# AEGIS — Operational Readiness Review - **Document ID:** ARCH-56 - **Phase:** E.4 — Readiness & Long-View - **Status:** Draft for review (post four-reviewer discipline) - **Version:** 0.1 - **Date:** 2026-07-10 - **Owner:** Chief Security Architect --- ## 1. Purpose Codify the pre-launch operational checklist for AEGIS deployments. Distinct from Implementation Readiness (ARCH-53, which certifies *building*) and Release Certification (ARCH-54, which certifies *release engineering*). ORR certifies the *operating envelope* — the humans, tooling, and drills needed to run a deployment safely. ## 2. Checklist ### 2.1 Runbooks - All required runbooks present per subsystem (ARCH-21). - "Last drilled" dates current (≤ 90 d for standard, ≤ 30 d for Kernel-critical). - Runbook drift audit clean. ### 2.2 On-Call - Rotation staffed with primary + secondary + escalation. - Sustainability metrics healthy. - Communication channels tested. ### 2.3 Drills - Quarterly runbook drills pass rate ≥ 95% (last window). - Monthly chaos drills recorded. - Recovery drills (backup, restore, DR) current. - Tabletop cadence met. ### 2.4 Monitoring - Dashboards owned per subsystem. - Alarm routing verified. - SLO baselines set. - Trust Score visibility (ARCH-52). ### 2.5 Communications - Tenant communication templates current. - Regulator notification jurisdictional matrix current. - Internal comms channels for SEV-1..4 documented. - Legal + executive briefed on runbooks. ### 2.6 Ceremonies - Signing hierarchies (release, Kernel, KEK, evidence) drilled biannually. - Ceremony environments hardened. - Ceremony participants trained + rotated. ### 2.7 Access Control - Privileged access re-attested within window (ARCH-23 M-4a). - Standard access reviewed quarterly. - Break-glass workflow tested. - Termination process tested. ### 2.8 Third-Party - Vendor risk assessments current. - Vendor exit-path drills within 12 months. - Provider trust vectors reviewed. ### 2.9 Debt & Metrics - No overdue Debt (per ARCH-29). - Architecture Health Metrics green (ARCH-44). - Trust Score above threshold per subsystem (ARCH-52). ### 2.10 Documentation - Onboarding path complete. - Handoff runbooks tested. - Ownership matrix current. ## 3. Assessment Format `docs/orr/.md` — signed by Ops Lead + SR + OR + Auditor. ## 4. Assumption (hypothesis) - **H-1.** *A signed ORR is a sufficient pre-launch gate for operational safety.* - Evidence: pilot deployment. - Validation: incident correlation post-launch. - Confidence: Medium. - Expiration: 12 months. - Review Date: 6 months. ## 5. Trust Score Contribution Fed into `Operational History` + `Recovery Status`. ## 6. Independent Architecture Review - **F-1.** *Checklist can bloat.* Governance rule + retirement discipline. - **F-2.** *Checkpoint overlap with ARCH-53 / ARCH-54.* Overlap intentional; different scopes but reinforcing. ## 7. Adversarial Architect Review - **A-1.** *Insider signs off falsely.* Multi-signer + auditor + consistency checker. - **A-2.** *Attacker exploits gap between ORR sign and launch.* Time-bound between ORR and launch; automated re-check on launch. ## 8. Operational Reliability Review - **O-1.** Owned by Ops Lead + reviewed by SR + OR + Auditor. - **O-2.** Sustainable — one per deployment per major upgrade. ## 9. Self-Critique - **S-1.** *"Ready to operate" is culture, not just checklist.* Culture + training + drilled runbooks together. - **S-2.** *Some tenants may pressure to launch before ORR clean.* Auditor + Owner triad; no bypass. ## 10. First-Target Analysis and Redesign **Target:** the gap between ORR sign-off and go-live. If the deployment changes in that window, sign-off is stale. Response: automated re-check on launch; ORR expires within a bounded window; changes trigger re-run. ## 11. Future Risks / Known Limitations / Out-of-Scope / Retirement - **Future Risks.** Multi-region + MSSP scale-out complicates ORR — separate variants planned. - **Known Limitations.** Snapshot-in-time; validated by re-run on launch. - **Out-of-Scope.** Feature-level launches within a running deployment (governed by release process). - **Retirement Conditions.** Never. ## 12. Decisions ### D-56-1. Per-deployment ORR signed by multi-role team with automated re-check on launch - **Reason.** Operational safety gate + Zero SPOT. ## 13. Change Log - **0.1 (2026-07-10)** — Initial draft.