# Production Readiness Review: [service]

> Pre-launch gate. Every row is a decision, a threshold, or a named
> owner – if a row reads "we'll figure it out", the service is not
> ready.

| Field | Value |
|-------|-------|
| Service | [name] |
| Review date | YYYY-MM-DD |
| Reviewer | @name |
| Verdict | Ready / Conditional / Blocked |

## Reliability

- [ ] SLOs written and approved (see `slo-doc`)
- [ ] One service dashboard shows its SLIs – the reviewable one exists
- [ ] Burn-rate alerts route to a staffed on-call rotation
- [ ] Runbook covers every alert that can page
- [ ] Readiness and liveness checks are distinct and wired

## Capacity & performance

- [ ] Load test run against SLO targets
- [ ] Headroom >= 2x expected peak
- [ ] Dependency limits documented (DB connections, API quotas)
- [ ] Cost ceiling and budget alert configured

## Security

- [ ] Threat model reviewed (see `threat-model`)
- [ ] Authn/z enforced on every external endpoint
- [ ] Secrets in the vault; none in code or config
- [ ] Dependency scan clean, or residual risk accepted in writing

## Operability

- [ ] Structured logs with correlation/request IDs
- [ ] Deploy is automated and rollback is tested
- [ ] Feature flags or kill switch for risky paths
- [ ] On-call rotation staffed, trained, with access
- [ ] Incident comms channel + status-page process agreed

## Data

- [ ] Backups configured AND a restore actually tested
- [ ] Data classification and retention documented
- [ ] PII handling reviewed against the privacy policy

## Launch criteria

| Gate | Threshold | Met? |
|------|-----------|------|
| Error rate | < N% sustained 7 days | [ ] |
| Latency p95 | < NNN ms | [ ] |
| | | [ ] |

## Open items

| Item | Owner | Due | Blocks launch? |
|------|-------|-----|----------------|
| | @name | YYYY-MM-DD | Yes / No |
