Scola V1 Production Baseline — Approved Bounded Core Product Contract¶
Status: Approved by requesting-user conversation on 2026-08-10 for the bounded Core V1 recommendation. Klasifikasi tetap bukan sertifikasi production readiness; runtime and package gates remain authoritative.
Documentation-program amendment (2026-09-04): seluruh tenant saat ini masuk full-SKU pilot/hardening scope, dengan lifecycle berbeda sebagaimana ditetapkan di README. Ini tidak otomatis mengubah entitlement/runtime atau mensertifikasi katalog.
SC-NEWStidak digunakan;scola_newsadalah bagianSC-CORE. PemecahanSC-ATTEND+menjadi targetSC-RFID,SC-STUDENT-FACE, danSC-STAFF-ATTENDmasihFUTURE_PLANdi domain Kehadiran, sehingga barisSC-ATTEND+di bawah hanya merekam kontrak/bukti historis dan belum memerintahkan migrasi SKU.
| Metadata | Nilai |
|---|---|
| Last verified | 2026-08-10 UTC |
| T4 hybrid amendment | 2026-08-26 — W05-A per-lesson 16/16 PASS. 2026-08-29 DEC-001 extension: bounded Core V1 attendance = per-lesson + daily manual gate + pickup registry; student RFID/face/geofence deferred to V2 (SC-ATTEND+). Evidence: T4-DEC-006-007-attendance-v1-matrix.md. |
| Mode | Server development; static audit, application code read-only |
| Workspace | /home/scola/odoo |
| Frontend baseline | scola-fe-v2 develop @ 68b77d88f78b3d32f0ede3a54b665e067b014062 |
| Backend baseline | custom_addons_scola/gcgscola main @ 2ff6ac7cb41810bbc3b66821cdad004b52d1658a |
| Runtime limitation | Tidak ada tenant/database/module-state/entitlement/effective-role/served-build yang disertifikasi dalam audit ini |
| Required approval | Product, Commercial/package owner, Security, DPO bila sensitif, Operations, dan School SME |
| Quality gate | QG-01 Product contract dan QG-16 decision closure |
Delta FE 68b77d88 hanya menyentuh development/operations documentation; delta backend e749832 memindahkan beberapa elevation dari controller ke ACL/model service dan menambahkan company-aware import-job polling, sedangkan 2ff6ac7 menyelaraskan topology pins. Delta tersebut tidak mengubah inventaris source 36 app, 143 menu group, 528 leaf, 1.003 effective route records, 67 manifest addon, empat directory tanpa manifest, ataupun reconnaissance W01–W20; belum menjadi bukti runtime dan tidak menutup W05 regular-save, active-role, atau first-prefix resolver. W00 ditambahkan pada kontrak di bawah sebagai platform prerequisite yang dinormalisasi dari auth/session/navigation code, bukan workflow domain baru yang ditemukan dalam daftar recon. Bukti: ../custom_addons_scola/gcgscola/scola_core/models/student_import_job.py:67-96, ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:1407-1597, src/router/index.js:1-17, dan docs/documentation-planning/product-surface-candidates.md:420-430.
1. Contract rules¶
1.1 Status eksklusif¶
Setiap app, addon/directory, dan workflow di bawah memiliki tepat satu status.
| Status | Contract meaning |
|---|---|
| Core V1 | Diusulkan sebagai baseline SIS yang harus tersedia pada setiap tenant V1. Tetap belum release-ready sampai blocker dan seluruh gate lulus. |
| Optional Supported | Memiliki package owner/SKU yang dapat disertifikasi terpisah di atas Core V1. Tidak boleh muncul tanpa install state, entitlement, capability, dan package-specific acceptance evidence. |
| Controlled Pilot | Hanya untuk tenant/user allowlist bernama dengan owner, telemetry, rollback/kill switch, expiry/review date, dan pilot gate. Bukan general availability. |
| Legacy / Deprecated | Compatibility/duplicate surface yang tidak boleh menjadi entry kanonis. Pertahankan redirect hanya selama masa migrasi yang disetujui. |
| Internal Platform | Installer, bridge/glue, observability, atau provider control plane; bukan school-user product surface. |
| Incomplete / Remove from Product Surface | Stub, source non-installable, atau workflow yang tidak dapat selesai. Sembunyikan/hapus dari launcher dan search sampai benar-benar dibangun dan disertifikasi. |
| Requires Product Decision | Kode tidak membuktikan package, owner, audience, atau policy yang disetujui; engineering tidak boleh mengubahnya menjadi produk secara sepihak. |
Aturan support adalah approved package + installed addon + entitlement + role capability + record scope + tenant/company scope + domain ownership + passing runtime evidence. Route, menu, manifest, feature flag, atau user guide saja tidak memenuhi kontrak ini. Install, entitlement, dan UI access memang merupakan tiga lapisan berbeda (docs/modular/product-tier-and-feature-flags.md:19-31).
1.2 Proposed V1 boundary¶
- Core V1 dibatasi pada SC-CORE: identity/session/portal shell, student master/onboarding, academic master/timetable, manual student-attendance domain, dan canonical news/calendar/notification shell. SPMB, fees, report card, learning, assessment, library, finance, operations, student services, people/payroll, smart attendance, dan foundation adalah package terpisah (
docs/modular/product-tier-and-feature-flags.md:37-83;docs/modular/plan/package-catalog.yaml:126-314). - Bounded Core V1 attendance (W05): (A) per-lesson sheet per
op.sessionper hari sekolah (save≡done, 16/16 PASS); (B) daily manual arrival/departure (/attendance/daily, check-in/out, bulk checkout, cancel/adjust); (C) pickup persons registry (/attendance/pickup-persons). Matrix: T4-DEC-006-007-attendance-v1-matrix.md. - V2 / optional (bukan Core V1): student RFID, face recognition, geofence smart attendance — SC-ATTEND+ (
featureFlag: scola_smart_attendance); fail-closed for Core-only tenants. Employee attendance remains SC-ATTEND+/SC-PEOPLE. - Residual per-lesson proof/privacy items closed bounded per T4 audit; daily cancel notification uses optional
notify_parent(default off, STAB-029). - SC-DAP dan SC-BOS tetap Controlled Pilot, sesuai katalog controlled public-sector; SC-BOS memerlukan SC-FIN + SC-OPS (
docs/modular/plan/package-catalog.yaml:315-364). - App/surface campuran hanya mewarisi status shell untuk kontainer. Setiap leaf tetap mengikuti package owner-nya; optional/pilot/legacy/undecided leaf harus hilang ketika tidak in-scope.
- Product boundary approval is recorded for the bounded Core V1 recommendation. Individual package/workflow rows remain Proposed / Requires approval until their applicable quality gates pass; no row is
GREENmerely because DEC-001 is approved. Jenjang and timezone profiles are still undecided: frontend distinguishespaud/tkfromsd/smp/sma/smk/slb/pkbm, and backend offers WIB/WITA/WIT (src/config/schoolJenjang.js:5-13;src/config/apps/appFragments/teacherPortalApp.js:129-177;../custom_addons_scola/gcgscola/scola_core/models/res_company.py:21-61). Until DEC-013 is closed, a manifest may claim only profiles with a Golden fixture and passing matrix; code choices are not evidence that every combination is supported.
1.3 Blocker and attendance-decision evidence index¶
ID singkat dalam tabel kontrak bukan bukti mandiri. Registry berikut adalah target evidence kanonisnya; finding lengkap tetap dibaca pada baris yang dirujuk.
| ID | Canonical repository evidence |
|---|---|
BLK-A01 |
docs/documentation-planning/documentation-blockers.md:80-90 |
BLK-A02 |
docs/documentation-planning/documentation-blockers.md:92-102 |
BLK-A03 |
docs/documentation-planning/documentation-blockers.md:104-114 |
BLK-A04 |
docs/documentation-planning/documentation-blockers.md:116-126 |
BLK-A05 |
docs/documentation-planning/documentation-blockers.md:128-138 |
BLK-A06 |
docs/documentation-planning/documentation-blockers.md:140-150 |
BLK-A07 |
docs/documentation-planning/documentation-blockers.md:152-162 |
BLK-A08 |
docs/documentation-planning/documentation-blockers.md:164-174 |
BLK-A09 |
docs/documentation-planning/documentation-blockers.md:176-186 |
BLK-A10 |
docs/documentation-planning/documentation-blockers.md:188-198 |
BLK-A11 |
docs/documentation-planning/documentation-blockers.md:200-210 |
BLK-A12 |
docs/documentation-planning/documentation-blockers.md:212-222 |
BLK-A13 |
docs/documentation-planning/documentation-blockers.md:224-234 |
BLK-A14 |
docs/documentation-planning/documentation-blockers.md:236-246 |
BLK-A15 |
docs/documentation-planning/documentation-blockers.md:248-258 |
BLK-A16 |
docs/documentation-planning/documentation-blockers.md:260-270 |
BLK-A17 |
docs/documentation-planning/documentation-blockers.md:272-282 |
BLK-A18 |
docs/documentation-planning/documentation-blockers.md:284-294 |
BLK-A19 |
docs/documentation-planning/documentation-blockers.md:296-306 |
BLK-A20 |
docs/documentation-planning/documentation-blockers.md:308-318 |
BLK-A21 |
docs/documentation-planning/documentation-blockers.md:320-330 |
BLK-A22 |
docs/documentation-planning/documentation-blockers.md:332-342 |
BLK-A23 |
docs/documentation-planning/documentation-blockers.md:344-354 |
BLK-B01 |
docs/documentation-planning/documentation-blockers.md:358-368 |
BLK-B02 |
docs/documentation-planning/documentation-blockers.md:370-380 |
BLK-B03 |
docs/documentation-planning/documentation-blockers.md:382-392 |
BLK-B04 |
docs/documentation-planning/documentation-blockers.md:394-404 |
BLK-B05 |
docs/documentation-planning/documentation-blockers.md:406-416 |
BLK-B06 |
docs/documentation-planning/documentation-blockers.md:418-428 |
BLK-B07 |
docs/documentation-planning/documentation-blockers.md:430-440 |
BLK-B08 |
docs/documentation-planning/documentation-blockers.md:442-452 |
BLK-B09 |
docs/documentation-planning/documentation-blockers.md:454-464 |
BLK-B10 |
docs/documentation-planning/documentation-blockers.md:466-476 |
BLK-B11 |
docs/documentation-planning/documentation-blockers.md:478-488 |
ATT-D01–ATT-D17 |
docs/documentation-planning/pilot-attendance-plan.md:320-343 |
2. Supported package contracts¶
Owner di kolom berikut adalah accountable function yang diusulkan, bukan person yang sudah ditunjuk. Product harus mencatat nama owner/approver, effective version, tenant scope, dan acceptance run sebelum mengesahkan kontrak.
| Module ID / commercial owner | Status | Intended roles (proposed; approval required) | Canonical shell, menu, and routes | Required backend addons | Dependencies | Proposed workflow owner | Maturity and open blockers |
|---|---|---|---|---|---|---|---|
SC-CORE — Scola Core |
Core V1 | school_admin, head_admin/admin_staff only after role closure; teacher, homeroom, student, parent; approved leadership read roles |
Shells admin-dashboard, teacher-portal, student-portal, parent-portal, academic, student-affairs, attendance, communication, settings. Canonical entries: /admin/dashboard, /faculty/dashboard, /student/dashboard, /parent/dashboard, /academic-year, /schedule, /students, /attendance/home, /news, /calendar, /settings/company, /admin/users. Optional leaves are separate apps/groups, not Core. |
Direct bundle: scola_core, scola_parent, scola_portal, scola_news, scola_lesson_hours, scola_timetable, scola_attendance; installer scola_bundle_core. Static dependency/auto-install closure also includes scola_platform_support, scola_identity_admin, scola_observability, scola_leadership_hub, and scola_platform when their manifest dependencies are satisfied (../custom_addons_scola/gcgscola/scola_core/__manifest__.py:23-32; ../custom_addons_scola/gcgscola/scola_identity_admin/__manifest__.py:10-17; ../custom_addons_scola/gcgscola/scola_observability/__manifest__.py:10-16; ../custom_addons_scola/gcgscola/scola_leadership_hub/__manifest__.py:10-17; ../custom_addons_scola/gcgscola/scola_platform/__manifest__.py:10-20). |
Odoo/OpenEduCat base models plus approved academic/student master. Auto-installed scola_leadership_hub remains Requires Product Decision and must not expose leadership UI by installation alone; scola_platform_support, scola_observability, and scola_platform remain internal/non-user-facing. No optional SKU may become a hidden prerequisite. |
Core Product Owner + School Operations/Curriculum SME | Blocked, not certified. Global BLK-A01–A03; student import BLK-B03; communication/settings BLK-A12, A15–A17; W05 BLK-A19–A23, B04–B06. Package membership: docs/modular/plan/package-catalog.yaml:126-143; manifest: ../custom_addons_scola/gcgscola/scola_bundle_core/__manifest__.py:1-21. |
SC-ADM — Admissions / SPMB |
Optional Supported | school_admin, approved head_admin/admin_staff, admissions committee roles represented by approved VP/leadership scope; pendaftar on standalone public/auth flow |
App admissions; admissions.pipeline, admissions.config; /admin/spmb/dashboard and canonical child routes. Pendaftar remains standalone, not an empty launcher. |
scola_admission; installer scola_bundle_admission; optional scola_admission_assessment, scola_admission_foundation, scola_admission_fees_bridge only with their peer SKU |
SC-CORE; SC-ASSESS/SC-FEES/SC-FOUND only for explicitly sold overlays |
Admissions Product Owner + School Admissions SME | Catalogued, not certified. BLK-A13, BLK-B01, BLK-B02; state/enrollment ownership decisions remain open. docs/modular/plan/package-catalog.yaml:145-158; src/config/apps/appFragments/admissionsApp.js:13-142. |
SC-FEES — Student Billing |
Optional Supported | school_admin, treasurer, approved head_admin/admin_staff/vice_principal_finance; student/parent self-scope read/pay roles |
finance.spp and portal finance leaves; /payment/schedule, enrollment/billing/payment routes, /parent/payment-list. Do not expose accounting/BOS as part of SC-FEES. |
scola_fees; installer scola_bundle_fees; parent/portal/admission bridges only when dependency modules coexist |
SC-CORE; optional SC-ADM bridge |
Finance/Billing Product Owner + School Treasurer SME | Blocked for broad release. BLK-A14, BLK-A17, BLK-B01, role/package drift. docs/modular/plan/package-catalog.yaml:159-172; src/config/apps/appFragments/financeApp.js:61-139. |
SC-REPORT — Report Card / E-Rapor |
Optional Supported | school_admin, curriculum owner, teacher/homeroom, approved principal/VP reviewers, student/parent self-scope readers |
academic.assessment, academic.report_card, teacher/student/parent report-card leaves; canonical admin and faculty report-card route families. Promotion is excluded until repaired. |
scola_report_card; installer scola_bundle_report_card |
SC-CORE; optional SC-LEARN grade source and SC-DAP bridge only by explicit integration contract |
Academic Assessment Product Owner + Curriculum SME | Blocked in part. BLK-A05 makes W08 incomplete; W07 source-of-truth, lock, approval, and runtime propagation require decision/test. docs/modular/plan/package-catalog.yaml:173-186; docs/documentation-planning/documentation-blockers.md:128-138. |
SC-LEARN — Learning Suite |
Optional Supported | school_admin learning admin, teacher, student, parent/homeroom read roles only when assignment relationship is enforced |
Teacher/student LMS leaves and academic.lms; canonical /faculty/lms*, /student/lms*, and admin LMS hub routes. |
scola_lms; installer scola_bundle_learning |
SC-CORE; assessment bridge topology must be decided before claiming assessment ownership |
Learning Product Owner + Teaching/Learning SME | Not certified. Assignment idempotency has static guard (NB-02) but package E2E, assignment scope, W07 integration, and assessment-owner decision remain. docs/modular/plan/package-catalog.yaml:187-198; ../custom_addons_scola/gcgscola/scola_bundle_learning/__manifest__.py:1-18. |
SC-ASSESS — Assessment Suite |
Optional Supported | assessment admin, question author/teacher, proctor, assigned student; parent only if approved read result exists | CBT leaves in teacher/student/admin and admissions overlay; canonical /admin/cbt*, faculty question/proctor routes, and student runner routes. Legacy OpenEduCat exam pages are outside this contract until consolidated. |
scola_cbt; installer scola_bundle_assessment; scola_admission_assessment only with SC-ADM |
SC-CORE; SC-ADM only for admissions assessment overlay |
Assessment Product Owner + Exam SME | Not certified. W04 late/reopen/retry/submission/result propagation and scola_assessment_bridge ownership remain open. docs/modular/plan/package-catalog.yaml:199-210; ../custom_addons_scola/gcgscola/scola_bundle_assessment/__manifest__.py:1-18. |
SC-LIB — Library |
Optional Supported | librarian operator; school_admin configuration only if approved; teacher/student/parent/principal self/read scope |
librarian and library shells share one domain contract; canonical management family /library/*, role-prefix mirrors only where guard/context differs; self-service /library/home. |
scola_library; installer scola_bundle_library |
SC-CORE; finance integration is not implied |
Library Product Owner + Librarian SME | Blocked for full lifecycle. BLK-B08 queue concurrency, B09 fine/invoice ownership, B10 settings view/manage; duplicate routes require IA consolidation. docs/modular/plan/package-catalog.yaml:211-222; docs/documentation-planning/documentation-blockers.md:442-476. |
SC-FIN — Finance Plus |
Optional Supported | treasurer, school_admin; approved finance VP/principal read/approve roles; no generic employee access |
finance app excluding SPP-only and BOS-only boundaries; /accounting/* plus approved finance reports/configuration. |
scola_account; installer scola_bundle_finance |
SC-CORE; optional SC-OPS valuation bridge and SC-BOS depend on explicit combined install |
Finance Controller/Product Owner + Accounting SME | Release-blocked. BLK-A03, BLK-A09; separation of view/create/edit/post/reconcile/approve and company scope unresolved. docs/modular/plan/package-catalog.yaml:223-236; docs/documentation-planning/documentation-blockers.md:176-186. |
SC-OPS — Operations and Inventory |
Optional Supported | inventory_officer, school_admin; approved VP infrastructure reviewer/approver |
inventory app excluding BOS group unless pilot enabled; /inventory/dashboard, master, operations, procurement, assets, reports. |
scola_inventory; installer scola_bundle_operations; inventory-account integration only after canonical owner decision |
SC-CORE; SC-FIN optional; SC-BOS requires both |
Operations Product Owner + Facilities/Inventory SME | Not certified. procurement ownership, stock-opname freeze/posting/recovery, 27 modeled VP-infrastructure denials, and inventory-account owner conflict remain. docs/modular/plan/package-catalog.yaml:237-250; docs/recon/role-permission-matrix.md:983-1020. |
SC-STUDENT — Student Services |
Optional Supported | counselor, approved student-affairs/homeroom roles; student/parent self-scope; leadership only explicit read/approval |
counselor, student-affairs.pembinaan, teacher/student/parent student-life leaves; canonical counseling/kesiswaan route families. |
scola_counseling, scola_student_activity, scola_rules; installer scola_bundle_student_services |
SC-CORE; dated assignment/child/self scope |
Student Services Product Owner + Counseling/Student Affairs SME + DPO | Release-blocked. BLK-A06, BLK-A08; sensitive-case, approval, points, attendance effects, and retention decisions open. docs/modular/plan/package-catalog.yaml:251-265; docs/documentation-planning/documentation-blockers.md:140-150,164-174. |
SC-PEOPLE — People and Payroll |
Optional Supported | school_admin HR, foundation_hr_admin where sold; employee self-service for assigned staff roles; payroll reviewer/approver/auditor must be distinct |
hr, foundation-hr-ops, and *.hr_personal sections; /teachers, /hr/employee, contract/leave/payroll/self-payslip route families. Employee attendance is not in this SKU. |
scola_hr, scola_payroll; installer scola_bundle_people |
SC-CORE; SC-FOUND only for foundation overlay |
People/Payroll Product Owner + HR/Payroll SME + DPO | Release-blocked. BLK-A07, multi-role scope, salary privacy, maker-checker, and self-versus-operator separation. docs/modular/plan/package-catalog.yaml:266-283; docs/documentation-planning/documentation-blockers.md:152-162. |
SC-ATTEND+ — Smart Attendance |
Optional Supported | attendance/HR operators, enrolled employees/students, explicitly provisioned device operators; no biometric access by role alone | attendance.rfid, attendance.face.students, HR attendance/self-attendance routes. Do not merge with W05 manual workflow or pickup. |
Intended commercial composition includes scola_smart_attendance and scola_hr_attendance, but current installers are split: scola_bundle_smart_attendance (student smart/RFID) and scola_bundle_hr_attendance (employee attendance) |
SC-CORE; Product must approve one composite SC-ATTEND+ contract or split the SKU; devices/GPS/face infrastructure and privacy basis remain required |
Smart Attendance Product Owner + HR/Attendance SME + Security/DPO | Not certified. STAB-024, BLK-B06, BLK-B07; installer/SKU composition, device/card manage authority, failed-event retry, correction, biometric retention/consent, and field-device readiness. docs/modular/plan/package-catalog.yaml:284-300; ../custom_addons_scola/gcgscola/scola_bundle_smart_attendance/__manifest__.py:10-14; ../custom_addons_scola/gcgscola/scola_bundle_hr_attendance/__manifest__.py:10-14. |
SC-FOUND — Foundation Analytics |
Optional Supported | foundation_chairman, foundation_auditor, foundation_hr_admin only for separately entitled HR operations; generic foundation role requires closure |
foundation, foundation-auditor, foundation-hr-ops only for sold peer packages; canonical /foundation/*. |
scola_foundation_analytics; enterprise/profile installers and scola_admission_foundation only by sold composition |
SC-CORE + SC-FIN per package note; peer SKUs for HR/admission/attendance features |
Foundation Product Owner + Foundation Governance SME | Not certified. generic-role catalog drift, company/foundation scope, contract verification, and mixed-package shell. docs/modular/plan/package-catalog.yaml:301-314; src/config/apps/roleApps.js:589-679; ../custom_addons_scola/gcgscola/scola_core/services/role_catalog.py:7-40. |
SC-DAP — Dapodik Sync |
Controlled Pilot | dapodik_operator; approved school admin oversight; no other role may execute sync |
dapodik-operator and strictly flagged Dapodik leaves; /dapodik/dashboard, /settings/dapodik, report-card sync only when companion installed. |
scola_dapodik_connector plus academic/report-card/attendance bridges and bundle variants listed by sold composition |
SC-CORE; attendance companion also requires SC-ATTEND+ |
Dapodik Product Owner + School Operator SME + Operations | Pilot blocked. BLK-A11; configure/preview/execute/destructive scopes, tenant matching, conflict/rollback, and Golden Tenant replay required. docs/modular/plan/package-catalog.yaml:315-342. |
SC-BOS — BOS / RKAS |
Controlled Pilot | bos_admin, approved finance/inventory operators and read-only leadership; approver chain must be explicit |
bos-admin plus inventory.budget/approved finance procurement leaves; /bos/dashboard, budget/report/ledger and canonical procurement routes. |
scola_bos_rkas, scola_bos_rkas_procurement, scola_bos_rkas_executive_bridge, scola_account, scola_inventory; installer scola_bundle_bos_rkas |
SC-FIN + SC-OPS |
BOS/RKAS Product Owner + School Finance/Procurement SME | Pilot blocked. BLK-A10; approval idempotency, attachment ownership, commitment, maker-checker, and legacy governance bridge decision. docs/modular/plan/package-catalog.yaml:343-364. |
3. Frontend application catalog — 36/36¶
Status shell tidak mengangkat status semua child menu. Mixed shell hanya dapat menjadi supported container bila optional/pilot/legacy/undecided leaves fail-closed.
| Application shell | Proposed status | Package owner / definitive boundary | Evidence and open gate |
|---|---|---|---|
admin-dashboard |
Core V1 | SC-CORE school operations home; personal HR leaves remain SC-PEOPLE/ATTEND+ | src/config/apps/appFragments/adminDashboardApp.js:16-75 |
teacher-portal |
Core V1 | SC-CORE teacher/homeroom shell; learning, assessment, report, library, student-services, people leaves remain optional | src/config/apps/appFragments/teacherPortalApp.js:47-578; canonical-home drift is tracked in IA |
student-portal |
Core V1 | SC-CORE student shell; billing/report/learning/assessment/student-services/library leaves remain optional | src/config/apps/appFragments/studentPortalApp.js:34-338 |
parent-portal |
Core V1 | SC-CORE parent/child shell; finance/report/learning/student-services/library are optional; legacy announcement excluded | src/config/apps/appFragments/parentPortalApp.js:31-363 |
principal-exec |
Requires Product Decision | No approved leadership SKU; mixes core, approvals, finance, admissions, complaint, analytics, library, people | src/config/apps/appFragments/principalApp.js:28-469; docs/recon/open-questions.md:35-42 |
counselor |
Optional Supported | SC-STUDENT; sensitive data remains blocked until least privilege and DPO policy close | src/config/apps/appFragments/counselorApp.js:32-304; BLK-A06 |
extracurricular-coach |
Optional Supported | SC-STUDENT specialist portal; duplicate leaf and invalid role home must be fixed | src/config/apps/appFragments/extracurricularCoachApp.js:4-40; src/config/apps/roleApps.js:191-203 |
librarian |
Optional Supported | SC-LIB operator portal | src/config/apps/appFragments/librarianApp.js:28-331 |
lab-technician |
Incomplete / Remove from Product Surface | Six child pages and dashboard family are placeholder/stub; HR utility does not make the shell supported | docs/recon/open-questions.md:44-54; src/views/Laboran/Inventory/LabInventoryList.vue:1-12 |
security-officer |
Requires Product Decision | No SKU/package owner; visitor/security scope not approved | src/config/apps/appFragments/securityOfficerApp.js:4-40; package absence docs/modular/plan/package-catalog.yaml:126-364 |
school-committee |
Requires Product Decision | No SKU/package owner; aggregate/news audience contract not approved | src/config/apps/appFragments/schoolCommitteeApp.js:4-40 |
bos-admin |
Controlled Pilot | SC-BOS controlled public-sector role portal | src/config/apps/appFragments/bosAdminApp.js:4-61; docs/modular/plan/package-catalog.yaml:343-364 |
dapodik-operator |
Controlled Pilot | SC-DAP controlled public-sector role portal | src/config/apps/appFragments/dapodikOperatorApp.js:4-55; docs/modular/plan/package-catalog.yaml:315-342 |
dpo |
Requires Product Decision | Compliance role exists but no product/SKU, purpose, retention, or audit-data contract | src/config/apps/appFragments/dpoApp.js:5-52; docs/recon/open-questions.md:62,68 |
foundation-auditor |
Optional Supported | SC-FOUND read-only governance candidate; tenant scope requires runtime proof | src/config/apps/appFragments/foundationAuditorApp.js:4-65 |
pickup-officer |
Core V1 | SC-CORE operator role for manual transport execution (/pickup/attendance); pickup registry admin remains attendance app |
src/config/apps/appFragments/pickupOfficerApp.js:4-31; T4-DEC-006-007-attendance-v1-matrix.md |
admin-staff |
Requires Product Decision | Synthetic mixed core/SC-ADM/SC-FEES/SC-ASSESS/people shell without package owner | src/config/apps/appFragments/adminStaffApp.js:25-243 |
foundation |
Optional Supported | SC-FOUND container; peer finance/people/admission/attendance leaves require their own SKU | src/config/apps/appFragments/foundationApp.js:30-250 |
foundation-hr-ops |
Optional Supported | SC-PEOPLE + foundation operations; SC-ATTEND+ leaves separately entitled | src/config/apps/appFragments/foundationHrOperationsApp.js:26-254 |
vp-curriculum |
Requires Product Decision | Mixed Core/SC-LEARN/SC-REPORT/promotion shell; leadership package and approval role absent | src/config/apps/appFragments/vicePrincipalApps.js:72-211 |
vp-student-affairs |
Requires Product Decision | Mixed Core/SC-STUDENT/SC-ADM shell | src/config/apps/appFragments/vicePrincipalApps.js:225-398 |
vp-infrastructure |
Requires Product Decision | Mixed SC-OPS/SC-BOS/SC-PEOPLE shell and high menu-route denial count | src/config/apps/appFragments/vicePrincipalApps.js:409-508; docs/recon/role-permission-matrix.md:983-1020 |
vp-public-relations |
Requires Product Decision | Mixed core news/calendar and SC-ADM; no root product gate | src/config/apps/appFragments/vicePrincipalApps.js:525-602 |
vp-finance |
Requires Product Decision | Mixed SC-FEES/SC-FIN/SC-PEOPLE; no canonical role/package boundary | src/config/apps/appFragments/vicePrincipalApps.js:616-686 |
academic |
Core V1 | Core academic master/timetable shell; assessment/report/LMS/exam/CBT/Dapodik sections remain separate | src/config/apps/appFragments/academicApp.js:35-377 |
student-affairs |
Core V1 | Core student/parent master only; pembinaan is SC-STUDENT | src/config/apps/appFragments/studentAffairsApp.js:23-146 |
hr |
Optional Supported | SC-PEOPLE and SC-ATTEND+ | src/config/apps/appFragments/hrApp.js:19-186 |
finance |
Optional Supported | SC-FEES/SC-FIN container; BOS, operations valuation, and people leaves separately owned | src/config/apps/appFragments/financeApp.js:37-452 |
inventory |
Optional Supported | SC-OPS; BOS group remains Controlled Pilot and HR utilities remain optional peer package | src/config/apps/appFragments/inventoryApp.js:35-351 |
library |
Optional Supported | SC-LIB shared management/self-service app | src/config/apps/appFragments/libraryApp.js:28-253 |
admissions |
Optional Supported | SC-ADM | src/config/apps/appFragments/admissionsApp.js:13-142 |
attendance |
Core V1 | Core manual-attendance hub: per-lesson (W05-A), daily gate (W05-B), pickup registry; RFID/face sections are SC-ATTEND+ (V2 optional) | src/config/apps/appFragments/attendanceApp.js:22-142; T4-DEC-006-007-attendance-v1-matrix.md |
analytics |
Legacy / Deprecated | Source calls it legacy leadership shortcuts; redirects compete with domain/leadership/platform destinations. Remove from supported role registries after migration. | src/config/apps/appFragments/analyticsApp.js:1-59; src/router/analyticsAdminRoutes.js:1-49 |
communication |
Core V1 | Canonical news/calendar/notification shell only; messaging and complaints require decisions, announcement is legacy | src/config/apps/appFragments/communicationApp.js:7-125; docs/recon/open-questions.md:34-42 |
settings |
Core V1 | Core company/access settings only; attendance/LMS/Dapodik settings follow package and manage authority | src/config/apps/appFragments/settingsApp.js:20-112 |
platform |
Internal Platform | Provider control plane and observability; never normal school navigation | src/config/apps/appFragments/platformApp.js:9-132 |
4. Backend addon catalog¶
4.1 Addons with manifest — 67/67¶
Installer/bridge status describes product-surface ownership, not code quality. An Internal Platform bridge can be required by a supported package while still having no direct user menu.
| Addon | Proposed status | Package/product owner | Evidence / rationale |
|---|---|---|---|
scola_account |
Optional Supported | SC-FIN | docs/modular/plan/package-catalog.yaml:223-236; ../custom_addons_scola/gcgscola/scola_account/__manifest__.py:1 |
scola_admission |
Optional Supported | SC-ADM | docs/modular/plan/package-catalog.yaml:145-158; ../custom_addons_scola/gcgscola/scola_admission/__manifest__.py:1 |
scola_admission_assessment |
Optional Supported | SC-ADM + SC-ASSESS overlay | docs/modular/module-classification-matrix.md:98-104; ../custom_addons_scola/gcgscola/scola_admission_assessment/__manifest__.py:1 |
scola_admission_fees_bridge |
Internal Platform | SC-ADM/SC-FEES glue | Auto-install bridge; docs/modular/product-tier-and-feature-flags.md:75-83; manifest path exists. |
scola_admission_foundation |
Optional Supported | SC-ADM + SC-FOUND overlay | docs/modular/module-classification-matrix.md:98-104; manifest path exists. |
scola_assessment_bridge |
Requires Product Decision | Assessment owner migration | Runtime dependency remains while classification calls it legacy and scola_assessment is non-installable; docs/modular/module-classification-matrix.md:105; ../custom_addons_scola/gcgscola/scola_lms/__manifest__.py:1. |
scola_attendance |
Core V1 | SC-CORE manual attendance | docs/modular/plan/package-catalog.yaml:126-143; manifest path exists. |
scola_bos_rkas |
Controlled Pilot | SC-BOS | docs/modular/plan/package-catalog.yaml:343-364; manifest path exists. |
scola_bos_rkas_bridge |
Legacy / Deprecated | SC-BOS upgrade compatibility | docs/modular/module-classification-matrix.md:107; manifest identifies shim. |
scola_bos_rkas_executive_bridge |
Internal Platform | SC-BOS read-model glue | docs/modular/module-classification-matrix.md:108; no direct user surface. |
scola_bos_rkas_governance_bridge |
Requires Product Decision | SC-BOS migration owner | Classification says legacy but current BOS bundle still depends on it; docs/modular/module-classification-matrix.md:109,122-127. |
scola_bos_rkas_procurement |
Controlled Pilot | SC-BOS procurement | docs/modular/plan/package-catalog.yaml:343-364; manifest path exists. |
scola_bos_rkas_procurement_bridge |
Legacy / Deprecated | SC-BOS compatibility | docs/modular/module-classification-matrix.md:110,126; manifest path exists. |
scola_bundle_admission |
Internal Platform | SC-ADM installer | docs/modular/plan/package-catalog.yaml:145-158; manifest path exists. |
scola_bundle_assessment |
Internal Platform | SC-ASSESS installer | docs/modular/plan/package-catalog.yaml:199-210; manifest path exists. |
scola_bundle_bos_rkas |
Internal Platform | SC-BOS pilot installer | docs/modular/plan/package-catalog.yaml:343-364; manifest path exists. |
scola_bundle_core |
Internal Platform | SC-CORE installer | User surface belongs to member domains; ../custom_addons_scola/gcgscola/scola_bundle_core/__manifest__.py:1-21. |
scola_bundle_dapodik |
Internal Platform | SC-DAP pilot installer | docs/modular/plan/package-catalog.yaml:315-342; manifest path exists. |
scola_bundle_dapodik_attendance |
Internal Platform | SC-DAP/SC-ATTEND+ companion installer | docs/modular/plan/package-catalog.yaml:315-342; manifest path exists. |
scola_bundle_enterprise |
Internal Platform | Aggregate/profile packaging | Aggregate installer is not one user workflow; docs/modular/module-classification-matrix.md:136-158. |
scola_bundle_fees |
Internal Platform | SC-FEES installer | docs/modular/plan/package-catalog.yaml:159-172; manifest path exists. |
scola_bundle_finance |
Internal Platform | SC-FIN installer | docs/modular/plan/package-catalog.yaml:223-236; manifest path exists. |
scola_bundle_hr_attendance |
Internal Platform | Historical/technical attendance installer | No direct surface; topology overlaps SC-ATTEND+ and requires package cleanup only if retained. docs/recon/application-map.md:626-697. |
scola_bundle_learning |
Internal Platform | SC-LEARN installer | ../custom_addons_scola/gcgscola/scola_bundle_learning/__manifest__.py:1-18. |
scola_bundle_library |
Internal Platform | SC-LIB installer | docs/modular/plan/package-catalog.yaml:211-222; manifest path exists. |
scola_bundle_operations |
Internal Platform | SC-OPS installer | docs/modular/plan/package-catalog.yaml:237-250; manifest path exists. |
scola_bundle_people |
Internal Platform | SC-PEOPLE installer | docs/modular/plan/package-catalog.yaml:266-283; manifest path exists. |
scola_bundle_profile_negeri |
Internal Platform | Deployment profile installer | docs/modular/plan/package-catalog.yaml:55-63; manifest path exists. |
scola_bundle_profile_swasta |
Internal Platform | Deployment profile installer | docs/modular/plan/package-catalog.yaml:64-72; manifest path exists. |
scola_bundle_profile_yayasan |
Internal Platform | Deployment profile installer | docs/modular/plan/package-catalog.yaml:73-83; manifest path exists. |
scola_bundle_report_card |
Internal Platform | SC-REPORT installer | docs/modular/plan/package-catalog.yaml:173-186; manifest path exists. |
scola_bundle_smart_attendance |
Internal Platform | SC-ATTEND+ installer | docs/modular/plan/package-catalog.yaml:284-300; manifest path exists. |
scola_bundle_student_services |
Internal Platform | SC-STUDENT installer | docs/modular/plan/package-catalog.yaml:251-265; manifest path exists. |
scola_cbt |
Optional Supported | SC-ASSESS | docs/modular/plan/package-catalog.yaml:199-210; manifest path exists. |
scola_core |
Core V1 | SC-CORE identity/RBAC/tenant foundation | docs/modular/module-classification-matrix.md:51-55; manifest path exists. |
scola_counseling |
Optional Supported | SC-STUDENT | docs/modular/plan/package-catalog.yaml:251-265; BLK-A06 applies. |
scola_dapodik_academic_bridge |
Internal Platform | SC-DAP/academic glue | docs/modular/module-classification-matrix.md:111; auto-install pilot bridge. |
scola_dapodik_attendance_bridge |
Internal Platform | SC-DAP/attendance glue | docs/modular/module-classification-matrix.md:112; auto-install pilot bridge. |
scola_dapodik_connector |
Controlled Pilot | SC-DAP | docs/modular/plan/package-catalog.yaml:315-342; manifest path exists. |
scola_dapodik_report_card_bridge |
Internal Platform | SC-DAP/SC-REPORT glue | docs/modular/module-classification-matrix.md:113; auto-install pilot bridge. |
scola_fees |
Optional Supported | SC-FEES | docs/modular/plan/package-catalog.yaml:159-172; manifest path exists. |
scola_foundation_analytics |
Optional Supported | SC-FOUND | docs/modular/plan/package-catalog.yaml:301-314; manifest path exists. |
scola_hr |
Optional Supported | SC-PEOPLE | docs/modular/plan/package-catalog.yaml:266-283; manifest path exists. |
scola_hr_attendance |
Optional Supported | SC-ATTEND+ | docs/modular/plan/package-catalog.yaml:284-300; manifest path exists. |
scola_identity_admin |
Core V1 | SC-CORE tenant identity administration | Auto-installed customer-facing core shell; docs/modular/module-classification-matrix.md:60-68; manifest path exists. |
scola_inventory |
Optional Supported | SC-OPS | docs/modular/plan/package-catalog.yaml:237-250; manifest path exists. |
scola_inventory_account_bridge |
Requires Product Decision | SC-OPS/SC-FIN owner migration | Active manifest conflicts with classification and non-installable proposed owner; docs/modular/module-classification-matrix.md:114,128-130. |
scola_leadership_hub |
Requires Product Decision | Leadership shell | Auto-installed customer surface is absent from SC-CORE package and role scope drifts; docs/modular/module-classification-matrix.md:60-68; docs/recon/open-questions.md:35-42. |
scola_lesson_hours |
Core V1 | SC-CORE timetable primitive | docs/modular/plan/package-catalog.yaml:126-143; manifest path exists. |
scola_library |
Optional Supported | SC-LIB | docs/modular/plan/package-catalog.yaml:211-222; manifest path exists. |
scola_lms |
Optional Supported | SC-LEARN | docs/modular/plan/package-catalog.yaml:187-198; manifest path exists. |
scola_news |
Core V1 | SC-CORE canonical publication | Legacy announcement is excluded; docs/modular/plan/package-catalog.yaml:126-143; manifest path exists. |
scola_observability |
Internal Platform | Platform diagnostics | docs/modular/module-classification-matrix.md:53-55; manifest path exists. |
scola_odoo_base |
Internal Platform | Upstream prerequisite installer | docs/modular/module-classification-matrix.md:136-159; manifest path exists. |
scola_parent |
Core V1 | SC-CORE parent identity | docs/modular/plan/package-catalog.yaml:126-143; manifest path exists. |
scola_parent_fees_bridge |
Internal Platform | SC-CORE/SC-FEES ACL glue | Auto-install bridge; docs/modular/product-tier-and-feature-flags.md:75-83. |
scola_payroll |
Optional Supported | SC-PEOPLE | docs/modular/plan/package-catalog.yaml:266-283; BLK-A07 applies. |
scola_platform |
Internal Platform | Provider control plane | docs/modular/product-tier-and-feature-flags.md:84-98; manifest path exists. |
scola_platform_support |
Internal Platform | Entitlement/auth helper kernel | docs/modular/module-classification-matrix.md:53-55; manifest path exists. |
scola_portal |
Core V1 | SC-CORE shared portals | docs/modular/plan/package-catalog.yaml:126-143; manifest path exists. |
scola_portal_fees_bridge |
Internal Platform | SC-CORE/SC-FEES route glue | Auto-install bridge; docs/modular/product-tier-and-feature-flags.md:75-83. |
scola_public_complaint |
Requires Product Decision | No approved SKU/owner | Internal auth, attachment, retention, and anti-bot contract unresolved; docs/recon/open-questions.md:18-18; manifest path exists. |
scola_report_card |
Optional Supported | SC-REPORT | Package supported candidate; W08 remains incomplete. docs/modular/plan/package-catalog.yaml:173-186. |
scola_rules |
Optional Supported | SC-STUDENT | docs/modular/plan/package-catalog.yaml:251-265; manifest path exists. |
scola_smart_attendance |
Optional Supported | SC-ATTEND+ | Operator-managed smart attendance; docs/modular/plan/package-catalog.yaml:284-300; BLK-B07 applies. |
scola_student_activity |
Optional Supported | SC-STUDENT | docs/modular/plan/package-catalog.yaml:251-265; BLK-A08 applies. |
scola_timetable |
Core V1 | SC-CORE timetable owner | docs/modular/plan/package-catalog.yaml:126-143; manifest path exists. |
4.2 Module-like directories without manifest — 4/4¶
| Directory | Proposed status | Product treatment | Evidence |
|---|---|---|---|
scola_assessment |
Incomplete / Remove from Product Surface | Do not treat as installable canonical owner until a manifest, dependency migration, upgrade path, and tests exist. | docs/recon/application-map.md:698-706; ../custom_addons_scola/gcgscola/scola_assessment/models/ |
scola_bos_rkas_account_bridge |
Incomplete / Remove from Product Surface | Source fragment cannot satisfy package claim; either complete as an installable bridge or remove after migration decision. | docs/recon/application-map.md:698-706; ../custom_addons_scola/gcgscola/scola_bos_rkas_account_bridge/models/ |
scola_bundle_school_standard |
Legacy / Deprecated | Combined shim conflicts with three explicit school-standard SKUs; remove after confirming no installed dependency. | docs/modular/product-tier-and-feature-flags.md:54-66; ../custom_addons_scola/gcgscola/scola_bundle_school_standard/ |
scola_inventory_account |
Incomplete / Remove from Product Surface | Proposed canonical owner is non-installable while runtime bridge remains; resolve ownership before SC-OPS + SC-FIN certification. | docs/modular/module-classification-matrix.md:84,114; ../custom_addons_scola/gcgscola/scola_inventory_account/models/ |
5. Product workflow catalog — W00–W20 (21 contract rows)¶
Workflow status is independent of a read-only page or parent module. A module may be Core V1 while one mutation journey is Controlled Pilot or incomplete.
| ID | Workflow | Proposed status | Product/package owner and gate | Evidence |
|---|---|---|---|---|
| W00 | Login, session, active role, application and navigation | Core V1 | SC-CORE/platform prerequisite; Product + Identity/RBAC + Platform owners. Must close STAB-007/008/024/025/028, approve active-role/profile semantics, and pass fresh-role menu/route/API parity before any domain workflow can certify. | src/stores/auth.store.js:511-666; src/router/index.js:1-17; ../custom_addons_scola/gcgscola/scola_core/controllers/auth.py:485-518 |
| W01 | Academic master to timetable | Core V1 | SC-CORE; Curriculum/Academic Operations owner. Must approve lock/edit ownership and pass downstream session tests. | docs/recon/workflow-candidates.md:18; docs/recon/page-relationships.md:16-27 |
| W02 | Student onboarding | Core V1 | SC-CORE; Student Administration owner. Manual create plus identity linkage; import subflow remains gated by BLK-B03 and runtime async-job evidence. |
docs/recon/workflow-candidates.md:19; src/views/AdminViews/StudentDatabase/UploadSiswa.vue:769-835 |
| W03 | SPMB applicant to enrolled student | Optional Supported | SC-ADM; Admissions owner. State, final approver, and moment/idempotency of student creation require decision. | docs/recon/workflow-candidates.md:20 |
| W04 | CBT exam lifecycle | Optional Supported | SC-ASSESS; Assessment owner. Reopen/late/retry/result propagation contract and E2E required. | docs/recon/workflow-candidates.md:21 |
| W05 | Manual student attendance (bounded Core V1) | Core V1 | SC-CORE; W05-A per-lesson 16/16 + W05-B daily gate + pickup registry per T4-DEC-006-007-attendance-v1-matrix.md. Student RFID/face (W20) V2 optional SC-ATTEND+. | T4-W05-domain-map.md; T4-DEC-006-007-attendance-v1-matrix.md |
| W06 | Employee self-attendance | Optional Supported | SC-ATTEND+; HR/Attendance owner. Device/location/face, lock, correction, and privacy contract required. | docs/recon/workflow-candidates.md:23 |
| W07 | Gradebook to report card | Optional Supported | SC-REPORT standalone; the canonical non-LMS grade source remains a product decision. SC-LEARN is only a separately certified optional grade-source bridge. Combined evidence cannot certify either SKU alone; runtime teacher/approver/company and propagation UAT remain required. | docs/recon/workflow-candidates.md:24; docs/documentation-planning/documentation-blockers.md:492-502 |
| W08 | Promotion and retention | Incomplete / Remove from Product Surface | SC-REPORT workflow; hide until BLK-A05 defect and recommend/decide/execute policy are fixed and certified. |
docs/recon/workflow-candidates.md:25; docs/documentation-planning/documentation-blockers.md:128-138 |
| W09 | HR to payroll and payslip | Optional Supported | SC-PEOPLE; HR/Payroll owner + DPO. Blocked by BLK-A07, maker-checker, source, and confidentiality decisions. |
docs/recon/workflow-candidates.md:26 |
| W10 | Billing and payment | Optional Supported | SC-FEES and optional SC-FIN integration; Billing/Finance owner. BLK-A14, reversal/refund/journal ownership. |
docs/recon/workflow-candidates.md:27 |
| W11 | Accounting transaction lifecycle | Optional Supported | SC-FIN; Finance Controller. BLK-A09, action-level authority, company scope, correction/reversal. |
docs/recon/workflow-candidates.md:28 |
| W12 | BOS/RKAS procurement | Controlled Pilot | SC-BOS; BOS/Procurement owner. BLK-A10, approval idempotency, attachment, commitment, maker-checker. |
docs/recon/workflow-candidates.md:29 |
| W13 | Stock opname | Optional Supported | SC-OPS; Inventory owner. Freeze, adjustment posting, concurrency, and recovery decision/test required. | docs/recon/workflow-candidates.md:30 |
| W14 | Library circulation | Optional Supported | SC-LIB; Library owner. BLK-B08–B10, lost/damaged/fine/waiver/recovery contract. |
docs/recon/workflow-candidates.md:31 |
| W15 | Counseling and student affairs | Optional Supported | SC-STUDENT; Counseling/Student Affairs owner + DPO. BLK-A06, A08; assignment, approval, retention, and privacy. |
docs/recon/workflow-candidates.md:32 |
| W16 | Canonical news publication | Core V1 | SC-CORE/scola_news; Communications owner. Legacy announcement excluded; audience/approval and calendar linkage must pass. |
docs/recon/workflow-candidates.md:33; ../custom_addons_scola/gcgscola/scola_news/models/scola_news.py:102-150 |
| W17 | Complaint intake and triage | Requires Product Decision | No package owner; Product/Security/DPO must decide audience, operator, attachment, retention, consent, and anti-spam before implementation support. | docs/recon/workflow-candidates.md:34; BLK-A04 |
| W18 | Messaging and notification | Requires Product Decision | Portal capability exists, but package/process owner, membership/company scope, attachment, quiet-hour/retry, and notification ownership remain open. | docs/recon/workflow-candidates.md:35; BLK-A15, A17 |
| W19 | Dapodik sync | Controlled Pilot | SC-DAP; Dapodik/Operations owner. BLK-A11, preview/execute/destructive split, matching, conflict, and rollback. |
docs/recon/workflow-candidates.md:36 |
| W20 | RFID attendance ingestion | Optional Supported | SC-ATTEND+; Smart Attendance owner. BLK-B07, device/card authority, retry/dead-letter, and downstream attendance integrity. |
docs/recon/workflow-candidates.md:37 |
6. Explicit exclusions and consolidation decisions¶
| Surface | Proposed disposition | Required action before baseline | Evidence |
|---|---|---|---|
/announcement, scola.announcement, and legacy service |
Legacy / Deprecated | Remove from menus/search; migrate data/audience contract to scola.news; retain a scoped redirect only if compatibility requires it. |
src/router/sharedExperienceRoutes.js:57-66; docs/recon/open-questions.md:39-40 |
analytics shortcut app and /admin/analytics/* redirect family |
Legacy / Deprecated | Route each approved task directly to its owning domain; remove shortcut app from supported role registries. | src/config/apps/appFragments/analyticsApp.js:1-59; src/router/analyticsAdminRoutes.js:1-49 |
| Student RFID/face/geofence attendance | V2 optional (SC-ATTEND+) | Remain entitlement-gated; not in Core V1 cert denominator. Core-only tenants must not see RFID/face menus. | src/config/apps/appFragments/attendanceApp.js; DEC-001 extension 2026-08-29 |
| Seven lab/register routed stubs | Incomplete / Remove from Product Surface | Hide route/menu from customer roles; return explicit unsupported/404 state until a package, owner, API, and E2E exist. | docs/recon/open-questions.md:44-54; src/views/Register.vue:1-7 |
| 119 redirect/alias records | Legacy / Deprecated unless explicitly accepted compatibility | None may appear as a separate product/menu/help target; each needs canonical destination, owner, test, expiry or permanent-compatibility reason. | docs/recon/route-inventory.md:1293-1415 |
| Installer/profile/bridge/observability/provider modules | Internal Platform | Exclude from school launcher and user workflow count; certify through install/integration/operations tests. | docs/modular/product-tier-and-feature-flags.md:75-98 |
| Leadership, DPO, security, committee, pickup, admin-staff mixed shells | Requires Product Decision | Approve SKU/audience/task set first; then split core/optional/pilot leaves and enforce the same contract at API. | App rows in §3; docs/recon/open-questions.md:35-42 |
7. Approval and freeze record¶
This proposed contract becomes definitive only when all fields below are populated and QG-01 passes.
| Required record | Acceptance criterion |
|---|---|
| Scope decision | Every row in §§2–5 has an approved status, owner, version, and tenant applicability; no verbal-only approval. |
| Package manifest | Installed addon set, bundle, entitlement, feature flags, and dependencies match the approved package table. |
| Role contract | Intended roles map to the approved role glossary and authorization model; technical admin is not used as normal E2E proof. |
| IA contract | Every supported task has one canonical menu/route; unsupported/legacy/internal/incomplete leaves are invisible and direct routes fail closed. |
| Defect/decision closure | No open decision or S0/S1 affects supported completion, authorization, tenant scope, privacy, integrity, correction, or recovery. |
| Runtime evidence | Golden Tenant positive/negative/scope/isolation/integration/UI tests pass on one exact FE/BE/DB/module build. |
| Freeze | Product, Commercial, Security/DPO, School SME, QA, Operations, and Release owner sign the immutable release manifest. |
Until that record exists, this file is an auditable proposal and backlog input—not permission to market, expose, or document a surface as generally supported.
8. Static install-topology qualification¶
The catalog above is the intended commercial/product contract, not a claim
that current Odoo manifests already implement it. Static manifest closure at the
recorded backend build contradicts several independent-SKU boundaries. Installation
and entitlement are different facts: an addon may be technically installed while
its user surface must remain unentitled and inaccessible. No affected package can
be certified until Product chooses the intended composition under DEC-001 and
engineering closes STAB-024; tests must record the exact installed closure.
| Candidate contract | Current manifest closure that contradicts or broadens it | Required product/engineering disposition | Evidence |
|---|---|---|---|
| SC-CORE excludes the SC-PEOPLE surface | Core-owned scola_attendance hard-depends on scola_hr; a Core database therefore installs part of the People implementation even when the People SKU is not entitled |
Decide whether this is an internal technical dependency or accidental coupling; either narrow/remove it or keep every SC-PEOPLE menu, route, capability, and API denied when only Core is entitled | ../custom_addons_scola/gcgscola/scola_attendance/__manifest__.py:24-36 |
| SC-ADM has only an optional SC-FEES bridge | scola_admission hard-depends on scola_fees |
Remove/split the hard dependency or approve SC-FEES as a commercial prerequisite; until then an isolated SC-ADM certificate is blocked | ../custom_addons_scola/gcgscola/scola_admission/__manifest__.py:22-31 |
| SC-REPORT is independently supported; SC-STUDENT/assessment ownership is separate | scola_report_card hard-depends on scola_assessment_bridge and scola_student_activity |
Establish a minimal standalone grade/report source and remove/split peer dependencies, or approve and publish the wider package composition | ../custom_addons_scola/gcgscola/scola_report_card/__manifest__.py:23-34 |
| SC-LEARN and SC-ASSESS are independently supported | scola_lms and scola_cbt both hard-depend on scola_report_card and scola_assessment_bridge |
Remove/split or explicitly approve the cross-SKU topology; a combined install is not independent certificate evidence | ../custom_addons_scola/gcgscola/scola_lms/__manifest__.py:20-31; ../custom_addons_scola/gcgscola/scola_cbt/__manifest__.py:20-28 |
| SC-DAP report-card sync is conditional | scola_bundle_dapodik always installs scola_dapodik_report_card_bridge, which hard-depends on scola_report_card |
Provide a connector/academic-only installer or approve SC-REPORT as a mandatory pilot prerequisite; test both entitled and unentitled surfaces | ../custom_addons_scola/gcgscola/scola_bundle_dapodik/__manifest__.py:10-16; ../custom_addons_scola/gcgscola/scola_dapodik_report_card_bridge/__manifest__.py:10-14 |
| SC-BOS declares SC-FIN + SC-OPS | The bundle always installs executive/governance bridges, pulling decision-gated leadership and Foundation Analytics; its Finance+Operations+procurement closure also auto-installs the inventory-account bridge | Split optional governance/executive bridges or approve the wider composition; deny all unentitled leadership/foundation/valuation surfaces and certify maker-checker boundaries independently | ../custom_addons_scola/gcgscola/scola_bundle_bos_rkas/__manifest__.py:10-18; ../custom_addons_scola/gcgscola/scola_bos_rkas_executive_bridge/__manifest__.py:10-14; ../custom_addons_scola/gcgscola/scola_bos_rkas_governance_bridge/__manifest__.py:10-14; ../custom_addons_scola/gcgscola/scola_inventory_account_bridge/__manifest__.py:10-25 |
| SC-ATTEND+ is proposed as one commercial package spanning student smart/RFID and employee attendance | scola_bundle_smart_attendance installs only Core + scola_smart_attendance; employee attendance uses separate scola_bundle_hr_attendance |
Approve one composite installer/profile with two independently tested subflows, or split the commercial SKU and catalog/test each package separately | ../custom_addons_scola/gcgscola/scola_bundle_smart_attendance/__manifest__.py:10-14; ../custom_addons_scola/gcgscola/scola_bundle_hr_attendance/__manifest__.py:10-14 |
| SC-FOUND is proposed as an independent optional package with SC-FIN | Its catalogued enterprise installer pulls Learning, Assessment, Library, Finance, Operations, BOS, People, Student Services, Smart/HR Attendance, Dapodik, admission assessment, and Foundation Analytics | Create a truthful minimal SC-FOUND installer or classify the current installer as an enterprise umbrella only; an enterprise install cannot certify isolated SC-FOUND | docs/modular/plan/package-catalog.yaml:301-314; ../custom_addons_scola/gcgscola/scola_bundle_enterprise/__manifest__.py:10-33 |
This is an engineering topology defect relative to the proposed contract, not
permission for engineering to choose a commercial bundle. DEC-001 selects the
target; STAB-024 aligns manifests, entitlement, navigation, API authority, and
fresh-database install tests to that decision.