You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Track only the remaining work required to call Release 1 operationally ready. The original implementation checklist is historical: issues #1–30, #32, #34–36, #38–39, and #41 are closed, and the repository-wide product consolidation epic #346 is complete. This epic now follows current readiness evidence instead of the archived 2026 build plan.
The application, database, DNS/TLS, and staff-group synchronization are deployed. Known release blockers are live channel delivery, exact private mobile build evidence, one retained human sign-in verification, release-critical monitoring evidence, and an explicit live-or-disabled decision for media/export/malware-scanning capabilities. SMS can remain visibly blocked for Release 1 if email and push are live and no SMS work is routed.
Verify one complete district Google OIDC sign-in/session and update docs/INTEGRATIONS.md(manual)
Verify release-critical CloudWatch alarms/actions are active for the exact release (manual)
Event media/exports and malware scanning are either live-verified or disabled server-side and removed from Release 1 operator paths; do not ship a mocked boundary as live
Record OIDC, monitoring, media/export, and malware-scanning truth; then run the existing monthly delivery-test capability once for the launch channels and complete the Release 1 go-live procedure.
The exact approved iOS and Android builds are installed through their intended private channels and match the retained version/build evidence (manual)
SMS is either live-verified or remains fail-closed, visibly unavailable, and receives no routable work
Release-critical CloudWatch alarms and actions are read back active for the exact release; publisher-dependent alarms are exercised by retained synthetic evidence (manual)
Event media/exports and malware scanning are either live-verified end to end or disabled server-side and absent from Release 1 operator paths
docs/INTEGRATIONS.md is current and contains no contradictory status for deployment, OIDC, monitoring, providers, EAS submission, or mobile installation
The four human-only actions, staff-only scope, server-side authorization, real/drill separation, append-only history, idempotency, and fail-closed provider behavior remain enforced
No student data, secret, real contact fixture, or new tenant-specific source literal is introduced
Production web and mobile builds succeed
Full test suite green
Zero lint warnings; typecheck clean
The product owner's direct instruction for the exact production release is recorded through the current go-live procedure (manual)
E2E flow(s) pass — N/A — the epic reuses the executable child-issue E2E evidence plus the manual operational/provider flows below
Acceptance tests / E2E flows
release-integrated-delivery-test(manual): an authenticated human runs the existing monthly delivery-test capability once for the launch channels and retains its append-only report; automation may prepare evidence but may not send the notifications.
mobile-private-build-smoke(manual): on the exact privately distributed iOS and Android builds, verify sign-in, secure unlock, authorized facilities, real/drill presentation, event navigation, and notification settings without starting a real incident.
Current green GitHub checks for the exact release commit plus the manual provider/device evidence above
Affected areas
Implementation primarily belongs to the canonical child issues above.
docs/INTEGRATIONS.md and docs/runbooks/go-live.md — OIDC, monitoring, media/export/malware, monthly-test, and exact-release truth owned directly by this epic where no child owns it.
Current media/export capability paths and infra/src/stack/** only if the release decision is to enable or disable those unowned boundaries.
Requiring SMS to launch when it remains honestly blocked and unroutable.
Public mobile-store distribution.
Student, guardian, schedule, reunification, or passive-location data.
A second approval form, acknowledgement phrase, hand-computed digest, or parallel release ledger.
Automated real incident activation, real notification, real all-clear, or real event closure.
Risk & rollback
Risk: high — the remaining work crosses live provider delivery and operational readiness.
Rollback: follow each child issue's rollback and the current deployment/mobile runbooks. Keep unverified channels dark, revert the affected immutable release, and preserve append-only event, delivery, audit, migration, and provider evidence.
Summary
Track only the remaining work required to call Release 1 operationally ready. The original implementation checklist is historical: issues #1–30, #32, #34–36, #38–39, and #41 are closed, and the repository-wide product consolidation epic #346 is complete. This epic now follows current readiness evidence instead of the archived 2026 build plan.
The application, database, DNS/TLS, and staff-group synchronization are deployed. Known release blockers are live channel delivery, exact private mobile build evidence, one retained human sign-in verification, release-critical monitoring evidence, and an explicit live-or-disabled decision for media/export/malware-scanning capabilities. SMS can remain visibly blocked for Release 1 if email and push are live and no SMS work is routed.
Canonical workstreams
Release blockers
docs/INTEGRATIONS.md(manual)(manual)Non-blocking follow-up
Duplicate consolidation
Recommended order
Definition of Done
(manual)(manual)(manual)(manual)docs/INTEGRATIONS.mdis current and contains no contradictory status for deployment, OIDC, monitoring, providers, EAS submission, or mobile installation(manual)Acceptance tests / E2E flows
release-integrated-delivery-test(manual): an authenticated human runs the existing monthly delivery-test capability once for the launch channels and retains its append-only report; automation may prepare evidence but may not send the notifications.mobile-private-build-smoke(manual): on the exact privately distributed iOS and Android builds, verify sign-in, secure unlock, authorized facilities, real/drill presentation, event navigation, and notification settings without starting a real incident.Verification
bun run checkAffected areas
docs/INTEGRATIONS.mdanddocs/runbooks/go-live.md— OIDC, monitoring, media/export/malware, monthly-test, and exact-release truth owned directly by this epic where no child owns it.infra/src/stack/**only if the release decision is to enable or disable those unowned boundaries.Out of scope
Risk & rollback