Forward-Deployed Engineering08
Handover is the last two weeks of every engagement, not an add-on at the end of one. It closes at a dated exit gate, when your engineers have released, rolled back and retrained the system with ours watching and not touching the keyboard.
FDE / 01Day by day
D1 – D10
The final two weeks of an engagement, drawn as a plan. Each bar ends in something your team holds; the diamonds are the dry run and the exit gate.
If the dry run does not go cleanly, the gate moves and the engagement is not finished, whatever the calendar says.
FDE / 02What crosses over
6 ITEMS
The engagement is complete when every item on this sheet has been checked off by the owner on your side, not by our engineer.
Every operating procedure, executed by your engineers in the dry run before it is signed. A step nobody on your side has performed is not in the runbook yet.
Each architectural decision, the options considered and why one was taken, dated, so the next engineer knows what was tried and why.
The golden set, the harness and the regression run, in your pipeline, run by your engineers in the dry run.
Every credential rotated in the last week, held in your vault under your identity provider. Ours are revoked at the gate.
Your rota carries the pager from the gate. Our engineer is second on it for an agreed period, then removed.
One named person on your side who has released, rolled back and retrained the system without us on the keyboard.
FDE / 03How handover is run
They make the exit real. Each is agreed at scoping and holds until the gate is passed.
The exit gate is written into the scope with its date and its criteria. Both sides can see it coming from the first week, so handover is planned into the build rather than squeezed after it.
From the midpoint of the engagement your engineers review more, deploy more and decide more, and ours less. By the last fortnight our engineer is answering questions, not doing the work. A handover that starts on the last day is not a handover.
A runbook step is signed when one of your engineers has done it with ours watching. A document read is not a procedure learned. The dry run is where this is proved.
Our engineer's credentials are revoked when the gate is passed, and that revocation is the last item on the manifest. Anything we need afterwards, we ask for, and it is granted for a task and then removed.
FDE / 04Specified
10 FIELDS
The terms as they stand inside every engagement. The system moves the detail; it does not move the shape.
FDE / 05Fit
FDE / 06Questions
6 QUESTIONS
No. It is the last two weeks of every engagement and part of the fee. A Production Sprint ends with it; a pod's quarter ends with it. It is scoped on its own only for a system that somebody else built and left.
A date and a set of criteria, written into the scope before week one: the dry run passed, the manifest ticked by your side, the runbook signed, our access revoked. If the criteria are not met, the date moves; the criteria do not.
It is usually visible weeks before the gate, because dependency is meant to decrease every week and we report on it. If the dry run does not pass, the gate moves and we stay until it does. If there is nobody to take the system, we say so and the honest option is to keep us running it.
Revoked at the gate, and that revocation is the last item on the manifest. Credentials are rotated in the final week so nothing we held is still valid. If you need us afterwards, access is granted for a task and removed after it.
It lives in your repository next to the code, and a change to the system is not merged without the runbook step it affects. Your engineers own it from the gate; the decision record explains why each step is the way it is.
Our engineer is second on your on-call rota for an agreed period, then removed. Beyond that, Managed Operations exists if you would rather we keep running the system, and a scoped sprint exists if you want it changed.
FDE / ENDStart
Book a scoping call; you leave it knowing what your team would need to hold at the end and when the gate would fall.