Lewati ke isi

08 — Normalized stabilization backlog

Scope note (2026-09-04): register ini mempertahankan temuan, keputusan, dan evidence historis. Status tanggal lama tidak boleh dibaca sebagai kondisi runtime terkini. Untuk program documentation-first, hanya item yang membuat instruksi tidak benar atau tidak aman yang menahan artikel; gunakan Documentation Confidence Gates. Semua item tetap berlaku untuk sertifikasi release sampai ditutup melalui QG yang sesuai.

Status dan aturan penggunaan

Backlog ini adalah program stabilisasi untuk Scola V1 Production Baseline, bukan persetujuan product scope dan bukan user documentation. Audit dilakukan dalam server-development mode dari /home/scola/odoo, dengan frontend develop@68b77d88f78b3d32f0ede3a54b665e067b014062 dan backend main@2ff6ac7cb41810bbc3b66821cdad004b52d1658a pada 2026-08-08. Delta hardening e749832/2ff6ac7 telah direview secara statis, tetapi belum menutup item STAB/CTRL tanpa acceptance dan regression evidence terkait.

Pedoman yang dibaca sebelum penyusunan: root dan frontend AGENTS.md, docs/ai-guidelines/AI_AGENT_MASTER_GUIDE.md, docs/ai-guidelines/development-guide.md, docs/ai-guidelines/workspace-governance.md, docs/ai-guidelines/architecture-api.md, docs/ai-guidelines/ui-design-pattern.md, docs/ai-guidelines/menu-architecture.md, docs/ai-guidelines/datetime-timezone.md, docs/ai-guidelines/rbac-user-management.md, docs/ai-guidelines/DOCUMENTATION_GOVERNANCE.md, dan docs/qa/testing-guidelines.md. Sumber temuan: seluruh docs/recon/, docs/documentation-planning/, serta audit release-readiness 01–04 dan 09.

Status produk/package di kolom berikut mengikuti proposed contract, bukan commercial approval (docs/release-readiness/01-product-contract.md:21-43). Defect optional/pilot tidak membuat package supported; bila package dikeluarkan dari V1, acceptance yang benar adalah menghapus/hide route/menu/API dari supported surface, bukan mempertahankan defect sebagai limitation.

Execution note — T0-A (2026-08-08)

Cross-cutting implementation started for STAB-005 / STAB-007 / STAB-008 (see docs/release-readiness/execution/T0-A-result.md). Status for those three items: Code fixed, runtime verification pending — not Closed. Do not treat source change alone as release evidence.

Execution note — T0-A.1 (2026-08-08)

Platform authorization closure for AUTH-004 fail-closed + method/action foundation + inventory dimensional correction (see docs/release-readiness/execution/T0-A1-result.md). STAB-005 / STAB-007 / STAB-008 remain Code fixed, runtime verification pendingnot Closed until T0-B. STAB-008 additionally gains method/action-aware rules and extractor CI gate (still runtime-pending).

Execution note — T0-B1 (2026-08-08)

DEC-002 session-scoped active role + Golden Tenant fixture foundation (see T0-B1-result.md). STAB-005/007/008 still not Closed pending T0-B2 runtime matrix.

Execution note — T6A.1 SPMB ops (2026-08-20)

Usage-felt operasional slice on certified W03 engine — not a new T6A COMPLETE claim. See docs/release-readiness/execution/T6A.1-SPMB-ops-plan.md and T6A.1-SPMB-ops-residuals.md. Staff queue, portal, and public quota surfaces align to w03_state; waitlist/ranking-as-decision/enrolled-reversal/fees/CBT remain out of scope.

Execution note — W02.1 / STAB-013 docs sync (2026-08-26)

Phase 3 docs sync only (plan Tutup Gap SPMB). See execution/W02.1-post-enrollment-archive-result.md, W02.1-post-enrollment-archive-residuals.md, and updated T6A.1-SPMB-ops-residuals.md. Does not rewrite auditor verdicts. Distinguishes historical snapshot vs current-tip engineering vs served-dev vs deferred product.

  • W02.1 (bounded): post-enrollment archive is admission-scoped (/archive-student-record) with reason, idempotency, immutable audit; FE uses archiveEnrolledStudentRecord (not generic setAdminStudentsActive for SPMB); enrolled remains terminal; quota unchanged. RT-W03-REC-01 = partial bounded closure, not full reversal.
  • STAB-013: original backlog row (view/config collapse) is a historical defect statement. On current-tip engineering, admission_config_api.py exposes distinct MUTATION_CAPABILITIES, unit negatives cover viewer / flag-off / cross-company / foreign FK / idempotency / archive-not-hard-delete (test_admission_config_api_unit.py), and legacy /admin/spmb/test|complaints|ranking deep links are fail-closed via productStatus + RC1_FAIL_CLOSED_ROUTE_PREFIXES. Status: Code hardened + unit negatives present — not Closed / not CERTIFIED for demo or production. Independent runtime matrix / DEC-008 product gate remains separate. Do not invent CERTIFIED claims.
  • Clamscan (W03): residual “missing full clamscan” in older T6A.1 text is outdated for W03 documents — source has quarantine + fail-closed w03_documents.scan_payload. T4.1 attendance proof residual (size/magic only) is a different surface.
  • Phase 5 leftovers (residual, non-blocker): principal/VP ranking routes still live outside /admin/spmb scope; this note is the STAB backlog docs sync for Phase 3.

Execution note — T4.1 W05 hardening (2026-08-19)

Usage-felt follow-on after T4-W05 / independent W05-A. See docs/release-readiness/execution/T4.1-W05-hardening-plan.md and T4.1-W05-hardening-residuals.md. This is not W05 CERTIFIED.

  • STAB-017 / STAB-018 / STAB-020 remain closed by T4 independent audit (regression only).
  • STAB-019 is PARTIAL: path A (mandatory correction reason + before/after audit). Formal DEC-006 draft/complete/correct/cancel is still open. Evidence: attendance_api_mixin.py _correction_reason_error / _record_sheet_correction; faculty/admin sheet CTA Koreksi.
  • STAB-021 residual T4W05-R-004 is CLOSED (bounded) at size/type/magic bytes (no malware scanner). Evidence: scola_attendance/utils/proof_file.py.
  • STAB-044 is CLOSED (bounded Core) — central jenjang resolver (src/config/schoolJenjang.js), menu/route guard parity for teacher attendance surfaces, RT-PROFILE-JENJANG-01 negative matrix (tests/menu/teacherAttendanceReportScope.spec.js). Full DEC-013 signed profile matrix remains PRE_OPTIONAL_EXPOSURE.
  • STAB-022 usage-closed on listed W05 surfaces: AttendanceSheetNew.vue, AttendanceSheetList.vue, WeeklyStudentReport.vue, ClassDailyReport.vue use getTodayDateInTimezone / getMondayOfDateInTimezone. Evidence: tests/unit/utils/timezone.spec.js 23:30/00:30 WIB/WITA/WIT.
  • STAB-027 usage-closed on listed W05 surfaces: canMutatePerLessonAttendance deny-list + denyRoles on /attendance/sheets/create; BE _admin_access_error and faculty save role check return 403 without DB write. Overview/insight stay on students.attendance.view.
  • Daily-gate 404/nodb is a host reliability track, OUT OF W05 (T4W05-R-002). Sheet save/create does not blindly re-POST after 404 (reconcile GET).

Execution note — W05-B DEC-006/007 (2026-08-29)

Bounded Core V1 manual attendance extended: daily gate + pickup registry (CORE_SUPPORTED). Student RFID/face remain V2 SC-ATTEND+. See execution/T4-DEC-006-007-attendance-v1-matrix.md and audit/RC1-W05B-attendance-boundary-reaudit.md.

  • STAB-019 daily path: cancel/adjust require reason; audit log via scola.attendance.daily.cancel.log; optional notify_parent on cancel (default off).
  • STAB-029: notify_parent wired when explicitly requested; no UI checkbox in V1.
  • RT-W05-DAILY- matrix rows moved to IN V1 baseline* — runtime PASS still pending on exact served pair.

1. Severity dan triage rules

Severity Definisi operasional
S0 Critical Confirmed code path dapat memberi akses/mutasi data sensitif tanpa domain authority, kebocoran membership/tenant boundary, atau perubahan ledger/master kritis melalui authority yang secara material salah. Stop release dan batasi/hide surface segera sambil melakukan runtime exploit validation.
S1 High Core/approved workflow tidak dapat diselesaikan dengan benar, authorization/data-integrity boundary materially gagal, atau release evidence dapat memberi false-green pada product/package. Selalu Release Blocker.
S2 Medium Bounded functional/consistency/recovery failure dengan containment/workaround aman; normally Must Fix. Tidak boleh diturunkan menjadi limitation bila menyentuh security, privacy, integrity, atau core completion.
S3 Low Polish atau maintainability debt yang tidak mengubah authority, data, task completion, recovery, atau safety.

Severity menyatakan impact, bukan kepastian exploit atau priority by component size. Temuan Requires runtime verification tetap diberi severity berdasarkan worst credible impact yang didukung code; downgrade hanya melalui evidence yang menutup kondisi tersebut. S0/S1 tidak boleh open pada baseline (docs/release-readiness/09-release-quality-gate.md:181-198). Product/business decisions berada di §7 tanpa S-severity. Missing runtime evidence berada di §8 dan tidak disamarkan sebagai bug.

2. Executive backlog summary

Severity Count IDs Release treatment
S0 6 STAB-001–STAB-006 Release Blocker; containment + fix + security/DPO regression
S1 23 STAB-007–STAB-028, STAB-044 Release Blocker; close or remove affected surface
S2 13 STAB-029–STAB-041 Must Fix by default; explicit bounded limitation only under QG policy
S3 2 STAB-042–STAB-043 Must Fix or post-release only after supported contract is unaffected
Decisions 14 DEC-001–DEC-014 No bug severity; owner decision must precede implementation where linked
Readiness controls 6 CTRL-001–CTRL-006 No bug severity; required evidence/control work

3. S0 Critical defects

ID Affected workflow / roles / package Root-cause category Required fix Owner / dependencies Proposed acceptance criteria Required regression tests Evidence / trace
STAB-001 W17 complaint; anonymous submitter, complaint operator; package Requires Product Decision Authorization + attachment/privacy Register public/internal actions explicitly; case/company assignment; strict anti-bot; server file allowlist/size/signature/scan; redaction/retention; safe download. Hide internal operator surface until fixed. Complaint Owner + Security + DPO; DEC-001/004/006/009 Only named operator can see/act on assigned company cases; public abuse and invalid files rejected; response/list minimal; audit/retention approved. Anonymous abuse/rate/Turnstile fail, viewer/unassigned/cross-company, MIME/size/signature, attachment download, redaction/audit. ../custom_addons_scola/gcgscola/scola_public_complaint/controllers/public_complaint_api.py:107-120,140-155,223-231,351-405,440-478; BLK-A04; AUTH-002/004/005/008/009/011.
STAB-002 W15 counseling; counselor, student-affairs viewer, student/parent; SC-STUDENT Authorization + sensitive data Split view/create/respond/refer/close/export; counselor/case/company/child scope; purpose projection; audited break-glass only. Counseling Owner + Security + DPO; DEC-003/004/006/009 View-only cannot mutate; only assigned counselor/case actors receive approved fields; all sensitive accesses audited. Cross-counselor/company/student/parent, viewer mutation, export/download, reassignment/closed case, break-glass expiry. ../custom_addons_scola/gcgscola/scola_counseling/controllers/counseling_domain_api.py:39-59,81,171-174,233-236,314-338; BLK-A06; AUTH-002/005/006/008–011.
STAB-003 W11 accounting; treasurer/viewer/approver; SC-FIN Authorization + cross-company financial integrity Split view/create/edit/post/reconcile/approve; scoped domain service before elevation; company/foreign-key validation; maker-checker and immutable audit. Finance Controller + Security; DEC-003/004/006/007 Viewer cannot mutate; no cross-company browse/write; self-post/reconcile and invalid state denied; one audited financial effect. Direct API, cross-company guessed/mixed IDs, maker-self approval, post/reconcile/reverse, concurrent/retry, before/after ledger. ../custom_addons_scola/gcgscola/scola_account/controllers/accounting_modules_api.py:20-59,69-167,212-300; BLK-A09; AUTH-002/005/009–011.
STAB-004 W19 Dapodik; Dapodik operator/admin; SC-DAP Controlled Pilot Authorization + tenant identity/master integrity Split view/configure/preview/execute/delete; tenant-scoped stable identifiers; mandatory exact diff; idempotent sync and rollback/recovery. Keep pilot disabled until certified. Dapodik/Integration Owner + Security + Data Steward; DEC-003/004/008 Viewer cannot sync/configure; cross-tenant identifiers never match; preview equals write set; rerun one effect; recovery/audit approved. NISN/NUPTK/rombel collision, flag off, viewer mutation, dry-run/write parity, concurrent/retry, partial failure/rollback. ../custom_addons_scola/gcgscola/scola_dapodik_connector/controllers/dapodik_api.py:22-95,214-313,327-435,474-571; BLK-A11; AUTH-002/005/006/009–011/014.
STAB-005 Core contextual tracking; any authenticated user; SC-CORE Generic elevated endpoint / object authorization Remove generic user surface or enforce model/action allowlist, native rights/rules, company/domain ownership and record purpose before elevation. Core Platform Security; DEC-003/009 Arbitrary model rejected; inaccessible ID returns 403 without existence leak; only allowlisted record/action succeeds and is audited. Model/res_id fuzzing, cross-company/record, disallowed field/action, inaccessible/existing ID indistinguishability, audit. ../custom_addons_scola/gcgscola/scola_core/controllers/core_reference_api.py:42-49; BLK-A12; AUTH-004/005/008/009/011.
STAB-006 W18 messaging; student/parent/teacher/staff; product decision pending within portal Membership authorization + attachment privacy Membership-filter every batch item; attachment linked to accessible message/channel; safe field allowlist; tenant/retention/access audit. Messaging Owner + Security + DPO; DEC-001/003/009/010 Arbitrary or mixed unauthorized channel IDs reveal no preview/count; unrelated attachment inaccessible; revoked member loses access. Non-member/mixed batch, guessed attachment, revoked membership, cross-company, list projection, read/download audit. ../custom_addons_scola/gcgscola/scola_portal/controllers/general_messaging_api.py:439-482,520-550,945-982; BLK-A15; AUTH-005/007–009/011.

4. S1 High defects

ID Affected workflow / roles / package Root-cause category Required fix Owner / dependencies Proposed acceptance criteria Required regression tests Evidence / trace
STAB-007 W00 and all workflows; every multi-role user; platform/SC-CORE Active-role semantics / SoD Active role becomes server-side enforcement context; assigned roles are eligibility only; conflict/delegation/break-glass and acting-role audit. Security + Product + Auth Owner; DEC-002/006 Capability unique to role A becomes 403 after switch to B; forged role rejected; audit records acting role. Single/multi/conflict role, switch/refresh/concurrent tabs, direct API, delegation expiry, provisioning migration. ../custom_addons_scola/gcgscola/scola_core/controllers/auth.py:485-518; ../custom_addons_scola/gcgscola/scola_core/services/auth_capabilities.py:676-771; BLK-A02; AUTH-001/011/013.
STAB-008 All protected APIs; all roles/packages Route authorization resolver / deny-default Exact/longest-prefix registry; action capability split; collision detector; every protected API registered and unknown protected denied; controller scope remains mandatory. Platform Security/Auth; DEC-003 Zero unintended overlap; specific library/fees/LMS rules resolve correctly; unregistered protected fixture denied. Prefix permutations, exact/action routes, public allowlist, FE/BE registry parity, route extraction count. ../custom_addons_scola/gcgscola/scola_platform_support/api_route_access.py:60,226,254,289,294,458,482-528; BLK-A03; AUTH-002–004/012/014.
STAB-009 W08 promotion; academic admin/approver; SC-REPORT Broken guard / missing implementation Define/import correct guard, action capability, owner/approval/state/reversal; hide promotion until happy and negative paths pass. Report Card Owner; DEC-004/006/007 Controller loads; authorized flow completes; unauthorized/self/invalid transition denied; supported rollback works. Startup/import, list/candidate/action, viewer, cross-company, self-approval, retry/reversal. ../custom_addons_scola/gcgscola/scola_report_card/controllers/promotion_admin_api.py:21-24,63-172; BLK-A05; AUTH-002/004/010/014.
STAB-010 W09 payroll; payroll viewer/operator/reviewer/approver/employee; SC-PEOPLE View/mutation capability collapse + sensitive finance Separate self/operator/reviewer/approver/auditor; employee/company scope, maker-checker, field projection, audit. Payroll/HR + Finance + Security/DPO; DEC-003/004/006/009 Viewer cannot confirm/cancel/draft/refund/input/batch; self sees own only; cross-company denied; salary projection approved. Every state action, self/peer, company, maker-checker, export, audit/field snapshot. ../custom_addons_scola/gcgscola/scola_payroll/controllers/payslip_admin_api.py:33-66,391-558; ../custom_addons_scola/gcgscola/scola_payroll/controllers/payroll_api.py:37-149,274-354; BLK-A07; AUTH-002/005/008/010/011.
STAB-011 W15 kesiswaan; viewer/operator/approver/student-affairs; SC-STUDENT View/mutation capability collapse + record ownership Separate achievement/permit/discipline read/create/edit/delete/approve/reject; class/case/company scope and SoD/audit. Student Affairs + Security; DEC-003/004/006 Viewer mutation 403; other class/case/company denied; maker cannot self-approve unless signed policy. Direct API per action, class/case/company, transition, self-approval/delegation, audit. ../custom_addons_scola/gcgscola/scola_student_activity/controllers/kesiswaan_domain_api.py:42-54,78-84,165-221,1032-1077; BLK-A08; AUTH-002/005/006/008/010/011.
STAB-012 W12 BOS/RKAS procurement; maker/approver; SC-BOS Pilot Idempotency/state + authorization + attachment ownership State/action guard, idempotency/constraint, SoD, company scope, attachment ownership/type/size/scan, compensating recovery. BOS/RKAS + Finance + Security; DEC-004/006/007/009 Repeated/concurrent approval creates one commitment; invalid state/viewer/foreign attachment rejected; one audit trail and approved recovery. Double/concurrent action, viewer, self-approval, cross-company/model attachment, file validation, partial failure/reversal. ../custom_addons_scola/gcgscola/scola_bos_rkas_procurement/models/purchase_request.py:142-164; ../custom_addons_scola/gcgscola/scola_bos_rkas_procurement/controllers/procurement_admin_api.py:35-62,355-384; BLK-A10; AUTH-002/005/009–011/014.
STAB-013 W03 config; admissions viewer/manager; SC-ADM (historical) View/config mutation collapse + package entitlement — current-tip engineering note 2026-08-26: mutation caps split + unit negatives present; not Closed / not CERTIFIED demo/prod (see Execution note W02.1 / STAB-013) Split view/configure/delete, protect referenced/effective-dated company masters, audit; gate SC-ADM. Admissions + Security; DEC-001/003/004/008 Viewer/flag-off/cross-company save/delete denied; referenced delete safe; manager change audited and rollbackable. Route/direct API, entitlement off/on, company, referenced record, effective date, rollback/audit. Current tip: admission_config_api.py MUTATION_CAPABILITIES + test_admission_config_api_unit.py; FE fail-closed /admin/spmb/test|complaints|ranking. Historical lines BLK-A13; AUTH-002/005/010–012.
STAB-014 W10 fee enrollment; billing operator/student; SC-FEES Missing explicit tenant ownership on elevated IDs/FKs Validate enrollment/student/course/batch/schedule company ownership before read/write; atomic scoped service. Fees + Security; DEC-003/008 Every lookup/detail/save filters active company; cross-company target/mixed FK rejected atomically. Guessed detail, mixed student/course/batch, list totals, active-company switch, mutation rollback. ../custom_addons_scola/gcgscola/scola_fees/controllers/fee_enrollment_api.py:135-175,180-235,263-267; BLK-A14; AUTH-005/006/009/014.
STAB-015 Calendar communication; admin/owner/attendee; SC-CORE Elevated event/user browse without proved owner/company scope Action manage capability, event owner/company policy, attendee scope, notification/cancel audit. Communications + Security; DEC-003/004/010 Viewer cannot save; guessed event/user and cross-company attendee denied; owner transitions and notifications audited. View/save direct API, other owner/company, attendee injection, invite/cancel propagation, audit. ../custom_addons_scola/gcgscola/scola_portal/controllers/calendar_admin_api.py:23-83; BLK-A16; AUTH-002/005/006/009–012.
STAB-016 Company/notification settings; school admin/platform role; SC-CORE + optional settings View/config authority and tenant/global drift Distinct configure capabilities; explicit tenant vs global owner; secret handling, effective date, rollback and audit; route/menu parity. Platform Ops + Communications + Security; DEC-003/004/008/010 Viewer cannot write; tenant change cannot affect another tenant; global only named platform role; secrets never returned/logged. View/config direct API, tenant/global, feature off, secret redaction, rollback/audit, UI parity. src/router/settingsRoutes.js:34-39; ../custom_addons_scola/gcgscola/scola_core/controllers/company_settings_api.py:119-125,205-249; ../custom_addons_scola/gcgscola/scola_portal/controllers/notification_config_api.py:25-57; BLK-A17; IA-011; AUTH-002/005/010–012.
STAB-017 W05 first save; fresh teacher/homeroom; SC-CORE Controlled Pilot workflow ACL/provisioning mismatch Canonical scoped create/write boundary for sheet/line; no unrelated legacy attendance group and no broad sudo. Attendance Backend + Identity/RBAC; DEC-002/003/012 Fresh teacher with canonical groups first-saves atomically; unassigned teacher denied. Fresh vs legacy user, create/write/read ACL, assigned/unassigned session, company, retry. ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:4304-4332; ../custom_addons_scola/gcgscola/scola_attendance/security/ir.model.access.csv:4,8; BLK-A19; AUTH-001/006/013/014.
STAB-018 W05 faculty/admin save; teacher/admin; SC-CORE Controlled Pilot workflow Roster/tenant validation and atomicity Exact event-date roster, duplicate/membership/company/completeness validation on every save path. Attendance Backend + School Ops; DEC-003/008 Duplicate/missing/out-of-batch/zero/cross-company IDs all rejected with zero partial writes; exact roster succeeds. Faculty/admin, single/combined session, all invalid roster variants, transaction rollback, concurrent update. ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:3335,3398-3422,4238-4275,4307-4334; BLK-A20; AUTH-005/006/009/014.
STAB-019 W05 complete/correct; teacher/admin/leadership; SC-CORE Controlled Pilot workflow State machine / correction ownership / audit Distinct draft/complete/correct actions per approved PO-01/AM-02/SG-01; reason/cutoff/approval/recovery and immutable before/after audit. Attendance PO + School SME + Security; DEC-006/007 Only approved transitions/actors; late/invalid correction rejected; correction carries actor/time/reason/before-after and propagates downstream. Role/state table, same/late day, self/approval, retry/concurrency, audit, student/parent update. ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:3398-3422,4307-4334; src/views/AttendanceManagement/Faculty/AttendanceSheet.vue:667-671,733-772; BLK-A21; UX-003; AUTH-002/010/011/014.
STAB-020 W05 statuses and aggregates; all W05 actors; SC-CORE Controlled Pilot workflow FE/BE state-model mismatch Implement approved SG-02 canonical status/subtype across input, serializer, aggregate, migration and labels. Attendance PO + SME + Analytics; DEC-006/007 Every approved value round-trips and aggregates deterministically; invalid/legacy values handled by approved rule. Create/read/update, period aggregate, parent/student, correction, legacy migration, invalid enum. src/i18n/attendanceStatus.js:33-54; ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:63-73,2855-2875,4313-4324; BLK-A22; UX-004/016; AUTH-002/010/014.
STAB-021 W05 proof; teacher, student/parent viewers; SC-CORE Controlled Pilot workflow Server file validation + privacy projection Server size/type/signature/scan; opaque authorized download; no raw proof in list payload; viewer/retention/delete policy and audit. Security + DPO + Attendance + Storage; DEC-006/009 Invalid/oversize rejected; raw bytes absent from list; only approved child/company viewer downloads; retention/audit signed. File matrix, spoofed MIME, payload size, child/company, download URL, retention/delete, audit. src/views/AttendanceManagement/Faculty/AttendanceSheet.vue:315-319,592-603,749-750; ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:2795-2796,2816-2833,4323-4324; BLK-A23; UX-005; AUTH-005/007–009/011/014.
STAB-022 W05 create/pending and date-effective reports; teacher/admin; SC-CORE Timezone/day-boundary defect Replace raw UTC date selection with school-timezone facade for school-day defaults/math. FE Attendance/Academic; timezone decision/runtime config Around UTC boundary, UI default, API date, persisted day and downstream view all equal school local date. UTC± offsets, 23:30/00:30 school local, reload/navigation, weekly Monday, daily report. src/views/AttendanceManagement/Admin/AttendanceSheetNew.vue:196,405; src/views/AttendanceManagement/Admin/AttendanceSheetList.vue:184; src/views/FacultyViews/WeeklyStudentReport.vue:590,628; src/views/FacultyViews/ClassDailyReport.vue:313; UX-001; SSOT docs/ai-guidelines/datetime-timezone.md:3-16,55-58.
STAB-023 W02 student create/import; viewer/identity admin; SC-CORE Route/action/API guard drift Route and CTA require students manage/import; retrace async-job state/error/retry; direct API same capability/scope. Identity Admin FE/BE + Security; DEC-003/008 Viewer cannot enter/call mutation; manager completes deterministic import with safe retry/error report. Route/menu/direct API, file/validation, async timeout/retry/idempotency, company, job error download. src/router/studentDataAdminRoutes.js:14-20,37-43; src/views/AdminViews/StudentDatabase/StudentList.vue:18,303; src/views/AdminViews/StudentDatabase/UploadSiswa.vue:769-778,835; BLK-B03; IA-024; AUTH-002/012/014.
STAB-024 W00 navigation/package entry and package installation; all roles; SC-CORE + all optional/pilot packages Declared-vs-actual package topology and product-gate leakage Generate the exact fresh-database dependency/auto-install closure for every bundle; remove/split undeclared peer-SKU hard dependencies or implement the Product-approved composition. Derive shell/group/leaf visibility from approved package + installed addon + entitlement + capability; installed module never implies entitled user surface; optional off means no menu/route/API authority. Product/Commercial + Backend Packaging + Platform + FE Navigation; DEC-001/011/012 Approved package dependencies match the exact installed closure. SC-CORE may technically install only approved internal dependencies; every peer-SKU addon that remains installed is explicitly classified and its menu/route/capability/API surface denied when unentitled. Each optional/pilot package has a truthful independent or explicitly composite installer. Empty-DB install/module-closure snapshot per bundle; unexpected transitive diff; entitlement/flag off/on; role/menu crawl; direct route/API; auto-install bridge; mixed shell; upgrade/uninstall compatibility. Static contradictions: 01 §8; manifests ../custom_addons_scola/gcgscola/scola_attendance/__manifest__.py:24-36, ../custom_addons_scola/gcgscola/scola_admission/__manifest__.py:22-31, ../custom_addons_scola/gcgscola/scola_report_card/__manifest__.py:23-34, ../custom_addons_scola/gcgscola/scola_lms/__manifest__.py:20-31, ../custom_addons_scola/gcgscola/scola_cbt/__manifest__.py:20-28, ../custom_addons_scola/gcgscola/scola_bundle_enterprise/__manifest__.py:10-33; IA-001/011–014/023; BLK-B01; AUTH-012–014.
STAB-025 W00 role entry/home; cashier/admin/head-admin/principal/VP/teacher and other roles; mixed packages Role catalog/home/visible-forbidden authority drift One canonical role/app/home contract mirrored by backend; remove orphan/invalid homes; reconcile admin vs school_admin, head-admin, VP scopes; zero visible-forbidden leaves. Product + Identity/RBAC + FE Navigation; DEC-001/002/004/011 Every fresh supported role lands on valid authorized home; all visible leaves load; unauthorized direct routes/API deny; no orphan role/app. Role×app×leaf crawl, fresh login/home, switch role, direct route/API, backend catalog parity. src/config/apps/roleApps.js:1-679; ../custom_addons_scola/gcgscola/scola_core/services/role_catalog.py:7-40; IA-002–005/008/015–018; AUTH-001/012–014.
STAB-026 W00 unsupported surface; normal roles/public; lab and registration Placeholder/incomplete product exposure Remove/hide/deprecate lab placeholder leaves and /register stub until complete product/API/owner/tests exist. Product + owning FE/module engineer; DEC-001/011 Zero supported menu/search/home link to placeholder; direct route removed/explicitly unavailable; no API/product promise. Role crawl, direct route, public route, search/deep link, feature off. docs/recon/open-questions.md:41-50; BLK-A18; IA-006/007; AUTH-004/012–014.
STAB-027 W05 monitor/correct UI; principal/VP/admin; SC-CORE Controlled Pilot CTA/route/API authority contradiction Default leadership read-only; hide mutation CTA/routes unless PO explicitly grants and backend enforces dedicated capability. Attendance PO + FE/BE RBAC; DEC-006 Principal/VP can read only approved scope, never see mutation CTA, and direct mutation returns 403/no data change; admin policy exact. Menu/list/detail/create/pending/direct API per role and active-role switch. src/views/AttendanceManagement/Admin/AttendanceSheetList.vue:9-20,192; ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:146-199,3335-3337; BLK-B04; UX-002; IA-025; AUTH-012.
STAB-028 Release regression; QA/release owner; SC-CORE and every package/composite bridge Test/package-boundary false-green Derive one suite manifest from the approved product contract and exact installed closure. Keep SC-CORE, each independent SKU, and every composite bridge result separate; installed-but-unentitled peer modules receive denial tests and never make a parent package green. QA/Release + Package Owners; DEC-001/012; STAB-024 Core smoke selects only Core journeys; each package result names exact module closure, entitlement/flags, independent/composite status, prerequisite results, and package denominator. SC-ADM/SPMB and all other optional/pilot suites are distinct. Script/manifest contract, suite list snapshot, empty-DB closure, Core with all peer entitlements off, package off/on, composite-bridge profile, CI/manual parity. package.json:36-39; docs/modular/product-tier-and-feature-flags.md:37-83; docs/ai-guidelines/development-guide.md:283-306; 07 §10; QG-14 docs/release-readiness/09-release-quality-gate.md:145.
STAB-044 W00 and teacher attendance/report entry; teacher with missing, unknown, unsupported, or unassigned jenjang; SC-CORE School-profile menu/route guard fail-open drift Centralize a recognized-and-assigned jenjang predicate. Missing/unknown/unsupported codes deny or route to a safe unsupported state; only explicitly retained early/non-early codes enter their branch. Menu, route guard, backend record scope, and profile resolver use the same contract. FE Navigation + Identity/RBAC + Academic Scope; DEC-003/013 Empty, malformed, unsupported, expired/unassigned, and other-company jenjang never enter either teacher attendance branch or subject-report route; every retained code reaches exactly its approved branch; denial leaks no records. Fresh teacher profile matrix; menu visibility; direct URL/deep link; role switch; missing/unknown code; other-company/level assignment; backend direct API; retained early/non-early positive cases. CLOSED (bounded Core, 2026-08-26): resolveRecognizedJenjangProfile + isJenjangAllowedForUser in src/config/schoolJenjang.js; route guards in src/router/teacherRouteFragments/attendance.js; menu parity in src/config/apps/appFragments/teacherPortalApp.js; evidence tests/menu/teacherAttendanceReportScope.spec.js (RT-PROFILE-JENJANG-01 negatives). Full DEC-013 signed matrix = PRE_OPTIONAL_EXPOSURE.

5. S2 Medium defects

ID Affected workflow / roles / package Root-cause category Required fix Owner / dependencies Proposed acceptance criteria Required regression tests Evidence / trace
STAB-029 Daily attendance cancellation; operator/parent; SC-CORE/SC-ATTEND+ boundary Parameter/side-effect contradiction Implement and observe notify_parent, or remove the control/claim and expose approved manual recovery; dedupe delivery. Attendance + Notification; DEC-010 Requested behavior equals delivered/audited state; failure visible with safe recovery. true/false, delivery failure/retry/dedupe, parent visibility, cancellation audit. ../custom_addons_scola/gcgscola/scola_attendance/controllers/attendance_api_mixin.py:1261-1320; BLK-B06.
STAB-030 W20 RFID; device/operator; SC-ATTEND+ View/mutation capability + retry state ambiguity Manage capability for config/retry; explicit event state machine, idempotent reset/retry, dead-letter owner/monitoring. Smart Attendance + Security/Ops; DEC-003/004/010 Viewer cannot mutate/retry; failed event has one supported retry path and one attendance effect. State/action matrix, processed error, repeated/concurrent retry, device/company, config route, dead-letter alert. ../custom_addons_scola/gcgscola/scola_smart_attendance/controllers/rfid_events_api.py:450-478,657-672; ../custom_addons_scola/gcgscola/scola_smart_attendance/models/rfid_event.py:147-168; BLK-B07.
STAB-031 W14 library queue; librarian/member; SC-LIB Concurrency integrity (static inference) Database lock/constraint or serialized assignment with deterministic priority and conflict recovery. Library Engineering + SME Concurrent attempts never assign one copy twice; deterministic winner and recovery audit. Parallel transactions, same priority tie, cancellation/expiry/retry, inventory reconciliation. ../custom_addons_scola/gcgscola/scola_library/controllers/library_queue_return_api.py:161-180; ../custom_addons_scola/gcgscola/scola_library/models/library_queue_auto.py:112-169; BLK-B08.
STAB-032 Library settings; viewer/manager; SC-LIB FE route vs API capability drift Gate page/load/save consistently: either read GET for viewer + manage save, or manage-only page; match menu/route/API. Library + FE RBAC; DEC-003/008 Viewer behavior intentional and consistent; manager load/save succeeds; direct mutation secured. Menu/route/load/save/direct API, flag off/on, company, role switch. src/router/libraryManagementRoutes.js:146-152; src/services/library/library.service.js:759-795; ../custom_addons_scola/gcgscola/scola_library/controllers/library_portal_reading_api.py:63-72; BLK-B10.
STAB-033 W16 communication; publisher/readers; SC-CORE Duplicate canonical/legacy publication Make scola.news sole writable source; legacy announcement read-only/migrated/removed; preserve history and audience/notification mapping. Communications + Platform; DEC-011 One canonical create/publish route; legacy write impossible; migration report and no duplicate delivery. Canonical publish, legacy direct API, history migration, audience/read receipt/notification parity. ../custom_addons_scola/gcgscola/scola_news/models/scola_news.py:96-198,571-634; ../custom_addons_scola/gcgscola/scola_portal/models/announcement.py:15-27,146-212,262-325; BLK-B11; IA-010.
STAB-034 Mutation feedback across supported pages; all roles/packages Multiple notification taxonomies/renderers One provider/renderer per shell; canonical error type/style/ARIA; mount on mobile/desktop; Indonesian close/default copy; prevent duplicate render. FE Design System Exactly one correctly styled/announced notification for each type on mobile/desktop. Component types, AppLayout branches, local+global renderer, timeout/persistent, keyboard dismiss. src/composables/useAlerts.js:47-52; src/components/AlertStack.vue:30-59,66-87; src/layouts/AppLayout.vue:18-29,37-75; UX-006.
STAB-035 Save/cancel/destructive actions; all operators/packages Modal lifecycle + native confirmation inconsistency Loading/dirty close guard, localized defaults, one consequence-aware confirm component; remove native confirm on supported routes. FE Design System + domain owners; DEC-007 Loading mutation cannot backdrop/Escape close; dirty cancel warns; destructive confirmation names effect/recovery; cancel performs no request. Escape/backdrop/loading, dirty form, double submit, delete/post/approve/cancel, focus return/i18n. src/components/ui/AppModal.vue:6-12,51-68,144-175; src/components/ui/AppConfirmDialog.vue:61-91; native examples src/views/AdminViews/AcademicConfig/AcademicCalendar/AcademicCalendarList.vue:802; UX-007/015.
STAB-036 Server-paginated student/academic tables; admins; SC-CORE Local sort over one server page Add server sort contract/event or disable sorting for server-paged columns; preserve total/page/filter semantics. FE Data Table + API owners Dataset >2 pages sorts globally or UI shows non-sortable; page traversal deterministic. Asc/desc each type, page traversal, filter+sort, reload, selection/bulk action. src/components/ui/AppTable.vue:61-103,294,423-471; src/views/AdminViews/StudentDatabase/StudentList.vue:115-118; src/views/AdminViews/AcademicConfig/AcademicYear/AcademicYearList.vue:61-62; UX-009.
STAB-037 Mobile shell and attendance summary tables; all portal/admin roles Missing topbar + inconsistent responsive/a11y semantics Require mobile topbar/header; canonical accessible tabs/table overflow/card alternative; route viewport inventory. FE Shell/Design System Every supported task at 320/360/390/768 px has title/navigation, no clipped action, keyboard/ARIA path and no page overflow. Route viewport crawl, keyboard/focus/screen reader, bottom-bar overlap, student/parent parity. src/layouts/AppLayout.vue:18-29; src/views/AdminViews/AcademicConfig/AcademicYear/AcademicYearList.vue:2-9; src/views/AttendanceManagement/Student/AttendanceList.vue:1-88; src/views/AttendanceManagement/Parent/AttendanceList.vue:1-104; UX-010/017.
STAB-038 Forms/tabs/filters/search; all supported roles/packages Component/validation/query-state inconsistency Canonical controls; required/backend parity; inline error/focus; labelled filters; debounce cancellation/reset/page-1/URL state. FE Design System + API owners Required UI matches backend; invalid request atomic; tabs keyboard-safe; search/filter reload/back deterministic. Missing/invalid/cross-scope, focus/ARIA, debounce race, reset, page state, empty-filter vs empty-data. src/components/ui/AppInput.vue:5-10,57,81-94; src/views/AdminViews/StudentDatabase/StudentList.vue:63-118,441,534; src/views/AdminViews/AcademicConfig/StudyGroup/StudyGroupList.vue:96-125,1672-1678; UX-012/013.
STAB-039 Loading/empty/error/retry; all supported pages Non-normalized UI and HTTP error states Canonical state blocks and safe 401/403/404/409/422/429/5xx/offline mapping; no raw backend error; retry only for safe/idempotent action. FE Platform + API owners No blank/infinite loading; 403 not empty; conflict offers reconcile; internal detail not rendered; safe retry deterministic. Forced response matrix, offline/timeout/stale, retry/idempotency, correlation reference, screen-reader announcement. src/components/ui/AppTable.vue:118-180; src/views/AttendanceManagement/Parent/Attendance.vue:344-366,419-427; src/views/AttendanceManagement/Admin/AttendanceSheetNew.vue:285-287,323-326,408-410; UX-014/018.
STAB-040 Attendance navigation/status labels; all attendance actors; SC-CORE/ATTEND+ Terminology collision Approve and implement glossary/page taxonomy for Kehadiran/Absensi/Presensi, daily/per-session/smart/pickup; aliases searchable but not competing labels. Attendance PO + Product Design; DEC-006/007/011 One canonical term per concept/locale; label maps to correct page/package; state meaning unchanged across roles. Menu/page/breadcrumb/i18n snapshot, cross-role route, search alias, state round-trip. src/i18n/locales/id.json:644,819,842,1079,1165,1199-1202,1516-1579,1881-1985; UX-016; IA-012.
STAB-041 W00 navigation; all roles/packages Duplicate leaf routes, aliases, breadcrumb gaps, validator drift One canonical page/route owner; duplicate leaves consolidate; alias registry has owner/sunset/telemetry; breadcrumbs resolve canonical; audit validator matches runtime policy. FE Navigation + Platform QA; DEC-011 No unexplained duplicate route key; all aliases redirect to canonical with lifecycle; hidden/detail route breadcrumb valid; validator zero false positive for approved contract. Route/menu graph, alias deep link, role crawl, breadcrumb chain, validator fixtures/runtime parity. BLK-B02; IA-009/019–022; source inventories docs/recon/route-inventory.md and docs/recon/open-questions.md:30-37.

6. S3 Low defects

ID Affected workflow / roles / package Root-cause category Required fix Owner / dependencies Proposed acceptance criteria Required regression tests Evidence / trace
STAB-042 Supported UI primitives; all roles/packages Duplicate component implementations Deprecate root primitives; migrate supported imports to components/ui; maintain explicit temporary allowlist. FE Design System Zero deprecated primitive import on supported surface, or each allowlist entry has owner/removal version. Static import inventory, component smoke/visual snapshot for migrated pages. src/components/AppButton.vue:1-40; src/components/ui/AppButton.vue:1-111; residual src/views/AdminViews/Infrastructure/Maintenance.vue:28-30; UX-008.
STAB-043 Page headers/spacing; all roles/packages Visual hierarchy drift Standardize title/subtitle/breadcrumb/CTA zone and container spacing without changing domain workflow. FE Design System Supported page inventory uses approved shell/header contract; no duplicate/missing title. Mobile/desktop visual snapshots, heading hierarchy, focus/landmark audit. src/views/AdminViews/AcademicConfig/AcademicYear/AcademicYearList.vue:4-9; src/views/AdminViews/AcademicConfig/GradeLevel/GradeLevelList.vue:4-9; docs/ai-guidelines/ui-design-pattern.md:31-33; UX-011.

7. Decision register — explicitly not bugs

No row in this section may receive S0–S3. A decision selects the intended product contract; only a divergence from the selected contract becomes a defect.

Decision ID Existing decision IDs Decision required Affected defects/workflows Recommended owner Unblock condition
DEC-001 SM-01–SM-03 Approve V1 packages, workflow/support status, mixed-shell boundary, and pilot entry/exit. STAB-001/004/006/013/024–026/028; all workflows Product + Commercial + Operations Signed 01 catalog, tenant package profiles, owner and review date.
DEC-002 RP-01 Active role enforcement vs union/separate-account model. STAB-007/017/025; W00/all sensitive Security + Product Chosen semantics, migration, conflict-role rules and tests approved.
DEC-003 RP-02/RP-03, PR-03 Capability taxonomy and tenant/company/school/class/assignment/self/child/cross-company policy. STAB-001–008,010–018,023–025,027/030/032 Security + DPO + domain owners Action/scope matrix signed and machine-readable acceptance updated.
DEC-004 PO-02, AM-01/AM-03 Process owner, maker-checker, delegation and conflict-of-interest. STAB-001–004,009–016 Product + Finance/HR/Academic/Operations/Security Named accountable owner and approval/delegation matrix per domain.
DEC-005 PO-03, ER-01–ER-03 Exception, recovery, escalation and irreversible-action ownership. STAB-009/012/019/029–031/035/039 Operations + Support + domain owners L1/L2/L3, recovery/compensating path, prohibited retries and SLA signed.
DEC-006 PO-01, AM-02, SG-02, ATT-D01–D17 W05 actors, completion/correction, status model, notification, privacy and exceptions. STAB-017–022/027/040; W05 Attendance PO + School SME + Security/DPO Complete W05 transition/role/field/privacy matrix and pilot exit criteria signed.
DEC-007 SG-01–SG-03 Canonical state glossary, irreversibility and correction/reversal semantics. STAB-003/009/012/019/020/030/033/035/040 Product Design + domain owners State/action/entry/exit/downstream/recovery table approved.
DEC-008 MD-01–MD-03 Master-data source/owner, matching/deletion and config effective dates. STAB-004/013/014/016/018/023/032 Data Steward + Integration/domain owners Field/record ownership, conflict and deletion/config policy approved.
DEC-009 PR-01/PR-02 Sensitive field, attachment/proof viewer, validation, retention/download/delete. STAB-001/002/005/006/010/012/021 DPO + Security + Storage/domain owners Purpose/field/viewer/retention matrix and threat controls approved.
DEC-010 NT-01–NT-03 Notification events, recipients, channel, dedupe, failure/retry and authoritative record. STAB-015/016/029/033 Communications + Operations + DPO Event-recipient-channel matrix, failure visibility and SLA approved.
DEC-011 LD-01–LD-03, CH-01–CH-03 Legacy/alias/deprecation and contextual-help delivery boundary. STAB-024–026/033/040/041 Product + Platform + Documentation Canonical IDs, sunset/redirect telemetry and hidden-surface rule approved.
DEC-012 RB-01–RB-03 Named runtime baseline, role fixtures and evidence threshold. STAB-007/017/024–028; CTRL-001–004 Operations + QA + Identity/RBAC Golden Tenant/versioned manifest/accounts and evidence policy approved.
DEC-013 No normalized prior workshop ID; exposed by current jenjang/timezone branch audit Approve the V1 certified school-profile set: jenjang/equivalence branches, supported IANA school timezones, and any profile-specific menu/workflow differences. W00 and every certified date-sensitive workflow/leaf mapped by CTRL-005; W01/W05/W06/W20 are the minimum known set; STAB-022/037/040; QG-01/04/05/12/17 Product + Operations + School SME + QA Signed profile matrix; one deterministic Golden profile per retained branch/timezone class; navigation, authorization, and date-boundary cases bound to the release manifest. No package inherits WIB or non-early-years proof without an approved equivalence mapping.
DEC-014 No normalized prior workshop ID; exposed by W00 exception-surface audit Approve the V1 credential lifecycle and recovery boundary: account activation, forced-password change, self/admin reset, unlock, expiry, concurrent-session revocation, recovery-channel ownership, break-glass eligibility, and audit/notification. Explicitly remove or hide every excluded surface. W00/W02 identity activation; STAB-007; E2E-GAP-12; QG-03/06/08/09/11/16 Product + Identity/RBAC + Security + Operations/Support + DPO for recovery data Signed state/action/actor/channel/token/session/audit matrix; fresh-role fixtures; retained paths have positive/negative/replay/expiry/revocation tests; excluded routes/actions are absent or denied.

Workshop source: docs/documentation-planning/decision-workshop.md:31-127. Recommended defaults remain proposals, not hidden engineering decisions.

8. Readiness controls and verification-only findings — no bug severity

Control Source finding Required work Owner Completion evidence
CTRL-001 BLK-A01, IA-026, RB-01/RB-02 Establish exact served runtime/product/role baseline and repeatable Golden Tenant; this is missing release evidence, not an application defect by itself. Release + Operations + QA Three deterministic seed/reset runs, exact FE/BE/DB/module/entitlement manifest, fresh-role login/menu/API snapshots.
CTRL-002 BLK-B05 Quarantine/supersede existing W05 user-guide claims until STAB-017–022/027 and DEC-006 pass. No final user documentation is produced in this task. Documentation Owner + Attendance PO Artifact inventory points to freeze status; no guide is treated as product contract. Evidence docs/documentation-planning/documentation-blockers.md:405-416.
CTRL-003 NB-01 Runtime-certify current weekly approval guards/company scope; static code improvement is not an open defect absent failing evidence. LMS Owner + QA Authorized approver, unrelated teacher/company, self-approval policy and audit/state tests tied to release build. Evidence docs/documentation-planning/documentation-blockers.md:480-491.
CTRL-004 NB-02 Runtime-certify LMS assignment idempotency, including concurrency where field uniqueness is not statically proved. LMS Owner + QA Same/concurrent token produces one record/side effect; timeout retry deterministic. Evidence docs/documentation-planning/documentation-blockers.md:492-502.
CTRL-005 E2E-GAP-01–E2E-GAP-12 Establish a truthful package denominator: map every retained canonical leaf/page to a named workflow/subflow and required release-test parameters, or narrow/remove it from the product contract. This is missing certification coverage, not proof of an application defect. Product + Package Owners + QA/Release Signed leaf→workflow→test manifest; all RT-PKG-GAP-* controls closed; package result denominator cannot omit an enabled surface or use a combined bridge as a standalone SKU certificate. Evidence 05 §8.1 and 07 §10.2.
CTRL-006 E2E-GAP-12; W00 credential exception surface Bound the credential lifecycle before release: retain only approved activation/change/reset/unlock/expiry/session-revocation/break-glass paths, assign recovery ownership, and create deterministic fresh-account/token/session fixtures. This is a decision/evidence gate, not a claim that every current path is defective. Product + Identity/RBAC + Security + Operations/Support + QA DEC-014 signed; route/action inventory maps every retained surface to W00 cases; excluded surface hidden/denied; RT-W00-REC-01 and RT-PKG-GAP-12 pass with token replay/expiry, session revocation, least privilege, safe notification and audit evidence. Code leads: src/router/adminShellRoutes.js:61-68, src/components/ChangePassword.vue:187-203, ../custom_addons_scola/gcgscola/scola_core/controllers/auth.py:367-400.

9. Trace reconciliation

9.1 Existing blocker register coverage

Source Normalized destination
BLK-A01 CTRL-001
BLK-A02–A04 STAB-007, STAB-008, STAB-001
BLK-A05–A17 STAB-009, STAB-002, STAB-010, STAB-011, STAB-003, STAB-012, STAB-004, STAB-005, STAB-013, STAB-014, STAB-006, STAB-015, STAB-016
BLK-A18 STAB-026
BLK-A19–A23 STAB-017–STAB-021
BLK-B01–B04 STAB-024/DEC-001, STAB-025/STAB-041, STAB-023, STAB-027
BLK-B05–B08 CTRL-002, STAB-029, STAB-030, STAB-031
BLK-B09 DEC-004/005/007 — auto-post behavior is confirmed, but desired approval/reversal is a product/finance decision until selected
BLK-B10–B11 STAB-032, STAB-033
NB-01/NB-02 CTRL-003/CTRL-004

Source index: docs/documentation-planning/documentation-blockers.md:41-76,78-502.

9.2 UX, authorization and IA audit coverage

Audit source Normalized destination
UX-001–UX-005 STAB-022, STAB-027, STAB-019, STAB-020, STAB-021
UX-006–UX-010 STAB-034, STAB-035, STAB-042, STAB-036, STAB-037
UX-011–UX-018 STAB-043, STAB-038, STAB-038, STAB-039, STAB-035, STAB-040, STAB-037, STAB-039
UX-019/UX-020 No defect; intentional differences remain gated by IC-01–IC-14 in docs/release-readiness/03-ux-consistency-audit.md.
AUTH-001–AUTH-004 STAB-007/STAB-008
AUTH-005–AUTH-012 Cross-cutting acceptance on STAB-001–STAB-027; exact BLK mapping is in docs/release-readiness/04-authorization-readiness.md.
AUTH-013/AUTH-014 STAB-007/017/023–028 plus CTRL-001–004
IA-001 STAB-024
IA-002–IA-005 STAB-025
IA-006/IA-007 STAB-026
IA-008 STAB-025
IA-009/IA-010 STAB-041/STAB-033
IA-011–IA-014 STAB-016/STAB-024/STAB-040
IA-015–IA-018 STAB-025
IA-019–IA-022 STAB-041
IA-023 STAB-024
IA-024 STAB-023
IA-025 STAB-027
IA-026 CTRL-001

IA evidence is defined in docs/release-readiness/02-information-architecture.md:169-194 under the exact IA IDs; no additional IA ID is invented here.

10. Backlog execution and closure contract

  1. Contain before repair: S0 and any directly exposed unsupported/placeholder surface is hidden/disabled for normal roles until fixed and tested. Containment is not closure.
  2. Decide before encoding: close linked DEC rows before implementing actor/state/approval/privacy semantics. Security deny-default and data-minimization do not wait for a permissive business decision.
  3. Fix by dependency: platform AUTH/package/IA defects (STAB-007/008/024/025/028) precede domain fixes; W01/W02 prerequisites precede W05; optional packages certify separately.
  4. One closure record: each defect records root cause, code/config/schema references, exact tests, before/after Golden Tenant result, owner review, and release manifest.
  5. No evidence-free downgrade: S0/S1 can only be downgraded after tests disprove the impact or scope is removed from product surface. A warning cannot close an authorization/privacy/data-integrity issue.
  6. Regression is mandatory: every row’s listed positive and negative tests join 07-release-test-matrix.md; required skipped/not-run cases fail the gate.
  7. Reconcile after decisions: selected DEC outcome must create explicit implementation/test deltas; decisions never auto-close linked defects.

Definition of backlog-ready for implementation

This backlog is ready to drive tranches when:

  • Product approves the relevant package/workflow boundary and every item has a named person/team owner;
  • DEC dependencies for the tranche have dated decisions;
  • each implementation unit is small enough to fix one root cause and carries the listed acceptance/regression IDs;
  • Golden Tenant prerequisites and second-tenant fixtures exist;
  • containment is active for open S0 and unsupported/incomplete surfaces;
  • no duplicate issue is implemented twice: BLK/UX/AUTH/IA references resolve to the single STAB row above; and
  • closure is judged by QG-01–QG-18 on one exact build, not by merging code alone.