You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reconcile Sponsor CRM table ownership with CloudFormation
Status: blocked — route B selected; waiting for a HUMAN AWS operator to obtain AWS Support guidance and the review team to approve a mutation-free remediation design
Tags: bug, infra, data, migration, testing, P1
Depends on: None — the route-B decision is already recorded in #140 and #141; #141 is not a blocker
Blocks: #136
Next owner: HUMAN AWS operator
Resume condition: sanitized confirmation that AWS Support guidance and authentic private diagnostics are available for Architecture/Security review; no production action is implied
Decision and objective
#140 and #141 found one historical table-creation event, but no trusted record cryptographically links its historical table identifier to the exact CloudFormation stack incarnation. Architecture and Security therefore classified the evidence as insufficient, rejected route A, and selected route B.
This issue designs, rehearses, approves, and—only after fresh explicit gates—coordinates a supported ownership reconciliation. It does not authorize a tagless exception or weaken #136.
Grooming this issue authorizes no AWS call, Support disclosure, backup, export, restore, import, replacement, tag, change set, deployment, migration, environment, repository, workflow, or data mutation. Every later AWS action must be enumerated in the accepted runbook and separately approved at the required gate.
Repository and template change lifecycle
If the selected supported path requires any repository, workflow, SAM/CloudFormation, infrastructure-template, validation, or operator-facing implementation change, that change must follow the full repository lifecycle before the related HUMAN AWS phase: Product Manager confirms the exact scope and repository, Software Engineer implements without committing, Architecture/Security re-review the frozen candidate where required, Tester runs the full affected verification, Product Manager performs final acceptance, Software Engineer commits with Refs #143, the orchestrator merges and pushes through the repository's approved path, and On-Call verifies CI/CD. A credentialed HUMAN apply for infrastructure that is not self-deployed remains a separate digest-bound gate and does not replace those stages.
If Support-backed reconciliation requires no repository change, PM must record that explicit no-change disposition and why; Tester and PM still verify the exact private-plan digest and sanitized evidence at the phase gates defined below. No Support response, runbook draft, or HUMAN approval retroactively authorizes an unreviewed file, workflow, template, deployment, or AWS mutation.
Public/private evidence boundary
Keep raw resource/account/principal identifiers, stack and table identifiers, events, item data, Support correspondence/case details, screenshots, commands containing identifiers, private locations/links, and credentials-adjacent material outside this public repository in the approved private knowledge/evidence system.
The public issue may contain only sanitized source classes, UTC bounds, counts, digests, state transitions, decisions, and PASS/FAIL/ABORT results. No raw operational document or evidence artifact is committed here.
Global security contract — applies to every phase
These three non-waivable controls apply to Support disclosure, baseline reads, backup/export, isolated rehearsal/restore, the selected ownership path, cutover, rollback, and cleanup. They supplement the Architecture-approved sequence and constraints; they do not replace any phase gate. Every mutation and rollback remains a separately named, frozen-runbook-digest-bound HUMAN approval.
1. Phase-scoped least privilege, session provenance, and operation reconciliation
Before each phase, the frozen private runbook must define a phase-specific access/session matrix containing the exact private account, region, resources, actor, expected principal, role/session source, issuance and expiry, MFA and approval provenance, and minimum API action/resource set. Read-only and mutation sessions must be separated where practical. The matrix must explicitly exclude shared/static credentials, production credentials in rehearsal, broad administrator sessions, and any broadening or reuse of the deployment OIDC role. Any IAM change requires a separately groomed Architecture/Security review and is not authorized by this issue.
Credentials must be short-lived, uniquely attributable, and scoped only to the approved phase. Entry and immediately pre-mutation checks must prove principal, account, region, resources, session validity, and frozen inputs. The runbook must retain privately both the exact allowed API/action/resource inventory and the exact observed operation inventory and reconcile them before the next mutation. Any extra permission, unexpected or missing API, unapproved principal/session, account/region/resource drift, expired session, or other mismatch causes ABORT before the next call.
At phase exit, capture session expiry or explicit revocation and prove that temporary access is no longer usable. Missing issuance, provenance, allowed/observed inventory, expiry, or revocation evidence fails closed. Enumerating calls never makes a broad administrator session acceptable.
2. Production-equivalent confidentiality for export and restored Sponsor data
Every backup, export, restored table, item, key, and derived integrity artifact retains the production Sponsor CRM classification in non-production for its entire lifetime. Use only approved isolated accounts/environments and principals, approved KMS keys, encryption in transit and at rest, private access paths, and controls that prevent public or unintended cross-account access. The target must have no external event source, webhook, mail/social/Telegram integration, scheduled writer, stream consumer, production credential, or uncontrolled integration/egress path; prove those exclusions before data is introduced and throughout rehearsal.
Item bodies, keys, per-item hashes, raw command output, and identifiers stay in the private evidence boundary and must not enter public CI/console logs, issues, screenshots, or routine Support material. Integrity evidence is private and access-controlled. Any digest that leaves the private boundary must use a Security-reviewed keyed or equivalently disclosure-resistant construction so low-entropy records cannot be guessed from fingerprints.
The private runbook must set a retention deadline, cleanup owner, inventory of data-bearing resources/artifacts/logs, rollback/incident-evidence hold, verified deletion procedure, and KMS/access revocation proof. Cleanup is blocked while an approved rollback or incident hold remains, then separately HUMAN-approved and verified complete. AWS Support receives only the minimum ownership diagnostics; production item data is excluded unless Security and an authorized HUMAN explicitly approve that specific disclosure.
3. Private audit/redaction execution and enforceable deploy/change/write freeze
Every phase must use a Security-reviewed execution mechanism that records UTC actor, session, action, result, state transition, and allowed-versus-observed operation evidence directly into the private evidence store. It must suppress shell tracing and verbose output that could expose credential material, item data, raw identifiers, private paths/links, or unredacted command output to public logs. Redaction and destination checks occur before any sanitized publication. An evidence mismatch or leak is an immediate ABORT and security-containment event; continuation requires a fresh Security decision.
Before snapshot or integrity comparison, detach/import, restore, or cutover, the runbook must enforce a deploy/change/write freeze with technical controls and captured proof; a procedural promise is insufficient. It must inventory every writer and mutator, including application writes, retries, TTL, streams, scheduled and asynchronous consumers, operators, deployment workflows, event-source mappings, integrations, and the #136 migration. For each one, define the enforced quiescence mechanism or complete ordered change-capture method, owner, start/end boundary, and verification.
Where complete quiescence is not possible, reconcile every captured mutation between equivalent logical points through cutover and throughout the rollback window. Abort before the next mutation on an unknown writer, reactivated workflow/integration, missing or unordered change, reconciliation mismatch, or unenforceable freeze. Freeze release is an explicit post-verification step and cannot silently occur during rollback or cleanup.
Phase 1 — AWS Support and read-only diagnosis
[HUMAN] Open or update an AWS Support case through an approved identity and disclose only the minimum private evidence needed.
Ask Support to determine whether the current table is associated with this stack or any other stack and why the canonical ownership marker is absent.
Obtain written guidance for the supported choices: association/ownership repair, retain-and-import of the existing table, or restore/replacement under a new physical name.
Ask Support to identify unsupported or destructive steps, import prerequisites, named-resource constraints, and whether any proposed sequence could delete or replace the production table.
Record privately the authenticated response, retrieval time, source, scope, and digest. Post only a sanitized summary here.
Architecture and Security classify the guidance as sufficient for design, ambiguous, or requiring escalation. Ambiguous guidance fails closed.
Do not manually create reserved aws: tags. Do not treat a same-name ARN, current mapping, current schema, or current table identifier as historical ownership proof. If Support unexpectedly supplies an authoritative exact historical stack↔table binding, stop route B and request a fresh independent #140 route review; route A does not become authorized automatically.
Phase 2 — immutable pre-change baseline and recoverability design
Before requesting approval for any backup/export action, the runbook must define the exact private baseline and evidence manifest:
Sanitized UTC capture time, retrieval principal/session provenance, API/command inventory, artifact sizes/digests, and complete-pagination proof.
A deterministic data-integrity method that covers every key/item, uses stable canonical serialization and paginated manifests/hashes, and does not rely on approximate item count alone.
Expected schema/configuration equality checks, exact item/key count checks, duplicate/missing-key checks, and separately identified settings that restore/import does not preserve automatically.
Private evidence retention, encryption, access, and deletion/retention owners.
The reviewed runbook must require a verified recovery source before any ownership mutation:
[HUMAN approval required] Create the selected on-demand backup and/or export only after Architecture, Security, Tester, and PM accept the backup plan and cost.
Verify terminal successful state, exact private source identity, UTC creation point, encryption/KMS access, retention, restore eligibility, size, and digest/manifest linkage.
Record how backup/export completeness will be independently checked and how recovery remains available throughout rollback.
Abort if the recovery artifact is incomplete, inaccessible, associated with a different source, not restorable, or cannot be retained through the rollback window.
Phase 3 — isolated restore rehearsal
The first restore is an explicitly approved non-production rehearsal, never an implicit production repair.
[HUMAN approval required] Use an approved isolated account/environment and a unique non-production name that cannot receive production traffic or collide with the retained production name.
Pin source recovery artifact, target region/account, encryption, capacity/load limits, network/access boundaries, timeout, cleanup owner, and maximum cost.
Restore and reconstruct all non-data configuration that the selected recovery mechanism does not preserve, following current official AWS guidance and the accepted runbook.
Run the full deterministic key/item manifest comparison plus exact schema/index/configuration checks. Approximate service-reported item counts are corroboration only.
Exercise the ownership/import/replacement sequence against the isolated target, including a reviewed CloudFormation change-set preview and proof of the final managed association.
Prove application compatibility without production traffic, write amplification, or destructive test data.
Preserve private evidence and publish only sanitized PASS/FAIL counts, digests, duration, load, and cost.
[HUMAN approval required] Clean up rehearsal resources only after evidence retention is confirmed.
Any mismatch, unexpected replacement/delete action, throttling risk, permission expansion, evidence leak, or inability to restore causes ABORT. A failed rehearsal must not advance to production.
Phase 4 — choose one supported CloudFormation path
Architecture and Security must select exactly one Support-backed path and reject the others in writing. Confirm every constraint against current official AWS documentation and Support guidance rather than assuming behavior.
Candidate A: retain/detach and import the existing table
Prove whether the resource is currently associated with this or another stack and whether import is supported in that state.
Define template/import identifiers, drift expectations, resource-policy/tag behavior, and the exact safe transition.
Apply both DeletionPolicy: Retain and UpdateReplacePolicy: Retain wherever the accepted design requires them, and prove their effective template/change-set state before removal or import.
Abort if import would require deleting the table, fabricating reserved tags, accepting ambiguous ownership, or bypassing CloudFormation validation.
Candidate B: restore/rebuild under a new physical name and cut over
Treat the named-table collision as a hard constraint: never plan an in-place replacement that requires two resources with the same custom name.
Define the new managed name, restore/copy method, full configuration reconstruction, deterministic integrity proof, application cutover, write-consistency strategy, downtime, and rollback window.
Keep the old table retained and isolated until post-cutover integrity and rollback gates pass.
Abort if concurrent writes cannot be reconciled, application configuration cannot be rolled back, or the expected change set includes an unapproved delete/replacement.
Candidate C: AWS-supported association repair
Use only a procedure explicitly supplied and confirmed by AWS Support for this exact private case.
Require the same backup, rehearsal, integrity, change preview, rollback, and approval gates as every other path.
Never simulate the outcome by manually writing reserved ownership tags.
Phase 5 — production runbook and explicit gates
Before any production action, publish a sanitized frozen runbook digest and retain the exact private runbook. It must enumerate:
ordered actor/action/API/console steps, immutable inputs, expected outputs, and approver for every step;
explicit separation of read-only checks, reversible mutations, cutover, irreversible actions, and cleanup;
preflight and repeated identity/configuration/integrity checks before and after every wait or state transition;
Tester accepts the rehearsal and exact integrity test plan/results.
PM accepts scope, operator clarity, downtime/cost, owners, and user impact.
[HUMAN] An authorized operator explicitly approves the named production phase and exact frozen runbook digest immediately before it begins.
On-Call verifies the finished ownership state and the normal CI/CD path. No manual app deploy substitutes for CI/CD.
An approval for one phase does not authorize a later phase or any extra API/action. Material drift invalidates the frozen runbook and returns to review.
Required production verification
CloudFormation reports the intended logical↔physical association and expected resource status through read-only checks.
Canonical ownership evidence is present and exactly consistent; no generic tagless exception is introduced.
Full schema/configuration and deterministic key/item integrity checks pass against the frozen baseline and recovery/rehearsal expectations.
No unapproved delete, replacement, retag, permission expansion, workflow dispatch, deployment, environment change, flag enablement, migration, or queue action occurred.
Rollback assets remain available for the accepted observation window; their later cleanup receives separate HUMAN approval.
Sanitized operation inventory, state transitions, counts, digests, downtime/load/cost, and PASS/FAIL verdicts are posted without private identifiers.
Support cannot determine ownership or proposes an unsupported shortcut
The design fails closed. No tag repair, import, replacement, or migration occurs; escalate for clearer Support guidance.
Backup/export is incomplete or cannot be restored
Abort before ownership work. Preserve the original table and obtain a newly reviewed recovery design.
Rehearsal restores but integrity/configuration differs
Abort. Approximate counts or sampled reads cannot waive deterministic mismatch.
Import preview reports existing ownership, replacement, or deletion
Abort and return to Architecture/AWS Support. Do not execute or manually detach/retag.
Named-table replacement collides
Use a reviewed new-name/cutover design or stop. Never delete the production table merely to free its name.
Production identity, writes, load, cost, or change set drifts
Abort before the next mutation, preserve recovery assets, and execute only the already approved rollback boundary.
Support later proves the exact historical pair
Stop route B and request fresh Architecture/Security review in #140. Do not revive route A by inference.
Private evidence appears in a public artifact
Stop, contain through the approved security process, and do not continue until Security records a new decision.
Acceptance criteria
AWS Support guidance and authentic diagnostics are retained privately with sanitized public provenance and decision.
One supported CloudFormation path is selected with import/replacement/Retain/named-resource constraints explicitly resolved.
A verified recovery artifact and successful isolated restore rehearsal precede any production ownership mutation.
Exact deterministic data and configuration integrity tests pass; approximate counts alone are never accepted.
The frozen production runbook includes actors, actions, APIs, immutable inputs, expected states, downtime/load/cost, rollback, cleanup, and hard abort criteria.
Every backup, restore, import, detach, replacement, cutover, cleanup, and other mutation receives the required explicit HUMAN approval; no approval is inferred from issue grooming.
Every phase uses the approved least-privilege short-lived session matrix, credential exclusions, entry/pre-mutation identity checks, exact allowed/observed operation reconciliation, and verified expiry/revocation; any access or operation drift aborts.
Every export/restore and derived Sponsor integrity artifact keeps production-equivalent confidentiality in isolated non-production, including approved KMS/access/egress controls, private keyed integrity evidence where required, minimal Support disclosure, retention holds, separately approved cleanup, verified deletion, and KMS/access revocation.
Every phase uses the reviewed private audit/redaction mechanism, and snapshot/integrity, ownership, restore, cutover, and rollback work is protected by an enforceable deploy/change/write freeze plus complete mutator inventory and ordered reconciliation.
Fresh Architecture, Security, Tester, PM, HUMAN, and On-Call gates pass with sanitized public decisions.
The final table is demonstrably CloudFormation-owned without manual reserved-tag creation or a generic tagless exception.
Reconcile Sponsor CRM table ownership with CloudFormation
Status: blocked — route B selected; waiting for a HUMAN AWS operator to obtain AWS Support guidance and the review team to approve a mutation-free remediation design
Tags:
bug,infra,data,migration,testing,P1Depends on: None — the route-B decision is already recorded in #140 and #141; #141 is not a blocker
Blocks: #136
Next owner: HUMAN AWS operator
Resume condition: sanitized confirmation that AWS Support guidance and authentic private diagnostics are available for Architecture/Security review; no production action is implied
Decision and objective
#140 and #141 found one historical table-creation event, but no trusted record cryptographically links its historical table identifier to the exact CloudFormation stack incarnation. Architecture and Security therefore classified the evidence as insufficient, rejected route A, and selected route B.
This issue designs, rehearses, approves, and—only after fresh explicit gates—coordinates a supported ownership reconciliation. It does not authorize a tagless exception or weaken #136.
Grooming this issue authorizes no AWS call, Support disclosure, backup, export, restore, import, replacement, tag, change set, deployment, migration, environment, repository, workflow, or data mutation. Every later AWS action must be enumerated in the accepted runbook and separately approved at the required gate.
Repository and template change lifecycle
If the selected supported path requires any repository, workflow, SAM/CloudFormation, infrastructure-template, validation, or operator-facing implementation change, that change must follow the full repository lifecycle before the related HUMAN AWS phase: Product Manager confirms the exact scope and repository, Software Engineer implements without committing, Architecture/Security re-review the frozen candidate where required, Tester runs the full affected verification, Product Manager performs final acceptance, Software Engineer commits with
Refs #143, the orchestrator merges and pushes through the repository's approved path, and On-Call verifies CI/CD. A credentialed HUMAN apply for infrastructure that is not self-deployed remains a separate digest-bound gate and does not replace those stages.If Support-backed reconciliation requires no repository change, PM must record that explicit no-change disposition and why; Tester and PM still verify the exact private-plan digest and sanitized evidence at the phase gates defined below. No Support response, runbook draft, or HUMAN approval retroactively authorizes an unreviewed file, workflow, template, deployment, or AWS mutation.
Public/private evidence boundary
Keep raw resource/account/principal identifiers, stack and table identifiers, events, item data, Support correspondence/case details, screenshots, commands containing identifiers, private locations/links, and credentials-adjacent material outside this public repository in the approved private knowledge/evidence system.
The public issue may contain only sanitized source classes, UTC bounds, counts, digests, state transitions, decisions, and PASS/FAIL/ABORT results. No raw operational document or evidence artifact is committed here.
Global security contract — applies to every phase
These three non-waivable controls apply to Support disclosure, baseline reads, backup/export, isolated rehearsal/restore, the selected ownership path, cutover, rollback, and cleanup. They supplement the Architecture-approved sequence and constraints; they do not replace any phase gate. Every mutation and rollback remains a separately named, frozen-runbook-digest-bound HUMAN approval.
1. Phase-scoped least privilege, session provenance, and operation reconciliation
Before each phase, the frozen private runbook must define a phase-specific access/session matrix containing the exact private account, region, resources, actor, expected principal, role/session source, issuance and expiry, MFA and approval provenance, and minimum API action/resource set. Read-only and mutation sessions must be separated where practical. The matrix must explicitly exclude shared/static credentials, production credentials in rehearsal, broad administrator sessions, and any broadening or reuse of the deployment OIDC role. Any IAM change requires a separately groomed Architecture/Security review and is not authorized by this issue.
Credentials must be short-lived, uniquely attributable, and scoped only to the approved phase. Entry and immediately pre-mutation checks must prove principal, account, region, resources, session validity, and frozen inputs. The runbook must retain privately both the exact allowed API/action/resource inventory and the exact observed operation inventory and reconcile them before the next mutation. Any extra permission, unexpected or missing API, unapproved principal/session, account/region/resource drift, expired session, or other mismatch causes ABORT before the next call.
At phase exit, capture session expiry or explicit revocation and prove that temporary access is no longer usable. Missing issuance, provenance, allowed/observed inventory, expiry, or revocation evidence fails closed. Enumerating calls never makes a broad administrator session acceptable.
2. Production-equivalent confidentiality for export and restored Sponsor data
Every backup, export, restored table, item, key, and derived integrity artifact retains the production Sponsor CRM classification in non-production for its entire lifetime. Use only approved isolated accounts/environments and principals, approved KMS keys, encryption in transit and at rest, private access paths, and controls that prevent public or unintended cross-account access. The target must have no external event source, webhook, mail/social/Telegram integration, scheduled writer, stream consumer, production credential, or uncontrolled integration/egress path; prove those exclusions before data is introduced and throughout rehearsal.
Item bodies, keys, per-item hashes, raw command output, and identifiers stay in the private evidence boundary and must not enter public CI/console logs, issues, screenshots, or routine Support material. Integrity evidence is private and access-controlled. Any digest that leaves the private boundary must use a Security-reviewed keyed or equivalently disclosure-resistant construction so low-entropy records cannot be guessed from fingerprints.
The private runbook must set a retention deadline, cleanup owner, inventory of data-bearing resources/artifacts/logs, rollback/incident-evidence hold, verified deletion procedure, and KMS/access revocation proof. Cleanup is blocked while an approved rollback or incident hold remains, then separately HUMAN-approved and verified complete. AWS Support receives only the minimum ownership diagnostics; production item data is excluded unless Security and an authorized HUMAN explicitly approve that specific disclosure.
3. Private audit/redaction execution and enforceable deploy/change/write freeze
Every phase must use a Security-reviewed execution mechanism that records UTC actor, session, action, result, state transition, and allowed-versus-observed operation evidence directly into the private evidence store. It must suppress shell tracing and verbose output that could expose credential material, item data, raw identifiers, private paths/links, or unredacted command output to public logs. Redaction and destination checks occur before any sanitized publication. An evidence mismatch or leak is an immediate ABORT and security-containment event; continuation requires a fresh Security decision.
Before snapshot or integrity comparison, detach/import, restore, or cutover, the runbook must enforce a deploy/change/write freeze with technical controls and captured proof; a procedural promise is insufficient. It must inventory every writer and mutator, including application writes, retries, TTL, streams, scheduled and asynchronous consumers, operators, deployment workflows, event-source mappings, integrations, and the #136 migration. For each one, define the enforced quiescence mechanism or complete ordered change-capture method, owner, start/end boundary, and verification.
Where complete quiescence is not possible, reconcile every captured mutation between equivalent logical points through cutover and throughout the rollback window. Abort before the next mutation on an unknown writer, reactivated workflow/integration, missing or unordered change, reconciliation mismatch, or unenforceable freeze. Freeze release is an explicit post-verification step and cannot silently occur during rollback or cleanup.
Phase 1 — AWS Support and read-only diagnosis
Do not manually create reserved
aws:tags. Do not treat a same-name ARN, current mapping, current schema, or current table identifier as historical ownership proof. If Support unexpectedly supplies an authoritative exact historical stack↔table binding, stop route B and request a fresh independent #140 route review; route A does not become authorized automatically.Phase 2 — immutable pre-change baseline and recoverability design
Before requesting approval for any backup/export action, the runbook must define the exact private baseline and evidence manifest:
The reviewed runbook must require a verified recovery source before any ownership mutation:
Phase 3 — isolated restore rehearsal
The first restore is an explicitly approved non-production rehearsal, never an implicit production repair.
Any mismatch, unexpected replacement/delete action, throttling risk, permission expansion, evidence leak, or inability to restore causes ABORT. A failed rehearsal must not advance to production.
Phase 4 — choose one supported CloudFormation path
Architecture and Security must select exactly one Support-backed path and reject the others in writing. Confirm every constraint against current official AWS documentation and Support guidance rather than assuming behavior.
Candidate A: retain/detach and import the existing table
DeletionPolicy: RetainandUpdateReplacePolicy: Retainwherever the accepted design requires them, and prove their effective template/change-set state before removal or import.Candidate B: restore/rebuild under a new physical name and cut over
Candidate C: AWS-supported association repair
Phase 5 — production runbook and explicit gates
Before any production action, publish a sanitized frozen runbook digest and retain the exact private runbook. It must enumerate:
Fresh gates are required in this order:
An approval for one phase does not authorize a later phase or any extra API/action. Material drift invalidates the frozen runbook and returns to review.
Required production verification
Test scenarios
Support cannot determine ownership or proposes an unsupported shortcut
The design fails closed. No tag repair, import, replacement, or migration occurs; escalate for clearer Support guidance.
Backup/export is incomplete or cannot be restored
Abort before ownership work. Preserve the original table and obtain a newly reviewed recovery design.
Rehearsal restores but integrity/configuration differs
Abort. Approximate counts or sampled reads cannot waive deterministic mismatch.
Import preview reports existing ownership, replacement, or deletion
Abort and return to Architecture/AWS Support. Do not execute or manually detach/retag.
Named-table replacement collides
Use a reviewed new-name/cutover design or stop. Never delete the production table merely to free its name.
Production identity, writes, load, cost, or change set drifts
Abort before the next mutation, preserve recovery assets, and execute only the already approved rollback boundary.
Support later proves the exact historical pair
Stop route B and request fresh Architecture/Security review in #140. Do not revive route A by inference.
Private evidence appears in a public artifact
Stop, contain through the approved security process, and do not continue until Security records a new decision.
Acceptance criteria
Out of scope