# Production and demo checklist
Original worksheet by Codex | September 28, 2026

## Before a second person tries the app
- [ ] A clean environment can install and run it from the README.
- [ ] Dependencies and configuration are documented.
- [ ] Secrets are server-side, outside source control and browser bundles.
- [ ] Input and output schemas are validated.
- [ ] Private data access is enforced in application code before retrieval.
- [ ] Logs identify failures without retaining unnecessary sensitive text.
- [ ] Timeouts, retries, tool steps and output size are bounded.
- [ ] Authentication, rate limits and cost controls match the demo's exposure.
- [ ] Refusals, missing evidence and dependency outages have a useful UI.
- [ ] Evaluation results and known failures are documented.
- [ ] Data retention/deletion and corpus updates are explained.
- [ ] Rollback or recovery has been tried.

## Failure drill
Break the provider connection, empty the search index, and submit an oversized request separately. Record expected behavior, observed behavior and the fix. Restore the normal configuration afterward.

## Three-minute demo outline
0:00-0:30: who the user is and what task matters.
0:30-1:30: complete the main workflow.
1:30-2:00: show the evidence and baseline comparison.
2:00-2:30: show one failure or abstention.
2:30-3:00: explain one tradeoff and the next improvement.

## Hand-off
Demo URL or recording:
Setup instructions:
Who tested it and what happened:
Current limitations:
Estimated usage cost and its assumptions:
Recovery steps:
