[{"data":1,"prerenderedAt":355},["ShallowReactive",2],{"navigation":3,"\u002Foperations\u002Fincidents":250,"\u002Foperations\u002Fincidents-surround":350},[4,28,56,91,117,135,169,224],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Start here","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Decisions and open gates","\u002Fgetting-started\u002Fdecisions","1.getting-started\u002F2.decisions",{"title":16,"path":17,"stem":18},"Scope and non-goals","\u002Fgetting-started\u002Fscope","1.getting-started\u002F3.scope",{"title":20,"path":21,"stem":22},"Organization pilot","\u002Fgetting-started\u002Fpilot","1.getting-started\u002F4.pilot",{"title":24,"path":25,"stem":26},"Economics and quotas","\u002Fgetting-started\u002Feconomics","1.getting-started\u002F5.economics","i-lucide-compass",{"title":29,"path":30,"stem":31,"children":32,"icon":55},"Architecture","\u002Farchitecture","2.architecture\u002F1.index",[33,35,39,43,47,51],{"title":34,"path":30,"stem":31},"System architecture",{"title":36,"path":37,"stem":38},"Trust zones","\u002Farchitecture\u002Ftrust-zones","2.architecture\u002F2.trust-zones",{"title":40,"path":41,"stem":42},"Control plane","\u002Farchitecture\u002Fcontrol-plane","2.architecture\u002F3.control-plane",{"title":44,"path":45,"stem":46},"Organization tenancy","\u002Farchitecture\u002Ftenancy","2.architecture\u002F4.tenancy",{"title":48,"path":49,"stem":50},"Core data model","\u002Farchitecture\u002Fdata-model","2.architecture\u002F5.data-model",{"title":52,"path":53,"stem":54},"Codebase organization","\u002Farchitecture\u002Fcodebase","2.architecture\u002F6.codebase","i-lucide-layers",{"title":57,"icon":58,"path":59,"stem":60,"children":61,"page":90},"Identity and security","i-lucide-shield-check","\u002Fsecurity","3.security",[62,66,70,74,78,82,86],{"title":63,"path":64,"stem":65},"Identity and sessions","\u002Fsecurity\u002Fidentity","3.security\u002F1.identity",{"title":67,"path":68,"stem":69},"Domains and TLS","\u002Fsecurity\u002Fdomains","3.security\u002F2.domains",{"title":71,"path":72,"stem":73},"Ingress and egress","\u002Fsecurity\u002Fnetworking","3.security\u002F3.networking",{"title":75,"path":76,"stem":77},"Access policies and WAF-lite","\u002Fsecurity\u002Faccess-policies","3.security\u002F4.access-policies",{"title":79,"path":80,"stem":81},"Secrets and integrations","\u002Fsecurity\u002Fsecrets-integrations","3.security\u002F5.secrets-integrations",{"title":83,"path":84,"stem":85},"Governance and ownership","\u002Fsecurity\u002Fgovernance","3.security\u002F6.governance",{"title":87,"path":88,"stem":89},"Threat model","\u002Fsecurity\u002Fthreat-model","3.security\u002F7.threat-model",false,{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":90},"Building applications","i-lucide-code","\u002Fdevelopment","4.development",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"AI and MCP","\u002Fdevelopment\u002Fai-mcp","4.development\u002F1.ai-mcp",{"title":102,"path":103,"stem":104},"Source control","\u002Fdevelopment\u002Fsource-control","4.development\u002F2.source-control",{"title":106,"path":107,"stem":108},"Sandboxed builds","\u002Fdevelopment\u002Fbuilds","4.development\u002F3.builds",{"title":110,"path":111,"stem":112},"Runtime contract and SDK","\u002Fdevelopment\u002Fruntime-contract","4.development\u002F4.runtime-contract",{"title":114,"path":115,"stem":116},"APIs and protocols","\u002Fdevelopment\u002Fapi","4.development\u002F5.api",{"title":118,"icon":119,"path":120,"stem":121,"children":122,"page":90},"Runtime and delivery","i-lucide-rocket","\u002Fdelivery","5.delivery",[123,127,131],{"title":124,"path":125,"stem":126},"Runtime clusters and previews","\u002Fdelivery\u002Fruntime-clusters","5.delivery\u002F1.runtime-clusters",{"title":128,"path":129,"stem":130},"Deployments and approvals","\u002Fdelivery\u002Fdeployments","5.delivery\u002F2.deployments",{"title":132,"path":133,"stem":134},"Databases and recovery","\u002Fdelivery\u002Fdata-recovery","5.delivery\u002F3.data-recovery",{"title":136,"icon":137,"path":138,"stem":139,"children":140,"page":90},"Operations","i-lucide-activity","\u002Foperations","6.operations",[141,145,149,153,157,161,165],{"title":142,"path":143,"stem":144},"Observability and audit","\u002Foperations\u002Fobservability","6.operations\u002F1.observability",{"title":146,"path":147,"stem":148},"Operating model","\u002Foperations\u002Foperating-model","6.operations\u002F2.operating-model",{"title":150,"path":151,"stem":152},"Deploy and roll back","\u002Foperations\u002Fdeploy-rollback","6.operations\u002F3.deploy-rollback",{"title":154,"path":155,"stem":156},"Back up and restore","\u002Foperations\u002Fbackup-restore","6.operations\u002F4.backup-restore",{"title":158,"path":159,"stem":160},"Upgrade and patch","\u002Foperations\u002Fupgrades","6.operations\u002F5.upgrades",{"title":162,"path":163,"stem":164},"Rotate keys and credentials","\u002Foperations\u002Fkey-rotation","6.operations\u002F6.key-rotation",{"title":166,"path":167,"stem":168},"Incidents and access revocation","\u002Foperations\u002Fincidents","6.operations\u002F7.incidents",{"title":170,"path":171,"stem":172,"children":173,"icon":223},"Implementation plan","\u002Froadmap","7.roadmap\u002F01.index",[174,175,179,183,187,191,195,199,203,207,211,215,219],{"title":170,"path":171,"stem":172},{"title":176,"path":177,"stem":178},"Phase 0: architecture spikes and ADRs","\u002Froadmap\u002Fphase-0","7.roadmap\u002F02.phase-0",{"title":180,"path":181,"stem":182},"Phase 1: control-plane foundation","\u002Froadmap\u002Fphase-1","7.roadmap\u002F03.phase-1",{"title":184,"path":185,"stem":186},"Phase 2: managed source and change sets","\u002Froadmap\u002Fphase-2","7.roadmap\u002F04.phase-2",{"title":188,"path":189,"stem":190},"Phase 3: sandboxed build system","\u002Froadmap\u002Fphase-3","7.roadmap\u002F05.phase-3",{"title":192,"path":193,"stem":194},"Phase 4: runtime and data plane","\u002Froadmap\u002Fphase-4","7.roadmap\u002F06.phase-4",{"title":196,"path":197,"stem":198},"Phase 5: deployment, preview, migration, and recovery","\u002Froadmap\u002Fphase-5","7.roadmap\u002F07.phase-5",{"title":200,"path":201,"stem":202},"Phase 6: Entra identity and security policy","\u002Froadmap\u002Fphase-6","7.roadmap\u002F08.phase-6",{"title":204,"path":205,"stem":206},"Phase 7: MCP and AI-native workflow","\u002Froadmap\u002Fphase-7","7.roadmap\u002F09.phase-7",{"title":208,"path":209,"stem":210},"Phase 8: Pilot hardening","\u002Froadmap\u002Fphase-8","7.roadmap\u002F10.phase-8",{"title":212,"path":213,"stem":214},"Phase 9: developer hybrid and v1 GA","\u002Froadmap\u002Fphase-9","7.roadmap\u002F11.phase-9",{"title":216,"path":217,"stem":218},"Test strategy","\u002Froadmap\u002Ftesting","7.roadmap\u002F12.testing",{"title":220,"path":221,"stem":222},"Definition of done","\u002Froadmap\u002Fdefinition-of-done","7.roadmap\u002F13.definition-of-done","i-lucide-list-checks",{"title":225,"icon":226,"path":227,"stem":228,"children":229,"page":90},"Reference","i-lucide-book-open","\u002Freference","8.reference",[230,234,238,242,246],{"title":231,"path":232,"stem":233},"Plan coverage","\u002Freference\u002Fplan-coverage","8.reference\u002F1.plan-coverage",{"title":235,"path":236,"stem":237},"Decision register","\u002Freference\u002Fdecisions","8.reference\u002F2.decisions",{"title":239,"path":240,"stem":241},"Glossary","\u002Freference\u002Fglossary","8.reference\u002F3.glossary",{"title":243,"path":244,"stem":245},"Sources","\u002Freference\u002Fsources","8.reference\u002F4.sources",{"title":247,"path":248,"stem":249},"Contributing and docs access","\u002Freference\u002Fcontributing","8.reference\u002F5.contributing",{"id":251,"title":166,"body":252,"description":343,"extension":344,"links":345,"meta":346,"navigation":347,"path":167,"seo":348,"stem":168,"__hash__":349},"docs\u002F6.operations\u002F7.incidents.md",{"type":253,"value":254,"toc":333},"minimark",[255,266,271,274,278,303,307,310,313,317,320,324],[256,257,258],"warning",{},[259,260,261,265],"p",{},[262,263,264],"strong",{},"Procedure specification — not yet operationally validated."," Before pilot use, the operations owner must attach exact console\u002FAPI\u002FCLI actions, environment identifiers, access requirements, escalation contacts, and rehearsal evidence. No platform command names or completed drills are implied here.",[267,268,270],"h2",{"id":269},"readiness","Readiness",[259,272,273],{},"Before the pilot, operations must assign incident ownership, an on-call route, pilot organization contacts, a secure evidence location, severity criteria, and communication\u002Fescalation timing. Exercise them in the Phase 8 tabletop. This document does not invent customer contacts or contractual response times.",[267,275,277],{"id":276},"respond","Respond",[279,280,281,285,288,291,294,297,300],"ol",{},[282,283,284],"li",{},"Record an incident ID, detection time, symptoms, affected organizations\u002Fapps\u002Fenvironments, and trace\u002Frequest IDs. Preserve append-only audit history.",[282,286,287],{},"Establish scope using redacted telemetry: identity abuse, cross-tenant access, malicious build\u002Fruntime behavior, secret exposure, policy bypass, data corruption, or availability failure.",[282,289,290],{},"Contain at the narrowest effective boundary: revoke grants\u002Fsessions, suspend a route\u002Fapp, deny an integration\u002Fegress capability, isolate a workload\u002Fcluster, or pause builds\u002Fdeployments.",[282,292,293],{},"Escalate suspected isolation failure to platform security. Preserve relevant evidence without copying production bodies, tokens, raw secrets, or sensitive personal data into support tools.",[282,295,296],{},"Select a reviewed recovery path: compatible artifact rollback, isolated DB restore, key rotation, or cluster reconstruction. Record the human decision and possible data loss.",[282,298,299],{},"Validate policy, identity, tenant boundaries, app behavior, and monitoring before restoring normal access.",[282,301,302],{},"Record resolution, impact, timeline, corrective actions, owners, and follow-up tests. Corrections to audit records create new events.",[267,304,306],{"id":305},"user-deactivation","User deactivation",[259,308,309],{},"On SCIM deactivation or an authorized access-removal event, disable the organization membership; revoke console and app access\u002Fsessions according to the documented revocation bounds; revoke MCP grants and developer credentials\u002Fdirect Git access. Reconcile group\u002Frole removal and pending operations. Test that revoked access fails.",[259,311,312],{},"Retain historical attribution. Keep production applications organization-owned and running according to policy; reassign or flag missing business\u002Ftechnical owners and alert administrators. Do not delete apps merely because their creator leaves.",[267,314,316],{"id":315},"provider-and-edge-outages","Provider and edge outages",[259,318,319],{},"For AI vendor failure, protect existing apps and use the approved manual maintenance path; AI availability is not a prerequisite for serving immutable deployments. For an edge-path outage, follow the validated recovery design without exposing an unauthenticated origin. For control-plane connectivity loss, apply the documented cache freshness, revocation, and fail-closed policy; those bounds must be established before the pilot.",[267,321,323],{"id":322},"pilot-data-boundary","Pilot data boundary",[259,325,326,327,332],{},"If regulated data is discovered, contain access and involve the organization's designated security\u002Fprivacy contacts under the agreed incident process. Do not copy it into AI prompts, ordinary logs, or support records. A future regulated tier requires the separate controls described in the ",[328,329,331],"a",{"href":330},"\u002Fgetting-started\u002Fpilot#regulated-data-boundary","pilot regulated-data boundary",".",{"title":334,"searchDepth":335,"depth":336,"links":337},"",1,2,[338,339,340,341,342],{"id":269,"depth":336,"text":270},{"id":276,"depth":336,"text":277},{"id":305,"depth":336,"text":306},{"id":315,"depth":336,"text":316},{"id":322,"depth":336,"text":323},"Triage, containment, identity deactivation, orphaned apps, and recovery evidence.","md",null,{},true,{"title":166,"description":343},"rkYsX29fM77nJeFMW6FTCtHHvxS_Pihiw--roTapiYA",[351,353],{"title":162,"path":163,"stem":164,"description":352,"children":-1},"Inventory, staged rotation, revocation, and recovery checks for platform credentials.",{"title":170,"path":171,"stem":172,"description":354,"children":-1},"Ten phases from architecture validation to the organization pilot and v1 general availability.",1790019415368]