Purpose
This restricted operational page governs the controlled promotion of an approved staging release into production and the first-day verification period. It does not authorize production by itself; the Production Readiness Gate must already show an authorized GO decision.
Pre-Deployment Hold Point
- Confirm signed production GO record and approved release/change ID.
- Freeze application changes except approved launch fixes.
- Capture current public-site and database backup/restore points.
- Verify production secrets exist only in provider secret stores.
- Verify production DNS targets, TLS, database, Auth and private Storage configuration.
- Confirm incident, rollback and decision authority contacts are available.
Controlled Deployment Sequence
- Apply approved production database migrations.
- Verify RLS, role taxonomy and private-storage policies.
- Deploy the production API and verify
/health, then/ready. - Deploy the approved frontend release.
- Activate/verify production DNS and HTTPS.
- Run anonymous/public-page smoke tests.
- Run authenticated role tests using authorized non-sensitive launch test accounts.
- Verify audit logging, protected documents and notification delivery.
- Record launch evidence and decision status.
First-Day Operations
For the first operating day, monitor authentication failures, API readiness, database connectivity, application submissions, role denials, document access, email/notification delivery, audit-event creation and error rates. Any material security, data-integrity or authorization defect triggers the rollback decision process.
Real-Record Enablement
Real applicant or student records remain disabled until production verification is complete. Enable real-record workflows only after the authorized launch owner records that the deployment matches the approved release and required controls are functioning.
Rollback Triggers
- Unauthorized cross-role access.
- Authentication bypass or broken identity linkage.
- Database migration/data-integrity failure.
- Protected document exposure.
- Persistent API readiness failure.
- Loss of required audit logging.
- Any condition the launch authority determines makes continued operation unsafe.
Launch Record
Release/Change ID: __________________________
Production deployment started: _______________
Production verification completed: ____________
Launch owner: _______________________________
Status: ☐ VERIFIED ☐ HOLD ☐ ROLLED BACK
Real-record enablement approved: ☐ YES ☐ NO
Notes/conditions: ____________________________