SUMMARY: Review a service retirement by testing the work that must remain possible after shutdown. Use synthetic cases in a tabletop exercise or authorized test environment. Do not disable a production service, revoke credentials, or delete records as an exploratory test.
1. Define What Is Retiring
Name the interface, intake process, processing function, archive, and support route separately. Identify which will stop, which will transfer, and which will remain available under restrictions. Establish a responsible approver for each boundary.
Start from a Dependency Register. A familiar interface may conceal an identity check, permission, or interpretation step that the replacement does not yet provide.
2. Select Three Residual Cases
- Unfinished work: a request was admitted before shutdown but has not been decided.
- Historical correction: a participant identifies a disputed field in an older outcome.
- Old reference: a returning participant has only the original case number and a notice naming the retiring service.
Give each synthetic case a clear expected destination. Include a deliberately unsupported case so the team must demonstrate an escalation rather than invent a promise it cannot fulfill.
3. Verify Meaning and Authority
Ask a receiving operator to reconstruct the case using the retained material. Then ask which next action that operator can actually perform. Record missing context separately from missing permission; they need different repairs.
Keep the old and new references linked without overwriting the original receipt or issuance time. A migration timestamp can describe the transfer, but it should not silently become the age of the participant’s request.
4. Test the Participant Route
Follow the instructions in the old notice from a test account with ordinary permissions. Does the route reach the accepted owner? Can a person report missing records without first obtaining those same records? Does the fallback disclose only information appropriate to that channel?
Use Test a Notice Chain when the retirement announcement or follow-up message depends on an account that will no longer work.
5. Record a Bounded Decision
For each case, retain the original reference, receiving reference, record location, permitted next action, accepting owner, test result, and unresolved exception. Apply the relevant retention and access rules rather than assuming that every copied record must remain indefinitely.
Approval should identify what was demonstrated and what remains outside the test. A failed critical path needs correction, an explicit exception, or a revised retirement boundary before closure is treated as complete.
Acceptance rule: records needed for the tested work remain interpretable, and an identified receiving function accepts responsibility for the next step. See Retirement as Governance for the decisions behind that handoff.
Place this retirement exercise within the Digital Systems Accountability review to connect handoff ownership with explanation, challenge, and verified correction.