Oshun Platform · Planning

V1 Launch Timeline — Phased Rollout Skeleton

A gate decision is a recorded artifact (decision, evidence links, dissents) in the launch-readiness review — the pattern the spec already requires (V1/features.md:5014, :6206-6209).

8sections6 minread4tables

On this page

Status: planning baseline, created 2026-06-12 to close V1_V7_PLAN_SET_AUDIT_2026-06-12.md §6.1(4) (no calendar/sequencing anywhere). Calendar dates are TBD; the structure, relative durations, cohort sizes, promotion criteria, and decision owners below are the commitments. T0 = the day Gate G0 passes. The launch phases instantiate the readiness ladder already named in the spec — internal dogfood → safety review → quality review → private beta → go/no-go → GA with canary analysis (V1/features.md:6206-6209) — and the canary percentages reuse the spec's own ramp schedule for workflow classes (1 % → 5 % → 25 % → 50 % → 100 %, V1/features.md:3576).

Cohort sizes and durations are planning assumptions adopted 2026-06-12; each carries its derivation inline.

Decision roles#

Role Authority
Launch Director owns every phase-promotion decision; sole authority to declare GA
Safety Lead (Lilith) veto at every gate (safety review is non-overridable)
SRE Lead capacity/DR/SLO sign-off at every gate
General Counsel per-region crypto gates (CRYPTO_REGULATORY_REVIEW §7)
Education Compliance Officer school-tenant gate (CHILD_SAFETY_COMPLIANCE §9)
Payments Lead payments-readiness sign-off
QA Lead quality review and automation-matrix completeness
Product Lead locale-dark decisions, beta-metric acceptance

A gate decision is a recorded artifact (decision, evidence links, dissents) in the launch-readiness review — the pattern the spec already requires (V1/features.md:5014, :6206-6209).


Gate G0 — Code-complete / readiness baseline (opens Phase 1)#

Entry evidence, all required:

  1. V1 Exit Criteria verified per the TODOS one-task-one-verification rule (V1/features.md:6211-6254; checkbox state is the only source of truth).
  2. Workflow-class release gates green for all five Living Scenes templates: continuity, determinism, watermark, cue policy, crisis, accessibility (V1/features.md:4483-4486).
  3. Tenant-isolation suite green (tests/security/tenant-isolation/, launch-gating per V1/ARCHITECTURE.md:1237-1239).
  4. C2PA SDK gap closed (V1/DEPENDENCIES.md §19; RISK_REGISTER R-09).
  5. Per-domain DB provisioning resolved (RISK_REGISTER R-17).
  6. DR-1 restore drill passed (SLO_AND_DR §6).
  7. Payments end-to-end on test substrate: regtest/testnet invoice → confirm → entitlement → refund → sweep for every rail, including induced reorgs (V1/DEPENDENCIES.md:435).
  8. Capacity load tests LT-1..LT-6 defined and runnable (passing required at G2, not here).

Decision owner: Launch Director, with QA Lead and SRE Lead co-sign.


Phase 1 — Internal dogfood (T0 → T0+30, minimum 30 days — hard floor)#

  • Cohort: all staff + ~50 friends-and-family accounts (≈ 150–250 users — planning assumption: large enough to exercise every template, locale spot-checks, and both mobile platforms daily; small enough that incidents are conversations, not tickets).
  • Scope: full product including crypto checkout on testnet-priced internal invoices; no school tenants, no real-money GA pricing.
  • Mandatory usage: every product/eng lead completes each of the five Living Scenes templates, one voice tutoring session, and one crypto payment per week — dogfood that nobody is forced to do does not happen.
  • Exit criteria (Gate G1):
    • ≥ 30 days elapsed, zero Sev-1 safety incidents, all dogfood Sev-2s closed.
    • Crash-free sessions ≥ 99.5 % both mobile platforms.
    • Safety review passed: crisis-frame, cue-policy, and PSE fixture suites re-run on the dogfood build (Safety Lead veto point).
    • Voice p95 and first-frame p95 within spec budgets at dogfood load.
    • Dogfood exit survey: ≥ 70 % of staff answer "ready for outsiders" (planning assumption: a deliberately blunt, low-tech leading indicator).
  • Decision owner: Launch Director; Safety Lead veto.

Phase 2 — Private beta (T0+30 → ≈ T0+90, three waves)#

Wave Start Cohort Composition
W1 G1 pass 500 invitees hand-picked contemplative-practice and educator communities; all 8 locales represented (derivation: ~60/locale gives usable per-locale eval samples)
W2 W1+14d 2,500 cumulative adds first non-school pilot tenants (2–3 orgs); App Review dry-run submission happens here (RISK_REGISTER R-11)
W3 W2+14d 10,000 cumulative adds 3–5 school pilot tenants — only if the school-tenant gate has passed (CHILD_SAFETY_COMPLIANCE §9); otherwise W3 proceeds without schools and school onboarding decouples from GA
  • Real payments switch on in W2 for regions whose crypto go/no-go gate has passed (CRYPTO_REGULATORY_REVIEW §7); unpassed regions see entitlement trials only.
  • Wave-promotion criteria (each wave): previous wave ≥ 14 days; activation (completed first Living Scene or tutoring session within 48 h of signup) ≥ 40 %; D7 retention ≥ 25 % (planning assumptions: mid-range consumer-subscription benchmarks — these are tripwires for investigation, not vanity targets; Product Lead may promote with a written rationale if a metric misses but diagnosis is benign); support contact rate < 8 tickets / 100 WAU; no SLO over error budget (SLO_AND_DR §2).
  • Exit criteria (Gate G2):
    • Load tests LT-1..LT-6 passed against the beta-validated capacity model (CAPACITY_MODEL §7), with observed beta attach rates folded into the re-forecast (§8).
    • DR-2 region-loss game day passed (SLO_AND_DR §6).
    • Beta metrics accepted by Product Lead; blocking-issue list empty (V1/features.md:6206-6207).
    • Locale decision recorded per locale: launch or launch-dark (RISK_REGISTER R-15).
    • Payments: ≥ 500 real settled invoices across ≥ 5 rails with confirmation success ≥ 99.5 % and zero entitlement-grant errors; refund drill executed on mainnet (Payments Lead sign-off).
    • App Store / Play approvals in hand (or the no-paywall iOS contingency invoked, R-11).
  • Decision owners: Launch Director; Safety Lead veto; SRE, Payments, QA co-sign; General Counsel for each payments region; Education Compliance Officer for the school wave.

Phase 3 — Canary GA ramp (≈ T0+90 → T0+120)#

Signup throttle opens to the public in steps using the spec's ramp schedule (V1/features.md:3576). "Percentage" = fraction of the public waitlist/signup inflow admitted; existing beta users are unaffected.

Step Admission Soak before promotion Promotion criteria (all required)
C1 1 % 72 h SLO burn < 1× on every surface; zero Sev-1; safety eval deltas zero vs G2 baseline; payments confirmation ≥ 99.5 %; capacity headroom ≥ 2× current step (CAPACITY_MODEL §8)
C2 5 % 72 h C1 criteria + support contact rate stable (< 1.5× beta rate)
C3 25 % 72 h C2 criteria + GPU unit economics within 1.5× model (RISK_REGISTER R-04 trigger not firing)
C4 50 % 48 h C3 criteria + DR-3 evidence complete (SLO_AND_DR §6)
C5 100 % = Gate G3, below
  • Rollback triggers (any step, automatic halt + Launch Director page): SLO burn ≥ 6× over 6 h on any 99.9-tier surface; any Sev-1 safety incident; any crisis-path failure (Sev-1 by definition, SLO_AND_DR §1); sanctions screening hit mishandled; queue BLACK state > 30 min. Halt = freeze admission at current step; rollback = re-throttle to previous step (the product itself rolls back by workflow-class version per V1/features.md:4487-4490).
  • Decision owner per promotion: Launch Director with SRE Lead co-sign; Safety Lead veto standing.

Gate G3 — GA declaration#

All of: C4 soak clean; every RED risk in RISK_REGISTER has its mitigation verified in place (not merely written); public status page, store listings, deep links live (V1/features.md:6242-6243); runbook inventory complete (V1/features.md:6200-6202); operator training done (:6203-6205); region payment-gate map final (CRYPTO_REGULATORY_REVIEW §7 table); SLO dashboard public-internal with 30 days of history.

Decision owner: Launch Director — sole authority, recorded go/no-go with every co-signer's evidence attached (V1/features.md:6207).

Phase 4 — Hypercare (GA → GA+30)#

  • War-room staffing: SRE + Safety + Payments on-call rotations doubled; daily launch-health review against the SLO dashboard.
  • Canary analysis continues on every deploy (the spec's post-deploy monitoring + canary analysis requirement, V1/features.md:6208-6209).
  • Weekly capacity re-forecast (CAPACITY_MODEL §8) and risk-register re-score with observed data (RISK_REGISTER maintenance section).
  • Exit (Gate G4, GA+30): hand off from launch governance to steady-state ops; postmortem of the launch itself; risk register L/I re-scored; this document archived with actuals annotated next to every assumption. Decision owner: Launch Director.

Decoupled tracks (deliberately not on the GA critical path)#

Track Gate Reason
School tenants CHILD_SAFETY_COMPLIANCE §9 gate, any time ≥ W3 consumer GA must not pressure child-safety sign-off, and vice versa
Per-region crypto checkout CRYPTO_REGULATORY_REVIEW §7 per region regions open independently; a blocked region never blocks GA elsewhere
Locale-dark locales Product Lead decision at G2, revisited monthly parity-failing locales launch when parity evals pass, not when marketing wants
Fiat rails (V1.x) own mini-gate post-GA spec'd as V1.x optional (V1/DEPENDENCIES.md:444-450)