# Open Production Items

Last updated: 2026-08-14

Source: `docs/production-readiness-checklist.md`

Open items: 1

## Launch Decision

1. `[GATE]` Real-money production readiness: blocked until licensing/provider contracts, reconciliation, security hardening, compliance operations, and incident response are complete.

## 1. Licensing, Legal, And Market Access

No open engineering items remain in this section. The backend now has legal market-access control records, admin evidence endpoints, regulated-activity decisions, operating-model records, jurisdiction legal memo placeholders, restricted term approvals for "bank", "savings" and "deposit", provider contract controls, safeguarding model records, customer policy/disclosure records, jurisdiction blocking/product eligibility controls and production-like config gates requiring legal evidence references. Actual counsel approval, licences/registrations, signed provider contracts, jurisdiction-specific legal memos and executive signoff remain external go-live gates.

## 2. Provider Integrations

No open items remain in this section. The backend now has provider integration records, production-like config gates against local providers, central outbound provider idempotency/retry/timeout/circuit-breaker controls, redacted request/response audit trails, provider metrics, webhook signature/replay/deduplication/ordering controls, admin provider evidence endpoints and sandbox test run records. Real licensed provider contracts, provider-specific production adapters, credentials, certification packs and approval for production traffic remain tracked under licensing and go-live gates.

## 3. Ledger, Balances, And Reconciliation

No open items remain in this section. Daily provider-vs-ledger reconciliation, end-of-day snapshots, trial balance, ledger export, explicit journal reversal workflow, high-volume validation coverage, and per-currency FX rounding policies now exist. Real provider balance feeds and finance signoff are still tracked under provider integration and operational readiness.

## 4. Payments And SEPA

No open items remain in this section. Real SEPA/payment rail integration, provider report ingestion and beneficiary risk checks remain partially ready in the main checklist until licensed provider contracts, certified production report formats, delivery channels and external risk-provider rules are connected.

## 5. Cards And PCI

No open items remain in this section. Card processor configuration, PCI scope assessment records, tokenization/key policy records, tokenized card metadata, authorization hold/clearing/reversal/expiry ledger events, dispute workflows and cardholder notification records now exist. Real issuer/processor contracts, certified PCI evidence, production credentials, browser/admin UI and QSA/security signoff remain tracked under licensing, provider integration, frontend, application security and go-live gates.

## 6. FX, Multi-Currency, And Treasury

No open items remain in this section. Provider/market-data integration is tracked as partially ready in the main checklist until a contracted production market-data adapter is connected.

## 7. Crypto And Stablecoins

No open items remain in this section. Custody scope decisions, legal memo workflow, custody provider config, explicit real-movement disablement controls, chain transaction status model, wallet address screening, travel-rule records, private-key/custody responsibility matrix and stablecoin issuer/network controls now exist. Real legal opinions, licensing/registration evidence and contracted production custody remain partially ready in the main checklist until counsel and provider evidence are attached.

## 8. KYC, AML, Fraud, And Compliance Operations

No open items remain in this section. Identity verification, sanctions/PEP/adverse-media monitoring and case permissions remain partially ready in the main checklist until contracted production providers, evidence retrieval, provider SLAs and narrower compliance roles are connected.

## 9. Authentication, Authorization, And Admin Controls

No open items remain in this section. Recovery codes, secure MFA reset maker-checker, admin role-change maker-checker APIs, explicit admin scope assignment, just-in-time admin elevation, session anomaly/remote revocation alerts and passkey credential/challenge records now exist. Browser WebAuthn ceremonies, frontend UX and external security signoff remain tracked under frontend, application security and go-live gates.

## 10. Application Security

No open items remain in this section. Managed secret/KMS config gates, key-rotation records, WAF/TLS/host enforcement, DAST workflow, penetration-test evidence records, secure logging with redaction tests, CSRF double-submit protection and vulnerability disclosure policy now exist. Real KMS/vault credentials, external DAST/pentest reports, WAF provider rules and security signoff remain tracked under infrastructure, provider integration, testing and go-live gates until evidence is attached.

## 11. Data Protection And Privacy

No open items remain in this section. Data inventory, retention/lawful-basis policy, privacy notices, encryption/backup attestations, audit tamper-evidence and residency controls remain partially ready in the main checklist until legal/security signoff, production infrastructure evidence and historical audit backfill are complete.

## 12. Infrastructure And Runtime

No open items remain in this section. Production hosting architecture, network segmentation, private service access gates, TLS/reverse-proxy requirements, internal metrics CIDR allowlists, production-like PostgreSQL HA/PITR/restore-drill gates, dev/staging/preprod/production environment separation, resource limits, deployment healthchecks, an async worker binary/profile and CD blue-green/canary strategy metadata now exist. Real cloud provisioning, first restore drill artifacts, autoscaling controller evidence and live rollout exercises remain tracked under database, observability and go-live gates.

## 13. Database, Migrations, And Data Integrity

No open items remain in this section. The repo now includes a migration-plan CLI with checksum and rollback coverage, CI/CD rollback-plan checks, a production migration approval artifact, restore-drill evidence tables and runbook, high-volume index review records, financial state-machine transition enforcement, retry classifier tests for deadlock/serialization paths, and archival policy records for audit, ledger, webhooks, provider reports, notifications and sessions. First live restore-drill evidence, live migration dry-run evidence and scheduled archive execution remain tracked under infrastructure, data-protection and go-live evidence gates.

## 14. Observability, Incident Response, And DORA-Style Resilience

No open items remain in this section. The repo now includes a Prometheus/Grafana/Alertmanager observability pack, dashboard coverage for API/DB/ledger/transfers/settlements/cards/KYC/AML/FX/auth/provider calls, severity/routing/on-call alert rules, request ID and W3C traceparent correlation, structured redacted logs with request and trace IDs, incident runbooks, major incident notification flow, BCDR drill plan and chaos/failure-injection scenarios. First live staging deployment evidence, real on-call integrations, live DR drill evidence and production provider/business metric emitters remain tracked under go-live, provider integration and operational readiness gates.

## 15. Testing And Quality Gates

No open items remain in this section. OpenAPI contract coverage, browser e2e checks for customer/admin flows, opt-in load tests for auth/account/transfers/cards/admin/webhooks, webhook replay/idempotency integration coverage and axe-based frontend accessibility checks now exist. Hosted CI evidence, live staging load runs and broader full-stack frontend coverage remain tracked under CI/CD, frontend experience, infrastructure and go-live gates.

## 16. CI/CD And Release Management

No open items remain in this section. The CD workflow now signs pushed API images with keyless Cosign, records image provenance, gates production releases through migration approval, publishes migration approval and deployment manifest artifacts, and includes a release-notes template covering risk, migrations, toggles and runbooks. Backend feature flags can disable high-risk payments, cards, FX, crypto, savings and admin-money surfaces per environment. Hosted GitHub environment configuration, first signed release evidence and live rollout exercises remain tracked under go-live and operational readiness gates.

## 17. Admin Operations And Backoffice

No open items remain in this section. FX and admin role maker-checker already existed; high-risk config change maker-checker, admin action export, evidence packages, operational queues, case assignment, notes, attachment references, SLA/status history, audited support impersonation records and role-specific dashboards now exist. Real operational procedures, evidence retention exports, customer-support training and frontend workflows remain tracked under documentation, frontend, go-live and operational readiness gates.

## 18. Frontend And Customer Experience

No open items remain in this section. The frontend now has a global step-up modal triggered by `step_up_required`, customer disclosures for payments, FX, cards, savings, crypto and stablecoins, stronger admin loading/error states, Playwright e2e coverage for login, MFA, transfer step-up, FX conversion, admin approval and settlement dashboard, Axe accessibility checks, keyboard navigation coverage and a localized content review record. Final legal-approved customer wording, full market localization and live support training remain tracked under licensing, documentation and go-live gates.

## 19. Documentation, Policies, And Training

No open items remain in this section. Architecture and data-flow diagrams, a domain-specific threat model, deploy/rollback/reconciliation-break runbooks, compliance procedures, customer support playbooks and role-based onboarding/training now exist. Production organization names, jurisdiction-specific legal deadlines, real provider procedures, learning-system evidence, completed drills and accountable owner signoff remain go-live evidence gates rather than documentation gaps.

## 20. Go-Live Gates

No open engineering items remain in this section. The backend now has a go-live gate control table, seeded Gate A/B/C records for items 133-151, admin go-live dashboard/endpoints, audit events for gate decisions, evidence/reference validation, production-like config gates for all go-live references, OpenAPI coverage and a go-live gates runbook. Actual staging evidence, beta approval, legal/licensing signoff, provider production approval, live reconciliation, external security review, compliance operations, DORA/PCI validation, restore-drill evidence and executive go/no-go remain real external launch evidence and are tracked inside the go-live controls rather than as code gaps.
