# P3-WP14 enterprise pilot UAT plan and local engineering report ## Result Current reportable state: `ENGINEERING_BASELINE_COMPLETE_ENTERPRISE_UAT_BLOCKED`. The 本地工程验收 boundary includes a Compose-parsed input closure and a lock/nonce/TTL-protected verification ledger; it does not represent 企业正式 UAT, a production deployment, or a signed release. The shared source/deployment migration head is `20260818_559` and no WP14 migration is required because this work package adds evidence and contract artifacts only. ## Acceptance layers | Layer | Evidence allowed | Current state | |---|---|---| | Local engineering acceptance | Checked-in contract tests, closed fixtures, local-only PostgreSQL evidence, documentation integrity and source/deployment parity | PASS_LOCAL when the fresh command ledger passes | | Formal second isolated environment | Same signed version in a second authorized isolated environment | BLOCKED_EXTERNAL: current manifest is unsigned and the enterprise environment/signature are TBD_EXTERNAL | | Local configuration portability rehearsal | Two non-secret local labels with restricted difference summary, bound to an unsigned manifest digest | PASS_LOCAL; not a signed-version or second enterprise environment result | | Enterprise formal UAT | Named enterprise users, approved sources, target environment, integrations, target-scale result, training records, P0/P1 decision, five-party signatures | BLOCKED_EXTERNAL | | Production acceptance | Approved change, deployed signed artifact, operations observation and recovery evidence | BLOCKED_EXTERNAL | ## Scope and roles The machine-readable matrix is `docs/acceptance/P3_WP14_UAT_CASES.json`. It covers P3-WP01–P3-WP13 local engineering paths and the following role boundaries: administrator, governance user, ordinary user, data owner, operations, security, and audit. It covers interfaces, database/ACL paths, available local browser/UI evidence, enterprise-integration boundaries, migration `20260818_559`, upgrade, rollback, restore, target scale, fault, security, training, operations, and five-party signing. The validation is a third-stage change-range regression, not a blanket repository test. A test or evidence path may prove local behavior only. The matrix records unprovided enterprise inputs as `TBD_EXTERNAL` or `BLOCKED_EXTERNAL` rather than synthesizing results. 任何本地 fixture、容器、检查清单或开发者测试均不能替代企业正式 UAT。 ## P0 and P1 gate Within the fresh local command set listed in the evidence report, P0:0 and 未关闭 P1:0. This is a constrained engineering observation, not a claim about enterprise or production conditions. Enterprise P0/P1 state remains TBD_EXTERNAL. An unclosed enterprise P1 needs a formal decision by actual business and technical owners; absent that decision it blocks formal acceptance. ## Enterprise UAT sequence 1. The enterprise assigns product, business, technical, security, and operations owners. 2. Owners provide approved IdP, two read-only sources, network, monitoring/notification/ITSM, security/legal, infrastructure, third-domain, AI, and conditional-package inputs as applicable. 3. The enterprise binds real roles, approved desensitized samples, metrics, target-scale workload, SLO/RTO/RPO, and rollback decision to the signed version. 4. Execute every `ENTERPRISE_FORMAL` case and attach durable evidence without raw data or secrets. 5. Resolve P0; resolve P1 or append the formal business/technical decision. 6. Complete user and operations training, target-environment upgrade/rollback/restore, handover, and five-party signoff. ## Residual external gates Pilot environment, five named signers, IdP, sources, network, monitoring, SMTP, collaboration, ITSM, security/legal, infrastructure, enterprise model, multi-tenancy, BI/AI, cost, plugin policy, target-scale results, and remote-save authorization are all `TBD_EXTERNAL` or `BLOCKED_EXTERNAL`. No external enterprise system is contacted by P3-WP14. ## Phase 3 completion assessment for UAT Round 1 Assessment date: `2026-08-18`. This assessment distinguishes implementation readiness from enterprise acceptance. | Work package | Engineering state | UAT interpretation | |---|---|---| | P3-WP00 | `COMPLETE`; enterprise confirmation `TBD_EXTERNAL` | Scope, metrics, ownership and enterprise inputs are defined, but the pilot goal is not confirmed. | | P3-WP01 | `ENGINEERING_READY_BLOCKED_EXTERNAL` | Acceptance package is ready; actual enterprise users, sources, infrastructure and training remain external. | | P3-WP02 | `ENGINEERING_COMPLETE_ENTERPRISE_IDP_UAT_BLOCKED` | Identity engineering is complete; real IdP and enterprise claims must be supplied. | | P3-WP03 | `ENGINEERING_COMPLETE_ENTERPRISE_SOURCE_UAT_BLOCKED` | Connector engineering is complete; two approved read-only sources and network access are missing. | | P3-WP04 | `ENGINEERING_COMPLETE_ENTERPRISE_EDGE_UAT_BLOCKED` | Edge engineering is complete; enterprise source, network and security/legal validation are missing. | | P3-WP05 | `ENGINEERING_COMPLETE_ENTERPRISE_OBSERVABILITY_UAT_BLOCKED` | Local observability paths are complete; monitoring, SMTP, collaboration and ITSM integrations are missing. | | P3-WP06 | `ENGINEERING_COMPLETE_ENTERPRISE_TRUSTED_DELIVERY_UAT_BLOCKED` | Trusted-delivery engineering is complete; enterprise identity, network and security/legal approval are missing. | | P3-WP07 | `ENGINEERING_COMPLETE_ENTERPRISE_INFRASTRUCTURE_UAT_BLOCKED` | Delivery artifacts are ready; target platform, registry, certificates, SLA and recovery inputs are missing. | | P3-WP08 | `ENGINEERING_COMPLETE_ENTERPRISE_THIRD_DOMAIN_UAT_BLOCKED` | Third-domain engineering is complete; the real domain, source, network and security/legal inputs are missing. | | P3-WP09 | `ENGINEERING_COMPLETE_ENTERPRISE_AI_UAT_BLOCKED` | Agent/model governance engineering is complete; approved model, budget, sandbox, golden set and red-team inputs are missing. | | P3-WP10 | `ENGINEERING_BASELINE_COMPLETE_MULTI_TENANCY_ACTIVATION_BLOCKED` | Multi-tenancy baseline is complete but must remain disabled until the delivery model and isolation level are approved. | | P3-WP11 | `ENGINEERING_BASELINE_COMPLETE_BI_AI_ACTIVATION_BLOCKED` | BI/AI catalog baseline is complete but enterprise provider activation is not approved. | | P3-WP12 | `ENGINEERING_BASELINE_COMPLETE_SHOWBACK_ACTIVATION_BLOCKED` | Showback baseline is complete; enterprise cost sources and finance approval are missing. | | P3-WP13 | `ENGINEERING_BASELINE_COMPLETE_PLUGIN_ACTIVATION_BLOCKED` | Plugin baseline is complete but enterprise trust, registry, CA, licence and sandbox decisions are missing. | | P3-WP14 | `ENGINEERING_BASELINE_COMPLETE_ENTERPRISE_UAT_BLOCKED` | Local acceptance and handover baseline is complete; formal enterprise UAT has not started. | The current machine matrix contains 30 cases: 20 `PASS_LOCAL`, 9 `BLOCKED_EXTERNAL`, and 1 `TBD_EXTERNAL`. This supports opening UAT preparation, not formal UAT execution. ## UAT Round 1 scope decision Current decision: `PREPARATION_OPEN_FORMAL_EXECUTION_BLOCKED`. Round 1 should use the P0 enterprise-pilot mainline as its mandatory scope: - P3-WP01 through P3-WP06; - P3-WP08; - P3-WP14 acceptance, defect, training, handover and signoff controls. P3-WP07 and P3-WP09 through P3-WP13 are conditional scope. They may enter Round 1 only when the named enterprise owner records an explicit activation decision and supplies the corresponding infrastructure, AI, multi-tenancy, BI/AI, cost or plugin inputs. Absence of a conditional-package decision must not silently expand the mandatory UAT scope. ## UAT Round 1 entry checklist | Entry gate | Required evidence | Current state | |---|---|---| | Scope and ownership | Pilot enterprise, objectives, dates, named product/business/technical/security/operations owners, acceptance owner | `TBD_EXTERNAL` | | Version and environment | Signed release digest, authorized pre-production environment, change window, second-environment decision, backup and rollback target | `BLOCKED_EXTERNAL` | | Identity, data and network | IdP contract, two read-only desensitized sources, third-domain glossary, service identities, routes, allowlists and denial paths | `TBD_EXTERNAL` | | Operations and security | Monitoring, SMTP, collaboration, ITSM, KMS/DLP/SIEM, retention, legal hold, SLA, SLO, RTO and RPO | `TBD_EXTERNAL` | | Test data and acceptance | Role roster, approved workloads, expected results, target-scale profile, defect owners, training roster and evidence repository | `TBD_EXTERNAL` | Formal execution may be scheduled only after all mandatory P0 entry gates have named evidence references. Local fixtures, unsigned manifests and developer-owned environments cannot satisfy these gates. ## UAT Round 1 execution waves 1. **Gate review and dry run** — freeze the signed version, verify evidence storage, assign case owners, validate sanitized test data and rehearse evidence capture without changing enterprise data. 2. **Identity and default-deny smoke** — execute authentication, role mapping, session expiry, cross-role denial, audit and no-secret evidence checks. Stop immediately on authorization leakage or untraceable identity. 3. **Mainline functional flow** — execute the approved source-to-governance-to-edge-to-third-domain scenarios, including duplicate delivery, replay, rollback and recovery. 4. **Operations, failure and scale** — execute monitoring, alert delivery, ITSM escalation, fault injection, capacity, backup, restore, upgrade and rollback against approved SLO/RTO/RPO. 5. **Training, defect decision and signoff** — complete user and operations exercises, close P0, close P1 or record the formal two-owner decision, then obtain five-party signoff. Each wave must record the case ID, signed release digest, environment ID, named executor, start/end time, sanitized inputs, expected result, actual result, evidence reference, defect ID and reviewer. Evidence must never contain raw credentials, tokens or unapproved production data. ## Stop and exit rules - Stop the affected wave for any P0, authorization bypass, cross-domain data exposure, unrecoverable corruption, missing audit chain or inability to restore the approved baseline. - A P1 blocks acceptance until closed with evidence or formally decided by the named business and technical owners. - P0 cannot be waived for the mandatory P0 scope. - Round 1 passes only when every mandatory enterprise case is executed against the signed version, required training and recovery evidence exists, P0 is zero, P1 is closed or formally decided, and all five signers approve the same evidence package. - Until then the highest reportable state remains `ENGINEERING_BASELINE_COMPLETE_ENTERPRISE_UAT_BLOCKED`. ## Inputs required before scheduling the formal run The enterprise must provide or confirm the following before a formal date is assigned: 1. pilot objective, enterprise/environment name, scope, target users, success metrics and proposed window; 2. five named signers and the enterprise pilot acceptance owner; 3. signed release digest and authorized evidence repository; 4. IdP metadata, claims mapping, service identities and certificate lifecycle; 5. two read-only desensitized data sources plus third-domain definitions and expected results; 6. network routes, allowlists, denial rules and security/legal controls; 7. monitoring, SMTP, collaboration, ITSM and on-call/escalation contacts; 8. infrastructure, registry, backup, restore, SLA/SLO/RTO/RPO and target-scale profile; 9. written include/defer decisions for AI, multi-tenancy, BI/AI, Showback and plugins; 10. user/operations training roster and the P0/P1 defect decision forum.