|
|
|
@@ -61,7 +61,7 @@ accepted as the current baseline and must not be reopened as greenfield work.
|
|
|
|
|
| Acting identity, function assignment, mandate, and ownership recovery | Implemented foundations span Identity, Organizations, IDM, Access, Mandates, generic ownership transfer/recovery, and audit provenance. Effective competence now resolves through a tenant-bound Mandate capability. |
|
|
|
|
|
| Governed data foundations | Connectors, Datasources, Dataflow, Reporting, and Search now exist. Datasources already provides live/cached/static modes, staging, immutable materializations, and publication contracts. |
|
|
|
|
|
| Task-focused projections and configured documentation | Views, view-surface declarations, configurable dashboards, and manifest-driven user/admin documentation exist. Rollout and content depth remain incremental. |
|
|
|
|
|
| Encryption as an optional capability | `govoplan-encryption` now defines key-vault, content-protection, recovery, and disable-preflight boundaries. It is not a reason to move domain ownership into Core. |
|
|
|
|
|
| Encryption as an optional capability | Core defines provider-neutral contracts; `govoplan-identity-trust` persists public device keys, key epochs and assurance evidence; and `govoplan-encryption` persists opaque vault/key lifecycle, versioned protection envelopes, quorum recovery authorization, outcome-unknown reconciliation, and disable preflight. No concrete cipher/provider or E2EE claim is bundled. |
|
|
|
|
|
| Search without mandatory OpenSearch | PostgreSQL-backed, permission-aware search and module provider contracts exist; OpenSearch remains an optional adapter. |
|
|
|
|
|
| Scale-out and recovery architecture | Stateless API/worker, shared database/object storage, event delivery, deployment, and recovery contracts are documented and partly exercised. Production profiles and drills remain active work. |
|
|
|
|
|
|
|
|
|
@@ -83,8 +83,10 @@ were proven now have independent persistent owners:
|
|
|
|
|
| External providers | Core validates provider objects/field groups, operations, integration maturity, source authority, bounded reads, freshness/health, idempotency, conflicts, outcome-unknown handling, evidence, correction, reconciliation, outage, classification, purpose, retention, and secret handling. Addresses/CardDAV, Files remote storage, Mail SMTP/IMAP, Calendar CalDAV/ICS/Graph/EWS, and Connectors tabular/sanctions providers declare the contract and tenant-bounded secret-free runtime state. | Registry validation rejects any declared external provider without a sanitized state provider. Future adapters must cross the same gate before activation. |
|
|
|
|
|
| Institutional context | Core provides versioned temporal, actor/representation, institution/unit/function/task/mandate/jurisdiction/service/case/party/work-item/workflow/approval/decision/record, legal-basis, evidence, information-governance, external-source, presentation, and geographic references. Events, automation actions, audit records, and the transactional Audit outbox preserve the envelope. | Owning modules must progressively require the relevant subset for consequential operations. |
|
|
|
|
|
| Semantic provider contracts | Provider-neutral DTOs and protocols cover Mandate resolution, versioned Service definitions, procedure Parties/representation, and formal Decisions. `govoplan-mandates`, `govoplan-services`, `govoplan-parties`, and `govoplan-decisions` now persist immutable revisions behind those contracts with tenant isolation, bounded reads, replay safety, OCC, migrations, uninstall guards, permissions, APIs, capability documentation, and recovery documentation. | The owners are deliberately headless. Procedure-specific UI remains with consuming modules. |
|
|
|
|
|
| Formal-outcome proof | Committee persists bodies, meetings, agenda items, votes, minutes, lifecycle events, and an optional protected local Decision projection. It resolves effective Mandate authority and records reconstructable formal Decisions through `decisions.registry` when installed. OCC, replay safety, tenant isolation, bounded reads, closure guards, and a full-height body/meeting/agenda/vote/minutes WebUI cover the aggregate. Provider-bound external or secret ballots use dynamic adapter capabilities; Committee validates and retains only aggregate counts, receipt/hash, and evidence, and rejects generic manual closure. | Concrete ballot-provider packages remain integration work because their protocol, custody, credentials, and operator evidence depend on the selected provider. This does not leave a Committee-owned ballot contract unspecified. |
|
|
|
|
|
| Service-to-case proof | Services owns the persistent exact definitions consumed by Portal discovery and Cases intake. Forms owns immutable form schemas and Forms Runtime owns definition-aware drafts, validation, submission receipts, status/evidence history, and handoff references. Portal exposes a tenant-scoped service-directory WebUI whose audiences derive from trusted principal/function state, re-fetches the exact Service revision, and delegates URL, Case, Form, or Workflow launch to an installed owner. Cases and Forms Runtime retain exact Service and binding provenance, enforce tenant isolation, replay safety and OCC, and expose bounded owner/manager APIs and WebUI. | Anonymous intake, concrete attachment/signature adapters, conditional multi-page authoring, and automatic domain handoff execution are product depth on established contracts. Portal still fails closed and explains any absent launcher or runtime prerequisite. |
|
|
|
|
|
| Formal-outcome proof | Committee persists bodies, meetings, agenda items, minutes, lifecycle events, and an optional protected local Decision projection. Voting separately owns immutable ballot definitions, frozen electorates, recorded casting/replacement, deterministic tally, certification, challenge, annulment, and provider-backed assurance profiles. Committee consumes `voting.ballots` and retains only deliberation linkage and verified aggregate outcome. | Native recorded ballots are reconstructable, not secret. A concrete confidential/secret/certified provider and deployment assurance still require protocol/custody/legal decisions and target evidence. |
|
|
|
|
|
| Service-to-case proof | Services owns the persistent exact definitions consumed by Portal discovery and Cases intake. Forms owns immutable multi-page/conditional/localized schemas, accessibility assessment and package fragments. Forms Runtime owns definition-aware drafts, validation, submission receipts, status/evidence history, and durable native Case/Workflow handoffs with intent-before-effect and outcome-unknown reconciliation. Portal delegates URL, Case, Form, or Workflow launch to an installed owner while retaining exact Service/Form provenance. | Anonymous intake and concrete attachment/signature providers remain product depth. Portal and Runtime fail closed and explain any absent launcher, target capability, or provider prerequisite. |
|
|
|
|
|
| Generic approvals and process execution | Approvals persists exact-subject chains, delegation, separation of duties, quorum, signatures-as-evidence, escalation, OCC, and replay-safe decisions. Campaign proves an exact-version delivery gate. Workflow Engine owns immutable definitions/instances plus API, schedule, event and parent triggers, durable timer/event waits, scale-out claims, current-authority rechecks, and idempotent starts independently of the optional editor. | Policy-authored Approval template selection, concrete signature providers, cron adapters, and broader BPMN execution profiles are product/provider depth on explicit contracts. |
|
|
|
|
|
| Device trust and content protection | Identity Trust separates public device keys, epochs, assurance and key-access decisions from login and Access. Encryption separates resource ownership from opaque provider key custody, versioned envelopes, migration evidence, quorum recovery authorization and uninstall proof. Files/Postbox fixtures prove the optional boundary. | Concrete reviewed KMS/HSM/client providers, feature adapters, backup/restore/key-loss drills, and E2EE interoperability/certification remain required before a deployment protection claim. |
|
|
|
|
|
| Procedure-party proof | Parties persists effective procedure roles, frozen contact snapshots, and representation powers. Existing powers cannot disappear or be silently rewritten; explicit OCC-guarded revocation is required. Cases resolves the provider capability and excludes expired/revoked authority from downstream delivery. | Procedure modules still decide which contextual fields and actions to present. |
|
|
|
|
|
| Integrated institutional journey | The executable `product.service-to-decision` fixture uses real SQL-backed Services, Cases, Parties, Mandates, Committee, and Decisions providers. It carries one exact Service version through persisted Case intake, representation and frozen delivery authority, effective Mandate resolution, a body/meeting/agendum/vote/minute sequence, a persisted formal Decision, confirmed Postbox effect, Audit/record evidence, remedy/review, and protected reconstruction. A second executable path proves Portal to exact Form revision, persisted submission, and idempotent replay. | This is architecture and composition evidence. Signed, release-bound target accessibility, privacy, security, operator, delivery-provider, and recovery-drill evidence is still required before the package may claim `reference_ready`. |
|
|
|
|
|
| Governed data catalogue | Datasources stores typed governance metadata, exposes bounded tenant-scoped filters and update APIs/UI, carries governance through staging, and snapshots it into immutable materializations. Reporting now persists immutable dataset, semantic-model, report, quality-plan, saved-view, and schedule revisions; executes typed semantic queries with quality gates, access checks, replay, pivoting, export/import assessment, and provenance; and exposes the governed analytical WebUI. | Rich dependency/impact traversal, additional expression functions, and policy-specific field visibility can grow on the established contracts without moving connector, transformation, or source ownership. |
|
|
|
|
@@ -465,16 +467,22 @@ truthfully completed by adding generic platform code:
|
|
|
|
|
The pinned-release evidence run is tracked in
|
|
|
|
|
[GovOPlaN #37](https://git.add-ideas.de/GovOPlaN/govoplan/issues/37).
|
|
|
|
|
|
|
|
|
|
Forms and Forms Runtime no longer constitute an architecture gap. Remaining
|
|
|
|
|
depth includes anonymous/public identity profiles, concrete file and signature
|
|
|
|
|
providers, conditional multi-page/localized authoring, and automatic handoff
|
|
|
|
|
adapters. Those additions use the implemented immutable definition, runtime,
|
|
|
|
|
policy, evidence, service-launch, and domain-owner boundaries rather than
|
|
|
|
|
requiring another platform split. They are tracked as
|
|
|
|
|
[Forms #3](https://git.add-ideas.de/GovOPlaN/govoplan-forms/issues/3) and
|
|
|
|
|
Forms Runtime [#2](https://git.add-ideas.de/GovOPlaN/govoplan-forms-runtime/issues/2),
|
|
|
|
|
[#3](https://git.add-ideas.de/GovOPlaN/govoplan-forms-runtime/issues/3), and
|
|
|
|
|
[#4](https://git.add-ideas.de/GovOPlaN/govoplan-forms-runtime/issues/4).
|
|
|
|
|
Forms and Forms Runtime no longer constitute an architecture gap. Conditional
|
|
|
|
|
multi-page/localized authoring, package-fragment import, and durable native
|
|
|
|
|
Case/Workflow handoffs are implemented. Remaining depth is limited to
|
|
|
|
|
anonymous/public identity profiles, concrete file/signature providers, and
|
|
|
|
|
additional handoff target adapters. Those use the implemented immutable
|
|
|
|
|
definition, runtime, policy, evidence, service-launch, and domain-owner
|
|
|
|
|
boundaries rather than requiring another split. Public/provider decisions stay
|
|
|
|
|
tracked in Forms Runtime
|
|
|
|
|
[#2](https://git.add-ideas.de/GovOPlaN/govoplan-forms-runtime/issues/2) and
|
|
|
|
|
[#3](https://git.add-ideas.de/GovOPlaN/govoplan-forms-runtime/issues/3).
|
|
|
|
|
|
|
|
|
|
Approvals, Voting, Workflow trigger/wait dispatch, Identity Trust, and
|
|
|
|
|
Encryption now likewise have repository owners, neutral Core contracts,
|
|
|
|
|
persistence, migrations, recovery/disable semantics, documentation and focused
|
|
|
|
|
tests. Their remaining tickets concern concrete providers, deeper adapters and
|
|
|
|
|
target evidence, not an unresolved institutional architecture boundary.
|
|
|
|
|
|
|
|
|
|
Everything else described as architecture in this document now has a
|
|
|
|
|
repository owner, versioned contract, bounded implementation, migration and
|
|
|
|
@@ -515,7 +523,18 @@ Its implementation work packages and resulting owners are:
|
|
|
|
|
- [Forms #2](https://git.add-ideas.de/GovOPlaN/govoplan-forms/issues/2):
|
|
|
|
|
immutable reusable definitions and the designer surface; and
|
|
|
|
|
- [Forms Runtime #1](https://git.add-ideas.de/GovOPlaN/govoplan-forms-runtime/issues/1):
|
|
|
|
|
definition-aware submissions and Portal service launch.
|
|
|
|
|
definition-aware submissions and Portal service launch;
|
|
|
|
|
- [Forms #3](https://git.add-ideas.de/GovOPlaN/govoplan-forms/issues/3) and
|
|
|
|
|
[Forms Runtime #4](https://git.add-ideas.de/GovOPlaN/govoplan-forms-runtime/issues/4):
|
|
|
|
|
conditional/localized definition depth and governed native handoffs;
|
|
|
|
|
- [Approvals #1](https://git.add-ideas.de/GovOPlaN/govoplan-approvals/issues/1)
|
|
|
|
|
and [Campaign #22](https://git.add-ideas.de/GovOPlaN/govoplan-campaign/issues/22):
|
|
|
|
|
generic exact-subject approval chains and one consequential delivery gate;
|
|
|
|
|
- `govoplan-voting`: governed recorded ballots plus fail-closed provider-backed
|
|
|
|
|
assurance profiles consumed by Committee; and
|
|
|
|
|
- Identity Trust #1 and Encryption #1-#3: public device trust, provider-neutral
|
|
|
|
|
key/protection lifecycle, recovery authorization and disable proof, while
|
|
|
|
|
concrete provider conformance remains separately gated.
|
|
|
|
|
|
|
|
|
|
Existing Projects #1, Reporting #4, Portal #1, Cases #1, Datasources #1,
|
|
|
|
|
Risk Compliance #2, GovOPlaN #14, and GovOPlaN #19 carry product-depth and
|
|
|
|
|