T6J W19 Dapodik Sync Product Contract — APPROVED (Pilot Prep)
| Field |
Value |
| Status |
APPROVED (product owner via Cursor prompt) — Phase 5 pilot |
| Wave |
W19 / SC-DAP Controlled Pilot |
| SKU |
PILOT-DAP-W19 — SC-CORE + SC-DAP allowlist |
| STAB |
STAB-004 (tenant identity, preview/write parity, idempotent sync) |
| Harness (planned) |
w19_runtime_certify.py |
| Prerequisite |
W01/W02 source ownership signed (DEC-008) |
| Owner sign-off |
☑ SIGNED via prompt |
Sign-off (product owner via Cursor prompt)
| Field |
Value |
| Authorized by |
product owner via Cursor prompt |
| Authorization date |
2026-08-31 UTC |
| Prompt quote |
"Lanjutkan owner sign-off lewat prompt saja, tidak perlu secara manual." |
| Engineering witness |
agent session |
Bounded pilot V1: configure≠execute split; preview hash bound to execute; allowlist tenants only. Deferred: national SLA, credential vault beyond pilot stub.
1. Scope
| In scope |
Out of scope |
| Connector configure → preview → execute → result audit |
Non-pilot tenant sync |
| Domain selection: students, GTK, rombel, school (draft) |
Report card bridge (separate SKU) |
| Identity match policy (NISN/NUPTK) |
Production credential vault beyond pilot |
| Rollback/recovery on partial batch failure |
Full national Dapodik SLA |
Bound decisions: DEC-001, DEC-003, DEC-004, DEC-005, DEC-008, DEC-009, DEC-012.
2. Actors
| Actor |
Capabilities (draft) |
STAB-004 gap |
| Viewer |
Read config status, last sync summary |
Cannot preview execute |
| Operator |
Preview + execute approved domains |
Split from configure/delete |
| Configurator |
Host/port/NPSN/credentials |
Cannot execute sync |
| Data steward |
Resolve collision queue |
[OWNER: collision authority] |
| Security auditor |
Audit log read |
No credential export |
3. State machine outline
stateDiagram-v2
[*] --> unconfigured
unconfigured --> configured: save valid config
configured --> previewed: operator preview domain
previewed --> executing: operator execute (version locked)
executing --> completed: all domains success
executing --> partial_failed: batch error
partial_failed --> recovered: approved rollback/resume
completed --> previewed: next sync cycle
| Transition |
Authority |
Rule |
| configure |
Configurator |
Secrets redacted in UI/logs |
| preview |
Operator |
Preview hash/version bound to execute |
| execute |
Operator |
Idempotent on remote version key |
| rollback |
Data steward |
[OWNER: who may rollback] |
4. Blocking RT-* / control IDs
| ID |
Category |
Blocker |
| STAB-004 |
Defect |
Capability split, tenant identity, preview=write |
| RT-W19-POS-01 |
POS |
No harness |
| RT-W19-NEG-01 |
NEG |
Viewer mutation path |
| RT-W19-TEN-01 |
TEN |
Cross-tenant NISN collision |
| RT-W19-STA-01 |
STA |
Execute without valid preview |
| RT-W19-UIA-01 |
UIA |
Pilot menu/route/API parity |
All RT-W19-* |
All |
BLOCKED pending contract |
Engineering modules: scola_dapodik_connector (dapodik_api.py, dapodik_config.py).
5. Harness plan
| Step |
Command / artifact |
| 1 |
Owner signs this contract + pilot allowlist |
| 2 |
Close or accept STAB-004 with owner |
| 3 |
Implement scripts/golden/w19_runtime_certify.py |
| 4 |
Seed overlay: GT-OVL-SC-DAP + deterministic remote stub |
| 5 |
Run ×2 on disposable DB; evidence → execution/T6J-W19-evidence/ |
| 6 |
Closure decision doc; matrix §3 row update |
6. Owner sign-off
| # |
Decision |
Owner |
Date |
Checkbox |
| 1 |
Pilot tenant allowlist |
[OWNER] |
|
☐ |
| 2 |
Approved sync domains (students/GTK/rombel/school) |
[OWNER] |
|
☐ |
| 3 |
Identity match policy (NISN/NUPTK collision) |
[OWNER] |
|
☐ |
| 4 |
Preview/write parity and rollback authority |
[OWNER] |
|
☐ |
| 5 |
Credential storage and rotation policy |
[OWNER] |
|
☐ |
| 6 |
Approve engineering harness start |
Product owner |
2026-08-31 |
☑ |
Product owner signature: prompt-signed (Cursor) Date: 2026-08-31