Operator manual · deployment gate
Production Checklist
Use this as a deployment gate, not as proof of regulatory compliance. A deployment can pass ENTITY protocol checks while still requiring domain-specific legal, privacy, security and operational review.
Release
- Using supported canonical
v3.4.2. - Commit/tag/release evidence recorded.
- No local edits presented as the immutable release.
- v3.4.1 explicitly treated as historical/superseded.
Identity & authority
- Production Entity IDs created in intended custody environment.
- Signing/recovery keys protected and tested.
- Application/device authority is explicit, scoped and revocable.
- No provider/service account is treated as sovereign authority by default.
Data & evidence
- Sources/licences/provenance documented.
- Ingestion hashes and evidence IDs retained.
- Rights holders/controllers are explicit rather than inferred.
- External claims are separated from cryptographic validity.
Recovery
- Encrypted backup/export created.
- Destructive recovery tested.
- Pre/post roots compared.
- Recovered signing verified.
BTDU
- ADAM root/configuration identified.
- BTDU mutation authorization verified.
- Exact reconstruction sample passed.
- Repository/data manifests retained.
- Topology is not used to infer ownership/economic entitlement.
External qualification
If your deployment requires the still-open post-release promotion gates—real-world training, compiled Rust qualification, hardware custody, physical multi-host, certified device, 30-day operation, independent audit or independent assessor—do not mark them complete until the corresponding external evidence exists.