Graduated Launch
How do we release without breaking trust? Release in four steps: internal, beta, soft launch, live. Each step exists so that failures surface before they reach everyone.
Four steps, each wider than the last.
What moves it to the next step
Each step ends when its evidence is in, not when the calendar says so.
Internal
The people who built it use it for real work, where a failure costs little.
It does the job on real tasks, and every step it takes is traced, so a failure can be found and explained.
Beta
Real users who know it's early, chosen because they'll hit the failures you haven't.
They keep using it without being told to.
Soft launch
New users arrive without a launch moment. The question changes from "does it work?" to "does the setup repeat?"
Each new customer gets going on the same setup, without special handling.
Live
Everyone can use it, and the announcement goes out.
What the earlier steps taught you is in the release, and someone is watching it.
From internal use to every clinic.
Illustrative example A clinic booking assistant. Not client work.
Internal, then beta clinics
We'd watch three things: whether patients book in chat without being told to, whether beta clinics keep it switched on after the pilot, and whether paid bookings turn up for their slots.
The gate
It goes to market only if the beta clinics keep using it.
Soft launch
One launch can be luck. Each new clinic proves the setup repeats.
Live for every clinic
With new clinics starting from the same setup.
Where it goes wrong
- Misread
Treating beta as a marketing phase
Why Beta exists to find failures, so it needs users who will actually hit them.
- Misread
Skipping the soft launch because beta went well
Why A few friendly beta users prove it works for them. A soft launch proves it works for the next customer.
- Misread
Moving on by date
Why A step ends when its evidence is in.
In the Journal: AI prototype to production
Published 24 September 2026. Graylemon original, from our engagement method.