Trust

See service status, support boundaries, and the public trust signals Artax shares.

ReviewAccountAdd-on

Release assurance

Release assurance, without pretending provenance is complete.

This page combines the current Artax release-evidence registry, explicit release-approval records, canary rules, provenance-attestation policy, release-attestation-artifact policy, release-tracking policy, release-evidence-linkage policy, release-record-adoption policy, release-approval-authority policy, release-promotion policy, release-smoke-verification policy, release-rollback policy, release-target launch gates, and provenance-baseline posture in one public-safe view. It is a real assurance surface, not a production launch approval or signed provenance statement.

Launch-gate linkedApproval-record linkedLinkage policy definedAdoption policy definedAttestation policy definedNot signed provenance

Release evidence and approval records

This page gathers release evidence, rollout gates, approval records, provenance posture, smoke checks, promotion records, and rollback targets in one place. It explains what is documented and what is still missing without turning policy files, pre-production wiring, or local evidence into a production approval claim.

Evidence records

Release evidence records tracked in the release registry.

14

Approval records

Release-target gates with explicit approval and provenance records.

2/2

Signed provenance

Release approval records that report signing artifacts or external attestation.

0/2

Canary rules

Bounded canary-rule records tied to production rollout posture.

1

Attestation policies

Provenance-attestation policy records defining required lineage and production verification posture.

2

Attestation records

Checked-in attestation artifact records. Live workflow-backed: 0. Local or synthetic proof: 2.

2

Authority records

Checked-in approval-authority records. Live workflow-backed: 0. Local or synthetic proof: 1.

1

Tracked releases

Checked-in tracked release records. Live workflow-backed: 0. Local or synthetic proof: 1.

1

Linkage records

Checked-in release evidence linkage records. Live workflow-backed: 0. Local or synthetic proof: 1.

1

Adoption records

Checked-in release record adoption records. Live workflow-backed: 0. Local or synthetic proof: 1.

1

Promotion records

Checked-in promotion records. Live workflow-backed: 0. Local or synthetic proof: 1.

1

Smoke records

Checked-in smoke verification records. Live workflow-backed: 0. Local or synthetic proof: 1.

1

Rollback targets

Checked-in trusted rollback target records. Live workflow-backed: 0. Local or synthetic proof: 1.

1

Production approvals

Release approval records that grant production launch approval.

0

Release posture

What is documented

Guarded rollout

Staging Rollout Gated Not Production. Approval state: Staging Bundle Backed Manual Rollout Only. Deployment allowed: yes.

Production launch

Production Rollout Workflow Defined Launch Blocked. Approval state: Production Rollout Workflow Defined Launch Blocked. Production ready: no.

Production timing

A healthy pre-production or production-candidate posture does not force an immediate production launch. Artax can keep validating on pre-production and devnet until the production milestone is met.

Provenance posture

Formal release approval records exist for the release targets, but only 0 records report signed provenance artifacts.

Attestation posture

2 attestation policy records define the provenance requirements, but only 0 report recorded attestation evidence.

Attestation artifact posture

3 release-attestation-artifact policy records define checked-in artifact expectations, and 2 checked-in attestation artifact records exist. Live workflow-backed: 0. Local or synthetic proof: 2.

Authority posture

2 release-approval-authority policy records define human approval and automation-reference requirements, and 1 checked-in approval-authority record exist. Live workflow-backed: 0. Local or synthetic proof: 1.

Release identity posture

2 release-tracking policy records define stable artifact-set identity rules, and 1 checked-in tracked release record exist. Live workflow-backed: 0. Local or synthetic proof: 1.

Release coherence posture

2 release-evidence-linkage policy records define cross-record artifact identity coherence, and 1 checked-in release evidence linkage record exist. Live workflow-backed: 0. Local or synthetic proof: 1.

Release adoption posture

2 release-record-adoption policy records define how generated bundle artifacts are promoted into checked-in release truth, and 1 checked-in adoption record exist. Live workflow-backed: 0. Local or synthetic proof: 1.

Promotion posture

2 release-promotion policy records define staged release promotion requirements, and 1 checked-in promotion record exist. Live workflow-backed: 0. Local or synthetic proof: 1.

Smoke posture

2 release-smoke-verification policy records define required post-deploy checks, and 1 checked-in smoke verification record exist. Live workflow-backed: 0. Local or synthetic proof: 1.

Rollback posture

2 release-rollback policy records define rollback-target expectations, and 1 checked-in trusted rollback target record exist. Live workflow-backed: 0. Local or synthetic proof: 1.

Canary posture

1 bounded canary rule describe the current production rollout ring. Approval status: Canary Rules Defined No Live Canary Smoke Or Dashboard Environment Key Record.

Release approval boundary

These records, canary rules, attestation policies, attestation-artifact policies, release-tracking policies, release-evidence-linkage policies, release-record-adoption policies, release-approval-authority policies, release-promotion policies, release-smoke-verification policies, and release-rollback policies describe current approval posture, rollout boundaries, bundle expectations, and blockers. They do not approve a production release, widen compatibility claims, or replace the actual launch gates.

Release approval records

release_approval.render_staging_rollout.bundle_backed_manual_staging

Staging approval posture

Current state

Staging Bundle Backed Manual Rollout Only

Approval mode

Manual Workflow Dispatch With Human Initiation. Scope: Staging Rollout Only.

Release and artifact identity

Release version source: Workflow Dispatch Ref Resolved To Checked Out Commit Sha. Artifact set source: Workflow Run Or Local Commit Scoped Release Artifact Set. Source revision source: Checked Out Commit Sha After Actions Checkout.

Provenance and signing

Digest source: Generated Release Evidence Bundle Sha256 Snapshots. Provenance: Per Run Bundle Generated Not Signed. Signing: Unsigned No External Attestation.

Required tracking policies

release_tracking_policy.render_staging_rollout.bundle_identity

Required authority policies

release_approval_authority.render_staging_rollout.manual_dispatch

Required promotion policies

release_promotion_policy.render_staging_rollout.explicit_stage_ladder

Required rollback policies

release_rollback_policy.render_staging_rollout.documented_ref

Required smoke policies

release_smoke_verification.render_staging_rollout.web_edge

Required attestation policies

attestation_policy.release_bundle_minimum_lineage

Required attestation-artifact policies

release_attestation_artifact.render_staging_rollout.bundle_lineage_snapshot

Execution posture

Test: Repo Devnet And Staging Checks Linked. Canary: No Separate Canary Stage Recorded. Production: Staging Only Not Production.

Required canary rules

none

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Bundle output

artifacts/release-evidence/staging/<github.run_id>/{pre-deploy,post-deploy}

Rollback target

docs/render-deployment-contract.md and docs/deployment-runbook.md

Current blockers

Attestation policy now defines required lineage fields, but current per-run release-evidence bundles are still unsigned and local-snapshot based rather than externally attested provenance.; Formal staging attestation-artifact policy now exists, but no checked-in staging attestation artifact record exists yet.; Formal staging release-evidence-linkage policy now exists, but no checked-in staging linkage record exists yet.; Formal staging release-record-adoption policy now exists, but no checked-in staging adoption record exists yet.; Formal staging approval-authority policy now exists, but no checked-in staging authority record exists yet.; Formal staging promotion policy now exists, but no checked-in staging promotion record exists yet.; Formal staging rollback policy now exists, but no checked-in trusted staging rollback target record exists yet.; Formal staging smoke-verification policy now exists, but no checked-in staging smoke verification record exists yet.; This record only documents the guarded staging rollout path and must not be used as a production launch approval.

release_approval.render_production_launch.rollout_workflow_defined_launch_blocked

Production approval posture

Current state

Production Rollout Workflow Defined Launch Blocked

Approval mode

Manual Rollout Workflow With Explicit Human Approval. Scope: Guarded Production Rollout Defined But Not Approved.

Release and artifact identity

Release version source: Workflow Dispatch Ref Resolved To Checked Out Commit Sha. Artifact set source: Workflow Run Or Local Commit Scoped Release Artifact Set. Source revision source: Checked Out Commit Sha After Actions Checkout.

Provenance and signing

Digest source: Generated Release Evidence Bundle Sha256 Snapshots. Provenance: Pre And Post Deploy Bundles Defined Not Signed. Signing: Unsigned No Production Attestation.

Required tracking policies

release_tracking_policy.render_production_launch.bundle_identity

Required authority policies

release_approval_authority.render_production_launch.manual_rollout

Required promotion policies

release_promotion_policy.render_production_launch.explicit_stage_ladder

Required rollback policies

release_rollback_policy.render_production_launch.documented_ref

Required smoke policies

release_smoke_verification.render_production_launch.web_edge

Required attestation policies

attestation_policy.release_bundle_minimum_lineage; attestation_policy.render_production_launch_signed_or_attested_release

Required attestation-artifact policies

release_attestation_artifact.render_production_launch.bundle_lineage_snapshot; release_attestation_artifact.render_production_launch.signed_or_attested_release

Execution posture

Test: Repo Devnet Production Contract Smoke And Private Dashboard Environment Key Path Linked. Canary: Canary Rules Defined No Live Canary Smoke Or Dashboard Environment Key Record. Production: Rollout Workflow Defined Launch Blocked.

Required canary rules

canary_rule.render_production_allowlisted_web_edge_rollout

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Bundle output

artifacts/release-evidence/production/<github.run_id>/{pre-deploy,post-deploy}

Rollback target

docs/render-deployment-contract.md and docs/deployment-runbook.md

Current blockers

Guarded production-candidate and production rollout workflows now exist, but no live production canary or smoke record exists yet.; The private dashboard environment-key proof is now a production launch-window requirement: production web must route devnet and mainnet-beta requests through the one production API, one signed-in account and one project must create separate cluster-bound keys, and no devnet key may be mutated into a mainnet-beta key before live approval.; Formal production attestation, release-attestation-artifact, release-tracking, release-evidence-linkage, release-record-adoption, release-approval-authority, release-smoke-verification, release-rollback, and release-promotion policies now exist, and first checked-in local or synthetic proof records now exist across the production attestation, tracking, linkage, adoption, authority, promotion, smoke-verification, and rollback families, but no signed provenance, live workflow-backed production release evidence, or nonzero production approval record exists yet.; No production compatibility certification evidence exists yet.

Canary rules

canary_rule.render_production_allowlisted_web_edge_rollout

Production canary boundary

Ring

Bounded Operator Initiated Canary

Traffic boundary

Allowlisted Review And Operator Checks Only

Rollout strategy

Manual Ref Pinned Render Hook Rollout With Post Deploy Web Smoke

Surfaces

Web Review Page; Web Operator Page; Web Dashboard Projects Page

Required evidence

evidence.production.cloud_preflight; evidence.production.render_candidate_workflow; evidence.production.dashboard_environment_key_flow_private; evidence.production.web_edge_smoke_path; evidence.production.render_rollout_workflow

Verification notes

Use the public web edge for a narrow review and operator verification ring after deploy rather than widening traffic by default.; Privately prove the dashboard environment-key path through the production web service after the one production API multi-cluster routing is configured and verified.; Treat this as a manual operator-initiated canary rule for the current production rollout path, not as proof of general production approval.

Prohibited claims

No signed provenance, formal production approval, or universal production support claim is allowed from this rule alone.; No broader compatibility or partner-support claim may be inferred from a bounded canary rule.

Attestation policies

attestation_policy.release_bundle_minimum_lineage

All Release Targets attestation policy

Stages

Staging; Production

Fulfillment

Policy Defined Release Bundles Still Unsigned

Required identity claims

Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot

Required promotion stages

Build Complete; Artifact Verified

Verification requirement

Release Bundle Digests And Selected Ref Context Must Be Recorded And Checkable Before Rollout

Rollback requirement

Rollback Targets Must Stay Versioned And Documented Until Signed Or Attested Artifacts Exist

Required before production approval

no

Attestation evidence recorded

no

Current blockers

Required lineage fields are now explicit, but no release bundle is currently signed or externally attested.

attestation_policy.render_production_launch_signed_or_attested_release

Single Release Target attestation policy

Stages

Production

Fulfillment

Policy Defined Zero Signed Or Attested Production Records

Required identity claims

Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot

Required promotion stages

Build Complete; Artifact Verified; Artifact Signed Or Attested; Candidate Tested; Canary Approved; Production Approved; Production Deployed; Post Deploy Verified

Verification requirement

Production Artifacts Must Be Signed Or Cryptographically Verifiable And Match The Intended Release Artifact

Rollback requirement

Rollback Targets Must Be Known Good Versioned Signed Or Attested Artifacts

Required before production approval

yes

Attestation evidence recorded

no

Current blockers

No signed provenance or external attestation artifact is currently recorded for production.; Production approval must remain zero until operators can verify the deployed artifact against the intended signed or attested release.

Release attestation artifact policies

release_attestation_artifact.render_staging_rollout.bundle_lineage_snapshot

Staging attestation artifact policy

Current artifact status

Artifact Policy Defined No Checked In Staging Attestation Records

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required identity claims

Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot

Verification required

no

Required before production approval

no

release_attestation_artifact.render_production_launch.bundle_lineage_snapshot

Production attestation artifact policy

Current artifact status

Artifact Policy Defined Checked In Local Or Synthetic Production Lineage Attestation Records Present

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required identity claims

Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot

Verification required

no

Required before production approval

no

release_attestation_artifact.render_production_launch.signed_or_attested_release

Production attestation artifact policy

Current artifact status

Artifact Policy Defined Zero Checked In Signed Or Attested Production Records

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required identity claims

Source Revision; Build Workflow; Builder Identity; Artifact Digest; Dependency Snapshot

Verification required

yes

Required before production approval

yes

Checked-in attestation artifact records

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_attestation_artifact.render_production_launch.bundle_lineage_snapshot

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Kind: Release Bundle Snapshot Only. Status: Local Bundle Lineage Snapshot Recorded For Post Deploy Smoke Verified. Verification: Local Lineage Only Not Cryptographically Verified. Reference: release_bundle:production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified.

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_attestation_artifact.render_production_launch.signed_or_attested_release

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Kind: Missing Required Attestation Material. Status: Required Attestation Artifact Missing For Post Deploy Smoke Verified. Verification: Cryptographic Verification Required Not Recorded. Reference: release_bundle:production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified.

Release tracking policies

release_tracking_policy.render_staging_rollout.bundle_identity

Staging release tracking

Artifact name

render_staging_rollout_release_evidence_bundle

Artifact type

Release Evidence Bundle

Current tracking status

Tracking Policy Defined No Checked In Release Records

Required identity fields

Artifact Name; Artifact Type; Artifact Version; Source Revision; Release Evidence Origin Class; Build Pipeline Identifier; Build Timestamp; Artifact Digest; Release Channel; Signing Status; Provenance Status; Dependency Snapshot Reference

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Artifact set strategy

Stage Gate Release Ref Workflow Run Identity Without Phase

Release identity rule

One Release Version Maps To One Artifact Set Within Gate And Release Channel

Hotfix rule

Distinct Release Version Required With Documented Bypass Notes If Any

Notes

Current checked-in automation can generate phase-specific staging release-evidence bundles keyed to a stable artifact-set identity, but no checked-in staging release record ledger exists yet.

release_tracking_policy.render_production_launch.bundle_identity

Production release tracking

Artifact name

render_production_launch_release_evidence_bundle

Artifact type

Release Evidence Bundle

Current tracking status

Tracking Policy Defined Checked In Local Or Synthetic Production Release Records Present

Required identity fields

Artifact Name; Artifact Type; Artifact Version; Source Revision; Release Evidence Origin Class; Build Pipeline Identifier; Build Timestamp; Artifact Digest; Release Channel; Signing Status; Provenance Status; Dependency Snapshot Reference

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Artifact set strategy

Stage Gate Release Ref Workflow Run Identity Without Phase

Release identity rule

One Release Version Maps To One Artifact Set Within Gate And Release Channel

Hotfix rule

Distinct Release Version Required With Documented Bypass Notes If Any

Notes

Current checked-in automation can generate phase-specific production candidate or rollout bundles keyed to a stable artifact-set identity, and one checked-in local or synthetic proof production release record now exists, but no live workflow-backed production release record or signed artifact record exists yet.

Checked-in tracked release records

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Bundle Generated For Post Deploy Smoke Verified. Recorded phases: Post Deploy Smoke Verified.

Release evidence linkage policies

release_evidence_linkage.render_staging_rollout.bundle_phase_consistency

Staging release evidence linkage

Current linkage status

Linkage Policy Defined No Checked In Staging Linkage Records

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required shared identity fields

Approval Record Id; Gate Id; Artifact Version; Artifact Set Id; Source Revision; Release Evidence Origin Class; Deployment Stage; Release Channel

Shared identity strategy

Approval Record Gate Artifact Version Artifact Set Source Revision Origin Class Stage And Channel Must Match Across Linked Record Families

Approval-ready bundle phase

not applicable

Linked record families

Pre Deploy Candidate: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Rollback Target Record | Post Deploy Smoke Verified: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record

Notes

Current staging bundle generation can emit phase-specific linkage records tying tracking, attestation, approval-authority, promotion, rollback, and smoke record families to one artifact set, but no checked-in staging linkage record ledger exists yet.

release_evidence_linkage.render_production_launch.bundle_phase_consistency

Production release evidence linkage

Current linkage status

Linkage Policy Defined Checked In Local Or Synthetic Production Linkage Records Present

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required shared identity fields

Approval Record Id; Gate Id; Artifact Version; Artifact Set Id; Source Revision; Release Evidence Origin Class; Deployment Stage; Release Channel

Shared identity strategy

Approval Record Gate Artifact Version Artifact Set Source Revision Origin Class Stage And Channel Must Match Across Linked Record Families

Approval-ready bundle phase

Post Deploy Smoke Verified

Linked record families

Pre Deploy Candidate: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Rollback Target Record | Post Deploy Smoke Verified: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record

Notes

Current production candidate and rollout bundle generation can emit phase-specific linkage records tying tracking, attestation, approval-authority, promotion, rollback, and smoke record families to one artifact set, and one checked-in local or synthetic proof production linkage record now exists, but no live workflow-backed production linkage record exists yet.

Checked-in release evidence linkage records

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_evidence_linkage.render_production_launch.bundle_phase_consistency

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Phase: Post Deploy Smoke Verified. Families present: Release Tracking Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record. Consistency: Linked Record Families Share Artifact Identity For Post Deploy Smoke Verified.

Release record adoption policies

release_record_adoption.render_staging_rollout.generated_bundle_import

Staging release record adoption

Current adoption status

Adoption Policy Defined No Checked In Staging Adoption Records

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required adoption evidence

Source Bundle Artifact Reference; Review Contract Artifact Reference; Generated Record Artifact References; Release Evidence Origin Class; Adoption Review Reference; Adopter Identity; Adopted Record Ids; Source Bundle Policy Version Dependencies; Current Policy Version Dependencies; Policy Version Dependency Status

Adopted record families

Pre Deploy Candidate: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Rollback Target Record | Post Deploy Smoke Verified: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record

Source artifact SHA strategy

Source Bundle And Generated Record Artifact Sha256 Must Match Before Checked In Adoption

Policy snapshot match strategy

Source Bundle Release Assurance Policy Version Dependencies Must Match Current Registry Snapshot Sha256 Before Checked In Adoption

Adoption review strategy

Human Review Reference Named Adopter And Review Contract Artifact Reference Required Before Generated Records Are Treated As Checked In Release Truth

Importer script

scripts/import-release-record-adoption.mjs

Reviewed apply script

scripts/apply-release-record-adoption.mjs

Approval-ready bundle phase

not applicable

Notes

Current staging bundle generation can emit machine-readable adoption candidates with exact bundle, record-artifact sha256, and live-versus-proof origin references, and canonical importer plus reviewed-apply paths now enforce current policy snapshot matching plus reviewed-contract artifact traceability before checked-in adoption, but no checked-in staging adoption ledger exists yet.

release_record_adoption.render_production_launch.generated_bundle_import

Production release record adoption

Current adoption status

Adoption Policy Defined Checked In Local Or Synthetic Production Adoption Records Present

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required adoption evidence

Source Bundle Artifact Reference; Review Contract Artifact Reference; Generated Record Artifact References; Release Evidence Origin Class; Adoption Review Reference; Adopter Identity; Adopted Record Ids; Source Bundle Policy Version Dependencies; Current Policy Version Dependencies; Policy Version Dependency Status

Adopted record families

Pre Deploy Candidate: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Rollback Target Record | Post Deploy Smoke Verified: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record

Source artifact SHA strategy

Source Bundle And Generated Record Artifact Sha256 Must Match Before Checked In Adoption

Policy snapshot match strategy

Source Bundle Release Assurance Policy Version Dependencies Must Match Current Registry Snapshot Sha256 Before Checked In Adoption

Adoption review strategy

Human Review Reference Named Adopter And Review Contract Artifact Reference Required Before Generated Records Are Treated As Checked In Release Truth

Importer script

scripts/import-release-record-adoption.mjs

Reviewed apply script

scripts/apply-release-record-adoption.mjs

Approval-ready bundle phase

Post Deploy Smoke Verified

Notes

Current production candidate and rollout bundle generation can emit machine-readable adoption candidates with exact bundle, record-artifact sha256, and live-versus-proof origin references, and canonical importer plus reviewed-apply paths now enforce current policy snapshot matching plus reviewed-contract artifact traceability before checked-in adoption. One checked-in local or synthetic proof production adoption record now exists, but no live workflow-backed production adoption record exists yet.

Checked-in release record adoption records

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_record_adoption.render_production_launch.generated_bundle_import

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Phase: Post Deploy Smoke Verified. Adopted families: Release Tracking Record; Release Evidence Linkage Record; Release Attestation Record; Release Approval Authority Record; Release Promotion Record; Release Smoke Verification Record; Release Rollback Target Record. Adopter: codex_user_directed. Review reference: terminal-review.user-directed-next-step.2026-04-10. Review contract: artifacts/release-evidence/synthetic/post-deploy/release-record-adoption.review.json#sha256=16c525ca0e33e66270ac55731b73687dda8e3fc9f205f9add3af852acf1dd35c. Status: Human Reviewed Generated Bundle Candidate Checked In For Post Deploy Smoke Verified.

Release approval authority policies

release_approval_authority.render_staging_rollout.manual_dispatch

Staging approval authority

Current authority status

Authority Policy Defined No Checked In Staging Authority Records

Human approval required

yes

Approver identity required before production approval

no

Approved automation reference allowed

yes

Allowed authority kinds

Workflow Dispatch Actor And Workflow Reference; Approved Workflow Reference Only; Local Manual Reference Only

Required authority evidence

Approval Mode; Approval Scope; Approval Reference; Authority Kind; Approver Identity Or Automation Reference

Authority reference strategy

Github Actor If Present Else Workflow Name And Run Id Else Local Trigger Source

Promotion policy linkage

release_promotion_policy.render_staging_rollout.explicit_stage_ladder

Notes

Current automation can snapshot staging workflow reference and optional actor identity into release bundles, but no checked-in staging approval-authority record ledger exists yet.

release_approval_authority.render_production_launch.manual_rollout

Production approval authority

Current authority status

Authority Policy Defined Checked In Local Or Synthetic Production Authority Records Present

Human approval required

yes

Approver identity required before production approval

yes

Approved automation reference allowed

yes

Allowed authority kinds

Workflow Dispatch Actor And Workflow Reference; Approved Workflow Reference Only; Local Manual Reference Only

Required authority evidence

Approval Mode; Approval Scope; Approval Reference; Authority Kind; Approver Identity Or Automation Reference

Authority reference strategy

Github Actor If Present Else Workflow Name And Run Id Else Local Trigger Source

Promotion policy linkage

release_promotion_policy.render_production_launch.explicit_stage_ladder

Notes

Current automation can snapshot production workflow reference and optional actor identity into release bundles, and one checked-in local or synthetic proof production approval-authority record now exists, but no live workflow-backed production authority record or production approval exists yet.

Checked-in approval authority records

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_approval_authority.render_production_launch.manual_rollout

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Local Manual Authority Reference Captured For Post Deploy Smoke Verified. Authority reference: trigger_source:local_manual. Approval reference: trigger_source:local_manual.

Release promotion policies

release_promotion_policy.render_staging_rollout.explicit_stage_ladder

Staging promotion policy

Current promotion status

Promotion Policy Defined No Checked In Staging Promotion Records

Required promotion stages

Build Complete; Artifact Verified; Candidate Tested; Post Deploy Verified

Manual promotion stages

Artifact Signed Or Attested; Canary Approved; Production Approved; Production Deployed

Approval reference strategy

Workflow Name And Run Id Or Local Manual Trigger Source

Compatibility matrix strategy

Generated Compatibility Matrix Snapshot Reference

Policy dependency strategy

Registry Snapshot Sha256 References For Attestation Tracking Smoke Rollback And Promotion Policies

Attestation policies

attestation_policy.release_bundle_minimum_lineage

Notes

Current checked-in automation can snapshot explicit staging promotion-stage state into release bundles, but no checked-in staging promotion record ledger exists yet.

release_promotion_policy.render_production_launch.explicit_stage_ladder

Production promotion policy

Current promotion status

Promotion Policy Defined Checked In Local Or Synthetic Production Promotion Records Present

Required promotion stages

Build Complete; Artifact Verified; Artifact Signed Or Attested; Candidate Tested; Canary Approved; Production Approved; Production Deployed; Post Deploy Verified

Manual promotion stages

Artifact Signed Or Attested; Canary Approved; Production Approved

Approval reference strategy

Workflow Name And Run Id Or Local Manual Trigger Source

Compatibility matrix strategy

Generated Compatibility Matrix Snapshot Reference

Policy dependency strategy

Registry Snapshot Sha256 References For Attestation Tracking Smoke Rollback And Promotion Policies

Attestation policies

attestation_policy.release_bundle_minimum_lineage; attestation_policy.render_production_launch_signed_or_attested_release

Notes

Current checked-in automation can snapshot explicit production promotion-stage state into candidate or rollout bundles, and one checked-in local or synthetic proof production promotion record now exists, but no live workflow-backed production promotion record exists yet.

Checked-in promotion records

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_promotion_policy.render_production_launch.explicit_stage_ladder

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Promotion Snapshot Generated For Post Deploy Smoke Verified. Completed stages: Build Complete; Artifact Verified; Candidate Tested; Production Deployed; Post Deploy Verified.

Release rollback policies

release_rollback_policy.render_staging_rollout.documented_ref

Staging rollback policy

Rollback target kind

Documented Release Ref And Runbook Reference

Current rollback status

Rollback Policy Defined No Checked In Trusted Staging Rollback Targets

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required rollback fields

Artifact Version; Artifact Set Id; Rollback Target Reference; Source Revision; Rollback Preparation Reference; Rollback Verification Status; Trusted Artifact Status; Rollback Operator Confirmation; Dependency Snapshot Reference

Reference strategy

Selected Release Ref Plus Checked In Staging Runbook Paths

Verification strategy

Manual Workflow Dispatch And Operator Confirmation Before Use

Trusted artifact requirement

Known Good Versioned Documented Ref Until Signed Or Attested Artifacts Exist

Rollback references

docs/render-deployment-contract.md; docs/deployment-runbook.md

Notes

Current checked-in automation can snapshot rollback references into staging release-evidence bundles, but no checked-in trusted staging rollback target records exist yet.

release_rollback_policy.render_production_launch.documented_ref

Production rollback policy

Rollback target kind

Documented Release Ref And Runbook Reference

Current rollback status

Rollback Policy Defined Checked In Local Or Synthetic Production Rollback Targets Present

Required bundle phases

Pre Deploy Candidate; Post Deploy Smoke Verified

Required rollback fields

Artifact Version; Artifact Set Id; Rollback Target Reference; Source Revision; Rollback Preparation Reference; Rollback Verification Status; Trusted Artifact Status; Rollback Operator Confirmation; Dependency Snapshot Reference

Reference strategy

Selected Release Ref Plus Checked In Production Runbook Paths

Verification strategy

Manual Workflow Dispatch And Operator Confirmation Before Use

Trusted artifact requirement

Known Good Versioned Signed Or Attested Artifact Before Production Approval

Rollback references

docs/render-deployment-contract.md; docs/deployment-runbook.md

Notes

Current checked-in automation can snapshot rollback references into production candidate or rollout release-evidence bundles, and one checked-in local or synthetic proof production rollback-target record now exists, but no live workflow-backed trusted production rollback target record or signed rollback artifact exists yet.

Checked-in trusted rollback target records

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_rollback_policy.render_production_launch.documented_ref

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Rollback Reference Documented After Post Deploy Verification. Trusted artifact: Documented Ref Only Not Signed Or Attested. Reference: docs/render-deployment-contract.md and docs/deployment-runbook.md; selected_release_ref=synthetic-proof-2026-04-10.

Release smoke verification policies

release_smoke_verification.render_staging_rollout.web_edge

Staging smoke verification

Smoke evidence

evidence.staging.web_edge_smoke

Verification kind

Web Edge Post Deploy Smoke

Current verification status

Policy Defined No Checked In Staging Smoke Records

Required bundle phases

Post Deploy Smoke Verified

Required smoke checks

Web Public Openapi Asset Available; Web Public Llms Asset Available; Web Public Llms Full Asset Available; Web Public Robots Asset Available; Web Public Sitemap Asset Available; Web Review Page Available; Web Proxy Health Ok; Web Public Config Available; Web Operator Session Unlocks; Web Operator Metrics Proxy Available

Operator session required

yes

Notes

Current checked-in automation can run staging web-edge smoke and emit a per-run smoke summary artifact, but no checked-in staging smoke verification records exist yet.

release_smoke_verification.render_production_launch.web_edge

Production smoke verification

Smoke evidence

evidence.production.web_edge_smoke_path

Verification kind

Web Edge Post Deploy Smoke

Current verification status

Policy Defined Checked In Local Or Synthetic Production Smoke Records Present

Required bundle phases

Post Deploy Smoke Verified

Required smoke checks

Web Public Openapi Asset Available; Web Public Llms Asset Available; Web Public Llms Full Asset Available; Web Public Robots Asset Available; Web Public Sitemap Asset Available; Web Review Page Available; Web Proxy Health Ok; Web Public Config Available; Web Operator Session Unlocks; Web Operator Metrics Proxy Available

Operator session required

yes

Notes

Current checked-in automation can run production web-edge smoke and emit a per-run smoke summary artifact, and one checked-in local or synthetic proof production smoke verification record now exists, but no live workflow-backed production smoke verification record exists yet.

Checked-in smoke verification records

production__render_production_launch__synthetic-proof-2026-04-10__20260410-post__post_deploy_smoke_verified__release_smoke_verification.render_production_launch.web_edge

Artifact version: synthetic-proof-2026-04-10. Artifact set: production__render_production_launch__synthetic-proof-2026-04-10__20260410-post. Channel: production. Evidence origin: Local Or Synthetic Proof Bundle. Status: Post Deploy Smoke Verified. Web base URL: https://staging.example.invalid. Verified checks: Web Public Openapi Asset Available; Web Public Llms Asset Available; Web Public Llms Full Asset Available; Web Public Robots Asset Available; Web Public Sitemap Asset Available; Web Review Page Available; Web Proxy Health Ok; Web Public Config Available; Web Operator Session Unlocks; Web Operator Metrics Proxy Available.

Current release-evidence records

evidence.repo.ci_monorepo_validation

Monorepo CI validation

Kind

Github Actions Workflow

Status

Implemented Initial

Stages

repo; staging; production

Provenance status

Preproduction Workflow Only

Production grade

no

Notes

This proves repo integrity and generated-doc freshness for a checked-out commit. It is not a production release bundle.

evidence.repo.provenance_baseline_generation

Generated provenance baseline for build and rollout inputs

Kind

Generated Provenance Baseline

Status

Implemented Initial

Stages

repo; staging; production

Provenance status

Local Hash Baseline Only

Production grade

no

Notes

This captures exact hashes of the checked-in build and rollout inputs. It improves traceability, but it is not a signed or externally attested provenance bundle.

evidence.local.production_like_rehearsal

Local production-like Docker rehearsal

Kind

Local Rehearsal

Status

Implemented Initial

Stages

local

Provenance status

Not A Release Bundle

Production grade

no

Notes

This is the strongest localhost rehearsal path and should stay local-first, but it does not certify staging or production support.

evidence.devnet.live_verification

Live devnet verification workflow

Kind

Github Actions Workflow

Status

Implemented Initial

Stages

devnet; staging; production

Provenance status

Preproduction Workflow Only

Production grade

no

Notes

This captures live rehearsal of the supported transfer ladder and current swap-review boundaries on Solana devnet.

evidence.staging.cloud_preflight

Cloud env-contract preflight for staging

Kind

Preflight Script

Status

Implemented Initial

Stages

staging

Provenance status

Pre Deploy Contract Check Only

Production grade

no

Notes

This validates the checked-in staging env contract before any Render deploy hooks are triggered.

evidence.staging.web_edge_smoke

Public web-edge staging smoke verification

Kind

Post Deploy Smoke

Status

Implemented Initial

Stages

staging

Provenance status

Post Deploy Smoke Only

Production grade

no

Notes

This verifies the intended private-API web-edge topology after a staging deploy and now unlocks the deliberate staging site-access gate before checking the bounded public-looking surfaces.

evidence.staging.extension_popup_runtime_acceptance

Extension popup runtime acceptance export

Kind

Browser Runtime Acceptance Export

Status

Implemented Initial

Stages

local; staging

Provenance status

Manual Browser Runtime Export Only

Production grade

no

Notes

This captures trusted browser-side runtime evidence for the preview extension popup-review surface from the install runtime lab. It improves local and staging acceptance truth, but it is not a production-grade workflow or broad browser-device certification.

evidence.staging.render_rollout_workflow

Render staging rollout workflow

Kind

Github Actions Workflow

Status

Implemented Initial

Stages

staging

Provenance status

Staging Rollout Only

Production grade

no

Notes

This is a guarded staging rollout path. It is not a production launch workflow and must not be described as production release evidence.

evidence.production.cloud_preflight

Cloud env-contract preflight for production

Kind

Preflight Script

Status

Implemented Initial

Stages

production

Provenance status

Pre Deploy Contract Check Only

Production grade

no

Notes

This validates the checked-in production env contract before any future production deploy path is considered. It does not prove a live production rollout.

evidence.production.render_candidate_workflow

Render production-candidate verification workflow

Kind

Github Actions Workflow

Status

Implemented Initial

Stages

production

Provenance status

Production Candidate Bundle Only

Production grade

no

Notes

This is a guarded production-candidate verification path. It validates the checked-in production contract and generates a release-evidence bundle, but it does not trigger production deploy hooks, prove live smoke, or grant production launch approval.

evidence.production.dashboard_environment_key_flow_private

Private production dashboard environment-key proof

Kind

Private Dashboard Acceptance Proof

Status

Defined Launch Window Manual Proof Pending

Stages

production

Provenance status

Production Manual Private Acceptance Defined Not Executed

Production grade

no

Notes

This proof is intentionally launch-window only because it exercises the one production API multi-cluster dashboard architecture. It must verify one-login project-level key management, separate devnet and mainnet-beta API-key scope, and no cross-cluster key mutation. It must not be treated as satisfied by docs alone or by a direct staging-web test.

evidence.platform.signer_boundary_workflow

Signer-boundary verification workflow

Kind

Github Actions Workflow

Status

Implemented Initial

Stages

staging; production

Provenance status

Live Runtime Boundary Proof Only

Production grade

no

Notes

This workflow captures workflow-backed signer-boundary evidence for the selected environment by proving live signer `/health` and authenticated `/v1/solana/keys` consistency against the expected key reference and signer address. It does not deploy the signer, prove web-edge rollout health, or grant production launch approval.

evidence.production.web_edge_smoke_path

Production web-edge smoke verification path

Kind

Post Deploy Smoke Path

Status

Implemented Initial

Stages

production

Provenance status

Production Smoke Path Defined Not Executed

Production grade

no

Notes

This defines the intended production web-edge smoke contract for a guarded rollout workflow, but it is not itself a recorded live production smoke result or launch approval.

evidence.production.render_rollout_workflow

Render production rollout workflow

Kind

Github Actions Workflow

Status

Implemented Initial

Stages

production

Provenance status

Production Rollout Workflow Defined Not Approved

Production grade

no

Notes

This is a guarded production rollout path with pre-deploy bundle generation, deploy-hook triggering, and post-deploy web-edge smoke steps. It does not by itself grant production approval, live canary approval, or signed provenance.

Release-target gates

gate.release_target.render_staging_rollout (staging)

Readiness: Staging Rollout Gated Not Production. Deployment allowed: yes. Production ready: no. Approval: Staging Bundle Backed Manual Rollout Only. Blockers: none.

gate.release_target.render_production_launch (production)

Readiness: Production Rollout Workflow Defined Launch Blocked. Deployment allowed: no. Production ready: no. Approval: Production Rollout Workflow Defined Launch Blocked. Blockers: Guarded production-candidate and production rollout workflows now exist, but no live production canary or smoke evidence exists yet.; Private dashboard environment-key proof is launch-window work: it must be run through the production web service against the one production API multi-cluster architecture, and it must prove one signed-in account and one project can hold separate devnet and mainnet-beta keys without cross-cluster key mutation.; A formal production approval record, canary rule, attestation policy, release-attestation-artifact policy, release-tracking policy, release-evidence-linkage policy, release-record-adoption policy, release-approval-authority policy, release-promotion policy, release-smoke-verification policy, and release-rollback policy now exist, and first checked-in local or synthetic proof records now exist across the production attestation, tracking, linkage, adoption, authority, promotion, smoke-verification, and rollback families, but no signed provenance, live workflow-backed production release evidence, or nonzero production approval record exists yet.; No production compatibility certification evidence exists yet.; Before live public production, a full repo security review must cover every checked-in line of code and unresolved trust-critical findings must block launch..

Provenance baseline scope

supply_chain.root_npm_workspace_lockfile

Scope: Repo Build. Control state: Lockfile Pinned Known Audit Advisories Reviewed Not Attested. Criticality: Critical. Workspace dependency resolution is anchored by package-lock.json. npm audit still reports transitive moderate/high advisories through the Solana client stack, Next's nested PostCSS dependency, and rpc-websockets/uuid without a non-breaking npm audit fix path. Those advisories are now recorded in registries/supply-chain/npm-audit-advisory-exceptions.registry.json and checked by npm run check:npm-audit-posture; any unknown, expired, or critical advisory remains a launch blocker. This is still not a signed production provenance bundle.

supply_chain.github_actions_workflows

Scope: Repo Validation And Release. Control state: Workflow Defined Not Attested. Criticality: Critical. These workflows currently define CI, devnet verification, staging rollout, signer-boundary verification, production-candidate verification, and a guarded production rollout path. They are versioned and reviewable, but not yet backed by signed release provenance.

supply_chain.node20_alpine_container_bases

Scope: Container Build. Control state: Tag Pinned Not Digest Pinned. Criticality: Critical. Current build and runtime images use node:20-alpine by tag. That is consistent and local-first, but production provenance should pin digests.

supply_chain.local_compose_infra_images

Scope: Local Rehearsal. Control state: Tag Pinned Local Rehearsal Only. Criticality: High. Local rehearsal currently depends on postgres:16-alpine and redis:7-alpine images. This is acceptable for localhost rehearsal, not production provenance.

supply_chain.render_blueprint_and_env_contract

Scope: Staging And Production Rollout. Control state: Versioned Contract Preflight Checked. Criticality: Critical. This is the real checked-in cloud contract, including the separate signer env contract. It is gated before staging rollout, signer-boundary verification, the production-candidate workflow, and the guarded production rollout workflow, but it is not yet a signed production release-evidence bundle.

supply_chain.release_gate_and_provenance_scripts

Scope: Staging And Production Rollout. Control state: Repo Local Controls Only. Criticality: Critical. These scripts keep registry truth, generated support truth, provenance baseline generation, release bundle generation, canary rule checks, attestation-policy checks, release-tracking checks, release-promotion checks, release-smoke-verification checks, release-rollback checks, and rollout or approval gate checks executable in local and CI flows.

Read next

Trust

Return to the public-safe trust overview that links to this bounded release-assurance layer.

Open

Read next

Compatibility

See how compatibility certification remains blocked alongside production release readiness.

Open

Read next

Status

Read the bounded public status page without confusing runtime posture with release assurance.

Open

Read next

Support

Use the current support and disclosure path if you need to report release or trust-surface issues.

Open

Read next

Developers

Inspect the current API, SDK, and rollout docs that these assurance records still bound.

Open
Artax