You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
NO-GO for clinic use, staging migration, merge to a canonical branch, or production deployment.
OpenVPM has meaningful product depth, observable non-demo use, and a fully green exact-SHA hardening stack. It is not yet a clinic-ready PIMS because independent governance, isolated staging, tested restoration, managed-data disposition, and a supervised human clinic pilot are still open. Green CI is necessary evidence; it is not authorization to release.
This issue is the authoritative release-train decision record. Component issues remain the source of implementation detail. Nothing below authorizes fabrication, destructive cleanup, production writes, spend, merge, migration, or deployment.
What is proven
Read-only aggregate evidence shows 56 practices, 12 practices with non-demo appointments, 10 recent non-demo creators, 430 clients, 1,001 patients, 38 appointments, and 109 invoices. This is behavioral evidence of real use, not identity proof that every account belongs to a human or that any clinic has accepted production readiness.
The eight-PR migration and clinical-integrity stack is draft, exact-head green, and mechanically clean:
The exact final head passes hosted CI, disposable PostgreSQL migrations and RLS contracts, patient merge, production build, dependency audit, artifact secret scan, and OSS release verification.
The configured data-bearing environment was audited read-only. No production/configured rows were mutated, no migration was applied, and no hosted resource was provisioned.
Exit evidence: live GitHub policy packet is green; two independent approvals exist; all required exact-head checks are green; migration reviewer records forward/repair boundaries.
Gate 2 — isolated synthetic staging
Complete Create isolated staging and provision fail-closed hosted operations #278 with an approved cost owner before spending: separate Supabase project, synthetic-only tenants, Stripe test mode, non-delivering email, independent storage/keys, least-privilege roles, fail-closed health, exact-SHA deployment, reset and retention procedure.
Apply the canonical stack from zero only in the new isolated environment.
Prove environment-secret separation and block real contact destinations.
Exit evidence: all configured-data audits return release-safe, or each accepted exception has a named clinical owner, rationale, expiry, and compensating control.
Name a veterinary clinical owner, practice manager, release owner, security owner, and incident commander.
In isolated staging, run one complete supervised day: onboarding/MFA, client and patient registration, appointment, chart/medical note, prescription, controlled drug, lab result, vaccination/certificate, estimate/invoice, payment/refund, close, export, backup, and restore.
Record defects, workarounds, timings, training gaps, support escalation, and explicit clinical acceptance.
Exercise incident response, secret rotation, rollback, and downtime procedure before production access.
Exit evidence: signed pilot acceptance, zero unresolved safety-critical defects, completed runbooks/on-call coverage, and a reviewed rollback decision.
Promotion checklist — all must be true
Gates 0–5 have named owners and complete evidence.
Two independent reviewers approve the exact release SHA.
Exact-SHA build, tests, migrations, RLS, schema conformance, CodeQL, dependency audit, secret scan, golden clinic workflow, and restore drill are green.
Hosted health is green with no release-blocking check downgraded to advisory.
Backup freshness and managed-object replica coverage meet policy.
No unresolved P0/P1 clinical safety, tenant isolation, authentication, medication, billing, backup, or recovery defect exists.
Production change window, communications, rollback trigger, and incident staffing are approved.
Final GO decision is recorded here by the release owner and independent clinical/security approvers.
Until every checkbox above is satisfied with current evidence, the decision remains NO-GO.
Ownership required now
Project owner: assign named humans and target dates for Gate 1 governance, Gate 2 cost approval, Gate 4 clinical data disposition, and Gate 5 clinic pilot. Engineering can continue producing evidence, but it cannot self-approve these controls or invent clinical decisions.
Executive decision — 2026-08-30
NO-GO for clinic use, staging migration, merge to a canonical branch, or production deployment.
OpenVPM has meaningful product depth, observable non-demo use, and a fully green exact-SHA hardening stack. It is not yet a clinic-ready PIMS because independent governance, isolated staging, tested restoration, managed-data disposition, and a supervised human clinic pilot are still open. Green CI is necessary evidence; it is not authorization to release.
This issue is the authoritative release-train decision record. Component issues remain the source of implementation detail. Nothing below authorizes fabrication, destructive cleanup, production writes, spend, merge, migration, or deployment.
What is proven
40323771)20259346)315f6db0)1c82344c)c43d3b72)1d53f8ba)39c4442f)956e733b)Ordered release train
Gate 0 — preserve containment
openvpm-stagingproject as disposable staging.Exit: every later gate is explicitly owned and containment has not been bypassed.
Gate 1 — independent governance and migration-line approval
Exit evidence: live GitHub policy packet is green; two independent approvals exist; all required exact-head checks are green; migration reviewer records forward/repair boundaries.
Gate 2 — isolated synthetic staging
Exit evidence: isolated environment inventory, synthetic-data attestation, exact SHA, migration/RLS/schema-conformance results,
/api/health200, and reset proof.Gate 3 — restore and recovery drill
Exit evidence: PHI-free drill record with RPO/RTO, operator, sources, checksums, test results, failures, and next due date.
Gate 4 — attributed data disposition
Exit evidence: all configured-data audits return release-safe, or each accepted exception has a named clinical owner, rationale, expiry, and compensating control.
Gate 5 — supervised clinic pilot
Exit evidence: signed pilot acceptance, zero unresolved safety-critical defects, completed runbooks/on-call coverage, and a reviewed rollback decision.
Promotion checklist — all must be true
Until every checkbox above is satisfied with current evidence, the decision remains NO-GO.
Ownership required now
Project owner: assign named humans and target dates for Gate 1 governance, Gate 2 cost approval, Gate 4 clinical data disposition, and Gate 5 clinic pilot. Engineering can continue producing evidence, but it cannot self-approve these controls or invent clinical decisions.