Production Risk and Dependency Review
Overview
Provide an evidence-first contract for critical-path dependencies, ownership, probability, impact, mitigations, triggers, and escalation.
When to use
Use only for the trigger conditions in the description and when the requested artifact needs explicit owners, evidence, limitations, and verification.
When NOT to use
Do not use to create the baseline schedule or silently accept missing owners.
Required inputs and context discovery
Collect exact project and build identity, requested scope, owners, dependencies, constraints, existing evidence, commands, artifact paths, risks, approvals, rollback or recovery, and unavailable information.
Safety and risk level
Risk level is read-only. Read-only review never authorizes mutation. Any load, rollout, publication, service, database, credential, or external-system action requires explicit human approval and bounded stop conditions.
Workflow
- Load the approved production plan and current workstream snapshots.
Completion criterion: evidence is recorded and unresolved items are explicit.
- Trace dependency chains and identify single points of failure or owner gaps.
Completion criterion: evidence is recorded and unresolved items are explicit.
- Score probability, impact, detectability, and schedule exposure with stated evidence.
Completion criterion: evidence is recorded and unresolved items are explicit.
- Assign mitigation, contingency, trigger, owner, and escalation date.
Completion criterion: evidence is recorded and unresolved items are explicit.
- Return PASS, FAIL, or BLOCKED per gate without changing the plan.
Completion criterion: evidence is recorded and unresolved items are explicit.
Evidence and output contract
Produce production-risk-review.json with scope, snapshot, findings, owners, commands and exit codes, artifacts, acceptance criteria, Verified facts, Snapshot assumptions, Unverified hypotheses, BLOCKED items, and next actions.
Handoff contract
Record repository and path, goal, owned scope, do-not-touch scope, decisions, files changed, commands, exit codes, artifacts, restore information, blockers, next owner, and reactivation prompt.
Pitfalls and anti-rationalization
- Missing evidence is
BLOCKED, never PASS.
- A plan or review does not authorize production execution.
- Compile success, screenshots, or anecdotes do not prove broader coverage.
- Preserve unrelated work and generated-source ownership.
Verification checklist
References and scripts
No bundled runtime helper is required. Use project-owned plans, evidence, runbooks, schemas, and validation commands; repository governance tools remain full-clone-only.
1---2name: production-risk-and-dependency-review3description: Use when a production plan needs a read-only dependency risk review covering critical path, ownership gaps, blocked handoffs, mitigation, escalation, and schedule exposure; not for creating the baseline production schedule.4license: MIT5---6# Production Risk and Dependency Review78## Overview9Provide an evidence-first contract for critical-path dependencies, ownership, probability, impact, mitigations, triggers, and escalation.1011## When to use12Use only for the trigger conditions in the description and when the requested artifact needs explicit owners, evidence, limitations, and verification.1314## When NOT to use15Do not use to create the baseline schedule or silently accept missing owners.1617## Required inputs and context discovery18Collect exact project and build identity, requested scope, owners, dependencies, constraints, existing evidence, commands, artifact paths, risks, approvals, rollback or recovery, and unavailable information.1920## Safety and risk level21Risk level is `read-only`. Read-only review never authorizes mutation. Any load, rollout, publication, service, database, credential, or external-system action requires explicit human approval and bounded stop conditions.2223## Workflow241. Load the approved production plan and current workstream snapshots.25 Completion criterion: evidence is recorded and unresolved items are explicit.262. Trace dependency chains and identify single points of failure or owner gaps.27 Completion criterion: evidence is recorded and unresolved items are explicit.283. Score probability, impact, detectability, and schedule exposure with stated evidence.29 Completion criterion: evidence is recorded and unresolved items are explicit.304. Assign mitigation, contingency, trigger, owner, and escalation date.31 Completion criterion: evidence is recorded and unresolved items are explicit.325. Return PASS, FAIL, or BLOCKED per gate without changing the plan.33 Completion criterion: evidence is recorded and unresolved items are explicit.3435## Evidence and output contract36Produce `production-risk-review.json` with scope, snapshot, findings, owners, commands and exit codes, artifacts, acceptance criteria, Verified facts, Snapshot assumptions, Unverified hypotheses, BLOCKED items, and next actions.3738## Handoff contract39Record repository and path, goal, owned scope, do-not-touch scope, decisions, files changed, commands, exit codes, artifacts, restore information, blockers, next owner, and reactivation prompt.4041## Pitfalls and anti-rationalization42- Missing evidence is `BLOCKED`, never PASS.43- A plan or review does not authorize production execution.44- Compile success, screenshots, or anecdotes do not prove broader coverage.45- Preserve unrelated work and generated-source ownership.4647## Verification checklist48- [ ] Scope, identity, owners, and exclusions are explicit.49- [ ] Every verdict cites observed evidence or is labeled Unverified/BLOCKED.50- [ ] Risks have mitigations, triggers, owners, and dates.51- [ ] No unauthorized mutation, publication, deployment, or destructive action occurred.52- [ ] Handoff names the next bounded action.5354## References and scripts55No bundled runtime helper is required. Use project-owned plans, evidence, runbooks, schemas, and validation commands; repository governance tools remain full-clone-only.