BLACKSWANCapital Markets OS Production Monitoring & Incident Command Centre · v1.0 draft ← Return to OS Architecture
Production Monitoring · Founder-only staging

Production Monitoring & Incident Command Centre Live service health, incident state, SLA/SLO breaches, control thresholds, evidence freshness drift, notification triggers, and post-incident evidence — all owner-named and audit-event-linked.

This Centre is internal monitoring evidence. Numbers below are staging / simulated readings; production thresholds and live telemetry will be wired only once Microsoft Entra OIDC cutover, Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events are on file. No state on this surface implies a supervisor notification, legal advice, an audit opinion, or authorization to launch externally.

Overall posture
Degraded (staging)
Degraded
Two amber signals: data-room policy binding pending; pack readiness drift across 7 packs.
Open incidents
2
Watch · Major 0
Sev-3 evidence-export rerun · Sev-4 MNPI binding watch. No Sev-1/Sev-2.
Notification reviews queued
1
Review
Stakeholder bundle limitation-text review — board observer notified.
SLO budget burn (30d)
17%
Green
Auth + API availability budgets within target on 30-day window.
Incident states used on this Centre
Normal
All domain signals green; no incident open.
Watch
One amber signal; observation under owner.
Degraded
Two or more amber signals; staged response.
Incident Open
Owner-named incident with active runbook.
Major Incident
Sev-1 or Sev-2; cross-team command.
Regulator / Board Notification Review
Counsel + CCO review whether external notification is required.
Contained
Impact arrested; recovery and evidence capture in flight.
Resolved
Service restored; post-incident review scheduled.
Post-Incident Review
T+24h / T+72h / D+7 / D+30 cadence active.
Ten monitoring domains

Each domain has named owner, threshold, and audit-event tag

A domain is the smallest unit that can change state independently. State changes here drive the Health, Incident, Notification, and Runbook sections below.

Domain 1
Auth & Access Founder MFA evidence, session timeout, Entra-ready identity model, Conditional Access posture.
Normal
Domain 2
API / Backend Health /api/health probe, error budget, latency SLO, staging-only SIEM forwarding.
Normal
Domain 3
Evidence Export Pipeline Pack export queue, hash continuity, reviewer signature, limitation text propagation.
Watch
Domain 4
Audit Log Ingestion Immutable audit store; SIEM forwarding lag; hash chain integrity (staging-only).
Normal
Domain 5
Data-Room / MNPI Access Policy-version binding, recipient ledger, watermark integrity, MNPI anomaly triage.
Degraded
Domain 6
Pack Readiness Drift Pack state regressions Green → Amber/Red after window opens; reviewer trail.
Degraded
Domain 7
Approval Expiry 60-day auto-expiry across Approval & Sign-Off conditional / risk-accepted states.
Watch
Domain 8
Jurisdiction State Drift ADGM/FSRA, UK FCA, MAS, MiFID/MiFID II perimeter changes during window.
Watch · 3R · 1A
Domain 9
Incident & Comms Open incidents by severity; comms tree health; notification review queue.
Normal
Domain 10
Third-Party Dependencies Identity provider, hosting, repo, notifications, storage, monitoring tooling.
Normal
Service health metrics

Eleven sample readings — staging values, not production telemetry

Tile thresholds map to the SLO/SLA targets section below and to the rollback triggers on the Release Control & Rollback Centre. Red tiles auto-feed the escalation runbook.

Service uptime (30d)
99.94% Combined Auth + API; staging-only.
Green
Error rate (24h)
0.06% 5xx / total responses across /api/*.
Green
Latency p95 (24h)
142 ms SLO target ≤ 300 ms.
Green
Failed auth (24h)
2 Mistyped passphrase events; below threshold.
Green
Export queue age (p95)
38 s SLO target ≤ 120 s.
Green
Audit ingestion lag
3 s SIEM forwarding lag p95; staging-only.
Green
Data-room anomalies (24h)
1 Policy-version binding pending; tracked on rollback trigger.
Amber
Stale evidence packs
7 Packs with state drift beyond release snapshot.
Amber
Expired approvals
0 Earliest auto-expiry 2026-07-15.
Green
Jurisdiction red / amber
3R · 1A UK FCA, MAS, MiFID/MiFID II red; ADGM/FSRA amber-conditional.
Red
Open incidents
2 Sev-3 / Sev-4. No Sev-1 / Sev-2 in 24h.
Amber
Incident command board

Owner-named incidents with severity, scope, evidence packs, next action, and SLO timer

Sample staging incidents consistent with the Release Control & Rollback Centre posture. No live customer impact.

Severity
Incident · scope · evidence · next action
State
SLO / SLA timer
Sev-4
Data-Room MNPI policy-version binding pending Counterparty Pilot stage on Release Control paused on this signal. Domain 5 amber; recipient ledger live but binding evidence outstanding.
Owner
CCO · CISO
Scope
Counterparty Data Room (paused)
Jurisdictions
ADGM · UK · MAS · EEA
Evidence
pack/data-room-mnpi-access
Next
Re-attest policy-version binding; reviewer pass.
Watch
SLO 72h · 18h elapsed
Sev-3
Evidence export rerun · pack hash continuity One pack export retried after reviewer-signature mismatch detected at limitation-text propagation. No external bundle issued.
Owner
CCO · Founder Admin
Scope
Stakeholder Bundle
Jurisdictions
ADGM · UK · MiFID
Evidence
pack/policy-attestation · export/limitation-text
Next
Limitation-text reviewer pass; restart export.
Incident Open
SLO 24h · 4h elapsed
Sev-3
Notification review · stakeholder bundle limitation-text Board observer notified; CCO and Legal Counsel asked to confirm no external notification required for the limitation-text revision. Internal-only.
Owner
CCO · Legal Counsel
Scope
Stakeholder Bundle
Jurisdictions
ADGM · UK · EEA
Evidence
memo/notification-review
Next
Counsel + CCO decision recorded with rationale.
Notification Review
SLO 24h · 6h elapsed
Sev-3
Jurisdiction state drift watch · UK / MAS / MiFID Three perimeter decisions remain red; no live customer impact, but external scopes blocked. Tracked here so any further drift escalates.
Owner
Regulatory Affairs
Scope
External Pilot · Full Launch
Jurisdictions
UK · MAS · MiFID
Evidence
pack/activity-perimeter-decision
Next
External counsel opinions; supervisor pre-engagement.
Watch
SLO 30d · 18d elapsed
Notification trigger matrix

Who is notified at which severity — conservative review-only triggers

"Required" = recipient must be informed on incident open. "Review" = counsel + CCO will review whether external notification is required; nothing on this surface auto-files a regulator notification. Production cutover and external notification still require Microsoft Entra OIDC and a Legal/Regulatory Counsel decision recorded on the Pack Registry.

Required Review Not required
Recipient Watch Degraded Sev-3 Incident Sev-2 Incident Sev-1 / Major External-notification review
Founder / CEO Not required Required Required Required Required Required
Compliance Owner (CCO / MLRO) Not required Required Required Required Required Required
Risk Owner (CRO / Risk Governance) Not required Review Required Required Required Required
Legal / Regulatory Counsel Not required Review Review Required Required Required
Operations Owner (COO / Post-Trade) Not required Review Required Required Required Review
Engineering / Security Owner (CISO) Required Required Required Required Required Required
Board / Independent Reviewer Not required Not required Review Required Required Required
External Regulator (review only) Not required Not required Not required Review Review Review
Escalation runbook

Nine steps from detection through post-incident review

Each step names the owner and the audit event emitted. Runbook is owner-driven; no step is automated past the staging Sev-3 threshold.

Detect & triage

  • 1. Detection — Domain signal flips Green → Amber/Red. Audit event: DOMAIN-STATE · detect. Owner: CISO.
  • 2. Triage — Open incident card with severity, scope, evidence pack. Audit event: INC-OPEN. Owner: Founder Admin.
  • 3. Contain — Pull scope to No-Go or pause matching Release Control stage. Audit event: SCOPE-CONTAIN. Owner: CISO + CCO.

Rollback & evidence

  • 4. Rollback / pause — Invoke matching trigger on Release Control. Audit event: RC-ROLLBACK. Owner: CISO / COO.
  • 5. Evidence capture — Snapshot affected packs, recipient ledger, audit chain. Audit event: EVIDENCE-CAPTURE. Owner: CCO.
  • 6. Internal notification — Run Notification Trigger Matrix; emit recipient list. Audit event: NOTIFY-INT. Owner: Founder Admin.

External review · recover · PIR

  • 7. External-notification review — Counsel + CCO decide whether supervisor notification is required. Audit event: NOTIFY-EXT-REVIEW. Owner: Legal Counsel.
  • 8. Recovery — Restore service; clear scope; reissue limitation text. Audit event: INC-RECOVER. Owner: COO + CCO.
  • 9. Post-incident review — Schedule T+24h / T+72h / D+7 / D+30 cadence; record lessons. Audit event: PIR-SCHEDULE. Owner: Founder Admin.
Regulatory evidence capture

Structured incident dossier — internal only, reviewer-signed

Snapshot consistent with the Sev-3 evidence-export rerun open above. This dossier is the input the Counsel + CCO Notification Review uses to decide whether external notification is required.

Incident timeline
T+0 2026-05-15 14:07Z · CCO detects reviewer-signature mismatch on stakeholder-bundle limitation-text propagation; export queue paused.
T+8m Founder Admin opens Sev-3; comms tree notified per matrix.
T+18m CCO + Legal Counsel begin external-notification review; bundle held internal-only.
T+45m Reviewer pass complete; export queue cleared.
Decision log
CCO + Legal Counsel: no external notification required at Sev-3; limitation-text revision is internal control event without customer or supervisor impact. Recorded on Pack Registry with rationale + reviewer signature.
Affected evidence packs
pack/policy-attestation · pack/board-pack-attestation · pack/regulatory-exam-response (FSRA limitation text). All other packs unaffected.
Affected jurisdictions
ADGM/FSRA (limitation text); UK FCA + EEA (cadence reference only). MAS unaffected. No live regulated activity, no external bundle distributed during the incident.
Customer / stakeholder impact
No live customer impact. Internal stakeholders (Founder Admin, CCO, CISO, COO, Legal, Board observer) notified per matrix.
Remediation evidence
Limitation-text reviewer pass re-run with second-set-of-eyes evidence; pack hash continuity reconciled; export queue cleared; SIEM event chain intact.
Approvals on file
Founder Admin (incident open); CCO (decision); Legal Counsel (no-external-notification rationale); CISO (audit chain integrity). All recorded on Approval & Sign-Off audit trail.
Residual risk
Pack readiness drift remains Amber (7 packs). Counterparty Pilot stage stays Paused on Data-Room MNPI binding. Stakeholder Bundle distribution remains internal-only.
SLO / SLA & control-threshold panel

Eight targets and current readings

Targets are staging defaults. Production targets will be set in the Microsoft Entra OIDC cutover memo and approved by the Approval & Sign-Off Workflow before any external scope is enabled.

Target
SLO / threshold
Current
State
Auth availability (30d)
≥ 99.9%
99.94%
Green
API availability (30d)
≥ 99.9%
99.91%
Green
Evidence export success rate (24h)
≥ 99%
99.4%
Green
Audit log freshness (lag p95)
≤ 10 s
3 s
Green
Data-room access anomaly threshold (24h)
≤ 0
1
Amber
Pack readiness drift threshold (24h)
≤ 3 packs
7
Amber
Approval expiry threshold (days)
≥ 14 days remaining
61 d
Green
Incident response time (Sev-3 p95)
≤ 60 min
14 min
Green
Third-party dependency panel

Identity provider, hosting, repo, notifications, storage, monitoring

Each dependency carries an owner, intended state, and the Outsourcing Concentration pack reference. Concentration exits and fallback providers remain open across all four jurisdictions — tracked separately on Launch Readiness Gate 3.

Identity provider Cutover pending
Microsoft Entra OIDC target. Staging founder-only backend in use today; cutover application not registered. Tracked on pack/auth and pack/policy-attestation.
Hosting Operating
Static asset hosting + lightweight Node backend (server.js). Single-tenant staging instance. No CDN edge logic affecting auth or evidence paths.
Repo · GitHub Operating
BlackswanPartnership/BlackswanCapitalMarketsOS · OAuth App access restrictions enforced. Pack-export hashes pinned at release freeze.
Email / notifications Manual
Internal stakeholder notification tree is manual today (Founder Admin emits per matrix). No auto-supervisor notification anywhere in the stack.
Data storage Operating
In-memory session registry (staging only); file-system Pack Registry. No real issuer, investor, KYC, MNPI, order-book, custody, or settlement data is enabled.
Monitoring / logging Staging-only
SIEM forwarding currently staging-only; production SIEM target identified but not yet wired. Audit-event capture verified for sign-in, evidence release, and approver actions.
Connected tooling Operating
Document drafting and Pack-Registry tooling. No automated regulator-shared distribution; all external bundles gated by Approval & Sign-Off + Release Control.
Post-incident review cadence

T+24h, T+72h, D+7, D+30 — owner, output, closure criterion

Cadence opened automatically on any incident close. The D+30 review feeds the next Approval & Sign-Off cycle and updates the Launch Readiness blocker register.

T+24h

Owner: Founder Admin + CISO. Same-day fact-check.

  • Timeline reconciled with audit chain.
  • Affected packs and jurisdictions confirmed.
  • Closure criterion: incident-evidence dossier reviewer-signed.

T+72h

Owner: CCO + Risk Owner.

  • Notification review decision recorded.
  • Limitation-text or recipient ledger updates issued.
  • Closure criterion: Counsel + CCO sign-off on rationale.

D+7

Owner: CCO + Founder Admin.

  • Trend review against the SLO/SLA panel.
  • Lessons learned added to Readiness Change Journal.
  • Closure criterion: trend back inside SLO target.

D+30

Owner: Founder/CEO + Board observer.

  • Approval & Sign-Off cycle refreshed.
  • Launch Readiness blocker register updated.
  • Closure criterion: residual risk recorded; incident archived.
Production Hostname, DNS, WAF & Partner-Route Readiness Register · summary

Ingress · edge · mTLS · partner-route controls · route-level monitoring posture

No real production hostname, DNS zone, WAF rule body, mTLS certificate body / private key, partner API endpoint, partner credential, token, or client secret appears here, in the API at /api/production-ingress-route-readiness, in the fixture, or in any commit. The staging URL on which this Centre is served does not count as a production endpoint. Internal ingress / partner-route readiness posture only — not security certification, not regulatory approval, not legal advice, not audit opinion, not compliance certification, not regulator submission, not permission grant, not launch authorisation, not client acceptance, not capital/liquidity adequacy, not external endpoint authorisation, and not external-use authorisation.

Controls assessed
20
Hostname · DNS · TLS · WAF · CDN · gateway · mTLS · partner · rate-limit · monitoring · rollback · authority
Internal-ready
0
Owner + approval + monitoring + rollback
In review
3
Owner / approval / monitoring in flight
Blocked / missing
15
Required controls not captured
Restricted review
1
Counsel / partner-routed review only
External-route blocked
16
Routes externally blocked at WAF / API gateway / DNS
Route monitoring pending
2
Per-route telemetry / SIEM forwarding not yet bound
Production launch
HOLD · NO-GO
Until presence + approval + monitoring + rollback + authority
Endpoint-safety handling

Production hostnames, DNS zones, WAF rule bodies, mTLS certificates, private keys, partner API endpoints, tokens, and client secrets are never read, logged, persisted, or emitted by this register. /api/production-ingress-route-readiness reports only ownership, declared (non-secret) env-key NAMES, per-key presence booleans, approval state, route exposure state, evidence references, and unlock criteria. Until production hostname & DNS ownership, TLS certificate lifecycle, WAF / security edge, API gateway / ingress, mTLS / partner controls, rate-limit / abuse controls, route-level monitoring + audit forwarding, rollback / failover, and the internal external-route go-live authority are present and approved, every external-facing route stays externally blocked at WAF / API gateway / DNS and production launch remains HOLD · NO-GO.

Authoritative register and full row table are rendered in Security Operations · IAM · Zero-Trust Centre, Final Production Launch Control Tower, Integration · API · Data Exchange Centre, and Completeness Command Centre. Cross-references /api/production-config-readiness, /api/entra-oidc-readiness, and /api/auth/posture.

Production Backup, Restore & Data Recovery Evidence Centre

Internal backup/recovery readiness posture only. Monitoring surface mirror — backup job monitoring, alerting, and DR exercise readiness. No backup vault credential, storage account key, database credential, encryption key material, recovery code, signed-URL secret, private endpoint, production data row, or live production dataset appears in this Centre, in the API at /api/backup-restore-recovery-evidence, in the fixture, or in any commit. Staging or demo backups do not count as production recovery evidence. Not security certification, not regulatory approval, not legal advice, not audit opinion, not external endpoint authorisation, and not external-use authorisation.

Controls assessed
15

Schedule · scope · encryption · restore · RPO/RTO · WORM · evidence · audit · DB · IaC · runbook · DR · monitoring · retention · authority

Ready · internal
0

Owner + approval + cadence + last backup + restore drill + RPO/RTO + retention captured

Recovery untested
15

Restore drill / DR exercise not within freshness window

RPO/RTO unverified
8

Targets declared · measurement not captured against drill

Retention unverified
15

Retention lock + legal-hold alignment not evidenced end-to-end

Approval pending
15

Required items lacking recovery authority counter-sign

Missing / blocked
10

Required backup / restore / retention evidence not captured

Production launch
HOLD · NO-GO

Until backup scope + restore drill + RPO/RTO + retention + authority captured

Authoritative row table is rendered in the Security Operations · IAM · Zero-Trust Centre and the Final Production Launch Control Tower. Day-2 backup, restore & recovery runbook lives in the Operational Runbooks & Day-2 Support Centre. Retention / legal-hold alignment lives in the Data Governance & Retention Centre. Mirrored summary in the Completeness Command Centre. Read-only fixture exposed via /api/backup-restore-recovery-evidence; cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, and /api/jurisdictional-permissions-matrix. No backup vault credential, storage account key, database credential, encryption key material, recovery code, signed-URL secret, private endpoint, production data row, or live production dataset is returned from any endpoint. Internal backup/recovery readiness posture only · not security certification · not regulatory approval · not external endpoint authorisation · not external-use authorisation. Staging or demo backups do not count as production recovery evidence.

Production Observability, SLO & Incident Evidence Loop

Internal observability/incident readiness posture only. Monitoring surface mirror — health checks, SLO targets & measurement, alert routing, SIEM forwarding, incident command, PIR, escalation SLAs, and regulator/board notification triggers. No monitoring token, webhook secret, SIEM ingest key, PagerDuty/Opsgenie key, on-call paging number, private monitoring endpoint, production log line, customer data, incident room URL, regulator/board notification channel, or live alert payload appears in this Centre, in the API at /api/observability-slo-incident-evidence, in the fixture, or in any commit. Staging or demo monitoring does not count as production observability evidence. Not security certification, not regulatory approval, not legal advice, not audit opinion, not incident notification submission, and not external-use authorisation.

Controls assessed
25

Health · SLOs · dependencies · alert routing · IC · SIEM · detection · export · notify · PIR · escalation · comms · chaos · maintenance · authority

Ready · internal
0

Owner + approval + SLO measured + tested route + logging + PIR captured

SLO unverified
8

Targets declared · measurement not captured

Alert route untested
25

Paging / channel route test not in freshness window

Logging unverified
2

SIEM forwarder / retention not evidenced end-to-end

PIR / drill untested
2

Post-incident review / chaos drill not within freshness window

Escalation / notify pending
25

Runbook + escalation + trigger status not approved end-to-end

Production launch
HOLD · NO-GO

Until SLO + routes + SIEM + IC + PIR + escalation + notify + authority captured

Authoritative row table is rendered in the Security Operations · IAM · Zero-Trust Centre and the Final Production Launch Control Tower. Day-2 incident runbooks live in the Operational Runbooks & Day-2 Support Centre. Regulator/board notification triggers are mirrored in the Regulatory Notification & Board Escalation Centre. Mirrored summary in the Completeness Command Centre. Read-only fixture exposed via /api/observability-slo-incident-evidence; cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, /api/backup-restore-recovery-evidence, /api/entra-oidc-readiness, and /api/jurisdictional-permissions-matrix. No monitoring token, webhook secret, SIEM ingest key, on-call paging number, private monitoring endpoint, production log line, customer data, incident room URL, or live alert payload is returned from any endpoint. Internal observability/incident readiness posture only · not security certification · not regulatory approval · not incident notification submission · not external endpoint authorisation · not external-use authorisation. Staging or demo monitoring does not count as production observability evidence.

Change Freeze, Release Approval & Rollback Evidence Gate

Internal release-control readiness posture only. Monitoring surface mirror for the release / change-freeze / rollback gate. Production launch requires an approved release candidate, a declared change freeze, an approved release window, CAB + Board + Compliance + Risk sign-offs, deployment evidence, CI/CD provenance, a rollback plan, a rehearsed rollback drill, database / data-migration rollback evidence, feature flag / kill-switch arming, a dependency freeze, a post-release monitoring window, incident bridge readiness, release communications, and a captured go-live authority. Staging or demo deployment does not count as production release evidence. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is exposed by this Centre, the API at /api/release-approval-rollback-evidence, the fixture, or any commit.

Controls assessed
28

Release candidate · freeze · window · sign-offs · deployment · CI/CD · rollback · DB · flags · dependency freeze · monitoring · bridge · comms · authority

Ready · internal
0

Owner + approver + approval + evidence + (where applicable) rollback drill captured

Approval pending
28

CAB · Board · Compliance · Risk · Founder Office counter-sign not yet captured

Rollback rehearsal untested
5

Rollback / DB rollback / kill-switch drill not in freshness window

Evidence missing
2

Manifest · sign-off · dependency lock · comms record not linked

Rollback blocked
8

Rollback plan + drill + DB rollback + flag/kill-switch not all approved & evidenced

Post-release monitoring
1

Post-release monitoring window not declared / approved / evidenced

Production launch
HOLD · NO-GO

Until release candidate + freeze + window + sign-offs + deployment + CI/CD + rollback + drill + DB + flags + dependency freeze + monitoring + bridge + comms + authority captured

Authoritative row table is rendered in the Release Control & Rollback Centre. Mirrored summaries in the Final Production Launch Control Tower, the Production Go/No-Go Board, the Approval & Sign-Off Workflow, the Programme Governance & Roadmap Centre, and the Completeness Command Centre. Read-only fixture exposed via /api/release-approval-rollback-evidence; cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, /api/backup-restore-recovery-evidence, /api/observability-slo-incident-evidence, /api/entra-oidc-readiness, /api/evidence-pack-gate-validation, and /api/jurisdictional-permissions-matrix. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is returned from any endpoint. Internal release-control readiness posture only · not security certification · not regulatory approval · not external endpoint authorisation · not external-use authorisation. Staging or demo deployment does not count as production release evidence.

Assumptions and limitations

This Production Monitoring & Incident Command Centre is internal monitoring evidence. Numbers shown are staging / simulated readings. It is explicitly not:

All regulated activity on the platform remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture and Completeness Command Centre. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events. Notification triggers on this surface are review-only: nothing here auto-files a supervisor notification. Items shown are plausible sample states consistent with the existing Release Control & Rollback Centre, Approval & Sign-Off Workflow, and Launch Readiness Command Centre; live values will be sourced from the Pack Registry once the cutover is signed off.