Operating realities
The product has more than one live boundary.
Identity, authorization, code, artifacts, environments, customer configuration, runtime behavior, billing and product outcomes change at different speeds. The system has to preserve how they relate without collapsing them into one dashboard state.
01Identity is not entitlement
A valid account does not prove the correct tenant, organization, role, plan, feature, data scope or acting authority. Customer administrators, support staff, service accounts, integrations and delegated users can cross boundaries if each authorization context is not explicit.
Context evidence: Customer and contract, tenant and organization, person or service actor, authentication event, session, role and entitlement, plan and feature, resource and data scope, delegated authority, support access, approval, expiry, revocation, policy decision, denial, correction and audit.
02Code is not customer release
A merged change may not be built, a built artifact may not be verified, a release may not be deployed, a deployment may reach only one environment or cohort, and a feature may remain disabled. Database and API compatibility can lag behind application code.
Context evidence: Requirement and acceptance criterion, source revision, author and review, dependency and licence record, build identity and artifact digest, test and security evidence, provenance, release manifest, approval, feature flag, environment and tenant cohort, migration and compatibility state, deployment receipt, rollback point, customer communication and correction.
03Telemetry is not service truth
Logs, traces, metrics and synthetic checks can be missing, sampled, delayed, misclassified or stripped of tenant context. Infrastructure uptime does not prove that a customer can complete the promised task, that data is correct, or that an incident has no material effect.
Context evidence: Service and dependency, environment and version, tenant-safe correlation, signal schema and instrumentation version, sampling and loss, user-centered service indicator, objective and measurement window, event time, detection and acknowledgement, customer impact, incident owner, mitigation, recovery, support evidence, status communication, correction and review.
04AI capability is not product authority
A model can produce fluent output while using the wrong source, leaking another tenant's context, ignoring policy, failing silently or changing after a provider update. An experiment score cannot authorize a consequential customer action or prove value in operation.
Context evidence: Use case and prohibited use, model and provider version, prompt and tool contract, allowed sources and tenant boundary, data purpose, evaluation set and limitation, output provenance and confidence, abstention, policy check, human review and authority, action receipt, monitoring, incident, customer notice, override, rollback, retirement and outcome comparison.