Source/commit → immutable build → migration → candidate environment → required QA → promotion/canary → post-release smoke
The evidence must name the same candidate all the way through.
Test:
The public page renders.
The authenticated API call fails.
What is the correct release conclusion?
Facts: what we observed Impact: who/what is affected Unknowns: what we have not proven Containment: what is safe now Next evidence: how we learn more
Three evidence rounds. Update your recommendation each time.
Deliver: release recommendation and incident update.
It requires a named approver, reason, incident record, and mandatory follow-up. It does not change failed evidence into passing evidence.
What exact evidence must exist before you promote a candidate?