Decision Workshop Pack
| Atribut |
Nilai |
| Mode |
Server development; planning/read-only, tanpa perubahan application code |
| Workspace root |
/home/scola/odoo |
| Reconnaissance baseline |
scola-fe-v2/docs/recon, terakhir diverifikasi 2026-08-05 |
| Current-code verification |
2026-08-08 |
| Frontend HEAD |
0275f7061e6e892b1f860eeb825c6f6a21851888 |
| Backend HEAD |
44425cc81d8d281ec76e9336c30b3e109a7fc473 |
| Tata kelola yang dibaca |
scola-fe-v2/docs/ai-guidelines/AI_AGENT_MASTER_GUIDE.md, scola-fe-v2/docs/ai-guidelines/development-guide.md, scola-fe-v2/docs/ai-guidelines/workspace-governance.md, scola-fe-v2/docs/ai-guidelines/architecture-api.md, scola-fe-v2/docs/ai-guidelines/DOCUMENTATION_GOVERNANCE.md |
| Evidence product |
Seluruh file Markdown pada scola-fe-v2/docs/recon/, existing user guides, dokumentasi domain/modular relevan, current FE/BE HEAD |
Pack ini mengubah pertanyaan reconnaissance menjadi pilihan keputusan. Recommended default adalah proposal konservatif untuk workshop, bukan business rule yang ditemukan di kode. Setiap keputusan tetap Open — Requires business confirmation sampai owner mengisi outcome, effective date, dan approver. Fakta kode yang melatarbelakangi proposal diberi status tersendiri pada kolom Evidence/status. Severity dan acceptance gate terkait berada di scola-fe-v2/docs/documentation-planning/documentation-blockers.md.
Output yang harus dicatat dalam workshop
Untuk setiap ID, catat: Decision, Rationale, Owner, Approver, Effective date/version, Affected tenants, Implementation ticket, dan Verification evidence. Jawaban “sesuai sistem saat ini” tidak diterima bila current code memiliki blocker pada scola-fe-v2/docs/documentation-planning/documentation-blockers.md.
Prioritas sesi yang disarankan:
- Sesi Security/DPO: RP-01–RP-03, AM-01–AM-03, PR-01–PR-03.
- Sesi Product/School SME: SM-01–SM-03, PO-01–PO-03, SG-01–SG-03, MD-01–MD-03.
- Sesi Operations/Engineering: NT-01–NT-03, ER-01–ER-03, LD-01–LD-03, RB-01–RB-03.
- Sesi Documentation/Product: CH-01–CH-03 setelah keputusan di atas memiliki owner.
1. Supported modules
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| SM-01 |
Module dan workflow mana yang masuk supported surface v1 per tenant? |
Route/menu count tidak membuktikan module installed, licensed, seeded, atau didukung. Dokumentasi v1 memerlukan boundary yang dapat diuji. |
Seluruh application map; terutama attendance, identity, academics, finance, HR, communication. |
Hanya surface yang masuk bundle core, lulus runtime UAT pada baseline bernama, dan memiliki owner; lainnya Optional, Pilot, atau Requires product decision. |
(a) Semua route dianggap supported; (b) tier-based surface tanpa runtime proof; (c) tenant-specific catalog penuh. |
False product promise, artikel 403/404, dan support burden. |
Product Owner, disetujui Platform Operations. |
Recon menyatakan runtime belum diverifikasi: docs/recon/README.md:9-14, docs/recon/open-questions.md:77-81. Open; Requires business confirmation + runtime verification. |
| SM-02 |
Apa gate minimum agar optional/pilot module boleh mendapat user documentation? |
“Approved taxonomy” tidak sama dengan provisioned feature; pilot perlu exit criteria agar tidak berubah diam-diam menjadi core. |
Semua feature-flagged modules, laboratory, CBT/advanced analytics, integrations. |
Gate: module/flag aktif pada tenant uji, owner/SLA, role matrix, happy/error/recovery UAT, privacy review bila sensitif; artikel diberi availability/version metadata. |
(a) Document-on-demand tanpa gate; (b) preview docs dengan explicit beta banner; (c) hide seluruh optional docs. |
Pilot/placeholder dipersepsikan sebagai production-ready. |
Product Operations + module Product Owner. |
docs/domains/governance/README.md:98-102; docs/modular/product-tier-and-feature-flags.md:17-28,33-100,140-150. Open; recommended default is a governance proposal. |
| SM-03 |
Apakah W05 Daily Student Attendance disetujui sebagai pilot pertama dengan scope sempit? |
W05 sentral untuk sekolah, tetapi current code memiliki blocker ACL, roster, state, status, dan proof privacy. |
Guru/wali kelas record daily attendance; admin monitor/correct; student/parent view result. Excludes employee/RFID/face/geofence/pickup/advanced analytics. |
Setujui sebagai pilot bersyarat; penulisan final baru dimulai setelah BLK-A19–A23 ditutup dan runtime UAT selesai. |
(a) Pilih workflow lebih stabil; (b) pilot read-only monitoring dulu; (c) perluas sekaligus ke RFID/employee. |
Pilot mengajarkan defect atau mencampur lima domain berbeda. |
Attendance Product Owner + School SME + Security/DPO. |
scola-fe-v2/docs/documentation-planning/documentation-blockers.md BLK-A19–A23; docs/recon/workflow-candidates.md W05. Open; code risks Confirmed from code. |
2. Role and permission
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| RP-01 |
Apakah active role harus mempersempit capability backend, atau hanya mengubah persona/menu? |
Backend saat ini mempertahankan union groups setelah role switch; FE menampilkan active persona. Role guide tidak dapat menjanjikan least privilege tanpa keputusan ini. |
Semua akun multi-role dan seluruh protected APIs. |
Active role menjadi enforcement context; effective capability = capability role aktif ∩ assignment/company scope, dengan break-glass terpisah. |
(a) Union permission tetap dan UI menyatakan jelas; (b) akun terpisah per role; (c) role switch disabled untuk sensitive combinations. |
Confused deputy, segregation-of-duties failure, audit attribution salah. |
Security Owner, disetujui Product Owner. |
custom_addons_scola/gcgscola/scola_core/controllers/auth.py:485-517; custom_addons_scola/gcgscola/scola_core/services/auth_capabilities.py:713-771; scola-fe-v2/src/components/RoleSwitcher.vue:135-170. Open; current union behavior Confirmed from code. |
| RP-02 |
Apa taxonomy capability standar untuk read, create, edit, delete, approve, post, export, dan configure? |
Banyak controller/registry memakai capability berakhiran .view untuk mutation. Dokumentasi per role memerlukan action-level contract. |
Counseling, payroll, kesiswaan, accounting, BOS/RKAS, Dapodik, SPMB, settings, RFID. |
Capability per action dengan deny-by-default; view tidak pernah mengizinkan mutation; approval/post/configure terpisah dari edit. |
(a) view + model ACL seperti sekarang; (b) role allowlist lokal; (c) satu .manage untuk semua mutation. |
Viewer diajarkan atau dapat melakukan mutation; matrix tidak dapat diverifikasi. |
Security Owner + Platform Auth Owner. |
scola-fe-v2/docs/documentation-planning/documentation-blockers.md BLK-A03, A06–A13, A17 dan BLK-B07. Open; inconsistencies Confirmed from code. |
| RP-03 |
Apa scope record wajib untuk company, school level, class, assignment, child, dan self? |
Capability saja tidak menentukan objek yang boleh dilihat/diubah; beberapa elevated browse/foreign-key lookups tidak menunjukkan ownership check. |
Attendance, fees, calendar, messaging, counseling, Dapodik, finance, parent/student portals. |
Deny-by-default; setiap route punya capability + company + domain ownership/assignment; self/child routes tidak menerima arbitrary target di luar relasi. |
(a) allowed companies saja; (b) role-only scope; (c) centralized policy service per domain. |
Cross-tenant/sensitive-data exposure dan panduan role yang salah. |
Security Owner + DPO + domain owners. |
BLK-A06–A16, A20, A23; docs/recon/role-permission-matrix.md. Open; exact risk varies, some Inferred from code and require runtime tests. |
3. Process ownership
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| PO-01 |
Siapa owner pencatatan, completion, monitoring, dan correction W05? |
UI/backend berbeda untuk principal/VP; save langsung done; correction reason/window tidak ada. |
W05 Daily Student Attendance. |
Guru/wali kelas mencatat dan complete kelas yang ditugaskan; admin attendance mengoreksi dengan reason/audit; principal/VP read-only monitor. |
(a) Wali kelas saja; (b) faculty mata pelajaran juga; (c) principal/VP dapat correct; (d) correction hanya central admin. |
Pengguna saling menunggu atau unauthorized correction dianggap normal. |
School Attendance SME + Product Owner. |
BLK-A21 dan BLK-B04. Open; current transitions/UI drift Confirmed from code. |
| PO-02 |
Siapa data/process owner untuk setiap mutation berisiko tinggi? |
Kode tidak dapat menentukan apakah librarian boleh post invoice, counselor approve, operator sync, atau admin mengubah global config. |
Payroll, accounting, BOS/RKAS, library fines, Dapodik, complaint, counseling, settings. |
Satu accountable business owner per process; role operator, reviewer, approver, auditor dipisah; owner tertulis pada catalog/document front matter. |
(a) School admin owns all; (b) module engineer decides; (c) tenant-specific ownership tanpa global minimum. |
Approval ownership kosong, audit finding, dan dokumentasi mengarang kewenangan. |
Product Owner assigns HR/Finance/Operations/School SMEs. |
BLK-A04, A06–A11, A16–A17; BLK-B09. Open; Requires business confirmation. |
| PO-03 |
Siapa menangani failure, data correction, dan user escalation per workflow? |
Contextual help/troubleshooting perlu batas antara user-recoverable dan support-only action. |
Import, Dapodik, attendance, RFID, notifications, finance posting, promotion. |
Tetapkan L1 school operator, L2 domain owner, L3 engineering; setiap state error punya escalation condition, required evidence, SLA, dan prohibition. |
(a) Semua ke school admin; (b) central support only; (c) informal chat escalation. |
Users retry destructive actions, duplicate effects, atau memasukkan data manual tanpa audit. |
Operations Owner + Support Lead. |
docs/recon/open-questions.md exception/recovery questions; BLK-A05, A10–A11, A21 dan BLK-B03, B06–B09. Open. |
4. Approval matrix
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| AM-01 |
Aksi mana wajib maker-checker dan siapa yang boleh approve? |
Mutation keuangan, payroll, disiplin, counseling, promotion, dan procurement berdampak tinggi; current view/manage mapping tidak cukup. |
Payroll, accounting, BOS/RKAS, library invoice/fine, promotion, kesiswaan, counseling. |
Maker tidak approve/post record sendiri; named approver by amount/domain/company; override hanya break-glass audited. |
(a) Single operator; (b) threshold-based maker-checker; (c) central approver untuk semua tenant. |
Fraud/error tidak terdeteksi dan docs memberi kewenangan yang salah. |
Finance Controller + HR Owner + Academic/Student Affairs Owners + Security. |
BLK-A05–A10 dan BLK-B09. Open; Requires business confirmation. |
| AM-02 |
Apakah correction attendance memerlukan approval, dan kapan? |
Kode mengizinkan re-edit completed sheet tanpa reason/window/approval contract. |
W05 correction, downstream summaries and parent/student views. |
Same-day correction oleh assigned teacher dengan reason; setelah cutoff hanya attendance admin; perubahan status sensitif/late historical membutuhkan approver; semua audited. |
(a) Unlimited teacher correction; (b) all corrections admin-only; (c) no approval but immutable audit. |
Histori attendance berubah tanpa accountability atau operasi terlalu lambat. |
Attendance SME + Principal/Operations Owner. |
custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:3398-3422,4307-4334; scola-fe-v2/src/views/AttendanceManagement/Faculty/AttendanceSheet.vue:667-671,733-772. Open; existing lack of controls Confirmed from code. |
| AM-03 |
Bagaimana delegation, substitute approver, dan conflict-of-interest ditangani? |
School operations memerlukan pengganti saat approver tidak tersedia, tetapi union multi-role dapat melemahkan segregation. |
Weekly reports, promotion, finance, payroll, BOS/RKAS, attendance corrections. |
Time-bounded delegation, same tenant/domain, no self-approval, visible audit trail; active role narrows permissions. |
(a) Permanent multi-role union; (b) central admin override; (c) no delegation. |
Workflow macet atau override tanpa accountability. |
Product Owner + Security Owner + Operations. |
Role union BLK-A02; weekly approval current guard NB-01. Open; delegation is Missing or unclear. |
5. State glossary
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| SG-01 |
Apa glossary canonical untuk Draft, Submitted, Approved, Rejected, Published, Posted, Done, Cancelled, dan Archived? |
Label sama dapat berarti efek/reversibility berbeda antar module; user guide harus menjelaskan consequence, bukan sekadar tombol. |
Academics, news, attendance, finance, procurement, counseling, library. |
Domain glossary dengan canonical label, entry criteria, allowed actor, downstream effect, reversibility, and terminal flag; UI/API aliases mapped. |
(a) Global glossary satu arti; (b) istilah bebas per module; (c) tampilkan backend states mentah. |
Users menganggap action reversible atau selesai padahal belum/justru sudah final. |
Product Design + each domain Product Owner. |
docs/recon/open-questions.md state questions; BLK-A10, A21 dan BLK-B09, B11. Open; Requires business confirmation. |
| SG-02 |
Apakah Sakit, Izin, dan Dispensasi adalah status terpisah atau subtype/remark? |
FE dan backend saat ini collapse/representasi berbeda; summaries dan guide lama tidak konsisten. |
W05 input, daily/period summary, parent/student view, analytics. |
Canonical status model eksplisit dan round-trip; jika subtype, UI/guide menyebut Izin — Sakit dan aggregation contract menyimpan subtype. |
(a) Tiga status top-level; (b) semua excused = Izin + reason; (c) tenant-custom states. |
Statistik dan komunikasi orang tua salah tafsir. |
Attendance Product Owner + School SME + Analytics Owner. |
BLK-A22. Open; current collapse Confirmed from code. |
| SG-03 |
State/action mana irreversible dan apa recovery resminya? |
Promotion, posting invoice/journal, approval commitment, sync, dan publish dapat berdampak downstream; code presence of Cancel/Retry tidak membuktikan business permission. |
Promotion, payroll/accounting, BOS/RKAS, library fines, Dapodik, news. |
Mark irreversible actions with confirmation + impact summary; recovery via compensating action owned approver, never silent overwrite/delete. |
(a) Direct rollback; (b) superadmin database repair; (c) no recovery. |
Destructive retry atau guide memberi rollback yang tidak aman. |
Domain Owner + Compliance/Finance where relevant. |
BLK-A05, A09–A11; BLK-B09, B11. Open. |
6. Master-data ownership
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| MD-01 |
Siapa source of truth dan owner untuk student, parent, teacher, course, batch, roster, dan academic period? |
Attendance/import/fees/Dapodik bergantung master ini; partial/cross-company roster checks dan multiple sync paths ada. |
Identity Admin, academics, attendance, fees, report card, LMS, Dapodik. |
Scola master per tenant adalah operational source; Dapodik/import melakukan controlled upsert via stable external IDs; only named data steward resolves conflicts. |
(a) Dapodik always authoritative; (b) manual Scola authoritative; (c) field-by-field ownership. |
Duplicate identities, wrong roster, cross-tenant mutation, inconsistent reports. |
School Data Steward + Integration Product Owner. |
BLK-A11, A14, A20; docs/recon/page-relationships.md. Open; Requires business confirmation. |
| MD-02 |
Apa conflict, matching, dan deletion policy untuk import/sync? |
Current guides dapat menyederhanakan preview/sync; IDs seperti NISN/NUPTK/name membutuhkan tenant-aware matching dan recovery. |
Student import, Dapodik student/GTK/rombel, parent identity, LMS bulk data. |
Preview/diff mandatory; match on tenant + approved stable ID; ambiguous match stops; no hard delete via sync; idempotent rerun and exportable error report. |
(a) Last-write-wins; (b) name-based matching; (c) manual-only reconciliation. |
Wrong person/class overwritten dan mass correction sulit. |
Integration Owner + School Data Steward + DPO. |
BLK-A11 and BLK-B03. Open; unsafe lookup aspects Confirmed from code. |
| MD-03 |
Siapa boleh mengubah configuration masters dan kapan perubahan berlaku? |
SPMB, company, notification, library, fee, attendance status settings dapat mengubah banyak workflows. |
SPMB config, company/notification/library settings, fee structures, attendance glossary. |
Named module manager; effective-dated changes; referenced values cannot be deleted; change log and rollback; read separate from manage. |
(a) School admin unrestricted; (b) central-only config; (c) tenant-specific custom permission. |
Historical records berubah makna dan viewer menjadi config editor. |
Product Owner + domain Operations Owner + Security. |
BLK-A13, A17, A22; BLK-B10. Open. |
7. Notification behavior
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| NT-01 |
Transition mana menghasilkan notification, kepada siapa, dan melalui channel apa? |
Config menyediakan event toggles, tetapi existence/toggle tidak membuktikan delivery; news legacy/canonical juga dapat mengirim berbeda. |
Attendance, billing, report card, grade reminders, admissions, news/announcement. |
Event-to-recipient matrix approved; in-app is authoritative record, external channels best-effort; sensitive content minimized; each transition has dedupe key. |
(a) All enabled channels guaranteed; (b) external-only; (c) no automated notifications. |
Docs menjanjikan pesan yang tidak terkirim atau mengirim data sensitif berlebih. |
Communication Product Owner + DPO + Operations. |
custom_addons_scola/gcgscola/scola_portal/controllers/notification_config_api.py:8-57; BLK-B11. Open; available toggles Confirmed from code, delivery policy unclear. |
| NT-02 |
Apa arti sent, delivered, failed, dan read, serta apa retry/SLA-nya? |
User troubleshooting perlu membedakan application event dari provider delivery/read receipt. |
WhatsApp, Telegram, email, push/in-app, messaging read receipts. |
created, queued, provider_accepted, delivered (jika callback), failed, read terpisah; capped retry + dead-letter + operator visibility; no delivery guarantee without receipt. |
(a) Boolean sent only; (b) provider-specific terms; (c) synchronous send blocking transaction. |
Support salah menyatakan keberhasilan dan user mengulang action bisnis. |
Notification Engineering Owner + Operations. |
Existing notification APIs/analytics in custom_addons_scola/gcgscola/scola_portal/controllers/portal_api.py:580-778,1147-1297; scola-fe-v2/docs/user-guide/school-admin/komunikasi/kanal-notifikasi.md:8-20. Open; runtime provider behavior Requires verification. |
| NT-03 |
Apakah attendance completion/correction/cancellation harus memberi tahu parent/student? |
Parent visibility dan cancellation notice diajarkan/diimplikasikan, tetapi cancel parameter diabaikan dan correction policy belum ada. |
W05 attendance, daily arrival cancellation, parent/student result. |
Completion tersedia in-app setelah successful final state; material correction/cancellation creates auditable in-app notice; external delivery is optional/failure-visible. |
(a) No notice, pull-only view; (b) notify every save; (c) external guaranteed message. |
Orang tua melihat data lama atau menerima notification spam/false assurance. |
Attendance Product Owner + Communication Owner + School SME. |
BLK-A21, A23; BLK-B05–B06. Open; cancel mismatch Confirmed from code. |
8. Privacy and sensitive data
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| PR-01 |
Field sensitif apa yang boleh dilihat tiap actor dan untuk tujuan apa? |
Payroll, counseling, complaints, student discipline, attendance proof, and messages carry sensitive/personal data. |
Payroll, counseling, public complaint, kesiswaan, attendance, messaging. |
Purpose-based field matrix; least data in list responses; detail/download only to assigned actor; export separate permission; audit sensitive access. |
(a) Entire record to any module viewer; (b) school-admin universal access; (c) case-by-case undocumented. |
Privacy breach, overexposure, noncompliance, unsafe screenshots/help text. |
DPO + Security Owner + domain owners. |
BLK-A04, A06–A08, A15, A23. Open; exposed fields/guards partly Confirmed from code. |
| PR-02 |
Apa policy attachment/proof untuk type, size, viewer, retention, download, dan deletion? |
Several endpoints accept raw data/arbitrary IDs/model links; browser accept is not security validation. |
Attendance proof, complaint attachments, messaging attachments, BOS/RKAS attachments, core contextual files. |
Server allowlist + magic-byte scan + per-file/total size; opaque authorized download; no raw bytes in list payload; explicit retention/deletion and malware quarantine. |
(a) Browser validation only; (b) object storage public links; (c) disable uploads until policy ready. |
Malware/storage DoS and sensitive evidence disclosure. |
Security Owner + DPO + Platform Storage Owner. |
BLK-A04, A10, A12, A15, A23. Open; validation gaps Confirmed from code. |
| PR-03 |
Apa multi-tenant isolation baseline dan siapa boleh cross-company? |
Elevated controllers and unscoped lookups/browse appear in current code; allowed_company_ids alone may not validate target ownership. |
Fees, Dapodik, calendar, counseling, accounting, attendance, identity. |
Every target/foreign key must belong to active allowed company; cross-company only named foundation/platform roles with explicit capability and audit; negative tests mandatory. |
(a) Current company context only; (b) role-based global access; (c) separate database per tenant. |
Cross-school data leak/mutation. |
Security Owner + DPO + Platform Architect. |
BLK-A06, A09, A11, A14, A16, A20. Open; some impacts Inferred from code and require runtime verification. |
9. Exception and recovery
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| ER-01 |
Aksi mana harus idempotent dan apa key/retry contract-nya? |
Network timeout dapat mendorong user menekan ulang; BOS commitment dan mass mutations dapat berlipat, sedangkan LMS mulai memiliki idempotency handling. |
BOS/RKAS actions, imports, Dapodik, attendance saves, LMS assignments/submissions, notifications. |
Every externally retriable mutation has client idempotency key and one-effect contract; UI exposes safe retry only for known states. |
(a) Disable retry; (b) optimistic duplicate detection; (c) manual support cleanup. |
Duplicate financial/data effects atau user takut retry. |
Platform Architect + module engineering owners. |
BLK-A10–A11, A20–A21; NB-02. Open; duplicate risk Confirmed/Inferred per path. |
| ER-02 |
Apa recovery resmi setelah partial/incorrect import atau external sync? |
User needs actionable recovery, but destructive sync/async jobs require source snapshots and ownership. |
Dapodik, student import, identity data, fee enrollment. |
Transactional chunk/atomic item; downloadable diff/error; no silent partial success; rollback/compensating job by data steward; immutable import log. |
(a) Re-upload corrected file; (b) manual row edits; (c) database restore. |
Repeated sync worsens data and audit trail hilang. |
Integration Owner + Data Steward + Operations. |
BLK-A11, A14; BLK-B03. Open. |
| ER-03 |
Bagaimana attendance/RFID exception dipulihkan tanpa kehilangan audit? |
Faculty first-save may fail, regular save lacks roster invariant, completed sheets are freely edited, RFID errors need manual reset/retry. |
W05 Daily Student Attendance and future RFID related article. |
Atomic W05 save; explicit correction workflow; RFID dead-letter with idempotent authorized retry; never advise changing date or direct DB edit as workaround. |
(a) Admin overwrite; (b) unlimited teacher edit; (c) discard failed events. |
Missing/duplicate attendance and untraceable corrections. |
Attendance Owner + Operations + Security. |
BLK-A19–A21; BLK-B05, B07. Open; current gaps Confirmed from code. |
10. Legacy and deprecation
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| LD-01 |
Apakah scola.news satu-satunya writable publishing surface, dan kapan legacy announcement ditutup? |
Dua model/workflow aktif berpotensi memiliki audience/approval/notification berbeda. |
News, announcements, portal notification/read receipts. |
scola.news canonical; legacy write disabled, history migrated/read-only, route/menu removed on announced date. |
(a) Maintain both with explicit purposes; (b) merge later without date; (c) legacy canonical. |
Duplicate/conflicting communications dan dua set dokumentasi. |
Communications Product Owner + Platform Owner. |
BLK-B11; docs/user-guide/quick-start/publish-berita.md:9-24. Open; parallel implementations Confirmed from code. |
| LD-02 |
Apa disposition canonical untuk route aliases, duplicate pages, placeholders, dan /register? |
Recon found 119 aliases and incomplete routes; one component should not get duplicate articles. |
Navigation inventory, laboratory, registration, duplicate admin/persona pages. |
One canonical page ID/article; aliases redirect and carry deprecation date; placeholder/register hidden from supported navigation/search until completed. |
(a) Document each alias; (b) keep aliases indefinitely; (c) remove immediately. |
Duplicate/stale articles and users land on unsupported pages. |
Product Owner + FE Navigation Owner. |
docs/recon/route-inventory.md; docs/recon/open-questions.md:41-50. Open; inventory Confirmed from code snapshot, current count needs regeneration. |
| LD-03 |
Berapa lama deprecated behavior didukung dan bagaimana migration communicated? |
Documentation needs a rule for old bookmarks/API/workflows and versioned screenshots. |
News legacy, aliases, old import guide, old attendance guide, raw RPC/call_kw migrations. |
Minimum announced window; deprecation banner + replacement link + telemetry; no new content except migration; removal requires usage/tenant review. |
(a) Immediate removal; (b) indefinite compatibility; (c) tenant-specific dates. |
Silent breakage atau legacy becomes permanent supported contract. |
Product Operations + Platform Architect + Documentation Owner. |
Existing drift BLK-B03, B05, B11; architecture/API guidance. Open; policy Missing or unclear. |
11. Runtime baseline
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| RB-01 |
Environment mana menjadi documentation acceptance baseline? |
Static HEAD tidak membuktikan deployed module, database state, tenant flags, or served bundle. |
All v1 documentation. |
Satu named staging tenant/database dengan production-like module profile, seeded non-sensitive data, recorded FE/BE hashes, timezone/locale and feature flags. |
(a) Local source only; (b) production tenant; (c) multiple tier baselines. |
Steps/screenshots/API behavior tidak reproducible. |
Platform Operations + Product Owner. |
docs/recon/README.md:9-14; docs/recon/open-questions.md:77-81. Open; runtime baseline Missing. |
| RB-02 |
Representative account fixtures apa wajib untuk acceptance? |
Canonical role count/mapping and effective groups differ; multi-role union affects actual access. |
All role guides; W05 teacher/admin/principal/VP/student/parent. |
Fresh single-role account per supported role plus selected multi-role/conflict fixtures; explicit company/class/child assignments; no legacy extra groups. |
(a) Reuse admin accounts; (b) manually provision per test; (c) only API impersonation. |
False positives from superuser/legacy groups and incorrect role matrix. |
Identity/RBAC Owner + QA/Operations. |
BLK-A01, A02, A19; docs/recon/role-permission-matrix.md. Open. |
| RB-03 |
Bukti apa membuat satu workflow “documentation ready”? |
Definition of done must be stronger than component existence or happy path screenshot. |
Every candidate workflow. |
Trace route→component→service→API→controller/model; positive/negative role/company tests; seeded prerequisites; state/downstream verification; owner sign-off; blocker closure; served-bundle evidence. |
(a) Code review only; (b) SME walkthrough only; (c) screenshot checklist only. |
Unverifiable claims and recurring documentation drift. |
Documentation Lead + QA Lead + domain Product Owner. |
User-requested traceability requirements; BLK-A01 and governance docs. Open; recommended default is a planning proposal. |
12. Contextual-help delivery
| ID |
Concise question |
Why the decision is needed |
Affected modules/workflows |
Recommended default |
Alternative options |
Risk if left undecided |
Decision owner |
Evidence/status |
| CH-01 |
Bentuk contextual help apa dipakai untuk workflow, page, field, action, warning, dan troubleshooting? |
Satu tooltip tidak cukup untuk consequence/recovery; terlalu banyak modal mengganggu operasi harian. |
All documented supported pages; W05 pilot first. |
Layered: page intro + role-aware workflow link; inline field help only for ambiguous input; pre-action warning for irreversible effects; error code links to troubleshooting. |
(a) Tooltips only; (b) external guide only; (c) guided tour on every visit. |
Help tidak ditemukan atau menutupi risk penting. |
Product Design + Documentation Lead. |
docs/recon/open-questions.md contextual-help items and requested pilot artifacts. Open; delivery mechanism Missing or unclear. |
| CH-02 |
Kapan contextual help harus disembunyikan atau diganti limitation banner? |
Route presence/menu visibility does not prove support; blocked/legacy/pilot behavior must not be taught as normal. |
Feature-gated, legacy, placeholder, and all Blocker A surfaces. |
No procedural contextual help on Blocker A; show non-procedural unavailable/known-limitation notice only if approved. Pilot/optional help carries badge/version/tenant prerequisites. |
(a) Publish draft help with disclaimer; (b) hide page entirely; (c) generic help for all roles. |
Defect normalized as contract dan user mencoba unsafe action. |
Documentation Lead + Product Owner + Security for sensitive pages. |
BLK-A01–A23, BLK-B01–B02. Open; recommended default is conservative governance. |
| CH-03 |
Siapa memelihara help dan trigger apa mewajibkan revalidation? |
Menu, route, API, role, states, and guides already drifted between snapshot and HEAD. |
All contextual help/user guides. |
Front matter owner + last verified FE/BE hash + supported roles/tenant; route/API/capability/state changes trigger traceability check; quarterly owner review and stale-content banner. |
(a) Annual review; (b) edit on support complaint; (c) auto-generated only. |
Silent stale guidance and unsafe permission claims. |
Documentation Lead + module code owners. |
Delta 2026-08-05→2026-08-08; BLK-B02, B03, B05. Open; drift Confirmed from code/document comparison. |
Decision dependencies
| Upstream decision |
Blocks |
| SM-01, SM-02, RB-01 |
Scope/version metadata for every user-facing artifact. |
| RP-01–RP-03 |
Role quick guides, role-permission matrix, contextual role filtering. |
| PO-01, AM-02, SG-02, NT-03, PR-02, ER-03 |
W05 pilot final writing and acceptance test. |
| PO-02, AM-01, SG-03 |
Finance/HR/counseling/procurement operator documentation. |
| MD-01, MD-02, ER-02 |
Import/Dapodik documentation. |
| LD-01–LD-03 |
Canonical links, search indexing, redirects, and archival plan. |
| CH-01–CH-03 |
Contextual-help implementation backlog. |
Definition of a decided item
Sebuah row baru dianggap Decided bila:
- salah satu option dipilih atau option baru ditulis secara eksplisit;
- owner dan approver bernama, bukan hanya departemen abstrak;
- affected roles, tenants, states, dan effective date tercatat;
- implementation/validation ticket dibuat bila keputusan berbeda dari code;
- related Blocker A/B dihubungkan dan acceptance criteria tidak dilemahkan;
- runtime verification evidence ditautkan sebelum keputusan dipakai sebagai pernyataan dokumentasi.