Ready Is Not a Feeling. It Is a List With Signatures.
The go-live gate written as a list with named owners and signatures, instead of a room of people agreeing that things feel about ready.
Certification Is Done. Readiness Is a Different Question.
The fourteen weeks between Post 15 and this room contained most of what the program will ever be judged on. The sustained-peak performance test, the remediation the Post 09 audit asked for, ran 16 to 20 February: 3.1 times average load held for twelve hours, kyc-verify peaking at 38K under autoscaling, comfortably below its 50K trigger. R04 closed on 20 February, ten months after it was written, and the internal audit's finding closed with it, fourteen months after the audit, which is what the auditors meant when they dated the remediation rather than demanding it immediately. January also contained a 72-hour incident that tested the register's new alert mesh in ways nobody requested; that story needs its own post (Post 19 in this series), but its evidence pack sits in today's board pre-read, doing quiet work in the operations row.
Then certification week. The Market C central bank audit ran on-site 9 to 13 March, Olumide Adebayo's directorate examining everything Posts 13 through 15 generated: the CR-001 trail, the Amendment 2 monitoring provisions live in code, the txn-screen latency evidence holding at 130ms p99, the RR-R04 detection-to-closure pack. The certificate issued on 20 March with two supervisory observations: OBS-1 requests production latency telemetry for the 200ms SLA at 90 days post-launch, and OBS-2 recommends Atlas Bank formalize the trigger-instrumentation practice into standing risk policy, which is the closest a banking supervisor comes to a compliment.
The cost of certification season: $280K drawn from R01's allocated envelope of $300K, covering the evidence preparation, the independent latency attestation, and the on-site week. The $20K residual stays parked against R01 until wave 1 exits cleanly; releasing reserve the same week you start spending real customer traffic is a celebration the program declines.
And here is the distinction this post exists to teach: certification is necessary and nothing like sufficient. The regulator certified that Falcon's controls meet the directive. Nobody certified that the bank can operate Falcon at 02:00 on a Sunday, that twenty runbooks have owners who have read them, that the failover actually fails over. Certification is the regulator's question. Readiness is everyone else's, and on 26 March, the readiness board convenes to ask it across eight dimensions with the Phase 4 clock five days from starting.
Alemu Reads the DR Section and Reaches for His Veto
Abebe Alemu, CTO, holds one of the charter's three named vetoes: no production cutover without his signature. He has carried it for fourteen months without using it. He uses it now, on the dimension everyone assumed was green.
The disaster recovery submission is, on paper, complete. HAProxy active/active across two availability zones, documented failover procedures, RTO of 15 minutes and RPO of 60 seconds, runbooks reviewed. The submission's evidence column cites the documents. Alemu's question is four words long.
The answer is never, and the room's discomfort is instructive, because the room is not wrong that the documentation is good. The DR design was reviewed in Phase 2, the configuration is in version control, the January incident even exercised parts of the recovery path under real pressure. But a documented failover and a demonstrated failover are different classes of evidence, and the gap between them is exactly where go-live disasters live. Priya Raman makes the engineering case for confidence; Alemu concedes every point of it and moves nothing.
The resolution is condition C1: a live failover exercise on the staging-mirrored production stack, 30 March, run by Jin-ho Park's team with Alemu observing. Pass criteria written before the exercise, not after: failed requests under 0.1 percent during transition, full recovery inside 90 seconds, zero manual intervention. The exercise runs on the 30th and passes at 0.04 percent and 61 seconds, and Alemu signs the same afternoon. Worth recording for the lessons register: the veto holder was not the obstacle. He was the only person in the room pricing evidence correctly.
Osei Wants Wave One to Be Ten Times Bigger
The cutover plan ramps Market A in waves: 5,000 customers on 13 April, 50,000 on 27 April, 400,000 on 25 May, full go-live 14 July. Samuel Osei, Head of Retail Banking, arrives at the board with a marketing calendar and a proposal: collapse wave 1 into wave 2 and launch at 50,000, because retail has a campaign window in mid-April and “a five-thousand-customer launch is a pilot wearing a launch costume.”
The resolution gives Osei a governed version of what he actually needs, which is a date he can market. Wave 1 holds at 5,000. The marketing window attaches to wave 2 on 27 April, whose exit criteria are published in the readiness assessment itself, and one new rule enters the cutover dimension: if wave 1 meets its exit criteria early, wave 2 may pull forward by up to seven days on steering approval. Osei gets a movable date with a mechanism instead of a fixed date with a hope. He takes it, and asks for the pull-forward rule in writing, which is the most program-literate thing he has done in sixteen posts.
Drafting the Readiness Assessment with IRAC
Readiness reviews fail in a characteristic way: every dimension reports confidence and nobody reports against a rule. The fix is to treat the board as adjudication, and the drafting framework that enforces adjudication is IRAC: Issue, Rule, Application, Conclusion, the structure legal education has used for case analysis for over a century. Well-cited in its home domain; its use as a prompt framework for program artifacts is an adaptation, noted as such. Per dimension, IRAC forces four moves: name the Issue (is this dimension ready for Phase 4?), state the Rule (the pre-agreed criterion, classified Must or Should before anyone knew their color), apply the Evidence against the rule, and conclude with a status that someone signs. The Must/Should classification borrows MoSCoW's vocabulary as a gate convention: Must criteria block the Go; Should criteria become dated conditions; nothing gets to be important and unclassified.
The Cross-Check That Earned Its Keep
The draft's IRAC blocks were competent and largely survived. The cross-check instruction is where the machine found the thing eight independent owners could not have found, because each of them was right in isolation.
DIMENSION 4: OPERATIONS AND SUPPORT. Issue: can the bank operate Falcon's twenty services from 1 April? Rule (Must): all service runbooks signed by their operating owner; 24/7 rota staffed with named primaries and secondaries for every on-call group. Application: 14 of 20 runbooks carry sign-off; the remaining six are drafted, unsigned. The submitted rota names primaries and secondaries for all groups. Conclusion: AMBER. Runbook completion is a bounded, dated task; recommend condition rather than block.
Eight green submissions can assemble into one red fact, and no dimension owner is positioned to see it. Each owner staffed their rota from the same short list of senior people, the way every organization does, and the overlap only exists in the union of documents nobody reads side by side, except a machine that was told to. The finding becomes condition C3: the rotas are restructured so no individual is primary in two groups, and a cross-training pair is assigned to txn-screen with sign-off due 31 March. Worth being honest about the division of labor here: the AI did not understand that a person can be in only one war room at a time. It matched names across documents. The understanding was the board's job; the matching was beyond the board's patience, and both were necessary.
The Readiness Assessment, as Decided
Consolidated Grid
| Dimension | Class | Status at Board | Condition / Evidence |
|---|---|---|---|
| 1 · Regulatory certification | Must | Green Certificate 20 Mar, 2 observations | OBS-1 telemetry due 90 days post-launch; owner A. Okonkwo |
| 2 · Technical platform | Must | Green Sustained-peak test passed 20 Feb; R04 closed | Latency holding 130ms p99 on txn-screen path |
| 3 · Disaster recovery | Must (reclassified) | Amber Documented; live failover unexercised | C1: live exercise 30 Mar; pass <0.1% failed, <90s recovery; sign-off A. Alemu. Passed: 0.04% / 61s |
| 4 · Operations and support | Must | Amber Runbooks 14/20; rota double-booking found | C2: 6 runbooks signed by 31 Mar (J. Park). C3: rota restructure + txn-screen cross-training pair by 31 Mar (P. Raman) |
| 5 · People and training | Should | Green 18/20 trained; remaining 2 inside C3 scope | Folded into C3 verification |
| 6 · Vendor readiness | Should | Green Hypercare terms agreed; attestations filed | Hypercare window: wave 1 through wave 3 + 30 days (D. Volkov) |
| 7 · Benefits instrumentation | Should | Green Dashboards live per Post 08 categories | Revenue category baseline capture starts at wave 1 (S. Osei, T. Richter) |
| 8 · Cutover and rollback | Must | Green Wave exit criteria published; rollback rehearsed in staging | Wave-2 pull-forward rule: ≤7 days on steering approval if wave-1 exits early |
Decision Record
CONDITIONAL GO. Phase 4 opens on schedule 1 April 2026. No customer traffic before wave 1 on 13 April; all three conditions carry 31 March deadlines, named owners, and named sign-offs, and all three cleared on time (C1 on 30 March, C2 and C3 on 31 March). Steering ratified 2 April. R01 residual ($20K of the $300K envelope; $280K utilized in certification) remains parked until wave 1 exit. Link: certification certificate and observations (20 Mar 2026); failover exercise report (30 Mar 2026); RR-R04 closure pack; January incident evidence pack.
What the Human Changed
- Reclassified disaster recovery from Should to Must. The draft inherited the submission's Should, reasoning that documentation plus the January evidence covered the risk. Fasil overruled it on a structural principle: any dimension protected by a charter veto is a Must by definition, because the veto holder can convert it to a block at will, and a gate that pretends otherwise is misreporting its own rules. Alemu proved the principle within the hour.
- Converted the recommendation from Go to Conditional Go. The draft recommended Go with the amber items listed as “follow-ups.” Follow-ups after a Go are suggestions; conditions before one are commitments. Three conditions, three dates, three named sign-offs, and the Go does not exist until they do.
- Promoted the cross-check finding from note to condition. The draft logged the double-booked SRE under “hypercare planning considerations.” A single-person dependency spanning the rollout window is not a consideration; it is C3, with a rota restructure, a cross-training pair, and a 31 March signature.
- Wrote the pass criteria for C1 before the exercise, into the document. The draft left the failover exercise's success definition to the exercise report. Criteria written after results are not criteria. The 0.1 percent and 90-second thresholds went into RA-001 on 26 March, four days before anyone knew the numbers would be 0.04 and 61.
- Embedded the wave-2 pull-forward rule in the cutover dimension. The Osei compromise lived in meeting minutes; minutes are where agreements go to be remembered differently. The rule, seven days maximum, steering approval required, wave 1 exit criteria as the trigger, is now a sentence in the ratified artifact that July cannot renegotiate.
The 30 March failover exercise is sixty-one seconds of rehearsal that becomes the program's muscle memory on go-live day, when the HAProxy pair gets exercised by reality instead of by appointment (Post 20). The conditional-go pattern, rules before colors, conditions before celebration, becomes the template the lessons register generalizes (Post 21). And OBS-1's 90-day production telemetry request matures into one of the measured commitments in the twelve-month value review (Post 22), because a supervisory observation is just a benefit measurement someone else scheduled for you.
Wave 1 went to 5,000 customers on 13 April and exited on its criteria. Wave 2 pulled forward four days under the rule nobody had to argue about, because it was written down. The series now steps back twice before it steps forward: Post 17 returns to the quarter where the money was re-baselined, and Post 18 to the night the program nearly got cancelled, both of which were already shaping the room this post described.
A fictional case study for teaching purposes. Atlas Bank, Project Falcon and all named individuals are invented. Technologies are industry-standard and publicly available.