attio-prod-checklist

v2026.09.24

Run an evidence-based production-readiness review for an Attio integration across identity, scopes, data ownership, retries, webhooks, observability, rollback, and support. Use when preparing to enable production Attio traffic. Trigger with "Attio production checklist", "Attio go-live", or "review Attio release".

GitHub
安装命令
npx skhub add jeremylongshore/attio-prod-checklist
Markdown
SKILL.md

Attio Production Readiness Review

Overview

This skill produces a release decision from repository and operational evidence. A checked box without a receipt is unresolved, not complete.

Prerequisites

  • Exact artifact, environment, workspace, and release owner
  • Endpoint inventory with methods and required scopes
  • Data ownership, retention, and deletion policy
  • Monitoring, incident, rollback, and support paths

Tool Discipline

Use Read, Glob, and Grep to inspect auth, mappings, tests, workflows, observability, and rollback code. Use WebFetch only for current official Attio documentation. Use Write or Edit only to remediate a named gap with verification.

Current Contract

  • Authentication must match the tenancy model and use endpoint-derived least privilege.
  • Record and entry identity, owned fields, and destructive boundaries must be explicit.
  • Retries must honor Retry-After and exclude permanent request failures.
  • Webhook receivers need raw-body HMAC verification and idempotent processing.
  • Pagination mode must be confirmed endpoint by endpoint.

Authentication

Verify secret location, workspace or tenant binding, scopes, rotation owner, revocation procedure, and absence from logs and artifacts. Use Bearer authentication for REST requests.

Instructions

  1. Bind the review to the exact artifact, environment, workspace, and endpoint inventory.
  2. Verify contract tests, schema discovery, field ownership, identity, and pagination termination.
  3. Verify credential storage, endpoint scopes, tenant isolation, rotation, and redaction.
  4. Verify timeouts, bounded retries, read/write traffic controls, and 429 handling.
  5. For webhooks, verify HTTPS, raw-body signature checks, idempotency keys, quick acknowledgement, and replay-safe workers.
  6. Exercise read-only smoke, approved canary, alert path, rollback, and recovery evidence.
  7. Record PASS, FAIL, or explicitly accepted risk for every item and name the approver.

Approval Boundaries

Only the release owner may accept unresolved data-loss, authorization, privacy, or rollback risk. Do not convert missing evidence into PASS.

Output

Return the bound release identity, control matrix with receipts, failed gates, accepted risks, approvers, and final GO or NO-GO decision.

Error Handling

ConditionResponse
Artifact or workspace is unboundReturn NO-GO.
Scope evidence is missingReturn NO-GO until endpoint mapping exists.
Webhook replay is untestedDisable webhook-driven mutation or return NO-GO.
Rollback cannot be exercisedLimit rollout or return NO-GO.

Examples

Input:

release=exact-sha; workspace=production-alias; canary=approved-record

Expected handoff:

decision=NO-GO; blocker=missing webhook replay proof; owner=integration-team

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/attio-prod-checklist

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8