SYSTEM STATE
StableFounder ControlledHuman Reviewed
DEPLOYMENT CONTROL
If deployment breaks, TheoB should know what broke before anyone panics.
Deployment Health Gate checks whether critical providers and credentials have purpose, ownership, rotation policy, alert rules, safe agent access, and human review.
Review Required · GitHub
GitHub Access83% deployment readinessWarn before expiration, failed auth, or unusual repo access.
✓ Purpose DefinedSource control, repo access, pushes, actions, deployment triggers.
✓ Owner DefinedFounder / Internal Technician
✓ Rotation Policy90 days or immediately after suspicion
✓ Agent Access Rulerequest-only
✓ Alert RuleWarn before expiration, failed auth, or unusual repo access.
• Human Reviewrequired before critical credential or production recovery action
Review Required · Vercel
Vercel Deployment83% deployment readinessWarn on failed build, expired token, domain issue, or deployment slowdown.
✓ Purpose DefinedProduction deploys, preview builds, rollback, domain deployment state.
✓ Owner DefinedFounder / Internal Technician
✓ Rotation Policy90 days or provider-policy based
✓ Agent Access Ruleprepare-only
✓ Alert RuleWarn on failed build, expired token, domain issue, or deployment slowdown.
• Human Reviewrequired before critical credential or production recovery action
Review Required · Hostinger / VPS
Hostinger / VPS Root83% deployment readinessWarn on SSH failure, server overload, login anomaly, or uptime drop.
✓ Purpose DefinedBackend runtime, server fixes, logs, agents, heavy services.
✓ Owner DefinedFounder only with delegated technician access
✓ Rotation Policyimmediate after emergency access or staff change
✓ Agent Access Ruleblocked-direct
✓ Alert RuleWarn on SSH failure, server overload, login anomaly, or uptime drop.
• Human Reviewrequired before critical credential or production recovery action
Review Required · Runtime / Vercel / VPS
Environment Variables83% deployment readinessWarn on missing env var, invalid secret, exposed value, or stale config.
✓ Purpose DefinedAPI keys, service URLs, secrets, database strings, agent configs.
✓ Owner DefinedInternal Technician
✓ Rotation Policyper-key policy
✓ Agent Access Rulemasked-request
✓ Alert RuleWarn on missing env var, invalid secret, exposed value, or stale config.
• Human Reviewrequired before critical credential or production recovery action
Review Required · Redis
Redis / Cache83% deployment readinessWarn on quota pressure, latency spikes, missing connection, or auth failure.
✓ Purpose DefinedLive queues, sessions, agent state, rate limits, fast coordination.
✓ Owner DefinedInfrastructure Technician
✓ Rotation Policy90 days or incident-based
✓ Agent Access Rulescoped-service
✓ Alert RuleWarn on quota pressure, latency spikes, missing connection, or auth failure.
• Human Reviewrequired before critical credential or production recovery action
Review Required · Postgres
Postgres / Database83% deployment readinessWarn on connection failure, slow queries, storage pressure, or suspicious writes.
✓ Purpose DefinedPersistent memory, users, audit logs, event anchors, operational records.
✓ Owner DefinedFounder / Database Technician
✓ Rotation Policy90 days or migration-based
✓ Agent Access Rulescoped-service
✓ Alert RuleWarn on connection failure, slow queries, storage pressure, or suspicious writes.
• Human Reviewrequired before critical credential or production recovery action
Review Required · Weather / News / Maps / AI / Payments
External APIs83% deployment readinessWarn on quota burn, expiry, billing spikes, degraded source, or failed calls.
✓ Purpose DefinedLive signals, intelligence feeds, maps, models, payment workflows.
✓ Owner DefinedProvider-specific operator
✓ Rotation Policyprovider-policy based
✓ Agent Access Rulescoped-request
✓ Alert RuleWarn on quota burn, expiry, billing spikes, degraded source, or failed calls.
• Human Reviewrequired before critical credential or production recovery action
HEALTH RULES
Deployment health is operational self-awareness.
Every critical provider needs owner, purpose, alert, and recovery awareness.
Agents may diagnose and prepare fixes, but cannot expose secrets.
Failed deployment should trigger rollback, notification, and incident memory.
Token expiration should be detected before it blocks a deploy.
Provider lock-in risk must be tracked before scale.
No production recovery should depend on one undocumented human action.