End-to-end workflows
How work moves through Platform and Apps from start to finish, who does each step and what the system does in response.
On this page (8)
Release from draft to active
Who: Operator O, release manager M, approver A (three test users)
| # | What the person does | What the system does |
|---|---|---|
| 1 | O: Releases > New, title, environment STAGING, rollback plan; Packages tab tick 2 certified packages; Evidence: Take and attach an SBOM | REL-000n Draft; Gates 'Before submit' list |
| 2 | O: Submit | Reviewed; artifact hash and provenance written |
| 3 | O: Rehearse the upgrade on a restored copy; Job runs > Run the scheduler now | Rehearsal drill Passed, reached the release's migration head |
| 4 | M: Stage | Staged; rehearsal linked |
| 5 | O (as approver too) tries Approve | Refused 'Somebody other than the person who prepared this release must approve it.' |
| 6 | A: Approve with QA disposition and rollback acceptance | Approved; manifest signed (valid) |
| 7 | O: deploy on the server (push, migrate, restart), then Activate inside the window with a verified backup inside the RPO | Active; environment shows it; event written; Release readiness 'traced' Yes |
Release sent back and fixed
Who: Operator O, approver A
| # | What the person does | What the system does |
|---|---|---|
| 1 | A: Send back a Staged release with reason 'Wrong package version' | Draft; approvals cleared; reason shown |
| 2 | O: Edit packages; Save packages; Submit again | Reviewed with new artifact hash |
| 3 | O: Rehearse again; M Stage; A Approve | Approved and signed again |
| 4 | Audit trail filtered to the release | release.reject, release.submit, release.stage, release.approve in order with correlation ids |
Bad release, recovery
Who: Operator O, configuration owner C
| # | What the person does | What the system does |
|---|---|---|
| 1 | REL-0002 Active; find a defect | Active |
| 2 | Run a restore drill on the newest backup; Run the scheduler now | Drill Passed |
| 3 | O: Recover REL-0002: Restored from backup with the drill id, reason | Recovered; drill linked; no down-migration |
| 4 | C: Retire REL-0002 with reason | Retired; environment has no active release until the next activation |
Feature flag two-person change
Who: Configuration owner C, approver A
| # | What the person does | What the system does |
|---|---|---|
| 1 | C: New flag sales.quick_quote, Yes / no, workspace; Save | Draft, In force false |
| 2 | C: Propose a value true | Proposed; Overview 'Flags waiting for approval' +1 |
| 3 | C (also holding approver) tries Approve | Refused 'Somebody other than the person who prepared this flag value must approve it.' |
| 4 | A: Approve | Active, value true, Version 1, approved by A |
| 5 | C: Propose a change false; A: Approve the change | Value false; Version 2; old value in force until approval |
Package registration to certification
Who: Operator O, release manager M, approver A
| # | What the person does | What the system does |
|---|---|---|
| 1 | O: Packages > Sync from this build | New module versions registered as Draft |
| 2 | A: Licence review Approved on one package | Licence Approved |
| 3 | M: Review | Reviewed (or refused with the first open check) |
| 4 | M (as approver too) tries Certify | Refused: the reviewer cannot certify |
| 5 | A: Certify | Certified; offered in release package pickers; Capabilities shows it Certified |
Restore drill evidence
Who: Operator O, auditor U
| # | What the person does | What the system does |
|---|---|---|
| 1 | Administration > Settings > Storage and backup: take and verify a backup | Backup succeeded, fingerprinted |
| 2 | O: Restore drills > Run a restore drill (Newest stored backup) | DRL queued; a run of platform.restore_drill appears in Job runs |
| 3 | O: Job runs > Run the scheduler now | Run Succeeded; drill Passed |
| 4 | U (viewer / auditor): Reporting > Recovery evidence; open the drill | Rows, file digests and ledger totals match; RTO and RPO shown; U has no Run button that works |
| 5 | U: export the Recovery evidence list | Export holds the same rows as the screen |
Job failure to dead letter to alert
Who: Operator O
| # | What the person does | What the system does |
|---|---|---|
| 1 | Create a test job whose handler fails (or use platform.restore_drill Run now with no drill) | Run fails |
| 2 | Run the scheduler now until attempts are used | Dead letter; error shown |
| 3 | Alerts > Evaluate now | DEAD-JOBS alert open |
| 4 | Acknowledge the alert | Acknowledged |
| 5 | Fix and Retry the run; Evaluate now | Run succeeds or is cancelled; dead count 0; alert Resolved |
Extension registration and activation
Who: Operator O, release manager M, approver A
| # | What the person does | What the system does |
|---|---|---|
| 1 | O: New extension x_acme on partner.after_save with core 1, function and a field | Draft; Checks tab |
| 2 | M: Review | Reviewed |
| 3 | O (with approver role too) tries Activate | Refused: the registrar cannot activate |
| 4 | A: Activate | Active only when the function imports; else 'The function cannot be loaded: ...' |
| 5 | O: Disable | Disabled; Active extensions tile goes down |