The Release Gate
Last reviewed · content updated
IntermediateWhat you'll learn
~18 min- Draw the release decision as states and transitions, each with the trigger that moves it
- Name who runs the gate, who signs, who records, and who holds the authority to reject or suspend
- State what a leader is signing and the only sentence they may repeat upward
Before the detail — Decision: run the gate as a state machine with typed outcomes. Outcome: a rejection that survives pressure, and a signature whose meaning is known. Artifact: the typed outcome and the state-transition log. Status of what follows: common baseline; the discontinue rule binding where M-25-21 applies.
Prompt first: the gate agenda and the transition log entry
Here is release-decision record RDR-2026-014 for MU-AI-004 [paste theexample record].
1. Draft the GATE AGENDA for this record: - what is on the table: sections 1 through 6, nothing else - no slides, no demo, no vendor material - the order: the independent reviewer's findings on section 2 and 3 read FIRST, then conditions (4), then section 5, then triggers (6); section 1 last, because it is what the risk is weighed against - the typed outcomes available: approved / approved-with- conditions / rejected / pilot-only (only where a pilot is authorized)2. Draft the STATE-TRANSITION LOG ENTRY for the outcome the record shows: from-state, to-state, the trigger (the gate decision), who ran the gate, who signed, who recorded, valid-through. Every name and date is NEEDS-OWNER.Do not recommend an outcome. The gate decides; you set the table.The agent lays the table correctly — sections in the right order, outcomes typed, the log entry with every field — and it must not sit at it. A recommended outcome from an agent is a number nobody sourced wearing a verdict’s clothes; the record’s evidence rows are what the room decides on.
The states and the transitions
A release decision is not an event; it is a state a system is in, with named ways of leaving it:
THE RELEASE GATE lifecycle states of one record; PILOT-ONLY is a decision value written on an approved-with-conditions record with an end date, not a state
draft: ─────────► approved every gate passed on target- system evidence; conditions none ─────────► approved-with-conditions gates passed; section 4 carries conditions with owners and dates ─────────► rejected a gate failed or the risk acceptor declined to sign
approved, approved-with-conditions (the state does not change while areview clock runs; the trigger is logged as an EVENT): ─────────► stale valid-through date passed; nothing else happened - the decision simply aged out ─────────► suspended an evidence-invalidating trigger fired (version boundary actually crossed, a gate's set changed, a condition failed) - the evidence no longer describes what is running ─────────► renewed | a review trigger's disposition (a notice withdrawn received, an incident, a context change, an owner seat vacated), decided inside the record's clock (6.1) - no wait for expiry
stale, suspended: ─────────► renewed the gate ran again on new evidence; a NEW record version with a new valid-through date, citing the old one ─────────► withdrawn the gate ran again, or nobody re-ran it, and the system stops serving; the register entry remains - retired, reported once moreLegend: “evidence-invalidating” is Lesson 6.1’s category — a change after which section 2 describes a system that no longer exists; a “review trigger” opens a clock instead and does not change state by itself. Two things to notice. Rejected is a typed outcome with a record, not the absence of an approval — a system that never reached the gate is unlisted, which is Module 1’s problem — getting it listed — not rejected. And suspended is not a punishment; it is the honest statement that the evidence and the system have parted, and it moves the system to advisory-only or off, per section 4’s failure column, until the gate runs again.
Who holds which authority
Three seats, assigned before testing began (Lesson 1.4), and each holds one thing. The release owner runs the gate: calls it, sets the section 3 thresholds, keeps the log. The risk acceptor signs — P. Delgado for MU-AI-004 — and holds the authority to approve, to approve with conditions, and to reject; rejection is theirs because acceptance is theirs, and a signer who cannot say no is a rubber stamp. The independent reviewer records — H. Lindqvist — and their findings can stop a signature, because a record whose integrity row is unsigned cannot be approved; but the reviewer does not accept risk and does not sign the second row.
Suspension is the transition nobody chooses. An evidence-invalidating trigger suspends the decision when it fires; the release owner records the transition and the reviewer confirms which evidence rows are now void. No signature is needed to suspend, because no one is accepting anything — the state is a fact about the evidence. What does need the acceptor is leaving suspended: renewed is a new signature on new evidence, and withdrawn is a decision too. Whether a gate exists for every system, who sits in the acceptor’s seat by tier, and where the organization’s risk appetite is set belong to the leadership training planned for AI adoption; this gate decides one system, and its authority map is the reason a rejection survives the pressure to reverse it — the risk sits with the person who said no, on the record, and not with whoever argued loudest.
The meeting
What is on the table is sections 1 through 6 of the record, and nothing else. No slide deck, because a slide is a claim with its evidence removed; no demo, because a demo is one attempt on an unsealed input; no vendor material beyond what section 2 already captured as claims and omissions. The reviewer’s findings are read first — before the owner’s case, before the benefit — so the room weighs the evidence before it hears why it wants the system. Then section 4, and the question for each condition is whether the enforcement point exists today; then section 5, which instrument if any applies; then section 6, what will end this decision. Section 1 comes last, as the thing the residual risk is weighed against.
The outcome is typed, written into the header block, and signed in section 7 in the meeting, with a valid-through date. Renewal is the same meeting on a new record version — RDR-2026-014-r2 — that cites the prior record and its two signatures; the signed bytes of the old record are never edited, because editing them would void the integrity signature that made them evidence.
What a leader is actually signing
The risk-acceptance signature is a statement with four bounds: this system behind this version boundary, on this evidence at this level, under these conditions, until this date. It is not a certification, and it is not, by itself, an authorization to operate — that is a separate signed decision, explained in Federal Delivery 1.1, a separate training in this series. It does not say the system is safe; it says the residual risk in sections 1 through 6 is accepted by someone entitled to accept it, for a named period.
That bound gives the leader the only sentence they may repeat upward: “passed the named gates on the named set; no claim beyond it.” Not “it passed testing,” which implies a test that does not exist; not “it is compliant,” which names no gate; not a percentage, which the sealed set cannot license. The sentence is short because the claim is. A leader who says more has signed for more than the record contains, and the difference is theirs when the system does what the set never tested.
Stop and escalate when the gate is asked to approve a production release on evidence whose level column reads mock or local run. The typed outcome available is pilot-only where a pilot is authorized, or rejected with the target-system run as the reason; an approval at that level is a signature on a rehearsal, and the acceptor should hear that from the release owner before the meeting, not from an assessor after.
RDR-2026-014 is approved-with-conditions, valid through 2027-02-27. In November the runtime provider announces that the pinned version will be retired in sixty days and the deployment will move to a successor. What happens to the decision's state today, and what happens when the migration lands?
The commercial starting practice is a change-advisory meeting that approves a release on a demo and a slide. The federal delta is that M-25-21’s minimum practices make the reviewer’s findings and the signed acceptance the substance of the meeting, and the discontinue rule makes “reject” and “withdraw” outcomes the memo expects rather than embarrassments. The handoff artifact is the typed outcome in the header and the state-transition log; what is not equivalent is that a commercial board may waive its own gate while a federal one records a waiver the public can read.
Practice status — among organizations that gate AI releases, commercial and federal
| Practice | Status | Also called |
|---|---|---|
| typed outcomes (approved / with conditions / rejected) | common baseline | go / conditional go / no-go |
| lifecycle states with stale and suspended | emerging | approval expiry and hold status |
| renewal as a new signed record version | strong optional | re-approval package |
| authority to reject or suspend named in the record | required (federal high-impact: the risk acceptor and CAIO); common baseline commercially | decision rights matrix |
Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging
Key takeaway
The release decision is a state, not an event: draft moves to approved, approved-with-conditions, or rejected (PILOT-ONLY is a decision value carried on an approved-with-conditions record); a notice opens a review clock while the state holds; an approval ages to stale or is suspended by actual evidence invalidation; and only a new signature on new evidence, in a new record version, renews it — or the system is withdrawn, directly, from any live state. The release owner runs the gate, the risk acceptor signs and can say no, the reviewer records and can stop a signature; suspension needs no signature because it is a fact about the evidence. The meeting reads sections 1 through 6 and nothing else, findings first. A leader signs residual risk on named evidence for a named period, and repeats upward only “passed the named gates on the named set; no claim beyond it.” Module 6 turns to the triggers that fire it, and how you prove which version answered.
LEADERSHIP DECISION sign residual risk for a named period on the record's evidence, hold the authority to reject, and repeat upward only the named-gates sentencePRACTITIONER ACTION run the gate on sections 1 to 6, findings first; log every transition with its trigger; never approve production on mock or local evidenceSUCCESS MEASURE zero systems serving under a stale or suspended record, read from the log at every review - the finding an assessor cannot make