{"schemaVersion":"mappls.capability-qualification.v1","id":"offline-automotive--automotive--qualification","matrixCellId":"offline-automotive--automotive","product":{"slug":"offline-automotive","name":"Offline & Automotive","summary":"Offline maps, search, routing, guidance, compilers, and embedded navigation runtimes.","category":"Embedded","accent":"#d6a600"},"platform":{"slug":"automotive","name":"Automotive","headline":"Treat in-vehicle navigation as a safety-aware, upgradeable system—not a screen."},"status":"ready-to-qualify","stateModel":"stateful","integrationLane":"entitled-runtime","decision":{"availability":"listed","evidenceStatus":"listed-with-exact-evidence","exactEvidence":[{"kind":"tutorial","fidelity":"exact-product-platform","slug":"offline-package-update","title":"Design an interruption-safe offline map update","href":"/tutorials/offline-package-update"},{"kind":"tutorial","fidelity":"exact-product-platform","slug":"linux-map-client","title":"Operate a Mappls client on embedded Linux","href":"/tutorials/linux-map-client"}],"supportingEvidence":[{"kind":"quickstart","fidelity":"platform-adjacent","slug":"automotive-navigation","title":"Simulate one recoverable navigation session","href":"/quickstart/automotive-navigation"},{"kind":"starter-kit","fidelity":"platform-adjacent","slug":"automotive-navigation-starter","title":"Automotive release-manifest starter","href":"/starter-kits/automotive-navigation-starter"},{"kind":"sample-app","fidelity":"product-adjacent","slug":"offline-release-control","title":"Offline Release Control","href":"/samples/offline-release-control"},{"kind":"journey","fidelity":"product-adjacent","slug":"offline-automotive-release","title":"Offline automotive release","href":"/journeys/offline-automotive-release"}],"boundary":"Listed means this product names the platform in the canonical catalog. Source evidence, repository activity, fixtures, tutorials, and successful builds still do not prove package availability, account entitlement, runtime compatibility, region, quota, support, or production approval."},"authenticationCandidates":[{"slug":"offline-device-activation","title":"Offline and automotive activation","runtime":"device","generation":"Entitled runtime and data release","visibility":"entitlement-specific","evidenceBoundary":"The public snapshot does not establish a universal offline/automotive credential or safety contract. Entitled release material is authoritative.","href":"/authentication#offline-device-activation"}],"identityLock":["Product and platform decision ID","Account and environment reference","Region and data-residency decision","Hardware/OS/runtime and protected distribution identity","License or entitlement reference—not its contents","Artifact checksum, update channel, and rollback owner","Source/distribution fingerprint and release owner","Quota, support, incident, rollback, and retirement owners"],"scenarios":[{"id":"clean-build","title":"Clean build and identity lock","purpose":"Prove the selected source, distribution, toolchain, and runtime identity from a clean environment.","expectedEvidence":"Checksums, dependency lock, build log, runtime identity, and exact evidence links agree without workstation-only state.","recovery":"Stop qualification, reconcile the exact distribution or contract, and rebuild from a clean environment."},{"id":"fixture-success","title":"Deterministic fixture success","purpose":"Exercise the application adapter without credentials or provider traffic.","expectedEvidence":"The fixture produces the documented application contract and retains source identity plus state ownership.","recovery":"Fix the application boundary before requesting account access; a live call must not compensate for an unproven adapter."},{"id":"authentication-denied","title":"Missing, denied, expired, and revoked access","purpose":"Prove least-privilege failure without logging, reflecting, or weakening credential controls.","expectedEvidence":"Every access failure is classified, redacted, bounded, and routes to entitlement or credential reconciliation.","recovery":"Stop retries, preserve only safe request evidence, and reconcile the issued account contract independently."},{"id":"quota-unavailable","title":"Quota, timeout, offline, and service unavailability","purpose":"Prove bounded retry, fallback, and user-visible degradation for the exact operation safety class.","expectedEvidence":"Retry-After is honored where present; uncertain state changes never become blind retries.","recovery":"Use bounded backoff for safe reads and reconcile state-changing unknown outcomes before replay."},{"id":"upgrade-rollback","title":"Upgrade, downgrade, and rollback","purpose":"Prove that source, SDK, wrapper, schema, and runtime changes are independently reversible.","expectedEvidence":"Compatibility evidence names both versions, acceptance results, rollback trigger, and retained data/state behavior.","recovery":"Freeze rollout, restore the last qualified artifact, and reopen source and entitlement selection."},{"id":"idempotent-replay","title":"Idempotent command replay","purpose":"Repeat one stable command identity after a committed or uncertain result.","expectedEvidence":"The aggregate version and application event identity do not duplicate.","recovery":"Reconcile by stable business and provider identity before any new command."},{"id":"stale-version","title":"Stale version and concurrent actor","purpose":"Prevent an older actor or callback from overwriting newer durable truth.","expectedEvidence":"The stale transition is rejected without state mutation or event emission.","recovery":"Reload the current aggregate, re-evaluate policy, and require a new attributable decision."},{"id":"unknown-outcome","title":"Unknown provider outcome","purpose":"Separate timeout from failure and preserve a recoverable pending state.","expectedEvidence":"The application records the attempt, reconciles provider truth, and completes or retries without duplication.","recovery":"Do not infer success or failure; reconcile using the exact issued operation and durable identity."},{"id":"restart-recovery","title":"Restart and delayed evidence","purpose":"Recover application-owned state after process restart and reject late or superseded callbacks.","expectedEvidence":"The journey resumes from durable records and preserves generation, actor, and event ordering.","recovery":"Rebuild the read model from immutable application evidence and quarantine ambiguous callbacks."}],"phases":[{"id":"select-authority","title":"Lock source and product authority","owner":"Product owner + application technical owner","state":"actionable","objective":"Resolve the exact product, platform, source, distribution, generation, account, region, and owner before code or access is approved.","activities":["Review exact evidence separately from adjacent learning material.","Record every unresolved package, endpoint, callback, entitlement, and version question.","Keep not-listed and selection-required decisions blocked until an attributable owner supplies exact evidence."],"exitEvidence":["Immutable product-platform decision","Exact source/distribution identities and fingerprints","Named product, security, application, and release owners"],"blockedBy":[]},{"id":"lock-runtime","title":"Lock runtime and authentication","owner":"Application owner + security","state":"actionable","objective":"Bind the runtime identity to one authentication generation and least-privilege placement without accepting a credential value.","activities":["Record the runtime identity fields for this integration lane.","Choose one issued authentication path and document forbidden placement.","Define non-production restrictions, rotation, redaction, and incident ownership."],"exitEvidence":["Runtime compatibility decision","Credential class and restriction record","Secret/public-value placement review"],"blockedBy":[]},{"id":"prove-fixture","title":"Prove the application contract offline","owner":"Application team","state":"actionable","objective":"Exercise a deterministic adapter and every application-owned invariant before provider access.","activities":["Run the clean-build and fixture-success scenarios.","Normalize provider-shaped data at the adapter edge and keep opaque objects out of durable state.","Prove denial, quota, unavailable, upgrade, and rollback behavior with fixtures."],"exitEvidence":["Fixture results tied to the source lock","Application contract/schema","Failure and rollback evidence"],"blockedBy":[]},{"id":"qualify-nonproduction","title":"Qualify issued non-production access","owner":"Product owner + application team","state":"external-evidence-required","objective":"Run the smallest read or explicitly approved test journey against an issued non-production account without exporting secrets or sensitive payloads.","activities":["Confirm account, entitlement, host, region, quota, and exact operation/distribution.","Capture credential-free conformance results and safe request identities.","Compare live shape and failure classification to the locked application contract."],"exitEvidence":["Signed or attributable product-owner decision","Credential-free conformance report","Account/region/quota/entitlement reference","Observed compatibility and divergence record"],"blockedBy":["Issued non-production account and approved provider contract are external requirements."]},{"id":"exercise-journey","title":"Exercise lifecycle and hostile paths","owner":"Application team + operations","state":"external-evidence-required","objective":"Prove complete success, denial, degradation, recovery, restart, and rollback behavior at the integration's true state depth.","activities":["Execute every published qualification scenario.","For hybrid/stateful work, prove replay, stale-version, unknown-outcome, and restart recovery.","Verify telemetry, quota alarms, support evidence, cleanup, and rollback."],"exitEvidence":["Scenario-by-scenario result ledger","State/reconciliation evidence where applicable","Alert, runbook, support, cleanup, and rollback evidence"],"blockedBy":["Operational telemetry and provider-degradation exercises require an approved environment."]},{"id":"approve-release","title":"Independent release and deployment","owner":"Independent security + operations + product release owners","state":"external-evidence-required","objective":"Freeze the qualified artifact and collect independent authority without allowing developer evidence to self-approve production.","activities":["Attach exact artifacts to the governed release workflow.","Review security/privacy, product conformance, operations, quota, regional, legal, and rollback evidence.","Use progressive deployment and independently reconcile production health."],"exitEvidence":["Immutable release artifact and evidence digests","Independent approvals","Progressive deployment, rollback, and post-release reconciliation evidence"],"blockedBy":["This catalog never grants entitlement, support, production release, or deployment authority."]}],"releaseEvidence":["Exact source, package/distribution, contract generation, and runtime identity","Issued account, entitlement, region, quota, and credential-class reference without secret values","Clean build, fixture, non-production conformance, hostile-path, upgrade, and rollback results","Security, privacy, accessibility, operational, legal/content, and product-owner decisions","Immutable release artifact digest, progressive deployment evidence, and independent post-release reconciliation"],"handoff":{"websitePath":"/platforms/qualify?product=offline-automotive&platform=automotive","apiPath":"/api/capability-qualifications?product=offline-automotive&platform=automotive","downloadPath":"/api/capability-qualifications?product=offline-automotive&platform=automotive&download=1","matrixPath":"/platforms/matrix?product=offline-automotive&platform=automotive","productPath":"/docs/offline-automotive","platformPath":"/platforms/automotive"},"safety":{"providerCalls":0,"credentialsAccepted":false,"providerPayloadsAccepted":false,"writesExposed":false,"productionApprovalGranted":false}}