← BLACKSWAN OS
Customer / Client Lifecycle · Entitlements
Internal Readiness · Simulated
Centre Status

Customer / Client Lifecycle & Entitlement Centre

Internal workspace for BLACKSWAN's end-to-end client lifecycle: prospect intake → KYC/KYB → jurisdiction & eligibility posture → classification → entitlements → counterparty documentation → service activation → access reviews → suspension/offboarding. Every transition is gated by counsel countersign, evidence-pack attestation, and SOD; nothing in this Centre constitutes a suitability determination, client acceptance, or any regulator-recognised onboarding act. Conservative posture throughout — internal readiness only.

Lifecycle stages
12
Prospect → Active → Suspended → Offboarded
Entitlement classes
10
Products · Venues · Data rooms · Reporting · Billing
Stakeholder views
9
Each view counsel-bounded for external surfaces
Open exceptions
7
Tied to KYC contract · counsel · auditor · break-glass
Lifecycle state legend
Prospect Intake KYC / KYB Pending Counsel Review Eligibility Assessed Docs Pending Entitlements Applied Active Access Review Suspended Offboarded Archived Blocked
Lifecycle stage model

Twelve stages · counsel-gated transitions · evidence captured at each step

1 · PROSPECT
Lead capture

Initial interest registered; no MNPI, no KYC artefact, no commercial engagement. Counsel-locked outreach language only.

2 · INTAKE
Internal triage

Internal Commercial + Compliance triage; jurisdiction first-look; counterparty-type drafted; RAID entry where flagged.

3 · KYC / KYB
Counterparty due diligence

KYC partner DD (contract pending) · KYB documents collected · UBO chain captured · sanctions/PEP screening logged.

4 · COUNSEL REVIEW
Counsel countersign

External counsel reviews jurisdiction posture, perimeter overlap, MNPI scope; locks counterparty wording.

5 · ELIGIBILITY
Eligibility assessment

Eligibility assessed against the activity perimeter (POL-005); never a suitability determination; never a regulator-recognised classification.

6 · CLASSIFICATION
Internal classification

Internal client classification (pilot / counterparty / observer); MNPI binding scope set; jurisdiction tags applied.

7 · DOCS
Counterparty documentation

MSA · DPA/SCC · pilot tenant template · NDA · counsel countersign per artefact (CTL-010).

8 · ENTITLEMENTS
Entitlement matrix applied

Product · venue · data-room · reporting · billing entitlements bound to client classification; least-privilege default.

9 · ACTIVATION
Service activation

Identity provisioned (Entra OIDC target) · per-pilot tenant created · per-recipient link signing keys issued · billing flagged.

10 · ACCESS REVIEW
Quarterly access review

Quarterly review per role; stale access flagged; consent / attestation re-confirmed; suspension recommended where stale.

11 · SUSPENDED
Suspension

Service paused; entitlements pulled; data retention hold applied; counsel-bounded resumption path documented.

12 · OFFBOARDED
Offboarding · archive

Service revoked; per-recipient signing keys rotated; retention class enforced; audit ledger frozen at 10-year retention.

Acceptance criteria — prospect → active → suspended/offboarded

Transition · gate · evidence captured · owner

TransitionGateAcceptance criteriaEvidence capturedOwner
Prospect → IntakeCounsel-locked outreachInternal-only outreach phrasing · no MNPI · no commercial commitmentOutreach log · counsel-locked footer hashOperations · Compliance
Intake → KYC / KYBKYC partner engagementKYB docs · UBO chain · sanctions / PEP screening cleanKYC partner ledger (KYC-EV-*)Operations · Compliance
KYC → Counsel ReviewCounsel countersignCounsel reviews jurisdiction / perimeter overlap; phrasing lockedCounsel countersign hash (CTL-010)External Counsel · Compliance
Counsel Review → EligibilityPerimeter alignmentActivity Perimeter pack (POL-005) confirms in-scope; no suitability claimEligibility note · perimeter cross-referenceCompliance · Operations
Eligibility → ClassificationInternal classificationPilot / counterparty / observer · MNPI scope bound · jurisdiction tags appliedClassification record · MNPI ledgerCompliance · Tech/Security
Classification → DocsDocumentation countersignMSA · DPA/SCC · pilot tenant template · NDA · counsel countersign per artefactCounterparty document hash setExternal Counsel · Operations
Docs → EntitlementsEntitlement matrix appliedProduct · venue · data-room · reporting · billing entitlements bound to classificationEntitlement ledgerOperations · Tech/Security
Entitlements → ActivationIdentity + tenant provisionedEntra OIDC sign-up · per-pilot tenant created · per-recipient link signing keys issuedActivation audit-event tag (CCLE-ACT-*)Tech/Security · Operations
Activation → Access ReviewQuarterly cadenceRole-bound access review · consent / attestation re-confirmedAccess review log (AR-008)Tech/Security · Compliance
Access Review → SuspendedStale access / breach signalTrigger logged · counsel-bounded resumption path documentedSuspension record · retention holdTech/Security · Compliance
Suspended → OffboardedOffboarding runbookPer-recipient keys rotated · entitlements pulled · billing closed · ledger frozenOffboarding manifest hash · 10-y retentionTech/Security · Operations · Compliance
Entitlement matrix

Ten entitlement classes × client classification

Entitlement classProspectPilot · Per-TenantCounterpartyObserver (Investor / Regulator-Review)Auditor (Engagement)Linked pack(s)Owner
Product accessNonePilot-scopedPer-contractRead-only · redactedn/aProduct Governance · Activity PerimeterOperations
Venue access (where in scope)NoneSandboxPer-contractDenyDenyActivity PerimeterCompliance · Operations
Data-Room / MNPIDenyPer-pilot · consentPer-engagement · consentCounsel-redactedScope-boundData-Room MNPI Access · Policy AttestationTech/Security · Compliance
Onboarding flowOutreachKYC partnerKYC partnern/an/aKYC/KYB OnboardingOperations
Counterparty documentationNDAPilot templateMSA + DPA/SCCn/aEngagement letterPartner-Route AssuranceExternal Counsel
Billing & revenueNonePilot fee schedulePer-contract billingNoneEngagement billingRevenue Recognition · Tax/VATFinance
Reporting packNonePilot dashboardPer-contract reportingRedacted externalScoped reportsBoard-Pack Attestation · Conduct Risk MIOperations
Complaints / escalationn/aPer-pilot · counsel routeStanding channelStanding channelEngagement channelComplaints · Conduct Risk MICompliance · Operations
Audit / evidence visibilityNonePilot evidenceCounsel-lockedCounsel-redactedAudit binder scopeRegulatory Exam Response · Control TestingExternal Counsel · Auditor
Support / break-glassn/aPilot support · JITTiered supportn/aEngagement supportOutsourcing Concentration · Settlement ResponsibilityTech/Security · Operations
Evidence-pack mapping

Lifecycle stage × BLACKSWAN evidence packs

Lifecycle stagePrimary evidence pack(s)Touches user-role postureCounsel countersign required
Prospect / IntakeActivity Perimeter · Policy AttestationCompliance · OperationsFor external phrasing only
KYC / KYBKYC/KYB Onboarding · Partner-Route Assurance · Outsourcing ConcentrationCompliance · Operations · Tech/SecurityYes
Counsel ReviewRegulatory Exam Response · Activity Perimeter · Regulatory ChangeCompliance / LegalYes — mandatory
EligibilityActivity Perimeter · Product Governance · Conduct Risk MICompliance · OperationsFor regulator-facing language
ClassificationData-Room MNPI · Policy Attestation · Product GovernanceCompliance · Tech/SecurityYes (where MNPI binding)
DocumentationPartner-Route Assurance · Settlement Responsibility · Outsourcing ConcentrationExternal Counsel · OperationsYes — per artefact (CTL-010)
EntitlementsProduct Governance · Auth · Data-Room MNPI · Policy AttestationTech/Security · OperationsFor external-bundle visibility only
ActivationAuth · KYC/KYB · Policy AttestationTech/Security · OperationsFor regulator-facing artefact
BillingRevenue Recognition · Tax/VAT · Settlement ResponsibilityFinance · OperationsFor revenue narrative
Access ReviewPolicy Attestation · Conduct Risk MITech/Security · Compliancen/a (internal)
Complaints / SuspensionComplaints · Conduct Risk MI · IncidentCompliance · OperationsFor regulator notification
OffboardingPolicy Attestation · Outsourcing Concentration · Regulatory Exam ResponseTech/Security · Operations · ComplianceFor regulator-facing reference
Stakeholder views

What each role sees / does in this Centre

View 1 · Founder / Admin

Full lifecycle view

Reads the full 12-stage ledger; approves Tier-1 transitions; standing risk acceptance for founder-root applies (DEC-005). Dual sign-off required on suspension/offboarding.

Admin · Dual
View 2 · Compliance / Legal

Counsel-bound view

Counsel countersigns every external-facing artefact (CTL-010); reviews jurisdiction / perimeter alignment; locks counterparty wording. Approves classification and MNPI binding.

Counsel Countersign
View 3 · Operations

Workflow operator view

Operates the 12-stage workflow; manages KYC partner flow; provisions per-pilot tenant; coordinates entitlement matrix. Approve on activation; dual sign-off on suspension.

Approve · Dual on Suspend
View 4 · Evidence Owner

Evidence-bound view

Writes the evidence-pack updates per stage (KYC, classification, docs, activation, offboarding); per-file limitation footer enforced (CTL-006).

Write · Pack Owner
View 5 · Client / Counterparty

Per-tenant view

Per-pilot tenant view only; reads onboarding status · entitlements · documentation; signs NDA / pilot template / MSA; never sees other tenants.

Consent · MNPI Binding
View 6 · Investor-Review

Investor-room view

Read-only on aggregated, redacted, counsel-approved "pipeline" view; no counterparty names; no MNPI; no auditor representation. Per-recipient link signing required.

Read · Redacted External
View 7 · Regulator-Review

Regulator-room view

Read-only on counsel-locked, redacted aggregate posture only; never sees Internal Only material; per-share TTL; per-recipient watermark; audit-logged access.

Read · Counsel-Locked
View 8 · Auditor / Assurance

Engagement-scope view

Reads engagement-scope evidence on revenue / classification / billing only; engagement letter required before any production access; counsel-bounded scope.

Read · Scope-Bound
View 9 · Technology / Security

IAM & tenant view

Provisions identity (Entra OIDC target) · per-pilot tenant · link signing keys; JIT elevation for break-glass; owns access-review cadence and consent records.

Admin · JIT
Segregation of duties & approval authorities

Workflow · accountable · approver · SOD pair · compensating control

WorkflowAccountableApproverSOD pairCompensating controlLinked policy / control
Onboarding decision (Eligibility → Classification)ComplianceFounder/Admin + External CounselTriage ≠ ApproverCounsel countersign · CTL-010POL-002 KYC/KYB · POL-005 Perimeter
MNPI binding for clientCompliance / Tech/SecurityExternal Counsel + Tech/Security (dual)Operator ≠ ApproverPer-share access review · audit logPOL-003 MNPI · CTL-003
Entitlement grant (Docs → Entitlements)OperationsTech/Security + ComplianceAuthor ≠ ApproverDual sign-off + entitlement ledgerPOL-019 Product Governance · CTL-004
Per-pilot tenant provisionTech/SecurityOperations + Tech/SecurityBuild ≠ Sign-offTenant manifest hash · audit logPOL-007 Partner Route · CTL-005
Billing activationOperations · FinanceFinance + External Counsel (for material)Booking ≠ ApprovalExternal Auditor + audit binderPOL-008 Revenue · POL-009 Tax · CTL-009
Suspension (Review → Suspended)Operations / Tech/SecurityCompliance + Tech/Security (dual)Single-party ≠ SuspensionCounsel-bounded resumption path · retention holdPOL-015 Complaints · POL-012 Incident
Offboarding (Suspended → Offboarded)Tech/Security · OperationsCompliance + Tech/Security (dual) · Finance for billing closeCustodian ≠ ApproverPer-recipient key rotation · ledger freezePOL-018 Attestation · CTL-006
Complaint escalation to regulatorComplianceCompliance + External CounselOperator ≠ SubmitterCounsel countersign + audit-logged decisionPOL-015 Complaints · POL-014 Reg Change
Access reviews · break-glass · stale-access alerts

Cadence · owner · break-glass · client-support rules

ReviewCadenceLast reviewOwnerOpen exception / gapState
Active client tenantsQuarterly2026-04-30Tech/Security · ComplianceKYC contract pending for new tenantsUnder Review
Investor-review roomsPer sharen/a · awaiting counselCompliance · FounderLocked until counsel rule-pack countersign (2026-05-19)Counsel Pending
Regulator-review roomsPer engagementn/a · counsel-boundedCompliance · External CounselCounsel session 2026-05-19Counsel Pending
Auditor engagement scopeAnnual · interimn/aFinance · ComplianceExternal auditor engagement letter pendingDocs Pending
Break-glass client supportQuarterly drill2026-02-12Tech/Security · OperationsDrill overdue (target 2026-05-12); JIT elevation only · dual approverBreak-Glass · Overdue
Stale prospect intakeMonthly sweep2026-05-15Operations · Compliance2 prospects > 60d without KYC start — auto-archive flaggedSweep
Stale classificationQuarterly2026-05-09Compliance · Tech/SecurityNone outside cadenceHealthy
External-bundle visibility gates

Four gates · all green before any client-facing artefact leaves internal scope

Gate 1
Counsel countersign

External counsel countersigns every external-facing client-lifecycle artefact (NDA · pilot · MSA · DPA/SCC · billing); per artefact, per audience.

Open · 2026-05-19
Gate 2
Classification + MNPI scope set

Internal classification recorded, MNPI binding scope explicit, jurisdiction tags applied; never an external suitability claim.

Met
Gate 3
Entitlement ledger

Every product / venue / data-room / reporting / billing entitlement bound to client classification with named owner and audit-event tag.

Met
Gate 4
Revocation readiness

Single-action revocation pulls per-pilot tenant keys + entitlements; offboarding runbook proven on most recent rotation drill.

Met
Current posture: three gates met · one open. No external client-lifecycle artefact ships under any external role until Gate 1 closes following the 2026-05-19 counsel rule-pack session.
Audit trail & evidence preservation

Audit log of lifecycle / entitlement events

Timestamp (UTC)ActorEvent familyActionEvidence hashLimitation recordedNext step
2026-05-08 09:00Operations · ComplianceLifecycle modelCCLE-LIFE — 12 stages publishedsha256:ccle…aa01"Internal readiness only."Quarterly review
2026-05-09 11:14Programme · Compliance · External CounselAcceptance criteriaCCLE-ACC — 11 transitions definedsha256:ccle…aa02"No suitability determination."Apply on next intake
2026-05-10 09:22Operations · Tech/SecurityEntitlement matrixCCLE-EM — 10 entitlement classessha256:ccle…aa03"Internal."Refresh on classification change
2026-05-11 14:08Head of Evidence · ComplianceEvidence mapCCLE-EV — 12 stages mapped to packssha256:ccle…aa04"Internal."Refresh on pack change
2026-05-12 09:50CoS · CISO · ComplianceStakeholder viewsCCLE-SV — 9 views scopedsha256:ccle…aa05"Counsel-bounded for external."Lock per-share counsel sign-off
2026-05-13 11:42CISO · External CounselSOD & approvalsCCLE-SOD — 8 workflows scopedsha256:ccle…aa06"Internal."Re-test on workflow change
2026-05-15 09:00Tech/Security · ComplianceAccess reviewsCCLE-AR — 7 review streams loggedsha256:ccle…aa07"Internal."Close break-glass drill
2026-05-15 11:30External Counsel · CEO · Tech/SecurityExternal visibility gatesCCLE-VG — 3 of 4 gates metsha256:ccle…aa08"No external bundle without all 4 gates."Close Gate 1 post 2026-05-19
2026-05-16 07:55CEO · CISO · ComplianceCentre attestationCCLE-ATTESTATION — monthly attestationsha256:ccle…aa09"Internal; not regulatory approval."Re-attest monthly
Assumptions and Limitations

What this Centre is — and is not

  • Staging / simulated lifecycle data. All client IDs, stage records, entitlement ledger entries, evidence hashes, dates, and audit events shown here are seed values for an internal readiness workflow. They are not a live CRM, not a live KYC system, and not a live audit log.
  • Internal readiness workflow only. This Centre captures BLACKSWAN's internal client-lifecycle posture. It is not legal advice, not regulatory approval, not certification, not an audit opinion, and not authorization for external launch.
  • Not a suitability determination. Eligibility and classification stages are internal posture only. No artefact in this Centre constitutes a regulator-recognised suitability assessment, client acceptance, or onboarding decision.
  • Counsel-bound by default for external surfaces. Every client-facing artefact requires external counsel countersign (CTL-010) before any external visibility gate is opened. Approve never implies external sign-off without counsel countersign.
  • Founder-root is a standing accepted risk. Per Programme Decision Log DEC-005, founder-root permanence carries MFA + re-auth + monthly attestation as compensating controls.