War-game a release train before freeze windows, cut lines, and comms templates harden into how every ship date gets promised.
Release trains fail when freezes invent discipline engineering never kept, when dependencies land after the cut without a named owner, when status pages lag the actual deploy, and when sales quotes dates the train cannot meet. A neat calendar is not evidence.
What must be frozen
State the cadence, freeze rules, who owns cut decisions and hotfixes, what success looks like after two quarters of on-time ships, and the kill criteria if missed windows or incident rate exceeds a named threshold. Attach the dependency map, sample release notes, on-call coverage, and the measured lag from merge to production. If engineering, product, and support disagree on what "in this train" means for a customer promise, reconcile before seating.
Name the decision you will make if the war game finds nothing new, and the hold criteria if any critical path still lacks a named owner or a measured rollback drill.
Where it breaks
- Freeze fiction: rules that look firm while late merges still land without a log.
- Dependency bleed: third-party or partner changes that arrive after the cut line.
- Comms lag: status and release notes that trail the deploy customers already felt.
- Hotfix theater: emergency paths that dual-count the same on-call hour.
- Sales overclaim: dates quoted from a slide the train never committed to.
Optional counsel seat if contractual ship dates or regulated change windows bind the form. Optional customer success seat if enterprise customers gate upgrades on the train.
Run it
Feed Pingpong the train brief, dependency map, and open risk list. Early passes steelman the cadence. Later passes attack from engineering, product, support, sales, and skeptic seats. End with a pass that turns surviving objections into clearer freeze owners, a published hotfix path, or a hold. Delete invented "we already ship on schedule" claims and dual-counted release capacity.
Ask engineering and support seats to price the behavior the new train will invite. If day-one copy promises weekly ships while rollback drills still fail, customers will treat the calendar as fiction. Write the intended freeze owners, the hotfix criteria, and the language you will refuse, then attack whether trust still holds under that discipline.
Force a day-after narrative: what happens if a critical dependency slips the day before cut, if a hotfix bypasses review, or if a large account reads the status page against an incomplete deploy. If those stories are stronger than your mitigation plan, fix the package before you operationalize it. Related: war-game a product launch, war-game a launch checklist, stress-test a feature flag rollout, stress-test a migration plan, and the war-game decisions hub. Process: how to run a Pingpong.