Files
govoplan/docs/STRATEGIC_REVIEW_2026-08-05.md
T
zemion 3ca068f76a
Dependency Audit / dependency-audit (push) Failing after 1m47s
Deployment Installer / deployment-installer (push) Successful in 6s
Security Audit / security-audit (push) Successful in 11m18s
Developer Meta-package Release / publish-package (push) Successful in 11s
Release v0.1.16
2026-08-05 19:52:32 +02:00

5.8 KiB

Strategic Review - 2026-08-05

Assessment

GovOPlaN has not lost its central direction. The architecture now expresses a coherent institutional governance platform, but architecture and repository breadth have advanced faster than complete, usable outcomes. The immediate need is convergence: fewer simultaneous fronts, stronger cross-cutting adoption, and end-to-end reference journeys that non-developers can complete.

This is a dated review. Current status belongs in Strategy Status; stable direction belongs in Platform Core Ideas.

What Is Already Strong

  • A modular runtime with manifests, capabilities, interfaces, migrations, optional integrations, signed releases, and permutation checks.
  • Explicit institutional semantics for identity, representation, organization, function, mandate, service, case, party, approval, decision, evidence, and record references.
  • Governed communication foundations spanning Campaign, Mail, Files, Postbox, Addresses, Distribution Lists, Templates, Audit, and Policy.
  • Governed data foundations spanning Connectors, Datasources, Dataflow, Reporting, Search, and immutable provenance.
  • Bitemporal browsing, views, contextual documentation, action/effect contracts, event delivery, recovery ledgers, and stateless deployment contracts.
  • A credible deployment and release foundation with signed artifacts and reproducible composition evidence.

Where The Program Veered

Repository breadth preceded product proof

Logical modularity often became a repository before a reference journey proved that an independent release boundary was required. Scaffolds are useful as ownership markers, but their number makes the product appear broader and more complete than its supported outcomes.

Foundations outran reference gates

Later-stage contracts such as federation, encryption, formal governance, deployment evidence, and broad module metadata were developed while basic human-work and records journeys remained incomplete. Those foundations are not wasted; they now need to be consumed by a small number of demonstrable products.

The module graph leaked into the experience

Navigation, routes, administration, errors, documentation, and configuration often present module names and package structure directly. This is appropriate for operators, but ordinary users should see work, services, records, and outcomes.

Status became duplicated

Roadmaps, target architecture, fit assessments, issue comments, and release documents each contained partial implementation snapshots. Their stable decisions remain valuable, but volatile counts and maturity claims diverged.

Too much work remained active simultaneously

The issue portfolio had many high-priority and in-progress items without milestones. This reduces the signal of both labels and roadmap order and makes completion harder to demonstrate.

Where GovOPlaN Has Not Gone Far Enough

  1. No composition has yet crossed the full reference_ready gate.
  2. The human-work spine is incomplete: work queues, tasks, handoffs, deadlines, reminders, escalation, and resumption need a coherent user experience.
  3. Records and document management remain too shallow for a public-sector operating platform.
  4. Real target integrations and GovOPlaN-to-GovOPlaN federation are not yet proven.
  5. Temporal browsing, purpose-aware access, retention, and institutional context exist as contracts but are not adopted uniformly by domain reads and effects.
  6. German completeness, contextual help, accessibility, responsive behavior, and browser-level journey testing are not yet release gates everywhere.
  7. Multi-host, backup/restore, provider interoperability, and independent signed target evidence still require real environments and operators.

Important Omissions

  • a named first institution, bounded users, volumes, and operating constraints;
  • measurable usability outcomes, not only functional tests;
  • installable sector packages and migration/exit demonstrations;
  • support, upgrade, deprecation, and LTS promises;
  • complete assisted, paper, telephone, and in-person channel handling;
  • a native eAkte/records model that can also overlay an external DMS or archive.

Opportunities Beyond The Original Idea

  • an institutional digital twin that exposes responsibilities, dependencies, obligations, services, work, data, controls, and change impact over time;
  • continuous assurance that evaluates controls and evidence as work happens;
  • process mining and conformance analysis over governed event histories;
  • federated product packages and inter-institution case/evidence exchange;
  • accountable assistance that drafts and explains without obscuring authority;
  • public evidence chains that disclose decisions and provenance without exposing protected source data.
  1. Freeze new repositories unless a real journey proves an independent owner, release lifecycle, security boundary, or optional installation need.
  2. Use one generated maturity/status dashboard and one current status document.
  3. Complete governed communication and function-bound Postbox against a real target.
  4. Complete the monthly-data journey, then sanctions screening on the same data foundations.
  5. Complete one browser-driven service-to-decision journey, including assisted intake and records.
  6. Make eAkte/records the next major product-depth program.
  7. Tie feature work to a reference journey, a security/recovery gate, or a measured usability defect.

Success Criterion

The reset succeeds when a public institution can install a signed composition, configure a named procedure, complete it through digital and assisted channels, connect an external source, reconstruct the authority and evidence, recover it after failure, and transfer or retire it without custom code.