Customer operator runbook
Operate the deployment after launch, including health checks, runtime coverage, Risk Signals, Cases, backup readiness, and support handoff.
Prerequisites
- CloudFormation deployment complete
- Operator access to Service Health
- At least one intended runtime route selected
Day 1 operating scope
- Operate the CloudFormation foundation and runtime stacks, application domain, TLS, load balancer, web app, gateway, services, and Service Health states.
- Track the three runtime coverage routes separately: Browser Extension, SDK/API or AI Gateway, and MCP Gateway.
- Treat observed applications as inventory and telemetry signals, not automatic governed routes.
Day 2 routine operations
- Review Service Health for degraded or unreachable services.
- Review Risk Signals, open Cases, unresolved approvals, high-risk policy actions, and Audit Log changes.
- Review Admin MCP configuration activity through the same RBAC and Audit Log controls as web UI changes.
- Review AI Spend for missing usage data, unpriced usage, import failures, budget blocks, or unexpected usage spikes.
- Confirm backup completion and retention status.
Support handoff
- Collect the safe request, Risk Signal, or Case ID; release tag; timestamp; affected route; Service Health state; and the last visible customer-safe error.
- Include relevant CloudFormation stack events, load balancer target state, or application health results when available.
- Do not share secrets, tokens, raw cookies, full authorization headers, or unredacted prompt/output content.
Validate
- Stack outputs and application domain confirmed
- Service Health states reviewed
- Runtime coverage routes selected
- Backup status reviewed
- Case and support handoff details understood
Next steps
- Run runtime coverage checks
- Review AI Spend telemetry states
- Confirm Risk Signal, Case, and backup workflows