Agent update lifecycle — who controls updates, how you are notified, and what happens to your cluster.
This page covers how the Layerup AI Agent is updated over time, with a clear distinction between the two deployment models. For Option 2 (your private cloud), your CI/CD pipeline controls every promotion — see CI/CD Pipeline & Deployment Strategies for that model. This page is specifically for Option 3 (Layerup’s Cloud), where Layerup operates the dedicated cluster on your behalf.The fundamental difference: who controls promotion
Two update categories
Category 1 — Non-critical updates (new capabilities, performance improvements, dependency refreshes)
Non-critical updates include new agent capabilities, OCR pipeline improvements, dependency version refreshes, performance optimisations, and LLM orchestration framework updates that do not address a confirmed security vulnerability. Advance notice: Layerup sends a release notification to your designated technical contact at least 14 calendar days before the update is scheduled to be applied to your dedicated cluster. The notification includes:- A changelog describing all changes in the new version
- The scheduled maintenance window (date, time, expected duration — maximum 30 minutes)
- A link to the updated SBOM and Cosign-signed image digest
- Instructions for submitting a freeze request if needed
Category 2 — Critical security patches (CVSS ≥ 7.0 vulnerabilities)
Critical security patches address confirmed vulnerabilities in the agent container, its dependencies, or the underlying OS layer.
For Critical patches, Layerup will notify your designated contacts as soon as the patch is confirmed ready, with a minimum 48-hour window before application. For CVSS ≥ 9.0 vulnerabilities, freeze requests do not apply — Layerup will apply the patch to protect the integrity of your cluster and the BAA obligations.
Freeze requests
What a freeze is
A freeze request instructs Layerup not to apply a scheduled non-critical update to your dedicated cluster. Freeze requests are honored for up to 90 calendar days from the scheduled update date. When to use a freeze:- Your team has a live regulatory examination or audit period where any system change must be avoided
- Your organization’s change freeze calendar prohibits non-emergency changes during a specific period
- Your integration team needs additional time to validate a specific release against your UAT environment before it is applied to production
How to request a freeze
Submit a freeze request to your Layerup implementation engineer at least 5 business days before the scheduled maintenance window. Include:- The specific update version you are requesting to freeze
- The duration of the freeze (up to 90 days)
- The reason (optional, but useful for Layerup to plan the rescheduled window)
Freeze limits and exceptions
Pre-update validation
Before applying any update to your dedicated cluster, Layerup runs an automated validation against a representative sample of your cluster’s recent processing history:- Shadow run: The new agent version is run against the 100 most recent cases from your cluster (from the shadow mode log — no live cases are re-processed). Shadow outputs are compared against the outputs produced by the current production version.
- Regression check: Layerup’s release team reviews any recommendation-level differences between the shadow and production outputs. A diff rate above 2% on any decision type blocks the release from being applied to your cluster until the discrepancy is investigated.
- Performance check: Processing time and confidence score distributions are compared against your cluster’s established baseline. A statistically significant shift in either metric blocks the release.
Rollback
If a production regression is confirmed after an update is applied to your dedicated cluster, Layerup will execute a rollback to the prior version within 4 hours of a confirmed regression report.How to report a regression
Contact your Layerup implementation engineer via the dedicated support channel (provided during the deployment engagement). Include:- The case IDs exhibiting anomalous behavior
- The specific output dimension that appears incorrect (recommendation type, confidence score range, evidence citation quality)
- The approximate time the anomaly started (to correlate with the update application time)
Update notification contacts
During the deployment engagement, your organization designates:
Contact designations can be updated at any time by notifying your Layerup implementation engineer.

