← Back to the call brief
Internal1 Apr 202625% captured

Comply v2 - GA Deployment Plan

39 turns · 8 min captured of 30 min stated?Only the captured portion exists in the database. The remaining 22 min of this call was never transcribed, so nothing said in it appears anywhere in this application.

Show facts?Markers in the left gutter show which facts the model built from each turn. Click a marker to open that fact's evidence — this is the citation trail running backwards.

Showing 39 of 39 turns · 18 turns were used as evidence for at least one fact.

  1. Ananya SharmaAegisCloud0:05turn 0ASR 96%

    Alright, I think everyone's on — can you guys hear me okay?

  2. Ravi GuptaAegisCloud0:11turn 1ASR 92%

    Yeah, loud and clear.

  3. Mike RomanoAegisCloud0:14turn 2ASR 96%

    Good here. Hey Ananya, hey Ravi.

  4. Nina KowalskiAegisCloud0:16turn 3ASR 92%

    Hi everyone! Sorry I'm like thirty seconds late, had a Slack thread that just would not die.

  5. Ananya SharmaAegisCloud0:24turn 4ASR 90%

    Ha, no worries at all. Okay so — April 7th is six days away, which honestly feels very real now, and I wanted to get the four of us together to go through the GA deployment plan for Comply v2 and make sure we're all aligned on the rollout sequence.

  6. Mike RomanoAegisCloud0:42turn 5ASR 97%

    Yeah, and I have to say, I'm actually pretty excited about this one. Like the on-demand reporting piece especially — I think customers are going to love that.

  7. Ravi GuptaAegisCloud0:53turn 6ASR 94%

    Same, I've been saying for months that the old scheduled-only model was a pain point, so yeah, really glad we're shipping this.

  8. Ananya SharmaAegisCloud1:02turn 7ASR 89%

    Okay so let me just share my screen real quick and pull up the deployment runbook I've been putting together... okay, can everyone see that?

  9. Nina KowalskiAegisCloud1:12turn 8ASR 95%

    Yep, got it.

  10. Ananya SharmaAegisCloud1:14turn 9ASR 93%

    Perfect. So the plan right now is to do the actual infrastructure changes on the night of April 6th — like a late evening deploy, probably around 10 PM Eastern — and then flip the feature flag to GA on the morning of the 7th. Ravi, does that sequence still work for you on the infra side?

  11. Ravi GuptaAegisCloud1:35turn 10ASR 94%

    Yeah, it does. I've already got the Terraform configs updated for the new reporting service nodes, and I ran a full dry-run in staging yesterday and it looked clean. I'm feeling good about the 10 PM window. We'll have, um, about a three hour buffer before any early morning traffic picks up.

  12. Ananya SharmaAegisCloud1:55turn 11ASR 89%

    Oh that's great news that the dry-run went well. Did you run into anything weird at all, or was it pretty smooth?

  13. Ravi GuptaAegisCloud2:03turn 12ASR 96%

    Mostly smooth, honestly. There was one thing — the new SOC 2 report generation was taking like 8 seconds on first call, which is a little longer than I'd expect, but I think that's just cold start on the Lambda, not a real issue. I'll add a warm-up ping to the pre-deploy checklist.

  14. Ananya SharmaAegisCloud2:22turn 13ASR 96%

    Oh good catch on the Lambda warm-up, yeah. Mike, did you have any concerns on the application side? I know you've been doing code review on the multi-framework stuff.

  15. Mike RomanoAegisCloud2:33turn 14ASR 97%

    Yeah so, I finished the review on the HIPAA and ISO 27001 report generators this morning and honestly the code is in really good shape. Priya did a great job on those. My only thing — and this is more of a minor nit — is the PCI DSS report has some hardcoded version strings that I'd like to see pulled into config, but it's not a blocker by any means.

  16. Ananya SharmaAegisCloud2:59turn 15ASR 94%

    Is that something we can get into a follow-up ticket and not hold up the GA?

  17. Mike RomanoAegisCloud3:05turn 16ASR 92%

    Definitely, yeah, I already filed it. It can live as a v2.0.1 cleanup item. I wouldn't block launch over it.

  18. Ananya SharmaAegisCloud3:13turn 17ASR 91%

    Perfect. Nina, okay — I really want to hear from you because you've been heads-down in QA for the past week and a half. Where are we on test coverage and are there any open issues you're nervous about?

  19. Nina KowalskiAegisCloud3:27turn 18ASR 96%

    Okay so, good news overall. We finished the full regression suite yesterday and everything passed. The on-demand report generation — all four frameworks, SOC 2, PCI DSS, HIPAA, ISO 27001 — tested across the three tenant sizes we defined, small, medium, enterprise, and all of them are generating correctly. The PDF rendering looks great, the data mapping to controls is accurate, we verified that manually.

  20. Ananya SharmaAegisCloud3:51turn 19ASR 96%

    That is music to my ears, Nina, honestly.

  21. Nina KowalskiAegisCloud3:54turn 20ASR 94%

    Ha, right? So the one area I'd flag — not necessarily a blocker but something I want us to have eyes on post-launch — is the concurrent report generation. When we hammered it with 50 simultaneous requests in the load test, we did see some queue latency creep up. Like, reports were still completing, but the p99 latency was around 22 seconds, which is above our SLO target of 15.

  22. Mike RomanoAegisCloud4:19turn 21ASR 96%

    Okay, 22 seconds at 50 concurrent — do we think that's a realistic scenario for day one? I mean, we're not flipping this on for all customers simultaneously, right?

  23. Ananya SharmaAegisCloud4:30turn 22ASR 97%

    No, exactly. We're doing a phased flag rollout — tier one customers first, which is maybe, what, a few hundred orgs, and then expanding over the following week. So I think the risk of hitting 50 concurrent on day one is pretty low.

  24. Nina KowalskiAegisCloud4:46turn 23ASR 88%

    Right, and honestly I agree it's low risk for launch. I just wanted it on the radar so we're not surprised if we see it in the MetricFlow dashboards. I'll set up a specific alert for queue depth on the reporting service so we can catch it early if it starts trending up.

  25. Ananya SharmaAegisCloud5:05turn 24ASR 92%

    That's exactly the right call, yeah. Ravi, can you work with Nina on that alert configuration before the 6th?

  26. Ravi GuptaAegisCloud5:13turn 25ASR 97%

    Absolutely, we can knock that out tomorrow morning. I'll ping you Nina.

  27. Ananya SharmaAegisCloud5:19turn 26ASR 93%

    Perfect. And actually, since we're on the topic of observability — and this is maybe a bit of a sore subject but I think it's worth saying out loud — after the Detect outage in March, I want to make sure we're not shipping Comply v2 with any single points of failure in the pipeline. Ravi, can you talk through the redundancy story?

  28. Ravi GuptaAegisCloud5:42turn 27ASR 92%

    Yeah, no, totally fair to bring up, and honestly the Detect situation kind of informed a lot of how we architected the reporting pipeline. So the event ingestion layer has redundant processing nodes — we're running three — and we've implemented the circuit breaker pattern on the report request handler so if one downstream service starts degrading, it fails gracefully instead of cascading. It's a very different story from what happened with Detect.

  29. Mike RomanoAegisCloud6:08turn 28ASR 91%

    Yeah, and to Ravi's point, the architecture review we did back in February specifically called out those failure modes and I think the team addressed them really thoroughly. I feel a lot better about the resilience story on this one.

  30. Ananya SharmaAegisCloud6:22turn 29ASR 90%

    Same. Okay, good. Let's talk about rollback — Ravi, what's the rollback plan if something goes sideways on the night of the 6th or morning of the 7th?

  31. Ravi GuptaAegisCloud6:33turn 30ASR 96%

    So rollback is clean. The feature flag means we can instantly revert to v1 behavior without redeploying anything — just flip the flag back. The infrastructure changes are additive, not replacing anything, so the v1 reporting service stays running in parallel until we're confident. We can decommission that after, uh, I was thinking two weeks post-GA.

  32. Ananya SharmaAegisCloud6:54turn 31ASR 97%

    Two weeks sounds right to me. Nina, does that give you enough time to catch any issues that might only surface under real customer traffic?

  33. Nina KowalskiAegisCloud7:04turn 32ASR 91%

    Yeah, two weeks is good. Most of the edge cases we'd be worried about would show up in the first week honestly. I'm comfortable with that.

  34. Ananya SharmaAegisCloud7:14turn 33ASR 91%

    Awesome. Okay, I think we're in really solid shape here. I'll update the runbook today with the alert config action item and the warm-up ping note, and I'll send it around for a final review by EOD Thursday. Does anyone have anything else they want to flag before we wrap up?

  35. Mike RomanoAegisCloud7:33turn 34ASR 94%

    Nothing from me. I'm honestly just pumped to ship this. It's been a long road.

  36. Ravi GuptaAegisCloud7:40turn 35ASR 91%

    Same, I'm really proud of what the team put together. This is going to be a good one.

  37. Ananya SharmaAegisCloud7:48turn 36ASR 97%

    Agreed. Okay, let's do it. Thanks everyone — I'll see you in Slack, and Ravi and Nina, I'll let you two coordinate on those alerts. Good call today!

  38. Nina KowalskiAegisCloud7:58turn 37ASR 91%

    Thanks Ananya, talk soon!

  39. Mike RomanoAegisCloud8:00turn 38ASR 94%

    Bye everyone.