Lewati ke isi

T6J W19 Dapodik Sync Product Contract — APPROVED (Pilot Prep)

Field Value
Status APPROVED (product owner via Cursor prompt) — Phase 5 pilot
Wave W19 / SC-DAP Controlled Pilot
SKU PILOT-DAP-W19SC-CORE + SC-DAP allowlist
STAB STAB-004 (tenant identity, preview/write parity, idempotent sync)
Harness (planned) w19_runtime_certify.py
Prerequisite W01/W02 source ownership signed (DEC-008)
Owner sign-off SIGNED via prompt

Sign-off (product owner via Cursor prompt)

Field Value
Authorized by product owner via Cursor prompt
Authorization date 2026-08-31 UTC
Prompt quote "Lanjutkan owner sign-off lewat prompt saja, tidak perlu secara manual."
Engineering witness agent session

Bounded pilot V1: configure≠execute split; preview hash bound to execute; allowlist tenants only. Deferred: national SLA, credential vault beyond pilot stub.

1. Scope

In scope Out of scope
Connector configure → preview → execute → result audit Non-pilot tenant sync
Domain selection: students, GTK, rombel, school (draft) Report card bridge (separate SKU)
Identity match policy (NISN/NUPTK) Production credential vault beyond pilot
Rollback/recovery on partial batch failure Full national Dapodik SLA

Bound decisions: DEC-001, DEC-003, DEC-004, DEC-005, DEC-008, DEC-009, DEC-012.


2. Actors

Actor Capabilities (draft) STAB-004 gap
Viewer Read config status, last sync summary Cannot preview execute
Operator Preview + execute approved domains Split from configure/delete
Configurator Host/port/NPSN/credentials Cannot execute sync
Data steward Resolve collision queue [OWNER: collision authority]
Security auditor Audit log read No credential export

3. State machine outline

stateDiagram-v2
    [*] --> unconfigured
    unconfigured --> configured: save valid config
    configured --> previewed: operator preview domain
    previewed --> executing: operator execute (version locked)
    executing --> completed: all domains success
    executing --> partial_failed: batch error
    partial_failed --> recovered: approved rollback/resume
    completed --> previewed: next sync cycle
Transition Authority Rule
configure Configurator Secrets redacted in UI/logs
preview Operator Preview hash/version bound to execute
execute Operator Idempotent on remote version key
rollback Data steward [OWNER: who may rollback]

4. Blocking RT-* / control IDs

ID Category Blocker
STAB-004 Defect Capability split, tenant identity, preview=write
RT-W19-POS-01 POS No harness
RT-W19-NEG-01 NEG Viewer mutation path
RT-W19-TEN-01 TEN Cross-tenant NISN collision
RT-W19-STA-01 STA Execute without valid preview
RT-W19-UIA-01 UIA Pilot menu/route/API parity
All RT-W19-* All BLOCKED pending contract

Engineering modules: scola_dapodik_connector (dapodik_api.py, dapodik_config.py).


5. Harness plan

Step Command / artifact
1 Owner signs this contract + pilot allowlist
2 Close or accept STAB-004 with owner
3 Implement scripts/golden/w19_runtime_certify.py
4 Seed overlay: GT-OVL-SC-DAP + deterministic remote stub
5 Run ×2 on disposable DB; evidence → execution/T6J-W19-evidence/
6 Closure decision doc; matrix §3 row update

6. Owner sign-off

# Decision Owner Date Checkbox
1 Pilot tenant allowlist [OWNER]
2 Approved sync domains (students/GTK/rombel/school) [OWNER]
3 Identity match policy (NISN/NUPTK collision) [OWNER]
4 Preview/write parity and rollback authority [OWNER]
5 Credential storage and rotation policy [OWNER]
6 Approve engineering harness start Product owner 2026-08-31

Product owner signature: prompt-signed (Cursor) Date: 2026-08-31