Fictional representative sample · no client data

A launch decision you can read in one sitting.

This fictional report shows the shape of a 48-hour review: one critical journey, evidence across seven gates, a clear decision, and conditions that make the next move explicit.

Decision

CONDITIONAL GO

Proceed with the limited draft-only beta. Keep external sending disabled until deterministic recipient-policy validation is implemented and re-tested.

The review boundary

One workflow. No production data.

Product

Northstar Support Drafts

A five-customer private beta where staff review AI-drafted support replies before sending.

Critical journey

An operator signs in, opens one synthetic tenant ticket, generates a source-linked draft, reviews it, and saves it without sending an external message.

01

Sign in

Tenant and operator boundary checked before the ticket opens.

02

Draft

Source-linked output generated with trace correlation.

03

Review + save

External send stays disabled until recipient policy is deterministic.

Seven-gate scorecard

What passed, what stayed conditional.

01

Critical journey

Fresh operator completed the named draft journey.

Pass
02

UI states

Loading, error, review, and recovery states matched the stored result.

Pass
03

Auth & permissions

Wrong-object requests were denied and tenant markers stayed isolated.

Pass
04

Actions & data

The send capability was disabled as containment.

Conditional
05

Failure handling

Timeout, retry, partial failure, and recovery paths were observed.

Pass
06

Operations

Limits, alerts, rollback, and ownership were recorded.

Pass
07

Discoverability

The narrow sample checked basic metadata, links, and deployed rendering.

Reviewed

Evidence-ranked finding

The reason this was not a full go.

F-001

High · launch-blocking

The send tool trusted a model-selected recipient without deterministic policy.

Evidence
A valid-shaped recipient different from the approved ticket contact was accepted in the synthetic harness.
Consequence
A mistaken or manipulated model output could send customer content to an unintended address.

Response

Keep sending disabled. Resolve the recipient from trusted ticket state, require exact-action confirmation, and add wrong-tenant regression tests before re-enabling.

Conditions & next actions

The report ends with ownership.

  • Keep the external send tool disabled for every beta tenant.
  • Limit access to the five named beta tenants and two support operators.
  • Alert on attempted invocation of the disabled send tool.
  • Re-review recipient validation before enabling external sending.

Handoff

  1. 01Implement deterministic recipient allowlisting.
  2. 02Monitor disabled-tool attempts during the beta.
  3. 03Keep the known-good build and stop owner recorded.

NOW / NEXT / LATER

The fix-first plan stays usable after the readout.

NOW

  • Keep external sending disabled.
  • Limit the beta to named tenants and operators.

NEXT

  • Implement deterministic recipient allowlisting.
  • Add wrong-tenant regression tests.

LATER

  • Re-review the send boundary before enabling it.
  • Keep the stop owner and rollback build recorded.

Your turn

Get a decision for the workflow you need to ship.

The real report uses evidence from your deployed product, your launch context, and the one journey that matters most.

Get your launch decision

Cookie preferences

We use necessary cookies to keep the site running, and optional analytics to see what content helps. No advertising trackers. · Privacy policy