> For the complete documentation index, see [llms.txt](https://gotts.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gotts.gitbook.io/docs/gotts-vaults/vault/18-deployment.md).

# Deployment Runbook

> **Document Type**: OPS (informative) | **Part of**: [Vault PRD](/docs/gotts-vaults/vault.md) | **Last Updated**: 2026-02-17
>
> This is an operational document, not a product requirement -- see [shared/doc-standards.md](/docs/prd-shared/doc-standards.md) for document type definitions.

***

## Overview

This document specifies the deployment procedure for Gotts Vaults on Base (primary) and Ethereum (identity interop). It covers deployment order, constructor arguments, post-deployment verification, multi-sig setup, and monitoring bootstrap.

***

## 1. Deployment Order

Contracts must be deployed in this order due to constructor dependencies. Each step depends on addresses from previous steps.

```
Step 1: IdentityRegistryAdapter
  |-- References: ERC-8004 Identity Registry (0x8004A818...), Reputation Registry (0x8004B663...)
  v
Step 2: RiskEngine
  |-- References: none (standalone)
  v
Step 3: AgentVaultFactory
  |-- References: IdentityRegistryAdapter, RiskEngine, V4 PoolManager, implementation template
  v
Step 4: FeeModule (template)
  |-- References: none (cloned per vault)
  v
Step 5: NAVAwareHook (template)
  |-- References: V4 PoolManager
  v
Step 6: LaunchFeeHook (template)
  |-- References: V4 PoolManager
  v
Step 7: OnboardRouter (Phase 2)
  |-- References: Factory, IdentityRegistryAdapter, Permit2
  v
Step 8: AgentProxy contracts (Phase 3)
  |-- References: Factory
```

***

## 2. Constructor Arguments

### IdentityRegistryAdapter

| Parameter            | Value (Base)      | Notes                                |
| -------------------- | ----------------- | ------------------------------------ |
| `identityRegistry`   | `0x8004A818...`   | ERC-8004 Identity Registry on Base   |
| `reputationRegistry` | `0x8004B663...`   | ERC-8004 Reputation Registry on Base |
| `owner`              | Deployer multisig | Can update adapter with longTimelock |

### RiskEngine

| Parameter                         | Value (Base)      | Notes                                      |
| --------------------------------- | ----------------- | ------------------------------------------ |
| `defaultMaxDrawdownBps`           | 1000 (10%)        | Per chain profile table in 06-contracts.md |
| `defaultOracleMaxStaleness`       | 1800 (30 min)     | Base L2 value                              |
| `defaultSharePriceMaxIncreaseBps` | 500 (5%)          | Per D-018                                  |
| `owner`                           | Deployer multisig |                                            |

### AgentVaultFactory

| Parameter         | Value (Base)                                 | Notes                  |
| ----------------- | -------------------------------------------- | ---------------------- |
| `identityAdapter` | Step 1 output address                        |                        |
| `riskEngine`      | Step 2 output address                        |                        |
| `poolManager`     | `0x000000000004444c5dc75cB358380D2e3dE08A90` | Uniswap V4 PoolManager |
| `implementation`  | AgentVaultCore template address              | EIP-1167 clone source  |
| `owner`           | Deployer multisig                            |                        |

***

## 3. Post-Deployment Verification Checks

Run these checks after each deployment step. All must pass before proceeding to the next step.

| Check                    | Command                                      | Expected Result                                  |
| ------------------------ | -------------------------------------------- | ------------------------------------------------ |
| Adapter identity query   | `adapter.isValidAgent(knownAgentId)`         | `true` for a known registered agent              |
| Factory identity adapter | `factory.identityAdapter()`                  | Matches Step 1 output address                    |
| Factory vault count      | `factory.vaultCount()`                       | `0` (no vaults yet)                              |
| Factory is deterministic | `factory.computeVaultAddress(testConfig, 0)` | Returns a non-zero address                       |
| Test vault creation      | `factory.createVault(testConfig)`            | Vault + hook + pool created; `vaultCount() == 1` |
| Test vault membership    | `factory.isVault(testVaultAddress)`          | `true`                                           |
| RiskEngine queryable     | `riskEngine.getVaultLimits(testVault)`       | Returns default limits                           |
| V4 pool initialized      | `poolManager.getSlot0(sharePoolId)`          | Non-zero sqrtPriceX96                            |

### Smoke Test Script

```bash
pnpm deploy:verify --network base --factory <address> --adapter <address>
```

This script runs all verification checks and outputs a pass/fail report.

***

## 4. Multi-Sig Setup

| Role             | Signers         | Threshold | Purpose                                                      |
| ---------------- | --------------- | --------- | ------------------------------------------------------------ |
| Factory Owner    | 5 team members  | 3-of-5    | Implementation upgrades, adapter changes (with longTimelock) |
| Sentinel         | 3 security team | 1-of-3    | Emergency pause, hook kill-switch (immediate)                |
| Cancel Authority | 3 security team | 1-of-3    | Proxy cancel-only key (D-004)                                |

All multisigs use Safe with Transaction Guard modules. The Sentinel multisig has NO ability to initiate transactions -- only `cancel()`, `pause()`, and `disableHook()`.

***

## 5. Monitoring Bootstrap

### Required Event Monitors

Deploy these OpenZeppelin Monitor watchers within 1 hour of factory deployment:

| Event                     | Source        | Threshold     | Alert Channel                |
| ------------------------- | ------------- | ------------- | ---------------------------- |
| `VaultCreated`            | Factory       | Any           | Info (Telegram)              |
| `CircuitBreakerTriggered` | RiskEngine    | Any           | Critical (PagerDuty)         |
| `RiskWarning`             | Any vault     | severity >= 2 | Warning (Discord + Telegram) |
| `HookDisabled`            | Any VaultHook | Any           | Critical (PagerDuty)         |
| `VaultPaused`             | Factory/Vault | Any           | Warning (Discord)            |
| `OracleStale`             | RiskEngine    | Any           | Warning (Discord)            |
| `AdapterExposureBreach`   | RiskEngine    | Any           | Critical (PagerDuty)         |

### Health Dashboard

The monitoring dashboard must show:

* Total vaults deployed, total TVL, total agents
* Per-vault: NAV, share price, idle ratio, oracle freshness
* Circuit breaker status (green/yellow/red) per vault
* Proxy queue depth and oldest pending announcement

***

## 6. Rollback Procedures

| Failure Mode                 | Rollback Action                                                                                | Time to Execute                         |
| ---------------------------- | ---------------------------------------------------------------------------------------------- | --------------------------------------- |
| Bug in vault implementation  | Deploy new factory with patched implementation; existing vaults unaffected (immutable)         | \~30 min                                |
| Identity adapter failure     | Deploy new adapter, call `factory.setIdentityAdapter()` (longTimelock)                         | 3-7 days                                |
| RiskEngine misconfiguration  | Update parameters via `setVaultLimits()` (shortTimelock)                                       | 12-24 hours                             |
| Hook vulnerability           | Sentinel calls `disableHook()` (immediate); re-enable requires Owner+Curator with longTimelock | Seconds (disable), 3-7 days (re-enable) |
| Complete protocol compromise | Sentinel pauses factory; all vaults enter emergency withdrawal mode                            | Seconds                                 |

***

## 7. Deployment Checklist

* [ ] All Phase gate tests pass (per 17-testing.md)
* [ ] Audit report received and all critical/high findings resolved
* [ ] Multi-sig wallets created and funded
* [ ] Constructor arguments reviewed by 2+ team members
* [ ] Deployment script produces deterministic output (same addresses on repeated runs)
* [ ] Post-deployment verification checks pass
* [ ] OpenZeppelin Monitor watchers deployed
* [ ] Health dashboard operational
* [ ] Rollback procedure tested on testnet
* [ ] Team communication channel established for launch day
