Begin with limited users, data, tools, volume, duration, and consequence. Define success, guardrail, stop, and review criteria before execution. Require a release owner to confirm the tested version, configuration, dependencies, known limits, specialist reviews, and rollback posture. A green technical suite is implementation evidence; it does not independently authorize commercial, legal, security, privacy, financial, or production decisions outside its scope.
Observe review burden, denied actions, errors, retries, source conflicts, unauthorized attempts, cost variance, affected-party feedback, and recovery events. Low incident counts can reflect low volume or poor detection, so they should not be interpreted alone as proof of safety. Compare actual behavior with the original prediction and document whether the next step is to scale, hold, narrow, redesign, or retire.
Keep the canary's exit mechanics ready throughout the run. Operators should know how to suspend new work, finish or cancel in-flight actions, revoke temporary access, preserve evidence, and communicate with affected owners. A test that can start but cannot stop cleanly is not bounded. Where external effects cannot be reversed, limit volume and require stronger pre-action verification.
Before handing the workflow to ordinary operators, provide concise operating guidance and rehearse the common hold states. Training should cover what the system can establish, what it cannot, how to inspect sources, when to refuse, and where to escalate. Completion of training is not proof of correct future action, so interfaces and runtime controls should support the operator rather than relying on memory alone.