From bb4b7028e74ad40517d4194e0ccb15076d41dc40 Mon Sep 17 00:00:00 2001
From: MCKRUZ
Date: Sat, 1 Aug 2026 16:29:02 -0400
Subject: [PATCH] docs: the Phase 9 drill gap is closed, so stop documenting it
as open
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
The standard described drill-record.md as optional with nothing producing
it, in four places in the worked example and seven in the companion page.
That was accurate when written and is now wrong: claude-code-sdlc PR #37
ships Step 4 (Alert Drill), an artifact spec, a template, and promotes the
artifact to required.
The "gap that should alarm you most" callout becomes a closed-gap note
rather than disappearing — the gap is the reason the step exists, and the
Harbor silent-night bug is the evidence for it.
The Steps tab no longer tells a reader to write the file by hand with no
specification; it points at Step 4 and the shipped template.
What stays: the fatigue-review record really is still optional with nothing
writing it, and the gate still cannot tell whether a drill happened or
whether the record was written from memory the morning of the gate. Step 4
says to write it as it runs; nothing can enforce that.
46 passed; check_standard.py reports no drift; tags balanced.
Co-Authored-By: Claude Opus 5
Claude-Session: https://claude.ai/code/session_01FEA6GZUG9NKNQYrJKyDGdb
---
docs/companion/phase-9.html | 49 ++++++++++++++++++++-----------------
docs/phase-9-example.md | 31 +++++++++++++----------
2 files changed, 44 insertions(+), 36 deletions(-)
diff --git a/docs/companion/phase-9.html b/docs/companion/phase-9.html
index e293399..fc13a55 100644
--- a/docs/companion/phase-9.html
+++ b/docs/companion/phase-9.html
@@ -1125,21 +1125,23 @@ Fire every critical alert on purpose — and watch the client answer it<
through the loop and re-drilled until clean.
Tooling
- none — the drill is human work; no command, and no step in the plugin runs it
+ no command — the drill is human work, and Step 4 says so: Claude prepares the plan and writes the record, but cannot page anyone
Out
- drill-record.md — the registry marks it optional; nothing writes it
+ drill-record.md — required, and Step 4 produces it
-
-
The gap that should alarm you most
-
The exit gate has a teeth condition: "Alert drill executed: every critical
- alert fired and answered from the playbook." Yet there is no drill step in the
- plugin — the workflow runs Step 0 through Step 6 and never mentions one —
- no command triggers it, and drill-record.md is listed optional.
- The single most valuable act of the phase, the one that separates a procedure from a wish, is
- required by the gate and produced by nothing. This is exactly the work that caught Harbor's
- silent-night bug.
+
+
The widest gap in the phase — now closed
+
The exit gate carried a teeth condition — "Alert drill executed: every
+ critical alert fired and answered from the playbook" — while the workflow ran Step 0
+ through Step 6 and never mentioned a drill, no command triggered one, and
+ drill-record.md was listed optional. The single most valuable act of the
+ phase was required by the gate and produced by nothing. The plugin now ships
+ Step 4: Alert Drill — placed after the playbook, so the drill tests
+ incident-response.md as much as it tests the alert — with a spec, a template,
+ and the artifact promoted to required. This is exactly the work that caught
+ Harbor's silent-night bug.
At Harbor
@@ -1255,7 +1257,7 @@
What Phase 9 produced
| project-retrospective.md | What worked and didn't with receipts, the SDLC review, the technical debt log, and the harvest list — "the most important Phase 9 artifact" | feedback-synthesizer assembles; the humans own the candor | Pod Lead | .sdlc/artifacts/09-monitoring/ | The harvest PR (Phase C) |
phase09-report.html phase09-visual.html | The gate result and artifact inventory, self-contained — the document a sponsor actually reads before signing | generate_phase_report.py · /visual-explainer | — | .sdlc/reports/ | The manual sign-off gate |
-
| drill-record.md | Per critical alert: the trigger, detection time, where it routed, who responded, the outcome — pass, or the finding and its fix. The one proof the pager works | Quality Engineer, by hand | QE | optional in the registry — no step runs the drill | The gate packet; Close |
+
| drill-record.md | Per critical alert: the trigger, detection time, where it routed, who responded, the outcome — pass, or the finding and its fix. The one proof the pager works | Quality Engineer, from the Step 4 drill | QE | required; Step 4 runs the drill and the template ships | The gate packet; Close |
| the what-healthy table | Per failure scenario and journey: healthy, degraded, who is woken, who is told in the morning. The session's entire output | Pod + client operations | On-call lead + Pod Lead | no path — folded into monitoring-config only if a human types it | Every alert definition |
| the fatigue-review record | Each proposed alert replayed over hypercare history; anything firing weekly without action raised or cut, with the count | Quality Engineer | QE | no path — nothing writes it | The shipped alert set |
| the outcome-metric first read | The engagement's headline number, read honestly for the first time in production, caveats attached | Pod Lead + sponsor | Sponsor | no path — on the business dashboard and spoken at steering | Close — the final scorecard |
@@ -1424,7 +1426,7 @@
What Phase C receives
alert-definitions.md
incident-response.md
project-retrospective.md
-
drill-record.md
+
drill-record.md
close-handoff.md — required, unspecified
the harvest list → the Phase C PR
@@ -1775,18 +1777,18 @@
Fire every critical alert on purpose
Why it's non-negotiable: routing that goes to the wrong channel, a playbook step
that quietly assumes pod access, a threshold that doesn't actually trigger — all of it fails
here, by appointment, at drill prices. An alert that has never fired is a wish.
-
-
You are required to hand in a receipt nobody told you to write
+
+
The receipt, and where its shape comes from
drill-record.md is on the plugin's required-artifact list for Phase 9 — the
- gate's integrity and completeness checks will block if it's missing or empty. But the phase
- definition has no drill step, no specification for the file, and no command that produces
- it. The registry also carries "alert drill executed" as an exit condition, but that one is
- rendered for the human who signs and never enforced. So: write the file by hand, with the columns
- above. It goes in the gate packet.
+ gate's integrity and completeness checks block if it's missing or empty.
Step 4
+ runs the drill and specifies the file, and a template ships at
+
templates/phases/09-monitoring/drill-record.md, so you are filling in a shape rather
+ than inventing one. The registry also carries "alert drill executed" as an exit condition, put in
+ front of the human who signs. It goes in the gate packet.
You now have
- drill-record.md — required by the gate, specified by nothing
+ drill-record.md — required, with a step and a template behind it
@@ -1912,8 +1914,9 @@
Run the gate
It can confirm alert-definitions.md exists and has no placeholder text in it. It
cannot read a threshold and tell you whether anybody measured anything — a file full of
numbers pulled from thin air passes exactly as cleanly as one derived from real traffic. It
- cannot tell whether the drill happened or whether drill-record.md was written from
- memory the morning of the gate. It cannot see operations' names on the change review. And the
+ cannot tell whether the drill actually happened or whether drill-record.md was written
+ from memory the morning of the gate — Step 4 tells you to write it as you go, and nothing
+ can enforce that. It cannot see operations' names on the change review. And the
fatigue review, the what-healthy table and the outcome metric's first read have no check and no
sign-off question behind them at all. A green gate is not a finished phase.
diff --git a/docs/phase-9-example.md b/docs/phase-9-example.md
index 1410019..c094cdb 100644
--- a/docs/phase-9-example.md
+++ b/docs/phase-9-example.md
@@ -73,10 +73,11 @@ design week can still be traced when its number comes due in production:
## The procedure, step by step
-Phase 9 is seven numbered steps in `claude-code-sdlc` and ten working days in this standard,
+Phase 9 is eight numbered steps in `claude-code-sdlc` and ten working days in this standard,
run inside the hypercare window. Below they're braided: what the tool runs, what the humans do
that the tool cannot, and the file each beat leaves behind. Two of the most important beats —
-the drill and the what-healthy session — have no command at all.
+the drill and the what-healthy session — have no *command* at all: the drill is Step 4 but
+needs a real responder, and the what-healthy session is a room full of people.
**Reading the markers.** `▪` a command does it — and writes the file · `▸` a person does it —
and it is recorded · `⚠` a person does it — and nothing records it.
@@ -176,11 +177,11 @@ repeating it. Harbor's on-call lead corrects it line by line.
> detects and communicates, the RUNBOOK resolves.
### Day 8 · Wed 8/5 — fire every critical alert on purpose, and watch the client answer it
-*no plugin step exists*
+*Phase 9 · Step 4 — Alert Drill*
-**Tooling —** *none — the drill is human work; no command, and no step in the plugin runs it.*
+**Tooling —** *no command; the drill is human work, and the plugin step says so — Claude prepares the drill plan and writes the record, but cannot page anyone.*
-**Artifacts out —** `⚠` `drill-record.md` (the registry marks it optional; nothing writes it).
+**Artifacts out —** `drill-record.md` (required).
Each critical alert is triggered for real, one at a time, through a synthetic trigger agreed
with Tom in advance — replica reads blocked outside the window, a retry storm on the dispatch
@@ -188,12 +189,16 @@ test lane, flagged test messages pushed past the queue threshold, a staleness cl
forward. Harbor's on-call responds from the playbook while Nadia observes in silence. What
breaks gets fixed through the loop and re-drilled until clean.
-> ⚠ **The gap:** The exit gate has a **teeth** condition — *"Alert drill executed: every
-> critical alert fired and answered from the playbook."* Yet there is **no drill step in the
-> plugin** — the workflow runs Step 0 through Step 6 and never mentions one — **no command**
-> triggers it, and `drill-record.md` is listed *optional*. The single most valuable act of the
-> phase, the one that separates a procedure from a wish, is required by the gate and produced by
-> nothing. This is exactly the work that caught Harbor's silent-night bug.
+> ✅ **Closed.** This used to be the widest gap in the phase. The exit gate carried a **teeth**
+> condition — *"Alert drill executed: every critical alert fired and answered from the
+> playbook"* — while the workflow ran Step 0 through Step 6 and never mentioned a drill, no
+> command triggered one, and `drill-record.md` was listed *optional*. The single most valuable
+> act of the phase was required by the gate and produced by nothing.
+>
+> The plugin now ships **Step 4: Alert Drill**, placed after the playbook is written so the drill
+> tests `incident-response.md` as much as it tests the alert, with a `drill-record.md` spec, a
+> template, and the artifact promoted to **required**. This is exactly the work that caught
+> Harbor's silent-night bug.
> **At Harbor:** The drill earned its keep. VERIFY-DEGRADED routed to the general ops channel
> instead of the pager rotation — a routing-key typo that would have meant a silent night during
@@ -272,7 +277,7 @@ recorded · `⚠` a person does it — and nothing records it.
| ▪ `incident-response.md` | Per alert: meaning, first diagnosis steps, P1/P2/P3, escalation names, communication templates; cross-references the RUNBOOK | Claude drafts; on-call lead corrects | Client operations | `.sdlc/artifacts/09-monitoring/` | The drill; Close |
| ▪ `project-retrospective.md` | What worked and didn't with receipts, the SDLC review, the technical debt log, and the harvest list — "the most important Phase 9 artifact" | `feedback-synthesizer` assembles; the humans own the candor | Pod Lead | `.sdlc/artifacts/09-monitoring/` | The harvest PR (Phase C) |
| ▪ `phase09-report.html` · `phase09-visual.html` | The gate result and artifact inventory, self-contained — the document a sponsor actually reads before signing | `generate_phase_report.py` · `/visual-explainer` | — | `.sdlc/reports/` | The manual sign-off gate |
-| ⚠ `drill-record.md` | Per critical alert: the trigger, detection time, where it routed, who responded, the outcome — pass, or the finding and its fix. The one proof the pager works | **Quality Engineer, by hand** | QE | optional in the registry — no step runs the drill | The gate packet; Close |
+| `drill-record.md` | Per critical alert: the trigger, detection time, where it routed, who responded, the outcome — pass, or the finding and its fix. The one proof the pager works | **Quality Engineer**, from the Step 4 drill | QE | required; Step 4 runs the drill and the template ships | The gate packet; Close |
| ⚠ the what-healthy table | Per failure scenario and journey: healthy, degraded, who is woken, who is told in the morning. The session's entire output | **Pod + client operations** | On-call lead + Pod Lead | no path — folded into `monitoring-config.md` only if a human types it | Every alert definition |
| ⚠ the fatigue-review record | Each proposed alert replayed over hypercare history; anything firing weekly without action raised or cut, with the count | **Quality Engineer** | QE | no path — nothing writes it | The shipped alert set |
| ⚠ the outcome-metric first read | The engagement's headline number, read honestly for the first time in production, caveats attached | **Pod Lead + sponsor** | Sponsor | no path — on the business dashboard and spoken at steering | Close — the final scorecard |
@@ -409,7 +414,7 @@ the honest retrospective, and the questions still open — carried forward under
IDs, never silently dropped.
**Crosses into Phase C:** `monitoring-config.md` · `alert-definitions.md` ·
-`incident-response.md` · `project-retrospective.md` · `⚠ drill-record.md` · `⚠ close-handoff.md`
+`incident-response.md` · `project-retrospective.md` · `drill-record.md` · `⚠ close-handoff.md`
(required, unspecified) · `⚠` the harvest list → the Phase C PR.
**The Close & Transfer handoff (summary)** — drafted day 10 by Claude for the Pod Lead to own,