BLACKSWANCapital Markets OS Production Go/No-Go Board · v1.0 draft ← Return to OS Architecture
Production Standby · HOLD · NO-GO Go-live switch locked Regulatory / counsel approval pending · internal readiness rehearsal only · external use disabled
Production Go/No-Go · Founder-only staging

Production Go/No-Go Board Turns Launch Readiness gate status, evidence status, blocker status, jurisdiction readiness, and stakeholder bundle status into a conservative launch decision.

This is an internal readiness decision. A green decision on this page never means regulatory approval, legal advice, or authorization to start any production activity — it means BLACKSWAN's named owners have accepted the evidence pack and limitation text for the scope shown. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events.

Overall recommended state · 2026-05-15
NO-GO · FULL EXTERNAL LAUNCH
External-bundle distribution and any externally-visible launch is blocked across ADGM/FSRA, UK FCA, MAS, and MiFID/MiFID II.
Four of six production gates are not closed: Control Evidence (amber), Operational Resilience (amber), Jurisdiction Readiness (red), Stakeholder Bundle (amber), Controlled Production Launch (red). Seven P0 launch blockers are open. A tightly-scoped Conditional Go is recommended for Internal Production and Founder/Admin Production; a Risk-Accepted Pilot may be considered for Board Preview and Regulator Prep with explicit limitation text, approver visibility, and a fixed review date. No-Go remains the conservative recommendation for Counterparty Data Room, Controlled External Pilot, and Full External Launch.
GO Conditional Go No-Go Defer Risk-Accepted Pilot
Decision states used on this Board
GO
All gates green; no P0 blockers open; approvers signed; external scope permitted.
Conditional Go
Amber items allowed with named owner, mitigation, expiry; scope limited to the approved cohort.
No-Go
Any open P0 or any red gate for the scope; external-bundle distribution blocked.
Defer
Insufficient evidence to render a decision; revisit at a stated date with the missing evidence packs.
Risk-Accepted Pilot
Approver accepts residual risk for a tightly-scoped, time-bounded, monitored pilot only.
Launch scopes

Recommended state per launch scope

Scope-by-scope view derived from the current Launch Readiness gate status. Each tile lists the recommended decision state, the named approvers required to move it to GO, and the residual risk the approvers must explicitly accept.

Internal Production Conditional Go
Founder Admin and named internal users only. No external surface, no regulator-shared bundle.
Founder · CISO sign-off Amber: Control Testing samples
Founder/Admin Production Conditional Go
Founder-only operations against production-flagged surfaces. MFA evidence and audit trail required end-to-end.
Founder · CISO · CCO sign-off Amber: Entra OIDC cutover
Board Preview Risk-Accepted Pilot
Watermarked Board pack distributed to named directors. Recipient ledger and reviewer trail evidenced.
Founder · Board Liaison sign-off Amber: Bundle limitation text
Regulator Prep Risk-Accepted Pilot
Internal-only response binders, exam-response packs, and supervisor pre-engagement rehearsal. No regulator-shared distribution yet.
CCO · Regulatory Affairs sign-off Amber: FSRA only · UK/MAS/EEA red
Counterparty Data Room No-Go
MNPI rooms not yet bound to current policy version with SIEM forwarding evidence. External counterparty distribution blocked.
CCO · CISO · Founder sign-off Red: Data-Room MNPI Access
Controlled External Pilot No-Go
Partner-routed or supervisor-acknowledged pilot. Requires Jurisdiction Readiness gate green for at least one named jurisdiction.
All approvers required Red: Jurisdiction Readiness
Full External Launch No-Go
Cross-jurisdiction external launch with full client onboarding. Requires every gate green, supervisor pre-engagement on file, and Board resolution.
All approvers · Board resolution Red: 4 of 6 gates not closed
Re-decision cadence Defer · 2026-07-15
No-Go and Risk-Accepted Pilot states automatically expire at the named review date. Reissue requires fresh evidence on the Pack Registry.
Owner: Founder Admin Cadence: 60 days
Gate-based acceptance criteria

P0/P1 gating mapped to the six Launch Readiness gates

No unresolved P0 for GO. Amber items allowed only for Conditional Go with owner/date/mitigation. Red blocks any external launch. Risk-accepted requires an approver, limitation text, expiry, and a monitoring control. The mark in each row reflects the current Launch Readiness state.

✓Closed ~Conditional ✗Blocking
Acceptance criterion
Gate
Priority
✓
Founder MFA evidence held server-side; Entra-ready identity model documented Foundation gate green; immutable audit store wired; session timeout enforced; Policy Attestation pack accepted.
Gate 1 · Foundation
P0
~
KYC/KYB onboarding evidence accepted with partner-route assurance attached Partner-routed in ADGM/UK/EEA; MAS notice 626 alignment evidence outstanding.
Gate 2 · Control Evidence
P0
~
Data-Room MNPI access bound to current policy version with SIEM forwarding evidence Policy-version binding and SIEM forwarding pending reviewer pass before any external counterparty distribution.
Gate 2 · Control Evidence
P1
✗
Product Governance route closed for target market, launch gates, distribution restrictions Target market, launch gates, and distribution restrictions remain open across all four jurisdictions — blocks any controlled external bundle.
Gate 2 · Control Evidence
P0
✗
Model Risk validation pack and monitoring threshold evidence complete Validation and monitoring evidence not complete; production use of any quantitative model is blocked across all jurisdictions.
Gate 2 · Control Evidence
P0
✗
Outsourcing Concentration: critical service map, exit plans, fallback providers, concentration scoring All four items open. Supervisor outsourcing notice cannot be filed; required for any external scope.
Gate 3 · Operational Resilience
P0
~
Settlement Responsibility: four-eye approval and partner SLA mapping Open across external routes — scope-limited launch possible only with explicit limitation text.
Gate 3 · Operational Resilience
P1
~
Capital/Liquidity Readiness: ICAAP/ICARA-style write-up board-approved Capital plan modelled; board approval and stress-test evidence pending.
Gate 3 · Operational Resilience
P1
~
ADGM/FSRA Activity Perimeter Decision and supervisor pre-engagement evidence Perimeter draft circulated; supervisor pre-engagement not yet on file.
Gate 4 · Jurisdiction Readiness
P0
✗
UK FCA Activity Perimeter Decision and supervisor pre-engagement evidence Licence scope, perimeter, and external counsel opinion absent.
Gate 4 · Jurisdiction Readiness
P0
✗
MAS Activity Perimeter Decision and licence class mapping Partner appointment evidence and notice 626 alignment outstanding.
Gate 4 · Jurisdiction Readiness
P0
✗
MiFID/MiFID II perimeter decision and best-execution evidence EEA cross-border treatment, investment-services scope, and best-execution evidence not finalised.
Gate 4 · Jurisdiction Readiness
P0
~
Board-Pack Attestation with watermarked recipient ledger and approver signatures Live for ADGM/UK/EEA; MAS-specific committee cadence pending.
Gate 5 · Stakeholder Bundle
P1
~
Regulatory Exam Response pack rehearsed with limitation text and reviewer trail FSRA bundle green; UK/MAS/EEA exam response packs rehearsed internally only.
Gate 5 · Stakeholder Bundle
P1
~
Revenue Recognition and Tax/VAT external bundle limitation text and auditor pre-clearance IFRS 15 drafted; auditor pre-clearance memo pending. Tax/VAT place-of-supply analysis open for UK/EEA.
Gate 5 · Stakeholder Bundle
P1
✗
Microsoft Entra OIDC tenant application registered with Conditional Access and RBAC/ABAC Production session issuance, Conditional Access, and SIEM forwarding pending. Cutover blocked.
Gate 6 · Controlled Production Launch
P0
✗
SIEM forwarding confirmed end-to-end for production environment Currently staging-only. Audit-event coverage gap blocks any external launch.
Gate 6 · Controlled Production Launch
P0
✗
Cutover and rollback runbook approved with regulator notification ledger Draft only. Supervisor pre-engagement record per jurisdiction not on file.
Gate 6 · Controlled Production Launch
P0
Jurisdiction decision strip

Conservative state and launch implications

Cells reflect internal evidence readiness only. None of the states below imply that any supervisor has authorised BLACKSWAN to launch any regulated activity. Authorisation is a supervisor-issued instrument, not an internal scorecard.

ADGM / FSRA Conditional Go
FSRA bundle limitation text accepted; Activity Perimeter draft circulated and supervisor pre-engagement scheduled. Conditional Go covers Internal Production and Board Preview only. No external counterparty distribution until Gate 4 closes.
UK FCA No-Go
Licence scope and perimeter not yet closed; external counsel opinion not on file. Any externally-visible launch is blocked. Internal evidence work continues against the UK pack.
MAS No-Go
Partner appointment evidence and notice 626 alignment outstanding; KYC/KYB partner SOC reports not on file. External launch blocked. MAS committee cadence work continues.
MiFID / MiFID II No-Go
EEA cross-border treatment, investment-services scope, and best-execution evidence not finalised. Cannot pass Gate 4 for EEA. Investor-protection items remain not-in-scope for MAS-only entity.
Approval workflow

Required approvers by launch scope

Each approver represents a defined accountability role inside BLACKSWAN. An approval is required, optional, or not required for the scope shown. Required approvals must be on file with named signatory, date, and the evidence-pack hash that was reviewed before any state moves to GO.

Required Optional Not required
Approver role Internal Production Founder/Admin Production Board Preview Regulator Prep Counterparty Data Room Controlled External Pilot Full External Launch
Founder / CEO Required Required Required Required Required Required Required
Compliance Owner (CCO / MLRO) Optional Required Required Required Required Required Required
Risk Owner (CRO / Risk Governance) Optional Required Required Required Required Required Required
Engineering / Security Owner (CISO) Required Required Optional Optional Required Required Required
Operations Owner (COO / Post-Trade) Optional Required Optional Optional Required Required Required
Legal / Regulatory Counsel Not required Optional Required Required Required Required Required
Board Resolution Not required Not required Optional Optional Required Required Required
Blocker burn-down · top launch risks

P0/P1 closure trajectory mapped to evidence packs

Numbers below are sample plausible counts consistent with the current Launch Readiness register. Burn-down is owner-driven; closure requires evidence pack uplift on the Pack Registry with reviewer signature.

Pack
Open
Trend
Product Governance · P0
3 open
Model Risk · P0
4 open
Outsourcing Concentration · P0
5 open
Activity Perimeter · UK/MAS/EEA · P0
3 open
Entra OIDC cutover · P0
1 open
Settlement Responsibility · P1
2 open
Data-Room MNPI Access · P1
2 open
Control Testing · P1
3 open
Revenue Recognition / Tax · P1
2 open
Board cadence · MAS · P1
1 open

Top launch risks

Active
  1. External-bundle distribution before Product Governance closes — uncontrolled target market or distribution restriction breach. Maps to Product Governance and Stakeholder Bundle gates.
  2. Model use without validation pack — quantitative model output relied on for any client decision. Maps to Model Risk pack and Control Evidence gate.
  3. Outsourcing concentration with no exit plan — single-provider dependency for a critical service without a tested fallback. Maps to Outsourcing Concentration pack and Operational Resilience gate.
  4. Launching into UK/MAS/EEA without perimeter sign-off — unauthorised regulated activity exposure. Maps to Activity Perimeter Decision pack and Jurisdiction Readiness gate.
  5. Staging-only Entra OIDC promoted to production — session issuance and Conditional Access gaps; SIEM forwarding incomplete. Maps to Policy Attestation pack and Controlled Production Launch gate.
  6. MNPI access without policy-version binding — controlled-bundle leakage with no current policy-version evidence trail. Maps to Data-Room MNPI Access pack and Control Evidence gate.
  7. Settlement responsibility ambiguity across external routes — four-eye approval and partner SLA mapping not closed. Maps to Settlement Responsibility pack and Operational Resilience gate.
Launch rehearsal · dry-run checklist

Owner-named dry run before any state moves to GO

Each rehearsal item must be exercised end-to-end with evidence captured on the Pack Registry. Items mirror BLACKSWAN's existing simulated-control surface and the Completeness Command Centre evidence flow — they do not introduce new regulated activity.

Identity & controls

  • Auth — founder MFA evidence captured server-side; Entra-ready identity model documented and rehearsed.
  • Data-Room MNPI controls — rooms bound to current policy version; reviewer trail and SIEM forwarding exercised.
  • Audit log — immutable audit-event capture verified for sign-in, evidence release, and approver actions.
  • Monitoring — SIEM detection rules tested for auth, MNPI, and outsourcing-route anomalies.

Evidence & bundles

  • Evidence export — pack export rehearsal across the Pack Registry with hash continuity check.
  • Board bundle — watermarked recipient ledger and approver signature evidenced for the named director cohort.
  • Regulator response room — FSRA bundle dry run; UK/MAS/EEA exam response packs walked through internally only.
  • Comms plan — internal stakeholder notification routes rehearsed; no external comms issued.

Recovery & rollback

  • Incident rollback — recall, distribution-gate reissue, and limitation-text refresh exercised against simulated incident.
  • Cutover runbook — staging-to-production cutover plus rollback steps walked through with owner sign-off.
  • Regulator notification ledger — pre-populated per jurisdiction with notification triggers and owner names.
  • Re-decision cadence — 60-day automatic expiry confirmed on No-Go and Risk-Accepted Pilot states.
Decision memo preview

Board/Regulator-ready preview · internal-only draft

Preview of the structured memo BLACKSWAN would record on the Pack Registry for the named scope. The memo is internal-only until Stakeholder Bundle distribution evidence is on file.

Production Go/No-Go memo · v1.0 draft · founder-only staging

Decision
No-Go for Full External Launch · No-Go for Controlled External Pilot and Counterparty Data Room · Risk-Accepted Pilot for Board Preview and Regulator Prep · Conditional Go for Internal and Founder/Admin Production.
Scope
Founder Admin and named internal users; Board preview limited to a watermarked recipient cohort with reviewer trail. No external counterparty, no regulator-shared distribution.
Jurisdictions
ADGM/FSRA · Conditional Go for internal scopes. UK FCA, MAS, MiFID/MiFID II · No-Go for any externally-visible launch.
Evidence basis
Launch Readiness gates: Foundation green; Control Evidence amber (Product Governance red, Model Risk red); Operational Resilience amber (Outsourcing Concentration red); Jurisdiction Readiness red; Stakeholder Bundle amber; Controlled Production Launch red. Sources: Pack Registry, Completeness Command Centre, Launch Readiness blocker register.
Residual risks
External-bundle distribution before Product Governance closes; model use without validation; outsourcing concentration; unauthorised activity in UK/MAS/EEA; staging-only Entra OIDC; MNPI without policy-version binding; settlement responsibility ambiguity.
Conditions
Internal Production: founder MFA evidence + audit log + monitoring on. Founder/Admin Production: add CCO and Risk Owner sign-off and limitation text. Board Preview / Regulator Prep: explicit limitation text, watermarked recipient ledger, approver visibility, and dry-run rehearsal evidence.
Expiry / review date
2026-07-15 · 60-day automatic expiry on No-Go and Risk-Accepted Pilot states. Reissue requires fresh evidence and a new memo.
Owner sign-offs
Founder/CEO · CCO · Risk Owner · CISO · COO · Legal/Regulatory Counsel. Board resolution required for any Controlled External Pilot or Full External Launch.
Limitations
This memo is internal readiness evidence. It is not legal advice, not regulatory approval, not an audit opinion, and not authorization to launch any regulated activity. Regulated activity remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture and Completeness Command Centre. No real issuer, investor, KYC, MNPI, order-book, custody, or settlement data is enabled.

Change Freeze, Release Approval & Rollback Evidence Gate

Internal release-control readiness posture only. Production launch requires an approved release candidate, a declared change freeze, an approved release window, CAB + Board + Compliance + Risk sign-offs, deployment evidence, CI/CD provenance, a rollback plan, a rehearsed rollback drill, database / data-migration rollback evidence, feature flag / kill-switch arming, a dependency freeze, a post-release monitoring window, incident bridge readiness, release communications, and a captured go-live authority. Staging or demo deployment does not count as production release evidence. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is exposed by this Board, the API at /api/release-approval-rollback-evidence, the fixture, or any commit.

Controls assessed
28

Release candidate · freeze · window · sign-offs · deployment · CI/CD · rollback · DB · flags · dependency freeze · monitoring · bridge · comms · authority

Ready · internal
0

Owner + approver + approval + evidence + (where applicable) rollback drill captured

Approval pending
28

CAB · Board · Compliance · Risk · Founder Office counter-sign not yet captured

Rollback rehearsal untested
5

Rollback / DB rollback / kill-switch drill not in freshness window

Evidence missing
2

Manifest · sign-off · dependency lock · comms record not linked

Rollback blocked
8

Rollback plan + drill + DB rollback + flag/kill-switch not all approved & evidenced

Post-release monitoring
1

Post-release monitoring window not declared / approved / evidenced

Production launch
HOLD · NO-GO

Until release candidate + freeze + window + sign-offs + deployment + CI/CD + rollback + drill + DB + flags + dependency freeze + monitoring + bridge + comms + authority captured

Authoritative row table is rendered in the Release Control & Rollback Centre. Mirrored summaries in the Final Production Launch Control Tower, the Approval & Sign-Off Workflow, the Production Monitoring & Incident Command Centre, the Programme Governance & Roadmap Centre, and the Completeness Command Centre. Read-only fixture exposed via /api/release-approval-rollback-evidence; cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, /api/backup-restore-recovery-evidence, /api/observability-slo-incident-evidence, /api/entra-oidc-readiness, /api/evidence-pack-gate-validation, and /api/jurisdictional-permissions-matrix. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is returned from any endpoint. Internal release-control readiness posture only · not security certification · not regulatory approval · not external endpoint authorisation · not external-use authorisation. Staging or demo deployment does not count as production release evidence.

§Risk · Production Risk Acceptance & Exception Register

Risk-exception readiness map — internal posture only

Holds every exception-dependent gate (production launch, regulator submission, external bundle release, incident escalation, CAB / production change, go-live counter-sign, partner-route activation, secret rotation) at HOLD · NO-GO until each required risk-exception control — Entra OIDC transition exception, jurisdictional permission limitation, evidence-pack metadata exception, external-bundle release limitation, regulator-submission limitation, backup / restore readiness exception, observability / SLO exception, release / rollback exception, approval-authority exception, partner-route / mTLS readiness exception, secret / key custody exception, production config missing exception, data / MNPI boundary exception, incident escalation exception, and go-live authority exception — is captured with owner + approver class descriptor + approval forum + approval state + evidence reference + limitation text + compensating control + expiry + review cadence + escalation path + last-reviewed date. Staging or demo acknowledgements do not count as production risk acceptance. Risk acceptance never overrides an unresolved P0 blocker without explicit authority evidence and limitation language.

Exceptions assessed
15
Ready · internal
0
In review
0
Not accepted
0
Blocked
0
Expired
0
Expiry missing
0
Owner missing
0
Authority missing
0
Limitation missing
0
Compensating control missing
0
Evidence missing
0
Production · risk acceptance
HOLD · NO-GO
External use · exception
HOLD · NO-GO
Regulator submission · exception
HOLD · NO-GO

Read-only fixture exposed via /api/risk-acceptance-exception-register; reference NAMES, ownership, approver class descriptors, approval forum names, approval state, evidence reference IDs, limitation text, compensating control text, expiry / review cadence rule class descriptors, escalation path class descriptors, linked gate / control / evidence-pack dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria only. Authoritative row table is rendered in the Approval & Sign-Off Workflow. Mirrored summaries in the Strategic Risk Register & Scenario Planning Centre, the Final Production Launch Control Tower, the Production Go/No-Go Board, the Regulatory Notification & Board Escalation Centre, the Programme Governance & Roadmap Centre, and the Completeness Command Centre. Internal risk-exception readiness posture only — not risk acceptance, not legal/compliance exception, not board waiver, not counsel approval, not regulator acceptance, not production approval, not go-live approval, not external-use waiver, and not temporary workaround approval. No approver name, approver email, approver signature, board minute, board meeting link, board resolution body, exception token, e-signature token, private risk-memo body, privileged legal advice text, privileged work-product, external counsel memo body, customer data, MNPI, live deploy credential, regulator submission body, partner credential, signed-URL secret, OTP code, watermark salt body, IP address, device fingerprint, or live notification channel is returned from any endpoint. Staging or demo acknowledgements do not count as production risk acceptance. Risk acceptance never overrides an unresolved P0 blocker without explicit authority evidence and limitation language.

Production Readiness Executive Cockpit (mirror)

Consolidated launch · external-use · regulator-release · external-bundle posture

HOLD · NO-GO

Mirror of the Production Readiness Executive Cockpit. Read-only consolidation exposed via /api/production-readiness-executive-cockpit; aggregates declared, non-secret summary KPIs from every prior readiness layer. Internal executive readiness consolidation posture only — never overrides a P0 blocker on this Board.

Domains assessed
15
Domains blocked
15
Production launch
HOLD · NO-GO
External use
HOLD · NO-GO
Regulator release
HOLD · NO-GO
External bundle release
HOLD · NO-GO
Open P0 blocker · class count
15
Domains ready · internal
0

Authoritative cockpit rendered in the Executive Cockpit & Daily Operating Rhythm Centre. Mirrored in the Final Production Launch Control Tower, the Completeness Command Centre, the Board Pack & Strategic Reporting Centre, and the Centre Index & Search. Internal executive readiness consolidation posture only — not a production launch authorisation, not regulator submission authorisation, not external-bundle release authorisation, not board approval, not counsel approval, not risk acceptance, not security certification, not compliance certification, not legal advice, not an audit opinion, not a permission grant, and not external-use authorisation. No real approver name, board minute, regulator contact, signed URL, room URL, secret, token, or credential is ever returned. Cockpit explains why BLACKSWAN remains HOLD · NO-GO; never overrides a blocker on this Board.

Assumptions and limitations

This Production Go/No-Go Board is internal readiness decision evidence. It is explicitly not:

All regulated activity on the platform remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture and Completeness Command Centre. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events. Items shown on this Board are plausible sample states consistent with the existing Launch Readiness Command Centre; live values will be sourced from the Pack Registry once the cutover is signed off.