EX-01 / SYNTHETIC FINDING
Make the recovery decision and owner explicit.
High before the next production release- Observation in this example
- The synthetic change record names the implementer but has no recovery decision owner. Its runbook contains no linked validation result.
- Why it matters
- If a release fails, the team may not know who decides to stop or recover, or which procedure has been demonstrated.
- Priority and rationale
- Resolve before a production release because recovery ownership affects service continuity. Reassess this priority if a current, accepted procedure and accountable owner already exist.
- Evidence and confidence
- Based only on the synthetic change record and runbook outline. Actual permissions, recoverability and business impact have not been assessed.
- Next action and owner
- The client service owner names the release/recovery approver. The delivery lead prepares the scoped workflow, acceptance checks and recovery exercise for approval.
- What remains unknown
- Workload criticality, recovery objectives, data dependencies, the approved recovery method and the result of any rehearsal.