Growth Control Runbook — operate the Completion v1.1 surfaces

Status: written with the build (2026-08-19), branch claude/growth-control-completion-v1-1-w7vg1c; everything here is [IN BUILD] until merged, then merged ≠ deployed ≠ live-verified — this runbook is the GATE-2 path from one state to the next. Plans of record: docs/MIZOKI_SIGNAL_GROWTH_CONTROL_UNIFIED_SYSTEM_r2.0.md + whitepaper r3.5.1/r3.5.2. Status authority once merged: docs/CANON_STATUS.md (generated; python scripts/gen_canon_status.py --check) and GET /api/v1/status/canon on service-audit-replay.

Prime rule: every surface below ships flag-OFF / config-absent = not_configured, honestly reported. Nothing in this runbook flips an activation or Preview label, enables a writeback, or registers a real holdout/geo — those are separate owner acts with their own evidence.

Tenant self-serve config (owner ruling 2026-08-23, landed 2026-08-27): every TENANT value — F5 treasury declarations, F2 discount/blend + order-economics pointer, F4 geos/cap/bounds + observations pointer, F3 inventory policy, the supply-veto threshold/scope/freshness — is entered by the tenant on the authenticated onboarding surface and read from their vault (economics_declared, via mizoki_contracts.tenant_lane_config; armed by TENANT_LANE_VAULT on the consuming service). The repo config/*.yaml files are SHAPE-ONLY templates that assert nothing, and the lanes no longer consult them for tenant values. Sections below describing "mount a filled copy" workflows are retired where marked.


1. Deploy paths (rule 04: a change that spans services deploys asymmetrically)

Surface Path in repo Deploy mechanism
Governance contracts (treasury, passport, jobs, pilot, canon-status) contracts/mizoki_contracts/** action-runner auto-deploys on merge (deploy-service-action-runner.yml watches contracts/**); policy-engine / audit-replay / DCP are dispatch-only via deploy-governance-services.yml (or operator ops/remediation/deploy_all.sh) — they do NOT redeploy on merge
Intent cells 33/34/35 (IEv2 retention) src/cells/cell33..35/** dispatch-only: deploy-intent-platform.yml (input cells: cell33 \| cell34 \| cell35 \| all) — a human dispatches
Cell 37 (F3) src/cells/cell37/** dispatch-only (deploy-cell37.yml)
net-yield (Workstream C) services/net-yield/** dispatch-only (deploy-net-yield.yml); registry row deployed-dispatch
Command Center UI miz-oki-command-center-ui/** auto-deploys on merge (deploy-ui.yml)
virtuoso-models-service (skillpack v3.2 data) services/virtuoso-models-service/** auto-deploys on merge (deploy-virtuoso-models.yml — watches the service dir only; src/shared/virtuoso_models/** alone does not trigger it, but this branch touches both)
Shared growth_control / creative_aesthetic libraries src/shared/growth_control/**, src/shared/creative_aesthetic/** library code — live only when a consuming service above redeploys

Consequence: after merge, the policy-engine and audit-replay revisions keep serving the old code until an operator runs ops/remediation/deploy_all.sh. That is the intended GATE-2 step, not drift — but never claim a route below is live until the serving revision has it (probe, don't infer).

2. F5 — treasury constraints on the policy engine

2b. Supply-chain stockout veto v2 (policy engine — measured)

3. ValidationPassport packages (audit-replay)

4. Decision Jobs + canon status (audit-replay)

5. 90-day pilot (audit-replay)

6. IEv2 retention sweeps (cells 33/34/35 — dispatch-only deploys)

All sweeps: flag INTENT_RETENTION_SWEEP (default False, ast-pinned); flag-off ⇒ route answers 503 retention_sweep_disabled. All routes are verify_caller-gated. Undatable timestamps KEEP data. Idempotent — safe to re-run. Suggested cadence once enabled: Cloud Scheduler → authed POST, daily; watch each cell's /health for the new fields.

7. F3 — observe-only inventory sync (cell 37)

8. F4 — micro-geo calibration (library; approval-gated by nature)

9. F1 — creative element effects (library)

10. F2 — LTV treatment regimes (library)

11. What stays OFF, and how to prove it

MEASUREMENT_WRITEBACK and NET_YIELD_WRITEBACK remain OFF — each has a fail-if-flipped source-literal test. Verify any suspicion with the tests, not memory:

VENV=<venv with pydantic 2.13.4/fastapi/pyyaml>
$VENV/bin/python -m pytest tests/governance -c tests/governance/pytest.ini
$VENV/bin/python -m pytest services/net-yield -q -p no:cacheprovider --override-ini="addopts="
$VENV/bin/python -m pytest tests/market_signal -q -p no:cacheprovider --override-ini="addopts="
python scripts/gen_canon_status.py --check

Shadow-deploy order for GATE 2 (each step: deploy → probe the serving revision → only then the next): action-runner (auto on merge) → ops/remediation/deploy_all.sh (policy-engine, audit-replay, DCP) → probe /health treasury field + one passport fixture assemble on demo-fixtures → dispatch deploy-intent-platform.yml (cells 33/34/35; probe 503 on sweep routes with flag off) → dispatch deploy-cell37.yml (probe F3 not_configured) → dispatch deploy-net-yield.yml (probe dry-run) → UI (auto). Smokes stay read-only: no flag flips, no real tenants.

← All docsView source on GitHub →