N · Checklists

Checklist: Runtime, Monitoring and Drift

Control Plane onboarding in the order that pays, the operating rhythm, and triage that does not drown anyone.

Coverage is not the goal in the first year; routing is. A signal with no owner produces alert fatigue, and alert fatigue disables every signal that follows it.

Onboard in the order below and stop when the alerts you have are being dispositioned reliably. Adding the next signal before that point makes the whole feed less useful.

Ticks are stored in this browser only. Nothing is sent anywhere, and clearing site data clears them.

A completed checklist is not evidence. The evidence is the record it told you to complete — the templates hold those.

Control Plane onboarding order

  • Inventory reconciled first — you cannot compare against a baseline you do not have Architect
  • Authorized configuration recorded as data for every Tier 3–4 system Architect
  • One signal wired end to end, including who receives it and what they do System Owner
  • Disposition rate measured before the second signal is added AI Governance Lead
  • Grounding-source change detection for the highest-tier retrieval system Data Owner
  • Supplier model version change detection across the estate Architect
  • Agent boundary comparison for every acting system Security Architect
  • Override-rate instrumentation on reviewed decision systems where D1 ≥ 3 System Owner

Daily

  • Tier 4 alerts reviewed same business day
  • Agent boundary divergences triaged as incidents, at any tier
  • Kill-switch activations reviewed, with the outcome recorded
  • Failed comparison jobs treated as an outage of the control, not as noise

Weekly

  • Tier 3 alerts within the five-day window
  • Open drift records with no disposition escalated
  • New systems in the inventory checked for tier and owner
  • Alert volume per owner reviewed — rising volume with flat disposition is the fatigue signal

Monthly

  • Override rates and acceptance rates reviewed against their thresholds
  • Accepted drift dispositions checked: was the approved state actually updated?
  • Exception register reviewed for expiry, not for count
  • Inventory reconciled against the model or asset register, where a second one exists
  • Conditions outstanding from gate decisions chased by name

Quarterly

  • Supplier concentration question answered at the Architecture Review Board
  • Cross-system classification comparison for consistency
  • Pattern coverage measured
  • Re-score triggers verified as wired, not merely documented
  • One retrieval of archived evidence tested

Triage discipline

  • Category assigned from the eight, before routing
  • Severity derived from category and tier together, not category alone
  • Model change and grounding change kept distinct — they route to different people
  • Every record closed with one of three dispositions: accepted, remediated, escalated
  • Accepted means the approved state was updated; otherwise the baseline is now fiction
  • Recurrence checked: a signal that fires repeatedly is a design problem, not an alert