BLACKSWANCapital Markets OS Release Control & Rollback Centre · v1.0 draft ← Return to OS Architecture
Release Control · Founder-only staging

Release Control & Rollback Centre Turns approved launch decisions into staged release execution with monitoring, hold/pause, rollback triggers, and post-launch evidence.

This Centre is internal release-operations evidence. Completed states never imply regulatory approval, legal advice, an audit opinion, or authorization to launch externally — they record that a named owner exercised the runbook against accepted evidence packs for the scope shown. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events.

Release windows
9
stages
From Pre-Release Freeze through Post-Launch Review.
In progress · staging only
2
In progress
Internal Production · Founder/Admin Production.
Risk-accepted pilots
2
Pilot
Board Preview · Regulator Prep (FSRA only).
Blocked / no-go
3
Blocked
Counterparty Data Room · External Pilot · Full Launch.
Release states used on this Centre
Not Started
Stage scoped but no runbook step exercised.
Ready
Entry criteria met; awaiting owner trigger.
In Progress
Runbook step executing under owner control.
Paused
Hold criterion fired; owner-approved resume required.
Rolled Back
Rollback runbook executed end-to-end; scope reverted to prior state.
Completed
Exit criteria met; post-launch review scheduled.
Blocked
Entry criteria unmet — typically P0 blocker or red jurisdiction.
Risk-Accepted Pilot
Owner accepts residual risk for a tightly-scoped, monitored pilot only.
Nine release stages

Owner-driven progression with explicit entry and exit criteria

Each stage names an owner, current state, and the evidence pack that closes it. Sample states below are aligned to the current Approval & Sign-Off Workflow and Production Go/No-Go Board posture: internal/founder scopes Conditional in flight; Board Preview and Regulator Prep Risk-Accepted Pilot; counterparty / external scopes Blocked.

Stage 1 · Pre-Release Freeze Completed
No non-critical merges; evidence-pack hashes pinned
Pack Registry and React bundle hash snapshots captured. Approver signatures from Approval & Sign-Off frozen against the current memo. Out-of-scope merges blocked until release window opens.
Owner
Founder Admin · CISO
Last action
2026-05-15
Stage 2 · Release Window Open Ready
Window time-boxed; comms tree confirmed
2-hour window scheduled for internal-scope rollout; comms tree confirmed (Founder Admin, CCO, CISO, COO observer); rollback responder on call; SIEM rules armed.
Owner
Founder Admin
Window
2026-05-16 14:00–16:00Z
Stage 3 · Canary / Internal Production In Progress
Founder Admin and named internal users only
Canary cohort: Founder Admin session only. Auth health, immutable audit, MNPI controls, SIEM detection on; rollback ready. No external surface.
Owner
Founder/CEO · CISO co-sign
Last action
2026-05-15 06:14Z
Stage 4 · Founder/Admin Production In Progress
Production-flagged surfaces, MFA evidence captured end-to-end
Founder operations against production-flagged surfaces; CCO + Risk Owner + COO sign-offs current; audit-event capture verified; rollback trigger registered.
Owner
Founder/CEO · CCO · CISO · COO
Last action
2026-05-15 09:01Z
Stage 5 · Board Preview Enablement Risk-Accepted Pilot
Watermarked recipient cohort; reviewer trail evidenced
Watermarked Board pack to named directors; token-access anomaly triage armed; recipient exception ledger live. Recall trigger registered against any distribution-gate breach.
Owner
Founder/CEO · Board Liaison
Last action
2026-05-15 11:48Z
Stage 6 · Regulator Prep Enablement Risk-Accepted Pilot
FSRA bundle limitation text on file; UK/MAS/EEA internal-only
Pre-engagement rehearsal scheduled with FSRA; UK FCA, MAS, MiFID/MiFID II response binders rehearsed internally only. Bundle scope drift detection live.
Owner
CCO · Regulatory Affairs
Last action
2026-05-15 13:22Z
Stage 7 · Counterparty Pilot Hold Paused
MNPI rooms not bound to current policy version
Hold criterion fired: Data-Room MNPI policy-version binding pending. No external counterparty distribution. Resume requires CCO + CISO co-sign after pack uplift.
Owner
CCO · CISO
Last action
2026-05-15
Stage 8 · Full External Launch Blocked
Seven P0 blockers open; four of six Launch Readiness gates not closed
Entry criteria unmet across Control Evidence, Operational Resilience, Jurisdiction Readiness, and Controlled Production Launch. Release authorization disabled until P0 blockers close.
Owner
Board · Founder/CEO
Last action
2026-05-15
Stage 9 · Post-Launch Review Not Started
D+1, D+7, D+30 evidence-refresh and limitation re-attestation
Triggered automatically after any Completed or Risk-Accepted Pilot release. Captures incident retrospective, monitoring evidence, defects, lessons learned, and limitation re-attestation.
Owner
Founder Admin · CCO · CISO
Last action
—
Release control board

Scope-level board with entry/exit criteria, rollback trigger, monitoring, and evidence output

Each scope below names the owner, current state, the criterion to enter, the criterion to exit, the rollback trigger, the monitoring signal armed, and the evidence pack that closes the row. States reflect the current launch posture; nothing on this board implies supervisor authorisation.

Scope / Owner
Criteria · trigger · monitoring · evidence
State
Last action
Internal Production
Founder/CEO · CISO co-sign
Entry
Stage 1 freeze captured; Auth + Policy Attestation packs Green.
Exit
Audit-event capture verified end-to-end for 24h; rollback rehearsal evidence recorded.
Rollback
Revoke Founder Admin session and pull scope to No-Go on any P0 SIEM detection.
Monitoring
SIEM rule on auth, MNPI access, outsourcing-route anomalies.
Evidence
pack/auth · pack/policy-attestation · pack/board-pack-attestation.
In Progress
2026-05-15 06:14Z
Founder/Admin Production
Founder · CCO · Risk · CISO · COO
Entry
Internal Production stable for 8h; CCO + Risk + COO sign-offs current.
Exit
30-day audit window without P0; Entra OIDC cutover decision review scheduled.
Rollback
Auto-revert to Internal Production; revoke session; notify Board observer.
Monitoring
Auth health, session anomalies, evidence-export anomalies.
Evidence
pack/policy-attestation · pack/incident · pack/conduct-risk-mi.
In Progress
2026-05-15 09:01Z
Board Preview
Founder/CEO · Board Liaison
Entry
Board pack watermarked; recipient ledger current; Board observer present.
Exit
Director sign-off recorded; recipient exception triage clean.
Rollback
Recall watermarked pack; reissue limitation text on any exception.
Monitoring
Token-access anomaly triage; recipient exception ledger.
Evidence
pack/board-pack-attestation · pack/board-room-recipient-ledger.
Risk-Accepted Pilot
2026-05-15 11:48Z
Regulator Prep · FSRA
CCO · Regulatory Affairs
Entry
FSRA bundle limitation text reviewer-signed; exam-response pack rehearsed.
Exit
FSRA pre-engagement record on file with bundle hash continuity.
Rollback
Suspend pre-engagement if perimeter changes; reissue limitation text.
Monitoring
FSRA bundle scope drift; UK/MAS/EEA perimeter change events.
Evidence
pack/regulatory-exam-response · pack/regulatory-change.
Risk-Accepted Pilot
2026-05-15 13:22Z
Counterparty Data Room
CCO · CISO · Founder
Entry
Data-Room MNPI Access pack Green; policy-version binding evidenced.
Exit
Recipient ledger evidenced; bundle limitation text reviewer-signed.
Rollback
Recall bundle; revoke recipient tokens; reissue limitation.
Monitoring
Token-access attempts; recipient anomaly triage.
Evidence
pack/data-room-mnpi-access · pack/evidence-share-links.
Paused · Hold
2026-05-15
Controlled External Pilot
Board resolution required
Entry
Jurisdiction Readiness gate Green for ≥1 jurisdiction; partner-route assurance attached.
Exit
Pilot run for ≥30 days without P0; supervisor pre-engagement on file.
Rollback
Pull pilot; recall partner-route; notify supervisor of suspension.
Monitoring
Activity perimeter change; partner-route SLA.
Evidence
pack/activity-perimeter-decision · pack/partner-route-assurance.
Blocked
2026-05-15
Full External Launch
Board · Founder/CEO
Entry
Every Launch Readiness gate Green; supervisor pre-engagement on file per jurisdiction; Board resolution recorded.
Exit
30-day Post-Launch Review clean; D+30 sign-off closure.
Rollback
Full revert to Founder/Admin scope; recall every external bundle; notify supervisors.
Monitoring
All monitoring tiles armed at high sensitivity.
Evidence
All 21 packs current with reviewer signature.
Blocked
2026-05-15
Rollback runbook

Eight rollback triggers, each with a named owner and runbook

Each trigger below describes the detection signal, the owner authorised to invoke rollback, and the runbook steps. Every rollback emits an audit event referenced in the timeline below.

Auth failure P0 trigger
Failed founder MFA evidence capture, repeated session-issuance errors, or Entra cutover regression.
  1. CISO revokes active production sessions.
  2. Pull scope to No-Go; emit AUTH-STG audit event.
  3. Restore staging Auth path; notify Founder Admin and Board observer.
Evidence export failure P0 trigger
Pack export hash discontinuity, missing reviewer signature, or controlled bundle limitation text mismatch.
  1. CCO halts all bundle distribution; reissue limitation text.
  2. Recall any in-flight controlled bundle via token revocation.
  3. Re-attest pack on Pack Registry; reviewer pass required before resume.
Stale jurisdiction state P1 trigger
Jurisdiction Readiness state for ADGM/FSRA, UK FCA, MAS, or MiFID/MiFID II slips to Red beyond SLA, or supervisor pre-engagement record expires.
  1. Regulatory Affairs flags the jurisdiction red on Launch Readiness.
  2. Pause every scope dependent on that jurisdiction.
  3. Re-attest Activity Perimeter Decision pack before resume.
Data-Room / MNPI access anomaly P0 trigger
Recipient-exception ledger fires, MNPI room policy-version mismatch, or watermark integrity check fails.
  1. CCO + CISO recall MNPI room access; revoke recipient tokens.
  2. Trigger reviewer round on the affected pack.
  3. Resume only after policy-version binding re-evidenced.
Audit log failure P0 trigger
Immutable audit-event store dropped events, hash continuity broke, or SIEM forwarding lag exceeded SLA.
  1. CISO suspends all scopes with external surface.
  2. Replay missing events from staging buffer; reconcile hash chain.
  3. Resume only after audit-log integrity reviewer pass.
Incident escalation P0 trigger
Any incident classified Sev-1 or Sev-2 on the Incident pack within an active release window.
  1. Founder Admin invokes hold; comms tree notified.
  2. Incident commander runs containment per Incident pack runbook.
  3. Post-incident review scheduled; Stage 9 trigger set.
Backend health failure P1 trigger
Health-probe error rate > 1% or sustained latency above SLO threshold during window.
  1. COO halts deployment; engineering rolls back to last known good.
  2. Comms tree updated; window paused.
  3. Resume only after health check stable for 30 minutes.
Regulator-response bundle mismatch P0 trigger
FSRA, UK FCA, MAS, or MiFID/MiFID II exam-response bundle drifts from approved scope or limitation text.
  1. CCO + Regulatory Affairs revoke any distributed bundle.
  2. Re-issue limitation text; reviewer pass required.
  3. Notify Founder Admin and Board observer.
Monitoring dashboard

Nine signals armed during any active release window

Sample readings consistent with the current staging posture. Signal thresholds map directly to the rollback triggers above. A red tile auto-routes to the escalation tree.

Auth health
99.94% Last 24h, founder MFA success ratio.
Green
API / backend health
99.91% /api/health probe; staging-only SIEM forwarding.
Green
Evidence export queue
2 / 0 In-flight / failed in the last hour.
Green
Audit log ingestion
100% Hash continuity intact; SIEM lag < 5s (staging).
Green
Data-room access anomalies
1 Policy-version binding pending; tracked on rollback trigger.
Amber
Pack readiness drift
7 Packs whose state changed in last 24h; compared to release snapshot.
Amber
Approval expiry
61d Days until earliest conditional / risk-accepted state auto-expires (2026-07-15).
Amber
Jurisdiction red / amber
3R · 1A UK FCA, MAS, MiFID/MiFID II red; ADGM/FSRA amber-conditional.
Red
Incident severity (24h)
0 · 0 · 0 Sev-1 · Sev-2 · Sev-3 open. None active during current window.
Green
Hold / pause criteria · escalation routing

Who can pause, who can resume, evidence emitted

Every pause emits an audit event referencing the rationale and the evidence pack snapshot at hold time. Resume requires the named approver and a reviewer pass on the underlying pack.

Pause trigger
Detail · evidence emitted
Pause approver
Resume approver
P0 SIEM detection
Any P0 rule fires (auth, MNPI, outsourcing-route anomaly). Audit event: AUTH-STG · pause.
CISO
CISO + Founder
Pack readiness drift
Pack state regresses Green → Amber/Red after window opens. Audit event: PACK-REG · pause.
CCO
CCO + Risk Owner
Approval expiry
Required approval lapses or 60-day auto-expiry hit. Audit event: APPROVE-EXP · pause.
Auto
Original approver + Founder
Jurisdiction state change
ADGM/FSRA, UK FCA, MAS, or MiFID/MiFID II perimeter state changes during window. Audit event: REG-CHG · pause.
Regulatory Affairs
CCO + Legal Counsel
Incident Sev-1 / Sev-2
Incident classified Sev-1 or Sev-2 anywhere on the platform during window. Audit event: INCIDENT · pause.
Founder Admin
Founder + COO + CISO
Bundle scope mismatch
Controlled bundle limitation text or scope drifts from approved memo. Audit event: BUNDLE-DRIFT · pause.
CCO
CCO + Regulatory Affairs
Launch-window checklist · dry-run evidence

Every item evidenced before the window opens

Each item is owner-named and produces an evidence artifact stored on the Pack Registry. A red checkbox blocks the window from opening.

✓Closed ~Conditional ✗Blocking
Window evidence
Owner
✓
Deployment artifact hash pinned React bundle, server.js, and Pack Registry snapshot SHA recorded at freeze.
CISO
✓
Approver snapshot from Approval & Sign-Off Every required sign-off for the window's scopes recorded with name, role, time, and pack hash.
Founder Admin
✓
Evidence pack snapshot All 21 packs' state, owner, last-reviewed, and limitation text captured at freeze.
CCO
✓
Rollback plan Eight rollback triggers mapped to named owners with runbook steps; revert path tested in staging.
CISO · COO
✓
Comms plan Internal stakeholder notification tree; no external comms during internal-scope window.
Founder Admin
✓
Monitoring plan All nine monitoring tiles armed; thresholds set to staging values; on-call rotation confirmed.
CISO · COO
✓
Incident contact tree Founder Admin, CCO, CISO, COO, Legal Counsel, Board observer; out-of-band channel verified.
Founder Admin
~
External-use restriction External use restricted to FSRA Risk-Accepted Pilot only; Counterparty Data Room, Controlled External Pilot, and Full External Launch remain blocked at the distribution gate.
CCO · Regulatory Affairs
Post-launch review

D+1, D+7, D+30 owner-driven evidence refresh

Each cadence captures defects, exceptions, residual risks, lessons learned, and sign-off closure. The D+30 review feeds the next Approval & Sign-Off cycle.

D+1 · Day after

Owner: Founder Admin + CISO + COO. Same-day evidence refresh.

  • Auth health, audit-log ingestion, and SIEM forwarding reconciled.
  • Open defects logged on Incident pack with severity and owner.
  • Exception ledger reviewed; rollback triggers reset if cleared.
  • Founder Admin sign-off on the day's release evidence pack.

D+7 · One week

Owner: CCO + Risk Owner. Cadence checkpoint.

  • Pack readiness drift reviewed; any regression escalated to Approval & Sign-Off.
  • Residual risks reconfirmed against the original decision memo.
  • Recipient ledger and bundle limitation text re-attested where applicable.
  • Outsourcing concentration and partner-route SLAs reviewed.

D+30 · Sign-off closure

Owner: Founder/CEO + Board observer. Closure or renewal.

  • Lessons learned recorded on Readiness Change Journal.
  • Limitation re-attestation; conditional / risk-accepted states refreshed or expired.
  • Next Approval & Sign-Off cycle scheduled with updated memo.
  • Stage 9 sign-off closure recorded; release evidence pack archived.
Audit timeline · release-control events

Every state change is timestamped, owner-named, and evidence-linked

Sample audit lines consistent with the current staging posture. Entries are simulated/staging evidence; production audit-event capture still requires SIEM-forwarded audit events under Microsoft Entra OIDC.

Timestamp
Owner
Action · rationale
Evidence ref
2026-05-15 02:00Z
CISO
Stage 1 freeze captured; React bundle and Pack Registry hashes pinned for the window. No non-critical merges.
snapshot/release#hash:1a4c…
2026-05-15 05:55Z
Founder Admin
Stage 2 window opened for Internal Production. Comms tree confirmed; rollback responder on call.
window/internal#hash:7c92…
2026-05-15 06:14Z
Founder/CEO
Stage 3 canary started; SIEM rules armed for auth, MNPI, outsourcing-route anomalies.
pack/auth#hash:9a2c…
2026-05-15 09:01Z
CCO
Stage 4 Founder/Admin Production entered; CCO + Risk + COO sign-offs on file; conditional terms registered.
pack/policy-attestation#hash:7e11…
2026-05-15 11:48Z
Board Liaison
Stage 5 Board Preview enablement as Risk-Accepted Pilot. Watermarked recipient ledger live.
pack/board-pack-attestation#hash:bc40…
2026-05-15 13:22Z
Regulatory Affairs
Stage 6 Regulator Prep enablement for FSRA only as Risk-Accepted Pilot. Bundle scope drift detection armed.
pack/regulatory-exam-response#hash:5d8f…
2026-05-15 14:07Z
CCO
Stage 7 Counterparty Pilot paused; Data-Room MNPI policy-version binding pending. Resume requires CCO + CISO co-sign.
pack/data-room-mnpi-access#hash:e5d0…
2026-05-15 14:08Z
Founder Admin
Stage 8 Full External Launch blocked; entry criteria unmet across Control Evidence, Operational Resilience, Jurisdiction Readiness, Controlled Production Launch.
memo/go-no-go#hash:3b1a…
2026-05-15 14:30Z
Founder Admin
Stage 9 Post-Launch Review scheduled D+1 / D+7 / D+30 with cadence owners assigned.
post-launch/cadence#hash:9f24…

Change Freeze, Release Approval & Rollback Evidence Gate

Internal release-control readiness posture only. Production launch requires an approved release candidate, a declared change freeze, an approved release window, CAB / Board / Compliance / Risk sign-offs, deployment evidence, CI/CD provenance, a rollback plan, a rehearsed rollback drill, database / data-migration rollback evidence, feature flag / kill-switch arming, a dependency freeze, a post-release monitoring window, incident bridge readiness, release communications, and a captured go-live authority. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential appears in this Centre, in the API at /api/release-approval-rollback-evidence, in the fixture, or in any commit. Staging or demo deployment does not count as production release evidence. Not security certification, not regulatory approval, not legal advice, not audit opinion, not external endpoint authorisation, and not external-use authorisation.

Controls assessed
28

Release candidate · freeze · window · CAB/Board/Compliance/Risk sign-off · deployment · CI/CD · rollback · drill · DB rollback · flags · dependency freeze · post-release monitoring · incident bridge · comms · authority

Ready · internal
0

Owner + approver + approval + evidence + (where applicable) rollback drill captured

Approval pending
28

CAB · Board · Compliance · Risk · Founder Office counter-sign not yet captured

Rollback rehearsal untested
5

Rollback / DB rollback / kill-switch drill not in freshness window

Evidence missing
2

Evidence reference (manifest hash · sign-off memo · dependency lock · comms record) not linked

Rollback blocked
8

Rollback plan + drill + DB rollback + flag/kill-switch not all approved & evidenced

Post-release monitoring
1

Post-release monitoring window not declared / approved / evidenced

Production launch
HOLD · NO-GO

Until release candidate + freeze + window + sign-offs + deployment + CI/CD + rollback + drill + DB rollback + flags + dependency freeze + post-release monitoring + incident bridge + comms + go-live authority captured

Read-only fixture exposed via /api/release-approval-rollback-evidence; reference NAMES, owner, approver / approval forum names, approval state, evidence references, release / deployment window descriptors, rollback criterion text, rollback drill dates, linked monitoring / control dependency endpoint paths, and unlock criteria only. Cross-references /api/production-config-readiness, /api/production-ingress-route-readiness, /api/secret-rotation-key-custody, /api/backup-restore-recovery-evidence, /api/observability-slo-incident-evidence, /api/entra-oidc-readiness, /api/evidence-pack-gate-validation, and /api/jurisdictional-permissions-matrix. Mirrored summaries in the Final Production Launch Control Tower, the Production Go/No-Go Board, the Approval & Sign-Off Workflow, the Production Monitoring & Incident Command Centre, the Programme Governance & Roadmap Centre, and the Completeness Command Centre. No deploy token, CI/CD secret, signing key, registry credential, production deploy log line, rollback credential, kill-switch admin key, feature-flag admin token, post-release log line, customer data, incident bridge URL, regulator/board release notification channel, or live release credential is returned from any endpoint. Internal release-control readiness posture only · not security certification · not regulatory approval · not external endpoint authorisation · not external-use authorisation. Staging or demo deployment does not count as production release evidence.

Authoritative reference table · release / rollback evidence
/api/release-approval-rollback-evidence
Loading authoritative release / rollback row table from /api/release-approval-rollback-evidence…

Assumptions and limitations

This Release Control & Rollback Centre is internal release-operations evidence. It is explicitly not:

All regulated activity on the platform remains simulated, partner-routed, locked, or production-regulated as defined in the OS Architecture and Completeness Command Centre. Production cutover still requires Microsoft Entra OIDC with Conditional Access, RBAC/ABAC, server-side session issuance, and SIEM-forwarded audit events. Items shown on this Centre are plausible sample states consistent with the existing Launch Readiness Command Centre, Production Go/No-Go Board, and Approval & Sign-Off Workflow; live values will be sourced from the Pack Registry once the cutover is signed off.