Create private snapshot
Build from one authenticated package; deny public and crawler access.
Governed staging and promotion
A private immutable snapshot separates rendering review from public release. Source lineage, automated evidence, human approval, effective time, sequence reservation, and rollback must converge before promotion.
Build from one authenticated package; deny public and crawler access.
Prove every public field maps to the frozen approved revision.
Validate schema, links, accessibility, SEO, security, search, and visual output.
Give authorised reviewers a time-bounded immutable preview.
Prove the named prior snapshot restores routes, search, sitemap, and authority.
Requester, staging, promotion, and security identities remain distinct.
Prevent concurrent or replayed packages from overtaking the candidate.
Activate content, route, search, sitemap, citations, and navigation together.
Check public route, indexes, metadata, monitoring, and effective version.
Record evidence or restore the verified target through incident authority.
Verification matrix
Every required control must record a passing evidence identifier, accountable executor, and completion time. Missing, warning, or failed evidence blocks promotion.
Source-to-render integrity
The diff compares the approved canonical fields with headings, body, metadata, citations, structured data, search document, sitemap entry, and navigation generated for the preview. Any unexplained difference rejects the snapshot.
Atomic promotion
Promotion updates the public route, knowledge index, search, sitemap, citations, and navigation as one snapshot. Production verification begins immediately. A failed critical check triggers the separated rollback workflow to the already verified target.
Signing trust →P010/P011 export pack →Operational evidence →Recovery architecture →