# Operator acceptance packet

Use this packet before any hosted or customer BYOC Enigma deployment is called live. It is a required review artifact, not evidence by itself. Hosted/BYOC remains blocked until the named operator or customer supplies the external infrastructure, credentials, approvals, and rehearsal evidence below.

## Claim boundary and evidence boundary

- Enigma evidence covers Enigma-controlled vault state, receipt chains, relay records, witness checkpoints, gateway decisions, policy hashes, and verifier output.
- Do not claim provider deletion, model forgetting, semantic erasure, imported-source completeness, token ROI/profit/equity/revenue share, tamper-proof hardware, raw compute superiority, or compliance status.
- Do not place raw memory plaintext, prompts, transcripts, completion bodies, embeddings, customer secrets, or decrypted capsules in this packet, public proof examples, relay records, witness checkpoints, SIEM exports, or support tickets.
- CI/package/demo evidence, including local relay/gateway `--state-file` evidence, does not replace this acceptance packet.

## Required packet metadata

| Field | Value |
| --- | --- |
| Packet ID |  |
| Customer / tenant |  |
| Deployment mode | Hosted / BYOC / on-prem-air-gapped |
| Environment | production / staging / pilot |
| Target regions |  |
| Requested go-live date |  |
| Evidence repository / ticket |  |
| Packet owner |  |
| Last updated |  |
| Decision | blocked / go / no-go |

## Required owners

| Role | Named owner | Organization | Contact / escalation | Approval status | Date |
| --- | --- | --- | --- | --- | --- |
| Business owner |  |  |  | pending |  |
| Enigma operator owner |  |  |  | pending |  |
| Customer infrastructure owner |  |  |  | pending |  |
| Security owner |  |  |  | pending |  |
| Legal/privacy owner |  |  |  | pending |  |
| Incident commander |  |  |  | pending |  |
| Support/SLA owner |  |  |  | pending |  |
| Tenant policy owner |  |  |  | pending |  |
| Backup/restore owner |  |  |  | pending |  |
| KMS/secrets owner |  |  |  | pending |  |
| SIEM/log owner |  |  |  | pending |  |

## Required external inputs

| Input | Required evidence | Owner | Status | External blocker if missing |
| --- | --- | --- | --- | --- |
| Cloud account/project, VPC/network, cluster, or deployment target | Account/project ID or customer-controlled target reference; access path recorded outside this public packet if sensitive |  | pending | Hosted/BYOC cannot be called live. |
| Deployment credentials | Runtime secret reference and operator access approval; no secrets in repo or packet |  | pending | Deployment cannot proceed. |
| Domain and DNS | Domain, zone owner, DNS record plan, propagation evidence |  | pending | Public hosted endpoint cannot be called live. |
| TLS certificates | Certificate issuer/reference, renewal path, expiry alert |  | pending | Public endpoints cannot accept tenant traffic. |
| KMS/secrets manager | KMS/BYOK reference, key owner, rotation cadence, emergency rotation path |  | pending | Signing, storage, and service secrets are not production-ready. |
| Durable storage | Storage service/reference, encryption-at-rest setting, retention/legal-hold policy, migration owner |  | pending | Relay/gateway state cannot be treated as production durable; local `--state-file` JSON is demo evidence only. |
| Backup target and restore process | Backup scope, RPO/RTO, restore rehearsal evidence, restored verifier output |  | pending | Production recovery is unproven. |
| Monitoring and alerting | Health, latency, 5xx, signing failure, policy load failure, storage failure, plaintext-rejection spike, and certificate-expiry alerts |  | pending | Operator readiness is incomplete. |
| SIEM/log destination | Approved sink, minimized field list, sample export without raw memory plaintext |  | pending | Audit routing is incomplete. |
| Incident response contacts | Incident commander, security/legal contacts, escalation path, customer notification path |  | pending | Incident handling is not accepted. |
| Support and SLA terms | Support hours, severity definitions, response targets, escalation channel, maintenance window |  | pending | Customer-facing operations cannot be called live. |
| Legal/compliance review | Approved wording and status for any compliance-sensitive external statement |  | pending | Compliance-sensitive claims remain blocked. |

## Evidence table

Store evidence in the repository/ticket named above. Link only to approved locations; do not paste secrets or raw memory content.

| Evidence item | Minimum acceptable evidence | Link / reference | Owner | Status |
| --- | --- | --- | --- | --- |
| Package/release artifact | Package/image identifier and local release evidence reference |  |  | pending |
| Deployment manifest | Versioned manifest or infrastructure change ticket |  |  | pending |
| Runtime secrets injection | Secret references and runtime injection method, with no secret values |  |  | pending |
| Domain/TLS | DNS and HTTPS validation plus renewal alert |  |  | pending |
| Durable storage | Storage endpoint/reference, encryption setting, migration/rollback note |  |  | pending |
| Local state-file demo, if used | Relay/gateway state-file path, permission model, backup/restore note, and evidence that snapshots contain no raw memory plaintext |  |  | optional / demo-only |
| KMS/secrets | Key references/versions and rotation owner, no raw key material |  |  | pending |
| Tenant policy | Policy version/hash, approver, rollback version |  |  | pending |
| Gateway allow/deny checks | Signed decisions for approved allow and fail-closed deny cases using metadata/committed addresses only |  |  | pending |
| Relay plaintext rejection | Rejection of plaintext-looking fields; acceptance of opaque encrypted record metadata only |  |  | pending |
| Witness/checkpoint minimization | Checkpoint/root/order metadata only; no raw memory plaintext |  |  | pending |
| SIEM/log minimization | Sample event with receipt/policy/decision metadata only |  |  | pending |
| Offline verification | Verifier output for accepted proof bundle or restored evidence bundle |  |  | pending |
| Backup/restore rehearsal | Restore run result, RPO/RTO result, verifier output after restore |  |  | pending |
| Incident drill | Drill notes, commander, contacts, evidence preservation, communications path |  |  | pending |
| Support/SLA | Signed support model, escalation matrix, maintenance window |  |  | pending |
| Legal/compliance approval | Approved statement scope or explicit no-claim decision |  |  | pending |

## Go/no-go checklist

Mark **go** only when every required item is complete for the exact tenant/environment.

- [ ] Packet metadata and named owners are complete.
- [ ] Hosted/BYOC responsibility split is signed by the operator and, for BYOC, the customer.
- [ ] Domain, DNS, TLS, ingress, and renewal alerts are configured.
- [ ] Admin endpoints are private, authenticated, least-privilege, and network-restricted.
- [ ] KMS/secrets manager is configured; no secrets, vault bundles, private keys, or tenant credentials are in images, source, packets, logs, or proof artifacts.
- [ ] Durable storage is configured for required relay/gateway/witness/policy/audit state; local `--state-file` demo state is not counted as hosted/BYOC durable storage.
- [ ] Tenant policy owner approved policy version/hash, rollback version, retention, deletion/tombstone, legal hold, and audit route.
- [ ] SIEM/log exports are plaintext-minimized and approved by the SIEM/log owner.
- [ ] Monitoring and alerting are active for health, errors, signing, storage, policy load, plaintext rejection spikes, and certificate expiry.
- [ ] Backup/restore rehearsal succeeded in a non-production or approved rehearsal environment and restored evidence verifies offline.
- [ ] Incident drill completed with named commander, contacts, preservation path, customer notification path, and claim-bounded communication template.
- [ ] Support/SLA placeholders are replaced with approved customer-facing terms.
- [ ] Legal/privacy approved any external compliance-sensitive language, or the packet records that no compliance status is claimed.
- [ ] All external blockers are closed or the decision is **no-go**.

Decision rule: any unchecked item above is a **no-go** for live hosted/BYOC operation. Local package, CLI, Docker-demo, and runbook readiness may still be accepted separately.

Local `--state-file` evidence may be attached to show source/package demo continuity only. It is acceptable supporting evidence for local review when it stores relay opaque/hash records or gateway policy/minimized SIEM evidence and fails closed on malformed/plaintext-looking state. It is not acceptable evidence for production database readiness, KMS/secrets custody, tenant backup policy, legal hold, RPO/RTO, multi-instance consistency, or hosted/BYOC go-live.

## Rollback plan

| Rollback area | Required entry |
| --- | --- |
| Trigger conditions | Signing failure, policy misconfiguration, storage write failure, TLS/ingress failure, SIEM leak risk, plaintext admission, failed restore, or customer security request. |
| Owner |  |
| Last known-good package/image |  |
| Last known-good deployment manifest |  |
| Last known-good tenant policy hash/version |  |
| Data rollback boundary | Enigma-controlled state only; do not claim provider deletion or model forgetting. |
| Rollback steps | 1. Freeze policy/deploy changes. 2. Preserve plaintext-minimized evidence. 3. Revert manifest/package/policy through approved change path. 4. Verify health and offline evidence. 5. Notify approved contacts with observed facts only. |
| Customer approval required? | yes / no / condition |
| Verification after rollback |  |

## Backup/restore rehearsal

| Rehearsal item | Required result | Owner | Status |
| --- | --- | --- | --- |
| Backup scope | Includes required vault-adjacent state, proof bundles, policy versions, gateway decisions, relay/witness persistence, configuration, and deployment manifests as applicable |  | pending |
| RPO/RTO | Tenant-specific RPO/RTO recorded and met or variance approved |  | pending |
| Restore location | Non-production or approved isolated environment |  | pending |
| Restore verification | Restored proof bundles and policy evidence verify offline |  | pending |
| Log minimization | Backup/restore logs contain no raw memory plaintext or secrets |  | pending |
| Failure handling | Failed restore blocks go-live and has owner/date for remediation |  | pending |

## Incident drill

| Drill item | Required result | Owner | Status |
| --- | --- | --- | --- |
| Scenario exercised | Secret exposure / plaintext admission / policy bypass / restore failure / unauthorized access / data residency exception |  | pending |
| Incident commander | Named and reachable |  | pending |
| Evidence preservation | Receipts, policy versions, gateway decisions, logs, proof bundles, and deployment state preserved with restricted access |  | pending |
| Containment | Stop affected ingress/workflow, rotate credentials if needed, freeze policy changes if needed |  | pending |
| Communications | Customer/security/legal notifications use observed facts only and stay within Enigma proof boundaries |  | pending |
| Post-incident review | Remediation owner/date and acceptance retest recorded |  | pending |

## External blockers

If any item remains pending, keep the decision at **blocked** or **no-go** and record the blocker here.

| Blocker | External owner | Needed input / approval | Impact | Target date | Status |
| --- | --- | --- | --- | --- | --- |
| Domain/DNS not supplied |  |  | Hosted public endpoint cannot be live |  | pending |
| Cloud/customer deployment target not supplied |  |  | Hosted/BYOC runtime cannot be accepted |  | pending |
| TLS path not supplied |  |  | Tenant traffic cannot open |  | pending |
| KMS/secrets path not supplied |  |  | Secrets/key custody is not production-ready |  | pending |
| Durable storage/backup target not supplied |  |  | Recovery and persistence are unproven; local `--state-file` demo state does not close this blocker |  | pending |
| SIEM/log sink not supplied |  |  | Audit routing is incomplete |  | pending |
| Support/SLA and incident contacts not approved |  |  | Customer operations cannot be called live |  | pending |
| Legal/compliance approval not complete |  |  | Compliance-sensitive language remains blocked |  | pending |

## Final acceptance

| Approver | Role | Decision | Conditions | Date |
| --- | --- | --- | --- | --- |
|  | Operator owner | go / no-go |  |  |
|  | Security owner | go / no-go |  |  |
|  | Legal/privacy owner | go / no-go |  |  |
|  | Customer infrastructure owner (BYOC) | go / no-go |  |  |
|  | Support/SLA owner | go / no-go |  |  |

Final statement: this environment is not live until every required owner records **go**, every blocker is closed, and evidence links show the target hosted/BYOC infrastructure was configured and rehearsed. Otherwise, state the posture as local/package/demo ready with hosted/BYOC blocked on external infrastructure and approvals.
