| SecurityBefore further external use | Read-only service controls exist; the temporary validation credential still requires rotation and final secret review. | Rotated secrets, repository/artifact scan, least privilege, and an approved test/operating policy. | Tenexity + OptiCat security |
| AuthenticationProduction hardening | The private MCP path uses an internal bearer boundary; production partner identity is not designed here. | Supported partner authentication with rotation, revocation, and documented trust boundaries. | OptiCat platform owner |
| AuthorizationProduction hardening | Catalog visibility depends on upstream key entitlement; customer/tenant isolation is outside the demonstration scope. | Per-partner authorization, entitlement visibility, quotas, and isolation tests. | OptiCat platform + API owner |
| ObservabilityDemo gate → production | Runs retain tool evidence, statuses, counts, and selected latency; production monitoring is not complete. | Health, latency, error, entitlement, truncation, and release metrics with operational ownership. | Tenexity engineering then OptiCat operations |
| LoggingProduction hardening | Redacted evaluation traces exist, but retention, access, and audit policy are not finalized. | Structured redacted logs, correlation IDs, retention controls, and incident-safe access. | OptiCat operations/security |
| AI governancePhase 1 closeout and every release | Evidence-only rules and KPI definitions exist; the full domain-approved replay remains open. | Versioned cases, named adjudicators, zero-tolerance safety gates, drift review, and controlled releases. | OptiCat product/domain + Tenexity evaluation |