By cutover weekend the load should have run at full volume three times already. The plan is a sequence with measured durations, reconciliation gates between stages, explicit go and no-go criteria and a rollback position that has been tested rather than assumed.
Cutover failures are rarely caused by a surprise in the data. They are caused by a load sequence that was never run end to end at full volume, and by a rollback position nobody tested.
Agile object dependencies decide the order. Manufacturer parts before AML. Components at the right revision before the structures that consume them. Attachments staged before the records that reference them. Completed changes replayed oldest effective date first. Each stage has a measured duration from rehearsal, and each has a reconciliation gate: if the counts do not match, the next stage does not start.
Attachments are usually the long pole, and they are also the stage most often estimated rather than measured. A multi-terabyte vault cannot be transferred, checksummed and uploaded inside a weekend unless the bulk moved beforehand and only the delta remains. Rehearsal is what turns that from a hope into a number.
The rollback position matters more than anyone wants it to. It means Agile remains authoritative, unfrozen and usable until the reconciliation gates have passed, and it means somebody has actually exercised the path back rather than written it on a slide.
If any of these is missing, the weekend is an experiment.
Every stage timed at full volume in rehearsal, so the critical path is arithmetic rather than optimism.
A count match required between stages. A stage that does not reconcile stops the sequence rather than feeding the next one bad data.
Exactly what engineering can and cannot do in Agile during the window, agreed and communicated before it starts.
A path back that someone has exercised, with the point of no return identified and stated explicitly.
Written before the weekend, in numbers, so the decision at 2am is a comparison rather than a judgement call.
Who decides, who is on call, and how they are reached. Every hour spent finding someone comes out of the window.
Rehearse until the run is boring, then do it for real.
First full-volume run. Expect failures; the purpose is to find the dependency problems and measure the stages for the first time.
Fixes applied, run repeated, durations refined and the attachment strategy proven against real vault volumes.
Clean run against the clock, with the reconciliation pack produced exactly as it will be on the night.
Change freeze begins, delta extract runs, go and no-go criteria checked against rehearsal figures.
Sequenced load with gates, reconciliation, sign-off, then hypercare while real users find the things rehearsals cannot.
A rehearsal that produces no numbers has told you only that the logic works. The point of running at full volume is to turn every stage of the cutover into a duration you can add up.
These are the figures the cutover plan is built from, and they are refined at each rehearsal rather than estimated once.
Three shapes, each suited to a different portfolio.
Everything moves in one window. Simplest to reason about, shortest coexistence, and the least room for anything to go wrong.
Smaller windows and lower risk per event, at the cost of a coexistence period that needs integration and governance.
Current revisions and structures first, then historical revisions and redlines afterwards. Shortens the critical window considerably.
For the structured product data alone, typically a weekend. What stretches it is attachments: a multi-terabyte vault cannot be transferred, checksummed and uploaded inside that window, so the bulk moves beforehand and only the delta is handled during cutover. The honest answer for any specific programme comes from rehearsal, because a duration measured at full volume is worth more than any estimate made from item counts.
It is the period when engineering cannot make changes in Agile, so that the delta extract captures a stable position. Typically it runs from the start of the cutover window to go-live, which is a few days. Scope matters as much as duration: exactly which activities are frozen, what the exception process is for a genuine emergency, and who can authorise one. All of that is agreed and communicated before the freeze starts, not during it.
Up to the point of no return, yes, and the plan states explicitly where that point is. Before it, Agile remains authoritative and unfrozen, so rolling back means resuming work there. After it, users have begun working in the target and rollback means reconciling two divergent positions rather than simply reverting. The rollback path is exercised during rehearsal, because an untested rollback is not a rollback.
They are written before the weekend and expressed in numbers, so that the decision at an unsociable hour is a comparison rather than a debate. Typically: every load stage reconciles within an agreed tolerance, the exception count is below an agreed threshold with no critical exceptions open, attachment checksums verify completely, elapsed time is inside the rehearsed window, and a named business owner accepts a sample validation. Any breach triggers the stated response, which may be to continue with a known issue, to pause, or to roll back.
Three full-volume rehearsals is the usual figure, and the count matters less than the condition: cutover should be the first time the run is boring. The first rehearsal finds dependency problems and produces the first real durations. The second proves the fixes and the attachment strategy. The third is a clean run against the clock producing the reconciliation pack exactly as it will be produced on the night.
Hypercare, usually for two weeks, with the migration team available and the exception process still running. Real users exercise paths that rehearsals cannot, and the issues they find are typically mapping decisions that were reasonable in design and wrong in practice rather than load failures. The Agile environment stays available read-only through hypercare, and only then does decommissioning start.
Book a call. We will walk through the load sequence, where the reconciliation gates sit, how attachment volume shapes the window, and what your go and no-go criteria should measure.