Acceptance and ownership
This matrix turns a design-partner pilot into a decision that both parties can review. It applies to one frozen, non-production workflow and uses synthetic data or test assets.
Responsibility matrix
| Area | Partner owns | Luvion owns | Joint decision |
|---|---|---|---|
| Workflow | Real operational sequence and decision owner | Structured workflow model | Exact operation in scope |
| Policy | Business limits, roles, and allowlist source | Policy encoding and validation | Frozen policy version |
| Integration | Sandbox/API access and provider facts | Adapter implementation and binding checks | Completion semantics |
| Credentials | Named partner actors and approved delivery channel | Digest-only configuration and role enforcement | Rotation drill timing |
| Testing | Business-valid expected outcomes | Test scripts, failure injection, and reproducibility | Pass/fail interpretation |
| Evidence | Retention and reviewer requirements | Signed exports, digests, and known limitations | Final evidence package |
| Operations | Partner escalation contacts | Service health and recovery procedure | Incident and retry ownership |
Entry gate
- One non-production operation and decision owner are named.
- Intent fields, policy version, roles, threshold, limits, and allowlist are frozen.
- The adapter mapping worksheet is complete.
- No production secrets, customer personal data, or live high-value assets are in scope.
- The environment reports healthy before the first test.
Functional acceptance
- A valid request succeeds only under the exact policy version.
- An ineligible role cannot approve, reject, authorize, or execute.
- Initiator and approver remain separated where the policy requires it.
- Below-threshold approvals cannot authorize an operation.
- An altered destination, amount, payload, policy, approval set, or certificate fails closed.
- Expired, replayed, and conflicting requests fail closed.
- Repeating an identical request cannot create a second logical execution.
- Provider rejection and retryable failure remain distinguishable.
Evidence and recovery acceptance
- Successful and rejected terminal paths each produce a complete export.
- The export includes the frozen policy, request record, authorization state, event-chain digest, and adapter receipt or explicit no-execution state.
- Persisted records validate after restart.
- A stopped-state backup validates and restores to a separate location.
- At least one dependency-failure and recovery drill is recorded.
- The final package lists every known limitation and production blocker.
Decision record
The final review records one of three outcomes:
- Extend the design partnership for a second workflow or deeper adapter.
- Revise and repeat after specific product or integration gaps are closed.
- Stop because the workflow value, integration cost, or operating model is not acceptable.
A production commercial proposal is a later decision. It is not implied by a pilot pass and requires separate security, audit, legal, infrastructure, data, support, and contractual review.