RELIABILITY KERNEL

Side effects stay observable and reversible.

This local cockpit shows receipts, retry and DLQ health, policy blocks, alert runbooks, trace events, and the no-production-side-effect boundary.

Health
healthy
Receipts
0
Queued
0
Retry
0
DLQ
0
Policy blocked
0
Local reliability store
.next/cache/wcn-agent-os/reliability-kernel.json
No production side effects
operator=false · alerts=false · metrics=false · partialGateCanClose=false · productionCompletionReady=false · productionReadyClaimAllowed=false
Bindings
6
Local ready
6
Production bound
0
External required
6
Evidence sections
8
Evidence ready
8
Operations ready
false
Bindings
6
Workflows
7
Console ready
true
Production console ready
false
Human Gate required
7
Cutover items
8
Evidence ready
8
Cutover ready
false
Operator workflows
7
External binding items
8
Evidence ready
8
External bindings ready
false
Human Gate required
8
Submission steps
8
Submission ready
true
Authority evidence
5
Human Gate submission
false
Handoff items
1
Closure handoff ready
true
Missing candidates
5
Unsatisfied criteria
8
Partial closable
0
productionCompletionReady
false
Ready receipts
2
Blocked readiness
4
Human Gate required
4
Outbox required
5

Production observability closure handoff package

This local takeover package fuses operator console workflows, cutover evidence, external binding evidence, Human Gate submission, and the production-observability closure matrix row so the gate stays explicit, blocked, and verifiable.

Closure handoff API
wcn-production-observability-closure-handoff-production-observability

Production observability and operator UI

wcn-module-completion-work-order-2-platform_reliability_kernel-production-observability

draft_not_submitted
Required candidates
5
Missing candidates
5
Closure criteria
8
Unsatisfied criteria
8
Closure draft status
draft_not_submitted
Partial closable
false
Closure matrix row
wcn-module-completion-closure-matrix-2-platform_reliability_kernel-production-observability
wcn-module-completion-execution-packet-2-platform-reliability-kernel-production-observability
/api/agent-os/production-readiness/closure-review/production-observability/human-gate-draft
Closure blockers
5 required evidence candidates are missing for production-observability.
8 closure criteria remain unsatisfied for production-observability.
closureEvidenceStored=false and acceptedForHumanGateClosureReview=false.
closureReviewStatus=awaiting_dry_run_accepted_closure_evidence_bundle; closureEvidenceAcceptedLocal=false.
closureHumanGateDecisionStatus=draft_not_submitted; decisionSubmitted=false.
Production execution records, post-execution verification, rollback readiness, and ready-claim approval are still external Human Gate dependencies.
External production observability evidence has not been submitted to Human Gate.
The local handoff package cannot close production-observability without real metrics, alert delivery, operator auth, smoke, rollback/replay, incident, audit export, and post-execution verification.
Next actions
Submit redacted candidate metadata for all 5 evidence requests in production-observability.
Dry-run a complete closure evidence bundle with POST /api/agent-os/production-readiness/closure-evidence.
Submit a closure review draft with POST /api/agent-os/production-readiness/closure-review/production-observability/human-gate-draft only after the closure evidence dry-run is accepted.
Record independent Human Gate review decisions without self-approval.
Attach real production execution records and post-execution verification outside local-only mode before any production-ready claim.
Submit all eight production observability external binding evidence groups through the Human Gate package.
Keep productionSideEffectExecuted=false and productionReadyClaimAllowed=false until an approved production authority packet exists.
Validation
npm run check:agent-os-implementation
npm run check:agent-os-reliability
npm run check:agent-os-completion-roadmap
curl -s http://localhost:3000/api/agent-os/modules/completion-roadmap
curl -s http://localhost:3000/api/agent-os/modules/completion-work-orders
curl -s http://localhost:3000/api/agent-os/reliability-kernel/production-observability
curl -s http://localhost:3000/api/agent-os/reliability-kernel/production-operator-console
curl -s http://localhost:3000/api/agent-os/reliability-kernel/production-observability-external-binding-evidence
curl -s http://localhost:3000/api/agent-os/reliability-kernel/production-observability-human-gate-submission
curl -s http://localhost:3000/api/agent-os/modules/completion-work-orders/execution-packets
curl -s http://localhost:3000/zh/agent-os/reliability
npm run check:agent-os-production-readiness
Operator workflows
wcn-operator-console-production-smoke-monitoring
wcn-operator-console-alert-triage
wcn-operator-console-incident-escalation
wcn-operator-console-rollback-readiness
wcn-operator-console-replay-reconciliation
wcn-operator-console-audit-export
wcn-operator-console-release-observability-handoff
Cutover items
wcn-prod-obs-cutover-release-window-intake
wcn-prod-obs-cutover-smoke-route-evidence
wcn-prod-obs-cutover-metrics-alert-binding
wcn-prod-obs-cutover-operator-runbook
wcn-prod-obs-cutover-incident-timeline
wcn-prod-obs-cutover-rollback-replay
wcn-prod-obs-cutover-dlq-retry-audit
wcn-prod-obs-cutover-release-handoff
External binding items
wcn-prod-obs-external-metrics-backend
wcn-prod-obs-external-alert-delivery
wcn-prod-obs-external-on-call-roster
wcn-prod-obs-external-operator-identity-mfa
wcn-prod-obs-external-incident-system
wcn-prod-obs-external-smoke-executor
wcn-prod-obs-external-rollback-replay-authority
wcn-prod-obs-external-audit-export
Submission steps
wcn-prod-obs-submission-metrics-backend
wcn-prod-obs-submission-alert-delivery
wcn-prod-obs-submission-on-call-roster
wcn-prod-obs-submission-operator-identity
wcn-prod-obs-submission-incident-runbook
wcn-prod-obs-submission-post-release-smoke
wcn-prod-obs-submission-rollback-replay-authority
wcn-prod-obs-submission-audit-export-ready-claim
False boundary
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
closureEvidenceStored=false
productionEvidenceComplete=false
partialGateCanClose=false
productionCompletionReady=false
productionReadyClaimAllowed=false
productionDeployExecuted=false
productionChainWriteExecuted=false
realFundsTouched=false
productionSecretsLoaded=false
productionAuthBound=false
productionSideEffectExecuted=false
source=lib/agent-os/production-observability-closure-handoff.ts · localOnly=true · readOnly=true · productionBound=false · partialGateCanClose=false · productionCompletionReady=false · productionReadyClaimAllowed=false

Production observability Human Gate submission

This local package orders the production-observability Human Gate submission: metrics backend, alert delivery, on-call roster, operator MFA, incident runbook, post-release smoke, rollback/replay authority, audit export, and ready-claim review.

Observability submission API
01 · metrics_backend_submission · 05-platform-reliability-kernel

Metrics backend submission

Submit the production metric stream, dashboard URL, retention, and escalation owner for Human Gate review.

humanGateRequired=true
Upstream refs
lib/agent-os/production-observability.ts
lib/agent-os/reliability-operations-evidence.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
Evidence ids
production-observability-evidence-01
Binding ids
wcn-prod-obs-metric-stream
External binding kinds
metrics_backend_binding
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability
GET /api/agent-os/reliability-kernel/production-observability-human-gate-submission
Human Gate inputs
Production metrics backend name and dashboard URL
Metric stream source, retention, sampling, and escalation owner
Proof metrics are emitted from production runtime, not local state
Missing production evidence
Production metric stream binding
Production dashboard URL
Metric retention and owner record
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
02 · alert_delivery_submission · 05-platform-reliability-kernel

Alert delivery submission

Bind external alert destinations, dedupe, rate limits, delivery audit, and on-call routing without allowing alerts to trigger side effects.

humanGateRequired=true
Upstream refs
lib/agent-os/production-observability.ts
lib/agent-os/production-observability-operator-console.ts
app/api/agent-os/reliability-kernel/observability/route.ts
Evidence ids
production-observability-evidence-02
Binding ids
wcn-prod-obs-alert-destination
External binding kinds
alert_delivery_channel_binding
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/observability
GET /api/agent-os/reliability-kernel/production-observability-external-binding-evidence
Human Gate inputs
External alert channel and delivery audit trail
Dedupe key, escalation policy, rate limit, and severity routing
Confirmation alert delivery cannot execute production side effects by itself
Missing production evidence
External alert destination
Alert delivery audit trail
On-call escalation routing proof
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
03 · on_call_roster_submission · 05-platform-reliability-kernel

On-call roster submission

Submit the accountable on-call roster for smoke monitoring, incident escalation, rollback readiness, replay reconciliation, and audit export.

humanGateRequired=true
Upstream refs
lib/agent-os/production-observability-operator-console.ts
lib/agent-os/production-observability-cutover-evidence.ts
app/api/agent-os/reliability-kernel/production-operator-console/route.ts
Evidence ids
production-observability-evidence-02
production-observability-evidence-03
Binding ids
wcn-prod-obs-authenticated-operator
wcn-prod-obs-runbook-ack
External binding kinds
on_call_roster_binding
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-operator-console
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
Human Gate inputs
Primary and backup on-call owners
Escalation window, severity thresholds, and handoff route
Separation between observer, release approver, and rollback executor
Missing production evidence
Production on-call roster
Escalation schedule
Handoff acknowledgement record
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
04 · operator_identity_mfa_submission · 08-human-gate-governance

Operator identity and MFA submission

Bind authenticated operator identity, MFA proof, role claims, and least-privilege actions before production operator UI is trusted.

humanGateRequired=true
Upstream refs
lib/agent-os/production-observability.ts
lib/agent-os/production-observability-external-binding-evidence.ts
app/api/agent-os/decision-ledger/reviewer-identities/route.ts
Evidence ids
production-observability-evidence-03
Binding ids
wcn-prod-obs-authenticated-operator
External binding kinds
operator_identity_mfa_binding
Validation
npm run check:agent-os-governance
npm run check:agent-os-reliability
GET /api/agent-os/decision-ledger/reviewer-identities
Human Gate inputs
Authenticated operator identity
MFA status, role claims, and action scope
Operator action audit destination
Missing production evidence
Production authenticated operator identity
MFA and role claim proof
Operator audit destination
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
05 · incident_runbook_submission · 05-platform-reliability-kernel

Incident system and runbook submission

Bind incident management, runbook acknowledgement, timeline retention, and closeout evidence before production incidents can be trusted.

humanGateRequired=true
Upstream refs
lib/agent-os/reliability-operations-evidence.ts
lib/agent-os/production-observability-operator-console.ts
lib/agent-os/production-observability-cutover-evidence.ts
Evidence ids
production-observability-evidence-04
Binding ids
wcn-prod-obs-runbook-ack
wcn-prod-obs-incident-timeline
External binding kinds
incident_management_system_binding
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/operations-evidence
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
Human Gate inputs
Production incident system project or queue
Runbook acknowledgement storage
Incident timeline retention and closeout owner
Missing production evidence
Incident management system binding
Runbook acknowledgement trail in production storage
Incident timeline retention proof
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
06 · post_release_smoke_submission · 05-platform-reliability-kernel

Post-release smoke submission

Attach production smoke executor, route probes, API probes, Agent OS probes, and release decision refs before production health can be accepted.

humanGateRequired=true
Upstream refs
lib/agent-os/product-release-human-gate-submission.ts
lib/agent-os/production-observability-cutover-evidence.ts
lib/agent-os/production-observability-external-binding-evidence.ts
Evidence ids
production-observability-evidence-05
Binding ids
wcn-prod-obs-release-smoke-probe
External binding kinds
production_smoke_executor_binding
Validation
npm run check:agent-os-product
npm run check:agent-os-reliability
GET /api/agent-os/product-system/release-human-gate-submission
Human Gate inputs
Production base URL and smoke executor identity
HTTP, API, and Agent OS route probe output
Release decision id that owns the smoke record
Missing production evidence
Production smoke executor
Post-release smoke output
Release Human Gate decision attachment
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
07 · rollback_replay_authority_submission · 05-platform-reliability-kernel

Rollback and replay authority submission

Submit rollback owner, replay owner, DLQ/retry audit, and emergency pause evidence for production reliability operations.

humanGateRequired=true
Upstream refs
lib/agent-os/reliability-side-effect-readiness.ts
lib/agent-os/production-observability-operator-console.ts
app/api/agent-os/reliability-kernel/side-effect-readiness/route.ts
Evidence ids
production-observability-evidence-04
production-observability-evidence-05
Binding ids
wcn-prod-obs-incident-timeline
External binding kinds
rollback_replay_authority_binding
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/side-effect-readiness
GET /api/agent-os/reliability-kernel/dlq
Human Gate inputs
Rollback owner, replay owner, and emergency pause authority
DLQ/retry audit location and idempotency proof
Replay and rollback thresholds
Missing production evidence
Production rollback authority
Production replay authority
DLQ/retry audit export
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
08 · audit_export_ready_claim_submission · 01-wcn-conductor

Audit export and ready-claim submission

Export final observability audit evidence and require explicit production-ready claim approval before WCN can call production observability complete.

humanGateRequired=true
Upstream refs
lib/agent-os/production-observability-external-binding-evidence.ts
lib/agent-os/production-readiness-external-evidence.ts
app/api/agent-os/production-readiness/external-evidence/route.ts
Evidence ids
production-observability-evidence-01
production-observability-evidence-02
production-observability-evidence-03
production-observability-evidence-04
production-observability-evidence-05
Binding ids
wcn-prod-obs-metric-stream
wcn-prod-obs-alert-destination
wcn-prod-obs-authenticated-operator
wcn-prod-obs-runbook-ack
wcn-prod-obs-incident-timeline
wcn-prod-obs-release-smoke-probe
External binding kinds
observability_audit_export_binding
Validation
npm run check:agent-os-reliability
npm run check:agent-os-production-readiness
GET /api/agent-os/production-readiness/external-evidence
Human Gate inputs
Production observability audit export
Accepted residual risk list
Production-ready claim approval decision
Missing production evidence
Production observability audit export
Residual-risk acceptance record
Production-ready claim approval
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
productionSideEffectExecuted=false
source=lib/agent-os/production-observability-human-gate-submission.ts · localOnly=true · productionBound=false · humanGateProductionSubmissionReady=false · productionObservabilityReady=false · productionReadyClaimAllowed=false

Production observability external binding evidence

This local matrix separates the real external production bindings still required for metrics backend, alert delivery, on-call roster, operator MFA, incident system, smoke execution, rollback/replay authority, and audit export.

External binding evidence API
01 · metrics_backend_binding · 05-platform-reliability-kernel

Metrics backend binding

Prove the production runtime emits metrics into an approved observability backend before release health can be trusted.

productionBound=false
Local signals
lib/agent-os/production-observability.ts
lib/agent-os/reliability-operations-evidence.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
Human Gate inputs
Production metrics provider and dashboard URL
Metric names, retention policy, and alert thresholds
Escalation owner for dashboard outage or missing metrics
Missing production bindings
Production metrics backend
Runtime metric emission proof
Dashboard retention and access-control evidence
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability
GET /api/agent-os/reliability-kernel/production-observability-external-binding-evidence
Binding ids
wcn-prod-obs-metric-stream
Evidence ids
wcn-reliability-evidence-metric-dashboard
Operator workflows
alert_triage
release_observability_handoff
Cutover items
metrics_alert_binding_matrix
release_observability_handoff_packet
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
02 · alert_delivery_channel_binding · 05-platform-reliability-kernel

Alert delivery channel binding

Bind critical alert routing, dedupe, delivery audit, and rate limits before production incidents can be closed.

productionBound=false
Local signals
app/api/agent-os/reliability-kernel/observability/route.ts
lib/agent-os/production-observability.ts
lib/agent-os/reliability-operations-evidence.ts
Human Gate inputs
External alert destination and escalation policy
Rate limit, dedupe key, and delivery audit policy
Critical alert closure rule
Missing production bindings
External alert delivery channel
Alert delivery proof
On-call escalation route
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/observability
GET /api/agent-os/reliability-kernel/production-observability-external-binding-evidence
Binding ids
wcn-prod-obs-alert-destination
Evidence ids
wcn-reliability-evidence-alert-delivery
Operator workflows
alert_triage
Cutover items
metrics_alert_binding_matrix
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
03 · on_call_roster_binding · 05-platform-reliability-kernel

On-call roster binding

Bind production on-call ownership to alert triage, incident escalation, rollback, replay, and release observability handoff.

productionBound=false
Local signals
lib/agent-os/production-observability-operator-console.ts
lib/agent-os/production-observability-cutover-evidence.ts
app/api/agent-os/reliability-kernel/production-operator-console/route.ts
Human Gate inputs
On-call roster and escalation calendar
Primary and backup operator identities
Coverage rule for release windows
Missing production bindings
Production on-call roster
Escalation coverage proof
Release-window operator acceptance
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-operator-console
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
Binding ids
wcn-prod-obs-alert-destination
wcn-prod-obs-authenticated-operator
Evidence ids
wcn-reliability-evidence-alert-delivery
wcn-reliability-evidence-operator-identity
Operator workflows
alert_triage
incident_escalation
rollback_readiness
Cutover items
metrics_alert_binding_matrix
operator_identity_runbook_matrix
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
04 · operator_identity_mfa_binding · 08-human-gate-governance

Operator identity and MFA binding

Prove production reliability actions are performed by authenticated operators with MFA, role claims, and separation of duties.

productionBound=false
Local signals
lib/agent-os/reviewer-identity.ts
lib/agent-os/production-governance-external-authority-evidence.ts
lib/agent-os/production-observability-operator-console.ts
Human Gate inputs
Production operator identity provider
MFA policy and role claim mapping
Role-to-action matrix for reliability operations
Missing production bindings
Authenticated production operator
MFA enforcement proof
Role-to-action enforcement proof
Validation
npm run check:agent-os-governance
npm run check:agent-os-reliability
GET /api/agent-os/decision-ledger/production-external-authority-evidence
Binding ids
wcn-prod-obs-authenticated-operator
Evidence ids
wcn-reliability-evidence-operator-identity
Operator workflows
incident_escalation
rollback_readiness
audit_export
Cutover items
operator_identity_runbook_matrix
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
05 · incident_management_system_binding · 05-platform-reliability-kernel

Incident management system binding

Bind production incident opening, timeline storage, closure, and Human Gate escalation before public-impact incidents can be resolved.

productionBound=false
Local signals
lib/agent-os/reliability-kernel.ts
lib/agent-os/reliability-kernel-store.ts
lib/agent-os/production-observability-cutover-evidence.ts
Human Gate inputs
Incident system and timeline retention policy
Critical incident closure rule
Human Gate escalation criteria
Missing production bindings
Production incident system
Immutable incident timeline export
Critical incident closure audit
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel
GET /api/agent-os/reliability-kernel/production-observability-external-binding-evidence
Binding ids
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-incident-timeline
Operator workflows
incident_escalation
audit_export
Cutover items
incident_timeline_evidence_matrix
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
06 · production_smoke_executor_binding · 02-wcn-product-system

Production smoke executor binding

Bind post-deploy smoke routes, executor identity, expected invariants, and rollback thresholds before production-ready claims.

productionBound=false
Local signals
lib/agent-os/product-release-production-binding-evidence.ts
lib/agent-os/production-observability-cutover-evidence.ts
app/api/agent-os/product-system/production-binding-evidence/route.ts
Human Gate inputs
Production smoke route list
Executor identity and execution window
Rollback threshold and owner
Missing production bindings
Production smoke execution record
Production domain target
Smoke executor identity proof
Validation
npm run build
npm run check:agent-os-product
GET /api/agent-os/reliability-kernel/production-observability-external-binding-evidence
Binding ids
wcn-prod-obs-release-smoke-probe
Evidence ids
wcn-reliability-evidence-post-release-smoke
Operator workflows
production_smoke_monitoring
Cutover items
release_window_intake
smoke_route_evidence_matrix
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
07 · rollback_replay_authority_binding · 05-platform-reliability-kernel

Rollback and replay authority binding

Bind rollback, replay, DLQ requeue, reconciliation, idempotency, and Human Gate approval before recovery actions touch production.

productionBound=false
Local signals
lib/agent-os/reliability-side-effect-readiness.ts
lib/agent-os/production-observability-operator-console.ts
app/api/agent-os/reliability-kernel/side-effect-readiness/route.ts
Human Gate inputs
Rollback and replay owner separation
High-impact recovery approval rule
Reconciliation output owner
Missing production bindings
Production rollback authority record
Production replay audit record
Reconciliation completion evidence
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/side-effect-readiness
GET /api/agent-os/reliability-kernel/dlq
Binding ids
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-rollback-replay
wcn-reliability-evidence-dlq-retry
Operator workflows
rollback_readiness
replay_reconciliation
Cutover items
rollback_replay_readiness_matrix
dlq_retry_audit_handoff
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
08 · observability_audit_export_binding · 05-platform-reliability-kernel

Observability audit export binding

Export release-window metrics, alerts, incidents, operator actions, DLQ/retry, rollback/replay, and residual risk into a Human Gate handoff packet.

productionBound=false
Local signals
lib/agent-os/reliability-operations-evidence.ts
lib/agent-os/production-observability-cutover-evidence.ts
lib/agent-os/system-handoff.ts
Human Gate inputs
Audit export destination and retention
Redaction and sensitive evidence policy
Residual-risk acceptance decision
Missing production bindings
Production observability audit export
Redacted release-window evidence package
Human Gate residual-risk acceptance
Validation
npm run check:agent-os-reliability
npm run check:agent-os-handoff
GET /api/agent-os/reliability-kernel/production-observability-external-binding-evidence
Binding ids
wcn-prod-obs-metric-stream
wcn-prod-obs-alert-destination
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-metric-dashboard
wcn-reliability-evidence-alert-delivery
wcn-reliability-evidence-dlq-retry
Operator workflows
audit_export
release_observability_handoff
Cutover items
dlq_retry_audit_handoff
release_observability_handoff_packet
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionAuditExported=false
productionReadyClaimAllowed=false
source=lib/agent-os/production-observability-external-binding-evidence.ts · localOnly=true · productionBound=false · productionObservabilityExternalBindingsReady=false · productionReadyClaimAllowed=false

Production observability cutover evidence

This local matrix binds release cutover workflows, smoke routes, metrics, alerts, operator identity, incident timeline, rollback/replay, DLQ audit, and handoff evidence into one production observability go/no-go packet.

Cutover evidence API
01 · release_window_intake · 02-wcn-product-system

Release window intake

Bind the release candidate, cutover window, production readiness gaps, and observability owners before any release-ready claim.

productionBound=false
Local signals
lib/agent-os/product-release-cutover-command-center.ts
lib/agent-os/production-readiness.ts
app/api/agent-os/product-system/release-cutover-command-center/route.ts
Human Gate inputs
Release candidate id and approved cutover window
Production observability owner
Accepted residual risk list
Missing production bindings
Approved production cutover window
Production observability owner roster
Production-ready claim approval
Validation
npm run check:agent-os-product
npm run check:agent-os-production-readiness
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
Release workflows
release_candidate_intake
deployment_target_cutover_authorization
Binding ids
wcn-prod-obs-release-smoke-probe
Evidence ids
wcn-reliability-evidence-post-release-smoke
Operator workflows
production_smoke_monitoring
release_observability_handoff
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionReadyClaimAllowed=false
02 · smoke_route_evidence_matrix · 05-platform-reliability-kernel

Smoke route evidence matrix

Map every production smoke route to its expected response, rollback threshold, evidence owner, and Human Gate handoff.

productionBound=false
Local signals
lib/agent-os/product-release-execution-plan.ts
lib/agent-os/production-observability.ts
lib/agent-os/reliability-operations-evidence.ts
Human Gate inputs
Approved smoke route list
Expected response invariants
Rollback threshold and owner
Missing production bindings
Production domain smoke target
Production smoke execution record
Rollback threshold evidence
Validation
npm run build
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-operator-console
Release workflows
build_route_claim_acceptance
smoke_observability_monitoring
Binding ids
wcn-prod-obs-release-smoke-probe
Evidence ids
wcn-reliability-evidence-post-release-smoke
Operator workflows
production_smoke_monitoring
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionReadyClaimAllowed=false
03 · metrics_alert_binding_matrix · 05-platform-reliability-kernel

Metrics and alert binding matrix

Tie metric streams, alert destinations, dedupe keys, severity routing, and on-call ownership to the release cutover packet.

productionBound=false
Local signals
lib/agent-os/production-observability.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
app/api/agent-os/reliability-kernel/observability/route.ts
Human Gate inputs
Metric dashboard provider and dashboard URL
External alert destination
Severity routing and on-call owner
Missing production bindings
Production metrics stream
External alert delivery proof
On-call escalation proof
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
Release workflows
smoke_observability_monitoring
Binding ids
wcn-prod-obs-metric-stream
wcn-prod-obs-alert-destination
Evidence ids
wcn-reliability-evidence-metric-dashboard
wcn-reliability-evidence-alert-delivery
Operator workflows
alert_triage
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionReadyClaimAllowed=false
04 · operator_identity_runbook_matrix · 08-human-gate-governance

Operator identity and runbook matrix

Ensure every high-impact observability action has an authenticated operator, MFA/role proof, runbook acknowledgement, and audit trail.

productionBound=false
Local signals
lib/agent-os/reviewer-identity.ts
lib/agent-os/production-governance.ts
lib/agent-os/reliability-operations-evidence.ts
Human Gate inputs
Production operator roster
MFA and role-claim evidence
Runbook owner and acknowledgement rule
Missing production bindings
Authenticated production operator
Production runbook acknowledgement record
Role-to-action enforcement proof
Validation
npm run check:agent-os-governance
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/operations-evidence
Release workflows
smoke_observability_monitoring
rollback_pause_rehearsal
Binding ids
wcn-prod-obs-authenticated-operator
wcn-prod-obs-runbook-ack
Evidence ids
wcn-reliability-evidence-operator-identity
wcn-reliability-evidence-runbook-ack
Operator workflows
incident_escalation
audit_export
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionReadyClaimAllowed=false
05 · incident_timeline_evidence_matrix · 05-platform-reliability-kernel

Incident timeline evidence matrix

Prepare a release-window timeline that links receipts, alerts, traces, operator actions, Human Gate decisions, and recovery events.

productionBound=false
Local signals
lib/agent-os/reliability-kernel.ts
lib/agent-os/reliability-kernel-store.ts
app/api/agent-os/reliability-kernel/route.ts
Human Gate inputs
Incident timeline retention policy
Timeline evidence export owner
Immutable event classification
Missing production bindings
Production incident timeline storage
Immutable timeline export proof
Release-window incident owner
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
Release workflows
smoke_observability_monitoring
release_evidence_handoff
Binding ids
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-incident-timeline
Operator workflows
incident_escalation
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionReadyClaimAllowed=false
06 · rollback_replay_readiness_matrix · 05-platform-reliability-kernel

Rollback and replay readiness matrix

Bind rollback commands, replay reconciliation, idempotency, Human Gate decisions, and side-effect false boundaries before cutover.

productionBound=false
Local signals
lib/agent-os/reliability-side-effect-readiness.ts
app/api/agent-os/reliability-kernel/side-effect-readiness/route.ts
app/api/agent-os/reliability-kernel/dlq/route.ts
Human Gate inputs
Rollback owner and rollback command
Replay policy and reconciliation owner
High-impact rollback approval decision id
Missing production bindings
Production rollback command proof
Production replay audit record
Reconciliation outcome evidence
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/side-effect-readiness
GET /api/agent-os/reliability-kernel/dlq
Release workflows
rollback_pause_rehearsal
Binding ids
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-rollback-replay
Operator workflows
rollback_readiness
replay_reconciliation
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionReadyClaimAllowed=false
07 · dlq_retry_audit_handoff · 05-platform-reliability-kernel

DLQ retry audit handoff

Expose queued, retry, DLQ, policy-block, and audit evidence required before a release-window issue can be closed.

productionBound=false
Local signals
lib/core/outbox.ts
app/api/admin/outbox/dlq/route.ts
lib/agent-os/reliability-operations-evidence.ts
Human Gate inputs
DLQ retention policy
Retry maximum attempts
Audit export recipient and redaction policy
Missing production bindings
Production DLQ storage
Production retry audit evidence
Production audit export destination
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/operations-evidence
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
Release workflows
smoke_observability_monitoring
release_evidence_handoff
Binding ids
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-dlq-retry
Operator workflows
replay_reconciliation
audit_export
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionReadyClaimAllowed=false
08 · release_observability_handoff_packet · 01-wcn-conductor

Release observability handoff packet

Export the production observability cutover packet for Human Gate, future Codex/Claude Code handoff, and release residual-risk review.

productionBound=false
Local signals
lib/agent-os/production-observability-cutover-evidence.ts
lib/agent-os/production-observability-operator-console.ts
lib/agent-os/product-release-cutover-command-center.ts
Human Gate inputs
Final production observability go/no-go
Accepted residual risk list
Production operator and follow-up owner list
Missing production bindings
Production observability evidence export
Final production operator handoff
Production-ready claim approval
Validation
npm run check:agent-os-implementation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability-cutover-evidence
Release workflows
release_evidence_handoff
Binding ids
wcn-prod-obs-metric-stream
wcn-prod-obs-alert-destination
wcn-prod-obs-authenticated-operator
wcn-prod-obs-release-smoke-probe
Evidence ids
wcn-reliability-evidence-metric-dashboard
wcn-reliability-evidence-alert-delivery
wcn-reliability-evidence-operator-identity
wcn-reliability-evidence-post-release-smoke
Operator workflows
audit_export
release_observability_handoff
No production side effects
externalAlertDelivery=false
productionMetricsStream=false
authenticatedOperator=false
productionSmokeExecuted=false
productionRollbackExecuted=false
productionReplayExecuted=false
productionIncidentOpened=false
productionIncidentClosed=false
productionReadyClaimAllowed=false
source=lib/agent-os/production-observability-cutover-evidence.ts · localOnly=true · productionBound=false · productionObservabilityCutoverReady=false · productionReadyClaimAllowed=false

Production operator console

These local workflows turn observability bindings and operations evidence into an operator handoff: smoke monitoring, alert triage, incident escalation, rollback readiness, replay reconciliation, audit export, and release observability handoff.

01 · production_smoke_monitoring · 02-wcn-product-system

Production smoke monitoring

Prepare post-release smoke checks and attach their expected evidence before any production-ready claim.

productionBound=false
Operator inputs
Approved release decision id
Production domain and smoke route list
Rollback owner and rollback threshold
Local signals
app/api/agent-os/product-system/release-execution-plan/route.ts
app/api/agent-os/production-readiness/route.ts
lib/agent-os/production-observability.ts
Runbook
Confirm the release gate is approved by Human Gate.
Run local build and Agent OS checks before any production probe.
Attach production HTTP smoke output only after deploy is separately approved.
Human Gate inputs
Release approval decision id
Approved production smoke routes
Rollback owner and rollback command
Missing production bindings
Production domain smoke target
Production smoke execution record
Rollback command and owner evidence
Validation
npm run check:agent-os-product
npm run check:agent-os-production-readiness
GET /api/agent-os/reliability-kernel/production-operator-console
Binding ids
wcn-prod-obs-release-smoke-probe
Evidence ids
wcn-reliability-evidence-post-release-smoke
02 · alert_triage · 05-platform-reliability-kernel

Alert triage

Turn local alert, metric, and runbook signals into a production alert-routing checklist.

productionBound=false
Operator inputs
Alert severity and dedupe key
Metric dashboard URL or local metric packet
On-call owner and escalation route
Local signals
operatorReport.alerts
ReliabilityAlert.runbook
app/api/agent-os/reliability-kernel/observability/route.ts
Runbook
Classify severity from local reliability alerts.
Map the alert to metric stream and external alert destination requirements.
Escalate critical public-impact alerts to Human Gate before closing.
Human Gate inputs
Severity-to-channel routing approval
On-call owner identity
Critical alert closure policy
Missing production bindings
External alert delivery channel
Production metrics stream
Authenticated on-call operator
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/observability
GET /api/agent-os/reliability-kernel/production-observability
Binding ids
wcn-prod-obs-metric-stream
wcn-prod-obs-alert-destination
Evidence ids
wcn-reliability-evidence-metric-dashboard
wcn-reliability-evidence-alert-delivery
03 · incident_escalation · 05-platform-reliability-kernel

Incident escalation

Bundle trace, receipt, runbook, and Human Gate context for incident review without opening a production incident automatically.

productionBound=false
Operator inputs
Affected receipt or trace id
Runbook acknowledgement note
Human Gate decision id when public claims, funds, chain, or user data are affected
Local signals
operatorReport.recentTraceEvents
operatorReport.recentOperatorActions
lib/agent-os/reliability-kernel.ts
Runbook
Link receipt, trace, alert, and operator action ids.
Require runbook acknowledgement before incident closure.
Route high-impact incidents to Human Gate instead of self-closing.
Human Gate inputs
Incident impact classification
Runbook owner and version
Closure or escalation decision id
Missing production bindings
Production incident timeline
Runbook acknowledgement audit store
Authenticated incident operator
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel
POST /api/agent-os/reliability-kernel/observability
Binding ids
wcn-prod-obs-runbook-ack
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-runbook-ack
wcn-reliability-evidence-incident-timeline
04 · rollback_readiness · 05-platform-reliability-kernel

Rollback readiness

Verify rollback ownership, command evidence, idempotency, and Human Gate inputs before any rollback is attempted.

productionBound=false
Operator inputs
Rollback candidate receipt ids
Rollback plan and owner
Approved Human Gate decision for high-impact rollback
Local signals
lib/agent-os/reliability-side-effect-readiness.ts
app/api/agent-os/reliability-kernel/side-effect-readiness/route.ts
app/api/agent-os/reliability-kernel/dlq/route.ts
Runbook
Check rollback plan exists before any high-impact side effect is trusted.
Confirm idempotency keys and audit trail are available.
Keep production rollback execution blocked until Human Gate approves.
Human Gate inputs
Rollback owner
Rollback command
Affected receipt and public-impact scope
Missing production bindings
Production rollback command
Production rollback audit record
Authenticated rollback operator
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/side-effect-readiness
GET /api/agent-os/reliability-kernel/dlq
Binding ids
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-rollback-replay
05 · replay_reconciliation · 05-platform-reliability-kernel

Replay reconciliation

Prepare DLQ replay and reconciliation evidence while keeping production replay execution disabled.

productionBound=false
Operator inputs
DLQ receipt ids and failure reasons
Replay idempotency key
Reconciliation owner and expected outcome
Local signals
summary.dlq
summary.retryScheduled
app/api/agent-os/reliability-kernel/process/route.ts
Runbook
Inspect terminal failure reason and retry count.
Confirm replay is deduplicated by idempotency key.
Escalate high-impact replay to Human Gate before production execution.
Human Gate inputs
Replay policy and maximum attempts
Reconciliation owner
High-impact replay approval decision id
Missing production bindings
Production DLQ storage
Production replay audit record
Reconciliation outcome evidence
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/dlq
POST /api/agent-os/reliability-kernel/process
Binding ids
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-dlq-retry
wcn-reliability-evidence-rollback-replay
06 · audit_export · 08-human-gate-governance

Audit export

Package local reliability operations evidence for Human Gate, release review, or future external auditor handoff.

productionBound=false
Operator inputs
Export scope and time window
Reviewer identity
Target decision, release, or incident id
Local signals
lib/agent-os/reliability-operations-evidence.ts
lib/agent-os/reviewer-identity.ts
app/api/agent-os/reliability-kernel/operations-evidence/route.ts
Runbook
Collect operations evidence sections and source anchors.
Attach reviewer identity evidence and Human Gate decision context.
Keep production audit export binding false until a governed destination is approved.
Human Gate inputs
Audit export recipient
Reviewer identity proof
Retention and redaction policy
Missing production bindings
Production audit export destination
Production reviewer identity proof
Retention and redaction enforcement
Validation
npm run check:agent-os-governance
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/operations-evidence
Binding ids
wcn-prod-obs-authenticated-operator
wcn-prod-obs-incident-timeline
Evidence ids
wcn-reliability-evidence-operator-identity
wcn-reliability-evidence-incident-timeline
07 · release_observability_handoff · 01-wcn-conductor

Release observability handoff

Summarize which production observability and operations evidence must be complete before a release can be called production-ready.

productionBound=false
Operator inputs
Release execution plan
Production readiness report
Open observability and reliability gaps
Local signals
lib/agent-os/product-release-execution-plan.ts
lib/agent-os/production-readiness.ts
lib/agent-os/production-observability-operator-console.ts
Runbook
Compare local release plan, production readiness, and reliability evidence.
List incomplete production bindings as release blockers.
Escalate the final readiness claim to Human Gate before public release.
Human Gate inputs
Release readiness decision id
Accepted residual risk list
Production observability owner
Missing production bindings
Production metrics dashboard
Production alert delivery
Production smoke and rollback evidence
Validation
npm run check:agent-os-implementation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-operator-console
Binding ids
wcn-prod-obs-metric-stream
wcn-prod-obs-alert-destination
wcn-prod-obs-release-smoke-probe
Evidence ids
wcn-reliability-evidence-metric-dashboard
wcn-reliability-evidence-alert-delivery
wcn-reliability-evidence-post-release-smoke
source=lib/agent-os/production-observability-operator-console.ts · localOnly=true · productionBound=false

Side-effect readiness

Every cross-module side effect is checked for policy, audit, idempotency, outbox topic, rollback plan, and Human Gate evidence before a local receipt is trusted.

meta_agent_os · none

system.handoff.package

Create or replay the local reliability receipt; do not execute production side effects.

ready_local_receipt
Readiness status
receipt=queued
policy=allowed
requiredDecision=none
Blocking reasons
No blocking reasons.
Satisfied controls
auditSink=ReliabilityReadiness.audit
idempotencyKey=readiness-meta-handoff
policyBound=true
outboxTopic not required
rollbackPlan not required
No production side effects
prismaTouched=false
eventOutboxProductionWrite=false
externalApiCalled=false
chainWriteExecuted=false
realFundsTouched=false
productionSideEffectExecuted=false
agent_interoperability_gateway · local_file

gateway.quarantine.write

Create or replay the local reliability receipt; do not execute production side effects.

ready_local_receipt
Readiness status
receipt=queued
policy=allowed
requiredDecision=none
Blocking reasons
No blocking reasons.
Satisfied controls
auditSink=ReliabilityReadiness.audit
idempotencyKey=readiness-gateway-quarantine
policyBound=true
outboxTopic=local.gateway.quarantine
rollbackPlan not required
No production side effects
prismaTouched=false
eventOutboxProductionWrite=false
externalApiCalled=false
chainWriteExecuted=false
realFundsTouched=false
productionSideEffectExecuted=false
wcn_product_system · db_write

product.fact.promote

Route the request to Human Gate and attach the approved decision id before local receipt creation.

blocked_missing_human_gate
Readiness status
receipt=blocked_by_policy
policy=blocked
requiredDecision=external_write
Blocking reasons
db_write requires Human Gate before reliability receipt creation.
Satisfied controls
auditSink=ReliabilityReadiness.audit
idempotencyKey=readiness-product-fact-promote
policyBound=true
outboxTopic=product.fact.promote
rollbackPlan provided
No production side effects
prismaTouched=false
eventOutboxProductionWrite=false
externalApiCalled=false
chainWriteExecuted=false
realFundsTouched=false
productionSideEffectExecuted=false
runtime_business_agent_network · external_api

runtime.provider.notify

Route the request to Human Gate and attach the approved decision id before local receipt creation.

blocked_missing_human_gate
Readiness status
receipt=blocked_by_policy
policy=blocked
requiredDecision=external_write
Blocking reasons
external_api requires an approved Human Gate decision id.
Satisfied controls
auditSink=ReliabilityReadiness.audit
idempotencyKey=readiness-runtime-provider-notify
policyBound=true
outboxTopic=runtime.provider.notify
rollbackPlan provided
No production side effects
prismaTouched=false
eventOutboxProductionWrite=false
externalApiCalled=false
chainWriteExecuted=false
realFundsTouched=false
productionSideEffectExecuted=false
blockchain_anchoring_module · chain_write

chain.anchor.broadcast

Keep the request blocked until the referenced Human Gate decision is approved and matches the module/action.

blocked_unapproved_human_gate
Readiness status
receipt=blocked_by_policy
policy=blocked
requiredDecision=chain_anchor
Blocking reasons
chain_write Human Gate decision is not approved: Human Gate decision was not verified.
Satisfied controls
auditSink=ReliabilityReadiness.audit
idempotencyKey=readiness-chain-anchor-broadcast
policyBound=true
outboxTopic=chain.anchor.broadcast
rollbackPlan provided
No production side effects
prismaTouched=false
eventOutboxProductionWrite=false
externalApiCalled=false
chainWriteExecuted=false
realFundsTouched=false
productionSideEffectExecuted=false
human_gate_governance · funds

settlement.execute

Route the request to Human Gate and attach the approved decision id before local receipt creation.

blocked_missing_human_gate
Readiness status
receipt=blocked_by_policy
policy=blocked
requiredDecision=funds
Blocking reasons
funds requires an approved Human Gate decision id.
Satisfied controls
auditSink=ReliabilityReadiness.audit
idempotencyKey=readiness-settlement-execute
policyBound=true
outboxTopic=settlement.execute
rollbackPlan provided
No production side effects
prismaTouched=false
eventOutboxProductionWrite=false
externalApiCalled=false
chainWriteExecuted=false
realFundsTouched=false
productionSideEffectExecuted=false
source=lib/agent-os/reliability-side-effect-readiness.ts · localOnly=true · productionBound=false

Reliability operations evidence

This local package prepares the evidence Human Gate needs for production reliability operations: dashboards, alerts, authenticated operators, runbook acknowledgement, incident timeline, post-release smoke, rollback/replay, and DLQ/retry audit.

metric_dashboard_packet · 05-platform-reliability-kernel

Metric dashboard evidence

productionBound=false
Local signals
lib/agent-os/production-observability.ts
app/api/agent-os/reliability-kernel/observability/route.ts
app/api/agent-os/reliability-kernel/production-observability/route.ts
Required production binding
Bind queued, retry, DLQ, policy-block, alert, and trace metrics to a production observability backend.
Record dashboard URL, retention, metric names, alert thresholds, and escalation owner.
Confirm metrics originate from production runtime events rather than local JSON state.
Human Gate inputs
Approved production dashboard provider and dashboard URL.
Metric owner and escalation owner.
Decision on which release gates require dashboard evidence.
Missing production evidence
Production dashboard URL.
Metric stream delivery proof.
Retention and alert threshold configuration.
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability
alert_delivery_packet · 05-platform-reliability-kernel

Alert delivery evidence

productionBound=false
Local signals
operatorReport.alerts
ReliabilityAlert.severity
ReliabilityAlert.runbook
Required production binding
Route critical and warning alerts to an external delivery channel with dedupe and rate limits.
Record delivery id, recipient, severity, runbook, escalation policy, and delivery audit state.
Prevent alert delivery from triggering production side effects without a separate operator action.
Human Gate inputs
Approved alert destination and on-call owner.
Severity-to-channel routing table.
Escalation policy for missed or failed alert deliveries.
Missing production evidence
External alert destination binding.
Alert delivery audit record.
On-call owner identity.
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/observability
operator_identity_packet · 08-human-gate-governance

Authenticated operator evidence

productionBound=false
Local signals
lib/agent-os/reviewer-identity.ts
lib/agent-os/production-governance.ts
app/api/agent-os/decision-ledger/reviewer-identities/route.ts
Required production binding
Bind reliability operator actions to production auth, MFA, role claims, and audit trail.
Map operators to allowed actions such as acknowledge, requeue, discard, pause, replay, and rollback.
Reject high-impact reliability actions when the operator is unauthenticated or conflicted.
Human Gate inputs
Production operator roster.
MFA and role-claim evidence.
Segregation-of-duties rule for release, rollback, and replay decisions.
Missing production evidence
Production auth provider binding.
Authenticated operator id.
Role-to-action matrix.
Validation
npm run check:agent-os-governance
npm run check:agent-os-reliability
runbook_acknowledgement_packet · 05-platform-reliability-kernel

Runbook acknowledgement evidence

productionBound=false
Local signals
ReliabilityAlert.runbook
operatorAction.note
operatorAction.createdAt
Required production binding
Require operators to acknowledge the relevant runbook before closing or escalating incidents.
Store acknowledgement notes in production audit storage.
Escalate replay, discard, rollback, or public-impact actions to Human Gate when required.
Human Gate inputs
Runbook owner and version.
Acknowledgement rules by severity.
Closure criteria for warning and critical incidents.
Missing production evidence
Production runbook acknowledgement record.
Operator note in production audit storage.
Runbook version hash or URL.
Validation
npm run check:agent-os-reliability
POST /api/agent-os/reliability-kernel/observability
incident_timeline_packet · 05-platform-reliability-kernel

Incident timeline evidence

productionBound=false
Local signals
operatorReport.recentTraceEvents
operatorReport.recentOperatorActions
app/api/agent-os/reliability-kernel/route.ts
Required production binding
Persist receipt, alert, operator action, retry, DLQ, Human Gate, and recovery events in a production timeline.
Protect incident timelines from deletion or silent mutation.
Export incident timelines into release evidence when production release or rollback is affected.
Human Gate inputs
Incident timeline retention policy.
Timeline owner and evidence export owner.
Decision on which events require immutable audit storage.
Missing production evidence
Production incident timeline id.
Immutable audit storage proof.
Linked Human Gate decision ids.
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel
post_release_smoke_packet · 02-wcn-product-system

Post-release smoke evidence

productionBound=false
Local signals
lib/agent-os/product-release-evidence.ts
app/api/agent-os/product-system/release-evidence/route.ts
app/api/agent-os/production-readiness/route.ts
Required production binding
Run production HTTP smoke checks against the approved domain after deploy.
Capture route, status, invariant, timestamp, operator identity, and release decision id.
Block production-ready claims until smoke evidence is attached to release and observability records.
Human Gate inputs
Production domain and required smoke routes.
Expected statuses and response invariants.
Smoke operator and rollback threshold.
Missing production evidence
Production HTTP smoke output.
Production domain binding.
Smoke operator identity.
Validation
npm run check:agent-os-product
npm run check:agent-os-production-readiness
rollback_replay_packet · 05-platform-reliability-kernel

Rollback and replay evidence

productionBound=false
Local signals
app/api/agent-os/reliability-kernel/process/route.ts
app/api/agent-os/reliability-kernel/dlq/route.ts
lib/agent-os/reliability-kernel.ts
Required production binding
Bind retry, replay, discard, and rollback actions to authenticated operators and idempotency evidence.
Record command, owner, threshold, affected receipts, and recovery outcome.
Require Human Gate for high-impact replay or rollback affecting public claims, funds, chain, or user data.
Human Gate inputs
Rollback owner and replay owner.
Approved rollback command and replay policy.
Decision threshold for emergency pause, rollback, or replay.
Missing production evidence
Production rollback command.
Production replay audit record.
Affected receipt and idempotency evidence.
Validation
npm run check:agent-os-reliability
npm run check:agent-os-production-readiness
dlq_retry_audit_packet · 05-platform-reliability-kernel

DLQ and retry audit evidence

productionBound=false
Local signals
summary.retryScheduled
summary.dlq
app/api/agent-os/reliability-kernel/dlq/route.ts
Required production binding
Persist retry attempts, terminal failures, DLQ reason, and operator resolution in production storage.
Deduplicate replays by idempotency key and source receipt.
Export DLQ and retry audit evidence to release and incident timelines when product surfaces are affected.
Human Gate inputs
DLQ owner and retry policy.
Maximum replay attempts by event kind.
Audit export scope for failed or replayed events.
Missing production evidence
Production DLQ storage.
Retry attempt history.
Operator resolution audit record.
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/dlq
source=lib/agent-os/reliability-operations-evidence.ts · localOnly=true · productionBound=false

Production observability bindings

wcn-prod-obs-metric-stream · metric_stream

Production metric stream

productionBound=false
Local signals
operatorReport.status
summary.queued
summary.retryScheduled
summary.dlq
summary.blockedByPolicy
Required production binding
Bind metrics to a production observability backend.
Record metric names, retention, dashboard URL, and escalation owner.
Verify metrics are emitted from the production runtime, not only local JSON state.
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/observability
wcn-prod-obs-alert-destination · external_alert_destination

External alert destination

productionBound=false
Local signals
operatorReport.alerts
ReliabilityAlert.severity
ReliabilityAlert.runbook
Required production binding
Bind critical and warning alerts to an external delivery channel.
Record rate limits, dedupe key, on-call owner, and delivery audit trail.
Confirm no alert destination can trigger production side effects by itself.
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel/production-observability
wcn-prod-obs-authenticated-operator · authenticated_operator

Authenticated operator identity

productionBound=false
Local signals
operatorAction.actorId
operatorAction.actionType
operatorAction.source.authenticatedOperator=false
Required production binding
Bind operator actions to production auth, MFA, and role claims.
Map operator roles to allowed reliability actions.
Reject DLQ requeue, external replay, and escalation without authenticated operator identity.
Validation
npm run check:agent-os-governance
npm run check:agent-os-reliability
wcn-prod-obs-runbook-ack · runbook_acknowledgement

Runbook acknowledgement trail

productionBound=false
Local signals
ReliabilityAlert.runbook
operatorAction.note
operatorAction.createdAt
Required production binding
Require operator acknowledgement before closing critical incidents.
Store runbook notes in an audit-backed production store.
Escalate high-impact replay or discard decisions to Human Gate.
Validation
npm run check:agent-os-reliability
POST /api/agent-os/reliability-kernel/observability
wcn-prod-obs-incident-timeline · incident_timeline

Incident timeline

productionBound=false
Local signals
traceEvents
recentTraceEvents
receipt.updatedAt
operatorActions
Required production binding
Persist trace events and operator actions in a production audit timeline.
Connect receipt, alert, runbook, and Human Gate decision ids.
Protect the timeline from deletion or silent mutation.
Validation
npm run check:agent-os-reliability
GET /api/agent-os/reliability-kernel
wcn-prod-obs-release-smoke-probe · release_smoke_probe

Post-release smoke probe

productionBound=false
Local signals
npm run build
npm run check:agent-os-implementation
GET /api/agent-os/production-readiness
Required production binding
Run production HTTP smoke checks after deploy.
Attach smoke evidence to the release Human Gate decision.
Record rollback owner and rollback command before declaring production readiness.
Validation
npm run build
npm run check:agent-os-implementation

Alerts

No reliability alerts are open.

Operator actions

No operator actions recorded yet.

Trace events

No trace events recorded yet.