# V1 Launch Timeline — Phased Rollout Skeleton

Status: planning baseline, created 2026-06-12 to close
`V1_V7_PLAN_SET_AUDIT_2026-06-12.md` §6.1(4) (no calendar/sequencing anywhere).
Calendar dates are TBD; the structure, relative durations, cohort sizes,
promotion criteria, and decision owners below are the commitments. **T0** =
the day Gate G0 passes. The launch phases instantiate the readiness ladder
already named in the spec — internal dogfood → safety review → quality review
→ private beta → go/no-go → GA with canary analysis
(`V1/features.md:6206-6209`) — and the canary percentages reuse the spec's own
ramp schedule for workflow classes (1 % → 5 % → 25 % → 50 % → 100 %,
`V1/features.md:3576`).

Cohort sizes and durations are planning assumptions adopted 2026-06-12; each
carries its derivation inline.

## Decision roles

| Role | Authority |
| ---- | --------- |
| **Launch Director** | owns every phase-promotion decision; sole authority to declare GA |
| **Safety Lead (Lilith)** | veto at every gate (safety review is non-overridable) |
| **SRE Lead** | capacity/DR/SLO sign-off at every gate |
| **General Counsel** | per-region crypto gates (CRYPTO_REGULATORY_REVIEW §7) |
| **Education Compliance Officer** | school-tenant gate (CHILD_SAFETY_COMPLIANCE §9) |
| **Payments Lead** | payments-readiness sign-off |
| **QA Lead** | quality review and automation-matrix completeness |
| **Product Lead** | locale-dark decisions, beta-metric acceptance |

A gate decision is a recorded artifact (decision, evidence links, dissents) in
the launch-readiness review — the pattern the spec already requires
(`V1/features.md:5014`, `:6206-6209`).

---

## Gate G0 — Code-complete / readiness baseline (opens Phase 1)

**Entry evidence, all required:**

1. V1 Exit Criteria verified per the TODOS one-task-one-verification rule
   (`V1/features.md:6211-6254`; checkbox state is the only source of truth).
2. Workflow-class release gates green for all five Living Scenes templates:
   continuity, determinism, watermark, cue policy, crisis, accessibility
   (`V1/features.md:4483-4486`).
3. Tenant-isolation suite green (`tests/security/tenant-isolation/`,
   launch-gating per `V1/ARCHITECTURE.md:1237-1239`).
4. C2PA SDK gap closed (`V1/DEPENDENCIES.md` §19; RISK_REGISTER R-09).
5. Per-domain DB provisioning resolved (RISK_REGISTER R-17).
6. DR-1 restore drill passed (SLO_AND_DR §6).
7. Payments end-to-end on test substrate: regtest/testnet invoice → confirm →
   entitlement → refund → sweep for every rail, including induced reorgs
   (`V1/DEPENDENCIES.md:435`).
8. Capacity load tests LT-1..LT-6 **defined and runnable** (passing required
   at G2, not here).

**Decision owner:** Launch Director, with QA Lead and SRE Lead co-sign.

---

## Phase 1 — Internal dogfood (T0 → T0+30, minimum 30 days — hard floor)

- **Cohort:** all staff + ~50 friends-and-family accounts (≈ 150–250 users —
  planning assumption: large enough to exercise every template, locale
  spot-checks, and both mobile platforms daily; small enough that incidents
  are conversations, not tickets).
- **Scope:** full product including crypto checkout on testnet-priced
  internal invoices; **no school tenants, no real-money GA pricing.**
- **Mandatory usage:** every product/eng lead completes each of the five
  Living Scenes templates, one voice tutoring session, and one crypto
  payment per week — dogfood that nobody is forced to do does not happen.
- **Exit criteria (Gate G1):**
  - ≥ 30 days elapsed, zero Sev-1 safety incidents, all dogfood Sev-2s closed.
  - Crash-free sessions ≥ 99.5 % both mobile platforms.
  - Safety review passed: crisis-frame, cue-policy, and PSE fixture suites
    re-run on the dogfood build (Safety Lead veto point).
  - Voice p95 and first-frame p95 within spec budgets at dogfood load.
  - Dogfood exit survey: ≥ 70 % of staff answer "ready for outsiders"
    (planning assumption: a deliberately blunt, low-tech leading indicator).
- **Decision owner:** Launch Director; Safety Lead veto.

## Phase 2 — Private beta (T0+30 → ≈ T0+90, three waves)

| Wave | Start | Cohort | Composition |
| ---- | ----- | ------ | ----------- |
| W1 | G1 pass | **500 invitees** | hand-picked contemplative-practice and educator communities; all 8 locales represented (derivation: ~60/locale gives usable per-locale eval samples) |
| W2 | W1+14d | **2,500 cumulative** | adds first non-school pilot tenants (2–3 orgs); App Review dry-run submission happens here (RISK_REGISTER R-11) |
| W3 | W2+14d | **10,000 cumulative** | adds 3–5 school pilot tenants — **only if** the school-tenant gate has passed (CHILD_SAFETY_COMPLIANCE §9); otherwise W3 proceeds without schools and school onboarding decouples from GA |

- **Real payments switch on in W2** for regions whose crypto go/no-go gate
  has passed (CRYPTO_REGULATORY_REVIEW §7); unpassed regions see entitlement
  trials only.
- **Wave-promotion criteria (each wave):** previous wave ≥ 14 days; activation
  (completed first Living Scene or tutoring session within 48 h of signup)
  ≥ 40 %; D7 retention ≥ 25 % (planning assumptions: mid-range
  consumer-subscription benchmarks — these are *tripwires for investigation*,
  not vanity targets; Product Lead may promote with a written rationale if a
  metric misses but diagnosis is benign); support contact rate < 8 tickets /
  100 WAU; no SLO over error budget (SLO_AND_DR §2).
- **Exit criteria (Gate G2):**
  - Load tests LT-1..LT-6 passed against the beta-validated capacity model
    (CAPACITY_MODEL §7), with observed beta attach rates folded into the
    re-forecast (§8).
  - DR-2 region-loss game day passed (SLO_AND_DR §6).
  - Beta metrics accepted by Product Lead; blocking-issue list empty
    (`V1/features.md:6206-6207`).
  - Locale decision recorded per locale: launch or launch-dark
    (RISK_REGISTER R-15).
  - Payments: ≥ 500 real settled invoices across ≥ 5 rails with confirmation
    success ≥ 99.5 % and zero entitlement-grant errors; refund drill executed
    on mainnet (Payments Lead sign-off).
  - App Store / Play approvals in hand (or the no-paywall iOS contingency
    invoked, R-11).
- **Decision owners:** Launch Director; Safety Lead veto; SRE, Payments, QA
  co-sign; General Counsel for each payments region; Education Compliance
  Officer for the school wave.

## Phase 3 — Canary GA ramp (≈ T0+90 → T0+120)

Signup throttle opens to the public in steps using the spec's ramp schedule
(`V1/features.md:3576`). "Percentage" = fraction of the public waitlist/signup
inflow admitted; existing beta users are unaffected.

| Step | Admission | Soak before promotion | Promotion criteria (all required) |
| ---- | --------- | --------------------- | --------------------------------- |
| C1 | 1 % | 72 h | SLO burn < 1× on every surface; zero Sev-1; safety eval deltas zero vs G2 baseline; payments confirmation ≥ 99.5 %; capacity headroom ≥ 2× current step (CAPACITY_MODEL §8) |
| C2 | 5 % | 72 h | C1 criteria + support contact rate stable (< 1.5× beta rate) |
| C3 | 25 % | 72 h | C2 criteria + GPU unit economics within 1.5× model (RISK_REGISTER R-04 trigger not firing) |
| C4 | 50 % | 48 h | C3 criteria + DR-3 evidence complete (SLO_AND_DR §6) |
| C5 | 100 % | — | = Gate G3, below |

- **Rollback triggers (any step, automatic halt + Launch Director page):**
  SLO burn ≥ 6× over 6 h on any 99.9-tier surface; any Sev-1 safety incident;
  any crisis-path failure (Sev-1 by definition, SLO_AND_DR §1); sanctions
  screening hit mishandled; queue BLACK state > 30 min. Halt = freeze
  admission at current step; rollback = re-throttle to previous step (the
  product itself rolls back by workflow-class version per
  `V1/features.md:4487-4490`).
- **Decision owner per promotion:** Launch Director with SRE Lead co-sign;
  Safety Lead veto standing.

## Gate G3 — GA declaration

All of: C4 soak clean; every RED risk in RISK_REGISTER has its mitigation
verified in place (not merely written); public status page, store listings,
deep links live (`V1/features.md:6242-6243`); runbook inventory complete
(`V1/features.md:6200-6202`); operator training done (`:6203-6205`); region
payment-gate map final (CRYPTO_REGULATORY_REVIEW §7 table); SLO dashboard
public-internal with 30 days of history.

**Decision owner:** Launch Director — sole authority, recorded go/no-go with
every co-signer's evidence attached (`V1/features.md:6207`).

## Phase 4 — Hypercare (GA → GA+30)

- War-room staffing: SRE + Safety + Payments on-call rotations doubled;
  daily launch-health review against the SLO dashboard.
- Canary analysis continues on every deploy (the spec's post-deploy
  monitoring + canary analysis requirement, `V1/features.md:6208-6209`).
- Weekly capacity re-forecast (CAPACITY_MODEL §8) and risk-register re-score
  with observed data (RISK_REGISTER maintenance section).
- **Exit (Gate G4, GA+30):** hand off from launch governance to steady-state
  ops; postmortem of the launch itself; risk register L/I re-scored; this
  document archived with actuals annotated next to every assumption.
  Decision owner: Launch Director.

## Decoupled tracks (deliberately not on the GA critical path)

| Track | Gate | Reason |
| ----- | ---- | ------ |
| School tenants | CHILD_SAFETY_COMPLIANCE §9 gate, any time ≥ W3 | consumer GA must not pressure child-safety sign-off, and vice versa |
| Per-region crypto checkout | CRYPTO_REGULATORY_REVIEW §7 per region | regions open independently; a blocked region never blocks GA elsewhere |
| Locale-dark locales | Product Lead decision at G2, revisited monthly | parity-failing locales launch when parity evals pass, not when marketing wants |
| Fiat rails (V1.x) | own mini-gate post-GA | spec'd as V1.x optional (`V1/DEPENDENCIES.md:444-450`) |
