← BLACKSWAN OS
Programme Governance · Roadmap · Delivery
Internal Readiness · Simulated
Centre Status

Programme Governance, Roadmap & Delivery Control Centre

Single pane of glass for board-level programme control across BLACKSWAN Capital Markets OS — roadmap, workstreams, milestones, gates, dependencies, RAID, delivery confidence, change control, decision log, and the board reporting pack. Conservative posture: internal programme readiness workflow only; sequence-and-dependency framing, not date-precision; not a binding delivery commitment; not regulatory approval; not authorization for external launch.

Workstreams
14
8 On Track · 4 Validation · 2 At Risk · 0 Blocked
Gates passed / open
7 / 10
3 gates outstanding · 2 dependency-bound
P0 / P1 blockers
2 / 5
All tracked in RAID with named owner
Programme confidence
0.72
Conditional — Entra cutover + counsel sign-off
Delivery state legend
Not Started Discovery Design Build Staging Validation Blocked At Risk On Track Complete Deferred Risk Accepted Closed
Twelve programme governance domains

Programme Governance, Roadmap & Delivery domains

Roadmap
Now/Next/Later mapped

Sequence-and-dependency framing tied to production-readiness milestones. No date precision; gates govern movement between bands.

Workstream Plan
14 workstreams

One workstream per Centre/spine; owner, current state, next milestone, dependency, blocker, evidence ref, delivery confidence.

Milestones
10 milestones · 3 open

Each milestone bound to a gate, acceptance criteria, evidence pack, named owner.

Dependency Management
2 critical · 5 watch

Upstream → downstream impact, owner, need-by window, contingency, current status. Cross-Centre.

RAID Log
10 open · 2 P0/P1

Risks · Assumptions · Issues · Dependencies — severity, owner, mitigation, due/watch, evidence reference.

Gate Acceptance
7 passed · 3 open

Each gate: acceptance criteria, evidence pack, owner, current state, next decision, risk if missed.

Resource / Owner Map
Named owners across functions

Founder · compliance · risk · security · operations · engineering · counsel · finance · commercial · external assurance.

Delivery Confidence
0.72 programme

Per-workstream confidence (0..1) feeding the programme aggregate. Conditional on Entra cutover + counsel sign-off.

Change Control
Wired to Release Control

Programme-level change record references Release Control, ADRs, evidence diff. Dual sign-off for Tier-1.

Board Reporting
Pack preview live

Executive summary, current launch posture, gates passed, open P0/P1, dependency watch, next decisions, asks of board.

Decision Log
9 decisions logged

Programme-level decisions with context, alternatives considered, rationale, owner, date, evidence hash.

Programme Evidence Pack
Pack assembled

Roadmap · workstreams · milestones · RAID · gates · RACI · change log · decisions · audit trail.

Workstream plan

Fourteen workstreams · owner · next milestone · dependency · confidence

Workstream Owner Current state Next milestone Dependency Blocker Confidence Evidence ref
Evidence Spine Head of Evidence On Track M-EV — Pack readiness re-attestation None None 0.92 PG-EV-WS-001
Auth / Security CISO · Identity Lead Validation M-AUTH — Entra OIDC cutover Tenant admin sign-off Entra tenant cutover pending (CHG-001) 0.58 PG-EV-WS-002
Jurisdiction Readiness Head of Regulatory · External Counsel At Risk M-REG — Counsel rule-pack sign-off (ADGM/FCA/MAS/MiFID) External counsel availability Counsel session pending 2026-05-19 0.55 PG-EV-WS-003
Launch Readiness Programme Manager On Track M-LR — Readiness review weekly cadence Auth + Regulatory workstreams None 0.82 PG-EV-WS-004
Go/No-Go & Sign-Off Programme Manager · CISO On Track M-GNG — Production go/no-go board Launch Readiness pack None 0.80 PG-EV-WS-005
Release Control SRE Lead · Programme Manager On Track M-RC — Quarterly rollback drill None None 0.90 PG-EV-WS-006
Monitoring / Incident SRE Lead · CISO On Track M-MON — Quarterly IR drill None None 0.88 PG-EV-WS-007
Stakeholder Rooms Head of Stakeholder Rooms · CISO On Track M-SR — Per-room access review on next share Auth workstream None 0.84 PG-EV-WS-008
Commercial Onboarding Head of Commercial · CFO Validation M-CO — KYC contract sign-off · onboarding go-live External Counsel KYC contract sign-off pending 0.68 PG-EV-WS-009
Financial Controls CFO · External Auditor (pending) Validation M-FC — External auditor validation External Auditor engagement Auditor engagement letter pending 0.62 PG-EV-WS-010
Data Governance Data Governance Lead · CISO On Track M-DG — DSR readiness drill None None 0.80 PG-EV-WS-011
Vendor Risk Head of Procurement · Risk Committee At Risk M-VR — Reclassify 2 vendors to material outsourcing External Counsel Counsel review pending (CHG-006) 0.60 PG-EV-WS-012
Model Governance CISO · Head of Regulatory Validation M-MG — Counsel rule-pack sign-off · re-validate Jurisdiction Readiness workstream Counsel rule pack pending 0.64 PG-EV-WS-013
Enterprise Architecture Programme Manager · SRE Lead On Track M-EA — DR drill 2026-06-12 SRE Lead capacity None 0.86 PG-EV-WS-014
Roadmap board

Now · Next · Later — sequence & dependency, not dates

Posture: roadmap items are scoped by sequence and dependency gate, not calendar date. "Now" means actively in the controlled middle path; "Next" sits behind a single named gate; "Later" sits behind two or more gates or is conditional on board/regulator/counsel engagement that has not opened. Movement between bands requires gate passage, not the calendar.

Now · in controlled middle path

  • Microsoft Entra OIDC cutoverCHG-001 · Auth / Security · Tier-1
  • Counsel rule-pack sign-off (ADGM/FCA/MAS/MiFID)Jurisdiction Readiness · External Counsel
  • WAF custom rule pack — shadow → enforceCHG-003 · Security Operations
  • SIEM DLP egress production testCHG-004 · Security · Data Governance
  • Quarterly DR drillCHG-005 · 2026-06-12 · all Tier-1
  • Vendor reclassification to material outsourcingCHG-006 · Vendor Risk · Counsel

Next · gated on Now

  • Production Go/No-Go boardGate: Auth + Reg + Sec all green
  • Revenue classifier validation v0.6.1CHG-002 · External Auditor sign-off
  • Commercial onboarding go-liveGate: KYC contract + Financial Controls
  • Promote Model Governance to production candidateGate: Counsel rule-pack signed
  • Promote Security Ops to production readyGate: Entra cutover + DLP test pass
  • Board reporting pack — first issueGate: Production posture stable for 2 cycles

Later · gated on Next

  • External launch authorizationGates: Board · Counsel · Regulator engagement
  • First counterparty pilot tenantGates: Commercial · Security · Counsel per-pilot
  • Regulator demoGates: Reg notification · Counsel pre-approval
  • External SOC 2 / ISO 27001 assessor engagementGates: Security pack · Board approval
  • External auditor full-year engagementGates: Financial Controls · Board approval
  • DORA / OpRes attestation trackGates: Resilience · Counsel · Reg engagement
Milestone & gate tracker

Milestone · gate · acceptance criteria · evidence · owner · status

Milestone Gate Acceptance criteria Evidence pack Owner Current status Risk if missed Next decision
M-AUTH Entra OIDC cutover Entra app registered · MFA enforced · sign-in failure rate < 0.5 % Security Evidence Pack CISO · Identity Lead Validation Dependent workstreams held at staging Run CHG-001 window
M-REG Counsel rule-pack sign-off External counsel countersign · jurisdiction limitation phrasing finalised Regulatory Notification Pack Head of Regulatory · External Counsel At Risk Model Governance & Reg. Escalation held Counsel session 2026-05-19
M-LR Launch Readiness review 21 evidence packs ≥ readiness threshold · zero P0 blockers Launch Readiness Pack Programme Manager On Track Go/No-Go delayed Continue weekly review
M-GNG Production Go/No-Go board Dual sign-off · zero P0 blockers · rollback plan attached Go/No-Go Pack Programme Manager · CISO On Track Production launch delayed Gate post Entra cutover
M-RC Quarterly rollback drill Rollback within Tier-1 RTO 30 m · evidence captured Release Control Pack SRE Lead On Track OpRes attestation slip Schedule next drill
M-MON Quarterly IR drill Tabletop completed · paging tested · evidence captured Incident Evidence Pack CISO · SRE Lead On Track OpRes attestation slip Schedule next drill
M-SR Per-room access review Recipient list · MNPI scope · TTL recorded Stakeholder Rooms Pack Head of Stakeholder Rooms On Track Room access ledger gap Continue per-share cadence
M-CO KYC contract sign-off Counsel-approved contract · KYC partner integration tested Commercial Onboarding Pack Head of Commercial · External Counsel Validation Commercial onboarding cannot go live Counsel sign-off window
M-FC External Auditor validation Engagement letter signed · validation suite passed Financial Controls Pack CFO · External Auditor Validation Revenue classifier hold continues Auditor sign engagement letter
M-EA DR drill (active-passive) Tier-1 RTO 30 m / RPO 5 m met · regression report clean Architecture Evidence Pack SRE Lead · CISO On Track · 2026-06-12 OpRes attestation slip Run CHG-005
Dependency map

Upstream → downstream · need-by window · contingency

Upstream dependency Downstream impacted Centre / pack Owner Need-by window Contingency Status
Entra OIDC cutover Security Ops · Model Gov · Vendor Risk · Commercial Onboarding CISO · Identity Lead Before Go/No-Go board Stage-only operation with simulated factors Critical
External counsel rule-pack sign-off Model Governance · Reg. Escalation · Vendor Risk Head of Regulatory · External Counsel Before Production Go/No-Go Restrict affected outputs · use limitation footer Critical
External Auditor engagement Financial Controls Pack · Revenue Classifier validation CFO Before commercial onboarding go-live Hold revenue treatment hints · audit-flag affected events Watch
KYC partner contract Commercial Onboarding Pack Head of Commercial · External Counsel Before commercial onboarding go-live Manual onboarding fallback (counsel-bounded) Watch
WAF custom rule pack sign-off (CISO) Security Ops · all edge routes CISO · SRE Lead Before custom-rule enforce OWASP pack live · manual review of critical paths On Track
SIEM DLP egress production test Security Ops · Data Governance Data Governance Lead · CISO Before promote Security Ops to production Restricted-class data tagged · ABAC denies enforced On Track
DR active-passive drill Architecture · Release Control · Monitoring SRE Lead · CISO 2026-06-12 window Quarterly recurrence; failure → re-drill in 2 wk On Track
RAID log

Risks · Assumptions · Issues · Dependencies

ID Type Title Severity Owner Mitigation Due / Watch Evidence ref State
RAID-001 Risk Entra cutover slips behind Go/No-Go window P0 CISO · Identity Lead Stage-only operations; weekly status; pre-cutover dry run 2026-06-08 SEC-EV-ENTRA-001 At Risk
RAID-002 Risk External counsel rule-pack sign-off delayed P1 Head of Regulatory Restrict affected outputs; limitation footer; counsel session 2026-05-19 2026-05-19 MR-EV-DTWN-001 At Risk
RAID-003 Assumption Entra tenant admin will sign off application registration on first request P2 CISO Pre-brief tenant admin; reserve fallback window 2026-05-30 SEC-EV-ENTRA-001 On Track
RAID-004 Issue Billing webhook technical owner not named in RACI P3 CFO · SRE Lead SRE on-call covers; billing-oncall alert routes 2026-05-22 EA-EV-SVC-013 In Progress
RAID-005 Issue Break-glass test overdue P2 CISO · COO Sealed account · dual approver · drill scheduled 2026-05-26 2026-05-26 SEC-EV-BREAK-007 On Track
RAID-006 Dependency External Auditor engagement letter open P1 CFO Maintain dual-source candidate list; counsel-aware 2026-06-15 EA-EV-SVC-013 Watch
RAID-007 Risk WAF false-positive spike on enforcement P2 CISO · SRE Lead Shadow-mode baseline 7 d · staged enforcement · auto-rollback rule 2026-05-30 WAF-EV-002 On Track
RAID-008 Assumption Counsel will support per-pilot tenant template under existing engagement P3 Head of Commercial · External Counsel Pre-brief counsel; reserve per-pilot review slot 2026-06-30 EA-EV-SVC-012 On Track
RAID-009 Risk Vendor concentration (single email provider) under FCA OpRes scrutiny P2 SRE Lead · Head of Procurement Dual-provider readiness · failover docs · drill 2026-06-08 EA-EV-SVC-017 In Progress
RAID-010 Dependency DR drill capacity (SRE oncall + CISO availability) P2 SRE Lead Hold window 2026-06-12 23:00–02:00 UTC · backup oncall named 2026-06-12 EA-EV-SVC-MASTER On Track
Acceptance criteria matrix

P0 / P1 / P2 by readiness track

Track P0 (blocker) P1 (must) P2 (should) Owner
Production launch Entra cutover · Tier-1 SLOs met · zero P0 RAID open Counsel rule-pack signed · DR drill passed · audit attestation External-assurance kick-off scheduled Programme Manager · CISO
External launch authorization Board approval · counsel sign-off · regulator engagement opened Counterparty pilot tenant validated · per-pilot counsel review External assessor engagement letter drafted Board · CEO · External Counsel
Board / Regulator preview Read-only preview env live · curated synthetic data · auto-revoke Counsel pre-approval · observer-role RBAC · audit-logged Demo runbook tested · rehearsal completed Head of Regulatory · Programme Manager
Stakeholder room activation Recipient list · MNPI scope · TTL · room-link signing Per-room access review · auto-revoke schedule Drill on anomaly triage Head of Stakeholder Rooms · CISO
Financial readiness CFO sign-off · revenue treatment baseline locked External Auditor validation · audit binder current Quarterly close timing tested CFO · External Auditor
Security readiness Entra OIDC enforced · zero open P0 vuln · access reviews current WAF custom pack enforced · DLP test passed · break-glass drill captured External pen-test scoped CISO
Data governance readiness Data inventory classified · retention policy enforced · DSR runbook live Cross-border posture signed · vendor DPA current · privacy incident wired External privacy assessment scoped Data Governance Lead · CISO
Resource · owner · RACI panel

Functional accountability across the programme

Function Lead Accountable for Responsible for Consulted Informed
Founder / CEO Founder External launch authorization · board engagement Strategic decisions · escalation acceptance Board · Counsel · CISO Programme · all leads
Compliance / Regulatory Head of Regulatory Jurisdiction readiness · counsel-bound submissions Rule pack · binder drafting · regulator engagement External Counsel · CISO · CFO Programme · Board
Risk Risk Committee Chair Programme risk posture · risk acceptance RAID log review · exception sign-off CISO · CFO · External Counsel Board · Programme
Security CISO Security posture · IAM · incident response Controls inventory · access reviews · IR drills SRE Lead · Data Governance Lead Programme · Board
Operations / SRE SRE Lead Production reliability · release control · DR Monitoring · runbooks · rollback · DR drills CISO · Programme Manager Programme · Board
Engineering Engineering Lead Build · staging · production candidate quality Service implementation · test evidence · ADR adherence SRE Lead · CISO Programme
Legal / Regulatory Counsel External Counsel Counsel-bound sign-offs · regulator-facing artefacts Rule pack countersign · pilot template · per-share review Head of Regulatory · CISO · Board Programme
Finance CFO Financial controls · revenue posture · audit readiness Billing · invoicing · audit binder · auditor engagement External Auditor · Head of Commercial Programme · Board
Commercial Head of Commercial Counterparty onboarding · pilot engagement KYC contract · pilot template · CRM integration External Counsel · CFO Programme
External Assurance External Assessor (pending) Independent attestation (SOC 2 / ISO / privacy) Scoped engagement on evidence pack CISO · CFO · Board Programme
Change control · programme view

Proposed change · affected Centre · evidence impact · release window

Change ID Proposed change Affected Centre / service Evidence impact Approval required Release window Rollback / communication need
CHG-001 Microsoft Entra OIDC cutover Auth · Security Ops · Model Gov · Vendor Risk · Commercial Onboarding Auth event log change · SIEM index re-bind · evidence access re-tag CISO + CEO sign-off · Board info 2026-06-08 02:00–05:00 UTC Revert to staging factors · re-issue tokens · stakeholder comms
CHG-002 Revenue classifier validation v0.6.1 Financial Controls · Model Governance Audit binder addendum · classifier evidence CFO + External Auditor 2026-06-15 (TBC) Lock previous baseline · audit-flag · CFO comms
CHG-003 WAF custom rule pack shadow → enforce Security Operations · all edge routes WAF event sample · SIEM index CISO sign-off 2026-05-30 22:00–24:00 UTC Disable custom pack · stakeholder comms if false-positive spike
CHG-004 SIEM DLP egress production test Security Operations · Data Governance DLP event evidence CISO + Data Governance Lead 2026-05-30 06:00–08:00 UTC Disable rule · revert to monitor-only
CHG-005 Quarterly DR drill All Tier-1 services DR drill report · RTO/RPO evidence SRE Lead + CISO 2026-06-12 23:00–02:00 UTC Snapshot pin · stakeholder comms · regulator info
CHG-006 Reclassify 2 vendors to material outsourcing Vendor Risk · Regulatory Escalation Vendor inventory diff · regulator notice template External Counsel + Risk Committee Effective 2026-06-01 Revert classification · Risk Committee comms
CHG-007 Board reporting pack — first issue Programme Governance · Board view Board pack evidence · narrative artefact CEO + Board Chair Effective on next board cycle Revert to summary-only · CoS comms
Board reporting pack · preview

Executive summary · posture · gates · blockers · asks of board

Executive summary

  • Posture · ConditionalProgramme confidence 0.72 · 2 P0/P1 RAID open
  • Gates passed7 of 10 · 3 open · 2 dependency-bound
  • Production postureHeld at Production Candidate pending Entra + counsel
  • External launchIn Later band — board + counsel + regulator engagement required
  • LimitationInternal readiness only · not regulatory approval

Completed gates & open blockers

  • Completed gates (7)EV · LR · GNG-prep · RC · MON · SR · DG
  • Open gates (3)AUTH (Entra) · REG (counsel) · CO (KYC contract)
  • P0 blockers (2)RAID-001 Entra slip · RAID-002 counsel rule-pack delay
  • P1 blockers (5)RAID-006 auditor · RAID-007 WAF false-positive risk · ...
  • Dependency watchEntra · counsel · auditor · KYC partner

Next decisions & asks of board / advisers

  • Board approveEntra cutover window (CHG-001)
  • Counsel commitRule-pack countersign by 2026-05-19 session
  • CFO + AuditorSign engagement letter; unblock revenue classifier (CHG-002)
  • Risk CommitteeApprove vendor reclassification (CHG-006)
  • Board confirmAcceptance of permanent founder-root risk (standing)
  • CEO + Board ChairApprove first issue of board reporting pack (CHG-007)
Programme decision log

Decision · context · alternatives · rationale · owner · evidence

Decision ID Decision Context Alternatives Rationale Owner Date Evidence hash
DEC-001 Hold Production Candidate services until Entra + counsel close External-launch risk vs. ship-now pressure Ship now · hold · ship subset Holding is the only posture that aligns with internal readiness disclaimers Programme Manager · CISO · CEO 2026-05-08 sha256:dec1…00a1
DEC-002 Roadmap uses Now/Next/Later, never dates Avoid false precision in board view Date-based Gantt · Now/Next/Later · OKR-only Sequence-and-gate framing is honest and defensible Programme Manager · CEO 2026-04-22 sha256:dec2…00a2
DEC-003 Issue board reporting pack only after 2 stable cycles post production posture Avoid premature external commitment Issue now · issue after 1 cycle · after 2 cycles Two cycles buys signal stability and counsel comfort CEO · Board Chair · External Counsel 2026-05-02 sha256:dec3…00a3
DEC-004 External launch held in Later band until board · counsel · regulator engagement opened Avoid unsupported external claims Soft-launch · pilot-first · hold Pilot-first inside Later band is the bounded path Board · CEO · External Counsel 2026-05-10 sha256:dec4…00a4
DEC-005 Accept permanent founder-root risk with monthly attestation Single-founder governance reality Eliminate root · time-box · accept with compensating control Accepted standing risk with compensating control (MFA + re-auth + monthly attestation) Board (dual) · CISO 2026-04-12 sha256:dec5…00a5
DEC-006 Hold revenue classifier outputs until external auditor signs engagement letter Conservative auditor posture Ship now · hold · audit-flag-only Hold + audit-flag is the only auditor-defensible posture CFO · External Auditor (pending) 2026-05-09 sha256:dec6…00a6
DEC-007 Counterparty pilots use per-pilot tenant template, not shared prod MNPI + counsel posture Shared tenant · per-pilot · per-counterparty per-engagement Per-pilot tenant is the boundary that survives MNPI scrutiny Head of Commercial · CISO · External Counsel 2026-05-11 sha256:dec7…00a7
DEC-008 Reclassify 2 vendors to material outsourcing pending counsel review UK FCA OpRes / EU DORA framing No-action · reclassify all · reclassify two Two-vendor reclassification is the proportionate response Head of Procurement · Risk Committee · External Counsel 2026-05-14 sha256:dec8…00a8
DEC-009 Adopt active-passive DR with Tier-1 RTO 30 m / RPO 5 m UK FCA important business service tolerance Active-active · active-passive · cold-standby Active-passive meets RTO/RPO at staged cost; ADR-008 SRE Lead · CISO 2026-05-09 sha256:dec9…00a9
Audit trail & evidence preservation

Audit log of programme & delivery events

Timestamp (UTC) Actor Programme item Action Evidence hash Limitation recorded Next step
2026-05-08 09:00 Programme Manager Workstream plan PG-WS — 14 workstreams published sha256:pg11…aa01 "Internal programme readiness only." Weekly status
2026-05-08 10:42 Programme Manager · CEO Roadmap board PG-ROADMAP — Now/Next/Later published sha256:pg22…aa02 "Sequence-and-dependency framing, not dates." Re-publish on gate movement
2026-05-09 11:18 Programme Manager Milestones PG-MILESTONES — 10 milestones / 3 open sha256:pg33…aa03 "Internal." Close M-AUTH then M-GNG
2026-05-10 08:32 Programme Manager · SRE Lead Dependency map PG-DEP — 7 dependencies tracked sha256:pg44…aa04 "Internal." Watch 2 critical
2026-05-11 14:00 Programme Manager · Risk Committee RAID log PG-RAID — 10 open · 2 P0/P1 sha256:pg55…aa05 "Internal." Weekly review
2026-05-12 09:48 Programme Manager · CISO Gate tracker PG-GATES — 7 passed · 3 open sha256:pg66…aa06 "Internal." Close AUTH · REG · CO gates
2026-05-08 17:00 Programme Manager · CISO · CEO DEC-001 (Hold Production Candidate) Decision recorded sha256:dec1…00a1 "Internal." Reassess on gate close
2026-04-22 11:30 Programme Manager · CEO DEC-002 (Now/Next/Later roadmap) Decision recorded sha256:dec2…00a2 "Internal." Re-publish on band movement
2026-05-15 13:00 CEO · Board Chair Board reporting pack preview PG-BOARD — preview issued sha256:pg77…aa07 "Preview; not external publication." Issue after 2 stable cycles
2026-05-14 09:05 CISO · Identity Lead CHG-001 (Entra cutover) Change record opened sha256:chg1…bb01 "Internal." Sign-off + run window
2026-05-16 08:30 Programme Manager · CISO · CFO Programme attestation PG-ATTESTATION — monthly programme attestation sha256:pg88…aa08 "Internal; not regulatory approval." Re-attest monthly
Change Freeze, Release Approval & Rollback Evidence Gate

Release-control readiness mirror

Programme-level mirror of the release / change-freeze / rollback gate. Production launch requires an approved release candidate, a declared change freeze, an approved release window, CAB + Board + Compliance + Risk sign-offs, deployment evidence, CI/CD provenance, a rollback plan, a rehearsed rollback drill, database / data-migration rollback evidence, feature flag / kill-switch arming, a dependency freeze, a post-release monitoring window, incident bridge readiness, release communications, and a captured go-live authority. Staging or demo deployment does not count as production release evidence. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is exposed by this Centre, the API at /api/release-approval-rollback-evidence, the fixture, or any commit.

Controls assessed
28

Release candidate · freeze · window · sign-offs · deployment · CI/CD · rollback · DB · flags · dependency freeze · monitoring · bridge · comms · authority

Ready · internal
0

Owner + approver + approval + evidence + (where applicable) rollback drill captured

Approval pending
28

CAB · Board · Compliance · Risk · Founder Office counter-sign not yet captured

Rollback rehearsal untested
5

Rollback / DB rollback / kill-switch drill not in freshness window

Evidence missing
2

Manifest · sign-off · dependency lock · comms record not linked

Rollback blocked
8

Rollback plan + drill + DB rollback + flag/kill-switch not all approved & evidenced

Post-release monitoring
1

Post-release monitoring window not declared / approved / evidenced

Production launch
HOLD · NO-GO

Until release candidate + freeze + window + sign-offs + deployment + CI/CD + rollback + drill + DB + flags + dependency freeze + monitoring + bridge + comms + authority captured

Authoritative row table is rendered in the Release Control & Rollback Centre. Mirrored summaries in the Final Production Launch Control Tower, the Production Go/No-Go Board, the Approval & Sign-Off Workflow, the Production Monitoring & Incident Command Centre, and the Completeness Command Centre. Read-only fixture exposed via /api/release-approval-rollback-evidence; cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, /api/backup-restore-recovery-evidence, /api/observability-slo-incident-evidence, /api/entra-oidc-readiness, /api/evidence-pack-gate-validation, and /api/jurisdictional-permissions-matrix. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is returned from any endpoint. Internal release-control readiness posture only · not security certification · not regulatory approval · not external endpoint authorisation · not external-use authorisation. Staging or demo deployment does not count as production release evidence.

§ Counsel, Compliance & Board Approval Authority Register

Counsel · Compliance · Board approval-authority map — internal posture only

Programme-level mirror of the approval-authority register. Production launch, regulator submission, external bundle release, incident escalation, and CAB / production change gates remain HOLD · NO-GO until each required approval-authority control — internal & external Counsel authority, Compliance / CCO, MLRO, Risk Committee, CISO, CFO, Board / Audit Committee / Risk Committee, Founder Office, go-live counter-sign, regulator-submission counter-sign, external bundle release counter-sign, incident escalation, CAB / production change, delegated authority matrix, expiry / recertification register, and escalation / override register — is captured with owner + named forum / approver class descriptor + approval state + evidence reference + quorum / signature rule + delegated authority reference + expiry / recertification rule + escalation path + last-reviewed date. Staging or demo acknowledgements do not count as production approval authority.

Controls assessed
19
Ready · internal
0
Approval pending
0
Quorum unverified
0
Signature rule missing
0
Delegation unverified
0
Expiry unset
0
Escalation unmapped
0
Production launch · approval
HOLD · NO-GO
External release · approval
HOLD · NO-GO
Regulator submission · approval
HOLD · NO-GO

Read-only fixture exposed via /api/approval-authority-register; reference NAMES, ownership, approval forum names, approver class descriptors, approval state, evidence reference IDs, quorum / signature rule class descriptors, delegated authority class descriptors, expiry / recertification rule class descriptors, escalation path class descriptors, linked gate / control / evidence-pack dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria only. Authoritative row table is rendered in the Approval & Sign-Off Workflow. Mirrored summaries in the Final Production Launch Control Tower, the Board Pack · Investor Narrative · Strategic Reporting Centre, the Regulatory Notification & Board Escalation Centre, and the Completeness Command Centre. Staging or demo acknowledgements do not count as production approval authority. Internal approval-authority readiness posture only — not Counsel approval, not Compliance / CCO / MLRO sign-off, not Risk Committee resolution, not CISO / CFO sign-off, not board approval, not quorum determination, not signature rule satisfaction, not delegated authority grant, not board minute, not board countersign, not go-live authorisation, not regulator-submission release authority, not external bundle release authority, not incident escalation authority, not production change / CAB authority, and not external-use authorisation.

§Risk · Production Risk Acceptance & Exception Register

Risk-exception readiness map — internal posture only

Holds every exception-dependent gate (production launch, regulator submission, external bundle release, incident escalation, CAB / production change, go-live counter-sign, partner-route activation, secret rotation) at HOLD · NO-GO until each required risk-exception control — Entra OIDC transition exception, jurisdictional permission limitation, evidence-pack metadata exception, external-bundle release limitation, regulator-submission limitation, backup / restore readiness exception, observability / SLO exception, release / rollback exception, approval-authority exception, partner-route / mTLS readiness exception, secret / key custody exception, production config missing exception, data / MNPI boundary exception, incident escalation exception, and go-live authority exception — is captured with owner + approver class descriptor + approval forum + approval state + evidence reference + limitation text + compensating control + expiry + review cadence + escalation path + last-reviewed date. Staging or demo acknowledgements do not count as production risk acceptance. Risk acceptance never overrides an unresolved P0 blocker without explicit authority evidence and limitation language.

Exceptions assessed
15
Ready · internal
0
In review
0
Not accepted
0
Blocked
0
Expired
0
Expiry missing
0
Owner missing
0
Authority missing
0
Limitation missing
0
Compensating control missing
0
Evidence missing
0
Production · risk acceptance
HOLD · NO-GO
External use · exception
HOLD · NO-GO
Regulator submission · exception
HOLD · NO-GO

Read-only fixture exposed via /api/risk-acceptance-exception-register; reference NAMES, ownership, approver class descriptors, approval forum names, approval state, evidence reference IDs, limitation text, compensating control text, expiry / review cadence rule class descriptors, escalation path class descriptors, linked gate / control / evidence-pack dependency endpoint paths, launch impact text, external-use impact text, and unlock criteria only. Authoritative row table is rendered in the Approval & Sign-Off Workflow. Mirrored summaries in the Strategic Risk Register & Scenario Planning Centre, the Final Production Launch Control Tower, the Production Go/No-Go Board, the Regulatory Notification & Board Escalation Centre, the Programme Governance & Roadmap Centre, and the Completeness Command Centre. Internal risk-exception readiness posture only — not risk acceptance, not legal/compliance exception, not board waiver, not counsel approval, not regulator acceptance, not production approval, not go-live approval, not external-use waiver, and not temporary workaround approval. No approver name, approver email, approver signature, board minute, board meeting link, board resolution body, exception token, e-signature token, private risk-memo body, privileged legal advice text, privileged work-product, external counsel memo body, customer data, MNPI, live deploy credential, regulator submission body, partner credential, signed-URL secret, OTP code, watermark salt body, IP address, device fingerprint, or live notification channel is returned from any endpoint. Staging or demo acknowledgements do not count as production risk acceptance. Risk acceptance never overrides an unresolved P0 blocker without explicit authority evidence and limitation language.

Assumptions and Limitations

What this Centre is — and is not

  • Staging / simulated programme data. All workstream names, confidence scores, milestone IDs, RAID entries, decision IDs, and audit events shown here are seed values for an internal programme readiness workflow. They are not a live PMO tool, not a live decision register, and not a live audit log.
  • Internal programme readiness workflow only. This Centre captures BLACKSWAN's internal programme posture. It is not a binding delivery commitment, not legal advice, not regulatory approval, not an audit opinion, and not authorization for external launch.
  • Sequence-and-dependency framing, not date-precision. The roadmap deliberately uses Now/Next/Later bands so movement is governed by gates, not calendar promises. Any specific dates (e.g., DR drill 2026-06-12) are scheduled windows the programme will run within, not customer commitments.
  • Conservative posture on external claims. External launch authorization, regulator demos, and counterparty pilots sit in the Later band specifically because they require board, counsel, and regulator engagement that has not opened. No artefact in this Centre constitutes such authorization.
  • RAID is the source of truth for blockers. If an item is not in the RAID log, it is not a programme commitment. Decisions are governed in the Decision Log; changes flow through Release Control with dual sign-off.