# Flow External Proof Cockpit

Decision: ready to prove, not yet fully proven.

## Executor
- Command: `npm run gate:flow:external-proof-executor`
- Artifact: `reports/flow-release/external-proof-executor.json|md`
- Queue: `/flow/production-proof-hub/live-proof-queue`

## External lanes

### CI ring proof
- Status: external-infra-pending
- Owner: Platform/DevOps
- Required artifact: release-governor + release-ultimate-gate output per ring

### Kustom paid proof
- Status: provider-merchant-lane-pending
- Owner: Finance Ops
- Required artifact: signed Kustom report with provider reference and admin sign-off

### Connector live proof
- Status: tenant-credentials-pending
- Owner: Integrations
- Required artifact: connector proof run with setup, webhook replay, reconciliation and provider status

### Live KPI proof
- Status: live-traffic-pending
- Owner: Revenue Ops
- Required artifact: weekly KPI target export with funnel completeness and conversion proof

### Security final proof
- Status: independent-review-pending
- Owner: Security
- Required artifact: security review report with findings, fixes, retest and owner sign-off

## Rules
- [ ] These blockers must remain visible because they require external systems or live customer evidence.
- [ ] Product development can continue, but release claims must reference proof state, not roadmap optimism.
- [ ] A lane moves to green only when the required artifact exists and is archived.
- [ ] The safest next go-live path is one pilot tenant with widget install, RFP/proposal, payment and connector proof.