FrameworkFive-Gate Deployment ModelSheet 20

The Five-Gate Deployment Model.

A pipeline enforces a sequence. A gate assigns a person to it. A deployment discipline for AI systems.

← Defensible AI · How the nine relate

§ 01Status

What this is.

REG-06 · Five-Gate Deployment Model™

Position in the architecture · Operational Machinery

Specification · Deposited. 10.5281/zenodo.22170122, CC BY 4.0.

The five gates in sequence, with entry evidence, accountable roles and exit criteria Five gates in order. Gate one, Data and Design, takes classification, residency, lineage and vendor clearance, is accountable to the named data owner, and on passage permits the system to be built but not exposed. Gate two, Validation, takes the inventory entry, pre-validation and an independent validation, is accountable to the named validator, and permits the system to be presented for approval within the validated envelope. Gate three, Approval, takes the closed validation and the approval package, is accountable to the named executive, and grants approval for a stated use with an expiry. Gate four, Deployment, takes release authority, contractual controls, configured guardrails and a tested rollback, is accountable to the named platform owner, and permits staged production traffic. Gate five, Operation, takes live monitoring and armed incident triggers, is accountable to the named head of the governance office, and is re-tested at every revalidation trigger rather than passed once. Each gate writes a gate passage record and each has a rejection path returning the system to a stated prior stage. The five gates in sequence, with entry evidence, accountable roles and exit criteria Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170122 https://doi.org/10.5281/zenodo.22170122 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/five-gate THE FIVE GATES ENTRY EVIDENCE MUST EXIST BEFORE THE GATE IS ENTERED classification residency, lineage vendor clearance stated intended use inventory entry, tier pre-validation independent validation second line, no stake validation closed approval package residual risk stated decision right assigned release authority contractual controls guardrails configured rollback tested monitoring live triggers armed revalidation register incident lead reachable G1 Data and Design named data owner writes a gate record G2 Validation named validator writes a gate record G3 Approval named executive writes a gate record G4 Deployment named platform owner writes a gate record G5 Operation named office head re-tested, not passed once WHAT PASSAGE PERMITS, AND NOTHING WIDER may be built and trained. MUST NOT be exposed may be presented for approval, for the use examined approved for a stated use, with an expiry or trigger may serve traffic, within the exposure the record states operates. Exits by retirement, rollback or loop-back every gate has a rejection path. A rejected system returns to a stated prior stage with the failing criterion named A gate passed without its entry evidence is not passed. A record naming a committee is not a gate passage record. The Five-Gate Deployment Model v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/five-gate · CC BY 4.0 · DOI 10.5281/zenodo.22170122
Figure 1. The five gates in order, with the framework supplying each gate’s entry criteria.
§ 02Five gates

Five gates.

No AI system reaches production, or remains there, except by passing five gates in order. G1 Data and Design consumes data classification and lineage from AI Data Governance and vendor clearance from AVRF. G2 Validation consumes independent validation from MESA MRM. G3 Approval binds a named person. G4 Deployment records what shipped. G5 Operation is where the system lives and where revalidation returns.

The three reverse paths: rejection, rollback and loop-back Three ways a system moves backwards through the model. Rejection at any gate returns the system to a stated prior stage with the failing criterion named: gate one returns it to design, gate two to design or gate one depending on whether the failure was in the system or the data, gate three to gate two, gate four to gate three only if the configuration differs from what was approved, and gate five to gate four. Rollback withdraws an operating system from production back to gate four, with the evidence of the reversal preserved, by a decision of the accountable person at gate five or gate three; the gate three approval remains valid. Loop-back reopens validation at gate two after an incident, so that the institution's assessment of a system is never older than the system, and which incidents trigger it must be defined in advance rather than decided afterwards by the people whose work would be reopened. A system leaves the model by retirement, which is a recorded decision and requires the evidence records of every gate to be retained. The three reverse paths: rejection, rollback and loop-back Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170122 https://doi.org/10.5281/zenodo.22170122 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/five-gate THE REVERSE PATHS Design not yet a gate G1 Data and Design G2 Validation G3 Approval G4 Deployment G5 Operation REJECTION a rejected system returns to a stated prior stage, and the record names the criterion that failed ROLLBACK G5 to G4. The system is withdrawn from production traffic. The evidence of the reversal is preserved, the rollback path was tested before G4 was passed, and the G3 approval remains valid. The system returns by passing G4 again. LOOP-BACK An incident at G5 reopens G2. Validation, not a patch. An incident is evidence about the validation as much as about the system. Which incidents trigger this is defined in advance, never decided afterwards by those whose work reopens. A system leaves the model by retirement, which is a recorded decision, and the gate records outlive the system. The Five-Gate Deployment Model v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/five-gate · CC BY 4.0 · DOI 10.5281/zenodo.22170122
Figure 2. Rollback and loop-back. The reverse paths are part of the model, not exceptions to it.
§ 03One named person, never a committee

One named person, never a committee.

The accountable role at every gate must be a single named person. A committee, a function, a team, a board or a role held jointly must not be recorded as the accountable role. This is the property that distinguishes the model from a pipeline: a pipeline enforces a sequence, and a gate assigns a person to it. An institution that records a committee has a sequence with a meeting attached.

Why the BOE mapping matters: records that share a shape can be joined Four kinds of record are shown side by side, each stating the same three things in the same shape: the boundary it fixes, the optimizer it frees, and the evidence that the boundary held. A gate passage record from the Five-Gate model, a validation record from model risk management, a residency attestation from data governance, and a screening record from vendor risk. Because all four state a boundary, an optimizer and evidence, an incident reconstruction can read across all of them and produce a single account. Beneath them a fifth record is shown outside the shape, carrying only a timestamp and a message, and it cannot join: it can be filed alongside the others but not read with them. The caption records that two controls emitting evidence in one shape compose, while two that do not are merely adjacent however well each is drawn. Why the BOE mapping matters: records that share a shape can be joined Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170122 https://doi.org/10.5281/zenodo.22170122 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/five-gate RECORDS THAT SHARE A SHAPE CAN BE JOINED FOUR FRAMEWORKS, FOUR RECORDS, ONE SHAPE FIVE-GATE, G3 Gate passage record B a system nobody is answerable for may not enter production O discretion over what the institution runs E the record, naming a person MESA MRM Validation record B an unexamined system may not be believed O free choice of method inside the envelope E the validation report, signed by the second line DATA GOVERNANCE Residency attestation B this data may not leave the jurisdiction O free choice of topology under that clause E routing evidence, per request AVRF Screening record B an unassessed vendor may not hold autonomy O free choice of supplier among those assessed E the questionnaire, with evidence attached one shape, so one query Incident reconstruction which boundary, which policy version, which person AND ONE THAT CANNOT JOIN Application log line timestamp, severity, message, stack trace no boundary stated, no optimizer stated, no policy version it can be filed beside the four above. It cannot be read with them, because it answers a different question. Two controls that emit evidence in one shape compose. Two that do not are adjacent, however well each is drawn. The Five-Gate Deployment Model v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/five-gate · CC BY 4.0 · DOI 10.5281/zenodo.22170122
Figure 3. Each gate record as a BOE Declaration, which is what makes it joinable with validation and residency records.
§ 04The reverse paths, and the field most often omitted

The reverse paths, and the field most often omitted.

Rollback and loop-back are part of the model. A system that cannot return to an earlier gate has a one-way pipeline with gates painted on it. Passing with conditions is permitted and must be recorded, because an unrecorded exception is a skipped gate. The field easiest to omit and the one reconstruction most needs is the policy version in force at the moment the gate was passed.

§ 05Where it applies

Which institutions, and on whose authority.

Any regulated institution

Five-Gate governs how any AI system reaches production and who said it could. The gates do not change by sector; what changes is which framework supplies each gate’s entry criteria, and how much evidence the supervisor expects to see at G3.

§ 06How it has changed

The record of its own revisions.

A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.

Change history

  • 2026-08-30 · entry v1.0 — First registry entry, status instrument-pending
  • 2026-08-30 · entry v1.0 — Records the promotion to the lifecycle spine of the governance family, and the BOE mapping
  • 2026-09-15 · entry v2.0 — The inbound supply edge from REG-02 now carries the revalidation trigger register at G5, which this framework names as an entry criterion at 3.6 of its own specification. The entry changes; the framework does not

Limitations recorded in the registry

  • A trademark clearance search has not been completed as of the date of this registry. The naming rule is stated as a discipline rather than as the outcome of one, and this registry does not assert that the mark is available.
  • No readiness assessment instrument exists, so an institution can be told what the gates require but cannot be scored against them.
  • No gate evidence templates are published.
  • Governs passage. Does not specify what a validation must contain, what a classification must cover or what a monitoring threshold should be.

What would show this to be wrong. Five-Gate is falsified if institutions operating five gates with a single named accountable person at each are found to deploy unfit AI systems at the same rate as institutions operating an automated delivery pipeline with equivalent automated checks and no named approver. The model's distinguishing claim is that a named person accountable at a checkpoint changes the outcome relative to an equivalent automated check, and evidence that it does not would leave the gates as latency.

§ 07Honest limits

What this does not claim.

Asserted. A trademark clearance search has not been completed against third-party registrations in the product-innovation field, where gated progression is a crowded space. The specification deliberately names no proprietor and no jurisdiction.

No institution unconnected to the author has been observed operating the model end to end.

§ 08Cite

Citation.

Cite this work. Five-Gate Deployment Model, version 1.0. 10.5281/zenodo.22170122. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.

§ 09Where this sits

In the practice.

§ 10Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”

A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.

Fin · Machine-Accessible Expertise
Point your assistant at the endpoint →