Skip to main content

Acceptance and ownership

This matrix turns a design-partner pilot into a decision that both parties can review. It applies to one frozen, non-production workflow and uses synthetic data or test assets.

Responsibility matrix

AreaPartner ownsLuvion ownsJoint decision
WorkflowReal operational sequence and decision ownerStructured workflow modelExact operation in scope
PolicyBusiness limits, roles, and allowlist sourcePolicy encoding and validationFrozen policy version
IntegrationSandbox/API access and provider factsAdapter implementation and binding checksCompletion semantics
CredentialsNamed partner actors and approved delivery channelDigest-only configuration and role enforcementRotation drill timing
TestingBusiness-valid expected outcomesTest scripts, failure injection, and reproducibilityPass/fail interpretation
EvidenceRetention and reviewer requirementsSigned exports, digests, and known limitationsFinal evidence package
OperationsPartner escalation contactsService health and recovery procedureIncident and retry ownership

Entry gate

  • One non-production operation and decision owner are named.
  • Intent fields, policy version, roles, threshold, limits, and allowlist are frozen.
  • The adapter mapping worksheet is complete.
  • No production secrets, customer personal data, or live high-value assets are in scope.
  • The environment reports healthy before the first test.

Functional acceptance

  • A valid request succeeds only under the exact policy version.
  • An ineligible role cannot approve, reject, authorize, or execute.
  • Initiator and approver remain separated where the policy requires it.
  • Below-threshold approvals cannot authorize an operation.
  • An altered destination, amount, payload, policy, approval set, or certificate fails closed.
  • Expired, replayed, and conflicting requests fail closed.
  • Repeating an identical request cannot create a second logical execution.
  • Provider rejection and retryable failure remain distinguishable.

Evidence and recovery acceptance

  • Successful and rejected terminal paths each produce a complete export.
  • The export includes the frozen policy, request record, authorization state, event-chain digest, and adapter receipt or explicit no-execution state.
  • Persisted records validate after restart.
  • A stopped-state backup validates and restores to a separate location.
  • At least one dependency-failure and recovery drill is recorded.
  • The final package lists every known limitation and production blocker.

Decision record

The final review records one of three outcomes:

  1. Extend the design partnership for a second workflow or deeper adapter.
  2. Revise and repeat after specific product or integration gaps are closed.
  3. Stop because the workflow value, integration cost, or operating model is not acceptable.

A production commercial proposal is a later decision. It is not implied by a pilot pass and requires separate security, audit, legal, infrastructure, data, support, and contractual review.