# MCP stop-and-restart handoff worksheet

Blank operational template. This does not enforce cancellation, grant authority or implement the MCP protocol. Complete it in a restricted incident system. Use evidence references, not credentials or raw sensitive payloads. All times must include a timezone.

## Incident and scope

- Incident ID:
- Barrier ID / durable record reference:
- Old root run and descendant run IDs:
- Affected tenant, environment and resources:
- Stop requested at / by:
- Current state: stop_incomplete
- Outgoing responder:
- Incoming responder:
- Ownership acknowledged at:
- Escalation contact / deadline:

## Enforcement evidence

- New dispatch blocked at / evidence:
- Root and descendant leases revoked at / evidence:
- Effect-side fence or equivalent enforcement / evidence:
- Queued work, delayed retries, callbacks and continuations inventoried / evidence:
- Old work unable to write later / evidence and scope limits:
- Unobservable services or workers:

An idle interval alone does not prove that old work cannot write. If the provider cannot be fenced, record its terminal status and verify its effects before clearing the operation.

## Outstanding operations

Copy this block for every accepted operation, including completed operations that need recovery.

- Operation ID:
- Provider / job ID / authoritative status endpoint:
- Target resource and intended effect:
- Cancellation request time / response:
- Last authoritative check time / evidence reference:
- Outcome: unknown
- Observed effect / effect receipt:
- Reconciliation owner:
- Owner acknowledged at:
- Next check due:
- Escalation if unresolved:
- Recovery decision: pending
- Recovery authorization reference, if a write is needed:

Allowed reconciled outcomes: cancelled_without_effect or completed_and_verified. A cancellation acknowledgement is not a terminal outcome. An owner accepting this block does not clear unknown status.

## Stop decision

- Pending calls:
- Unknown outcomes:
- Active old leases:
- Delayed work accounted for / evidence:
- Observation interval and reason for its duration:
- Evidence reviewer / reviewed at:
- Decision: stop_incomplete

Use stopped_and_quiet only after the completion rule and enforcement checks pass. Keep the original records if a later check changes the decision.

## Separate restart decision

- Decision: restart_blocked
- Current target state / version / checked at:
- Remaining work to continue, compensate or abandon:
- Evidence all old outcomes are reconciled:
- Evidence old work cannot create later effects:
- New run identity:
- Allowed operations and target scope:
- Fresh authority expiry:
- Restart approver / approval time / decision reference:
- Dispatch-time checks required:

Do not reuse the old lease. Do not approve restart while an old operation remains unknown. Recovery writes need their own scoped approval. If state changes after approval, re-evaluate before dispatch.

## Tabletop exercise record

This template ships without an executed production exercise.

1. Supply a synthetic job with cancellation acknowledged but terminal status unknown. Expected: stop_incomplete and restart_blocked.
2. Transfer ownership. Expected: the incoming responder acknowledges the next check; status remains unknown.
3. Reveal that the job completed and created a reservation. Expected: completed_and_verified with an effect receipt, then an explicit recovery decision.
4. Attempt restart without fresh authority. Expected: restart_blocked.
5. Supply reconciliation, effect-side enforcement, current state and scoped approval. Expected: restart_approved only if every gate is satisfied.

- Exercise date / participants:
- Observed result for each step:
- Missing evidence or enforcement:
- Follow-up owner / deadline:
