Forward-Deployed Engineering08

The engagement endswhen your team runs itwithout us in the room.

Handover is the last two weeks of every engagement, not an add-on at the end of one. It closes at a dated exit gate, when your engineers have released, rolled back and retrained the system with ours watching and not touching the keyboard.

HANDOVER TRANSFERTransferring
SOLONOMOUSYOUR TEAM
  1. Runbook
  2. Decision record
  3. Evaluation suite
  4. Keys
  5. On-call
When
The last two weeks of any engagement
Exit gate
Dated at scoping, written down
Dry run
Your engineers on the keyboard
After
We hold no standing access

FDE / 01Day by day

D1 – D10

The last ten days.

The final two weeks of an engagement, drawn as a plan. Each bar ends in something your team holds; the diamonds are the dry run and the exit gate.

D1D2D3D4D5D6D7D8D9D10
RunbookDeploy, rotate credentials, retrain, roll back, escalate; written by our engineer, corrected by yours
TrainingYour engineers have run the harness, read the dashboards and changed a threshold, each once with us and once alone
Dry runA release, a rollback and a retrain performed by your engineers with ours in the room and off the keyboard
On-callYour rota carries the pager; ours is second on it for the agreed period after the gate
Exit gateThe manifest ticked by your side, the runbook signed, our access revoked

If the dry run does not go cleanly, the gate moves and the engagement is not finished, whatever the calendar says.

FDE / 02What crosses over

6 ITEMS

Six items, ticked by your side.

The engagement is complete when every item on this sheet has been checked off by the owner on your side, not by our engineer.

HANDOVER MANIFEST6 ITEMS
  • The runbook

    Every operating procedure, executed by your engineers in the dry run before it is signed. A step nobody on your side has performed is not in the runbook yet.

  • The decision record

    Each architectural decision, the options considered and why one was taken, dated, so the next engineer knows what was tried and why.

  • The evaluation suite

    The golden set, the harness and the regression run, in your pipeline, run by your engineers in the dry run.

  • The keys

    Every credential rotated in the last week, held in your vault under your identity provider. Ours are revoked at the gate.

  • The on-call

    Your rota carries the pager from the gate. Our engineer is second on it for an agreed period, then removed.

  • The trained owner

    One named person on your side who has released, rolled back and retrained the system without us on the keyboard.

FDE / 03How handover is run

Four rules.

They make the exit real. Each is agreed at scoping and holds until the gate is passed.

  1. The gate is dated before the work starts

    The exit gate is written into the scope with its date and its criteria. Both sides can see it coming from the first week, so handover is planned into the build rather than squeezed after it.

  2. Dependency decreases every week

    From the midpoint of the engagement your engineers review more, deploy more and decide more, and ours less. By the last fortnight our engineer is answering questions, not doing the work. A handover that starts on the last day is not a handover.

  3. Nothing is signed that has not been performed

    A runbook step is signed when one of your engineers has done it with ours watching. A document read is not a procedure learned. The dry run is where this is proved.

  4. Access ends at the gate

    Our engineer's credentials are revoked when the gate is passed, and that revocation is the last item on the manifest. Anything we need afterwards, we ask for, and it is granted for a task and then removed.

FDE / 04Specified

10 FIELDS

Handover, specified.

The terms as they stand inside every engagement. The system moves the detail; it does not move the shape.

Shape
The last two weeks of any engagement; part of the fee, not an option
Exit gate
Dated and written into the scope before week one, with the criteria for passing it
Who must be there
The owner of the outcome and at least one engineer on your side who will run the system
The runbook
Deploy, rotate credentials, retrain, roll back, escalate; each step performed by your engineer before it is signed
The decision record
Dated entries: the decision, the options considered, the reason; kept in the repository
The dry run
A release, a rollback and a retrain by your engineers with ours in the room and off the keyboard
Training
By doing, in your tools, on the real system; no slide deck
On-call after the gate
Your rota first; our engineer second for an agreed period, then removed
Access after the gate
None standing; granted for a task on request and removed after it
If the dry run fails
The gate moves, the fixes are written down and the engagement is not finished until it passes

FDE / 05Fit

Ready to hand over

Handover is ready when

  • The workflow runs on real traffic with monitoring live and rollback armed
  • At least one engineer on your side has been reviewing and deploying for weeks
  • The runbook has been executed end to end by your engineers
  • The golden-set score is above threshold and your team can run the harness
  • The owner on your side can name who is on call next week

It is not when

  • The system still runs only in a staging environment
  • Nobody on your side has approved a pull request on it
  • The runbook exists but only our engineer has followed it
  • No one has been named to carry the pager
  • Your team has no capacity to run it; Managed Operations is the honest answer, not a handover

FDE / 06Questions

6 QUESTIONS

Asked about handover.

Is handover a separate engagement?

No. It is the last two weeks of every engagement and part of the fee. A Production Sprint ends with it; a pod's quarter ends with it. It is scoped on its own only for a system that somebody else built and left.

What does the exit gate consist of?

A date and a set of criteria, written into the scope before week one: the dry run passed, the manifest ticked by your side, the runbook signed, our access revoked. If the criteria are not met, the date moves; the criteria do not.

What if our engineers are not ready?

It is usually visible weeks before the gate, because dependency is meant to decrease every week and we report on it. If the dry run does not pass, the gate moves and we stay until it does. If there is nobody to take the system, we say so and the honest option is to keep us running it.

What happens to your access?

Revoked at the gate, and that revocation is the last item on the manifest. Credentials are rotated in the final week so nothing we held is still valid. If you need us afterwards, access is granted for a task and removed after it.

How is the runbook kept current?

It lives in your repository next to the code, and a change to the system is not merged without the runbook step it affects. Your engineers own it from the gate; the decision record explains why each step is the way it is.

What support exists after the gate?

Our engineer is second on your on-call rota for an agreed period, then removed. Beyond that, Managed Operations exists if you would rather we keep running the system, and a scoped sprint exists if you want it changed.

FDE / ENDStart

The exit gate is writtenbefore the first commit.

Book a scoping call; you leave it knowing what your team would need to hold at the end and when the gate would fall.