Skip to main content

Make “production remains unchanged” the default failure mode

An update creates an immutable candidate revision. It does not mutate the active revision in place. Release Guard compares compatible, persisted active and candidate evidence before promotion.
Validate with explicit cost and privacy acknowledgement. Validation traffic is bounded by persisted policy; InferCrane does not shadow or duplicate production requests silently.
The values above illustrate the output shape; your result comes from persisted measurements. When evidence is missing or incomparable, Release Guard returns WAIT instead of inventing a result.

What the decision proves

Every evaluation records:
  • active and candidate revision identity;
  • the exact policy snapshot;
  • compatible benchmark IDs and workload parameters;
  • measurements that were available;
  • explicit unavailable measurements;
  • deterministic reason codes and timestamp.
Use the persisted decision during an incident or approval review:
After an accepted promotion, issue an Inference Passport to bind the revision to its release evidence in an independently verifiable artifact.