Phase 7 — Production Readiness & Controlled Rollout (Rev.3)
Phase 7 has been fully defined as a production gate: six non-compensatory readiness families, the pilot-to-production delta method, GC-01…GC-05 production reconfirmation, and registers A–AA with their acceptance criteria, evidence requirements and accountable authorities. It has NOT been executed. The governing entry condition — formal Phase 6 acceptance — is unmet, because Phase 6A is on HOLD and Phase 6B has not commenced. Every readiness family is therefore carried at ENTRY_CONDITION_NOT_MET. No certification, operational acceptance, compliance acceptance, cyber clearance or value baseline is claimed, and none may be inferred from the completeness of this definition.
Entry · Governing entry condition
Phase 7 begins only after Phase 6 receives formal acceptance. — NOT SATISFIED.
- Phase 6A Pre-Execution Readiness Closure disposition: HOLD — CONTROLLED PILOT EXECUTION NOT AUTHORIZED (1/10 GO criteria met, 10 blocking preconditions).
- Phase 6B Controlled Pilot Execution: NOT COMMENCED.
- No accepted Phase 6 execution evidence exists.
- No Pilot residual-risk action register exists (it can only be produced by execution).
- The Pilot Architecture Drift Register is active but empty — no Pilot implementation exists to compare against the baselines.
Enterprise Capability Baseline: AVAILABLE — consumed unchanged.
Phase 4 Option C Decision Baseline: AVAILABLE — consumed unchanged (Option C selected; Option B controlled fallback only).
Phase 5 Technical Architecture Baseline: AVAILABLE — ACCEPT WITH CONTROLLED CONDITIONS; GC-01…GC-05 binding.
Phase 6 Pilot Definition Baseline: AVAILABLE — FROZEN, unchanged, zero logged change requests.
Accepted Phase 6 execution evidence: ABSENT — Phase 6B not executed.
Pilot residual-risk actions: ABSENT — no Pilot executed.
Pilot Architecture Drift Register: EMPTY — no implementation to compare.
Pilot success is never automatic Production authorization — and the absence of a Pilot can never be treated as the absence of risk.
A · Executive summary — prohibited claims
- Claiming any production certification, acceptance or UAT result
- Extrapolating Pilot value to enterprise scale (no Pilot value exists)
- Beginning cutover, initial data load or any rollout stage
- Treating this definition's completeness as evidence of readiness
- Compensating a failed readiness family with strength in another
Close Phase 6A (GC-01…GC-05 + field, measurement and Critical Control preconditions) → obtain GO → execute Phase 6B → obtain formal Phase 6 acceptance → re-enter Phase 7 with real evidence.
Disposition · Framework disposition — ACCEPT as Definition Baseline
Baseline nature
- The A–AA registers are the baseline structure for future production-readiness assessment.
- This acceptance does not represent production readiness.
- Treat the current deliverable as PRODUCTION READINESS DEFINITION BASELINE, not PRODUCTION READINESS EVIDENCE.
NO_GO basis
- Phase 6 has no formal acceptance; Phase 6B Controlled Pilot Execution has not been executed.
- No production evidence exists; the Pilot-to-Production delta cannot be validated.
- No production-scale GC-01…GC-05 reconfirmation can be demonstrated.
- No production integration, IAM, cyber, resilience, support or stewardship certification may be inferred.
- No Option C production sustainability conclusion may be drawn.
The A–AA Phase 7 readiness structure is frozen. After Phase 6 execution, production acceptance criteria must not be silently rewritten merely to accommodate Pilot findings.
Permitted change classes: CLARIFICATION · EVIDENCE_CORRECTION · SCOPE_CHANGE · ARCHITECTURE_IMPACT
Transition rule: Phase 7 transitions from DEFINITION BASELINE to EXECUTABLE PRODUCTION READINESS GATE only after Phase 6A GO → Phase 6B execution → Phase 6 formal acceptance.
Program sequence
- Phase 6A — Close Pilot Preconditions → GO/HOLD
- Phase 6B — Execute Controlled Pilot
- Phase 6 — Acceptance
- Phase 7 — Execute Production Readiness → GO / GO_WITH_CONTROLLED_CONDITIONS / HOLD / NO_GO
Next authorized step: PHASE 6A — PRE-EXECUTION READINESS CLOSURE (Pilot status remains HOLD until Pilot-release conditions are closed with evidence).
§1 · Non-compensatory readiness families
Requires: Construction, ES&H, Project Controls, Functional Owners, Commissioning and Operations demonstrate understanding and ownership of READY / CONDITIONAL / HOLD / STOP / CONTINUE / REASSESS and the escalation and decision rights behind them.
AcceptanceAuthority: Operational authority (per discipline)
Blocker: No Pilot operation has occurred against which operational understanding could be demonstrated.
Requires: Legal, regulatory and control acceptance for digital records, identity, signatures, IPERC, PETAR, permits, approvals, retention, audit trail, offline capture and evidence custody.
AcceptanceAuthority: Legal / compliance + ES&H authority
Blocker: CA-04 classification and retention remain unresolved (GC-05 open); no regulatory conclusion may be inferred from technical capability.
Requires: Certified interfaces, IAM, rules, resilience, offline behaviour, observability and performance at production scale.
AcceptanceAuthority: Enterprise Architecture + IT/IM
Blocker: 0 of 6 sources hold a validated participation mode; no production interface can be certified.
Requires: Staffed stewardship of the nine federation keys with tested MATCHED / PARTIAL / CONFLICT / UNRESOLVED / PROPOSED_MAPPING handling and validated multi-project isolation.
AcceptanceAuthority: Federation Mapping Steward + Enterprise Architecture
Blocker: Mapping stewardship unstaffed; no Pilot-measured mapping exception volume exists to size capacity.
Requires: Funded, executed P3-TRN-01 change plan; workforce, supervision, ES&H, Project Controls, functional owners and governance roles ready; Pilot workaround findings addressed by root cause.
AcceptanceAuthority: Project / site leadership
Blocker: No Pilot workaround findings exist to address; P3-TRN-01 unfunded.
Requires: Demonstrably functioning L1/L2/L3 support and staffed stewardship sustainable without design-team dependency.
AcceptanceAuthority: Operational Support owner + Product Ownership
Blocker: 7 of 7 stewardship roles unstaffed; the design-team-withdrawn test has not been run.
The six readiness families are non-compensatory. Strength in technical readiness never offsets a failure in operational, compliance, federation, organizational or support readiness. No mandatory failure may be compensated by another domain.
B · Pilot-to-Production Delta Register
Pilot: CV-07 corridor crews, supervisors and stewards (defined, never mobilised).
Production: Full project population across areas and shifts.
Justification: No Pilot user population was ever mobilised, so no adoption or load evidence exists to extrapolate.
Pilot: Four Locations in one corridor.
Production: All governed Locations across the asset.
Justification: Location governance and stewardship capacity must be revalidated at expanded scale even if the Pilot had succeeded.
Pilot: Mechanical, electrical, instrumentation.
Production: All disciplines including commissioning and operations interfaces.
Justification: Additional disciplines introduce new applicability and SIMOPS interaction classes.
Pilot: Six sources, none validated.
Production: Full enterprise interface set with monitoring and reconciliation.
Justification: Production certification cannot build on an unvalidated Pilot interface set.
Pilot: Not measured.
Production: Enterprise decision and evidence-write volume.
Justification: No Pilot throughput measurement exists.
Pilot: Critical Control SIMULATED.
Production: Real Life-Critical controls governing real authorization.
Justification: A simulated Critical Control path can never support production integration; real participation must be designed and validated.
Pilot: Applicability, no-compensation, SIMOPS CUM-1…7, inheritance defined.
Production: Governed, versioned, approved production rule set.
Justification: Every production rule needs Rule_ID, owner, authority basis, version, approver, effectivity and rollback.
Pilot: ADR-15 / ADR-17 unresolved for Job Card and Temporary Modification.
Production: Full enterprise lifecycle authority across all operational objects.
Justification: Unresolved authority at Pilot scale becomes an enterprise authority gap at production scale.
Pilot: Support model defined, unstaffed.
Production: L1/L2/L3 across shifts with measured response and resolution.
Justification: No Pilot support demand measurement exists to size the production model.
Pilot: Journey classified NOT_EXECUTABLE_IN_CURRENT_PILOT.
Production: Routine field offline capture at scale.
Justification: Offline behaviour has never been demonstrated on a real mechanism.
Pilot: Not measured.
Production: Decision latency and evaluation cost under concurrent load.
Justification: No Pilot performance evidence exists.
Pilot: Observational, non-authorizing.
Production: Real IPERC / PETAR / permit and retention obligations.
Justification: Production carries statutory record and evidence-custody obligations the Pilot never incurred.
Pilot evidence must not be extrapolated beyond its valid scope without justification. Where no Pilot evidence exists, the delta is NOT_DETERMINABLE — never NO_MATERIAL_CHANGE.
C · GC-01…GC-05 production reconfirmation
Pilot closure: NOT CLOSED for the Pilot.
Production requirement: Every production interface certified with mechanism, read/write boundary, version handling, failure behaviour, reconciliation, monitoring and named support owner.
Pilot closure: NOT CLOSED for the Pilot.
Production requirement: Certified authentication, identity resolution, role provisioning, four scope dimensions, delegation, expiry, segregation of duties, privileged administration and denied-action evidence — exercised across authorized, unauthorized, expired, delegated and vacant authority.
Pilot closure: NOT CLOSED for the Pilot.
Production requirement: Lifecycle authority resolved for all production object classes, not only CV-07 scope.
Pilot closure: NOT CLOSED for the Pilot.
Production requirement: Eight production stewardship roles staffed with capacity sized against measured demand; mandatory vacancy blocks the dependent capability.
Pilot closure: NOT CLOSED for the Pilot.
Production requirement: Approved classification, compensability and retention per evidence class for the production jurisdiction, with distinct Control / Record / Validation / Archive frequencies.
A condition closed for the CV-07 Pilot is not automatically closed for enterprise rollout. Production closure requires reassessment at production scale, with its own evidence.
D–S · Certification gates
Requirement: Competent acceptance from Construction, ES&H, Project Controls, Functional Owners, Commissioning and the Operations/Owner interface, with demonstrated understanding of READY / CONDITIONAL / HOLD / STOP / CONTINUE / REASSESS and confirmed escalation and decision-right ownership.
EvidenceRequired: Signed acceptance per domain plus observed decision exercises.
Authority: Operational authorities
Note: Understanding can only be demonstrated against real operation; none has occurred.
Requirement: Production applicability confirmed for digital records, identity, signatures, IPERC, PETAR, permits, approvals, retention, audit trail, offline capture and evidence custody, with ControlFrequency, RecordFrequency, ValidationFrequency and ArchiveFrequency explicitly distinguished.
EvidenceRequired: Written legal/regulatory determination per instrument.
Authority: Legal / compliance + ES&H
Note: No regulatory conclusion may be inferred solely from technical capability; CA-04 remains unresolved.
Requirement: Certify authentication, identity resolution, role provisioning, project/area/activity/risk scope, delegation, authority expiry, segregation of duties, privileged administration and denied-action evidence; exercise authorized, unauthorized, expired, delegated and vacant authority.
EvidenceRequired: Executed test evidence per case, including denial records.
Authority: Enterprise IAM owner + ES&H
Note: No unresolved identity may issue real authorization; enterprise IAM remains NOT_CONNECTED.
Requirement: Per interface: System, Object, Authority, InterfaceMechanism, ReadBoundary, WriteBoundary, VersionHandling, FailureBehaviour, Reconciliation, Monitoring, SupportOwner.
EvidenceRequired: Certification record per production interface.
Authority: Source system owners + Integration governance
Note: Any interface remaining manual, snapshot-based or partially validated must be visible and explicitly accepted — never presented as integrated.
Requirement: Production stewardship for Project_ID, Location_ID, Equipment_ID, P6_Activity_ID, WBS_ID, IWP_NO, WorkPackage_ID, JobCard_ID, Person_ID; tested MATCHED / PARTIAL / CONFLICT / UNRESOLVED / PROPOSED_MAPPING; validated multi-project isolation.
EvidenceRequired: Steward assignment plus executed match-class test set and isolation test.
Authority: Federation Mapping Steward
Note: SEMANTIC_PROPOSAL remains non-authoritative and must never be consumed by the decision engine.
Requirement: LocationConcurrentWorkSet, PairwiseSIMOPS, CumulativeSIMOPS, LocationCriticalRiskContext and LocationContinuityRecord validated at representative high-complexity Locations.
EvidenceRequired: Executed concurrent-work tests at expanded scale.
Authority: Location Steward + ES&H
Note: PAIRWISE PASS NEVER IMPLIES LOCATION PASS; INHERIT CONTEXT — NEVER INHERIT AUTHORIZATION.
Requirement: Governed applicability, no-compensation, validity, frequency, authority, Q4 mappings, SIMOPS CUM rules, inheritance, alerts and Critical Control mappings; every rule carries Rule_ID, Owner, AuthorityBasis, Version, ApprovedBy, EffectiveFrom, EffectiveTo, Rollback.
EvidenceRequired: Approved rule register with versioned effectivity.
Authority: Rule Governance (ADR-16)
Note: Unapproved configuration must not execute — the engine refuses to evaluate an unapproved rule version.
Requirement: Enterprise security assessment of IAM, device security, mobile/offline data, encryption, service identities, secrets, privileged access, interfaces, audit logs, vulnerability management and incident response.
EvidenceRequired: Completed enterprise security assessment with explicitly recorded unresolved risk.
Authority: Cyber owner
Note: Unresolved cyber risk is recorded explicitly, never absorbed silently.
Requirement: Executed failure tests for Q4, Aconex, P6, IAM, Critical Control source, network, mapping conflict, rule service, evidence store and synchronization; verify CURRENT / STALE / UNVERIFIABLE and DegradedMode, ExitAuthority, Reconciliation, RecoveryVerification.
EvidenceRequired: Executed failure-injection results per dependency.
Authority: Platform owner + Integration owner
Note: Service restoration alone does not equal recovery.
Requirement: MinimumSafeInformationSet, OfflineCapture, BaseVersion, QueueIntegrity, Encryption, Reconnect, ConflictDetection, Reconciliation.
EvidenceRequired: Certified offline behaviour on the production mechanism.
Authority: Platform owner + ES&H
Note: OFFLINE DOES NOT AUTHORIZE. Any proposed change to this requires a separate architecture/governance decision.
Requirement: Monitoring for source availability, stale data, interface failure, federation conflicts, rule execution, decision latency, evidence-write failure, unresolved authority, degraded mode, synchronization and SIMOPS evaluation.
EvidenceRequired: Live monitoring with alert ownership and runbooks.
Authority: Platform owner
Note: Monitoring must distinguish TECHNOLOGY_FAILURE from OPERATIONAL_READINESS_FAILURE — a healthy platform reporting HOLD is not an incident.
Requirement: Functioning L1/L2/L3 exercised for user error, authority question, mapping conflict, rule issue, integration failure, offline conflict and evidence reconstruction, each with Owner, Escalation, Response, Resolution, Evidence.
EvidenceRequired: Executed support scenario results with measured response and resolution.
Authority: Operational Support owner
Note: The system is not production-ready if only the design team can support it.
Requirement: Staffed, sustainable LocationSteward, MappingSteward, RuleOwner, ProductOwner, IntegrationOwner, PlatformOwner, CyberOwner and EnterpriseArchitectureOwner, with capacity validated against Pilot-measured stewardship demand.
EvidenceRequired: Named assignments plus a demand-versus-capacity analysis.
Authority: Project / site leadership
Note: No Pilot-measured demand exists; mandatory vacancy blocks the dependent production capability (DISABLED_SAFE).
Requirement: Funded, executable change plan with demonstrated readiness of field workforce, supervisors, superintendents, ES&H, Project Controls, functional owners, support teams and governance roles; Pilot workaround findings addressed by root cause.
EvidenceRequired: Funded plan plus per-audience readiness evidence.
Authority: Change / Adoption owner
Note: Structural usability or authority problems must not be solved with training alone.
Requirement: Execute normal READY, HOLD, STOP, denied authority, source unavailable, Forecast Readiness, SIMOPS, Location Continuity, change/reassessment and evidence reconstruction, recording Expected, Actual, Role, Authority, Evidence, Disposition.
EvidenceRequired: Completed UAT register signed by role owners.
Authority: Product Ownership + operational authorities
Note: UAT cannot precede a validated interface and identity foundation.
Requirement: Validated initial Location, Job Card, Equipment and Person identity mappings, rules and configurations, each with Source, Version, Validation, Evidence, Exception, Reconciliation.
EvidenceRequired: Validated load register with exception disposition.
Authority: Federation Mapping Steward + Rule Governance
Note: Bulk loading does not equal governance.
T · Cutover / Rollback plan
PreCutoverChecks: All Phase 7 registers certified; no mandatory family in a failed state; residual risk explicitly owned.
FreezeBoundary: Declared boundary in source systems after which state changes are captured for initial sync; boundary is announced and evidenced.
InitialSync: Governed load of validated mappings and pinned source versions; exceptions dispositioned, never auto-resolved.
IdentityValidation: Every production actor resolves to a single accountable enterprise identity before any authorization is offered.
AuthorityValidation: Authorized, unauthorized, expired, delegated and vacant authority re-exercised in the production tenant.
MappingValidation: Federation key match classes re-tested post-load; UNRESOLVED entries fail closed for dependent decisions.
RuleValidation: Only approved rule versions are executable; unapproved configuration is refused.
OperationalVerification: Live confirmation that decisions issued match operational reality at representative Locations before authority is transferred.
GoLiveAuthority: Named authority issues go-live; no cutover window may create ambiguous operational authorization — the prior control regime remains authoritative until go-live is issued.
Rollback triggers
Authority failure: Any authorization issued without resolved identity or valid authority.
Integration failure: Sustained loss of a mandatory-decision source without a safe degraded mode.
Evidence failure: Evidence-write failure or inability to reconstruct a decision basis.
Cyber event: Confirmed compromise of identity, device, offline data or interface.
Unacceptable operational impact: The capability materially disrupts mandatory production or control processes.
Systemic federation conflict: Mapping conflict volume exceeds stewardship capacity, producing unresolved decision context.
- Authoritative systems remain authoritative throughout — rollback never rewrites source state.
- Decision history is preserved in full, including decisions made during the reverted window.
- Evidence is retained and remains reconstructable after reversion.
- Operational control is never ambiguous: reversion names the authoritative control regime and its effective moment.
U · Production value measurement baseline
Carried forward from Pilot: NONE — no evidence-supported Pilot metric exists, because Phase 6B was not executed.
These three are measured independently and never conflated; time released is not time saved, and neither is productive time captured.
Post-go-live measures
Pilot savings must never be extrapolated linearly to enterprise scale without evidence. With zero Pilot measurement, any production ROI statement at this point would be unsupported.
V · Option C production sustainability
FederationMaintenanceEffort: NOT_MEASURED
InterfaceReliability: NOT_MEASURED — no interface validated
MappingExceptionDemand: NOT_MEASURED
StewardshipDemand: NOT_MEASURED
SupportDemand: NOT_MEASURED
ArchitectureFlexibility: DESIGN-LEVEL ONLY — confirmed in Phase 5 §T
OperationalBenefit: NOT_MEASURED
Option C production sustainability cannot be assessed: the reassessment is defined to consume Pilot evidence, and no Pilot evidence exists. No ENTERPRISE OPTION REOPEN REQUEST is raised, because raising one requires evidence of disproportion, which is equally absent.
If Option C later proves disproportionate at production scale, raise an ENTERPRISE OPTION REOPEN REQUEST. Never silently simplify into Option B — the Phase 4 fallback requires an explicit architecture decision.
W · Architecture Drift Register
Architecture decisions — never normal features
- Making Q4 the universal System of Record
- Changing Location authority
- Enabling offline authorization
- Introducing weighted compensation
- Changing non-inheritable work controls
- Bypassing federation governance
- Changing authority or write boundaries
ACTIVE — zero entries. No production implementation exists to compare against the baselines. An empty drift register is not evidence of architectural conformance.
X · Residual Risk Register
Control: Every register carries ENTRY_CONDITION_NOT_MET; the disposition is NO_GO.
Control: Phase 5 acceptance is design sufficiency only and explicitly does not authorize deployment.
Control: Any move from C to B requires an explicit enterprise architecture decision; drift classification applies.
Control: Register G requires such interfaces to be visible and explicitly accepted by name.
Control: Value baseline carries forward nothing; post-go-live measures must be instrumented before go-live.
Control: Register Q requires root-cause disposition of workaround findings by class.
Control: GoLiveAuthority names the authoritative control regime and its effective moment; the prior regime holds until then.
Y · Controlled rollout plan
Scope: CV-07 corridor, four Locations, three disciplines.
Gate: Phase 6A GO + Phase 6B acceptance.
Scope: Adjacent Locations within the same Area.
Gate: Pilot acceptance + delta revalidation for the added scope.
Scope: Additional Areas with independent stewardship.
Gate: Stewardship capacity evidenced against measured demand.
Scope: All disciplines including commissioning interfaces.
Gate: Applicability and SIMOPS rule set recertified for new interaction classes.
Scope: Additional projects on the federated platform.
Gate: Multi-project isolation validated; per-project authority and stewardship staffed.
Every expansion requires its own Scope, Readiness, Evidence, ResidualRisk and AcceptanceAuthority. There is no uncontrolled enterprise-wide rollout.
Z · Production Acceptance Register
AA · Final recommendation
NO_GO is recorded rather than HOLD because the governing entry condition for Phase 7 is not met at all: Phase 6 has no formal acceptance, Phase 6B has not been executed, and none of the nine required production acceptances has been sought or obtained. HOLD would imply Phase 7 is in progress awaiting a final item; it is not — it is defined and not entered. All six readiness families are ENTRY_CONDITION_NOT_MET, and the families are non-compensatory, so no combination of design maturity can produce a GO.
A complete, executable Phase 7 gate definition: readiness families with acceptance authorities, the pilot-to-production delta method, GC-01…GC-05 production reconfirmation criteria, sixteen certification gates with evidence requirements, cutover and rollback design, the value measurement baseline, Option C sustainability method, drift control, the staged rollout plan, the residual-risk register and the production acceptance register.
Path to GO
- Close Phase 6A: evidence GC-01…GC-05, field prerequisites, prospective BEFORE measurement and a Path A/B Critical Control decision.
- Obtain a formal GO — CONTROLLED PILOT EXECUTION AUTHORIZED.
- Execute Phase 6B against the frozen twenty journeys without removing difficult ones.
- Obtain formal Phase 6 acceptance with its residual-risk actions and drift register.
- Re-enter Phase 7 and execute registers B–Z with real evidence.
Production readiness is not demonstrated by deployment completion. It is demonstrated when the organization can operate, govern, support, recover, audit, measure and change the capability without weakening the accepted operational-control architecture.