The flow
A run is a single pass through six phases. Each phase has a clear trigger and a concrete output, and the transitions that carry real risk are guarded by a human approval gate. The diagram below shows the phase order left to right, with gate markers on the transitions that require sign-off.
The six phases
Initiation
Triggered when an approved request enters the pipeline. IPM sets up cross-account credentials, the Zoho Agent creates the delivery project, and the Admin gate confirms the account setup. Produces access and roles that are ready to use, plus a project shell to track the work against.
Analysis
Triggered once initiation completes. The SOW Analyzer structures the request, and the Routing Engine splits the work between template and generated paths. Produces the structured requirements, the infrastructure query, the work breakdown, and the OneClick-versus-TerraFormGen service split.
Infra Generation
Triggered by the analysis output. OneClick provisions the base infrastructure, TerraFormGen writes the additional services, and the Compliance check validates the result and applies safe auto-fixes. Produces a complete Terraform file set under terraform/ plus a compliance result.
Deploy
Triggered after the Tech Lead approves the generated Terraform. The GitHub Agent opens a pull request carrying a CI workflow that runs plan, a security scan, a cost estimate, and apply; the Ansible Agent configures the instances after they are provisioned, guarded by a Tech Lead gate on the apply. Produces the repository, the PR, CI results, and configured instances.
Docs
Triggered once deploy succeeds. Runbook and documentation are generated and then reviewed by the Project Manager. Produces the runbook artifacts. This phase is planned and not yet deployed.
Handover
Triggered after the docs review passes. The signoff document is generated and routed for dual signature, then the project is closed. Produces the signed signoff artifact and a closed project.
Approval gates
The guiding principle is simple: nothing critical applies without a human gate. Each gate is owned by a specific role, and the run pauses at the gate until that role approves.
| Gate | Owner | When |
|---|---|---|
| Admin gate | Admin | Before analysis. Approves cross-account setup and IAM role creation. |
| Terraform review | Tech Lead | After generation, before the GitHub apply. Reviews the generated Terraform and compliance result. |
| Deploy review | Tech Lead | Guards the apply during deploy. |
| Docs review | Project Manager | Before customer handover. Reviews the runbook. Planned. |
| Final handover | Project Manager | Final verification before the project closes. |
Pause and resume
When a run reaches a gate it pauses with its state saved. Approving continues from that point, so no completed work is repeated. The Docs review gate and the Documentation phase are planned.