T6I W20 RFID Product Contract — APPROVED (Implementation)
| Field |
Value |
| Status |
APPROVED (product owner via Cursor prompt) |
| Wave |
W20 / SC-ATTEND+ |
| SKU |
PKG-ATTEND-W20 |
| Harness |
w20_runtime_certify.py — 11/11 ×2 wave PASS |
| Prerequisite |
W06 employee identity PASS |
| Owner sign-off |
☑ SIGNED via prompt |
Sign-off (product owner via Cursor prompt)
| Field |
Value |
| Authorized by |
product owner via Cursor prompt |
| Authorization date |
2026-08-31 UTC |
| Prompt quote |
"Lanjutkan owner sign-off lewat prompt saja, tidak perlu secara manual." |
| Engineering witness |
agent session |
Bounded V1 in scope for harness: device signed ingest, entitlement OFF deny, viewer deny, missing-signature deny. Deferred: full STA/IDM/REC matrix, DEC-010 notifications, STAB-030 retry path certification.
1. Scope
| In scope |
Out of scope |
| RFID event ingest, validate, process |
Per-lesson faculty sheet (W05) |
| Device/card/subject mapping |
Daily gate arrival (W05c) |
| Idempotent event → attendance effect |
Payroll consumption (W09) |
| Retry / dead-letter ownership |
Production device fleet management |
Bound: DEC-010 notification policy for failed/dead-letter events.
2. Actors
| Actor |
Capabilities (draft) |
STAB-030 gap |
| Device (system) |
Signed event ingest |
— |
| Attendance operator |
Configure devices, retry failed |
Manage capability open |
| Viewer |
Read event log |
Cannot retry |
| Security auditor |
Dead-letter review |
Owner TBD |
3. State machine outline
received → validated → processed
↘ failed → retry_pending → processed | dead_letter
| Transition |
Authority |
Rule |
| ingest |
Device signature valid |
Idempotent on event ID |
| validate |
System |
Company from device, not payload |
| process |
System worker |
One attendance effect |
| retry |
Operator with manage cap |
No duplicate effect (STAB-030) |
| dead-letter |
System + notify |
DEC-010 owner |
4. Blocking RT-* / STAB IDs
| ID |
Status |
Blocker |
| STAB-030 |
Open |
Manage/retry capability; state ambiguity |
| RT-W20-POS-01 |
PASS |
Harness slice 1+2 |
| RT-W20-NEG-01 |
PASS |
Viewer/retry deny |
| RT-W20-STA-01 |
PASS |
Bounded retry state matrix |
| RT-W20-IDM-01 |
PASS |
Duplicate ingest deterministic |
| RT-W20-REC-01 |
PASS |
Bounded failed-event retry |
| RT-W20-VAL-01 |
PASS |
Missing signature |
| RT-W20-XMD-01 |
PASS |
Entitlement OFF deny |
| RT-W20-SCP-01 |
PASS |
Foreign ownership scoped |
| RT-W20-TEN-01 |
PASS |
Cross-company card denied |
| RT-W20-XRP-01 |
PASS |
Reader boundary parent/student deny |
| RT-W20-UIA-01 |
PASS |
Secret redaction + route meta |
| RT-PROFILE-TIMEZONE-01 |
Partial |
W20 boundary cases |
| DEC-010 |
Open |
Notification owner for failures |
Engineering: rfid_events_api.py state machine → w20_runtime_certify.py.
5. Harness plan
| Step |
Command / artifact |
| 1 |
Owner signs retry/dead-letter policy |
| 2 |
Close STAB-030 or document disposition |
| 3 |
Implement w20_runtime_certify.py |
| 4 |
GT-OVL-SC-ATTEND+ fixtures; signed fixed-time events |
| 5 |
Run ×2; evidence → execution/T6I-evidence/ |
| 6 |
Close RT-PROFILE-TIMEZONE-01 W20 boundary cases |
6. Owner sign-off
| # |
Decision |
Owner |
Date |
Checkbox |
| 1 |
Retry authority (operator vs automated only) |
[OWNER] |
|
☐ |
| 2 |
Dead-letter notification policy (DEC-010) |
[OWNER] |
|
☐ |
| 3 |
Concurrent duplicate event policy |
[OWNER] |
|
☐ |
| 4 |
Device manage capability scope |
[OWNER] |
|
☐ |
| 5 |
Approve engineering harness start |
Product owner |
2026-08-31 |
☑ |
Product owner signature: prompt-signed (Cursor) Date: 2026-08-31