilot for Board Preview; watermarked recipient ledger active; reviewer trail captured.
pack/board-pack-attestation#hash:bc40…
2026-05-15 13:22Z
Regulatory Affairs
Risk-Accepted Pilot for FSRA Regulator Prep; bundle scope agreed; UK/MAS/EEA remain internal-only.
pack/regulatory-exam-response#hash:5d8f…
2026-05-14 16:05Z
Risk Owner
Challenge round: Settlement Responsibility and MNPI policy binding deferred to next reviewer pass; Conditional applied.
pack/settlement-responsibility#hash:1f73…
2026-05-12 10:11Z
Product Governance
Rejected external use; target market and distribution restrictions remain open across jurisdictions.
pack/product-governance#hash:38ab…
2026-05-10 08:42Z
Model Risk
Rejected production model use; validation pack and monitoring thresholds incomplete.
Disabled for any external scope until P0 blockers are closed
The Release Authorization button is intentionally inert here; this is staging. Production release authorization will be issued only when every required sign-off is Approved (or Approved with Conditions) and every P0 blocker is closed.
Internal Production · Founder/Admin Production
Conditional Release
Conditional
All required approvals are Approved or Approved with Conditions. Founder/CEO and CISO co-sign on file. SIEM monitoring active. 60-day auto-expiry registered. This panel is staging-only; actual production release authorization is issued out-of-band by Founder Admin.
Expires 2026-07-15Rollback ready
Counterparty Data Room · Controlled External Pilot · Full External Launch
Blocked · No-Go
Blocked
Seven P0 blockers open; four of six Launch Readiness gates not closed; jurisdiction states red for UK FCA, MAS, MiFID/MiFID II; Stage 4 Security/Ops Readiness rejected; Stage 5 Legal/Regulatory Counsel Review pending. Release authorization is unavailable.
P0 open · 7Gates not closed · 4 of 6Re-decision 2026-07-15
Captures the named sign-offs and the conditions that bound them. Internal-only until Stakeholder Bundle distribution evidence is on file. Use the browser's Print menu to produce a clean PDF (no script run is required).
Conditional Release for Internal Production and Founder/Admin Production; Risk-Accepted Pilot for Board Preview and Regulator Prep · FSRA; No-Go for Counterparty Data Room, Controlled External Pilot, and Full External Launch.
Scope
Founder Admin and named internal users; Board preview limited to a watermarked recipient cohort. No external counterparty, no regulator-shared distribution beyond FSRA pilot evidence.
Legal/Regulatory Counsel Stage 5 for all four external scopes; Board resolution for Counterparty Data Room, Controlled External Pilot, Full External Launch; Operations Owner for external scopes; CISO for external scopes.
Conditions
60-day auto-expiry across all conditional and risk-accepted states; SIEM monitoring on auth, MNPI, outsourcing-route anomalies; rollback trigger pulls scope to No-Go on any P0 detection; external use restricted to FSRA pilot evidence only.
Residual risks
External-bundle distribution before Product Governance closes; production model use without validation pack; outsourcing concentration without exit plan; unauthorised activity in UK/MAS/EEA; staging-only Entra OIDC; MNPI without policy-version binding; settlement responsibility ambiguity.
Re-decision date
2026-07-15 · 60-day automatic expiry on Conditional and Risk-Accepted Pilot states; reissue requires fresh evidence release and a new memo.
Limitations
This memo is internal sign-off evidence. It is not legal advice, not regulatory approval, not an audit opinion, and not authorization to launch any regulated activity. Regulated activity remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture, Completeness Command Centre, Launch Readiness Command Centre, and Production Go/No-Go Board. No real issuer, investor, KYC, MNPI, order-book, custody, or settlement data is enabled.
Internal release-control readiness posture only. The release-approval chain mirrored here is captured against the named release candidate / release window in the Release Control & Rollback Centre. Production launch requires CAB + Board + Compliance (CCO + MLRO + Legal) + Risk (CISO + CFO) sign-offs, plus deployment evidence, CI/CD provenance, rollback plan + rehearsed drill, dependency freeze, post-release monitoring, incident bridge readiness, communications, and a captured go-live authority counter-sign. Staging or demo deployment does not count as production release evidence. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is exposed by this Workflow, the API at /api/release-approval-rollback-evidence, the fixture, or any commit.
Authoritative row table is rendered in the
Release Control & Rollback Centre.
Mirrored summaries in the
Final Production Launch Control Tower,
the Production Go/No-Go Board,
the Production Monitoring & Incident Command Centre,
the Programme Governance & Roadmap Centre,
and the Completeness Command Centre.
Read-only fixture exposed via /api/release-approval-rollback-evidence; cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, /api/backup-restore-recovery-evidence, /api/observability-slo-incident-evidence, /api/entra-oidc-readiness, /api/evidence-pack-gate-validation, and /api/jurisdictional-permissions-matrix. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is returned from any endpoint. Internal release-control readiness posture only · not security certification · not regulatory approval · not external endpoint authorisation · not external-use authorisation. Staging or demo deployment does not count as production release evidence.
Read-only fixture exposed via /api/approval-authority-register; reference NAMES, ownership, approval forum names, approver class descriptors (e.g. "Counsel · external", "CCO · group", "Board · Audit Committee"), approval state, evidence reference IDs, quorum / signature rule class descriptors, delegated authority class descriptors, expiry / recertification rule class descriptors, escalation path class descriptors, linked gate / control / evidence-pack dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria only. Cross-references the
Change Freeze, Release Approval & Rollback Evidence Gate,
the Regulatory Notification & Board Escalation Centre,
the Stakeholder Rooms & Evidence Distribution Centre,
the Evidence-Pack Gate Validation,
the Jurisdictional Permissions Matrix,
the Board Pack · Investor Narrative · Strategic Reporting Centre,
the Final Production Launch Control Tower,
the Programme Governance & Roadmap Centre,
and the Completeness Command Centre.
No Counsel name, External Counsel name, Compliance / CCO / MLRO name, Risk Committee member identity, CISO / CFO name, Board / observer identity, board pack body, board minute body, board resolution body, board meeting link, attendee identity, signature image, signature hash, e-signature token, approval token, delegated authority instrument body, power-of-attorney body, board secretariat email, private board distribution channel, privileged legal advice text, privileged work-product, external counsel memo body, customer data, MNPI, or live approval-token timer is returned from any endpoint. Internal approval-authority readiness posture only — not Counsel approval, not Compliance / CCO / MLRO sign-off, not Risk Committee resolution, not CISO / CFO sign-off, not board approval, not quorum determination, not signature rule satisfaction, not delegated authority grant, not board minute, not board countersign, not go-live authorisation, not regulator-submission release authority, not external bundle release authority, not incident escalation authority, not production change / CAB authority, and not external-use authorisation. Staging or demo acknowledgements do not count as production approval authority.
Authority control
Group
Approval forum
Approver class
Quorum / signature
Delegation
Expiry
Escalation
State
Unlock
Loading approval-authority readiness fixture…
§Risk · Production Risk Acceptance & Exception Register
Risk-exception readiness map — internal posture only
Holds every exception-dependent gate (production launch, regulator submission, external bundle release, incident escalation, CAB / production change, go-live counter-sign, partner-route activation, secret rotation) at HOLD · NO-GO until each required risk-exception control — Entra OIDC transition exception, jurisdictional permission limitation, evidence-pack metadata exception, external-bundle release limitation, regulator-submission limitation, backup / restore readiness exception, observability / SLO exception, release / rollback exception, approval-authority exception, partner-route / mTLS readiness exception, secret / key custody exception, production config missing exception, data / MNPI boundary exception, incident escalation exception, and go-live authority exception — is captured with owner + approver class descriptor + approval forum + approval state + evidence reference + limitation text + compensating control + expiry + review cadence + escalation path + last-reviewed date. Staging or demo acknowledgements, founder-only rehearsal waivers, simulated board exception walkthroughs, fixture-only counsel exception reviews, internal demo authority readings, and sandbox e-signature rehearsals do not count as production risk acceptance. Risk acceptance never overrides an unresolved P0 blocker without explicit authority evidence and limitation language. No approver name, approver email, approver signature, board minute, board meeting link, board resolution body, exception token, e-signature token, private risk-memo body, privileged legal advice text, privileged work-product, external counsel memo body, customer data, MNPI, live deploy credential, regulator submission body, partner credential, signed-URL secret, OTP code, watermark salt body, IP address, device fingerprint, or live notification channel appears in this Workflow, fixture, API, or commit.
Mirror of the Manifest Approval Workflow & Export Request Queue summary exposed via /api/manifest-approval-workflow-export-request-queue. Class-descriptor index of approval phases, required dependency-gate classes, and blocker rollups. Never an export, never a release, never a transmission. Never resolves real recipients. Never overrides any blocker.
This Approval & Sign-Off Workflow is internal sign-off evidence. It is explicitly not:
legal advice — external counsel sign-off remains a separate evidence pack; nothing here substitutes for it.
regulatory approval — no Approved state on this surface implies that ADGM/FSRA, the UK FCA, MAS, an EEA NCA, or any other supervisor has authorised BLACKSWAN to launch any regulated activity. Authorisation is a supervisor-issued instrument, not an internal scorecard.
an audit opinion — internal control testing referenced here is not a substitute for an independent ISAE 3402 / SOC 2 / financial-statement audit.
authorization to launch — this surface aids Founder Admin and Board oversight. The decision to start any production activity sits with the Board after each gate is closed, every required sign-off is on file, and supervisor pre-engagement is recorded per jurisdiction.
All regulated activity on the platform remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture and Completeness Command Centre. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events. Items shown on this Workflow are plausible sample states consistent with the existing Launch Readiness Command Centre and Production Go/No-Go Board; live values will be sourced from the Pack Registry once the cutover is signed off.