Testing, QA & Release Evidence Centre
Internal workspace for staging-to-production verification: test strategy, QA matrix, evidence-pack acceptance, defect triage, sign-off workflow, release candidate states, rollback proof, and post-release monitoring. Every release candidate is bound to the 21-pack evidence spine, the policy/control library, and the existing Approval & Sign-Off / Release Control / Production Go/No-Go Centres. Conservative posture: internal readiness only — not legal advice, not regulatory approval, not certification, not audit opinion, not regulator submission, not authorization for external launch.
Internal class-descriptor hash ledger · chain status visible · external release HOLD · NO-GO
Compact mirror of the Evidence Integrity Hash Ledger summary exposed via /api/evidence-integrity-hash-ledger. SHA-256 digests of safe class-descriptor objects (readiness snapshot, change journal, manifest summary, approval queue, production standby control state, evidence-pack gate summary, approval authority, MNPI boundary, jurisdictional permissions, regulator submission gate) and the chain linking them. Class-descriptor index only — never evidence payloads, never MNPI, never signatures, never tokens, never real recipients. Never overrides any blocker. Never proves audit opinion, never proves regulatory approval. Authoritative surface is the Final Production Launch Control Tower.
Twelve suites · category · owner · automation · cadence
| Suite ID | Suite | Category | Automation | Owner | Cadence | Linked policy / control | State |
|---|---|---|---|---|---|---|---|
| TS-001 | Unit tests | Automated | 100% | Engineering | Per commit | POL-006 · CTL-Static | Passed |
| TS-002 | Integration tests | Automated | 95% | SRE Lead | Per merge | POL-006 · CTL-Schema | Passed |
| TS-003 | Contract tests (API) | Automated | 100% | SRE Lead | Per merge + nightly | POL-019 · IADE schema check | In Progress (schema drift) |
| TS-004 | UAT | Manual | 0% | Operations · Evidence Owner | Per release candidate | POL-019 · POL-013 | UAT |
| TS-005 | Regression | Automated | 85% | SRE Lead | Per release + weekly | POL-006 | Passed |
| TS-006 | Security (SAST · DAST · secret scan) | Automated | 100% | CISO · SRE Lead | Per release + nightly | POL-018 · CTL-Secret-Scan | Passed |
| TS-007 | Access-control testing | Mixed | 70% | Tech/Security · Compliance | Per release + quarterly | POL-001 · POL-018 · CTL-001/002/004 | In Progress |
| TS-008 | Performance / load | Automated | 80% | SRE Lead | Per release | POL-006 | Passed |
| TS-009 | DR / failover drill | Manual | 0% | SRE Lead · CISO | Quarterly | POL-012 · CTL-008 RTO/RPO | Scheduled 2026-06-12 |
| TS-010 | Compliance / policy attestation | Mixed | 40% | Compliance · CoS | Per release | POL-018 · CTL-010 Counsel | Counsel Review |
| TS-011 | Schema / data quality | Automated | 100% | Evidence Owner · SRE Lead | Per merge + nightly | POL-006 · IADE schema | Schema drift |
| TS-012 | Evidence pack acceptance | Manual | 0% | Evidence Owner · Programme | Per release | POL-013 · CTL-006 Footer | Passed |
Ten stages · sign-off-gated transitions
Test strategy
Test plan, scope, risk RAID drafted; affected packs identified; coverage matrix populated.
Automated + manual
All 12 suites executed; passing thresholds met; defects triaged.
User acceptance
Evidence Owner + Operations confirm staging acceptance; per-pack attestation captured.
Counsel review
External counsel reviews regulator/client-facing language and release notes; locks phrasing.
Approval & Sign-Off
Programme Manager + CISO dual sign-off; rollback plan attached; Production Go/No-Go board reviewed.
Release candidate
Build artefacts pinned; release notes finalised; per-pack evidence hashes recorded.
Production cutover
Cutover under change-control; rollback rehearsed; per-recipient signing keys rotated where applicable.
Post-release watch
SLO · error rate · DLP · audit-log forwarding watched in Production Monitoring; counsel notified for regulator-facing.
Recovery
RB-RC-ROLLBACK engaged on regression; reason logged; post-mortem opened in Incident.
10-year retention
Release manifest, evidence hashes, sign-off records, post-mortem (if any) frozen for retention.
21 BLACKSWAN evidence packs × applicable test suite(s)
| Evidence pack | Applicable test suite(s) | Critical path? | Owner | Counsel countersign on release notes? |
|---|---|---|---|---|
| Auth | TS-006 Security · TS-007 Access · TS-002 Integration | Yes — Tier-1 | CISO · Identity Lead | For regulator-facing artefact |
| KYC / KYB Onboarding | TS-002 · TS-004 UAT · TS-010 Compliance | Yes | Operations · Compliance | Yes — when contract closes |
| Data-Room MNPI Access | TS-007 Access · TS-006 Security · TS-012 Evidence | Yes — Tier-1 | CISO · Stakeholder Rooms | For external share |
| Settlement Responsibility | TS-002 · TS-005 Regression · TS-010 Compliance | Yes | CFO · Operations | For regulator-facing |
| Activity Perimeter Decision | TS-010 Compliance · TS-004 UAT | Yes | Compliance · External Counsel | Yes — mandatory |
| Control Testing | All 12 suites | Yes — Tier-1 | SRE Lead · Programme | For regulator-facing |
| Partner-Route Assurance | TS-002 · TS-005 · TS-010 | Yes | Vendor Risk · Operations | For material outsourcing |
| Revenue Recognition | TS-002 · TS-004 UAT · TS-012 Evidence · TS-010 Compliance | Yes | Finance · External Auditor (pending) | Yes — for revenue narrative |
| Tax / VAT | TS-002 · TS-010 Compliance | Scope | Finance · Tax Adviser | For external use |
| Regulatory Digital Twin Decision | TS-003 Contract · TS-010 Compliance · TS-011 Schema | Yes | Compliance · Tech/Security | Yes — counsel-locked phrasing |
| Model Risk | TS-010 Compliance · TS-004 UAT | Yes | Compliance · CISO | Yes — for external use |
| Incident | TS-009 DR · TS-006 Security · TS-005 Regression | Yes — Tier-1 | SRE Lead · CISO | For regulator-notify path |
| Board-Pack Attestation | TS-012 Evidence · TS-010 Compliance | Yes | CoS · Programme | For board-pack issue |
| Regulatory Change | TS-010 Compliance · TS-003 Contract | Yes | Compliance · Programme | Yes — counsel-locked |
| Complaints | TS-002 · TS-004 UAT | Scope | Operations · Compliance | For regulator-notify |
| Outsourcing Concentration | TS-010 Compliance · TS-005 Regression | Yes | Vendor Risk · Risk Committee | For material outsourcing |
| Capital / Liquidity Readiness | TS-010 Compliance · TS-012 Evidence | Scope | Finance · External Counsel | For external use |
| Policy Attestation | TS-010 Compliance · TS-007 Access | Yes | Compliance · Tech/Security | For annual attestation |
| Product Governance | TS-004 UAT · TS-010 Compliance | Yes | Operations · Compliance | For regulator-facing |
| Conduct Risk MI | TS-002 · TS-004 UAT · TS-012 Evidence | Scope | Operations · Risk Committee | For MI external use |
| Regulatory Exam Response | TS-012 Evidence · TS-010 Compliance | Yes — Tier-1 | Compliance · External Counsel | Yes — mandatory |
Severity rules · closure criteria · waiver authority
| Defect ID | Title | Severity | Affected pack(s) | Owner | Mitigation / waiver | Target close | State |
|---|---|---|---|---|---|---|---|
| DF-001 | MFA enforcement test pending until Entra cutover | P1 | Auth · Policy Attestation | CISO | Staging factors enforced (compensating control) | 2026-06-08 | Waiver · Conditional |
| DF-002 | WAF custom rule pack in shadow mode only | P2 | Incident · Control Testing | CISO · SRE Lead | OWASP pack live · manual review on critical paths | 2026-05-30 | Waiver |
| DF-003 | External auditor engagement letter pending | P1 | Revenue Recognition · Tax/VAT · Capital/Liquidity | CFO | Hold revenue treatment hints; audit-flag affected events | 2026-06-15 | Waiver · Conditional |
| DF-004 | Counsel rule-pack countersign open | P0 | Activity Perimeter · Digital Twin · Model Risk · Reg Change · Exam Response | Compliance · External Counsel | Restrict affected outputs · limitation footer enforced | 2026-05-19 (counsel session) | Blocked |
| DF-005 | KYC partner contract sign-off pending | P0 | KYC/KYB · Client Lifecycle · Partner-Route | Operations · External Counsel | No client activations until contract closes | 2026-06-05 | Blocked |
| DF-006 | Schema drift on Evidence Pack API (2 unsigned changes) | P2 | Control Testing · Board-Pack Attestation | Evidence Owner · SRE Lead | Re-attest schemas · re-test against curated pack set | 2026-05-26 | In Progress |
| DF-007 | Quarterly break-glass drill overdue | P2 | Auth · Incident · Policy Attestation | Tech/Security · COO | Sealed account + dual approver + auto-rotate | 2026-05-26 | Waiver |
Per-release artefacts · owner · audience · counsel countersign
| Artefact | Owner | Audience | Counsel countersign | Retention | Linked centre(s) |
|---|---|---|---|---|---|
| Test plan | SRE Lead · Programme | Internal | n/a | 10 y | Approval & Sign-Off |
| Test coverage report | SRE Lead | Internal · Auditor (engagement) | For external use | 10 y | Control Testing pack · Programme Governance |
| UAT attestation | Evidence Owner · Operations | Internal · Board (where applicable) | For board pack | 10 y | Approval & Sign-Off · Strategic Reporting |
| Security test report | CISO | Internal · Regulator-review (counsel-bounded) | Yes — for external use | 10 y | Security Operations · Regulatory Exam Response |
| Access-control test report | Tech/Security · Compliance | Internal · Auditor | For external use | 10 y | User Role/Permission · Security Operations |
| Release notes | SRE Lead · Programme | Internal · Client (per-pilot) · Board | Yes — for any external audience | 10 y | Release Control · Client Lifecycle · Strategic Reporting |
| Rollback rehearsal proof | SRE Lead · CISO | Internal · Regulator-review (OpRes) | For OpRes filing | 10 y | Release Control · Enterprise Architecture · Production Monitoring |
| DR drill report | SRE Lead · CISO | Internal · Regulator-review (OpRes) | For OpRes filing | 10 y | Release Control · Production Monitoring |
| Sign-off record (dual) | Programme · CISO | Internal · Board | For board pack | 10 y | Approval & Sign-Off · Production Go/No-Go |
| Post-release monitoring summary | SRE Lead | Internal · Board (after 2 cycles) | For board pack | 10 y | Production Monitoring · Strategic Reporting |
Ten role experiences of the QA/release surface
Full QA board
Reads the full test/release ledger; co-signs Tier-1 release with CISO; standing risk acceptance for founder-root applies (DEC-005).
Coverage owner view
Owns QA coverage matrix per release; tracks acceptance criteria per pack; co-signs UAT acceptance with Evidence Owner.
Engineering owner view
Owns automated suites (unit · integration · contract · regression · security · perf · schema). JIT elevation for break-glass; dual sign-off on release.
Counsel-bound view
Owns counsel-bound suites (Compliance · Evidence acceptance · regulator-facing release notes). External counsel countersign on every external artefact.
UAT operator view
Drives UAT, DR drill execution, complaint capture, client-impact narrative; approve on release activation.
Evidence-bound view
Captures per-pack evidence hashes per release; per-file limitation footer enforced; signs UAT attestation.
Board-only view
Reads board-pack release section after 2 stable cycles; never sees raw test logs; receives sign-off attestation + post-release monitoring summary.
Counsel-locked view
Read-only on counsel-locked, redacted release evidence (security · access · DR · OpRes); per-engagement TTL; counsel-locked language only.
Engagement-scope view
Engagement-scope read on test coverage report, sign-off record, audit-track evidence; engagement letter required before any production access.
Per-pilot release notes
Per-pilot tenant view of release notes only · counsel-approved · counterparty names redacted; never sees other tenants.
Workflow · accountable · approver · SOD pair · linked control
| Workflow | Accountable | Approver | SOD pair | Linked policy / control |
|---|---|---|---|---|
| Test acceptance (suite owner sign-off) | Suite owner | Programme | Author ≠ Approver | POL-006 · CTL-004 |
| UAT acceptance | Operations · Evidence Owner | Programme Manager | Operator ≠ Approver | POL-013 · POL-018 |
| Security report sign-off | CISO | CISO + Programme (dual) | Tester ≠ Approver | POL-018 · CTL-001/002/004 |
| Counsel review · regulator/client-facing release notes | Compliance | External Counsel + CEO | Drafter ≠ Counsel | POL-005 · POL-014 · CTL-010 |
| Release sign-off (Tier-1) | Programme Manager | Programme + CISO (dual) | Build ≠ Sign-off · SRE ≠ CISO | POL-006 · CTL-004 · Release Control runbook |
| Production Go/No-Go board | Programme Manager | Programme + CISO + Board observer (where regulator-facing) | Build ≠ Board | Production Go/No-Go Centre · Approval & Sign-Off |
| Rollback authority | SRE Lead | SRE + CISO (dual) on Tier-1 | Single-party ≠ Rollback on Tier-1 | Release Control · POL-012 Incident |
| Board pack · release section | CoS | CEO + Board Chair | Drafter ≠ Approver | POL-013 Board-Pack Attestation · Strategic Reporting workflow |
Open exceptions · owner · remediation
| Alert ID | Item | Issue | Severity | Owner | Remediation | State |
|---|---|---|---|---|---|---|
| AL-TQRE-001 | Counsel rule-pack release notes | Counsel countersign pending (2026-05-19) | P0 | Compliance · External Counsel | Lock phrasing after counsel session | Counsel Pending |
| AL-TQRE-002 | KYC partner contract | No client activations until contract closes | P0 | Operations · External Counsel | Close KYC contract | Blocked |
| AL-TQRE-003 | External auditor engagement letter | Revenue treatment hints held | P1 | CFO · External Auditor | Sign engagement letter | Auditor Pending |
| AL-TQRE-004 | Evidence Pack API schema drift | 2 unsigned schema changes flagged | P2 | Evidence Owner · SRE Lead | Re-attest schemas; re-test | In Progress |
| AL-TQRE-005 | DR drill 2026-06-12 | Pre-drill posture; evidence pending | P1 | SRE Lead · CISO | Run drill · capture RTO/RPO evidence | Scheduled |
| AL-TQRE-006 | Quarterly break-glass drill | Drill overdue (target 2026-05-12) | P2 | Tech/Security · COO | Schedule drill · capture evidence · revoke | Stale |
| AL-TQRE-007 | Complaints capture flow | Capture flow being defined pre first pilot | P3 | Operations · Compliance | Define + test pre first pilot | Planned |
Four gates · all green before any release artefact leaves internal scope
Counsel-locked release language
External counsel countersigns every regulator-/client-facing release-note paragraph (CTL-010). Per-artefact, per-audience.
P0 closed · P1 waived
Zero P0 open · every P1 has compensating control + Programme + CISO dual sign-off · documented waiver.
Evidence hashed & cross-linked
Per-pack evidence hashes captured · cross-Centre links updated · audit-event tag applied · per-pack DEK in place for restricted.
Rollback rehearsal proven
RB-RC-ROLLBACK ran within Tier-1 RTO 30m on latest rehearsal · evidence captured · per-recipient signing keys rotate on cut.
Audit log of testing / release events
| Timestamp (UTC) | Actor | Event family | Action | Evidence hash | Limitation recorded | Next step |
|---|---|---|---|---|---|---|
| 2026-05-08 09:00 | SRE Lead · Programme | Test taxonomy | TQRE-TAX — 12 suites catalogued | sha256:tqre…aa01 | "Internal readiness only." | Quarterly review |
| 2026-05-09 11:14 | Programme · SRE Lead | Release state model | TQRE-RS — 10 stages published | sha256:tqre…aa02 | "Internal." | Apply on next release |
| 2026-05-10 09:22 | SRE Lead · Evidence Owner · Compliance | QA coverage matrix | TQRE-QM — 21 packs × suites mapped | sha256:tqre…aa03 | "Internal." | Refresh on pack/suite change |
| 2026-05-11 14:08 | Programme · CISO · Compliance | Defect board | TQRE-DF — 7 open defects logged | sha256:tqre…aa04 | "Internal." | Close DF-004 + DF-005 P0s |
| 2026-05-12 09:50 | Programme · SRE · Compliance | Release artefact register | TQRE-AR — 10 artefacts catalogued | sha256:tqre…aa05 | "Internal." | Refresh per release |
| 2026-05-13 11:42 | CoS · CISO · Compliance | Stakeholder views | TQRE-SV — 10 views scoped | sha256:tqre…aa06 | "Counsel-bounded for external." | Lock per-share counsel sign-off |
| 2026-05-14 08:18 | Programme · CISO · External Counsel | Sign-off workflow | TQRE-SO — 8 workflows scoped | sha256:tqre…aa07 | "Internal." | Re-test on workflow change |
| 2026-05-15 09:00 | Programme · SRE Lead | Stale / missing sweep | TQRE-AL — 7 alerts opened | sha256:tqre…aa08 | "Internal." | Close break-glass drill · counsel session |
| 2026-05-15 11:30 | External Counsel · CEO · Programme | External release gates | TQRE-VG — 2 of 4 gates met | sha256:tqre…aa09 | "No external release artefact without all 4 gates." | Close Gate 1 + Gate 2 |
| 2026-05-16 07:55 | CEO · CISO · Compliance | Centre attestation | TQRE-ATTESTATION — monthly attestation | sha256:tqre…aa10 | "Internal; not regulatory approval." | Re-attest monthly |
What this Centre is — and is not
- Staging / simulated test & release data. All suite IDs, defect IDs, evidence hashes, dates, sign-off records, and audit events shown here are seed values for an internal readiness workflow. They are not a live test management system, not a live release pipeline, and not a live audit log.
- Internal readiness workflow only. This Centre captures BLACKSWAN's internal testing & release-evidence posture. It is not legal advice, not regulatory approval, not certification, not an audit opinion, not regulator submission, not client acceptance, and not authorization for external launch.
- P0 blocks release; P1 requires compensating control. No waiver of a P0. P1 waivers require dual sign-off and a written compensating control; counsel countersign is required where regulator-facing.
- Counsel-bound for external surfaces. Every regulator- or client-facing release artefact requires external counsel countersign (CTL-010) before per-recipient signing keys are issued.
- Founder-root is a standing accepted risk. Per Programme Decision Log DEC-005, founder-root permanence carries MFA + re-auth + monthly attestation as compensating controls.