Release Guard
- Classify: L0 read-only, L1 sandbox, L2 reversible canary requiring approval, L3 production-data or irreversible action that must not auto-execute.
- Fail closed unless root-cause confidence, zero required test failures, rollback readiness, and required approval all pass policy.
- Attach
case_id + action + target_versionas the idempotency key and pass the approval ID to the tool. - Start with the policy canary percentage and observation window. Compare technical and business health with the baseline.
- Promote only when every guard is healthy. Trigger the predeclared rollback directly on threshold breach; do not wait for model judgment.
- Return
status,risk_level,approval,canary,decision,rollback,evidence_refs,audit_ref, andtrace_id.
Workers must not receive real production credentials; use scoped gateway injection. Never auto-execute an L3 action.
微信扫一扫