P3_WP14_UAT_PLAN_AND_REPORT.md 11 KB

P3-WP14 enterprise pilot UAT plan and local engineering report

Result

Current reportable state: ENGINEERING_BASELINE_COMPLETE_ENTERPRISE_UAT_BLOCKED. The 本地工程验收 boundary includes a Compose-parsed input closure and a lock/nonce/TTL-protected verification ledger; it does not represent 企业正式 UAT, a production deployment, or a signed release. The shared source/deployment migration head is 20260818_559 and no WP14 migration is required because this work package adds evidence and contract artifacts only.

Acceptance layers

Layer Evidence allowed Current state
Local engineering acceptance Checked-in contract tests, closed fixtures, local-only PostgreSQL evidence, documentation integrity and source/deployment parity PASS_LOCAL when the fresh command ledger passes
Formal second isolated environment Same signed version in a second authorized isolated environment BLOCKED_EXTERNAL: current manifest is unsigned and the enterprise environment/signature are TBD_EXTERNAL
Local configuration portability rehearsal Two non-secret local labels with restricted difference summary, bound to an unsigned manifest digest PASS_LOCAL; not a signed-version or second enterprise environment result
Enterprise formal UAT Named enterprise users, approved sources, target environment, integrations, target-scale result, training records, P0/P1 decision, five-party signatures BLOCKED_EXTERNAL
Production acceptance Approved change, deployed signed artifact, operations observation and recovery evidence BLOCKED_EXTERNAL

Scope and roles

The machine-readable matrix is docs/acceptance/P3_WP14_UAT_CASES.json. It covers P3-WP01–P3-WP13 local engineering paths and the following role boundaries: administrator, governance user, ordinary user, data owner, operations, security, and audit. It covers interfaces, database/ACL paths, available local browser/UI evidence, enterprise-integration boundaries, migration 20260818_559, upgrade, rollback, restore, target scale, fault, security, training, operations, and five-party signing.

The validation is a third-stage change-range regression, not a blanket repository test. A test or evidence path may prove local behavior only. The matrix records unprovided enterprise inputs as TBD_EXTERNAL or BLOCKED_EXTERNAL rather than synthesizing results. 任何本地 fixture、容器、检查清单或开发者测试均不能替代企业正式 UAT。

P0 and P1 gate

Within the fresh local command set listed in the evidence report, P0:0 and 未关闭 P1:0. This is a constrained engineering observation, not a claim about enterprise or production conditions. Enterprise P0/P1 state remains TBD_EXTERNAL. An unclosed enterprise P1 needs a formal decision by actual business and technical owners; absent that decision it blocks formal acceptance.

Enterprise UAT sequence

  1. The enterprise assigns product, business, technical, security, and operations owners.
  2. Owners provide approved IdP, two read-only sources, network, monitoring/notification/ITSM, security/legal, infrastructure, third-domain, AI, and conditional-package inputs as applicable.
  3. The enterprise binds real roles, approved desensitized samples, metrics, target-scale workload, SLO/RTO/RPO, and rollback decision to the signed version.
  4. Execute every ENTERPRISE_FORMAL case and attach durable evidence without raw data or secrets.
  5. Resolve P0; resolve P1 or append the formal business/technical decision.
  6. Complete user and operations training, target-environment upgrade/rollback/restore, handover, and five-party signoff.

Residual external gates

Pilot environment, five named signers, IdP, sources, network, monitoring, SMTP, collaboration, ITSM, security/legal, infrastructure, enterprise model, multi-tenancy, BI/AI, cost, plugin policy, target-scale results, and remote-save authorization are all TBD_EXTERNAL or BLOCKED_EXTERNAL. No external enterprise system is contacted by P3-WP14.

Phase 3 completion assessment for UAT Round 1

Assessment date: 2026-08-18. This assessment distinguishes implementation readiness from enterprise acceptance.

Work package Engineering state UAT interpretation
P3-WP00 COMPLETE; enterprise confirmation TBD_EXTERNAL Scope, metrics, ownership and enterprise inputs are defined, but the pilot goal is not confirmed.
P3-WP01 ENGINEERING_READY_BLOCKED_EXTERNAL Acceptance package is ready; actual enterprise users, sources, infrastructure and training remain external.
P3-WP02 ENGINEERING_COMPLETE_ENTERPRISE_IDP_UAT_BLOCKED Identity engineering is complete; real IdP and enterprise claims must be supplied.
P3-WP03 ENGINEERING_COMPLETE_ENTERPRISE_SOURCE_UAT_BLOCKED Connector engineering is complete; two approved read-only sources and network access are missing.
P3-WP04 ENGINEERING_COMPLETE_ENTERPRISE_EDGE_UAT_BLOCKED Edge engineering is complete; enterprise source, network and security/legal validation are missing.
P3-WP05 ENGINEERING_COMPLETE_ENTERPRISE_OBSERVABILITY_UAT_BLOCKED Local observability paths are complete; monitoring, SMTP, collaboration and ITSM integrations are missing.
P3-WP06 ENGINEERING_COMPLETE_ENTERPRISE_TRUSTED_DELIVERY_UAT_BLOCKED Trusted-delivery engineering is complete; enterprise identity, network and security/legal approval are missing.
P3-WP07 ENGINEERING_COMPLETE_ENTERPRISE_INFRASTRUCTURE_UAT_BLOCKED Delivery artifacts are ready; target platform, registry, certificates, SLA and recovery inputs are missing.
P3-WP08 ENGINEERING_COMPLETE_ENTERPRISE_THIRD_DOMAIN_UAT_BLOCKED Third-domain engineering is complete; the real domain, source, network and security/legal inputs are missing.
P3-WP09 ENGINEERING_COMPLETE_ENTERPRISE_AI_UAT_BLOCKED Agent/model governance engineering is complete; approved model, budget, sandbox, golden set and red-team inputs are missing.
P3-WP10 ENGINEERING_BASELINE_COMPLETE_MULTI_TENANCY_ACTIVATION_BLOCKED Multi-tenancy baseline is complete but must remain disabled until the delivery model and isolation level are approved.
P3-WP11 ENGINEERING_BASELINE_COMPLETE_BI_AI_ACTIVATION_BLOCKED BI/AI catalog baseline is complete but enterprise provider activation is not approved.
P3-WP12 ENGINEERING_BASELINE_COMPLETE_SHOWBACK_ACTIVATION_BLOCKED Showback baseline is complete; enterprise cost sources and finance approval are missing.
P3-WP13 ENGINEERING_BASELINE_COMPLETE_PLUGIN_ACTIVATION_BLOCKED Plugin baseline is complete but enterprise trust, registry, CA, licence and sandbox decisions are missing.
P3-WP14 ENGINEERING_BASELINE_COMPLETE_ENTERPRISE_UAT_BLOCKED Local acceptance and handover baseline is complete; formal enterprise UAT has not started.

The current machine matrix contains 30 cases: 20 PASS_LOCAL, 9 BLOCKED_EXTERNAL, and 1 TBD_EXTERNAL. This supports opening UAT preparation, not formal UAT execution.

UAT Round 1 scope decision

Current decision: PREPARATION_OPEN_FORMAL_EXECUTION_BLOCKED.

Round 1 should use the P0 enterprise-pilot mainline as its mandatory scope:

  • P3-WP01 through P3-WP06;
  • P3-WP08;
  • P3-WP14 acceptance, defect, training, handover and signoff controls.

P3-WP07 and P3-WP09 through P3-WP13 are conditional scope. They may enter Round 1 only when the named enterprise owner records an explicit activation decision and supplies the corresponding infrastructure, AI, multi-tenancy, BI/AI, cost or plugin inputs. Absence of a conditional-package decision must not silently expand the mandatory UAT scope.

UAT Round 1 entry checklist

Entry gate Required evidence Current state
Scope and ownership Pilot enterprise, objectives, dates, named product/business/technical/security/operations owners, acceptance owner TBD_EXTERNAL
Version and environment Signed release digest, authorized pre-production environment, change window, second-environment decision, backup and rollback target BLOCKED_EXTERNAL
Identity, data and network IdP contract, two read-only desensitized sources, third-domain glossary, service identities, routes, allowlists and denial paths TBD_EXTERNAL
Operations and security Monitoring, SMTP, collaboration, ITSM, KMS/DLP/SIEM, retention, legal hold, SLA, SLO, RTO and RPO TBD_EXTERNAL
Test data and acceptance Role roster, approved workloads, expected results, target-scale profile, defect owners, training roster and evidence repository TBD_EXTERNAL

Formal execution may be scheduled only after all mandatory P0 entry gates have named evidence references. Local fixtures, unsigned manifests and developer-owned environments cannot satisfy these gates.

UAT Round 1 execution waves

  1. Gate review and dry run — freeze the signed version, verify evidence storage, assign case owners, validate sanitized test data and rehearse evidence capture without changing enterprise data.
  2. Identity and default-deny smoke — execute authentication, role mapping, session expiry, cross-role denial, audit and no-secret evidence checks. Stop immediately on authorization leakage or untraceable identity.
  3. Mainline functional flow — execute the approved source-to-governance-to-edge-to-third-domain scenarios, including duplicate delivery, replay, rollback and recovery.
  4. Operations, failure and scale — execute monitoring, alert delivery, ITSM escalation, fault injection, capacity, backup, restore, upgrade and rollback against approved SLO/RTO/RPO.
  5. Training, defect decision and signoff — complete user and operations exercises, close P0, close P1 or record the formal two-owner decision, then obtain five-party signoff.

Each wave must record the case ID, signed release digest, environment ID, named executor, start/end time, sanitized inputs, expected result, actual result, evidence reference, defect ID and reviewer. Evidence must never contain raw credentials, tokens or unapproved production data.

Stop and exit rules

  • Stop the affected wave for any P0, authorization bypass, cross-domain data exposure, unrecoverable corruption, missing audit chain or inability to restore the approved baseline.
  • A P1 blocks acceptance until closed with evidence or formally decided by the named business and technical owners.
  • P0 cannot be waived for the mandatory P0 scope.
  • Round 1 passes only when every mandatory enterprise case is executed against the signed version, required training and recovery evidence exists, P0 is zero, P1 is closed or formally decided, and all five signers approve the same evidence package.
  • Until then the highest reportable state remains ENGINEERING_BASELINE_COMPLETE_ENTERPRISE_UAT_BLOCKED.

Inputs required before scheduling the formal run

The enterprise must provide or confirm the following before a formal date is assigned:

  1. pilot objective, enterprise/environment name, scope, target users, success metrics and proposed window;
  2. five named signers and the enterprise pilot acceptance owner;
  3. signed release digest and authorized evidence repository;
  4. IdP metadata, claims mapping, service identities and certificate lifecycle;
  5. two read-only desensitized data sources plus third-domain definitions and expected results;
  6. network routes, allowlists, denial rules and security/legal controls;
  7. monitoring, SMTP, collaboration, ITSM and on-call/escalation contacts;
  8. infrastructure, registry, backup, restore, SLA/SLO/RTO/RPO and target-scale profile;
  9. written include/defer decisions for AI, multi-tenancy, BI/AI, Showback and plugins;
  10. user/operations training roster and the P0/P1 defect decision forum.