Files
govoplan/docs/strategy/STRATEGY_STATUS.md
T
zemion 69519a92b4
Dependency Audit / dependency-audit (push) Successful in 1m40s
Deployment Installer / deployment-installer (push) Successful in 6s
Security Audit / security-audit (push) Successful in 10m37s
feat: prove assisted resident permit intake
2026-08-19 02:45:53 +02:00

7.4 KiB

GovOPlaN Strategy Status

Status Record

Field Value
Reconciled on 2026-08-17
Source scope Local workspace manifests, source inventory, focused journey checks, signed release evidence, and live Gitea issue state
Stable direction Platform Core Ideas and Roadmap
Collected product input Product Input Register
Delivery source Gitea issues

This is the only prose source for current cross-product status. It is a reconciliation, not a release certification. Module manifests and target evidence remain authoritative for specific maturity claims.

Portfolio Snapshot

  • 67 source module manifests were loadable and architecture-declared.
  • 50 modules declared vertical_slice; 17 declared scaffold.
  • No module declared reference_ready, supported, or lts.
  • The coordinated package version was 0.1.18, with version alignment passing across all 78 release repositories.
  • The live portfolio had 137 open issues: 42 priority-P1, 92 priority-P2, and 3 priority-P3 items. Every open issue had labels.
  • 129 open issues had no milestone, so issue labels do not yet express a reliable completion sequence on their own.
  • Three product package manifests existed: governed communication, governed data and assurance, and service to decision. None had crossed the complete target-evidence gate.

These counts are dated. Refresh them rather than copying them into another document.

Interface And Contract Evidence

The 2026-08-17 source inventory found:

  • 1,344 UI fields and 1,331 UI actions;
  • 8,412 stable interface declarations with no duplicate IDs;
  • 43 frontend routes and 943 backend endpoints;
  • no public WebUI surfaces missing runtime declarations;
  • no stale runtime route declarations;
  • no unclassified endpoint without a static UI reference;
  • all 1,344 fields with a resolvable F1 context; 175 have statically specific help and 1,169 remain candidates for richer field-specific content beyond page/module fallback;
  • German (de) as the complete reference locale and no used key missing from the required German or English catalogs;
  • 3 module information-governance dimensions classified as enforced, 1 as partial, and 264 as contract_only. This is an honest platform-wide baseline, not a claim that temporal, purpose, retention, and institutional-context adoption is complete.

Credible Current Outcomes

Platform foundation

Module discovery, optional dependency validation, migrations, shared WebUI, tenant and access foundations, signed catalogs/packages, event delivery, recovery contracts, contextual help, views, temporal titlebar context, and stateless-runtime patterns are implemented and tested at varying depths.

Governed communication

Campaign authoring, recipient data, attachments, templates, mail profiles, mock/real delivery paths, audit evidence, reporting, distribution-list composition, and optional Postbox delivery form the deepest product cluster. Target provider, accessibility, recovery, and high-volume evidence still prevent a reference-ready claim.

Institutional service and decision

Services, Forms, Forms Runtime, Cases, Parties, Mandates, Approvals, Committee, Voting, Decisions, Portal, Postbox, and Audit have an executable service-to- decision fixture. Public and invitation intake can retain Files-backed evidence; Forms submissions, Cases, and formal Decisions can be explicitly filed as exact eAkte source revisions and reconstructed through permission- rechecked native Search projections. A durable Workflow Engine handoff now survives session restart and appears through the Tasks work inbox until the authoritative transition completes. Browser-complete assisted intake, broader work projections and escalation, production identity and delivery, a named archive profile, and target evidence remain.

Governed data and assurance

Connectors, Datasources, Dataflow, Reporting, Search, Policy, Risk Compliance, and Workflow provide source governance, immutable snapshots, transformation, quality, semantic reporting, and provenance foundations. The monthly-data and sanctions compositions now prove immutable connector snapshots, pinned Dataflow publication, Risk Compliance review, and rescreening in process. The journeys still need target connector profiles, complete interactive reconciliation, governed export/delivery, and browser-level handoff evidence.

Material Gaps

Gap Consequence Next proof
No reference-ready product package The platform cannot yet make a bounded supported-product claim Complete one named target composition and evidence bundle
Human-work spine is only an MVP Tasks aggregates explicit work plus Workflow, Approval, and unread Postbox projections, but broad domain coverage, deadline escalation, assignment lifecycle, and focused product UX remain Extend source providers through the three reference journeys and prove overdue/reassignment behavior in browser tests
Records/eAkte target integration incomplete Native lifecycle, retention, holds, approval, recovery, and transfer simulation are implemented, but real custody is not proved Target-test one archive/xdomea profile and browser-test the now server-enforced assisted reference journey
Cross-cutting governance adoption uneven Historical and purpose-sensitive behavior varies by module Enforced adoption declarations and route/query/effect migration
Explicit help/accessibility depth incomplete German/reference and F1 association gates now pass, but generic fallback remains too common High-risk German help content and browser/a11y matrix
Real federation absent Cross-institution exchange remains connector-specific Paired-instance signed exchange and reconciliation proof
External production evidence incomplete Scale, restore, interoperability and custody claims remain conditional Real target drills and independent signed evidence

Active Strategic Order

  1. Establish German, help, temporal, purpose, retention, and institutional context as enforceable platform quality contracts.
  2. Complete governed communication and Postbox against a named target.
  3. Complete the monthly-data flow and use it as the data foundation for sanctions screening.
  4. Complete the browser proof for the digital and assisted service-to-decision journey; server-side assisted resume, provenance, correction, and read-back enforcement now complement its existing exact eAkte filing contracts.
  5. Complete native PostgreSQL search coverage for remaining journey-owned objects and prove reauthorization and reindex operations at target volume; keep OpenSearch optional. Communication, Records, service-to-decision, Dataflow, Reporting, Risk Compliance, and Datasource catalogue sources now exist.
  6. Prove one external product connector and one GovOPlaN federation exchange.
  7. Finish multi-host, restore, provider, accessibility, and independent signed target evidence before increasing maturity claims.

Refresh Procedure

Refresh this page only from evidence:

  1. run tools/checks/check-manifest-shapes.py;
  2. run tools/inventory/platform-interface-inventory.py --strict --strict-declarations --strict-endpoints;
  3. run the selected reference-journey checks;
  4. inspect signed release and target evidence;
  5. query live Gitea issue/milestone state;
  6. update the dated values and material gaps here;
  7. retain prior assessments as dated evidence rather than rewriting them.