Fasil PM logoFasil PMProject & IT ConsultancyBook a call

Ready Is Not a Feeling. It Is a List With Signatures.

The go-live gate written as a list with named owners and signatures, instead of a room of people agreeing that things feel about ready.

Programme
Project Falcon
Organisation
Atlas Bank
Phase
Execution
Template
Readiness Assessment
Post 16 of 22 following Project Falcon at Atlas Bank. Full program context is in Post 01. Previously, Post 15 caught risk R04 materializing in shadow telemetry, fixed it for $52K, and wired the register's trigger conditions into live alerts. This post is the gate all of that was building toward: the board that decides whether Falcon is allowed to meet its customers.

Certification Is Done. Readiness Is a Different Question.

The fourteen weeks between Post 15 and this room contained most of what the program will ever be judged on. The sustained-peak performance test, the remediation the Post 09 audit asked for, ran 16 to 20 February: 3.1 times average load held for twelve hours, kyc-verify peaking at 38K under autoscaling, comfortably below its 50K trigger. R04 closed on 20 February, ten months after it was written, and the internal audit's finding closed with it, fourteen months after the audit, which is what the auditors meant when they dated the remediation rather than demanding it immediately. January also contained a 72-hour incident that tested the register's new alert mesh in ways nobody requested; that story needs its own post (Post 19 in this series), but its evidence pack sits in today's board pre-read, doing quiet work in the operations row.

Then certification week. The Market C central bank audit ran on-site 9 to 13 March, Olumide Adebayo's directorate examining everything Posts 13 through 15 generated: the CR-001 trail, the Amendment 2 monitoring provisions live in code, the txn-screen latency evidence holding at 130ms p99, the RR-R04 detection-to-closure pack. The certificate issued on 20 March with two supervisory observations: OBS-1 requests production latency telemetry for the 200ms SLA at 90 days post-launch, and OBS-2 recommends Atlas Bank formalize the trigger-instrumentation practice into standing risk policy, which is the closest a banking supervisor comes to a compliment.

The cost of certification season: $280K drawn from R01's allocated envelope of $300K, covering the evidence preparation, the independent latency attestation, and the on-site week. The $20K residual stays parked against R01 until wave 1 exits cleanly; releasing reserve the same week you start spending real customer traffic is a celebration the program declines.

And here is the distinction this post exists to teach: certification is necessary and nothing like sufficient. The regulator certified that Falcon's controls meet the directive. Nobody certified that the bank can operate Falcon at 02:00 on a Sunday, that twenty runbooks have owners who have read them, that the failover actually fails over. Certification is the regulator's question. Readiness is everyone else's, and on 26 March, the readiness board convenes to ask it across eight dimensions with the Phase 4 clock five days from starting.

Certification is the regulator's signature. Readiness is everyone else's.

Alemu Reads the DR Section and Reaches for His Veto

Abebe Alemu, CTO, holds one of the charter's three named vetoes: no production cutover without his signature. He has carried it for fourteen months without using it. He uses it now, on the dimension everyone assumed was green.

The disaster recovery submission is, on paper, complete. HAProxy active/active across two availability zones, documented failover procedures, RTO of 15 minutes and RPO of 60 seconds, runbooks reviewed. The submission's evidence column cites the documents. Alemu's question is four words long.

Abebe Alemu: “When did it run? Not the document review. The failover. When did this program last kill a live load balancer on purpose and watch what the platform actually does? Because if the answer is never, then what I am being asked to sign is a prediction, and my veto exists precisely so that nobody takes Atlas Bank into production on a prediction.”

The answer is never, and the room's discomfort is instructive, because the room is not wrong that the documentation is good. The DR design was reviewed in Phase 2, the configuration is in version control, the January incident even exercised parts of the recovery path under real pressure. But a documented failover and a demonstrated failover are different classes of evidence, and the gap between them is exactly where go-live disasters live. Priya Raman makes the engineering case for confidence; Alemu concedes every point of it and moves nothing.

Alemu: “I believe your design. I have read your January evidence. And the exercise still runs before I sign, because the day we need this to work, nobody will care what I believed in March.”

The resolution is condition C1: a live failover exercise on the staging-mirrored production stack, 30 March, run by Jin-ho Park's team with Alemu observing. Pass criteria written before the exercise, not after: failed requests under 0.1 percent during transition, full recovery inside 90 seconds, zero manual intervention. The exercise runs on the 30th and passes at 0.04 percent and 61 seconds, and Alemu signs the same afternoon. Worth recording for the lessons register: the veto holder was not the obstacle. He was the only person in the room pricing evidence correctly.

Osei Wants Wave One to Be Ten Times Bigger

The cutover plan ramps Market A in waves: 5,000 customers on 13 April, 50,000 on 27 April, 400,000 on 25 May, full go-live 14 July. Samuel Osei, Head of Retail Banking, arrives at the board with a marketing calendar and a proposal: collapse wave 1 into wave 2 and launch at 50,000, because retail has a campaign window in mid-April and “a five-thousand-customer launch is a pilot wearing a launch costume.”

Samuel Osei: “I own the revenue benefit. Every week the ramp stretches is a week of Revenue category value deferred, and my campaign window does not move because this program enjoys caution. Give me one operational reason wave 1 cannot be 50,000.”
Fasil Alemeye Abate: “One: wave 1 is not a launch, it is the only full-scale rehearsal we get with real money and a population small enough to hand-hold if the rehearsal fails. At 5,000, a critical defect is a bad week and a war room. At 50,000, it is a press story and a supervisory phone call from the office that certified us six days ago. The ramp is not caution. It is the price of the certificate staying clean.”

The resolution gives Osei a governed version of what he actually needs, which is a date he can market. Wave 1 holds at 5,000. The marketing window attaches to wave 2 on 27 April, whose exit criteria are published in the readiness assessment itself, and one new rule enters the cutover dimension: if wave 1 meets its exit criteria early, wave 2 may pull forward by up to seven days on steering approval. Osei gets a movable date with a mechanism instead of a fixed date with a hope. He takes it, and asks for the pull-forward rule in writing, which is the most program-literate thing he has done in sixteen posts.

The Gate Sequence · March to July 2026
Certification, readiness, conditions, and the wave ramp as one line. The board sits at the hinge: everything left of it is evidence, everything right of it is exposure.
9-13 Mar cert audit

20 Mar certificate 2 observations

26 Mar readiness board CONDITIONAL GO

30-31 Mar C1-C3 cleared

1-2 Apr Phase 4 opens, steering ratifies

13 Apr wave 1: 5K

27 Apr wave 2: 50K campaign window

25 May wave 3: 400K

14 Jul full go-live

left of the hinge: evidence · right of the hinge: exposure

A Conditional Go is not a hedge. It is a Go with its homework attached.

Drafting the Readiness Assessment with IRAC

Readiness reviews fail in a characteristic way: every dimension reports confidence and nobody reports against a rule. The fix is to treat the board as adjudication, and the drafting framework that enforces adjudication is IRAC: Issue, Rule, Application, Conclusion, the structure legal education has used for case analysis for over a century. Well-cited in its home domain; its use as a prompt framework for program artifacts is an adaptation, noted as such. Per dimension, IRAC forces four moves: name the Issue (is this dimension ready for Phase 4?), state the Rule (the pre-agreed criterion, classified Must or Should before anyone knew their color), apply the Evidence against the rule, and conclude with a status that someone signs. The Must/Should classification borrows MoSCoW's vocabulary as a gate convention: Must criteria block the Go; Should criteria become dated conditions; nothing gets to be important and unclassified.

Prompt · Readiness Assessment Draft · 23 March 2026
You are drafting a go-live Readiness Assessment for a regulated banking program entering controlled rollout. Structure every dimension in IRAC: ISSUE (the readiness question), RULE (the pre-agreed criterion and its Must/Should classification), APPLICATION (submitted evidence applied against the rule, cited), CONCLUSION (Green / Amber / Red, with the sign-off owner named). CONTEXT. Program Falcon, Atlas Bank. Day 433. Phase 3 closes 31 Mar 2026; Phase 4 (Controlled Rollout) opens 1 Apr. Market C certificate issued 20 Mar 2026 with 2 supervisory observations. Wave plan: 5K (13 Apr), 50K (27 Apr), 400K (25 May), full go-live 14 Jul 2026. Readiness board: 26 Mar 2026. DIMENSIONS AND SUBMISSIONS (owner submissions attached as context): 1 Regulatory certification (Must). 2 Technical platform incl. sustained-peak test of 16-20 Feb (Must). 3 Disaster recovery (classified Should in submissions: documentation complete, live failover unexercised). 4 Operations and support: runbooks 14/20 signed, 24/7 rota submitted (Must). 5 People and training: 18/20 services trained (Should). 6 Vendor readiness and hypercare terms (Should). 7 Benefits instrumentation per Post 08 categories (Should). 8 Cutover and rollback plan incl. wave exit criteria (Must). TASK. Draft the Readiness Assessment with one IRAC block per dimension, a consolidated RAG grid, and a recommendation (Go / Conditional Go / No-Go). Cross-check the dimension submissions against each other and flag any inconsistencies between them; owners drafted their sections independently. Keep under 1,100 words.

The Cross-Check That Earned Its Keep

The draft's IRAC blocks were competent and largely survived. The cross-check instruction is where the machine found the thing eight independent owners could not have found, because each of them was right in isolation.

AI Draft · Readiness Assessment · Dimension 4 (Extract) and Cross-Check

DIMENSION 4: OPERATIONS AND SUPPORT. Issue: can the bank operate Falcon's twenty services from 1 April? Rule (Must): all service runbooks signed by their operating owner; 24/7 rota staffed with named primaries and secondaries for every on-call group. Application: 14 of 20 runbooks carry sign-off; the remaining six are drafted, unsigned. The submitted rota names primaries and secondaries for all groups. Conclusion: AMBER. Runbook completion is a bounded, dated task; recommend condition rather than block.

AI flagged: “Cross-check finding: the operations rota (dimension 4) and the txn-screen support plan (dimension 2 annex) each name the same senior SRE as primary on-call. Each submission is internally consistent; together they schedule one person as simultaneous primary for the Market A rollout group and the txn-screen group through April. Additionally, the training submission (dimension 5) lists the two untrained services as case-mgmt and txn-screen; txn-screen's only trained backup is the same individual. This is a single-person dependency at the center of the rollout window. No submission is wrong; the combination is.”

Eight green submissions can assemble into one red fact, and no dimension owner is positioned to see it. Each owner staffed their rota from the same short list of senior people, the way every organization does, and the overlap only exists in the union of documents nobody reads side by side, except a machine that was told to. The finding becomes condition C3: the rotas are restructured so no individual is primary in two groups, and a cross-training pair is assigned to txn-screen with sign-off due 31 March. Worth being honest about the division of labor here: the AI did not understand that a person can be in only one war room at a time. It matched names across documents. The understanding was the board's job; the matching was beyond the board's patience, and both were necessary.

The Readiness Assessment, as Decided

Readiness AssessmentRA-001 · v1.0
Phase 4 Entry: Go / No-Go, Market A Controlled Rollout
Project Falcon · Atlas Bank · Board chaired by Fatima Idris · Prepared by Fasil Alemeye Abate
Decision Conditional Go Board 26 Mar 2026 · Conditions cleared 31 Mar 2026 · Steering ratified 2 Apr 2026

Consolidated Grid

DimensionClassStatus at BoardCondition / Evidence
1 · Regulatory certificationMustGreen Certificate 20 Mar, 2 observationsOBS-1 telemetry due 90 days post-launch; owner A. Okonkwo
2 · Technical platformMustGreen Sustained-peak test passed 20 Feb; R04 closedLatency holding 130ms p99 on txn-screen path
3 · Disaster recoveryMust (reclassified)Amber Documented; live failover unexercisedC1: live exercise 30 Mar; pass <0.1% failed, <90s recovery; sign-off A. Alemu. Passed: 0.04% / 61s
4 · Operations and supportMustAmber Runbooks 14/20; rota double-booking foundC2: 6 runbooks signed by 31 Mar (J. Park). C3: rota restructure + txn-screen cross-training pair by 31 Mar (P. Raman)
5 · People and trainingShouldGreen 18/20 trained; remaining 2 inside C3 scopeFolded into C3 verification
6 · Vendor readinessShouldGreen Hypercare terms agreed; attestations filedHypercare window: wave 1 through wave 3 + 30 days (D. Volkov)
7 · Benefits instrumentationShouldGreen Dashboards live per Post 08 categoriesRevenue category baseline capture starts at wave 1 (S. Osei, T. Richter)
8 · Cutover and rollbackMustGreen Wave exit criteria published; rollback rehearsed in stagingWave-2 pull-forward rule: ≤7 days on steering approval if wave-1 exits early
RA-001 consolidated grid as ratified. Classification (Must/Should) was agreed on 12 March, before any dimension submitted evidence: rules first, colors second.

Decision Record

CONDITIONAL GO. Phase 4 opens on schedule 1 April 2026. No customer traffic before wave 1 on 13 April; all three conditions carry 31 March deadlines, named owners, and named sign-offs, and all three cleared on time (C1 on 30 March, C2 and C3 on 31 March). Steering ratified 2 April. R01 residual ($20K of the $300K envelope; $280K utilized in certification) remains parked until wave 1 exit. Link: certification certificate and observations (20 Mar 2026); failover exercise report (30 Mar 2026); RR-R04 closure pack; January incident evidence pack.

What the Human Changed

What the Human Changed (AI Draft to Ratified RA-001)
  1. Reclassified disaster recovery from Should to Must. The draft inherited the submission's Should, reasoning that documentation plus the January evidence covered the risk. Fasil overruled it on a structural principle: any dimension protected by a charter veto is a Must by definition, because the veto holder can convert it to a block at will, and a gate that pretends otherwise is misreporting its own rules. Alemu proved the principle within the hour.
  2. Converted the recommendation from Go to Conditional Go. The draft recommended Go with the amber items listed as “follow-ups.” Follow-ups after a Go are suggestions; conditions before one are commitments. Three conditions, three dates, three named sign-offs, and the Go does not exist until they do.
  3. Promoted the cross-check finding from note to condition. The draft logged the double-booked SRE under “hypercare planning considerations.” A single-person dependency spanning the rollout window is not a consideration; it is C3, with a rota restructure, a cross-training pair, and a 31 March signature.
  4. Wrote the pass criteria for C1 before the exercise, into the document. The draft left the failover exercise's success definition to the exercise report. Criteria written after results are not criteria. The 0.1 percent and 90-second thresholds went into RA-001 on 26 March, four days before anyone knew the numbers would be 0.04 and 61.
  5. Embedded the wave-2 pull-forward rule in the cutover dimension. The Osei compromise lived in meeting minutes; minutes are where agreements go to be remembered differently. The rule, seven days maximum, steering approval required, wave 1 exit criteria as the trigger, is now a sentence in the ratified artifact that July cannot renegotiate.
The Future Payoff

The 30 March failover exercise is sixty-one seconds of rehearsal that becomes the program's muscle memory on go-live day, when the HAProxy pair gets exercised by reality instead of by appointment (Post 20). The conditional-go pattern, rules before colors, conditions before celebration, becomes the template the lessons register generalizes (Post 21). And OBS-1's 90-day production telemetry request matures into one of the measured commitments in the twelve-month value review (Post 22), because a supervisory observation is just a benefit measurement someone else scheduled for you.

Wave 1 went to 5,000 customers on 13 April and exited on its criteria. Wave 2 pulled forward four days under the rule nobody had to argue about, because it was written down. The series now steps back twice before it steps forward: Post 17 returns to the quarter where the money was re-baselined, and Post 18 to the night the program nearly got cancelled, both of which were already shaping the room this post described.

The Takeaway
Ready is not a feeling. It is a list with signatures.
Every program reaches a room where someone asks “are we ready?” and the honest answer is a mood. The readiness assessment exists to make the mood inadmissible: classify the criteria before the evidence arrives, judge each dimension against its rule instead of its owner's confidence, cross-check the submissions against each other because eight green documents can hide one red fact, and let a Conditional Go be what it is, a Go that respects its own findings. The two ambers in Falcon's grid were not weaknesses in the program. They were the grid working: one veto holder pricing evidence correctly, one machine reading documents side by side, and five days of homework standing between a good program and a defensible one.

A fictional case study for teaching purposes. Atlas Bank, Project Falcon and all named individuals are invented. Technologies are industry-standard and publicly available.