# Lamp release acceptance

Lamp's useful outcome is one business operating a public status page and incident
communication desk from its own installation. An operator must be able to sign in,
maintain real components, publish and resolve an incident, schedule maintenance,
manage confirmed subscribers, and inspect actual notification outcomes. Customers
must receive complete, private, script-independent status information and control
their own subscriptions. The accepted public design and every obligation in
`CONTRACT.md` and `BASELINE.md` remain part of this release; no clause is waived by
this document.

A complete release requires an exact committed candidate, a fresh frozen-lockfile
install and full `pnpm verify`, with no skipped or failed requirements, plus:

- Empty owner-account setup and repeat deployment that preserve existing data.
- Native emailed sign-in, confirmation, incident lifecycle, maintenance, subscriber
  management and erasure, alert intake, reports and configured AI in real browser
  journeys, including mobile and script-disabled public access.
- Authorized mail-provider acceptance, signed delivery events and received-message
  evidence for DKIM unsubscribe-header coverage and no tracking. API acceptance
  alone never proves mailbox receipt. A controlled webhook receiver must verify
  the complete signed notification and failure behavior.
- Original-data export, clean restore, equivalent re-export, failed-restore recovery,
  previous-release migration and preserved owner customisations/intent.
- D1, Queue and R2 failure branches: public retained snapshots remain readable,
  `/health` reports dependency failure, failed work is visible, and recovery
  publishes current data. Cached outage proof states whether the edge was warm;
  it must never be represented as independently hosted global outage protection.
- A release record that names the exact source/tag and deployment, provider,
  browser, recovery and verification receipts, separate from source metadata.

## Release evidence boundary

Version 1.1.0 adds real SendGrid support, deployment and restore correctness, owner
sidecar migrations, delivery acceptance details, and a verified native AI adapter
configuration. The original local 1.0.0 release is preserved. Local behavior suites
and provider-shaped test fixtures do not constitute live acceptance.

Completion evidence is recorded externally at
`/Users/zemaj/.orchestrator/evidence/statuspage/lamp-complete/` in this authoring
workspace. An owner adopting this source should record the same outcomes for
their own installation; source metadata alone does not prove a release.

Hosted installation, native magic-link and invitation sign-in, confirmed
subscription, incident/report publication, scheduled maintenance, alert intake,
configured AI, signed delivery receipts, received DKIM unsubscribe-header
coverage, controlled webhook HMAC verification and one-click unsubscribe have
now been observed on the owner installation. The malformed-R2-pointer test
retained warmed artifacts beyond their normal freshness interval and restored
the exact original pointer; an uncached request during that fault returned 503.
Remote restore/equality has now preserved 39 tables, 119 rows and 98 R2 objects with
exact bytes and metadata. Temporary production identities and records have been
erased, preserving the original owner and anonymised audit attribution. The final release receipt separately identifies native publication from the
restored deployment, the integrated CI result and the release decision. These observations are separate
from the green local verifier.
