Production readiness and what remains
Understand the launch gates every organization must satisfy and the platform investments that remain after the first campaign.
GTM Brain's hosted production application runs on Cloudflare with PostgreSQL, Temporal, governed proof storage, versioned workflows, replay validation, and worker rollback controls. Customer-managed Databricks remains an optional legacy deployment and analytics target; references below record that target's certification history rather than the hosted product's current topology. Learning remains reporting-only. Live dispatch is never implied by installing the application or connecting a provider; every organization must satisfy the launch gates below and explicitly activate the tenant/campaign-version-bound, expiring canary with an explicit ceiling no greater than 50 sends/day.
Connection state, ICP policy, suppressions, proof assets, and campaign results are private tenant operations. They are visible in the authenticated application and are intentionally not published in this documentation.
Organization launch gates
| Priority | Work | Why it blocks launch |
|---|---|---|
| P0 | Approve and configure at least one trusted qualification source | Stub or shadow-only signals must never authorize live sends |
| P0 | Connect Instantly and choose the campaign ID | Delivery, inbox rotation, warmup, and stop-on-reply |
| P0 | Register at least one warmed sending inbox | The policy engine needs a safe daily ramp and sender identity |
| P0 | Seed suppression entries and import customer/do-not-contact domains | Prevent outreach to customers, unsubscribes, and protected domains |
| P0 | Define ICP, geography, personas, exclusions, and daily cap | Gives the judge a bounded operating policy |
| P0 | Run dry-run and review the first shortlist/drafts | Human verification before any live send |
| P0 | Promote one governed, unexpired proof for every active offer | Readiness fails closed when an offer lacks approved proof |
| P0 | Pass preflight and authorize the live canary (up to 50/day) | The system intentionally has no implicit or tenant-wide go-live |
| P0 | Atomically promote the campaign version via gtm.promote_campaign_live | A subject-bound principal proof clears dry-run and activates in one durable transition; agents cannot call this action |
Production hardening after launch
| Priority | Investment | Outcome |
|---|---|---|
| P1 | Configure transactional email | Verification, magic-link login, password reset, approval notifications |
| P1 | Review Google or GitHub OAuth before enabling | Both providers are deliberately disabled in UI and server configuration |
| P1 | Add job/App failure notifications | Faster response to failed projections or deployments |
| P1 | Add backup/restore and branch recovery drill | Proven operational recovery, not only configured HA |
| P1 | Run a controlled end-to-end vendor sandbox test | Validate sense → judge → approval → delivery → webhook without prospects |
| P2 | Build AI/BI dashboard on funnel and gateway usage | Executive visibility into cost, conversion, and throughput |
| P2 | Close the MLflow outcome loop | Compare prompt/model variants against replies and meetings |
| P2 | Add provider failover policy | Controlled fallback between system models and a provider service |
| P2 | Add synthetic App checks | Continuous login, API, SQL, Lakebase, and worker health monitoring |
Reference deployment verification
- The production hardening Databricks App deployment is active.
- The proof Volume is bound through the Databricks bundle and both production and canary App identities have read/write access. Fresh production logs contain no missing-resource warning.
- Temporal namespace registration, V1/V2 replay, restart/resume, canary, rollback, and V1 drain checks have passed.
- The live Databricks integration suite passed its workspace checks.
- The protected finite-agent suite passed reviewer and generator execution on
databricks-claude-sonnet-4-6; its frozen Fabric Experiments dataset met the1.0contract threshold and produced a privacy-safe hash-only scorecard. - Readiness doctor passed workspace auth, Gateway v2, model discovery, real Claude request, SQL, gateway usage, analytics/OTel, MLflow, and Lakebase TLS.
- The serverless Lakebase-to-Delta projection completed successfully.
- A staging V2 Health & Governance lineage replay was idempotent and excluded message/evidence content.
- GTM, API, mail-provider, replay, and workspace type checks pass.
- Password login, organization creation, organization-owner access, and Integrations UI were tested against the current production deployment.
- A real-source V2 pass completed sensing, model judgment, drafting, notification, authenticated rejection, and durable resolution with zero delivery attempts.
- The dedicated Instantly preview endpoint accepted a one-recipient internal transport check without adding a campaign lead. The global V2 live-delivery flag remained disabled.
- The production readiness gate passed all non-dispatch checks.
- The first supervised one-send prospect canary completed successfully on 2026-08-07 (Travelers, one exact tenant/campaign/recipient, natural-person approval). Production returned to disabled/off after that single verified send.
- Lakebase schema ledger is at migration 53. See the production readiness review and the first-live-send runbook for the complete evidence chain.
- Production remains deliberately disabled/off until an operator creates the separate active non-dry-run campaign version and supplies its strict, expiring, bounded canary binding.
Phase 4 platform status
Phase 4 is implemented:
- tenant skill drafts carry structured I/O, knowledge bindings, explicit allowed actions, risk, approval, fixtures, and finite runtime budgets;
- activation fails closed on missing fixtures, inactive tenant knowledge, unreviewed actions, or unsafe approval settings;
- the assistant can propose and test this exact contract, but cannot activate it or convert an allowlist entry into an action grant; and
- general tenant skills execute durably through
gtm.request_skill_run, compact Temporal history, the compiled no-toolskill-runner, immutable private output staging, exact execution-time skill scope, proposal-only results, and 30-day bounded retention; and - protected Databricks reviewer/generator/skill-runner runs are evaluated against a frozen Fabric Experiments dataset and emit a privacy-safe release scorecard; and
- each passing certification is persisted as one retry-bound native managed-MLflow run, read back through Fabric Experiments, and required to satisfy fail-closed release gates; and
- exact-version certification and revocation are governed Platform actions, promotion fails closed at enablement and every execution seam, the operator console exposes the immutable promotion ledger, and a privacy-safe rolling outcome projection reports run reliability, reviewer classifications, and independently decided generator proposals with small-cohort suppression.
Phase 4 implementation is complete. Phase 5's commercial experiment foundation, governed lifecycle, activation binding, immutable assignment control plane, campaign-bound draft consumption, actual-delivery exposure, immutable attribution repair, and governed exposure retention are implemented. Fabric Experiments' published lifecycle actions are adapted into GTM Brain's existing Fabric Platform Host, with tenant-scoped Lakebase persistence, stable command admission, canonical audit events, and explicit human capabilities. A plan may be created, submitted, and approved only when its two variant payloads exactly bind currently certified immutable artifact-generator versions.
The prospective analysis still uses Fabric Experiments' published deterministic assignment and exposure schemas, isolates assignment by tenant and opaque account cluster, recognizes exposure only for an exact actual delivery, and evaluates two fixed 30-day windows after the complete 21-day maturity period. It fails closed on unattributed delivery, uses the predeclared 10,000-resample account-cluster bootstrap and release thresholds, and returns reporting evidence for human review.
Production routing remains pinned to the certified control.
gtm.record_commercial_experiment_activation_v1 accepts only an approved plan's exact binding hash,
one immutable active campaign version, two exact approved treatment artifact revisions/runs, and an
immutable Product, Marketing, and Security/Privacy decision ID/hash that already exists in the
reviewed source-controlled registry. That production registry is currently empty. When a tuple is
injected in tests, the start policy revalidates its plan, campaign, manifest, artifact provenance,
and current certifications, and
gtm.assign_commercial_experiment_treatment_v1 persists one tenant-bound, no-crossover account
assignment through the Fabric Experiments Node client. Lakebase migration 45 stores activation and
assignment evidence under an opaque tenant-bound account-cluster hash, without a raw account
identifier.
Lakebase migration 46 stores the immutable campaign treatment-consumption contract and exact
draft-consumption binding. The campaign-pass activity resolves assignment server-side;
gtm.draft_outreach_v2 recalculates it, selects the assigned immutable artifact, and commits the
draft, consumption row, and privacy-safe event atomically. Callers cannot select a variant.
Lakebase migration 47 adds actual-delivery exposure. The approved-send handler and adapter revalidate
the exact running treatment binding before provider delivery. After provider acceptance, the
delivery-attempt sent transition, touch/cooldown row, and canonical Fabric Experiments exposure
commit in one transaction. A missing or conflicting exposure rolls the transaction back; governed
reconciliation repairs a provider-accepted attempt without sending twice. A later pause or
certification revocation blocks new sends but does not block truthful recovery of the exact immutable
binding that the provider already accepted.
Lakebase migration 48 adds audit_24m exposure deadlines and privacy-minimized retention tombstones.
The daily, stable-idempotency internal Platform action
gtm.enforce_commercial_experiment_exposure_retention_v1 deletes at most 250 expired active rows per
tenant and atomically preserves only the exposure hash, experiment/version, deletion time, policy,
and invocation linkage. An atomic run marker makes retry return the exact same tombstones or empty
result and rejects changed parameters; late delivery recovery cannot resurrect evidence. Human
attribution_fix corrections through gtm.correct_outcome_v2 preserve the original event and may
rebind only to an exact sent V2 touch for the same company and tenant. The tenant operator endpoint
exposes
aggregate active/retained evidence and correction counts without delivery or subject identifiers.
The remaining activated-path work is the privacy-minimized Fabric Experiments analysis/export projection plus live Databricks BDD/evaluation certification before any accepted tuple is added to the production activation registry.
The experiment lifecycle, activation, and assignment actions are not in the external-agent catalog. Hermes and other external agents cannot configure, approve, activate, assign, start, pause, resume, or kill an experiment. Fabric Experiments remains the lifecycle, assignment, exposure, and evaluation owner; every GTM business mutation still passes through Fabric Platform. It is not an alternate mutation path.
Production-ready source seams are Apollo Signal V2, curated Monid Signal V2, Instantly enrichment, and manual/external-agent Signal V2 ingestion. Monid credentials are organization-owned, while the endpoint catalog is deployment-owned, versioned, schema/price pinned, legally approved, and cost-capped. An empty or shadow-only catalog cannot authorize a live campaign. After an organization completes its private dry run, the next safe milestone is a human-reviewed first batch with a deliberately small daily cap and separate authorization for live dispatch.