Skip to main content

24 — Reference appendix.

Reference material for technical diligence: glossary, object index, tool-pattern index, action registry, role × permission matrix, event taxonomy, and integration / rollout checklists. All entries are generic platform contracts.

24.1 Glossary

For full definitions, see §4. Selected entries:

24.2 Object schema index

All 28 objects of the Insurance Ontology (§5):

24.3 Tool-pattern index

24.4 Action registry (kinds)

Tenant-specific actions inherit one of these kind families. The platform does not reserve names; tenants register kinds in the action registry.

24.5 Role × permission matrix

Default role grants. Tenants override per their authority model.

24.6 Event taxonomy index

See §17.3 for the full taxonomy. Top-level families:
  • identity.* · policy.* · data.* · ontology.*
  • tool.* · model.* · decision.* · action.*
  • config.* · incident.* · audit.*

24.7 Integration checklist

  • Identity — SSO (SAML/OIDC) bound · SCIM provisioning · MFA required · break-glass policy signed off.
  • Tenancy — Region pin set · BYOK keys provisioned · DR class chosen · audit anchoring chosen.
  • Ingest — Channels enabled · per-channel auth configured · dedupe keys reviewed · rate budgets set.
  • Mappings — Per-source mappings authored · ontology pin set · provenance shape verified · replay sample passes.
  • Tools — Tool registry populated · scopes / markings / purposes declared · contract tests in pack.
  • Agents — Agent definitions reviewed · scopes minimised · budgets set · handoff queues provisioned.
  • Models — Approved registry populated · region pinning enforced · no-train signal verified · evals passing.
  • Action plane — SoR adapters configured · idempotency proven on contract tests · approval policies signed off · compensation paths covered.
  • Security — Markings defined · RBAC + ABAC seeded · purpose taxonomy seeded · PDP latency within SLO.
  • Observability — OTel collector configured · dashboards installed · alert routing set · cost attribution rolled up.
  • DR — RPO/RTO class verified · DR drill scheduled · backup integrity checks run.

24.8 Production rollout checklist

  • Architecture readiness — All planes deployed; contracts verified; per-plane SLOs in green for 30 days.
  • Security readiness — Penetration test cleared; SOC2 / ISO controls mapped; tenant security primary signed off.
  • Model readiness — All approved models passing eval gates; drift baselines stable; calibration up to date.
  • Integration readiness — All adapters in green; idempotency drills passed; reversal drills passed.
  • Governance readiness — Audit chain anchored; legal-hold tested; retention policy enforced.
  • Production readiness — Capacity plan signed off; on-call rotations live; runbooks current; freeze windows declared.
  • Rollout readiness — Canary plan approved; rollback rehearsed; tenant comms plan signed off.
This documentation specifies the platform contract. Concrete tenant configurations — specific models in each lane, specific tools, specific mappings, specific authority limits, specific retention durations — are tenant artefacts and live alongside this documentation under the tenant’s release governance.