Print it. Check boxes with a pen if you have to. Our list has 47 rows; below is the shape, not every bullet—ask us for the full sheet if you are shipping next week.
Environment & config
- Production env vars match staging names and differ only in values.
- Secrets are not in Vercel dashboard screenshots in Slack.
- Feature flags documented: who can flip, rollback path.
SEO & crawl
- Canonicals on templates with parameters.
- Noindex on preview, auth, cart fragments.
- Redirect map tested with real query strings.
robots.txtandsitemap.xmllast-mod honest.
Analytics & consent
- CMP fires before non-essential scripts in EU traffic.
- Conversion events named the same in dev notes and GTM.
- 404 page tracked separately from soft 404 templates.
Performance
- LCP image traced in RUM, not just lab.
- Fonts: no FOUT on primary headline path.
- Third-party list signed off with owners.
Security
- Headers: HSTS, CSP at least report-only in prod.
- Cookie flags: Secure, SameSite plan written down.
- Dependency audit this week, not “soon.”
Content & legal
- Footer company data matches registry.
- Pricing footnotes match finance’s source file.
- Contact form delivers to the address legal expects.
Incident readiness
- Status page account exists and is tested.
- On-call rotation knows how to roll back data migrations, not just deploys.
Where this breaks down
When “launch” is a marketing date and engineering first sees the redirect list the night before.
Our read
Nobody wants this checklist. Everybody wants sleep the night after cutover. We trade an hour of boredom for that.