End-to-end workflows

How work moves through Platform and Apps from start to finish, who does each step and what the system does in response.

On this page (8)

Release from draft to active

Who: Operator O, release manager M, approver A (three test users)

#What the person doesWhat the system does
1O: Releases > New, title, environment STAGING, rollback plan; Packages tab tick 2 certified packages; Evidence: Take and attach an SBOMREL-000n Draft; Gates 'Before submit' list
2O: SubmitReviewed; artifact hash and provenance written
3O: Rehearse the upgrade on a restored copy; Job runs > Run the scheduler nowRehearsal drill Passed, reached the release's migration head
4M: StageStaged; rehearsal linked
5O (as approver too) tries ApproveRefused 'Somebody other than the person who prepared this release must approve it.'
6A: Approve with QA disposition and rollback acceptanceApproved; manifest signed (valid)
7O: deploy on the server (push, migrate, restart), then Activate inside the window with a verified backup inside the RPOActive; environment shows it; event written; Release readiness 'traced' Yes

Release sent back and fixed

Who: Operator O, approver A

#What the person doesWhat the system does
1A: Send back a Staged release with reason 'Wrong package version'Draft; approvals cleared; reason shown
2O: Edit packages; Save packages; Submit againReviewed with new artifact hash
3O: Rehearse again; M Stage; A ApproveApproved and signed again
4Audit trail filtered to the releaserelease.reject, release.submit, release.stage, release.approve in order with correlation ids

Bad release, recovery

Who: Operator O, configuration owner C

#What the person doesWhat the system does
1REL-0002 Active; find a defectActive
2Run a restore drill on the newest backup; Run the scheduler nowDrill Passed
3O: Recover REL-0002: Restored from backup with the drill id, reasonRecovered; drill linked; no down-migration
4C: Retire REL-0002 with reasonRetired; environment has no active release until the next activation

Feature flag two-person change

Who: Configuration owner C, approver A

#What the person doesWhat the system does
1C: New flag sales.quick_quote, Yes / no, workspace; SaveDraft, In force false
2C: Propose a value trueProposed; Overview 'Flags waiting for approval' +1
3C (also holding approver) tries ApproveRefused 'Somebody other than the person who prepared this flag value must approve it.'
4A: ApproveActive, value true, Version 1, approved by A
5C: Propose a change false; A: Approve the changeValue false; Version 2; old value in force until approval

Package registration to certification

Who: Operator O, release manager M, approver A

#What the person doesWhat the system does
1O: Packages > Sync from this buildNew module versions registered as Draft
2A: Licence review Approved on one packageLicence Approved
3M: ReviewReviewed (or refused with the first open check)
4M (as approver too) tries CertifyRefused: the reviewer cannot certify
5A: CertifyCertified; offered in release package pickers; Capabilities shows it Certified

Restore drill evidence

Who: Operator O, auditor U

#What the person doesWhat the system does
1Administration > Settings > Storage and backup: take and verify a backupBackup succeeded, fingerprinted
2O: Restore drills > Run a restore drill (Newest stored backup)DRL queued; a run of platform.restore_drill appears in Job runs
3O: Job runs > Run the scheduler nowRun Succeeded; drill Passed
4U (viewer / auditor): Reporting > Recovery evidence; open the drillRows, file digests and ledger totals match; RTO and RPO shown; U has no Run button that works
5U: export the Recovery evidence listExport holds the same rows as the screen

Job failure to dead letter to alert

Who: Operator O

#What the person doesWhat the system does
1Create a test job whose handler fails (or use platform.restore_drill Run now with no drill)Run fails
2Run the scheduler now until attempts are usedDead letter; error shown
3Alerts > Evaluate nowDEAD-JOBS alert open
4Acknowledge the alertAcknowledged
5Fix and Retry the run; Evaluate nowRun succeeds or is cancelled; dead count 0; alert Resolved

Extension registration and activation

Who: Operator O, release manager M, approver A

#What the person doesWhat the system does
1O: New extension x_acme on partner.after_save with core 1, function and a fieldDraft; Checks tab
2M: ReviewReviewed
3O (with approver role too) tries ActivateRefused: the registrar cannot activate
4A: ActivateActive only when the function imports; else 'The function cannot be loaded: ...'
5O: DisableDisabled; Active extensions tile goes down