Running zero-tolerance financial checks and managing executive sign-offs — I didn't improvise any of this, because nothing here is worth gambling on.
De-risking trust before I needed it
I ran both platforms in parallel and reconciled daily through every wave, not just in a final test window. By the time cutover arrived, the target had already matched the source for weeks — so the switch removed the old system instead of gambling on the new one.
I wanted trust earned before go-live, not asked for after. A big-bang cutover means the first real test happens in front of the business; dual-run means I'd already seen weeks of clean reconciliation before anyone else even noticed the switch happened.
I opened an elevated-support window at go-live: a daily war-room I ran myself, fast-track defect SLAs, and champions fielding questions inside each function. I set the exit criteria myself too — defect rate below threshold and adoption climbing — before I'd let hypercare close and support go back to normal.
The gate I wouldn't move on
I agreed every go/no-go criterion before the meeting happened, so the decision was reading the evidence, not debating the bar. I kept one named decider — the executive sponsor — but the numbers had to pass before it ever reached them.
Agreeing the bar after the evidence is in is how "close enough" quietly becomes the new standard under deadline pressure. Setting the criteria before the meeting is what let me hold the line on one pending UAT sign-off instead of waving it through.
| Criterion | Threshold I set | Status |
|---|---|---|
| Financial reconciliation | Zero variance on all financial metrics | Pass |
| Open defects | No Sev-1 / Sev-2 open | Pass |
| Report parity | 100% of in-scope reports signed off | Pass |
| Rollback tested | Rehearsed in a non-prod dry run | Pass |
| UAT sign-off | All function SMEs signed | 1 pending |
| Support readiness | Hypercare team & runbook staffed | Pass |
Every step sequenced against a T-clock, with an owner and a checkpoint. The freeze protected data integrity; the reconciliation gate was my point of no return.
Cutover weekend is the worst possible time to improvise a decision. A minute-by-minute runbook with a pre-agreed rollback trigger meant nobody had to find me to ask permission when the reconciliation gate mattered most.
| T-clock | Step | Owner | Checkpoint |
|---|---|---|---|
| T-48h | Comms sent; freeze announced; support on standby | Change Lead | Acknowledged |
| T-2h | Source freeze — no writes to legacy EDW | Data Eng | Freeze confirmed |
| T-0 | Final incremental load; catch-up to freeze point | Data Eng | Load complete |
| T+1h | Final reconciliation — revenue to the penny | Testing / me | Go point |
| T+2h | Re-point reports & connections to Snowflake | BI Lead | Smoke test pass |
| T+3h | Open access to users; announce live | Me | Live |
| Any | Rollback trigger I set: reconciliation fails or Sev-1 found → revert to legacy, unfreeze, stand down | Me | Legacy restored |
Golden thread · go-live
At the T+1h gate, CLOSE_AMOUNT_USD reconciled to the penny against the frozen source — the same field that ran 6% high in test now matched exactly, because I'd already fixed the grain and definition upstream. That single green check is what let the sponsor say go.
Scar tissue
What I Actually Decided Here
Decision: I found a 0.003% rounding discrepancy in the historical variance reports, caused by legacy floating-point differences, and I refused to allow the Phase 4 cutover gate to pass until it was patched.
Friction: Executive sponsors wanted to waive the variance to hit the quarter-end milestone — 0.003% sounded small enough to wave through.
Outcome: I preserved absolute financial audit credibility instead of trading it for a date, and had the transformation logic patched within 48 hours anyway.