Go-live gates

Use these gates before enabling approved live submission operations or a production pilot.

GateOwnerRequirementBlocker criteriaEvidence
1. Authorized standards confirmedFHIR lead and standards ownerThe Ontario MHA PDS data dictionary, implementation guide, package, and terminology references are version-pinned for the release.Package version, source, or validation configuration is unknown or differs from the approved implementation baseline.Standards register, package metadata, Settings export, and validation configuration record.
2. Tenant and access controls approvedSecurity lead, privacy officer, administratorProduction tenant, memberships, RLS policies, role checks, export protection, and audit logging are verified.Any cross-tenant read/write succeeds or users can access restricted exports/actions without the required role.RLS tests, role matrix, audit export, and access review sign-off.
3. Data quality blockers resolvedData owner and quality leadMandatory fields, dates, identifiers, terminology crosswalks, and timeline consistency pass for the production candidate extract.Unresolved fatal/error validation issue or unowned mandatory-field gap remains.Data quality remediation tracker, source preflight report, and final validation report.
4. Mappings approvedClinical owner, data owner, FHIR leadSource-to-FHIR mappings for required and conditional fields are reviewed, approved, or formally deferred.Required field mappings remain draft or clinical mappings lack owner approval.Mapping workbook export, approval status, and decision notes.
5. Terminology governance completeTerminology lead and clinical ownerLocal source codes are inventoried, mapped, approved, and retained with a package-aligned terminology snapshot.Required coded fields have unmapped production values without accepted remediation.Terminology catalogue export, crosswalk, self-check result, and approval log.
6. Validation evidence acceptedQA lead and FHIR leadSource preflight, conversion traceability, local requirement validation, structural validation, package validation, and terminology validation are retained.Validation reports cannot be reproduced or show unresolved fatal/error items.Validation evidence package, OperationOutcome diagnostics, and issue disposition log.
7. Interface-engine dry run acceptedIntegration lead and operations leadLive Feed can queue, process, and record mock/dry-run jobs with traceable Bundle IDs, attempts, statuses, and diagnostics.Jobs fail without actionable diagnostics or accepted jobs cannot be traced to source rows and Bundles.Feed job export, attempt history, dry-run response, and support notes.
8. Transport and credentials approvedIntegration lead and security leadEndpoint, token ownership, rotation, timeout, retry, support contacts, and live-mode enablement procedure are approved.Credentials are unmanaged, endpoint is not approved, or live mode can be enabled without go/no-go approval.Transport checklist, credential owner register, and endpoint approval notes.
9. Operations and hypercare readyOperations lead and support leadDaily queue review, incident triage, retry/replay procedure, escalation path, and release notes are prepared.No named support owner, no incident procedure, or no monitoring process exists for failed/retrying jobs.Hypercare plan, support roster, incident playbook, and queue review schedule.
10. Final go/no-go recordedExecutive sponsorBusiness, clinical, data, privacy, security, FHIR, integration, and operations owners record final readiness decision.Any required owner has not signed off or has open blocker conditions.Go/no-go record, owner sign-offs, final evidence pack, and launch decision.