Provider Activation Change Control + Canary/Rollout Safety Foundation
This gate adds the missing boundary between “reviewed/observable” and “allowed to become live”: independent dual-control approval, a bounded activation window, exact artifact/profile/recovery binding, small canary start, controlled ramp steps, abort thresholds, and an explicit maximum rollout ceiling. QA uses deterministic simulator evidence only. It does not contact a provider, send traffic, or activate production.
SCHEMA
Provider activation schema
READYExpected schema v39.
AUTOMATED ATTACK PATHS
Activation + canary self-test
READYRuns the server-owned change-control, canary, ramp and abort attack matrix.
VISIBLE QA FLOW
Exercise the activation boundary
GREEN means safe simulator evidence was accepted. EXPECTED BLOCK means Clara stopped an unsafe activation/ramp attempt. RED means something unexpected happened.
READYSafe flow should approve a simulator plan, then 5% → 15% → 25% simulator exposure while production traffic stays 0%.
PolicyLoad state after starting QA.
PLAN ATTACK PATHS
Change-control attempts that must be blocked
ROLLOUT ATTACK PATHS
Canary/ramp attempts that must be blocked
Activation plans
No evidence loaded yet.
Canary/ramp evidence
No evidence loaded yet.
Immutable activation events
No evidence loaded yet.
PRODUCTION LATER
Production activation gates — do not fake these green
Leave these open until ClaraWide has real production provider/artifact evidence, live observability, exercised recovery, independent approval, a staffed activation window, bounded canary mechanics, and production abort controls.
Recent provider activation QA runs
No QA runs recorded yet.
Evidence tools
Clearing browser evidence never rewrites server-owned activation plans, rollout evidence or immutable events.