{"blockers":["deployment_plan","rollback_plan","monitoring","security_review","customer_safe_release"],"checks":[{"id":"deployment_plan","label":"Deployment plan","proof_needed":"Approved target, environment config, rollback path, and owner sign-off.","status":"missing"},{"id":"rollback_plan","label":"Rollback plan","proof_needed":"Tested rollback command/path and data restore boundary.","status":"missing"},{"id":"monitoring","label":"Monitoring","proof_needed":"Health checks, logs, alert route, and failure triage owner.","status":"missing"},{"id":"security_review","label":"Security review","proof_needed":"Secrets audit, auth/role/tenant proof, dependency review, and customer-boundary review.","status":"missing"},{"id":"customer_safe_release","label":"Customer-safe release","proof_needed":"Read-only surface proof, approved report workflow, and no raw evidence/probe exposure.","status":"missing"},{"denied_status_code":403,"evidence_hash":"2fa1750eb573af1c30b690bfe20710ac97fe8265b2df30197a93902901452cad","id":"customer_route_denial","identity_guard_receipt_hash":"8db22bfd9d39d3bab2916581174efa1a6b4f644498c978c896411d1f9255c626","label":"Customer route denial","proof_needed":"Current local proof only: the reserved customer route returns 403 until SSO, tenant boundary, signed redaction review, and release approval are present.","route":"/customer/visibility-output","status":"local_pass"},{"drilldown_url":"/api/reports/workshop-identity-guard-receipt/latest","evidence_hash":"8db22bfd9d39d3bab2916581174efa1a6b4f644498c978c896411d1f9255c626","id":"workshop_identity_guard","label":"Workshop identity guard","proof_needed":"Current local proof only: the reserved customer route is wired to a fail-closed guard while real Workshop SSO, tenant, and read-only role proof remain blocked.","status":"local_pass"},{"drilldown_url":"/api/reports/production-audit-middleware-contract/latest","evidence_hash":"b17e31fe62c13e138ef9f58217becd2734d8beb7286ac4b826397a3044cf3f27","id":"local_audit_runtime","label":"Local audit runtime","linked_denial_chain_hash":null,"production_audit_middleware_installed":false,"production_audit_store_connected":false,"proof_needed":"Current local proof only: the reserved customer denial route writes a local immutable audit event chain. Production audit middleware/store, Workshop SSO, tenant boundary, and release approval are still not proven.","runtime_hooks_blocked":2,"runtime_hooks_implemented":1,"status":"local_pass"}],"customer_visible":false,"deployment_performed":false,"external_send_performed":false,"generated_at":"2026-09-26T16:07:48.603056+00:00","monitoring_proven":false,"next_action":"Approve deployment target, rollback, monitoring, security review, and customer-safe release proof before any release claim.","operator_gate":"no_deploy_release_readiness_only","production_db_migration_performed":false,"publish_performed":false,"release_ready":false,"rollback_tested":false,"security_review_complete":false,"status":"local_release_readiness_packet"}
