Skip to content

Clinic-readiness release train and authoritative NO-GO decision #302

Description

@evangauer

Executive decision — 2026-08-30

NO-GO for clinic use, staging migration, merge to a canonical branch, or production deployment.

OpenVPM has meaningful product depth, observable non-demo use, and a fully green exact-SHA hardening stack. It is not yet a clinic-ready PIMS because independent governance, isolated staging, tested restoration, managed-data disposition, and a supervised human clinic pilot are still open. Green CI is necessary evidence; it is not authorization to release.

This issue is the authoritative release-train decision record. Component issues remain the source of implementation detail. Nothing below authorizes fabrication, destructive cleanup, production writes, spend, merge, migration, or deployment.

What is proven

Ordered release train

Gate 0 — preserve containment

Exit: every later gate is explicitly owned and containment has not been bypassed.

Gate 1 — independent governance and migration-line approval

Exit evidence: live GitHub policy packet is green; two independent approvals exist; all required exact-head checks are green; migration reviewer records forward/repair boundaries.

Gate 2 — isolated synthetic staging

  • Complete Create isolated staging and provision fail-closed hosted operations #278 with an approved cost owner before spending: separate Supabase project, synthetic-only tenants, Stripe test mode, non-delivering email, independent storage/keys, least-privilege roles, fail-closed health, exact-SHA deployment, reset and retention procedure.
  • Apply the canonical stack from zero only in the new isolated environment.
  • Prove environment-secret separation and block real contact destinations.

Exit evidence: isolated environment inventory, synthetic-data attestation, exact SHA, migration/RLS/schema-conformance results, /api/health 200, and reset proof.

Gate 3 — restore and recovery drill

Exit evidence: PHI-free drill record with RPO/RTO, operator, sources, checksums, test results, failures, and next due date.

Gate 4 — attributed data disposition

Exit evidence: all configured-data audits return release-safe, or each accepted exception has a named clinical owner, rationale, expiry, and compensating control.

Gate 5 — supervised clinic pilot

  • Complete the first-clinic path in Add exact prospective first-clinic-win preflight and cohort hardening #260 and associated lifecycle delivery in Make optional lifecycle marketing delivery durable and provider-I/O-safe #259.
  • Name a veterinary clinical owner, practice manager, release owner, security owner, and incident commander.
  • In isolated staging, run one complete supervised day: onboarding/MFA, client and patient registration, appointment, chart/medical note, prescription, controlled drug, lab result, vaccination/certificate, estimate/invoice, payment/refund, close, export, backup, and restore.
  • Record defects, workarounds, timings, training gaps, support escalation, and explicit clinical acceptance.
  • Exercise incident response, secret rotation, rollback, and downtime procedure before production access.

Exit evidence: signed pilot acceptance, zero unresolved safety-critical defects, completed runbooks/on-call coverage, and a reviewed rollback decision.

Promotion checklist — all must be true

  • Gates 0–5 have named owners and complete evidence.
  • Two independent reviewers approve the exact release SHA.
  • Exact-SHA build, tests, migrations, RLS, schema conformance, CodeQL, dependency audit, secret scan, golden clinic workflow, and restore drill are green.
  • Hosted health is green with no release-blocking check downgraded to advisory.
  • Backup freshness and managed-object replica coverage meet policy.
  • No unresolved P0/P1 clinical safety, tenant isolation, authentication, medication, billing, backup, or recovery defect exists.
  • Production change window, communications, rollback trigger, and incident staffing are approved.
  • Final GO decision is recorded here by the release owner and independent clinical/security approvers.

Until every checkbox above is satisfied with current evidence, the decision remains NO-GO.

Ownership required now

Project owner: assign named humans and target dates for Gate 1 governance, Gate 2 cost approval, Gate 4 clinical data disposition, and Gate 5 clinic pilot. Engineering can continue producing evidence, but it cannot self-approve these controls or invent clinical decisions.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions