An artifact strong enough to trust is strong enough to forge. Part 7 of the Proof Series: the other lanes of a migration, gates on named facts, and the signature chain no single person can produce.
Part 6 ended with the buyer's question, and it is the right one to end on. The seal defends itself against regression. It cannot defend itself against its own creation. Suppose one administrator's account can confirm the pairs, seal the map, and sign the acceptance. Then the artifact proves one thing only: a single person was very busy, once, at two in the morning.
An auditor knows this, which is why auditors weigh self-generated evidence near zero. So this last part answers two questions. Who may produce the artifact, and what do the phase gates demand before anyone gets the chance?
First, a widening the data conversation usually skips. Parts 2 through 6 followed one lane, the data. A real migration runs on four, and each carries its own kind of claim.
The code lane holds the custom logic a company built into its old system over twenty years. Little of it can map to the new system, because the new system keeps its behavior in configuration rather than in code. So a custom code element does not get a mapping. It gets a verdict, one of three: absorbed into configuration, rebuilt as something new, or retired. A verdict is only recordable over confirmed evidence of what the code touches, never over a guess. Every element must carry one before the phase that consumes them closes.
The configuration lane mirrors the field map's law. A setting on the old side corresponds to a setting on the new side, and suggestion and confirmation stay different objects. A confirmed parent comes before the detail, exactly as the table pair came before the columns.
The process lane carries the claims about how work flows, and it holds the subtlest rule of the four. A process step is not proven by a structural match alone. Something that looks connected is a hypothesis, and a hypothesis cannot clear a process anchor by itself. Evidence clears it, or a person does.
Four lanes, one discipline. In every lane, the tiers never blur, the confirmations carry provenance, and the sealed never mixes with the suggested.
Now watch what a phase gate does with those lanes, because this is where most governance software goes soft.
The usual gate is a percentage. Readiness at ninety-two percent, and the room decides that ninety-two is close enough, and nobody can say what lives inside the missing eight. A percentage is an argument. Our gates do not argue.
A phase advances when specific, named things are true. Every unmatched object carries one of three dispositions: it migrates, it retires, or it is out of scope with a reason. Every custom code element carries its fate. Every critical risk is dispositioned, or accepted with a countersignature from someone entitled to accept it. Every claimed object stands on a human warrant.
The gate reads those facts from the record, and each count on the screen is a link to the list behind it. The question why is this blocked has a literal answer: these items, these owners.
There is no close enough at a gate like that, and there is also no mystery. The gap is never a percentage. It is a list of named things with names attached, which is exactly what a stalled migration needs and a status meeting never produces.
Then the chain itself, and the rule that makes it credible.
The separation is structural. The person who confirms a mapping is not the person who proposed it. The person who seals is not among the people whose confirmations the seal rests on, past a set share. And the business signer at the end is a business owner who prepared none of what they are signing. At Danubia, the analyst confirmed pairs she did not propose. The delivery lead sealed a map she did not confirm, and the finance director signed an acceptance he took no part in preparing.
The enforcement lives where our whole platform puts its rules: at the single writer that records the act, never in the user interface. A screen can be redesigned, and a script can call an interface directly. Neither can route around a writer that refuses the same identity twice in one chain.
The acceptance obeys one more rule, and it is the one auditors care most about. The system's own output is never the acceptance evidence for the system's own output. The business signs over reports produced by the target system's own reporting engine, brought across and stamped so nobody can quietly swap them. It also signs over checks the business re-performed itself. Our platform holds the chain and the proof. The evidence that the migration worked comes from the thing that was migrated to, which is the only place it can honestly come from.
Even the emergency path keeps the shape. A hotfix lane exists, because production does not wait for quorums. It defers the ratification, never the record: the act lands with its identity attached, and the review it skipped is owed, tracked, and completed after.
Two boundaries close the series' honest ledger, in the same spirit as every boundary before them.
We do not execute your migration, and nothing in this part changes that. The loading, the cutover weekend, the scripts: your integrator's work, on your side of the line. We hold the decisions, the gates, and the proof.
And one rule we hold is younger than the rest. Every destructive step of a cutover, the freeze, the load, the go-live, should carry an authorizing identity on its record. Our own internal audit pressed on that rule this year. It found the enforcement thinner than the statement in places, and that finding is open on our own board. We would rather tell you that here than let a demo imply otherwise, because the alternative is being the vendor this series argues against.
Count the buyer's inventory, because it is the point of all seven parts. A map decided by named people under fail-closed gates, with its absences decided rather than discovered. A tie-out nobody authored. A seal that re-proves itself on every read and breaks loudly when the ground moves. Dispositions and fates on everything that did not map, and a signature chain your auditor can verify without asking us a single question.
That last clause is the product. Anyone can generate the map. What you are buying is the part no generator produces. It is an artifact that argues for itself, in front of people paid to disbelieve it, years after its builders moved on.
The Proof Series, complete. Seven parts on one claim: generation is cheap, and the signature that survives an auditor is the scarce thing a migration actually needs.
This site uses cookies
We use essential cookies for the site to function and analytics cookies (Google Analytics) to understand how you use it. Analytics cookies are only activated with your consent. We do not track you across other websites. Your data is stored in the EU and processed in accordance with GDPR. Read our Privacy Policy