# Hatchways Agentic Mode Due Diligence Checklist

Give a Hatchways product or engineering owner a narrow validation checklist for the live HotTea proof before account-level GitHub App creation or procurement work.

## Validation Checks

### Reviewer packet utility

- Check: Open the sample packet and confirm the reviewer can see correctness, hidden-test status, AI process quality, transcript/session counts, git/test evidence, and follow-up questions without logging into a dashboard.
- Proof: https://hottea.ai/sample-report
- Pass signal: Reviewer can make a 10-minute yes/no call on whether the packet adds signal beside Hatchways hidden grading.

### Repo workflow fit

- Check: Inspect the GitHub Actions fallback and integration guide for candidate repo, PR, workflow, SHA, diff, test, and session-export evidence ingestion.
- Proof: https://hottea.ai/hatchways/integration.md
- Pass signal: Engineering can validate the adapter path without a GitHub App or customer repo access.

### Candidate experience boundary

- Check: Review the demo script and pilot kit for the candidate-visible flow: assignment packet, provisioned VM, Claude/Codex recorder wrappers, tests, ae-finalize, and final submission.
- Proof: https://hottea.ai/hatchways/demo-script.md
- Pass signal: The flow reads as a practical assessment workspace, not locked-browser proctoring.

### Risk and non-claims

- Check: Open the security, objection, and readiness packets and confirm the current limits are explicit.
- Proof: https://hottea.ai/hatchways/security.md
- Pass signal: No reviewer or buyer has to infer missing SOC 2, DPA, SSO, retention SLA, procurement, GitHub App, partnership, or anti-cheat claims.

### Pilot go/no-go

- Check: Use the decision brief and rollout checklist to decide whether one internal Hatchways-style assessment is worth testing.
- Proof: https://hottea.ai/hatchways/decision.md
- Pass signal: The only recommended next step is a limited technical pilot through the verified fallback path.

## Minimum Evidence to Accept

- Sample report renders and exposes hidden-test status, AI-process analysis, transcript/session counts, VM events, git/test evidence, and ATS-ready reviewer note.
- GitHub Actions fallback remains available because the real GitHub App is not configured.
- OpenAPI, /llms.txt, and /api/config discover the Hatchways proof routes.
- Markdown packets do not leak object-serialization artifacts.

## Blocked Until Account Work

- Real GitHub App creation.
- GITHUB_APP_INSTALL_URL deployment configuration.
- Official Hatchways partnership approval.
- Enterprise procurement artifacts such as SOC 2, DPA, SSO, retention SLA, and vendor security review.

## Not Claimed

- No official Hatchways partnership.
- No real GitHub App before GITHUB_APP_INSTALL_URL is configured.
- No enterprise procurement readiness.
- No perfect anti-cheat or outside-AI prevention.
- No automated hiring decision.

## Proof URLs

- Due diligence JSON: https://hottea.ai/hatchways/due-diligence.json
- Sample reviewer packet: https://hottea.ai/sample-report
- Integration guide: https://hottea.ai/hatchways/integration.md
- Demo script: https://hottea.ai/hatchways/demo-script.md
- Security packet: https://hottea.ai/hatchways/security.md
- Objection packet: https://hottea.ai/hatchways/objections.md
- Readiness scorecard: https://hottea.ai/hatchways/readiness.md
- Decision brief: https://hottea.ai/hatchways/decision.md
- Rollout checklist: https://hottea.ai/hatchways/rollout.md
