JBNX · projects.jbnx.io/framework/ready

Production & Subscription Readiness Framework

Version 3.0 — a scored audit for taking a web app to production and selling subscriptions against it. Synthesized from Google SRE Production Readiness Reviews, Cortex and OpsLevel PRR checklists, and SaaS billing and launch guides.

Raw markdownJSON

How to use it

  1. Pick your stage tier — it defines which items are required rather than deferred. T1 (MVP Launch): first paying customers, single region, small team. T2 (Growth): real revenue, on-call exists, multiple environments. T3 (Scale): SLAs to customers, compliance obligations, multi-team.
  2. Score each pillar 1–10 against the rubric below. Every item requires evidence — a link, screenshot, test run or dashboard. Self-attestation without evidence caps that item's pillar at 6.
  3. Compute the weighted composite and check the launch gates.

Universal scoring rubric

ScoreAnchor
1–3Absent or ad-hoc; no evidence
4–6Partially implemented; manual; untested under failure
7–8Implemented and tested; evidence exists; gaps documented with owners
9–10Implemented, tested, automated and monitored, and verified within the last 90 days
Launch gates. Go-live (T1): every pillar ≥ 6, and Security, Billing and Legal ≥ 7 — no exceptions on those three. Scale-up (T2→T3): every pillar ≥ 7, composite ≥ 8.0. Any gap below a gate gets a written exception with an expiration date and a remediation owner — or it blocks launch.

Pillar weights

PillarWeight
1. Reliability & Infrastructure15%
2. Security & Compliance15%
3. Observability & Operations10%
4. Performance & Scalability10%
5. Billing & Subscription Infrastructure15%
6. Pricing & Packaging10%
7. Conversion Funnel & Growth10%
8. Retention & Revenue Health5%
9. Legal & Trust5%
10. Support & Customer Success5%

Composite = Σ (pillar score × weight).

Pillar 1 — Reliability & Infrastructure (15%)

Can the app stay up, recover, and redeploy safely?

ItemTierEvidence
Reproducible deploys via CI/CD; no manual prod changesT1Pipeline run link
Rollback tested, not just documentedT1Rollback drill record
Automated DB backups + restore actually testedT1Restore drill log
Health checks + auto-restart on the platformT1Config + uptime log
Staging environment matching prodT2Env diff
Defined RTO/RPO; DR runbook exercisedT2Drill report
Multi-AZ/region, or documented acceptance of single-point riskT3Architecture doc
Infrastructure as codeT3Repo link

Pillar 2 — Security & Compliance (15%)

Would a breach or an audit end the business?

ItemTierEvidence
Auth via proven provider/library; MFA available; session expiryT1Config review
Secrets in a manager — never in code or client bundlesT1Repo scan output
OWASP Top 10 pass: injection, XSS, CSRF, IDOR/authz on every endpointT1Scan report + manual authz test
TLS everywhere; security headers (CSP, HSTS)T1Scanner grade
Dependency scanning + patch cadenceT1CI job
Row-level security / tenant isolation verified with negative testsT1Test suite
Least-privilege access for humans and services; offboarding processT2Access review
Pen test or structured external reviewT3Report
SOC 2 / ISO track if selling to companies that askT3Roadmap or report

Pillar 3 — Observability & Operations (10%)

When it breaks, do you find out from your dashboard or from Twitter?

ItemTierEvidence
Structured, centralized, searchable logs — no PII or secrets in logsT1Log query demo
Error tracking with alerting (Sentry-class)T1Alert screenshot
Uptime monitoring from outside your infraT1Monitor config
Alerts tied to user-facing symptoms, not internal noiseT2Alert audit
Metrics dashboard: latency, error rate, saturation, trafficT2Dashboard link
Incident process: severity levels, runbooks, postmortemsT2Last postmortem
Distributed tracing where architecture warrantsT3Trace sample

Pillar 4 — Performance & Scalability (10%)

ItemTierEvidence
Load test at 3–5× expected launch peak; know your breaking pointT1Test report
Core Web Vitals green on key pages (landing, signup, checkout)T1Lighthouse / CrUX
DB indexed for hot queries; no N+1 on hot pathsT1Query analysis
CDN / static asset cachingT1Config
Rate limiting on auth, API and checkout endpointsT1Test
Horizontal scaling path documented and testedT2Scale test
Capacity planning reviewed quarterlyT3Doc

Pillar 5 — Billing & Subscription Infrastructure (15%)

The pillar where most subscription launches quietly fail.

ItemTierEvidence
Billing via Stripe / Paddle / Chargebee — never custom-builtT1Integration
Every webhook handled: created, payment succeeded/failed, canceled, plan changedT1Test-mode event log
Webhook handlers idempotent — replay every event and verify stateT1Replay test
Full lifecycle tested: trial → convert, upgrade, downgrade (proration), cancel, resubscribeT1Test matrix
Entitlements enforced server-side; plan change reflects in access within secondsT1Negative test
Tax handling for actual sales jurisdictions (Stripe Tax / Paddle MoR)T1Config
Dunning: retries, pre-expiration card reminders, update-payment promptsT2Flow screenshots
Grace periods + involuntary-churn recovery flowT2Config
Billing state reconciliation job — your DB vs. processor truthT2Job output
Revenue recognition / accounting exportT3Report

Pillar 6 — Pricing & Packaging (10%)

Research-backed pricing correlates with a 65% higher chance of hitting first-year revenue goals.

ItemTierEvidence
Pricing tested with ≥ 20 real prospects — not gut feelT1Interview notes
Anchored against named competitorsT1Comparison doc
Tier structure maps to a real value metric (seats, usage, features)T1Packaging doc
Free trial or freemium decision made deliberately, with a conversion hypothesisT1Doc
Annual/monthly mix with discount rationaleT2Pricing page
Price experimentation mechanism, incl. grandfathering planT3Policy

Pillar 7 — Conversion Funnel & Growth (10%)

Being able to bill is not the same as being able to sell.

ItemTierEvidence
Landing page states problem, outcome and price; loads fastT1Page + vitals
Signup → activation flow instrumented end-to-endT1Funnel dashboard
Defined activation moment and time-to-value targetT1Metric definition
Onboarding drives to activation: checklist, empty states, sample dataT1Walkthrough
Checkout friction audit: steps counted, guest info minimal, failures handled gracefullyT1Audit
Funnel conversion baselines set; weekly reviewT2Dashboard
Lifecycle email: welcome, trial-ending, win-backT2Sequences

Pillar 8 — Retention & Revenue Health (5%)

ItemTierEvidence
MRR, ARR, churn, LTV:CAC tracked from day oneT1Dashboard
Voluntary vs. involuntary churn separated — involuntary is fixable via Pillar 5T2Report
At-risk signals defined: login decline, feature-usage drop, support spikesT2Alert definition
Cancellation flow captures reason + offers alternatives (pause, downgrade)T2Flow
NRR tracked; expansion revenue path existsT3Report

Pillar 9 — Legal & Trust (5%)

ItemTierEvidence
ToS + Privacy Policy reviewed against your actual data practicesT1Docs
Refund/cancellation policy published; cancel is as easy as signup (click-to-cancel)T1Flow test
GDPR/CCPA basics: consent, data export, deletion on requestT1Process
PCI scope minimized — processor-hosted fields; card data never touches your serversT1Architecture
DPA available for business customersT2Template
This framework is not legal advice — have counsel review your policies.

Pillar 10 — Support & Customer Success (5%)

ItemTierEvidence
Support channel with committed response time; billing questions routed fastestT1Policy
Docs/FAQ covering the top 10 predicted questions, including billingT1Docs
Status page or incident comms planT2Page
Feedback loop from support → product backlogT2Process

Worked example (T1 SaaS, pre-launch)

PillarScoreWeighted
Reliability71.05
Security71.05
Observability60.60
Performance60.60
Billing81.20
Pricing50.50
Funnel60.60
Retention60.30
Legal70.35
Support60.30
Composite6.55

Gate check: all pillars ≥ 6 ✓; Security, Billing and Legal ≥ 7 ✓ → cleared for T1 launch, with Pricing (5) flagged as an exception: “run 20 prospect interviews within 30 days, owner: founder.”

Cadence

Re-run the audit at launch, at each architecture change, at each pricing change, after any Sev-1 incident, and quarterly. Automate whatever can be checked in CI — security scans, webhook replay tests, restore drills.

Sources

Google SRE — Production Readiness Review · Cortex — Production Readiness Checklist · OpsLevel — Production Readiness In Depth · DesignRevision — SaaS Launch Checklist · Stripe — SaaS Subscriptions Guide · Chargebee — Dunning Management · Baremetrics — SaaS Metrics Checklist

Audit runs against this framework

Dated, immutable runs — a re-audit gets a new date rather than overwriting the old one. /framework/<project> always redirects to that project's latest.

All frameworks and audit runs →