{"version":"2026.08","globalSearch":{"api":"/api/search","destinations":714,"scopes":["all","reference","build","learn"],"boundary":{"indexedFields":["title","description","eyebrow","keywords","canonical path"],"queryProcessing":"browser-local","queryLogging":false,"queryAnalytics":false,"providerCalls":0,"maximumQueryCharacters":160,"maximumRenderedResults":12}},"apiSandbox":{"href":"/sandbox","api":"/api/sandbox","operations":162,"scenarios":["success","empty","validation-error","auth-error","rate-limit","server-error"],"providerCredentialsAccepted":false,"providerNetworkCalls":false},"sdkCatalog":{"href":"/sdks","api":"/api/sdks","summary":{"entries":58,"sourceSdks":24,"binaryDistributions":34,"platforms":{"Android":7,"Cordova/Ionic":1,"Flutter":2,"REST":1,"React Native":4,"Web":4,"iOS":40},"maturity":{"current":13,"deprecated":10,"distribution":34,"legacy":1},"readiness":{"do-not-start":10,"entitlement-and-compatibility-review":34,"migration-required":1,"source-ready-after-validation":13},"withInstallEvidence":41,"withSourceSamples":40}},"authentication":{"href":"/authentication","api":"/api/authentication","summary":{"paths":14,"runtimes":10,"products":10,"noCredential":1,"publicRestricted":3,"trustedOrEntitled":10,"normalizedOperationsConsidered":162},"providerCredentialsAccepted":false},"errorsAndDiagnostics":{"href":"/errors","api":"/api/errors","console":"/console/logs","summary":{"classes":11,"runtimes":8,"normalizedOperationsConsidered":162,"operationsWithResponseEvidence":162,"documentedResponseStatuses":["200","201","203","204","206","400","401","403","404","405","406","409","412","422","500","503"],"maintainedSdkCodeSignals":51},"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"developerSupportRequests":{"tenant":"/console/support","tenantApi":"/api/support-requests","tenantTransitionApiTemplate":"/api/support-requests/{supportRequestId}","admin":"/admin/support","adminApi":"/api/admin/support-requests","adminTransitionApiTemplate":"/api/admin/support-requests/{supportRequestId}","repositoryDocumentation":"docs/DEVELOPER_SUPPORT_REQUESTS.md","categories":["integration","authentication","entitlement","request_failure","stateful_journey","usage_quota","webhook","other"],"severities":["standard","degraded","blocked"],"statuses":["submitted","acknowledged","resolved","cancelled"],"actions":["cancel","acknowledge","resolve"],"boundary":"A support request is a tenant-owned communication record. It does not grant Mappls access to credentials, payloads, precise locations, customer data, provider systems, or your application. Any investigation that needs privileged diagnostic access requires a separate, purpose-bound support case, step-up authentication, explicit scope, and an expiring delegated session.","optimisticVersions":true,"immutableEvents":true,"applicationOwnershipRequired":true,"dailySubmissionLimit":10,"openRequestLimit":20,"investigationAuthorized":false,"supportCaseCreated":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"organizationAccessRequests":{"publicEntry":"/get-started","publicApi":"/api/organization-requests","cancellationApiTemplate":"/api/organization-requests/{requestId}","admin":"/admin/organization-requests","adminApi":"/api/admin/organization-requests","adminReviewApiTemplate":"/api/admin/organization-requests/{requestId}","approvedOwnerHandoffTemplate":"/admin/developers#developer-{developerId}","repositoryDocumentation":"docs/ORGANIZATION_REQUESTS.md","statuses":["submitted","approved","rejected","cancelled"],"adminCapabilities":["search-safe-fields","filter-status","inspect-immutable-timeline","approve-exact-version","reject-exact-version","continue-to-separate-owner-activation"],"dailyBrowserLimit":3,"openPerNormalizedEmailOrCompany":1,"ownership":"signed-http-only-browser-session","emailIsAuthority":false,"optimisticVersions":true,"immutableEvents":true,"independentSteppedUpReview":true,"approvalCreates":["active-organization","verified-profile","development-project"],"approvalDoesNotCreate":["sign-in-authority","credentials","entitlements","production-approval"],"ownerActivationSeparate":true,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false},"environmentsAndDeployment":{"href":"/environments","api":"/api/environments","console":"/console/environments","admin":"/admin/environments","summary":{"persistedEnvironments":3,"executionModes":2,"controls":11,"rule":"Promote code and immutable configuration references—not credentials, provider identities, durable data, or unverified state—from one environment to another."},"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"organizationOwnerActivation":{"admin":"/admin/developers","issueApiTemplate":"/api/admin/developers/{developerId}/owner-invitation","acceptanceEntry":"/auth/login?invitationToken={oneTimeToken}","postClaimConsole":"/console/get-started","repositoryDocumentation":"docs/ORGANIZATION_OWNER_ACTIVATION.md","prerequisite":"active-approved-organization","role":"owner","identityRole":"org_admin","lifetimeDays":7,"tokenBytes":32,"persistedTokenForm":"sha256-digest-only","sensitiveAdminOperation":"organization_owner.invite","identityAuthority":"verified-oidc-issuer-subject","emailIsAuthority":false,"oneUse":true,"reissueRotatesUnclaimedToken":true,"secondActiveOwnerAllowed":false,"atomicRosterBindingLifecycleAndAudit":true,"externalDirectoryCompletionImplied":false},"teamInvitation":{"console":"/console/team","issueApi":"/api/team","acceptanceEntry":"/auth/login?invitationToken={oneTimeToken}","repositoryDocumentation":"docs/TEAM_ACCESS.md","lifetimeDays":7,"tokenBytes":32,"persistedTokenForm":"sha256-digest-only","statuses":["pending","accepted","cancelled","expired-effective"],"identityAuthority":"verified-oidc-issuer-subject","emailIsAuthority":false,"oneUse":true,"atomicRosterAndBinding":true,"externalDirectoryCompletionImplied":false},"teamOwnershipTransfer":{"console":"/console/team","tenantApi":"/api/team/ownership-transfers","tenantTransitionApiTemplate":"/api/team/ownership-transfers/{transferId}","admin":"/admin/access","adminApi":"/api/admin/team-ownership-transfers","repositoryDocumentation":"docs/TEAM_OWNERSHIP_TRANSFER.md","statuses":["pending","accepted","declined","cancelled","expired"],"actions":["accept","decline","cancel"],"lifetimeDays":7,"requester":"current-active-owner","nominee":"named-active-administrator","separation":["outgoing-governed-identity","incoming-governed-identity"],"optimisticTransferVersion":true,"optimisticRosterVersions":true,"exactlyOneOwner":true,"immutableEvents":true,"platformOverrideExposed":false,"tenantIdentityBindingsExposed":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"accessCertification":{"console":"/console/team","tenantApi":"/api/team/access-certifications","tenantDecisionApiTemplate":"/api/team/access-certifications/{campaignId}/items/{itemId}","admin":"/admin/access","adminApi":"/api/admin/access-certifications","adminDecisionApiTemplate":"/api/admin/access-certifications/{campaignId}/items/{itemId}","adminCancelApiTemplate":"/api/admin/access-certifications/{campaignId}","repositoryDocumentation":"docs/ACCESS_CERTIFICATION.md","statuses":["open","completed","completed_with_actions","cancelled","expired"],"decisions":["retain","remediate"],"reviewLanes":["tenant_owner","platform_admin"],"lifetimeDays":{"minimum":7,"maximum":90},"immutableSnapshots":true,"optimisticItemVersions":true,"directAccessMutation":false,"remediationIsCompletionProof":false,"tenantIdentityBindingsExposed":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"accessRemediation":{"console":"/console/team","tenantApi":"/api/team/access-remediations","tenantActionApiTemplate":"/api/team/access-remediations/{remediationId}","admin":"/admin/access","adminApi":"/api/admin/access-remediations","adminTransitionApiTemplate":"/api/admin/access-remediations/{remediationId}","repositoryDocumentation":"docs/ACCESS_REMEDIATION.md","statuses":["requested","assigned","action_recorded","verified","overdue"],"correctiveActions":["suspend_member","set_member_role","transfer_ownership","revoke_identity"],"dueDays":{"minimum":1,"maximum":60},"separation":["operator","verifier"],"optimisticVersions":true,"immutableEvents":true,"sourceLedgerConvergenceRequired":true,"directAccessMutation":false,"actionRecordIsCompletionProof":false,"tenantIdentityBindingsExposed":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"identityLifecycleReconciliation":{"admin":"/admin/access","adminApi":"/api/admin/identity-lifecycle","adminRetryApiTemplate":"/api/admin/identity-lifecycle/{operationId}","signedProviderResultApi":"/api/internal/identity-lifecycle-events","repositoryDocumentation":"docs/IDENTITY_LIFECYCLE_RECONCILIATION.md","operations":["provision","reactivate","deprovision"],"statuses":["requested","succeeded","failed"],"exactBindingVersion":true,"optimisticVersions":true,"immutableProviderEvents":true,"idempotentSignedResults":true,"deprovisionRequiresSessionRevocationConfirmation":true,"callbackCanMutateLocalBinding":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"privilegedAccess":{"admin":"/admin/access","dashboardApi":"/api/admin/privileged-access","stepUpChallengeApi":"/api/admin/step-up-challenges","delegationApi":"/api/admin/support-delegations","delegationActionApiTemplate":"/api/admin/support-delegations/{delegationId}","supportSessionApiTemplate":"/api/admin/support-delegations/{delegationId}/session","delegatedView":"/support/delegated","repositoryDocumentation":"docs/PRIVILEGED_ACCESS.md","actionClasses":["support_delegation_request","support_delegation_approval","support_session_start","emergency_access_activation","emergency_access_review","sensitive_admin_change"],"sensitiveAdminOperations":["developer.provision","developer.approve","developer.suspend","developer.resume","organization_owner.invite","organization_request.approve","organization_request.reject","identity_binding.create","identity_binding.revoke","identity_binding.reactivate","application.provision","entitlement_request.approve","entitlement_request.reject","entitlement.update","entitlement_drift.acknowledge","entitlement_drift.request_remediation","incident.declare","incident.identified","incident.monitoring","incident.resolved","incident.postmortem.publish","support_case.create","support_case.close","release_record.create","release_record.evidence","release_record.submit_review","release_record.cancel","release_record.approve","release_record.reject","release_handoff.accept","release_handoff.reject","release_deployment.create","release_deployment.authorize","release_deployment.start_canary","release_deployment.advance","release_deployment.begin_observation","release_deployment.reconcile","release_deployment.rollback","release_deployment.cancel","plan.create","rate_card.create","rate_card.activate","invoice.generate","invoice.adjust","invoice.finalize","billing_dispute.accept","billing_dispute.reject","outbox.replay","webhook_policy.update","slo_policy.update","identity_lifecycle.retry","application_retirement.approve","application_retirement.reject","application_retirement.retry","mcp_client.approve","mcp_client.reject","webhook_replay_request.approve","webhook_replay_request.reject","documentation_evidence.create","documentation_evidence.submit","documentation_evidence.approve","documentation_evidence.reject","documentation_evidence.cancel","documentation_feedback.triage","documentation_feedback.submit","documentation_feedback.approve","documentation_feedback.reject","documentation_feedback.dismiss","access_certification.create","access_certification.cancel","access_certification_item.retain","access_certification_item.remediate","access_remediation.assign","access_remediation.record_action","access_remediation.verify","data_resilience.create","data_resilience.authorize","data_resilience.start","data_resilience.submit_evidence","data_resilience.reconcile","data_resilience.fail","data_resilience.cancel","data_lifecycle.create","data_lifecycle.authorize","data_lifecycle.start","data_lifecycle.submit_evidence","data_lifecycle.reconcile","data_lifecycle.fail","data_lifecycle.cancel","data_practice.approve","data_practice.reject"],"sensitiveAdminBinding":["canonical_request_sha256","operation","target_type","target_id","target_version","actor_subject","identity_binding_version"],"delegationModes":["standard","emergency"],"capabilities":["organization_metadata:read","application_metadata:read","operations_evidence:read"],"standardMaximumMinutes":30,"emergencyMaximumMinutes":15,"emergencyPostReviewHours":24,"oneUseStepUpAssertions":true,"independentStandardApproval":true,"independentEmergencyPostReview":true,"baseRoleMutation":false,"customerImpersonation":false,"writesExposed":false,"credentialsExposed":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"agentIntegrations":{"href":"/ai/agents","api":"/api/agent-integrations","summary":{"patterns":6,"governanceControls":12,"evaluationDimensions":8,"mcpToolProfiles":2,"writeTools":0,"rule":"Give an agent only the offline or live-read Mappls tools required for one declared purpose; keep credentials, durable state, approval, and consequential action outside model context."},"patterns":[{"slug":"developer-research","title":"Developer integration assistant","recommendedMode":"offline","sample":"/samples/spatial-agent"},{"slug":"place-concierge","title":"Place discovery concierge","recommendedMode":"live-read","sample":"/samples/store-locator"},{"slug":"route-decision","title":"Route decision assistant","recommendedMode":"live-read","sample":"/samples/trip-planner"},{"slug":"fleet-operations","title":"Fleet operations copilot","recommendedMode":"live-read","sample":"/samples/delivery-control-tower"},{"slug":"field-operations","title":"Field operations analyst","recommendedMode":"live-read","sample":"/samples/field-service"},{"slug":"release-review","title":"Compatibility and release reviewer","recommendedMode":"offline","sample":"/samples/offline-release-control"}],"providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"writesExposed":false},"journeySimulator":{"href":"/tools/journey-lab","api":"/api/journey-simulator","summary":{"journeys":18,"scenarios":5,"fixturePaths":90,"states":132,"transitions":140,"codeLanguages":6,"providerCalls":0,"writesExposed":false},"scenarios":[{"slug":"complete-journey","title":"Complete journey","outcome":"Commit the shortest reviewed success path to the journey-specific operating target."},{"slug":"idempotent-replay","title":"Idempotent replay","outcome":"Repeat one command identity and prove that version, event identity, and side effects do not duplicate."},{"slug":"stale-version","title":"Stale version","outcome":"Reject a command based on an outdated aggregate version without changing durable truth."},{"slug":"invalid-transition","title":"Invalid transition","outcome":"Reject a known command when the current state does not permit it."},{"slug":"unknown-outcome","title":"Unknown outcome recovery","outcome":"Reconcile after a lost response, then replay the original command identity safely."}],"profiles":[{"slug":"field-service-task","title":"Field-service task lifecycle","productSlug":"workmate","aggregate":"task","stateModel":"stateful","initialState":"unassigned","targetState":"completed","creationCommand":"create_task","commands":["create_task","assign","accept","start_travel","arrive","submit_proof","approve_proof"],"events":["task.created","task.assigned","task.accepted","task.en_route","task.started","task.proof_submitted","task.completed"],"sourceGuideSlugs":["mapmyindia-workmate-apis","mappls-workmate-android-sdk"],"contractSlugs":["workmate-post-tasks-to-create-new-task","workmate-get-tasks-taskid-to-get-the-task-details-for-the-given-task-id","workmate-put-tasks-taskid-to-update-the-task-description-status","workmate-get-users-to-get-all-the-user-details-which-belongs-to-your-organization","workmate-get-clients-to-get-all-your-client-details"],"sampleSlug":"field-service"},{"slug":"connected-fleet-trip","title":"Connected fleet trip","productSlug":"intouch-telematics","aggregate":"trip","stateModel":"stateful","initialState":"planned","targetState":"closed","creationCommand":"create_trip","commands":["create_trip","confirm_device_ready","start_trip","request_close","close_trip"],"events":["trip.created","trip.ready","trip.started","trip.close_requested","trip.closed"],"sourceGuideSlugs":["mappls-intouch-rest-apis","mappls-intouch-android-sdk","mappls-intouch-ios-sdk","mappls-intouch-ios-distribution","mappls-intouch-ios-distribution-base","mapmyindia-intouch-ios-sdk","mappls-react-native-intouch-sdk"],"contractSlugs":["intouch-post-trips-this-api-will-create-a-trip","intouch-get-trips-this-api-will-get-all-the-trips-for-a-user","intouch-get-trips-id-gets-the-details-of-a-single-trip","intouch-post-trips-id-close-post-api-to-close-a-trip","intouch-get-devices-gets-the-live-data-of-devices","intouch-get-devices-deviceid-events-gets-the-historical-location-events-of-a-device"],"sampleSlug":"delivery-control-tower"},{"slug":"fleet-geofence-exception","title":"Fleet geofence exception","productSlug":"intouch-telematics","aggregate":"geofence case","stateModel":"stateful","initialState":"draft","targetState":"resolved","creationCommand":null,"commands":["publish_geofence","record_breach","acknowledge_case","resolve_case"],"events":["geofence.published","geofence.breached","geofence_case.acknowledged","geofence_case.resolved"],"sourceGuideSlugs":["mappls-intouch-rest-apis","mapmyindia-intouch-web-plugins"],"contractSlugs":["intouch-post-geofences-create-a-new-geofence","intouch-get-geofences-id-get-a-single-or-multiple-geofence-s","intouch-get-geofences-activities-get-all-the-activities-done-by-devices-w-r-t-various-geofences","intouch-post-geofences-id-update-a-geofence","intouch-delete-geofences-id-delete-a-geofence"],"sampleSlug":"fleet-geofence"},{"slug":"emergency-incident-response","title":"Coordinated incident response","productSlug":"routes-navigation","aggregate":"incident","stateModel":"stateful","initialState":"reported","targetState":"reviewed","creationCommand":"report_incident","commands":["report_incident","resolve_location","dispatch","accept_dispatch","confirm_arrival","resolve","review"],"events":["incident.reported","incident.located","incident.dispatched","dispatch.accepted","incident.arrived","incident.resolved","incident.reviewed"],"sourceGuideSlugs":["mappls-rest-apis","mappls-intouch-rest-apis","mapmyindia-intouch-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-rest-key-rev-geocode-reverse-geocode-api","core-location-get-rest-key-resources-profile-geopositions-distance-matrix-api","core-location-get-rest-key-resources-profile-geopositions-routing-api","intouch-get-devices-gets-the-live-data-of-devices","intouch-get-devices-deviceid-events-gets-the-historical-location-events-of-a-device"],"sampleSlug":"incident-dispatch"},{"slug":"navigation-session","title":"Recoverable navigation session","productSlug":"routes-navigation","aggregate":"navigation session","stateModel":"hybrid","initialState":"draft","targetState":"ended","creationCommand":null,"commands":["calculate_route","start_guidance","confirm_arrival","end_session"],"events":["route.calculated","navigation.started","navigation.arrived","navigation.ended"],"sourceGuideSlugs":["mappls-android-sdk","mappls-ios-sdk","mappls-react-native-sdk","mapmyindia-maps-vectorsdk-android","mapmyindia-maps-vectorsdk-ios"],"contractSlugs":[],"sampleSlug":"trip-planner"},{"slug":"governed-spatial-analysis","title":"Governed spatial analysis","productSlug":"gis-analytics","aggregate":"analysis run","stateModel":"hybrid","initialState":"draft","targetState":"shared","creationCommand":"create_dataset_version","commands":["create_dataset_version","validate","publish","run_analysis","complete_analysis","create_share"],"events":["dataset.version_created","dataset.validation_started","dataset.published","analysis.started","analysis.completed","share.created"],"sourceGuideSlugs":["mapmyindia-mgis-apis","mapmyindia-mgis-libraries","mappls-insight-sdk"],"contractSlugs":[],"sampleSlug":"retail-site-lab"},{"slug":"durable-weekend-itinerary","title":"Durable multi-stop itinerary","productSlug":"routes-navigation","aggregate":"trip itinerary","stateModel":"hybrid","initialState":"draft","targetState":"completed","creationCommand":"create_trip","commands":["create_trip","add_or_reorder_stop","preview_route","start_trip","visit_or_skip_next","complete_trip"],"events":["trip.created","trip.sequence_changed","trip.route_previewed","trip.started","trip.stop_completed","trip.completed"],"sourceGuideSlugs":["mappls-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-rest-key-resources-profile-geopositions-routing-api"],"sampleSlug":"trip-planner"},{"slug":"consented-address-verification","title":"Consented address verification","productSlug":"search-places","aggregate":"address verification","stateModel":"stateful","initialState":"entered","targetState":"verified","creationCommand":"enter_verification","commands":["enter_verification","normalize_address","authorize_capture","capture_evidence","compare","verify"],"events":["address_verification.entered","address_verification.normalized","address_verification.capture_authorized","address_verification.evidence_captured","address_verification.compared","address_verification.verified"],"sourceGuideSlugs":["mappls-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-rest-key-rev-geocode-reverse-geocode-api"],"sampleSlug":"address-verifier"},{"slug":"governed-spatial-agent-run","title":"Governed spatial agent run","productSlug":"ai-location","aggregate":"agent run","stateModel":"stateful","initialState":"asked","targetState":"completed","creationCommand":"ask","commands":["ask","create_plan","approve_plan","start_execution","complete_execution"],"events":["agent.question_received","agent.plan_created","agent.plan_approved","agent.execution_started","agent.execution_completed"],"sourceGuideSlugs":["mappls-rest-apis","mappls-intouch-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-api-places-nearby-json-nearby-api","core-location-get-rest-key-resources-profile-geopositions-routing-api","intouch-get-devices-gets-the-live-data-of-devices"],"sampleSlug":"spatial-agent"},{"slug":"offline-automotive-release","title":"Offline automotive release","productSlug":"offline-automotive","aggregate":"device release","stateModel":"stateful","initialState":"manufactured","targetState":"operational","creationCommand":"register_device","commands":["register_device","activate","stage_base_release","qualify"],"events":["device.registered","license.activated","release.installed","release.qualified"],"sourceGuideSlugs":[],"contractSlugs":[],"sampleSlug":"offline-release-control"},{"slug":"widget-selection-session","title":"Application-owned widget selection","productSlug":"app-widgets-deep-links","aggregate":"widget selection session","stateModel":"hybrid","initialState":"draft","targetState":"submitted","creationCommand":"create_session","commands":["create_session","open_widget","receive_candidate","accept_selection","submit"],"events":["host.session_created","widget.opened","location.candidate_received","location.selected","host.submitted"],"sourceGuideSlugs":["mappls-app-widgets","mappls-android-sdk","mappls-ui-widget-ios-distribution","mappls-ui-widget-ios-distribution-base","mappls-flutter-sdk","mappls-react-native-sdk"],"contractSlugs":[],"sampleSlug":"widget-journey-host"},{"slug":"ios-direction-planning-handoff","title":"iOS direction planning and navigation handoff","productSlug":"routes-navigation","aggregate":"route planning session","stateModel":"hybrid","initialState":"draft","targetState":"handed_off","creationCommand":"create_plan","commands":["create_plan","open_direction_ui","request_routes","receive_routes","request_navigation","confirm_handoff"],"events":["route_plan.created","route_plan.editor_opened","route_plan.calculation_requested","route_plan.candidates_received","route_plan.navigation_requested","route_plan.navigation_handed_off"],"sourceGuideSlugs":["mappls-direction-ui-ios-distribution","mappls-direction-ui-ios-distribution-base"],"contractSlugs":[],"sampleSlug":"deep-link-journey-host"},{"slug":"ios-geofence-draft","title":"iOS geofence draft and publication boundary","productSlug":"intouch-telematics","aggregate":"geofence draft","stateModel":"hybrid","initialState":"draft","targetState":"approved_draft","creationCommand":"create_geofence_draft","commands":["create_geofence_draft","open_editor","receive_geometry","submit_for_review","approve_draft"],"events":["geofence_draft.created","geofence_draft.editor_opened","geofence_draft.geometry_received","geofence_draft.review_requested","geofence_draft.approved"],"sourceGuideSlugs":["mappls-geofence-ui-ios-distribution","mappls-geofence-ui-ios-distribution-base"],"contractSlugs":[],"sampleSlug":"deep-link-journey-host"},{"slug":"ios-feedback-report-review","title":"iOS feedback report and review","productSlug":"capture-feedback","aggregate":"feedback report","stateModel":"hybrid","initialState":"draft","targetState":"resolved","creationCommand":"create_report","commands":["create_report","open_feedback_ui","receive_candidate","commit_submission","queue_review","resolve_report"],"events":["feedback_report.created","feedback_report.ui_opened","feedback_report.candidate_received","feedback_report.submitted","feedback_report.review_queued","feedback_report.resolved"],"sourceGuideSlugs":["mappls-feedback-kit-ios-distribution","mappls-feedback-kit-ios-distribution-base","mappls-feedback-uikit-ios-distribution","mappls-feedback-uikit-ios-distribution-base"],"contractSlugs":[],"sampleSlug":"place-contribution-desk"},{"slug":"location-capture-evidence","title":"Consent-bound location capture evidence","productSlug":"capture-feedback","aggregate":"location capture attempt","stateModel":"hybrid","initialState":"draft","targetState":"accepted","creationCommand":"create_attempt","commands":["create_attempt","request_permission","prepare_sdk","start_acquisition","receive_location","accept_evidence"],"events":["location_capture.attempt_created","location_capture.permission_requested","location_capture.sdk_ready","location_capture.acquisition_started","location_capture.candidate_received","location_capture.evidence_accepted"],"sourceGuideSlugs":["mappls-location-capture-android-sdk","mappls-location-capture-ios-sdk","mappls-location-capture-sdk-ios-distribution"],"contractSlugs":[],"sampleSlug":"address-verifier"},{"slug":"place-contribution-publication","title":"Governed place contribution and publication","productSlug":"capture-feedback","aggregate":"place contribution","stateModel":"stateful","initialState":"draft","targetState":"published","creationCommand":"create_contribution","commands":["create_contribution","open_widget","report_submission","queue_reconciliation","confirm_publication"],"events":["place_contribution.created","place_contribution.widget_opened","place_contribution.submission_reported","place_contribution.reconciliation_queued","place_contribution.published"],"sourceGuideSlugs":["mappls-app-widgets","mappls-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-apis-o2o-entity-eloc-place-detail-api"],"sampleSlug":"place-contribution-desk"},{"slug":"realview-remote-inspection","title":"Entitled RealView remote inspection","productSlug":"app-widgets-deep-links","aggregate":"remote visual inspection","stateModel":"stateful","initialState":"draft","targetState":"accepted","creationCommand":"create_inspection","commands":["create_inspection","request_entitlement","confirm_entitlement","open_viewer","record_observation","submit_review","accept"],"events":["realview_inspection.created","realview_inspection.entitlement_requested","realview_inspection.entitlement_confirmed","realview_inspection.viewer_opened","realview_inspection.observation_recorded","realview_inspection.review_requested","realview_inspection.accepted"],"sourceGuideSlugs":["mappls-app-widgets","mappls-web-maps-js"],"contractSlugs":[],"sampleSlug":"realview-inspection-desk"},{"slug":"vision-inference-review","title":"Governed SkyDNN inference review","productSlug":"ai-location","aggregate":"vision evidence case","stateModel":"stateful","initialState":"registered","targetState":"accepted","creationCommand":"register_case","commands":["register_case","lock_model","request_inference","record_inference","submit_review","accept"],"events":["vision.case_registered","vision.model_locked","vision.inference_requested","vision.inference_recorded","vision.review_requested","vision.accepted"],"sourceGuideSlugs":["skydnn-aiapi-docs"],"contractSlugs":["skydnn-ai-get-server-whoami-returns-the-current-models-in-port","skydnn-ai-get-models-api-model-key-returns-the-details-of-provided-model","skydnn-ai-post-predict-returns-the-prediction-as-response-in-form-of-json"],"sampleSlug":"vision-evidence-desk"}],"providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false,"writesExposed":false},"journeyWorkshops":{"href":"/journeys","detailTemplate":"/journeys/{journeySlug}/workshop","api":"/api/journey-workshops","summary":{"workshops":18,"labs":144,"codeSamples":90,"simulationScenariosPerWorkshop":5,"providerCalls":0,"writesExposed":false},"index":[{"slug":"field-service-task","title":"Build Field-service task lifecycle","journeySlug":"field-service-task","productSlug":"workmate","stateModel":"stateful","aggregate":"task","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"field-service","websitePath":"/journeys/field-service-task/workshop","apiPath":"/api/journey-workshops?journey=field-service-task"},{"slug":"connected-fleet-trip","title":"Build Connected fleet trip","journeySlug":"connected-fleet-trip","productSlug":"intouch-telematics","stateModel":"stateful","aggregate":"trip","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"delivery-control-tower","websitePath":"/journeys/connected-fleet-trip/workshop","apiPath":"/api/journey-workshops?journey=connected-fleet-trip"},{"slug":"fleet-geofence-exception","title":"Build Fleet geofence exception","journeySlug":"fleet-geofence-exception","productSlug":"intouch-telematics","stateModel":"stateful","aggregate":"geofence case","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"fleet-geofence","websitePath":"/journeys/fleet-geofence-exception/workshop","apiPath":"/api/journey-workshops?journey=fleet-geofence-exception"},{"slug":"emergency-incident-response","title":"Build Coordinated incident response","journeySlug":"emergency-incident-response","productSlug":"routes-navigation","stateModel":"stateful","aggregate":"incident","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"incident-dispatch","websitePath":"/journeys/emergency-incident-response/workshop","apiPath":"/api/journey-workshops?journey=emergency-incident-response"},{"slug":"navigation-session","title":"Build Recoverable navigation session","journeySlug":"navigation-session","productSlug":"routes-navigation","stateModel":"hybrid","aggregate":"navigation session","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"trip-planner","websitePath":"/journeys/navigation-session/workshop","apiPath":"/api/journey-workshops?journey=navigation-session"},{"slug":"governed-spatial-analysis","title":"Build Governed spatial analysis","journeySlug":"governed-spatial-analysis","productSlug":"gis-analytics","stateModel":"hybrid","aggregate":"analysis run","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"retail-site-lab","websitePath":"/journeys/governed-spatial-analysis/workshop","apiPath":"/api/journey-workshops?journey=governed-spatial-analysis"},{"slug":"durable-weekend-itinerary","title":"Build Durable multi-stop itinerary","journeySlug":"durable-weekend-itinerary","productSlug":"routes-navigation","stateModel":"hybrid","aggregate":"trip itinerary","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"trip-planner","websitePath":"/journeys/durable-weekend-itinerary/workshop","apiPath":"/api/journey-workshops?journey=durable-weekend-itinerary"},{"slug":"consented-address-verification","title":"Build Consented address verification","journeySlug":"consented-address-verification","productSlug":"search-places","stateModel":"stateful","aggregate":"address verification","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"address-verifier","websitePath":"/journeys/consented-address-verification/workshop","apiPath":"/api/journey-workshops?journey=consented-address-verification"},{"slug":"governed-spatial-agent-run","title":"Build Governed spatial agent run","journeySlug":"governed-spatial-agent-run","productSlug":"ai-location","stateModel":"stateful","aggregate":"agent run","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"spatial-agent","websitePath":"/journeys/governed-spatial-agent-run/workshop","apiPath":"/api/journey-workshops?journey=governed-spatial-agent-run"},{"slug":"offline-automotive-release","title":"Build Offline automotive release","journeySlug":"offline-automotive-release","productSlug":"offline-automotive","stateModel":"stateful","aggregate":"device release","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"offline-release-control","websitePath":"/journeys/offline-automotive-release/workshop","apiPath":"/api/journey-workshops?journey=offline-automotive-release"},{"slug":"widget-selection-session","title":"Build Application-owned widget selection","journeySlug":"widget-selection-session","productSlug":"app-widgets-deep-links","stateModel":"hybrid","aggregate":"widget selection session","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"widget-journey-host","websitePath":"/journeys/widget-selection-session/workshop","apiPath":"/api/journey-workshops?journey=widget-selection-session"},{"slug":"ios-direction-planning-handoff","title":"Build iOS direction planning and navigation handoff","journeySlug":"ios-direction-planning-handoff","productSlug":"routes-navigation","stateModel":"hybrid","aggregate":"route planning session","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"deep-link-journey-host","websitePath":"/journeys/ios-direction-planning-handoff/workshop","apiPath":"/api/journey-workshops?journey=ios-direction-planning-handoff"},{"slug":"ios-geofence-draft","title":"Build iOS geofence draft and publication boundary","journeySlug":"ios-geofence-draft","productSlug":"intouch-telematics","stateModel":"hybrid","aggregate":"geofence draft","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"deep-link-journey-host","websitePath":"/journeys/ios-geofence-draft/workshop","apiPath":"/api/journey-workshops?journey=ios-geofence-draft"},{"slug":"ios-feedback-report-review","title":"Build iOS feedback report and review","journeySlug":"ios-feedback-report-review","productSlug":"capture-feedback","stateModel":"hybrid","aggregate":"feedback report","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"place-contribution-desk","websitePath":"/journeys/ios-feedback-report-review/workshop","apiPath":"/api/journey-workshops?journey=ios-feedback-report-review"},{"slug":"location-capture-evidence","title":"Build Consent-bound location capture evidence","journeySlug":"location-capture-evidence","productSlug":"capture-feedback","stateModel":"hybrid","aggregate":"location capture attempt","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"address-verifier","websitePath":"/journeys/location-capture-evidence/workshop","apiPath":"/api/journey-workshops?journey=location-capture-evidence"},{"slug":"place-contribution-publication","title":"Build Governed place contribution and publication","journeySlug":"place-contribution-publication","productSlug":"capture-feedback","stateModel":"stateful","aggregate":"place contribution","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"place-contribution-desk","websitePath":"/journeys/place-contribution-publication/workshop","apiPath":"/api/journey-workshops?journey=place-contribution-publication"},{"slug":"realview-remote-inspection","title":"Build Entitled RealView remote inspection","journeySlug":"realview-remote-inspection","productSlug":"app-widgets-deep-links","stateModel":"stateful","aggregate":"remote visual inspection","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"realview-inspection-desk","websitePath":"/journeys/realview-remote-inspection/workshop","apiPath":"/api/journey-workshops?journey=realview-remote-inspection"},{"slug":"vision-inference-review","title":"Build Governed SkyDNN inference review","journeySlug":"vision-inference-review","productSlug":"ai-location","stateModel":"stateful","aggregate":"vision evidence case","duration":"2 hr 10 min","labs":8,"codeSamples":5,"scenarios":5,"sampleSlug":"vision-evidence-desk","websitePath":"/journeys/vision-inference-review/workshop","apiPath":"/api/journey-workshops?journey=vision-inference-review"}],"mcpTool":"mappls_get_journey_workshop","mcpResource":"mappls://catalog/journey-workshops","providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false,"writesExposed":false},"capabilityMatrix":{"href":"/platforms/matrix","api":"/api/capability-matrix","detailTemplate":"/api/capability-matrix?product={productSlug}&platform={platformSlug}","summary":{"schemaVersion":"mappls.capability-matrix.v1","products":10,"platforms":13,"cells":130,"listed":47,"notListed":83,"listedWithExactEvidence":43,"listedSelectionRequired":4,"exactEvidenceLinks":796,"providerCalls":0,"credentialsAccepted":false},"options":{"summary":{"schemaVersion":"mappls.capability-matrix.v1","products":10,"platforms":13,"cells":130,"listed":47,"notListed":83,"listedWithExactEvidence":43,"listedSelectionRequired":4,"exactEvidenceLinks":796,"providerCalls":0,"credentialsAccepted":false},"rules":["The matrix evaluates every canonical product against every canonical platform exactly once.","Only the product's explicit platform list creates a listed cell; repository, tutorial, sample, or neighboring-platform evidence cannot infer support.","Exact evidence is identity-preserving source, SDK, API, or product-and-platform tutorial evidence. Quickstarts and starter kits are platform-adjacent; samples and journeys are product-adjacent.","Not listed is an honest selection stop, not a claim that a capability is impossible or commercially unavailable.","Listed and source-evidenced are discovery states, never proof of package availability, account entitlement, compatibility, region, quota, support, or production approval."],"products":[{"slug":"maps","name":"Maps","stateModel":"stateless","platforms":["Web","Android","iOS","React Native","Flutter","Cordova","Xamarin","REST"]},{"slug":"search-places","name":"Search & Places","stateModel":"stateless","platforms":["REST","Web","Android","iOS","React Native","Flutter","Widgets"]},{"slug":"routes-navigation","name":"Routes & Navigation","stateModel":"hybrid","platforms":["REST","Android","iOS","Automotive","Linux","React Native"]},{"slug":"intouch-telematics","name":"InTouch Telematics","stateModel":"stateful","platforms":["REST","Android","iOS","React Native","Web","Widgets"]},{"slug":"workmate","name":"Workmate","stateModel":"stateful","platforms":["REST","Android","Web"]},{"slug":"gis-analytics","name":"GIS & Analytics","stateModel":"hybrid","platforms":["REST","Web","Widgets","MCP"]},{"slug":"app-widgets-deep-links","name":"App Widgets & Deep Links","stateModel":"stateless","platforms":["Widgets","Deep links","Web","Android","iOS"]},{"slug":"offline-automotive","name":"Offline & Automotive","stateModel":"stateful","platforms":["Automotive","Linux","Android"]},{"slug":"ai-location","name":"AI & Location","stateModel":"hybrid","platforms":["REST","Web","MCP"]},{"slug":"capture-feedback","name":"Capture & Feedback","stateModel":"hybrid","platforms":["Android","iOS"]}],"platforms":[{"slug":"rest","name":"REST","headline":"Put Mappls behind a stable service boundary in any stack."},{"slug":"web","name":"Web","headline":"Build expressive browser maps without surrendering performance or control."},{"slug":"android","name":"Android","headline":"Compose native maps, places, tracking, and navigation with Android lifecycle discipline."},{"slug":"ios","name":"iOS","headline":"Deliver Mappls-native Apple experiences through modular, lifecycle-safe frameworks."},{"slug":"react-native","name":"React Native","headline":"Share product logic while keeping native Mappls capabilities honest on both platforms."},{"slug":"flutter","name":"Flutter","headline":"Use one Dart experience with deliberate native Mappls configuration underneath."},{"slug":"cordova","name":"Cordova","headline":"Maintain hybrid location experiences with explicit native ownership and a migration path."},{"slug":"xamarin","name":"Xamarin","headline":"Stabilize existing .NET mobile integrations and move forward without losing behavior."},{"slug":"linux","name":"Linux","headline":"Run location and navigation reliably on controlled, embedded Linux systems."},{"slug":"automotive","name":"Automotive","headline":"Treat in-vehicle navigation as a safety-aware, upgradeable system—not a screen."},{"slug":"widgets","name":"Widgets","headline":"Embed complete Mappls experiences while keeping hand-off, privacy, and fallback deliberate."},{"slug":"deep-links","name":"Deep links","headline":"Open useful Mappls place and journey experiences from any channel—with no SDK requirement."},{"slug":"mcp","name":"MCP","headline":"Give AI systems typed Mappls capabilities with policy, evidence, and human control."}],"website":"/platforms/matrix","api":"/api/capability-matrix"},"mcpTool":"mappls_get_capability_matrix","mcpResource":"mappls://catalog/capability-matrix","providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false,"writesExposed":false},"capabilityQualifications":{"href":"/platforms/qualify","api":"/api/capability-qualifications","detailTemplate":"/api/capability-qualifications?product={productSlug}&platform={platformSlug}","downloadTemplate":"/api/capability-qualifications?product={productSlug}&platform={platformSlug}&download=1","summary":{"schemaVersion":"mappls.capability-qualification.v1","plans":130,"readyToQualify":43,"selectionRequired":4,"notListed":83,"phases":780,"scenarios":1053,"providerCalls":0,"credentialsAccepted":false,"writesExposed":false},"options":{"products":[{"slug":"maps","name":"Maps"},{"slug":"search-places","name":"Search & Places"},{"slug":"routes-navigation","name":"Routes & Navigation"},{"slug":"intouch-telematics","name":"InTouch Telematics"},{"slug":"workmate","name":"Workmate"},{"slug":"gis-analytics","name":"GIS & Analytics"},{"slug":"app-widgets-deep-links","name":"App Widgets & Deep Links"},{"slug":"offline-automotive","name":"Offline & Automotive"},{"slug":"ai-location","name":"AI & Location"},{"slug":"capture-feedback","name":"Capture & Feedback"}],"platforms":[{"slug":"rest","name":"REST"},{"slug":"web","name":"Web"},{"slug":"android","name":"Android"},{"slug":"ios","name":"iOS"},{"slug":"react-native","name":"React Native"},{"slug":"flutter","name":"Flutter"},{"slug":"cordova","name":"Cordova"},{"slug":"xamarin","name":"Xamarin"},{"slug":"linux","name":"Linux"},{"slug":"automotive","name":"Automotive"},{"slug":"widgets","name":"Widgets"},{"slug":"deep-links","name":"Deep links"},{"slug":"mcp","name":"MCP"}],"statuses":["ready-to-qualify","selection-required","not-listed"]},"mcpTool":"mappls_get_capability_qualification","mcpResource":"mappls://catalog/capability-qualifications","providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false,"writesExposed":false,"productionApprovalGranted":false},"liveConformance":{"href":"/conformance","api":"/api/conformance","downloadTemplate":"/api/conformance?operation={operation}&generation={generation}&region={region}&download=1","summary":{"schemaVersion":"mappls.live-conformance-catalog.v1","executableReadOperations":8,"coveredProducts":3,"productFamilies":10,"writeOperations":0,"providerCallsWhilePlanning":0},"operations":[{"slug":"autosuggest","title":"Autosuggest","productSlug":"search-places","service":"search","providerOperation":"search.autosuggest","safety":"read-only","dataClass":"place-query","requiredEnvironment":["MAPPLS_CONFORMANCE_QUERY"],"sourceOperationSlugs":["core-location-get-api-places-search-json-autosuggest-api"],"sourceBoundary":"The runner-owned current path and the acquired legacy source operation are compared as separate generations; a passing probe proves only the issued account contract."},{"slug":"geocode","title":"Geocode","productSlug":"search-places","service":"search","providerOperation":"search.geocode","safety":"read-only","dataClass":"place-query","requiredEnvironment":["MAPPLS_CONFORMANCE_ADDRESS"],"sourceOperationSlugs":["core-location-get-api-places-geocode-geocode-api"],"sourceBoundary":"Address input stays operator-selected and is never emitted in the report. Source evidence does not prove regional entitlement."},{"slug":"reverseGeocode","title":"Reverse geocode","productSlug":"search-places","service":"search","providerOperation":"search.reverse_geocode","safety":"read-only","dataClass":"route-coordinate","requiredEnvironment":["MAPPLS_CONFORMANCE_ORIGIN"],"sourceOperationSlugs":["core-location-get-rest-key-rev-geocode-reverse-geocode-api"],"sourceBoundary":"The coordinate is used only by the approved runner process and is excluded from evidence output."},{"slug":"nearby","title":"Nearby search","productSlug":"search-places","service":"search","providerOperation":"search.nearby","safety":"read-only","dataClass":"route-coordinate","requiredEnvironment":["MAPPLS_CONFORMANCE_ORIGIN"],"sourceOperationSlugs":["core-location-get-api-places-nearby-json-nearby-api"],"sourceBoundary":"The bounded fixture radius is not a coverage, ranking, or commercial guarantee."},{"slug":"route","title":"Route","productSlug":"routes-navigation","service":"route","providerOperation":"routes.plan","safety":"read-only","dataClass":"route-coordinate","requiredEnvironment":["MAPPLS_CONFORMANCE_ORIGIN","MAPPLS_CONFORMANCE_DESTINATION"],"sourceOperationSlugs":["core-location-post-api-places-along-route-poi-along-the-route-api","core-location-get-rest-key-resources-profile-geopositions-route-optimization-api"],"sourceBoundary":"A route response proves only the selected locations, profile, account, generation, region, and observation time."},{"slug":"matrix","title":"Distance matrix","productSlug":"routes-navigation","service":"route","providerOperation":"routes.matrix","safety":"read-only","dataClass":"route-coordinate","requiredEnvironment":["MAPPLS_CONFORMANCE_ORIGIN","MAPPLS_CONFORMANCE_DESTINATION"],"sourceOperationSlugs":["core-location-get-rest-key-resources-profile-geopositions-distance-matrix-api","core-location-get-rest-key-distance-matrix-predictive-driving-coordinates-distance-matrix-predictive-eta-api"],"sourceBoundary":"A two-point read does not qualify production matrix size, quota, predictive behavior, or optimization writes."},{"slug":"assetStatus","title":"Asset status","productSlug":"intouch-telematics","service":"intouch","providerOperation":"intouch.device_status","safety":"read-only","dataClass":"sensitive-live-location","requiredEnvironment":["MAPPLS_INTOUCH_ACCESS_TOKEN","MAPPLS_CONFORMANCE_DEVICE_ID"],"sourceOperationSlugs":["intouch-get-devices-gets-the-live-data-of-devices","intouch-get-device-gets-the-live-data-of-devices"],"sourceBoundary":"The authorized device identifier and provider body never leave the runner. Treat all returned location as sensitive."},{"slug":"assetEvents","title":"Asset events","productSlug":"intouch-telematics","service":"intouch","providerOperation":"intouch.device_events","safety":"read-only","dataClass":"sensitive-live-location","requiredEnvironment":["MAPPLS_INTOUCH_ACCESS_TOKEN","MAPPLS_CONFORMANCE_DEVICE_ID"],"sourceOperationSlugs":["intouch-get-device-deviceid-events-gets-the-historical-location-events-of-a-device","intouch-get-devices-deviceid-events-gets-the-historical-location-events-of-a-device"],"sourceBoundary":"The runner limits history to one hour and emits no event body, coordinate, device identity, or token."}],"productCoverage":[{"product":{"slug":"maps","name":"Maps","stateModel":"stateless"},"status":"dedicated-qualification-required","operations":[],"boundary":"No generic live probe is claimed. Use the product-platform qualification plan and its exact SDK, widget, sovereign, AI, or stateful journey evidence."},{"product":{"slug":"search-places","name":"Search & Places","stateModel":"stateless"},"status":"bounded-read-runner","operations":["autosuggest","geocode","reverseGeocode","nearby"],"boundary":"4 bounded read probes are implemented. SDK, widget, write, callback, quota, commercial, privacy, and production behavior remain separate evidence."},{"product":{"slug":"routes-navigation","name":"Routes & Navigation","stateModel":"hybrid"},"status":"bounded-read-runner","operations":["route","matrix"],"boundary":"2 bounded read probes are implemented. SDK, widget, write, callback, quota, commercial, privacy, and production behavior remain separate evidence."},{"product":{"slug":"intouch-telematics","name":"InTouch Telematics","stateModel":"stateful"},"status":"bounded-read-runner","operations":["assetStatus","assetEvents"],"boundary":"2 bounded read probes are implemented. SDK, widget, write, callback, quota, commercial, privacy, and production behavior remain separate evidence."},{"product":{"slug":"workmate","name":"Workmate","stateModel":"stateful"},"status":"dedicated-qualification-required","operations":[],"boundary":"No generic live probe is claimed. Use the product-platform qualification plan and its exact SDK, widget, sovereign, AI, or stateful journey evidence."},{"product":{"slug":"gis-analytics","name":"GIS & Analytics","stateModel":"hybrid"},"status":"dedicated-qualification-required","operations":[],"boundary":"No generic live probe is claimed. Use the product-platform qualification plan and its exact SDK, widget, sovereign, AI, or stateful journey evidence."},{"product":{"slug":"app-widgets-deep-links","name":"App Widgets & Deep Links","stateModel":"stateless"},"status":"dedicated-qualification-required","operations":[],"boundary":"No generic live probe is claimed. Use the product-platform qualification plan and its exact SDK, widget, sovereign, AI, or stateful journey evidence."},{"product":{"slug":"offline-automotive","name":"Offline & Automotive","stateModel":"stateful"},"status":"dedicated-qualification-required","operations":[],"boundary":"No generic live probe is claimed. Use the product-platform qualification plan and its exact SDK, widget, sovereign, AI, or stateful journey evidence."},{"product":{"slug":"ai-location","name":"AI & Location","stateModel":"hybrid"},"status":"dedicated-qualification-required","operations":[],"boundary":"No generic live probe is claimed. Use the product-platform qualification plan and its exact SDK, widget, sovereign, AI, or stateful journey evidence."},{"product":{"slug":"capture-feedback","name":"Capture & Feedback","stateModel":"hybrid"},"status":"dedicated-qualification-required","operations":[],"boundary":"No generic live probe is claimed. Use the product-platform qualification plan and its exact SDK, widget, sovereign, AI, or stateful journey evidence."}],"mcpTool":"mappls_plan_live_conformance","mcpResource":"mappls://catalog/live-conformance","reportSchemaVersion":"mappls.live-conformance-report.v1","inspectorExecution":"browser-local-only","providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCallsWhilePlanning":false,"writesExposed":false,"productionApprovalGranted":false},"developerAcademy":{"href":"/academy","api":"/api/learning-path","summary":{"useCases":16,"platforms":13,"experienceLevels":3,"personalizedPaths":624,"canonicalTutorials":40,"maintainedCapstones":21,"providerCredentialsAccepted":false,"providerNetworkCalls":0,"writesExposed":false},"options":{"useCases":[{"slug":"last-mile-delivery","industry":"Logistics","title":"A delivery promise customers can trust","summary":"Validate addresses, allocate stops, guide drivers, stream progress, and prove completion."},{"slug":"ride-hailing","industry":"Mobility","title":"A pickup flow that survives the real world","summary":"Find entrances, match riders and drivers, route continuously, and resolve pickup ambiguity."},{"slug":"field-service","industry":"Utilities","title":"Dispatch the right technician, with the right proof","summary":"Turn outages or service requests into skill-aware, route-efficient field jobs."},{"slug":"energy-grid-resilience","industry":"Energy","title":"Restore the grid from alarm to verified service","summary":"Correlate network alarms, weather exposure, switching plans, field crews, and restoration evidence."},{"slug":"retail-expansion","industry":"Retail","title":"Choose the next store with evidence","summary":"Combine catchments, demographics, competition, access, and existing performance."},{"slug":"banking-address-risk","industry":"Financial services","title":"Make address risk explainable","summary":"Standardize applications, verify presence, enrich geography, and route cases for review."},{"slug":"insurance-claims","industry":"Insurance","title":"Evidence-led claims from incident to settlement","summary":"Capture location and imagery, use governed vision triage, dispatch assessors, and understand catastrophe exposure."},{"slug":"hospital-care-logistics","industry":"Healthcare","title":"Coordinate time-critical care without losing custody","summary":"Resolve facilities and entrances, dispatch suitable transport, track hand-offs, and preserve privacy-minimized care logistics evidence."},{"slug":"emergency-response","industry":"Public safety","title":"Route coordinated response under pressure","summary":"Resolve caller location, find capable resources, route around incidents, and maintain a common picture."},{"slug":"smart-city-operations","industry":"Government","title":"A living operations map for the city","summary":"Unify assets, incidents, crews, citizen feedback, and long-term spatial analysis."},{"slug":"connected-vehicle","industry":"Automotive","title":"Navigation built for intermittent connectivity","summary":"Ship an activated, updateable in-vehicle navigation lifecycle with online enhancement."},{"slug":"aviation-ground-operations","industry":"Aviation","title":"Run a safe, punctual airport turnaround","summary":"Coordinate stands, service vehicles, restricted zones, inspections, and turnaround milestones on one governed operating picture."},{"slug":"travel-discovery","industry":"Travel","title":"Turn inspiration into an itinerary","summary":"Help travelers discover, sequence, visualize, and open rich place experiences."},{"slug":"agriculture-field-ops","industry":"Agriculture","title":"Coordinate field operations across every plot","summary":"Map parcels, schedule crews, track equipment, and compare observations over time."},{"slug":"mining-haulage-safety","industry":"Mining","title":"Move material safely across a changing mine","summary":"Version haul roads and exclusion zones, dispatch compatible equipment, track cycles, and reconcile safety and production evidence."},{"slug":"telecom-network-care","industry":"Telecommunications","title":"Operate the network from tower to doorstep","summary":"Link network assets, alarms, field teams, and customer impact spatially."}],"platforms":[{"platform":"REST","quickstartSlug":"rest-api","readiness":"public-source"},{"platform":"Web","quickstartSlug":"web-map","readiness":"public-source"},{"platform":"Android","quickstartSlug":"android-native","readiness":"public-source"},{"platform":"iOS","quickstartSlug":"ios-native","readiness":"public-source"},{"platform":"React Native","quickstartSlug":"react-native-map","readiness":"public-source"},{"platform":"Flutter","quickstartSlug":"flutter-map","readiness":"public-source"},{"platform":"Cordova","quickstartSlug":"cordova-maintenance","readiness":"legacy-maintenance"},{"platform":"Xamarin","quickstartSlug":"xamarin-maintenance","readiness":"entitlement-required"},{"platform":"Linux","quickstartSlug":"linux-embedded","readiness":"entitlement-required"},{"platform":"Automotive","quickstartSlug":"automotive-navigation","readiness":"entitlement-required"},{"platform":"Widgets","quickstartSlug":"widgets-place","readiness":"public-source"},{"platform":"Deep links","quickstartSlug":"deep-links","readiness":"public-source"},{"platform":"MCP","quickstartSlug":"mcp-agent","readiness":"local-reference"}],"experiences":[{"slug":"beginner","title":"New to Mappls","description":"Begin with platform orientation and a credential-safe first success before composing products."},{"slug":"intermediate","title":"Integration experience","description":"Start at the exact runtime boundary, then practice composition, failure handling, and durable state."},{"slug":"advanced","title":"Production practitioner","description":"Audit contracts, attack lifecycle assumptions, prove a capstone, and assemble release evidence."}]},"deviceProgress":{"storage":"browser-local","synchronization":false,"analytics":false,"providerCalls":0,"credentialsAccepted":false,"personalDataAccepted":false,"maximumSavedPaths":12,"authority":"Self-recorded learning preference only. Completion is not Mappls certification, entitlement, provider conformance, release approval, or deployment evidence."},"providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false,"writesExposed":false},"implementationRecipes":{"href":"/recipes","api":"/api/recipes","summary":{"recipes":48,"industries":16,"modes":3,"generatedCodeSamples":384,"codeLanguages":8,"sandboxScenariosPerRecipe":6,"maintainedCapstones":5,"providerNetworkCallsForPlanning":0,"writesExposed":false},"modes":[{"slug":"request-response","title":"Request/response slice","stateModel":"stateless","duration":"35–50 min","workflowStages":2,"description":"Prove one bounded contract, identity handoff, failure response, and observable first success."},{"slug":"composed-experience","title":"Composed application flow","stateModel":"hybrid","duration":"90–120 min","workflowStages":4,"description":"Compose multiple capabilities while the application owns user intent, policy, and continuity."},{"slug":"durable-operation","title":"Durable operating journey","stateModel":"stateful","duration":"2–3 hr","workflowStages":5,"description":"Operate the full lifecycle with versioned state, hostile-path recovery, audit, and release evidence."}],"providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false,"writesExposed":false},"integrationManifests":{"href":"/integration-manifests","api":"/api/integration-manifest","summary":{"schemaVersion":"mappls.integration-manifest.v1","combinations":624,"useCases":16,"platforms":13,"modes":3,"providerNetworkCalls":0,"writesExposed":false},"options":{"useCases":[{"slug":"last-mile-delivery","industry":"Logistics","title":"A delivery promise customers can trust"},{"slug":"ride-hailing","industry":"Mobility","title":"A pickup flow that survives the real world"},{"slug":"field-service","industry":"Utilities","title":"Dispatch the right technician, with the right proof"},{"slug":"energy-grid-resilience","industry":"Energy","title":"Restore the grid from alarm to verified service"},{"slug":"retail-expansion","industry":"Retail","title":"Choose the next store with evidence"},{"slug":"banking-address-risk","industry":"Financial services","title":"Make address risk explainable"},{"slug":"insurance-claims","industry":"Insurance","title":"Evidence-led claims from incident to settlement"},{"slug":"hospital-care-logistics","industry":"Healthcare","title":"Coordinate time-critical care without losing custody"},{"slug":"emergency-response","industry":"Public safety","title":"Route coordinated response under pressure"},{"slug":"smart-city-operations","industry":"Government","title":"A living operations map for the city"},{"slug":"connected-vehicle","industry":"Automotive","title":"Navigation built for intermittent connectivity"},{"slug":"aviation-ground-operations","industry":"Aviation","title":"Run a safe, punctual airport turnaround"},{"slug":"travel-discovery","industry":"Travel","title":"Turn inspiration into an itinerary"},{"slug":"agriculture-field-ops","industry":"Agriculture","title":"Coordinate field operations across every plot"},{"slug":"mining-haulage-safety","industry":"Mining","title":"Move material safely across a changing mine"},{"slug":"telecom-network-care","industry":"Telecommunications","title":"Operate the network from tower to doorstep"}],"platforms":[{"name":"REST","description":"Composable HTTP APIs for trusted backends, automation, data platforms, and any language."},{"name":"Web","description":"Browser-native maps, plugins, analytics, and embeddable location experiences."},{"name":"Android","description":"Native maps, places, routes, navigation, telematics, capture, and UI widgets."},{"name":"iOS","description":"Native frameworks distributed through Swift Package Manager with modular UI extensions."},{"name":"React Native","description":"Shared JavaScript/TypeScript interfaces backed by Mappls native SDKs."},{"name":"Flutter","description":"Dart wrappers for native Android and iOS mapping capabilities."},{"name":"Cordova","description":"Legacy hybrid bridges for Cordova and Ionic applications."},{"name":"Xamarin","description":"Legacy .NET mobile samples for SDK-backed maps and REST APIs."},{"name":"Linux","description":"Native mapping and routing runtimes for controlled devices and embedded systems."},{"name":"Automotive","description":"Offline-capable navigation SDKs, data compilers, activation, and vehicle integration hooks."},{"name":"Widgets","description":"Prebuilt UI for places, directions, nearby, geofences, feedback, and rich Mappls content."},{"name":"Deep links","description":"Universal Mappls URLs for place views, directions, navigation, and app hand-off."},{"name":"MCP","description":"Typed tools and resources that let agents discover and invoke Mappls capabilities safely."}],"modes":[{"slug":"request-response","title":"Request/response slice","stateModel":"stateless","duration":"35–50 min","workflowStages":2,"description":"Prove one bounded contract, identity handoff, failure response, and observable first success."},{"slug":"composed-experience","title":"Composed application flow","stateModel":"hybrid","duration":"90–120 min","workflowStages":4,"description":"Compose multiple capabilities while the application owns user intent, policy, and continuity."},{"slug":"durable-operation","title":"Durable operating journey","stateModel":"stateful","duration":"2–3 hr","workflowStages":5,"description":"Operate the full lifecycle with versioned state, hostile-path recovery, audit, and release evidence."}]},"cliCommands":["manifest create","manifest validate"],"mcpTool":"mappls_build_integration_manifest","mcpResource":"mappls://catalog/integration-manifests","providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false,"writesExposed":false},"applicationLaunchDossiers":{"consoleTemplate":"/console/apps/{applicationId}/build?useCase={useCaseSlug}&mode={mode}","apiTemplate":"/api/apps/{applicationId}/launch-dossier?useCase={useCaseSlug}&mode={mode}","handoffSubmissionTemplate":"/api/apps/{applicationId}/release-handoffs","companyQueue":"/admin/releases","schemaVersion":"mappls.application-launch-dossier.v1","authorities":["source-contract","application-configuration","provider-conformance","security-privacy","operations","production-release","deployment"],"cliCommand":"dossier validate","handoffAcceptanceChangesReleaseState":false,"handoffAcceptanceSatisfiesGates":false,"productionReadyClaimed":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false,"providerNetworkCalls":false,"writesExposed":false},"applicationClientPacks":{"consoleTemplate":"/console/apps/{applicationId}/clients?useCase={useCaseSlug}&mode={mode}&language={language}","downloadTemplate":"/api/apps/{applicationId}/client-pack?useCase={useCaseSlug}&mode={mode}&language={language}","repositoryDocumentation":"docs/APPLICATION_CLIENT_PACKS.md","schemaVersion":"mappls.application-client-pack.v1","languages":8,"contents":["application-manifest","integration-manifest","operation-allowlist","blank-environment","integrity-verifier","generated-client-archive","client-sha256"],"deterministicArchive":true,"tenantScoped":true,"applicationOwnershipRequired":true,"providerCredentialsAccepted":false,"providerCredentialValuesIncluded":false,"providerPayloadsAccepted":false,"providerNetworkCallsWhileGenerating":false,"allowlistAutomaticallyEnforced":false,"entitlementGranted":false,"productionApprovalGranted":false,"writesExposed":false},"releaseDeploymentGovernance":{"admin":"/admin/releases","createApi":"/api/admin/release-deployments","transitionApiTemplate":"/api/admin/release-deployments/{deploymentId}","tenantEvidenceTemplate":"/console/apps/{applicationId}/build","statuses":["planned","authorized","canary","ramping","observing","reconciled","rolled_back","cancelled"],"actions":["authorize","start_canary","advance","begin_observation","reconcile","rollback","cancel"],"prerequisites":["approved-release","accepted-application-handoff"],"separation":["creator","operator","authorizer"],"optimisticVersions":true,"immutableEvents":true,"releaseGatesMutated":false,"tenantWritesExposed":false,"operatorIdentitiesExposedToTenant":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"dataResilienceGovernance":{"admin":"/admin/resilience","adminApi":"/api/admin/data-resilience","transitionApiTemplate":"/api/admin/data-resilience/{exerciseId}","tenantEvidence":"/console/resilience","tenantApi":"/api/console/data-resilience","repositoryDocumentation":"docs/DATA_RESILIENCE_GOVERNANCE.md","exerciseTypes":["restore","regional_failover"],"statuses":["planned","authorized","running","evidence_submitted","reconciled","failed","cancelled"],"actions":["authorize","start","submit_evidence","reconcile","fail","cancel"],"separation":["creator","authorizer","operator","data-owner"],"objectives":["RPO","RTO","restored-record-count","zero-variance-reconciliation"],"optimisticVersions":true,"immutableEvents":true,"productionApplicationRequired":true,"infrastructureRecoveryPerformed":false,"productionTrafficAuthorized":false,"tenantWritesExposed":false,"operatorIdentitiesExposedToTenant":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"dataLifecycleGovernance":{"admin":"/admin/data-lifecycle","adminApi":"/api/admin/data-lifecycle","transitionApiTemplate":"/api/admin/data-lifecycle/{exerciseId}","tenantEvidence":"/console/data-lifecycle","tenantApi":"/api/console/data-lifecycle","repositoryDocumentation":"docs/DATA_LIFECYCLE_GOVERNANCE.md","statuses":["planned","authorized","running","evidence_submitted","reconciled","failed","cancelled"],"actions":["authorize","start","submit_evidence","reconcile","fail","cancel"],"separation":["creator","privacy-reviewer","operator","data-owner"],"controls":["maximum-retention-age","deletion-backlog","residency","backup-inventory"],"optimisticVersions":true,"immutableEvents":true,"productionApplicationRequired":true,"sampledEvidenceOnly":true,"infrastructureMutated":false,"legalBasisEstablished":false,"unsampledRecordsProven":false,"tenantWritesExposed":false,"operatorIdentitiesExposedToTenant":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"applicationDataPractices":{"tenant":"/console/data-practices","tenantApi":"/api/data-practices","tenantTransitionApiTemplate":"/api/data-practices/{practiceId}","admin":"/admin/privacy","adminApi":"/api/admin/data-practices","adminReviewApiTemplate":"/api/admin/data-practices/{practiceId}","repositoryDocumentation":"docs/APPLICATION_DATA_PRACTICES.md","statuses":["submitted","approved","rejected","cancelled","superseded"],"dataCategories":["precise_location","approximate_location","search_queries","routes","telemetry","device_identifiers","account_identifiers","user_contributions","imagery","derived_insights"],"processingModes":["transient_request","application_storage","analytics","personalization","safety_security","human_review","ai_inference","sharing_export"],"dataSubjects":["customers","workforce","drivers","passengers","visitors","minors"],"revisions":true,"independentAdminReview":true,"immutableEvents":true,"legalBasisEstablished":false,"noticesVerified":false,"runtimeDataInspected":false,"processingAuthorized":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"applicationRetirementGovernance":{"tenant":"/console/retirements","tenantApi":"/api/application-retirements","tenantTransitionApiTemplate":"/api/application-retirements/{retirementId}","admin":"/admin/retirements","adminApi":"/api/admin/application-retirements","adminReviewApiTemplate":"/api/admin/application-retirements/{retirementId}","signedProviderResultApi":"/api/internal/application-retirement-events","repositoryDocumentation":"docs/APPLICATION_RETIREMENT_GOVERNANCE.md","statuses":["submitted","approved","rejected","cancelled","retired","failed"],"dispositions":["retain_under_policy","export_then_delete","delete_under_policy","transfer_to_replacement"],"blockers":["active_credentials","active_webhooks","active_entitlements","pending_entitlement_requests","active_deployments","active_resilience_exercises","active_data_lifecycle_exercises"],"independentAdminReview":true,"signedProviderReconciliation":true,"optimisticVersions":true,"immutableEvents":true,"hardDeletePerformed":false,"dataDeletionPerformed":false,"legalRetentionDecided":false,"downstreamMigrationPerformed":false,"providerCredentialsAccepted":false,"providerPayloadsAccepted":false},"solutionArchitect":{"href":"/architect","api":"/api/solution-plan","scenarios":16,"platforms":13,"products":10},"deepLinkBuilder":{"href":"/tools/deep-links","api":"/api/deep-link","intents":[{"slug":"navigation","title":"Start navigation","summary":"Hand a validated destination to Mappls navigation through an HTTPS universal link, with an optional installed-app URI.","fields":["latitude","longitude","destinationName","mode"]},{"slug":"share-place","title":"Share a Mappls Pin","summary":"Open one stable six-character Mappls place identity without coordinates or a credential in the URL.","fields":["mapplsPin"]},{"slug":"point-on-map","title":"Open a point on map","summary":"Open one validated latitude/longitude point using the documented point-on-map route.","fields":["latitude","longitude"]},{"slug":"get-pin","title":"Get a Mappls Pin","summary":"Open the documented signed-in Mappls flow for creating or retrieving a Mappls Pin.","fields":[]}]},"widgetBuilder":{"href":"/tools/widgets","api":"/api/widget-config","exactGenerators":7,"families":[{"slug":"places","title":"Places","surface":"iframe","buildStatus":"exact-generator","credentialBoundary":"optional-browser-token","stateModel":"stateless-view","summary":"Embed one Mappls Pin as an interactive place view.","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/widgets/mappls-places-widget/readme/","evidenceBoundary":"The official page supplies the iframe path and Pin, token, fullscreen, position, zoom, and pitch parameters. Token issuance and production entitlement remain account-specific."},{"slug":"nearby","title":"Nearby","surface":"iframe","buildStatus":"exact-generator","credentialBoundary":"optional-browser-token","stateModel":"stateless-view","summary":"Show categories or keywords around one Mappls Pin.","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/widgets/mappls-nearby-widget/readme/","evidenceBoundary":"The official page supplies the iframe path and Pin, token, traffic, keyword, fullscreen, and pitch parameters. Category availability remains an acceptance test."},{"slug":"earthview","title":"EarthView","surface":"iframe","buildStatus":"exact-generator","credentialBoundary":"optional-browser-token","stateModel":"stateless-view","summary":"Present a Mappls place in a two- or three-dimensional EarthView.","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/widgets/mappls-earthView-widget/readme/","evidenceBoundary":"The official page supplies the EarthView path, BSMP5 basemap, view, controls, zoom, rotation, details, timeline, and optional token parameters."},{"slug":"metaverse","title":"3D Metaverse","surface":"iframe","buildStatus":"exact-generator","credentialBoundary":"optional-browser-token","stateModel":"stateless-view","summary":"Embed an interactive 3D venue where Mappls has immersive coverage.","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/widgets/mappls-3D-metaverse-widget/readme/","evidenceBoundary":"The official page supplies the immersive path and Pin, optional token, place details, shadow, and rotation parameters. Venue coverage must be confirmed independently."},{"slug":"post-on-map","title":"Post on Map","surface":"iframe","buildStatus":"exact-generator","credentialBoundary":"none-documented","stateModel":"application-owned-state","summary":"Open the documented Post on Map contribution surface inside an owned host journey.","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/widgets/mappls-post-on-map/","evidenceBoundary":"The official page shows the postOnMap iframe path and display parameters. Submission identity, moderation, callbacks, and completion semantics are not inferred by this generator."},{"slug":"realview","title":"RealView Auth2","surface":"iframe","buildStatus":"exact-generator","credentialBoundary":"required-entitlement-token","stateModel":"application-owned-state","summary":"Show entitled panoramic street imagery near a Pin or coordinate.","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/widgets/mappls-realview-widget-auth2/","evidenceBoundary":"The official Auth2 page marks RealView as an access-controlled paid service and documents the pano iframe, required access_token, distance, control, and inset-map parameters. This lab emits only a placeholder."},{"slug":"add-a-place","title":"Add a Place","surface":"iframe","buildStatus":"exact-generator","credentialBoundary":"none-documented","stateModel":"application-owned-state","summary":"Collect a place contribution through the Mappls-hosted flow without treating submission UI as publication evidence.","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/widgets/mappls-add-a-place/addaplace/","evidenceBoundary":"The official page and demo establish the addAplace iframe and display parameters. Its examples append the first option with '&'; a dated public probe confirms the conventional '?' query shape succeeds while the documented ampersand path does not. No callback, receipt, moderation-status, withdrawal, or publication contract is documented."},{"slug":"mgis","title":"mGIS enterprise widgets","surface":"javascript-wrapper","buildStatus":"integration-guide","credentialBoundary":"company-contract-required","stateModel":"enterprise-stateful","summary":"Mount entitled mGIS work views and map widgets through the enterprise JavaScript wrapper.","officialDocumentationUrl":"https://developer.mappls.com/analytics/mgis-widgets","evidenceBoundary":"The official page documents widgets.js and MGIS.Widget(container, options), including widgetName, widgetKey, map settings, and workViewName. Keys, work views, tenant data, and lifecycle events belong to the enterprise contract."},{"slug":"native-widgets","title":"Native and cross-platform widgets","surface":"native-sdk","buildStatus":"integration-guide","credentialBoundary":"company-contract-required","stateModel":"application-owned-state","summary":"Use platform-owned autocomplete, nearby, direction, geofence, tracking, and picker journeys.","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/android/","evidenceBoundary":"Android, iOS, Flutter, and React Native publish distinct package, lifecycle, permission, and callback contracts. Select an exact platform/version guide; an iframe configuration cannot stand in for native integration."}],"addPlaceIntegration":{"verifiedAt":"2026-08-17","demoUrl":"https://embed.mappls.com/addAplace","supportedQueryShape":"https://embed.mappls.com/addAplace?position=top-left&zoom=16&pitch=0&fullscreen=true","sourceCorrection":"The official examples use '&' before the first option. On 2026-08-17 the base demo and conventional '?' query returned HTTP 200, while the literal documented ampersand path returned HTTP 401. Reconfirm this public behavior before release.","callbackBoundary":"No public source establishes a postMessage payload, submission receipt, moderation status, Mappls Pin return, withdrawal operation, or publication SLA. Frame load and visible success copy are not durable provider evidence.","lifecycle":[{"state":"draft","owner":"Host application","proof":"One contribution case owns business context, purpose, actor, consent, and bounded non-sensitive notes."},{"state":"widget_open","owner":"Browser lifecycle","proof":"One iframe generation is visible with loading, blocked, offline, cancel, and direct-link fallback states."},{"state":"submission_reported","owner":"User plus host","proof":"The user reports completing the hosted flow. This is interaction evidence only—not a Mappls receipt or published place."},{"state":"publication_pending","owner":"Host operations","proof":"A review task waits for an independently observable Mappls result under an explicit SLA and retry policy."},{"state":"published","owner":"Host reconciliation","proof":"A provider-backed search or approved Mappls receipt establishes the published Mappls Pin, observed fields, source, and time."},{"state":"rejected","owner":"Host operations","proof":"A documented provider outcome or attributable review records reason, evidence, appeal/retry policy, and attempt identity."},{"state":"withdrawn","owner":"Contributor or privacy operator","proof":"The application stops its case and retention workflow without claiming it withdrew an undocumented provider-side submission."}],"applicationRecords":["Contribution case: external business identity, purpose, actor, state, version, and current attempt","Attempt: iframe generation, source version, opened/reported times, and non-sensitive user confirmation","Publication evidence: Mappls Pin, provider-backed observation, observed fields, source fingerprint, event/receipt time, and reviewer","Audit/outbox: idempotency key, optimistic version, actor, event, downstream status, and retention action"],"useCases":[{"industry":"Retail","scenario":"A newly opened store is missing from discovery before launch week.","proof":"Case identity, authorized contributor, storefront evidence, category, review owner, and verified Mappls Pin."},{"industry":"Healthcare","scenario":"A new clinic must become discoverable without publishing unreviewed medical contact details.","proof":"Purpose, consent, approved public fields, location evidence, moderation outcome, and privacy retention."},{"industry":"Real estate","scenario":"A newly handed-over development needs one canonical entrance rather than duplicate listings.","proof":"Development identity, entrance coordinate, duplicate search, authoritative name, and reconciliation result."},{"industry":"Tourism","scenario":"A community documents a landmark while protecting sensitive or restricted locations.","proof":"Source attribution, safety review, category, public-interest basis, and bounded published detail."},{"industry":"Emergency services","scenario":"A new fire station must be discoverable while operational-only fields remain private.","proof":"Agency authority, public address, service category, publication observation, and prohibited-field review."},{"industry":"Events","scenario":"A temporary venue needs arrival guidance with an expiry and removal plan.","proof":"Event dates, temporary-location policy, arrival entrance, accessibility context, and post-event review."},{"industry":"Education","scenario":"A new campus gate should resolve consistently across admissions, transport, and safety apps.","proof":"Institution authority, entrance identity, address normalization, duplicate resolution, and shared Mappls Pin."}],"releaseTests":["Official base and '?' query shapes plus literal documented '&' regression","Frame load, blocked embedding, offline, slow, and direct-link fallback","Desktop, mobile, keyboard, screen reader, and focus return","No invented postMessage listener, provider receipt, Mappls Pin, or publication claim","Duplicate case and duplicate place search before contribution","User-reported submission remains distinct from publication evidence","Retry creates a linked attempt without overwriting failure history","Sensitive-field minimization, consent, retention, withdrawal, and support escalation","Idempotency replay, optimistic version conflict, restart recovery, audit, and outbox"]},"realViewIntegration":{"verifiedAt":"2026-08-17","currentWidgetOrigin":"https://pano.mappls.com","currentWidgetTemplate":"https://pano.mappls.com/realview_widget/{MAPPLS_PIN_OR_COORDINATE}?access_token={ENTITLED_BROWSER_TOKEN}","adjacentSurfaces":[{"surface":"Auth2 iframe","evidence":"Current official widget page","host":"pano.mappls.com","boundary":"Paid, access-controlled iframe with Mappls Pin or coordinate, required access_token, radius, navigation, inset-map, zoom, and control options."},{"surface":"Earlier iframe","evidence":"Separate official widget page","host":"realview.mappls.com","boundary":"Similar documented shape on a different host. Do not silently swap hosts; pin the account-approved generation."},{"surface":"Web Maps JS layer","evidence":"Public mappls-web-maps-js repository","host":"mapObj.realview(boolean)","boundary":"A map-layer toggle available from Web Maps JS v3.0, not the iframe callback or a panorama metadata API."},{"surface":"Local experimental thumbnail","evidence":"Local mapplsaiwebtesting implementation","host":"undocumented","boundary":"Uses layer introspection and an undocumented thumbnail path. It is adjacent implementation evidence only and is not published as a supported contract."}],"entitlementBoundary":"The Auth2 page marks RealView as paid and access controlled, requires an access_token in the iframe query, and says default OAuth access-token validity is 24 hours but configurable. The generator accepts no credential and emits only YOUR_ENTITLED_REALVIEW_ACCESS_TOKEN. Production must use the exact account-approved browser-visible credential class, expiry, origin policy, and renewal design; never substitute a server secret.","callbackContract":"The only documented parent-window signal is a no-imagery condition with data.status === 204. No success, panorama identity, capture date, camera pose, selected frame, measurement, annotation, export, or inspection-completion callback is established.","originCorrection":"The official example accepts any origin containing 'mappls.com'. Use exact equality with the selected contract origin—https://pano.mappls.com for Auth2—and a narrow payload schema. Subdomains such as attacker-mappls.com must not pass.","publicProbe":"On 2026-08-17 both documented iframe hosts returned an HTTP 200 shell without a token, but the shell explicitly rendered 'Required access_token.!'. HTTP success therefore proves neither entitlement nor imagery coverage.","lifecycle":[{"state":"draft","owner":"Host application","proof":"One inspection owns external asset/site identity, purpose, selected Mappls Pin or coordinate, data classification, and version."},{"state":"entitlement_pending","owner":"Platform administrator","proof":"Account, environment, approved widget generation, browser-visible credential class, origin restrictions, expiry, quota, and permitted use are recorded."},{"state":"ready","owner":"Host application","proof":"An unexpired entitlement reference and bounded viewer configuration exist; no token value or iframe URL has been persisted."},{"state":"viewing","owner":"Browser lifecycle","proof":"One attempt owns the exact iframe origin, location/radius config, token-handle reference, mount, message listener, timeout, and disposal."},{"state":"coverage_unavailable","owner":"Provider adapter","proof":"An exact-origin, schema-valid status 204 message is recorded for this attempt and configuration—not generalized into permanent absence."},{"state":"observation_recorded","owner":"Inspector","proof":"A human records a bounded checklist and notes with attempt identity and time; no undocumented panorama metadata or copied imagery is claimed."},{"state":"review_pending","owner":"Inspection operations","proof":"An immutable observation set awaits a separately authorized reviewer under a declared policy."},{"state":"accepted","owner":"Reviewer","proof":"A named reviewer accepts the observation set for its exact business purpose and policy version.","terminal":true},{"state":"rework_required","owner":"Reviewer","proof":"The review retains reason and prior evidence, then requires a new viewer attempt or alternate field evidence."},{"state":"cancelled","owner":"Inspector or operations","proof":"The inspection ends with actor and reason while every prior attempt and observation remains attributable.","terminal":true}],"applicationRecords":["Inspection aggregate: external asset/site identity, purpose, Mappls Pin or coordinate, state, version, assignee, and policy","Entitlement reference: approved product/host/environment, credential class, issued/expiry metadata, restrictions, and revocation state—never the token value","Viewer attempt: exact origin, location/radius/control config, token-handle reference, opened/disposed times, and validated 204 outcome","Observation/review: bounded checklist, inspector notes, attempt link, reviewer decision, policy version, event/receipt time, and retention class","Audit/outbox: command identity, optimistic version, actor, transition, delivery state, and cleanup action"],"useCases":[{"industry":"Utilities","scenario":"Review poles, cabinets, trenches, and right-of-way context before dispatching a survey crew.","proof":"Asset identity, imagery availability, human observation, visible limitations, reviewer, and field-verification trigger."},{"industry":"Road operations","scenario":"Triage a reported sign, shoulder, marking, or surface concern before scheduling inspection.","proof":"Road segment identity, observation time, bounded checklist, confidence limits, and maintenance/field escalation."},{"industry":"Insurance","scenario":"Understand public street context around a declared incident without treating imagery as incident-time evidence.","proof":"Claim purpose, place identity, imagery-source limitation, reviewer notes, and explicit prohibition on occurrence inference."},{"industry":"Real estate","scenario":"Review approach roads and neighborhood context for a property due-diligence queue.","proof":"Property/entrance identity, accessibility checklist, observed limitations, capture freshness unknown state, and review decision."},{"industry":"Retail","scenario":"Screen storefront approach, visibility, and pedestrian context before an on-site feasibility visit.","proof":"Candidate-site version, human observations, no automated footfall claim, reviewer, and required field-validation items."},{"industry":"Telecom","scenario":"Assess cabinet or tower approach constraints before dispatch and permit planning.","proof":"Asset identity, access-route observation, safety caveat, coverage result, and engineer review."},{"industry":"Government","scenario":"Prioritize civic-asset surveys across a large inspection backlog.","proof":"Public purpose, location scope, equitable prioritization policy, observation ledger, and field confirmation."},{"industry":"Travel","scenario":"Provide optional arrival context for a hotel or attraction with an accessible non-imagery alternative.","proof":"Stable place identity, optional viewer state, no-currentness promise, accessible text/map alternative, and handoff outcome."}],"releaseTests":["Issued paid entitlement, exact Auth2 host, environment, browser credential class, restrictions, expiry, quota, and revocation","Token never enters source, logs, analytics, persistence, model context, screenshots, support exports, or an application referrer","Exact https://pano.mappls.com origin equality rejects suffix, prefix, scheme, port, null, and sibling-host attacks","Message schema accepts only the documented integer status 204 no-imagery signal and never invents success fields","Mappls Pin and coordinate identity plus min/max radius boundary and stale-config invalidation","HTTP 200 shell, frame load, human viewing, 204 no imagery, and accepted inspection remain distinct evidence","Expired token, denied entitlement, unavailable coverage, slow/offline, blocked frame, and direct/accessible fallback","Mount, duplicate message, timeout, unmount, navigation, back-forward cache, and superseded attempt cleanup","No imagery copying, panorama metadata, measurement, automated inference, or licensing/retention right is assumed","Idempotency replay, optimistic conflict, reviewer separation, immutable rework, restart recovery, audit, and outbox"]}},"nativeWidgetMatrix":{"href":"/tools/widgets/native","api":"/api/native-widget-path","platforms":[{"slug":"android","platform":"Android","documentationVersion":"v2.0.2","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/android/","repositoryGuideSlugs":["mappls-android-sdk","mappls-android-compose-demo"],"supportedComponents":["Map SDK 9.0.3","Place Search Widget 3.0.2","Direction Widget 3.0.1","Nearby UI Widget 2.0.1","GeoFence Widget 2.0.0","Feedback UI 4.0.0"],"lifecycleOwner":"One Activity, Fragment, or Compose wrapper owns launch, callback registration, saved state, and disposal.","returnBoundary":"Translate the documented Activity/Fragment result into a small application selection before persisting it.","cancellationBoundary":"Back, close, process recreation, denied configuration, and an unavailable Activity are distinct outcomes.","credentialBoundary":"Use the updated post-August-2025 Android configuration files restricted to package and signing identity; never put a server credential in the APK.","productionChecks":["BoM/component versions resolve together","Debug and release signing identities are separately approved","Rotation and process death do not duplicate a commit","Fragment/Activity listeners are removed with their owner"],"scaffold":{"language":"kotlin","label":"Kotlin host contract","code":"data class PlaceSelection(val mapplsPin: String, val label: String)\n\ninterface MapplsPlaceWidget {\n    suspend fun selectPlace(): PlaceSelection? // null means deliberate cancellation\n}\n\nclass AddressDraft(private val widget: MapplsPlaceWidget) {\n    suspend fun choose(): PlaceSelection? = widget.selectPlace()?.also { selected ->\n        require(Regex(\"^[A-Za-z0-9]{6}$\").matches(selected.mapplsPin))\n        // Persist through the application repository, not a Fragment reference.\n    }\n}"},"verifiedAt":"2026-08-17"},{"slug":"ios","platform":"iOS","documentationVersion":"v2.0.2","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/ios-sdk/","repositoryGuideSlugs":["mappls-ui-widget-ios-distribution","mappls-nearby-ui-ios-distribution","mappls-direction-ui-ios-distribution","mappls-geofence-ui-ios-distribution"],"supportedComponents":["MapplsUIWidget 2.0.1","MapplsNearbyUI 2.0.0","MapplsDirectionUI 2.0.0","MapplsGeofenceUI 2.0.0","MapplsFeedbackUIKit 3.0.0","MapplsMap 6.1.4"],"lifecycleOwner":"One presenting UIViewController or SwiftUI representable owns presentation, delegate lifetime, dismissal, and cancellation.","returnBoundary":"Copy the documented delegate result into a Sendable application value before dismissing the provider controller.","cancellationBoundary":"Interactive dismissal, explicit cancel, delegate error, scene deactivation, and no result are represented separately.","credentialBoundary":"Bundle only the issued iOS configuration files for the exact bundle identity. Server tokens and cross-application configuration do not belong in the app.","productionChecks":["Swift Package versions match the documented release family","The delegate cannot outlive its presenting owner","Interactive dismissal records cancellation once","Scene restoration never reuses a stale candidate"],"scaffold":{"language":"swift","label":"Swift host contract","code":"struct PlaceSelection: Sendable {\n    let mapplsPin: String\n    let label: String\n}\n\nprotocol MapplsPlaceWidget: Sendable {\n    @MainActor func selectPlace() async throws -> PlaceSelection?\n}\n\n@MainActor\nfunc choose(using widget: any MapplsPlaceWidget) async throws -> PlaceSelection? {\n    guard let selected = try await widget.selectPlace() else { return nil }\n    precondition(selected.mapplsPin.range(of: #\"^[A-Za-z0-9]{6}$\"#, options: .regularExpression) != nil)\n    return selected // Repository commit happens outside the provider controller.\n}"},"verifiedAt":"2026-08-17"},{"slug":"flutter","platform":"Flutter","documentationVersion":"v2.0.1","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/flutter-sdk/","repositoryGuideSlugs":["mappls-flutter-sdk"],"supportedComponents":["Map SDK 2.0.5","Place Search Widget 2.0.0","Direction Widget 2.0.0","Nearby Widget 2.0.0"],"lifecycleOwner":"One route/widget state owns the MethodChannel launch Future, mounted check, cancellation, and application commit.","returnBoundary":"Validate the returned platform value, Mappls Pin, and request generation before updating Dart state.","cancellationBoundary":"A null result, PlatformException, route disposal, background interruption, and user cancellation are not interchangeable.","credentialBoundary":"Use the platform-specific Android/iOS configuration files associated with the final application identities; Web configuration is a separate browser boundary.","productionChecks":["Android and iOS plugin versions are resolved by one lockfile","Every awaited result checks mounted/generation","PlatformException is mapped to a typed UI state","A late result cannot update a disposed route"],"scaffold":{"language":"dart","label":"Dart host contract","code":"final class PlaceSelection {\n  const PlaceSelection(this.mapplsPin, this.label);\n  final String mapplsPin;\n  final String label;\n}\n\nabstract interface class MapplsPlaceWidget {\n  Future<PlaceSelection?> selectPlace();\n}\n\nFuture<void> choose(MapplsPlaceWidget widget) async {\n  final generation = ++_launchGeneration;\n  final selected = await widget.selectPlace();\n  if (!mounted || generation != _launchGeneration || selected == null) return;\n  if (!RegExp(r'^[A-Za-z0-9]{6}$').hasMatch(selected.mapplsPin)) throw const FormatException('invalid_mappls_pin');\n  setState(() => _selected = selected); // Persist through the app repository on submit.\n}"},"verifiedAt":"2026-08-17"},{"slug":"react-native","platform":"React Native","documentationVersion":"v2.0.0","officialDocumentationUrl":"https://developer.mappls.com/documentation/sdk/react-native-sdk/","repositoryGuideSlugs":["mappls-react-native-sdk"],"supportedComponents":["Map SDK 2.0.2","Place Search Widget 2.0.0","Direction Widget 2.0.1","Nearby UI Widget 2.0.0","GeoFence Widget 2.0.0"],"lifecycleOwner":"One focused screen owns the native Promise, bridge generation, AppState changes, cancellation, and normalized JavaScript result.","returnBoundary":"Parse unknown bridge data into a versioned TypeScript value; do not store an opaque native result object.","cancellationBoundary":"Promise rejection, native cancellation, screen blur/unmount, bridge reload, and malformed data are typed separately.","credentialBoundary":"Configure both native applications with their own issued files and identities. No privileged REST credential belongs in JavaScript or the bundle.","productionChecks":["Public repository and developer-documentation version drift is resolved before dependency pinning","Peer native SDK versions are compatible","Only the focused mounted screen accepts a Promise result","Bridge data is schema-validated","Fast Refresh and native recreation do not double-commit"],"scaffold":{"language":"typescript","label":"TypeScript host contract","code":"type PlaceSelection = { version: 1; mapplsPin: string; label: string };\n\ninterface MapplsPlaceWidget {\n  selectPlace(): Promise<unknown>;\n}\n\nasync function choose(widget: MapplsPlaceWidget, generation: number) {\n  const value = await widget.selectPlace();\n  if (!isFocused() || generation !== currentGeneration()) return;\n  if (!isPlaceSelection(value)) throw new Error(\"invalid_widget_result\");\n  commitCandidate(value); // Store normalized data, never the opaque native object.\n}\n\nfunction isPlaceSelection(value: unknown): value is PlaceSelection {\n  const item = value as Partial<PlaceSelection> | null;\n  return item?.version === 1 && /^[A-Za-z0-9]{6}$/.test(item.mapplsPin ?? \"\") && typeof item.label === \"string\";\n}"},"verifiedAt":"2026-08-17","repositoryObservation":{"documentationVersion":"v2.0.1","supportedComponents":["Map SDK 2.0.3","Place Search Widget 2.0.1","Direction Widget 2.0.2","Nearby UI Widget 2.0.1","GeoFence Widget 2.0.1"],"sourceUrl":"https://github.com/mappls-api/mappls-react-native-sdk","observedAt":"2026-08-17","boundary":"The public repository main branch is newer than the current developer-documentation root. Confirm the released package, native peer versions, and selected widget guide before pinning dependencies."}}],"capabilities":[{"slug":"place-search","title":"Place search and picker","stateModel":"selection","durableIdentity":"Mappls Pin plus application-owned display label","platforms":{"android":{"availability":"published","component":"Place Search Widget","version":"3.0.2","documentationUrl":"https://developer.mappls.com/documentation/sdk/android/"},"ios":{"availability":"published","component":"MapplsUIWidget","version":"2.0.1","documentationUrl":"https://developer.mappls.com/documentation/sdk/ios-sdk/"},"flutter":{"availability":"published","component":"Place Search Widget","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/flutter-sdk/"},"react-native":{"availability":"published","component":"Place Search Widget","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/react-native-sdk/"}}},{"slug":"nearby","title":"Nearby discovery","stateModel":"session","durableIdentity":"Query/category generation plus selected Mappls Pin","platforms":{"android":{"availability":"published","component":"Nearby UI Widget","version":"2.0.1","documentationUrl":"https://developer.mappls.com/documentation/sdk/android/"},"ios":{"availability":"published","component":"MapplsNearbyUI","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/ios-sdk/"},"flutter":{"availability":"published","component":"Nearby Widget","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/flutter-sdk/docs/v2.0.0/Nearby-Widget/"},"react-native":{"availability":"published","component":"Nearby UI Widget","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/react-native-sdk/docs/v2.0.0/Nearby-Widget/"}}},{"slug":"directions","title":"Directions UI","stateModel":"session","durableIdentity":"Application route request/revision identity; provider UI is not a navigation session","platforms":{"android":{"availability":"published","component":"Direction Widget","version":"3.0.1","documentationUrl":"https://developer.mappls.com/documentation/sdk/android/"},"ios":{"availability":"published","component":"MapplsDirectionUI","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/ios-sdk/"},"flutter":{"availability":"published","component":"Direction Widget","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/flutter-sdk/"},"react-native":{"availability":"published","component":"Direction Widget","version":"2.0.1","documentationUrl":"https://developer.mappls.com/documentation/sdk/react-native-sdk/"}}},{"slug":"geofence","title":"Geofence editor","stateModel":"draft","durableIdentity":"Versioned application geofence draft and provider rule identity after separate publication","platforms":{"android":{"availability":"published","component":"GeoFence Widget","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/android/"},"ios":{"availability":"published","component":"MapplsGeofenceUI","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/ios-sdk/"},"flutter":{"availability":"not-listed-in-current-overview","component":null,"version":null,"documentationUrl":"https://developer.mappls.com/documentation/sdk/flutter-sdk/"},"react-native":{"availability":"published","component":"GeoFence Widget","version":"2.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/react-native-sdk/docs/v2.0.0/Geofence-Widget/"}}},{"slug":"feedback","title":"Feedback UI","stateModel":"draft","durableIdentity":"Application feedback draft and attributable submission/reconciliation identity","platforms":{"android":{"availability":"published","component":"Feedback UI","version":"4.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/android/"},"ios":{"availability":"published","component":"MapplsFeedbackUIKit","version":"3.0.0","documentationUrl":"https://developer.mappls.com/documentation/sdk/ios-sdk/"},"flutter":{"availability":"not-listed-in-current-overview","component":null,"version":null,"documentationUrl":"https://developer.mappls.com/documentation/sdk/flutter-sdk/"},"react-native":{"availability":"not-listed-in-current-overview","component":null,"version":null,"documentationUrl":"https://developer.mappls.com/documentation/sdk/react-native-sdk/"}}}],"pairings":20},"mgisPlanner":{"href":"/tools/mgis","api":"/api/mgis-plan","summary":{"verifiedAt":"2026-08-17","officialWidgetFamilies":4,"repositoryWidgetFamilies":7,"webMethods":12,"apiGroups":8,"surfaces":4},"surfaces":[{"slug":"widget-wrapper","title":"mGIS integrated widget wrapper","stateModel":"browser-runtime","readiness":"entitlement-required","summary":"Mount an entitled MGIS.Widget map/workview surface with 2D or 3D view, basemap selection, and basic map controls.","durableIdentity":"Tenant/workspace plus approved workViewName and application-owned embedding record","credentialBoundary":"The official option is widgetKey and describes it as an access token. It is browser-visible. Use only the credential class, origin restrictions, lifetime, and tenant scope approved for this wrapper; never substitute a server secret.","sourceLabels":["Official mGIS Widgets","Public widget repository"],"sourceUrls":["https://developer.mappls.com/analytics/mgis-widgets","https://github.com/mappls-api/mapmyindia-mgis-libraries"],"evidenceBoundary":"The official page lists Map View 2D/3D, Workview, Basemap Option, and Basic Map Tools and documents MGIS.Widget(container, options). The public repository supplies the hosted widgets.js URL and additionally describes 3D Landmark, Real View, and Tour; those extra families require current contract confirmation."},{"slug":"web-sdk-methods","title":"mGIS methods for Web Maps JS","stateModel":"browser-runtime","readiness":"entitlement-required","summary":"List, render, inspect, style, bound, and visualize entitled tenant or catalog datasets through the documented v1.0 browser module.","durableIdentity":"Dataset/workspace identity, style revision, view revision, and feature identity copied into application state","credentialBoundary":"The documented methods accept access_token in browser JavaScript. This planner emits only YOUR_MAPPLS_MGIS_ACCESS_TOKEN and never accepts a credential value.","sourceLabels":["Official Web JS mGIS Methods v1.0"],"sourceUrls":["https://developer.mappls.com/documentation/sdk/Web/Web%20JS/docs/V3.0/mGIS_Methods/"],"evidenceBoundary":"The official method guide documents twelve discovery, visualization, info, style, bounds, centroid, catalog, and raster calls. Two examples contain naming drift and remain selection-required until confirmed."},{"slug":"workspace-apis","title":"mGIS dataset and analysis workspace","stateModel":"workspace-stateful","readiness":"contract-selection-required","summary":"Build durable ingestion, validation, publication, styling, query, visualization, raster, AI/ML, and export workflows around mGIS resources.","durableIdentity":"Workspace, immutable dataset version, style revision, analysis attempt, output version, and governed share","credentialBoundary":"Execute stateful API calls from a trusted service using the account-specific authentication contract. Never infer a write endpoint, reuse a browser token as a server credential, or retry an unknown write with a new identity.","sourceLabels":["Official mGIS APIs","Public mGIS API repository"],"sourceUrls":["https://developer.mappls.com/analytics/mgis-apis/","https://github.com/mappls-api/mapmyindia-mgis-apis"],"evidenceBoundary":"The official overview and public repository establish API groups and lifecycle intent, but several exact operation contracts route to Swagger or API Support. This surface therefore provides a state machine and adapter seam, not manufactured URLs."},{"slug":"sovereign-migist","title":"Mappls IGIST sovereign deployment","stateModel":"deployment-stateful","readiness":"local-reference","summary":"Evaluate the separate MIGIST SDK/API/Thin Client distribution for sovereign, defence, offline, and air-gapped GIS deployments.","durableIdentity":"Deployment, license, node, release manifest, capability provider, workspace, actor, and audit event","credentialBoundary":"MIGIST uses deployment-local identity, license, API-key/OAuth, RBAC, and audit contracts. It is not the mGIS cloud widget key and must not be presented as drop-in compatible.","sourceLabels":["Local migist-complete architecture","Local MIGIST SDK specification"],"sourceUrls":["/sources/local-rohan-migist-complete","/sources/local-rohan-migist-complete"],"evidenceBoundary":"The local distribution explicitly positions MIGIST as a sovereign product layer over IGIST with SDK, API, Thin Client, licensing, offline assets, and air-gap deployment. Its architecture also states that uniform capability routing and full IGIST adapter coverage are not yet complete."}],"methods":[{"slug":"layer-list","title":"List tenant datasets","callName":"getLayerList","purpose":"Fetch datasets visible to the entitled mGIS account.","requiredFields":["access_token"],"optionalFields":[],"evidenceStatus":"documented","evidenceBoundary":"Exact constructor name and access_token are documented."},{"slug":"dataset-map","title":"Render a dataset map","callName":"getMap","purpose":"Render point, line, or polygon tenant data as a WMS-backed map layer.","requiredFields":["map","datasetName","access_token"],"optionalFields":["id","bbox","srs","service","version","format","transparent","crossOrigin","zIndex","styles"],"evidenceStatus":"documented","evidenceBoundary":"Exact constructor and WMS-oriented fields are documented."},{"slug":"feature-info","title":"Inspect one dataset feature","callName":"getFeatureInfo","purpose":"Fetch feature attributes at a projected map pixel.","requiredFields":["map","datasetName","x","y","access_token"],"optionalFields":["style"],"evidenceStatus":"naming-confirmation-required","evidenceBoundary":"The heading documents getFeatureInfo while its example invokes getCatalogFeatureInfo. Confirm the tenant-dataset call name before release."},{"slug":"legend","title":"Render a dataset legend","callName":"getLegendImage","purpose":"Attach the style legend for a rendered tenant dataset.","requiredFields":["map","datasetName","access_token"],"optionalFields":["styles","position","draggable"],"evidenceStatus":"documented","evidenceBoundary":"The method, map/dataset inputs, and legend presentation fields are documented."},{"slug":"styles","title":"Read dataset styles","callName":"getStyles","purpose":"Read the applied style definition for a dataset.","requiredFields":["datasetName","styleType","access_token"],"optionalFields":[],"evidenceStatus":"documented","evidenceBoundary":"The exact constructor, datasetName, styleType, and access_token are documented."},{"slug":"set-layer-style","title":"Apply a layer style","callName":"setStyle","purpose":"Create or update a basic, category, bubble, cluster, heat, chart, or rule-based style.","requiredFields":["datasetName","styleType","access_token"],"optionalFields":["style properties","label"],"evidenceStatus":"naming-confirmation-required","evidenceBoundary":"The table of contents says setLayerStyle while the section example invokes mappls.setStyle. Confirm the exported constructor and exact style schema before release."},{"slug":"bounding-box","title":"Read a dataset extent","callName":"getBoundingBox","purpose":"Fetch the bounding box of a tenant or scoped layer.","requiredFields":["datasetName","access_token"],"optionalFields":["query","dataStoreName","layerType","countryName"],"evidenceStatus":"documented","evidenceBoundary":"The exact constructor and dataset extent fields are documented."},{"slug":"feature-centroid","title":"Read a feature centroid","callName":"getFeatureCentroid","purpose":"Fetch the centroid of one tenant or catalog feature.","requiredFields":["datasetName","featureID","access_token"],"optionalFields":["datastorename"],"evidenceStatus":"documented","evidenceBoundary":"The exact constructor, datasetName, featureID, and optional catalog datastore are documented."},{"slug":"catalog-map","title":"Render a Mappls catalog layer","callName":"getCatalogMap","purpose":"Render an entitled Mappls administrative catalog dataset.","requiredFields":["map","datasetName","dataStoreName","access_token"],"optionalFields":["id","layers","layerType"],"evidenceStatus":"documented","evidenceBoundary":"The catalog constructor and required datastore identity are documented."},{"slug":"catalog-feature-info","title":"Inspect a catalog feature","callName":"getCatalogFeatureInfo","purpose":"Fetch attributes for one clicked Mappls catalog feature.","requiredFields":["map","datasetName","dataStoreName","x","y","access_token"],"optionalFields":["style"],"evidenceStatus":"documented","evidenceBoundary":"The exact catalog feature-info constructor and pixel inputs are documented."},{"slug":"catalog-legend","title":"Render a catalog legend","callName":"getCatalogLegendImage","purpose":"Attach the legend for a rendered Mappls catalog layer.","requiredFields":["map","datasetName","styles","type","access_token"],"optionalFields":["position","draggable"],"evidenceStatus":"documented","evidenceBoundary":"The catalog legend constructor, style, type, and presentation fields are documented."},{"slug":"raster-catalog-map","title":"Render a raster catalog layer","callName":"getRasterCatalogMap","purpose":"Visualize an entitled raster catalog dataset such as a night-light layer.","requiredFields":["map","datasetName","access_token"],"optionalFields":["id"],"evidenceStatus":"documented","evidenceBoundary":"The raster catalog constructor and dataset identity are documented."}],"apiGroups":[{"title":"Search & navigation","purpose":"Batch geocode, reverse-geocode, and routing layers from tabular inputs.","lifecycle":"asynchronous derived dataset"},{"title":"Data operations","purpose":"Save/append/truncate, describe, list, type, and read datasets.","lifecycle":"versioned dataset"},{"title":"Layer styling","purpose":"Create and revise thematic visualization rules.","lifecycle":"style revision"},{"title":"Dataset query & validation","purpose":"Filter, join, aggregate, transform, and save results.","lifecycle":"analysis attempt and output"},{"title":"Layer visualization & info","purpose":"Render maps, feature info, and legends.","lifecycle":"view revision"},{"title":"Raster catalogue","purpose":"Discover and visualize entitled raster datasets.","lifecycle":"catalog reference"},{"title":"Satellite AI/ML","purpose":"Run entitled imagery segmentation workflows.","lifecycle":"long-running model job"},{"title":"Feature export","purpose":"Export governed output into documented geospatial formats.","lifecycle":"export request and artifact"}]},"automotiveReleaseControl":{"href":"/tools/automotive","journey":"/journeys/offline-automotive-release","sample":"/samples/offline-release-control","contract":{"verifiedAt":"2026-08-17","title":"Offline and automotive release control","readiness":"entitlement-and-contract-required","publicBoundary":"The public Mappls organization advertises NaviMaps SDK APIs for hybrid embedded navigation and the public Android index names NCASE, NaviMaps, and Navigation SDK families. The reviewed public snapshot does not establish the production automotive runtime, package, activation, compiler, vehicle-interface, or safety contract.","localBoundary":"Local repositories contain a newer Telecons engine line with map, search, route, simulation, GPS, voice, traffic-event customization, and 2026 release evidence; a separate legacy Hybrid Android SDK; and sparse earlier Linux/navigation repositories. These generations are adjacent evidence, not interchangeable SDK syntax.","credentialBoundary":"The reference workflow accepts no credential, activation key, license file, protected package, binary, package URL, or artifact body. It persists only non-secret entitlement references, manifest identities, verifier attestations, target compatibility, and release decisions.","runtimeBoundary":"Fixture qualification proves the application control plane only. It does not emulate Mappls navigation, certify a package, establish road safety, or replace the entitled runtime owner's acceptance suite.","publicEvidence":[{"label":"Mappls API public organization","url":"https://github.com/mappls-api","evidence":"Advertises NaviMaps SDK APIs as hybrid navigation for embedded systems."},{"label":"Mappls Android documentation index","url":"https://developer.mappls.com/documentation/sdk/android/","evidence":"Names NCASE Automotive Suite, NaviMaps, and Navigation SDK product families without exposing an automotive implementation contract in the reviewed index."}],"evidenceGenerations":[{"generation":"Public product surface","source":"github.com/mappls-api and developer.mappls.com","status":"public-product-evidence","capabilities":["NaviMaps embedded/hybrid navigation family","NCASE and Navigation SDK family names"],"boundary":"Product discovery evidence only; obtain the entitled edition and exact contract before implementation."},{"generation":"Telecons engine line","source":"local/mappls-telecons-offline-sdk","status":"local-current-reference","capabilities":["Map rendering","Offline and online route planning","Search and nearby","Simulation","GPS state","Voice guidance","Traffic-event customization"],"boundary":"Local implementation evidence dated through March 2026; not a public redistribution or compatibility promise."},{"generation":"Hybrid Android line","source":"local/offline-sdk","status":"local-legacy-reference","capabilities":["Region download","Offline/online mode switching","Map lifecycle","Offline map/search/route concept"],"boundary":"Legacy MapmyIndia 0.0.1 documentation exposes app-held credential patterns that must not be copied into a current architecture."},{"generation":"Earlier embedded lines","source":"local/linuxsdk-dev1, linuxsdk-dev2, mapmyindia-navigation-sdk","status":"identity-only-reference","capabilities":["Repository identity"],"boundary":"Sparse READMEs do not establish symbols, versions, compatibility, or readiness."}],"releasePhases":[{"phase":"manufacture","owner":"Manufacturing system","proof":"Unique hardware, vehicle, edition, target CPU/ABI/OS/graphics, and manufacturing batch identity."},{"phase":"activate","owner":"Fleet release manager","proof":"Non-secret entitlement reference, edition, regions, expiry, offline grace, and restriction fingerprint."},{"phase":"install","owner":"Package verifier","proof":"One signed manifest binds runtime, data, configuration, voice, target, component hashes, and observed content digest."},{"phase":"qualify","owner":"Vehicle runtime","proof":"Versioned startup, render, offline search, offline route, position, voice, and storage suite passes."},{"phase":"update","owner":"Release control plane","proof":"Inactive slot advances through download, verification, staging, atomic switch, and target qualification checkpoints."},{"phase":"recover","owner":"Boot control and watchdog","proof":"Power loss or health regression selects a known-good slot without erasing the rejected manifest or incident."},{"phase":"retire","owner":"Fleet release manager","proof":"Activation and protected-package access are revoked while release and support history remain."}],"durableRecords":["Device identity: hardware, vehicle, product edition, target facts, and lifecycle version.","Release manifest: runtime, data, configuration, voice, target, component digests, and verifier reference.","A/B slot table: active pointer, previous known-good pointer, slot status, and immutable manifest identity.","Update plan: campaign, source/target slots, phase checkpoints, interruption, switch, and qualification evidence.","Qualification and incident ledgers: suite version, results, signal, action, outcome, actor, and time.","Append-only audit and transactional outbox committed with every state change."],"useCases":[{"industry":"Passenger vehicles","scenario":"Head-unit map and guidance release","proof":"Cold boot, local render/search/route, vehicle-signal simulation, voice, HMI policy, and rollback."},{"industry":"Commercial fleets","scenario":"Regional truck navigation rollout","proof":"Vehicle profile, restricted-road data, cohort health, offline grace, and route-regression threshold."},{"industry":"Mining","scenario":"Disconnected haul-road navigation","proof":"Private-region package identity, long offline operation, positioning degradation, storage health, and field recovery."},{"industry":"Agriculture","scenario":"Farm machinery guidance console","proof":"Seasonal regional data, rugged-device target, intermittent activation refresh, operator controls, and rollback."},{"industry":"Emergency response","scenario":"Resilient in-vehicle map stack","proof":"Deterministic boot, offline place/route availability, stale-data disclosure, power interruption, and safe degraded mode."},{"industry":"Public transit","scenario":"Bus console release campaign","proof":"Route-set compatibility, depot cohorting, audio prompts, driver-distraction review, and watchdog evidence."},{"industry":"Industrial mobility","scenario":"Yard and port vehicle terminals","proof":"Facility data edition, target GPU/ABI, GNSS shadow handling, restricted zones, and support diagnostics."},{"industry":"Two-wheelers","scenario":"Compact offline navigation display","proof":"Storage budget, simplified HMI, voice/haptic policy, power cycling, and target-specific qualification."}],"releaseTests":["Reject CPU, ABI, OS, graphics, runtime, data, configuration, or voice incompatibility before active-slot mutation.","Reject malformed manifests, mismatched observed digests, failed signature attestations, and protected artifact input.","Prove there is exactly one bootable active slot through interruption at every update checkpoint.","Power loss before the switch boots the unchanged known-good slot and retains resumable staging evidence.","Power loss after the switch but before qualification restores the prior known-good slot.","A newly qualified route, crash, rendering, positioning, voice, or storage regression halts the cohort and rolls back.","Expired activation follows the contracted offline-grace policy and cannot be extended by changing device time.","Idempotent replay and stale aggregate versions cannot duplicate campaigns, switches, incidents, audit, or outbox work.","Process restart recovers device, slots, phase checkpoints, qualification, incidents, audit, and outbox atomically.","Retirement revokes protected access without deleting manifests, support evidence, or prior release decisions."]}},"visionEvidenceWorkflow":{"href":"/tools/vision","journey":"/journeys/vision-inference-review","sample":"/samples/vision-evidence-desk","contract":{"verifiedAt":"2026-08-17","title":"SkyDNN vision evidence workflow","readiness":"entitlement-and-model-selection-required","publicBoundary":"The public SkyDNN repository establishes a bearer-authenticated OpenAPI 3 surface at ai.mappls.com with synchronous multipart POST /predict and model-discovery GET operations. Its prose also mentions /predict/polygon, but that path is absent from the reviewed OpenAPI document and therefore remains selection-required rather than an implemented contract.","marketingBoundary":"Current Mappls material describes satellite imagery, street photographs, and video frames returning confidence, labels, and bounding-box, polygon, or polyline geometry. It also advertises JavaScript integration and human-in-the-loop annotation workflows, but does not make those exact SDK or review-state contracts available in the reviewed public repository.","localBoundary":"The local source snapshot mirrors the public API documentation and contains a separate beta SkyDNN category-icon package with nineteen map/road ontology icons. Icon names, internal paths, model configuration examples, and historic release metadata are evidence for documentation review—not a stable inference SDK or production model entitlement.","trustBoundary":"The reference workflow accepts no image bytes, image URL, video frame, bearer token, face, number plate, or provider-internal model path. It uses fixture asset hashes and synthetic provider envelopes to prove application state, validation, review, retention, audit, and recovery without redistributing imagery or credentials.","providerBoundary":"The documented POST /predict response is synchronous. Queueing, case state, policy evaluation, reviewer decisions, retention, redaction, retry, and outbox delivery in the reference app are explicitly application-owned; they are not represented as SkyDNN provider features.","publicEvidence":[{"label":"Mappls SkyDNN public repository","url":"https://github.com/mappls-api/skydnn-aiapi-docs","evidence":"Documents model discovery and synchronous JSON prediction from multipart imagery."},{"label":"Mappls SkyDNN AI APIs","url":"https://about.mappls.com/skydnn/ai-apis/","evidence":"Describes satellite, street, and video-frame inputs plus confidence, label, and geometry outputs."},{"label":"Mappls SkyDNN platform","url":"https://about.mappls.com/skydnn/skydnn-platform/","evidence":"Describes distributed assets, inference visualization, annotation, and human-in-the-loop workflows at product level."}],"operations":[{"method":"GET","path":"/server/whoami","purpose":"Discover the model keys currently exposed by the entitled server.","contract":"public-openapi"},{"method":"GET","path":"/models","purpose":"List available model details.","contract":"public-openapi"},{"method":"GET","path":"/models/{api_model_key}","purpose":"Inspect one selected model before inference.","contract":"public-openapi"},{"method":"POST","path":"/predict","purpose":"Submit one multipart image and receive a synchronous JSON inference response.","contract":"public-openapi"},{"method":"POST","path":"/predict/polygon","purpose":"Mentioned in prose but absent from the reviewed OpenAPI; confirm before use.","contract":"selection-required"}],"lifecycle":[{"state":"registered","owner":"Asset steward","proof":"Purpose, lawful basis, asset hash, media class, capture time, location context, retention deadline, and no raw media in the case store."},{"state":"model_locked","owner":"Vision service","proof":"Entitled server identity, selected model key, model fingerprint, classes, policy version, and input compatibility."},{"state":"inference_requested","owner":"Application worker","proof":"One idempotent attempt identity, exact asset and model fingerprints, and a secret-safe provider request boundary."},{"state":"inferred","owner":"Application adapter","proof":"Schema-valid status, timing, output hash, labels, confidence, normalized geometry, and provider provenance separated from business policy."},{"state":"review_pending","owner":"Decision service","proof":"Versioned thresholds, reason codes, uncertainty band, required reviewer role, and immutable inference evidence."},{"state":"accepted_or_rejected","owner":"Independent reviewer","proof":"Attributable decision, reason, policy/model/output identities, separation of duties, and no rewritten inference."},{"state":"redacted","owner":"Privacy worker","proof":"Derived detection detail removed at retention deadline while minimal hashes, decision, and audit evidence remain."}],"durableRecords":["Vision case: external identity, purpose, state, optimistic version, policy, and retention boundary.","Asset envelope: opaque asset reference, SHA-256 content identity, media class, dimensions, capture time, location context, and consent or lawful-basis reference.","Model lock: server reference, API model key, model fingerprint, class vocabulary, compatibility decision, and lock time.","Inference attempt: request identity, asset/model fingerprints, lifecycle timing, outcome, safe error class, normalized result, and response hash.","Policy and review: thresholds, uncertainty reasons, reviewer, disposition, explanation, and immutable linkage to one inference attempt.","Retention, audit, command receipt, and transactional outbox records committed with every transition."],"useCases":[{"industry":"Urban planning","scenario":"Building-footprint change triage","proof":"Satellite source/date, polygon validity, confidence band, temporal comparison, and planner review."},{"industry":"Road operations","scenario":"Lane and road-furniture survey","proof":"Sequence/frame identity, camera context, polyline or box normalization, duplicate suppression, and field verification."},{"industry":"Retail mapping","scenario":"Shop-sign and POI discovery","proof":"Purpose-limited imagery, text/box confidence, Mappls place reconciliation, reviewer confirmation, and privacy controls."},{"industry":"Automotive","scenario":"ADAS dataset quality gate","proof":"Model/version lock, scenario coverage, false-negative review, no live safety actuation, and release acceptance outside this API."},{"industry":"Utilities","scenario":"Roadside asset inventory","proof":"Asset class vocabulary, geometry projection, route/date provenance, human verification, and maintenance-system identity."},{"industry":"Agriculture","scenario":"Vegetation and water segmentation","proof":"Imagery resolution/date, area-of-interest identity, polygon topology, seasonal baseline, and agronomist review."},{"industry":"Insurance","scenario":"Visual damage triage","proof":"Explicit consent, no biometric reuse, confidence as triage only, adjuster review, retention, and appeal evidence."},{"industry":"Privacy operations","scenario":"Face and plate redaction quality","proof":"Sensitive-class policy, miss-rate sampling, access restriction, derived-output retention, and independent audit."}],"releaseTests":["Reject image bodies, media URLs, bearer tokens, credentials, faces, plates, and provider-internal file paths at the reference-app boundary.","Reject malformed asset hashes, unsupported media classes, invalid dimensions, expired lawful basis, and retention deadlines outside policy.","Lock only a model key observed through the entitled model-discovery boundary and retain its fingerprint across the attempt.","Never represent an application queue, review, retry, redaction, or terminal business decision as a SkyDNN provider state.","Normalize rectangles, polygons, and polylines only after bounds, topology, label, score, and source-dimension validation.","Route low confidence, unsupported labels, malformed geometry, privacy-sensitive classes, and policy ambiguity to independent review.","Prevent the inference actor from reviewing its own recommendation and preserve rejection or override reasons.","Make request replay and stale versions unable to duplicate inference attempts, reviews, audit, or outbox work.","Recover cases, attempts, decisions, command receipts, audit, and outbox atomically after process restart.","Redact derived detections at retention expiry without deleting minimal decision, policy, hash, and audit evidence."]}},"products":[{"slug":"maps","name":"Maps","eyebrow":"Render the world","category":"Core location","summary":"Fast, expressive vector and raster maps across web, mobile, hybrid, and embedded apps.","description":"Build location experiences with global basemaps, India-first detail, 3D buildings, traffic, custom styles, annotations, GeoJSON, KML, heatmaps, raster catalogues, and camera controls. Use native SDKs for deep platform integration or Web Maps JS for the fastest path to an interactive map.","accent":"#7c5cff","stateModel":"stateless","platforms":["Web","Android","iOS","React Native","Flutter","Cordova","Xamarin","REST"],"capabilities":["Vector and raster basemaps","Markers, shapes, layers, and overlays","Traffic and thematic visualization","Custom styles and camera controls","Static and travelled-route images","Offline and embedded map packages"],"repositories":["mappls-web-maps-js","mappls-android-sdk","mappls-ios-sdk","mappls-flutter-sdk","mappls-react-native-sdk","mappls-map-ios-distribution"],"auth":{"type":"Static key or access token","guidance":"Use a domain-restricted static key for browser SDKs and server-issued credentials for trusted backends."},"samples":[{"language":"html","label":"Web Maps JS","code":"<!doctype html>\n<html>\n  <head>\n    <script src=\"https://sdk.mappls.com/map/sdk/web?v=3.0&access_token=YOUR_STATIC_KEY\"></script>\n    <style>html, body, #map { height: 100%; margin: 0; }</style>\n  </head>\n  <body>\n    <div id=\"map\"></div>\n    <script>\n      const map = new mappls.Map(\"map\", {\n        center: { lat: 28.612964, lng: 77.229463 },\n        zoom: 12\n      });\n    </script>\n  </body>\n</html>"},{"language":"kotlin","label":"Android","code":"// app/build.gradle.kts\ndependencies {\n  implementation(platform(\"com.mappls.sdk:mappls-bom:VERSION\"))\n  implementation(\"com.mappls.sdk:mappls-android-sdk\")\n}\n\n// Application.kt\nclass Application : android.app.Application() {\n  override fun onCreate() {\n    super.onCreate()\n    Mappls.getInstance(this)\n  }\n}"}]},{"slug":"search-places","name":"Search & Places","eyebrow":"Turn intent into place","category":"Core location","summary":"Autosuggest, geocoding, nearby discovery, place details, and Mappls Pin addressing.","description":"Resolve messy human intent into precise places. Search as a user types, convert addresses to coordinates, reverse coordinates into addresses, discover relevant POIs, inspect place details, search along a route, and use compact Mappls Pins instead of error-prone latitude and longitude pairs.","accent":"#00a88f","stateModel":"stateless","platforms":["REST","Web","Android","iOS","React Native","Flutter","Widgets"],"capabilities":["Autosuggest and text search","Forward and reverse geocoding","Nearby and route-corridor search","Place details and categories","Address validation and standardization","Mappls Pin and DIGIPIN workflows"],"repositories":["mappls-rest-apis","mappls-android-sdk","mappls-ios-sdk","mappls-web-plugins"],"auth":{"type":"Restricted static key (current) or OAuth bearer (legacy)","guidance":"Current core REST uses a restricted static key in the documented access_token query contract. The pre-August-2025 line uses OAuth bearer with legacy hosts and paths. Never mix generations; keep server-use keys off untrusted clients and request logs."},"samples":[{"language":"javascript","label":"Autosuggest","code":"import { createMapplsClientFromEnvironment } from \"@mappls/server-sdk\";\n\n// MAPPLS_STATIC_KEY is applied using the current documented query contract.\n// Keep the restricted key inside this trusted server process.\nconst mappls = createMapplsClientFromEnvironment();\nconst suggestions = await mappls.autosuggest({\n  query: \"coffee\",\n  region: \"IND\"\n});"}]},{"slug":"routes-navigation","name":"Routes & Navigation","eyebrow":"Move with confidence","category":"Mobility","summary":"Routes, matrices, optimization, map matching, predictive ETAs, and turn-by-turn navigation.","description":"Plan and operate journeys for cars, bikes, trucks, pedestrians, and fleets. Choose between single-shot route calculations and a stateful navigation session that continuously responds to progress, traffic, deviations, incidents, and destination changes.","accent":"#ff7a45","stateModel":"hybrid","platforms":["REST","Android","iOS","Automotive","Linux","React Native"],"capabilities":["Multi-profile routing and alternatives","Distance and time matrices","Trip and vehicle-route optimization","Map matching and snap-to-road","Predictive routes and refreshed ETAs","Online and offline turn-by-turn navigation"],"repositories":["mappls-rest-apis","mappls-android-sdk","mappls-ios-sdk","mapmyindia-navigation-sdk","mappls-routenet","mappls-telecons-offline-sdk"],"auth":{"type":"Restricted static key (current) or legacy OAuth, plus SDK entitlement","guidance":"Current core REST routing uses the restricted static-key query contract; legacy OAuth requires its issued host/path generation. Route calls are stateless, while navigation requires an entitled, lifecycle-aware SDK session."},"samples":[{"language":"kotlin","label":"Route request","code":"val route = MapplsDirections.builder()\n  .origin(\"MMI000\")\n  .destination(\"MMI001\")\n  .profile(DirectionsCriteria.PROFILE_DRIVING)\n  .resource(DirectionsCriteria.RESOURCE_ROUTE)\n  .steps(true)\n  .build()\n\nroute.enqueueCall(object : Callback<DirectionsResponse> {\n  override fun onResponse(call: Call<DirectionsResponse>, response: Response<DirectionsResponse>) {\n    val primaryRoute = response.body()?.routes()?.firstOrNull()\n  }\n  override fun onFailure(call: Call<DirectionsResponse>, error: Throwable) = Unit\n})"}],"journey":{"title":"A complete navigation session","description":"Treat navigation as a durable state machine, not a route polyline with voice prompts.","steps":[{"title":"Plan","description":"Resolve origin, stops, vehicle profile, constraints, and alternatives.","state":"draft"},{"title":"Preview","description":"Present ETA, distance, tolls, incidents, and route trade-offs.","state":"ready","event":"route.calculated"},{"title":"Start","description":"Acquire location, initialize guidance, and begin progress tracking.","state":"navigating","event":"navigation.started"},{"title":"Respond","description":"Refresh progress, reroute on deviation, and surface traffic events safely.","state":"navigating","event":"route.updated"},{"title":"Arrive","description":"Confirm arrival, stop sensors, persist trip summary, and release the session.","state":"completed","event":"navigation.arrived"}]}},{"slug":"intouch-telematics","name":"InTouch Telematics","eyebrow":"Understand every moving asset","category":"Operations","summary":"Live tracking, trips, devices, vehicles, events, geofences, and fleet intelligence.","description":"Connect vehicles, phones, and IoT devices to a longitudinal operational model. InTouch combines ingestion, identity, asset assignment, trip construction, event detection, live state, historical playback, and reporting. Integrations should model provisioning and lifecycle transitions explicitly.","accent":"#e052a0","stateModel":"stateful","platforms":["REST","Android","iOS","React Native","Web","Widgets"],"capabilities":["Device and vehicle provisioning","Live location and historical trails","Trips, stoppages, and events","Geofences, alerts, and notifications","Driver behavior and fleet reports","Mobile sensor-based tracking SDKs"],"repositories":["mappls-intouch-rest-apis","mappls-intouch-android-sdk","mappls-intouch-ios-sdk","mappls-react-native-intouch-sdk"],"auth":{"type":"OAuth bearer with project and asset entitlement","guidance":"Generate a time-bound InTouch bearer token from the subscribed project's client credentials. Separate provisioning identities from data-plane tracking tokens and rotate device credentials independently."},"samples":[{"language":"typescript","label":"Asset event consumer","code":"type AssetEvent = {\n  id: string;\n  assetId: string;\n  occurredAt: string;\n  type: \"position\" | \"ignition\" | \"geofence.entered\" | \"geofence.exited\";\n  position?: { latitude: number; longitude: number; speedKph?: number };\n};\n\nexport async function handleAssetEvent(event: AssetEvent) {\n  // Idempotency matters: delivery may be retried.\n  if (await events.exists(event.id)) return;\n  await events.transaction(async () => {\n    await events.record(event);\n    await assets.apply(event.assetId, event);\n  });\n}"}],"journey":{"title":"Vehicle from activation to daily operations","description":"The complete fleet journey spans control-plane and data-plane state.","steps":[{"title":"Provision","description":"Create the organization, project, asset, device, and entitlements.","state":"provisioned","event":"asset.created"},{"title":"Activate","description":"Securely bind the physical device or mobile SDK to the asset.","state":"active","event":"device.activated"},{"title":"Ingest","description":"Accept ordered and delayed telemetry while tracking connection health.","state":"online","event":"position.received"},{"title":"Operate","description":"Build trips, evaluate geofences, notify operators, and power live views.","state":"in_trip","event":"trip.started"},{"title":"Maintain","description":"Diagnose gaps, replace devices, transfer assets, and preserve history.","state":"maintenance","event":"device.replaced"},{"title":"Retire","description":"Revoke credentials and detach hardware without deleting audit history.","state":"retired","event":"asset.retired"}]}},{"slug":"workmate","name":"Workmate","eyebrow":"Orchestrate work in the field","category":"Operations","summary":"Workforce automation for people, clients, tasks, attendance, proof, and live operations.","description":"Build dispatch and field-service systems around organizations, teams, workers, clients, tasks, shifts, location evidence, forms, and approvals. Workmate is journey-oriented: assignment, acceptance, execution, proof, exception handling, and completion are all first-class states.","accent":"#3478f6","stateModel":"stateful","platforms":["REST","Android","Web"],"capabilities":["Worker and team management","Task assignment and dispatch","Attendance and shift workflows","Client visits and proof of service","Live operations and exceptions","Forms, evidence, and completion reports"],"repositories":["mapmyindia-workmate-apis","mappls-workmate-android-sdk"],"auth":{"type":"Organization and user-scoped access","guidance":"Use service identities for dispatch integrations and user identities for worker actions; preserve the actor in every transition."},"samples":[{"language":"json","label":"Task lifecycle","code":"{\n  \"externalId\": \"JOB-2026-004219\",\n  \"type\": \"equipment_inspection\",\n  \"assigneeId\": \"worker_1288\",\n  \"location\": { \"mapplsPin\": \"MMI000\" },\n  \"window\": { \"startsAt\": \"2026-08-17T04:30:00Z\", \"endsAt\": \"2026-08-17T06:30:00Z\" },\n  \"requiredProof\": [\"arrival_location\", \"checklist\", \"photo\", \"customer_signature\"]\n}"}],"journey":{"title":"A field-service job end to end","description":"Every transition is attributable, replayable, and safe to retry.","steps":[{"title":"Create","description":"Attach client, site, SLA, skills, time window, and proof requirements.","state":"unassigned","event":"task.created"},{"title":"Dispatch","description":"Choose a qualified worker using proximity, load, shift, and route cost.","state":"assigned","event":"task.assigned"},{"title":"Accept","description":"Worker accepts, rejects, or raises an availability exception.","state":"accepted","event":"task.accepted"},{"title":"Travel","description":"Navigate to the site and notify operations of predicted SLA risk.","state":"en_route","event":"task.en_route"},{"title":"Execute","description":"Verify arrival, collect structured work evidence, and handle blockers.","state":"in_progress","event":"task.started"},{"title":"Close","description":"Validate proof, obtain sign-off, sync downstream systems, and audit.","state":"completed","event":"task.completed"}]}},{"slug":"gis-analytics","name":"GIS & Analytics","eyebrow":"Make geography explain the business","category":"Intelligence","summary":"Spatial data, analysis, maps, dashboards, and embeddable location intelligence.","description":"Publish governed geospatial data, run spatial operations, build thematic views, and embed interactive dashboards. The mGIS and Insight families cover both API-first analysis and long-lived workspaces containing datasets, layers, styles, maps, permissions, and shares.","accent":"#17a8e3","stateModel":"hybrid","platforms":["REST","Web","Widgets","MCP"],"capabilities":["Dataset upload and cataloguing","Layer styling and thematic maps","Spatial queries and analysis","Dashboards and embedded insights","Workspace roles and governed sharing","Import, export, and lineage"],"repositories":["mapmyindia-mgis-apis","mapmyindia-mgis-libraries","mappls-insight-sdk","migist-complete"],"auth":{"type":"Workspace and resource-scoped access","guidance":"Keep immutable source data separate from derived layers; authorize reads and writes at workspace, dataset, and share boundaries."},"samples":[{"language":"python","label":"Point-in-polygon analysis","code":"import requests\n\nresponse = requests.post(\n    f\"{MAPPLS_GIS_BASE_URL}/analysis/point-in-polygon\",\n    headers={\"Authorization\": f\"Bearer {token}\"},\n    json={\n        \"pointsDatasetId\": \"deliveries_2026_08\",\n        \"polygonDatasetId\": \"service_zones_v4\",\n        \"include\": [\"zone_id\", \"manager\", \"sla_minutes\"],\n    },\n    timeout=30,\n)\nresponse.raise_for_status()\njob = response.json()  # Poll or subscribe to the returned analysis job.\n"}],"journey":{"title":"From raw data to governed decision layer","description":"Large analyses are asynchronous, reproducible resources with lineage.","steps":[{"title":"Ingest","description":"Upload or connect a source and validate its schema and coordinate system.","state":"validating","event":"dataset.created"},{"title":"Publish","description":"Version the dataset, define access, and expose a queryable layer.","state":"published","event":"dataset.published"},{"title":"Analyze","description":"Run a spatial job with explicit inputs, parameters, and output ownership.","state":"processing","event":"analysis.started"},{"title":"Visualize","description":"Style the derived layer and assemble a map or dashboard.","state":"ready","event":"analysis.completed"},{"title":"Share","description":"Embed or grant access with expiry, audience, and export controls.","state":"shared","event":"share.created"}]}},{"slug":"app-widgets-deep-links","name":"App Widgets & Deep Links","eyebrow":"Ship a complete experience in minutes","category":"Experience","summary":"Embeddable Mappls experiences for places, directions, 3D views, RealView, and app hand-off.","description":"Use universal URLs and embeddable widgets when you need a polished Mappls experience without owning a full map or navigation integration. Most app widgets need no API credential, making them ideal for content, support, campaigns, and lightweight product surfaces.","accent":"#ff4f64","stateModel":"stateless","platforms":["Widgets","Deep links","Web","Android","iOS"],"capabilities":["Place and map visualization","Directions and navigation hand-off","Immersive 3D and RealView experiences","Cross-platform universal links","Low-code embeds","Credential-free entry points"],"repositories":["mappls-app-widgets","mappls-web-plugins"],"auth":{"type":"Often credential-free","guidance":"Use an API key only when the selected widget explicitly requires one; validate and encode all user-provided URL parameters."},"samples":[{"language":"html","label":"Place link","code":"<a\n  href=\"https://mappls.com/MMI000\"\n  target=\"_blank\"\n  rel=\"noopener noreferrer\"\n>\n  Open this place in Mappls\n</a>"}]},{"slug":"offline-automotive","name":"Offline & Automotive","eyebrow":"Location that keeps working","category":"Embedded","summary":"Offline maps, search, routing, guidance, compilers, and embedded navigation runtimes.","description":"Power in-vehicle, industrial, and disconnected experiences with licensed regional data packages and embedded runtimes. This product family includes offline search and route compilers, native SDKs, traffic-event customization, voice guidance, GPS health, and update workflows.","accent":"#d6a600","stateModel":"stateful","platforms":["Automotive","Linux","Android"],"capabilities":["Offline maps, search, and routing","Turn-by-turn guidance runtime","Regional data compilation","Voice and traffic customization","GPS health and dead reckoning hooks","Signed data and software updates"],"repositories":["mappls-telecons-offline-sdk","mappls-telecons-compiler","mappls-telecons-search-compiler","mappls-telecons-background-compiler","mappls-routenet","linuxsdk-dev1","linuxsdk-dev2","yahaan"],"auth":{"type":"Device activation and licensed data package","guidance":"Design for activation, entitlement refresh, package compatibility, rollback, and long periods without network access."},"samples":[{"language":"cpp","label":"Lifecycle pattern","code":"// Illustrative lifecycle: concrete symbols vary by licensed SDK edition.\nNavigationRuntime runtime(configuration);\nruntime.installDataPackage(verifiedPackagePath);\nruntime.setPositionProvider(vehiclePositionProvider);\n\nauto route = runtime.plan(origin, destination, vehicleProfile);\nif (route.ok()) {\n  runtime.startGuidance(route.value());\n}\n\n// Keep sensor callbacks non-blocking; persist the resumable session safely.\nruntime.onProgress([](const GuidanceProgress& progress) {\n  tripStore.checkpoint(progress);\n});"}],"journey":{"title":"A safe offline navigation lifecycle","description":"Vehicle integrations must survive power loss, partial updates, and intermittent connectivity.","steps":[{"title":"Manufacture","description":"Bind hardware identity, software edition, and regional entitlement.","state":"manufactured","event":"device.registered"},{"title":"Activate","description":"Verify license and install a compatible signed base package.","state":"activated","event":"license.activated"},{"title":"Operate","description":"Plan and guide locally while checkpointing recoverable trip state.","state":"navigating","event":"guidance.started"},{"title":"Update","description":"Download, verify, stage, atomically switch, and retain rollback data.","state":"updating","event":"package.staged"},{"title":"Recover","description":"Restore the last compatible runtime and resume safely after interruption.","state":"recovered","event":"runtime.recovered"}]}},{"slug":"ai-location","name":"AI & Location","eyebrow":"Reason over the physical world","category":"Intelligence","summary":"AI/ML APIs, vision, location-aware agents, ranking, and natural-language spatial workflows.","description":"Combine Mappls data and platform operations with models that classify imagery, understand spatial intent, rank places, and orchestrate tools. AI integrations should ground every answer in a typed Mappls operation and expose provenance rather than allowing the model to invent locations or operational state.","accent":"#845ef7","stateModel":"hybrid","platforms":["REST","Web","MCP"],"capabilities":["Vision and imagery analysis","Location-aware retrieval and ranking","Natural-language map operations","Typed tools for AI agents","Spatial workflow orchestration","Evaluation and grounding patterns"],"repositories":["mappls-ai-apis","skydnn-aiapi-docs","genesis-toolkit","mapplsaiwebtesting"],"auth":{"type":"Underlying product credential, held by the tool server","guidance":"Never place keys or tokens in model context. Use the exact current or legacy authentication generation required by each underlying product, execute typed policy-checked tools on a trusted server, and redact precise coordinates and credential-bearing URLs from logs."},"samples":[{"language":"typescript","label":"Agent tool contract","code":"const nearbyPlacesTool = {\n  name: \"mappls_search_nearby\",\n  description: \"Find real places near a validated Mappls Pin or coordinate.\",\n  inputSchema: {\n    type: \"object\",\n    required: [\"location\", \"category\"],\n    properties: {\n      location: { type: \"string\", description: \"Mappls Pin or 'lat,lng'.\" },\n      category: { type: \"string\" },\n      radiusMeters: { type: \"integer\", minimum: 50, maximum: 10_000 }\n    }\n  }\n};"}]},{"slug":"capture-feedback","name":"Capture & Feedback","eyebrow":"Keep location truth fresh","category":"Data operations","summary":"On-demand location capture, camera evidence, map feedback, and update workflows.","description":"Capture a trustworthy position with explicit accuracy and timeout budgets, attach camera or form evidence, and submit map feedback through user-friendly SDK surfaces. This family helps delivery, insurance, survey, compliance, and citizen apps prove where an action happened and improve the map safely.","accent":"#1c9c62","stateModel":"hybrid","platforms":["Android","iOS"],"capabilities":["Single-shot and subscribed location","Accuracy and timeout policies","Camera and field evidence","Map issue reporting","Reviewable update workflows","Battery-aware capture"],"repositories":["mappls-camera-sdk-android","mappls-camera-sdk-ios","mappls-location-capture-android-sdk","mappls-location-capture-ios-sdk","mappls-feedback-kit-ios-distribution","mappls-feedback-uikit-ios-distribution"],"auth":{"type":"SDK entitlement and user consent","guidance":"Request the minimum device permission needed, retain evidence only for the declared purpose, and make capture policy visible to the user. The repository snapshot documents entitled SDK operations; direct REST access remains selection-required until an authoritative HTTP contract is supplied."},"samples":[{"language":"swift","label":"Capture policy","code":"struct CapturePolicy {\n  let desiredAccuracyMeters: Double\n  let timeoutSeconds: TimeInterval\n  let acceptsCachedLocationSeconds: TimeInterval\n}\n\nlet policy = CapturePolicy(\n  desiredAccuracyMeters: 25,\n  timeoutSeconds: 12,\n  acceptsCachedLocationSeconds: 5\n)\n\n// Pass the equivalent policy into the entitled Mappls Location Capture SDK.\n// Always handle permission denial, timeout, and insufficient-accuracy states."}]}],"platforms":[{"name":"REST","description":"Composable HTTP APIs for trusted backends, automation, data platforms, and any language.","bestFor":"Server-side workflows and cross-platform business logic","languages":["JavaScript","Python","Java","Go","C#","PHP","Ruby","cURL"]},{"name":"Web","description":"Browser-native maps, plugins, analytics, and embeddable location experiences.","bestFor":"Web apps, portals, dashboards, and public experiences","languages":["JavaScript","TypeScript","Angular"]},{"name":"Android","description":"Native maps, places, routes, navigation, telematics, capture, and UI widgets.","bestFor":"Deep Android integration and foreground/background location","languages":["Kotlin","Java"]},{"name":"iOS","description":"Native frameworks distributed through Swift Package Manager with modular UI extensions.","bestFor":"High-quality iPhone, iPad, and embedded Apple experiences","languages":["Swift","Objective-C"]},{"name":"React Native","description":"Shared JavaScript/TypeScript interfaces backed by Mappls native SDKs.","bestFor":"Cross-platform product teams needing native maps and tracking","languages":["TypeScript","JavaScript"]},{"name":"Flutter","description":"Dart wrappers for native Android and iOS mapping capabilities.","bestFor":"One UI codebase with native map rendering","languages":["Dart"]},{"name":"Cordova","description":"Legacy hybrid bridges for Cordova and Ionic applications.","bestFor":"Maintaining established hybrid applications","languages":["JavaScript","Objective-C","Java"]},{"name":"Xamarin","description":"Legacy .NET mobile samples for SDK-backed maps and REST APIs.","bestFor":"Existing Xamarin estates planning a migration","languages":["C#"]},{"name":"Linux","description":"Native mapping and routing runtimes for controlled devices and embedded systems.","bestFor":"Kiosks, industrial systems, and embedded navigation","languages":["C","C++"]},{"name":"Automotive","description":"Offline-capable navigation SDKs, data compilers, activation, and vehicle integration hooks.","bestFor":"Head units, clusters, and connected vehicle platforms","languages":["C++","Java","Kotlin"]},{"name":"Widgets","description":"Prebuilt UI for places, directions, nearby, geofences, feedback, and rich Mappls content.","bestFor":"Fast feature delivery with a supported user experience","languages":["HTML","Swift","Kotlin"]},{"name":"Deep links","description":"Universal Mappls URLs for place views, directions, navigation, and app hand-off.","bestFor":"Zero-SDK campaigns, messages, content, and fallbacks","languages":["URL","HTML"]},{"name":"MCP","description":"Typed tools and resources that let agents discover and invoke Mappls capabilities safely.","bestFor":"AI assistants, copilots, and spatial workflow agents","languages":["TypeScript","Python","JSON Schema"]}],"platformPlaybooks":[{"slug":"rest","platform":"REST","headline":"Put Mappls behind a stable service boundary in any stack.","sourcePlatforms":["REST"],"architecture":[{"title":"Trusted application backend","description":"Own credentials, validation, retries, quotas, caching, and response normalization in a service you control."},{"title":"Mappls data plane","description":"Call stateless location APIs directly and model long-running jobs or operational resources with durable identifiers."},{"title":"Your product surfaces","description":"Expose only the location capabilities and data needed by web, mobile, partner, batch, and automation clients."}],"startHere":[{"title":"Choose the narrowest API","description":"Start with an endpoint contract and confirm its current host, entitlement, region, and authentication mode."},{"title":"Create a server client","description":"Load credentials from a secret manager, set explicit timeouts, and attach a request or trace identifier."},{"title":"Normalize failure behavior","description":"Separate invalid requests from quota, authentication, transient service, and transport failures."},{"title":"Add production controls","description":"Measure latency and consumption, cache safe reads, back off retryable failures, and redact sensitive data."}],"productionChecks":["Credentials never reach a browser or mobile bundle","Timeout, retry, and idempotency policies are explicit","Coordinates, addresses, and identifiers have data-retention rules","Every operation is attributable in logs and usage reporting"],"href":"/platforms/rest"},{"slug":"web","platform":"Web","headline":"Build expressive browser maps without surrendering performance or control.","sourcePlatforms":["Web"],"architecture":[{"title":"Browser experience","description":"Render maps, layers, controls, markers, and accessible place or route interactions in the user interface."},{"title":"Restricted public key","description":"Use only browser-supported credentials and restrict them to the exact production and development origins."},{"title":"Backend-for-frontend","description":"Keep privileged REST calls, secrets, business rules, persistence, and third-party orchestration on your server."}],"startHere":[{"title":"Select a rendering surface","description":"Choose Web Maps JS for a full map, a plugin for a focused workflow, or a widget when Mappls can own the experience."},{"title":"Create a bounded map","description":"Give the container a real size, initialize once, and destroy listeners and instances during unmount."},{"title":"Add one user journey","description":"Connect search, selection, route preview, or data visualization before expanding the surface."},{"title":"Measure real devices","description":"Profile startup, tile loading, interaction latency, memory, accessibility, and slow-network behavior."}],"productionChecks":["Origin restrictions include every deployed hostname","Map lifecycle follows the framework lifecycle","Large datasets are tiled, clustered, or progressively loaded","Keyboard, touch, reduced-motion, and failure states are tested"],"href":"/platforms/web"},{"slug":"android","platform":"Android","headline":"Compose native maps, places, tracking, and navigation with Android lifecycle discipline.","sourcePlatforms":["Android"],"architecture":[{"title":"Application layer","description":"Own permissions, UI state, domain models, navigation between screens, and consent-facing experiences."},{"title":"Mappls SDK modules","description":"Install only entitled map, place, route, navigation, tracking, capture, or workforce modules."},{"title":"Secure backend","description":"Issue scoped tokens, protect privileged APIs, receive events, and persist durable operational state."}],"startHere":[{"title":"Confirm compatibility","description":"Pin the SDK release, Android Gradle Plugin, Kotlin, minSdk, targetSdk, and repository requirements together."},{"title":"Configure credentials","description":"Use manifest or runtime configuration only as documented and keep server secrets outside the APK."},{"title":"Forward lifecycle","description":"Connect the map or navigation view to activity, fragment, process, and saved-state behavior."},{"title":"Test device realities","description":"Exercise denied permissions, background limits, process death, offline periods, rotation, and low-memory recovery."}],"productionChecks":["Dependency versions are pinned and reproducible","Location permission is contextual and revocable","Background work complies with current Android policy","SDK resources and observers are released deterministically"],"href":"/platforms/android"},{"slug":"ios","platform":"iOS","headline":"Deliver Mappls-native Apple experiences through modular, lifecycle-safe frameworks.","sourcePlatforms":["iOS"],"architecture":[{"title":"Swift application","description":"Own scenes, permissions, presentation, product state, accessibility, and privacy disclosures."},{"title":"Mappls packages","description":"Resolve the smallest map, place, navigation, tracking, capture, or UI module set through the supported package channel."},{"title":"Backend trust boundary","description":"Exchange credentials, retain operational records, and perform privileged API calls away from the app binary."}],"startHere":[{"title":"Choose package lineage","description":"Match the current SDK documentation with its distribution repository and supported Xcode and deployment targets."},{"title":"Initialize once","description":"Configure the SDK at the documented application or scene boundary before creating dependent views."},{"title":"Respect ownership","description":"Keep delegates, coordinators, subscriptions, and map views alive only for the required lifecycle."},{"title":"Verify on hardware","description":"Test permissions, background transitions, interrupted navigation, memory pressure, and poor connectivity on devices."}],"productionChecks":["Package and binary versions belong to the same release line","Secrets are not recoverable from the app bundle","Info.plist purpose strings match actual collection","Delegates, observers, and background sessions terminate cleanly"],"href":"/platforms/ios"},{"slug":"react-native","platform":"React Native","headline":"Share product logic while keeping native Mappls capabilities honest on both platforms.","sourcePlatforms":["React Native"],"architecture":[{"title":"TypeScript interface","description":"Expose stable application-level components, hooks, and event types instead of leaking every native implementation detail."},{"title":"Native Mappls bridges","description":"Configure Android and iOS independently, including packages, credentials, manifests, permissions, and lifecycle callbacks."},{"title":"Backend services","description":"Retain credentials and stateful workflows centrally so app reinstalls and cross-device use remain recoverable."}],"startHere":[{"title":"Align the version matrix","description":"Confirm React Native, Android, iOS, Mappls wrapper, and underlying native SDK compatibility."},{"title":"Install both native halves","description":"Complete Gradle and Xcode configuration before treating the JavaScript API as available."},{"title":"Create a typed boundary","description":"Normalize coordinates, feature IDs, commands, callbacks, and errors at the application edge."},{"title":"Test asymmetric failures","description":"Verify upgrades, permissions, backgrounding, and process recovery independently on Android and iOS."}],"productionChecks":["Native and wrapper releases are compatible","High-frequency events are throttled before crossing the bridge","Unmount releases native views and listeners","Platform-specific behavior is documented, not hidden"],"href":"/platforms/react-native"},{"slug":"flutter","platform":"Flutter","headline":"Use one Dart experience with deliberate native Mappls configuration underneath.","sourcePlatforms":["Flutter"],"architecture":[{"title":"Dart feature layer","description":"Own widgets, application state, typed models, and platform-neutral business behavior."},{"title":"Flutter platform plugin","description":"Bridge map rendering and native capabilities to correctly configured Android and iOS SDKs."},{"title":"Trusted backend","description":"Issue scoped credentials and own privileged calls, persistence, events, and operational workflows."}],"startHere":[{"title":"Pin the plugin","description":"Match Flutter, Dart, Android, iOS, and Mappls plugin requirements before resolving dependencies."},{"title":"Configure native projects","description":"Apply repository, manifest, Info.plist, package, and credential steps on both platforms."},{"title":"Build a lifecycle-safe widget","description":"Create controllers once, await readiness, and dispose streams and native resources."},{"title":"Exercise release builds","description":"Test shrinking, signing, permissions, backgrounding, and platform-view performance outside debug mode."}],"productionChecks":["Android and iOS configuration is version-controlled","Controllers are used only after readiness","Streams and platform views are disposed","Release builds are tested on physical devices"],"href":"/platforms/flutter"},{"slug":"cordova","platform":"Cordova","headline":"Maintain hybrid location experiences with explicit native ownership and a migration path.","sourcePlatforms":["Cordova/Ionic"],"architecture":[{"title":"Web application shell","description":"Own navigation, UI, business state, and a narrow JavaScript interface to mapping capabilities."},{"title":"Cordova native plugin","description":"Bridge platform permissions, lifecycle, SDK calls, and callbacks across Android and iOS."},{"title":"Compatibility envelope","description":"Pin every toolchain and plugin dependency while planning replacement of unsupported components."}],"startHere":[{"title":"Classify the estate","description":"Record Cordova, Ionic, plugin, Android, iOS, and Mappls versions plus current release constraints."},{"title":"Reproduce the build","description":"Lock dependencies and prove a clean signed build before adding new location behavior."},{"title":"Constrain the bridge","description":"Keep commands and callbacks small, typed, serializable, and resilient to view recreation."},{"title":"Design migration seams","description":"Separate application state from plugin calls so the UI or native host can be replaced incrementally."}],"productionChecks":["Supported status is verified before new development","Toolchain and plugin versions are frozen","Bridge inputs are validated and bounded","A tested migration and rollback path exists"],"href":"/platforms/cordova"},{"slug":"xamarin","platform":"Xamarin","headline":"Stabilize existing .NET mobile integrations and move forward without losing behavior.","sourcePlatforms":["Xamarin/.NET"],"architecture":[{"title":"Shared .NET domain layer","description":"Retain portable models, workflows, persistence interfaces, and tests independent of the UI framework."},{"title":"Platform SDK adapters","description":"Isolate Android and iOS Mappls bindings, lifecycle, permissions, and rendering behind explicit interfaces."},{"title":"Migration target","description":"Move screens or features toward a supported .NET or native stack while preserving contract tests."}],"startHere":[{"title":"Inventory dependencies","description":"Capture NuGet packages, native bindings, SDK binaries, build hosts, signing, and entitlement state."},{"title":"Freeze observable behavior","description":"Add tests around coordinate conversion, search, routes, state restoration, and native callbacks."},{"title":"Extract adapters","description":"Move Mappls-specific calls behind interfaces that a replacement platform can implement."},{"title":"Migrate by journey","description":"Move complete user journeys, validate parity, then retire the corresponding legacy surface."}],"productionChecks":["The support and security posture is documented","Build inputs can be reproduced","Native resources have deterministic ownership","Migration parity is measured with journey-level tests"],"href":"/platforms/xamarin"},{"slug":"linux","platform":"Linux","headline":"Run location and navigation reliably on controlled, embedded Linux systems.","sourcePlatforms":["Linux/Embedded"],"architecture":[{"title":"Device application","description":"Own process supervision, UI or service behavior, hardware integration, storage, and observability."},{"title":"Mappls native runtime","description":"Load entitled libraries and compatible map or routing data for the target architecture."},{"title":"Provisioning and updates","description":"Activate devices, stage signed artifacts, switch versions atomically, and preserve rollback state."}],"startHere":[{"title":"Define the target","description":"Record architecture, ABI, libc, graphics stack, storage, memory, sensors, and connectivity constraints."},{"title":"Validate the bundle","description":"Match runtime, compiler, data format, license, and device activation before application integration."},{"title":"Build a supervised lifecycle","description":"Handle startup, health, corrupted data, expired activation, resource pressure, and clean shutdown."},{"title":"Prove field updates","description":"Test resumable download, signature verification, atomic switch, rollback, and power interruption."}],"productionChecks":["Runtime and data compatibility is enforced","Device identity and activation can be rotated","Updates are signed, resumable, and reversible","Health and resource telemetry survive application restarts"],"href":"/platforms/linux"},{"slug":"automotive","platform":"Automotive","headline":"Treat in-vehicle navigation as a safety-aware, upgradeable system—not a screen.","sourcePlatforms":["Automotive","Linux/Embedded"],"architecture":[{"title":"Vehicle integration layer","description":"Own GNSS and sensor fusion inputs, vehicle signals, audio, displays, policy, and driver-distraction constraints."},{"title":"Navigation runtime","description":"Plan, guide, reroute, search, match position, and operate with the installed online or offline data."},{"title":"Fleet control plane","description":"Manage activation, entitlements, staged releases, map data, telemetry, incidents, and rollback across device cohorts."}],"startHere":[{"title":"Specify the operating envelope","description":"Define platforms, displays, controls, vehicle signals, offline duration, regions, languages, and safety constraints."},{"title":"Integrate simulation first","description":"Feed deterministic routes, GNSS traces, deviations, tunnels, and failures before vehicle testing."},{"title":"Model navigation state","description":"Make route planning, preview, guidance, reroute, arrival, pause, and termination explicit and recoverable."},{"title":"Qualify the release system","description":"Validate runtime, map data, configuration, activation, cohort rollout, health signals, and rollback together."}],"productionChecks":["Driver-distraction and safety requirements are testable","Navigation recovers after power and connectivity loss","Runtime and map data roll out as a compatible unit","Simulation and road-test evidence cover full journeys"],"href":"/platforms/automotive"},{"slug":"widgets","platform":"Widgets","headline":"Embed complete Mappls experiences while keeping hand-off, privacy, and fallback deliberate.","sourcePlatforms":["Widgets/Deep links","Web"],"includeKinds":["Widget"],"architecture":[{"title":"Host product","description":"Own placement, surrounding content, consent, identity, and the moment the embedded experience begins or ends."},{"title":"Mappls widget","description":"Own the focused place, route, feedback, geofence, visualization, or immersive interaction."},{"title":"Event and fallback layer","description":"Capture supported callbacks, provide a useful no-script or blocked-embed path, and keep business state outside the widget."}],"startHere":[{"title":"Select the owned journey","description":"Choose a widget when its complete supported interaction matches the outcome you need."},{"title":"Define the container","description":"Set responsive dimensions, loading UI, accessibility context, content policy, and failure behavior."},{"title":"Pass minimal context","description":"Provide only documented identifiers, locations, configuration, and callbacks—never privileged credentials."},{"title":"Test hand-offs","description":"Verify completion, cancellation, back navigation, app opening, blocked content, and small-screen behavior."}],"productionChecks":["Embedding and content-security policies permit only required origins","No sensitive business state lives only inside the widget","Loading, failure, and unsupported-browser fallbacks exist","Analytics distinguish view, engagement, completion, and hand-off"],"href":"/platforms/widgets"},{"slug":"deep-links","platform":"Deep links","headline":"Open useful Mappls place and journey experiences from any channel—with no SDK requirement.","sourcePlatforms":["Widgets/Deep links"],"includeKinds":["Deep link"],"architecture":[{"title":"Link producer","description":"Create documented Mappls URLs from trusted place, Mappls Pin, destination, or route context."},{"title":"Universal hand-off","description":"Let the operating system open the Mappls app when available and a useful web experience otherwise."},{"title":"Campaign measurement","description":"Track link placement and downstream business outcomes without putting private data into the URL."}],"startHere":[{"title":"Choose the destination type","description":"Use a place, map, directions, navigation, or other documented link shape for one clear intent."},{"title":"Encode from structured data","description":"Build and validate URL components with a URL library instead of concatenating user input."},{"title":"Provide visible context","description":"Tell users what opens, show the destination in human-readable form, and preserve a copyable fallback."},{"title":"Test every channel","description":"Verify installed and uninstalled states across mobile browsers, messaging, email, QR, desktop, and in-app webviews."}],"productionChecks":["User or confidential data never appears in query parameters","All variable values are encoded and length-bounded","App and browser fallbacks reach the same intent","Redirect and campaign domains are allow-listed and monitored"],"href":"/platforms/deep-links"},{"slug":"mcp","platform":"MCP","headline":"Give AI systems typed Mappls capabilities with policy, evidence, and human control.","sourcePlatforms":["AI/MCP"],"architecture":[{"title":"AI host","description":"Plan user intent, request tool calls, present approvals, and keep generated text separate from authoritative results."},{"title":"Mappls MCP boundary","description":"Advertise narrow schemas, validate arguments, enforce policy, call supported Mappls services, and return provenance."},{"title":"Credential and audit plane","description":"Scope credentials by tenant and tool, redact logs, meter usage, trace calls, and support revocation."}],"startHere":[{"title":"Start read-only","description":"Expose discovery, search, route, and documentation tools before any command that changes durable state."},{"title":"Constrain every schema","description":"Use enums, bounds, required fields, coordinate validation, result limits, and explicit units."},{"title":"Separate plan from effect","description":"Preview stateful commands, require approval, attach idempotency, and return the created resource identifier."},{"title":"Evaluate adversarially","description":"Test prompt injection, secret requests, confused-deputy access, fabricated APIs, retries, and partial failure."}],"productionChecks":["Tools expose the least authority needed","State-changing calls require explicit policy and approval","Responses identify source, freshness, and uncertainty","Every tool call is tenant-scoped, metered, redacted, and traceable"],"href":"/platforms/mcp"}],"quickstarts":{"count":13,"href":"/api/quickstarts"},"starterKits":{"count":13,"href":"/api/starter-kits","index":"/starter-kits"},"sourceLaunchpads":{"summary":{"launchpads":60,"starterPacks":60,"withSourceExamples":38,"codeLabs":60,"workshops":60,"adapterSamples":120,"selectionRequired":3,"stateModels":{"stateless":40,"hybrid":13,"stateful":7},"providerCalls":0,"credentialValuesIncluded":false},"href":"/api/launchpads","index":"/launchpads","providerCredentialsAccepted":false,"providerNetworkCalls":false},"contractGenerationMigrationKits":{"summary":{"schemaVersion":"mappls.contract-generation-migration-kits.v1","kits":17,"adapterLanguages":8,"runnableFixtureTests":51,"providerCalls":0,"credentialsAccepted":false},"href":"/api/contract-generations","index":"/api-generations","downloadTemplate":"/downloads/api-generations/{generationGroupSlug}-migration-kit.zip","providerCredentialsAccepted":false,"providerNetworkCalls":false},"developerCli":{"href":"/cli","download":"/downloads/mappls-developer-cli.zip","checksum":"/downloads/mappls-developer-cli.zip.sha256","commands":9,"providerCredentialsAccepted":false,"providerNetworkCalls":false},"migrations":{"count":13,"href":"/api/migrations"},"journeyBlueprints":[{"slug":"field-service-task","title":"Field-service task lifecycle","eyebrow":"Workmate · command-driven aggregate","productSlug":"workmate","stateModel":"stateful","summary":"Create, assign, accept, travel, prove, approve, and close a field job without losing actor, retry, or evidence history.","aggregate":"task","actors":["Dispatcher","Field worker","Supervisor","Integration service"],"sourceGuideSlugs":["mapmyindia-workmate-apis","mappls-workmate-android-sdk"],"contractSlugs":["workmate-post-tasks-to-create-new-task","workmate-get-tasks-taskid-to-get-the-task-details-for-the-given-task-id","workmate-put-tasks-taskid-to-update-the-task-description-status","workmate-get-users-to-get-all-the-user-details-which-belongs-to-your-organization","workmate-get-clients-to-get-all-your-client-details"],"sampleSlug":"field-service","states":[{"id":"unassigned","label":"Unassigned","meaning":"The job exists with client, site, SLA, skills, window, and proof policy but no worker owns it.","recovery":"Re-run assignment using the same external job identifier; never create a second job to recover a timeout."},{"id":"assigned","label":"Assigned","meaning":"A specific eligible worker owns the next decision and dispatch has recorded why they were selected.","recovery":"Expire or explicitly reassign after checking worker availability and the last committed task version."},{"id":"accepted","label":"Accepted","meaning":"The worker has acknowledged responsibility and the customer-facing plan can become firm.","recovery":"If the device is offline, accept locally with a client command ID and reconcile once connectivity returns."},{"id":"en_route","label":"En route","meaning":"Travel has begun and ETA, route deviation, and SLA-risk observations may change continuously.","recovery":"Resume from the last task version and latest trusted position; recalculate route rather than replaying old guidance."},{"id":"in_progress","label":"In progress","meaning":"Arrival is established and work evidence can be gathered under the declared proof policy.","recovery":"Keep an offline evidence queue with hashes and local IDs; upload without losing capture time or actor."},{"id":"proof_pending","label":"Proof pending","meaning":"The worker submitted an immutable evidence set awaiting automated or supervisor validation.","recovery":"A rejected set returns to in-progress through an explicit event; retain the rejected evidence for audit."},{"id":"completed","label":"Completed","meaning":"Required proof is accepted and downstream billing, inventory, SLA, and customer workflows may run.","recovery":"Treat completion as terminal; corrections are compensating records, not destructive edits to history.","terminal":true},{"id":"cancelled","label":"Cancelled","meaning":"A named actor stopped the job with a reason before completion.","recovery":"Create a replacement job only when business intent genuinely changes and link it to the cancelled task.","terminal":true}],"transitions":[{"command":"create_task","actor":"Integration service","from":[],"to":"unassigned","event":"task.created","idempotency":"Use the upstream job ID as a stable creation key."},{"command":"assign","actor":"Dispatcher","from":["unassigned","assigned"],"to":"assigned","event":"task.assigned","idempotency":"Deduplicate by dispatcher command ID and compare expected task version."},{"command":"accept","actor":"Field worker","from":["assigned"],"to":"accepted","event":"task.accepted","idempotency":"Generate the key on-device before network transmission and persist it through retry."},{"command":"start_travel","actor":"Field worker","from":["accepted"],"to":"en_route","event":"task.en_route","idempotency":"A repeated start must return the same state and must not create a second trip."},{"command":"arrive","actor":"Field worker","from":["en_route"],"to":"in_progress","event":"task.started","idempotency":"Bind arrival evidence and command ID to the same transition transaction."},{"command":"submit_proof","actor":"Field worker","from":["in_progress"],"to":"proof_pending","event":"task.proof_submitted","idempotency":"Hash the evidence manifest and reject a reused key with different content."},{"command":"approve_proof","actor":"Supervisor","from":["proof_pending"],"to":"completed","event":"task.completed","idempotency":"Commit approval and downstream outbox entries atomically."},{"command":"reject_proof","actor":"Supervisor","from":["proof_pending"],"to":"in_progress","event":"task.proof_rejected","idempotency":"Preserve decision reason and the rejected evidence version."}],"invariants":["One upstream external job maps to one durable task aggregate.","Only the assigned worker can accept, travel, arrive, or submit proof unless an attributable override is recorded.","Every command carries tenant, actor, idempotency key, expected version, and occurrence time.","Completion is impossible until the declared proof policy passes.","Task history is append-only; corrections use new events or compensating work."],"records":[{"name":"Task snapshot","purpose":"Fast current-state reads and optimistic concurrency.","keyFields":["taskId","externalId","state","version","assigneeId","mapplsPin"]},{"name":"Audit event","purpose":"Attributable, replayable history for support and compliance.","keyFields":["eventId","aggregateVersion","actor","commandId","occurredAt"]},{"name":"Evidence manifest","purpose":"Immutable references and hashes for checklist, media, signature, and consent.","keyFields":["manifestId","taskVersion","captureTime","contentHash","retentionClass"]},{"name":"Transactional outbox","purpose":"Reliable downstream billing, inventory, notification, and analytics delivery.","keyFields":["outboxId","eventId","status","attempts","nextAttemptAt"]}],"failures":[{"trigger":"Create-task response times out","detection":"No provider response but the upstream external ID and idempotency key are known.","recovery":"Query by known identity or repeat the same command; do not mint a new job ID."},{"trigger":"Two dispatchers edit the same task","detection":"The submitted expected version is older than the current aggregate version.","recovery":"Return conflict with current state; refresh context and require an intentional new command."},{"trigger":"Worker is offline during proof capture","detection":"Evidence exists locally but no server acknowledgement or event ID exists.","recovery":"Retain command ID, hashes, capture timestamps, and retry queue until the committed event is returned."},{"trigger":"Downstream system is unavailable after completion","detection":"Task is complete but its outbox entry remains pending or retrying.","recovery":"Retry outbox delivery independently; never reopen or re-complete the task to trigger side effects."}],"observability":["Command acceptance, rejection code, actor, task version, and latency","Time spent in each state and SLA-risk interval","Duplicate command rate and version-conflict rate","Offline queue age and proof upload completeness","Outbox backlog, attempt count, and dead-letter age","Precise-location access with purpose and retention class"],"href":"/journeys/field-service-task"},{"slug":"connected-fleet-trip","title":"Connected fleet trip","eyebrow":"InTouch · telemetry-backed operations","productSlug":"intouch-telematics","stateModel":"stateful","summary":"Provision an observable trip, follow live vehicle state, explain exceptions, close deliberately, and retain a replayable operational record.","aggregate":"trip","actors":["Fleet planner","Driver","Operations controller","Telematics service"],"sourceGuideSlugs":["mappls-intouch-rest-apis","mappls-intouch-android-sdk","mappls-intouch-ios-sdk","mappls-intouch-ios-distribution","mappls-intouch-ios-distribution-base","mapmyindia-intouch-ios-sdk","mappls-react-native-intouch-sdk"],"contractSlugs":["intouch-post-trips-this-api-will-create-a-trip","intouch-get-trips-this-api-will-get-all-the-trips-for-a-user","intouch-get-trips-id-gets-the-details-of-a-single-trip","intouch-post-trips-id-close-post-api-to-close-a-trip","intouch-get-devices-gets-the-live-data-of-devices","intouch-get-devices-deviceid-events-gets-the-historical-location-events-of-a-device"],"sampleSlug":"delivery-control-tower","states":[{"id":"planned","label":"Planned","meaning":"Stops, service window, asset, driver, and business identifiers are fixed enough to create the trip.","recovery":"Reconcile by external trip ID after a timeout and update the plan only through versioned commands."},{"id":"ready","label":"Ready","meaning":"The trip and assigned device are provisioned, entitled, and emitting sufficiently fresh location.","recovery":"Block departure or enter a documented degraded mode when device health cannot be established."},{"id":"active","label":"Active","meaning":"Positions, events, progress, ETA, and exception state are continuously observed.","recovery":"Accept delayed telemetry by event time, preserve received time, and rebuild derived state deterministically."},{"id":"exception","label":"Exception","meaning":"A deviation, delay, device gap, geofence, or safety event requires operator attention.","recovery":"Record acknowledgement and resolution as separate attributable actions without deleting the underlying event."},{"id":"closing","label":"Closing","meaning":"Arrival is plausible but late events, final proof, and device state are still being reconciled.","recovery":"Use a bounded grace window and surface unresolved gaps instead of fabricating completion evidence."},{"id":"closed","label":"Closed","meaning":"The provider trip and internal aggregate are closed with a final trace, metrics, and exception record.","recovery":"Apply late telemetry to a derived revision while keeping the original close event immutable.","terminal":true}],"transitions":[{"command":"create_trip","actor":"Fleet planner","from":[],"to":"planned","event":"trip.created","idempotency":"Use the dispatch or order journey ID across retries."},{"command":"confirm_device_ready","actor":"Telematics service","from":["planned"],"to":"ready","event":"trip.ready","idempotency":"Bind the decision to device identity and observed health version."},{"command":"start_trip","actor":"Driver","from":["ready"],"to":"active","event":"trip.started","idempotency":"Persist the driver command ID before the first transmission."},{"command":"raise_exception","actor":"Telematics service","from":["active","exception"],"to":"exception","event":"trip.exception_raised","idempotency":"Derive a stable key from rule, asset, and source-event identity."},{"command":"resolve_exception","actor":"Operations controller","from":["exception"],"to":"active","event":"trip.exception_resolved","idempotency":"Record acknowledgement and resolution command IDs separately."},{"command":"request_close","actor":"Driver","from":["active","exception"],"to":"closing","event":"trip.close_requested","idempotency":"The same close request may be safely replayed while finalization runs."},{"command":"close_trip","actor":"Telematics service","from":["closing"],"to":"closed","event":"trip.closed","idempotency":"Provider close and internal completion must reconcile to one terminal version."}],"invariants":["A device is assigned to at most one active trip in the same operational context.","Raw telemetry is immutable and distinguished by event time and receipt time.","Derived live state can be rebuilt from ordered observations and commands.","Trip closure never discards unresolved exceptions or data gaps.","Every provider identifier is mapped to the internal trip and tenant."],"records":[{"name":"Trip aggregate","purpose":"Current operational state and identity mapping.","keyFields":["tripId","externalId","providerTripId","deviceId","state","version"]},{"name":"Telemetry envelope","purpose":"Immutable position and vehicle observation.","keyFields":["sourceEventId","deviceId","eventTime","receivedTime","position","quality"]},{"name":"Exception case","purpose":"Operator-owned acknowledgement and resolution workflow.","keyFields":["caseId","rule","severity","owner","status","sourceEventIds"]},{"name":"Trip revision","purpose":"Recomputed summary when bounded late data arrives.","keyFields":["tripId","revision","inputWatermark","metrics","generatedAt"]}],"failures":[{"trigger":"Telemetry arrives late or out of order","detection":"Event time is behind the trip watermark or its sequence creates a gap.","recovery":"Store raw input, recompute the bounded affected window, and publish a new derived revision."},{"trigger":"Device stops reporting","detection":"Freshness exceeds the vehicle-specific health threshold.","recovery":"Raise a connection exception, show last-known time explicitly, and avoid extrapolating authoritative position."},{"trigger":"Close succeeds remotely but the response is lost","detection":"Internal trip remains closing while provider detail reports closed.","recovery":"Reconciliation closes the internal aggregate with the original command identity."},{"trigger":"Driver or vehicle assignment changes mid-trip","detection":"A control-plane version differs from the assignment captured at trip start.","recovery":"Use an explicit transfer transition and retain both assignment intervals."}],"observability":["Telemetry freshness, ordering lag, rejection, and quality","Active trips without a healthy assigned device","ETA error and route-deviation duration","Open exception age by severity and owner","Trips stuck in closing and reconciliation outcomes","Raw-to-derived lineage and revision count"],"href":"/journeys/connected-fleet-trip"},{"slug":"fleet-geofence-exception","title":"Fleet geofence exception","eyebrow":"InTouch · rule and case lifecycle","productSlug":"intouch-telematics","stateModel":"stateful","summary":"Create a governed zone, evaluate vehicle activity, suppress noise, raise an actionable case, and retire the rule safely.","aggregate":"geofence case","actors":["Fleet administrator","Telematics service","Operations controller","Compliance reviewer"],"sourceGuideSlugs":["mappls-intouch-rest-apis","mapmyindia-intouch-web-plugins"],"contractSlugs":["intouch-post-geofences-create-a-new-geofence","intouch-get-geofences-id-get-a-single-or-multiple-geofence-s","intouch-get-geofences-activities-get-all-the-activities-done-by-devices-w-r-t-various-geofences","intouch-post-geofences-id-update-a-geofence","intouch-delete-geofences-id-delete-a-geofence"],"sampleSlug":"fleet-geofence","states":[{"id":"draft","label":"Draft","meaning":"Geometry, rule semantics, asset scope, schedule, and notification policy are being validated.","recovery":"Keep draft versions separate from the active provider rule."},{"id":"active","label":"Active","meaning":"The versioned zone is deployed and evaluated against an explicit asset and schedule scope.","recovery":"Reconcile provider rule identity and version before treating observations as authoritative."},{"id":"breached","label":"Breached","meaning":"A debounced enter, exit, dwell, or prohibited-presence event created an operational case.","recovery":"Deduplicate by source activity ID and retain all supporting positions."},{"id":"acknowledged","label":"Acknowledged","meaning":"A named operator owns investigation, severity, and response deadline.","recovery":"Reassign through an attributable command if the owner becomes unavailable."},{"id":"resolved","label":"Resolved","meaning":"The outcome and evidence are recorded without erasing the initiating activity.","recovery":"Reopen as a new case version if new facts change the operational decision.","terminal":true},{"id":"retired","label":"Retired","meaning":"The zone no longer generates new cases but historical activities remain queryable.","recovery":"Create a new rule version rather than silently reactivating a retired definition.","terminal":true}],"transitions":[{"command":"publish_geofence","actor":"Fleet administrator","from":["draft"],"to":"active","event":"geofence.published","idempotency":"Key by internal rule ID and definition version."},{"command":"record_breach","actor":"Telematics service","from":["active","breached"],"to":"breached","event":"geofence.breached","idempotency":"Use provider activity identity plus rule version."},{"command":"acknowledge_case","actor":"Operations controller","from":["breached"],"to":"acknowledged","event":"geofence_case.acknowledged","idempotency":"Deduplicate the operator action, not the underlying telemetry."},{"command":"resolve_case","actor":"Operations controller","from":["acknowledged"],"to":"resolved","event":"geofence_case.resolved","idempotency":"Commit outcome, evidence references, and notification outbox atomically."},{"command":"retire_geofence","actor":"Fleet administrator","from":["draft","active"],"to":"retired","event":"geofence.retired","idempotency":"Reconcile provider deletion and internal retirement with one command key."}],"invariants":["Geometry and coordinate reference are validated before publication.","Every activity names the geofence definition version that evaluated it.","Noise suppression never deletes raw source observations.","One provider activity creates at most one operational case per rule version.","Retirement stops new evaluation while preserving case and audit history."],"records":[{"name":"Geofence definition","purpose":"Versioned geometry, schedule, assets, and rule policy.","keyFields":["ruleId","version","providerId","geometryHash","assetScope","status"]},{"name":"Source activity","purpose":"Immutable enter, exit, dwell, or presence evidence.","keyFields":["activityId","ruleVersion","deviceId","eventTime","position"]},{"name":"Exception case","purpose":"Human ownership, SLA, disposition, and notification state.","keyFields":["caseId","activityIds","severity","owner","status","resolution"]}],"failures":[{"trigger":"GPS jitter creates repeated boundary crossings","detection":"Alternating activities occur inside the configured hysteresis time and distance.","recovery":"Debounce into one case while retaining raw activities for review."},{"trigger":"Rule update races with incoming activity","detection":"The activity cites an earlier provider or internal definition version.","recovery":"Evaluate and display it under the cited version; never reinterpret history silently."},{"trigger":"Provider deletion times out","detection":"Internal retirement is pending and provider reconciliation is unknown.","recovery":"Retry the same delete identity and keep the rule visibly retiring until confirmed."},{"trigger":"Notification delivery fails","detection":"The case exists but the notification outbox remains pending.","recovery":"Retry independently and escalate by age; do not create another case."}],"observability":["Activities per device and rule before and after debouncing","Case acknowledgement and resolution time","Rules with provider/internal version drift","Notifications pending, retrying, and dead-lettered","Geometry validation and publication failures","Retired rules still receiving activity"],"href":"/journeys/fleet-geofence-exception"},{"slug":"emergency-incident-response","title":"Coordinated incident response","eyebrow":"Search + Routes + InTouch · command and evidence lifecycle","productSlug":"routes-navigation","stateModel":"stateful","summary":"Resolve an incident location, select a capable available responder, route and observe the unit, adapt to hazards, establish arrival, resolve with evidence, and review every decision.","aggregate":"incident","actors":["Call taker","Dispatcher","Responder","Incident commander","Telematics service"],"sourceGuideSlugs":["mappls-rest-apis","mappls-intouch-rest-apis","mapmyindia-intouch-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-rest-key-rev-geocode-reverse-geocode-api","core-location-get-rest-key-resources-profile-geopositions-distance-matrix-api","core-location-get-rest-key-resources-profile-geopositions-routing-api","intouch-get-devices-gets-the-live-data-of-devices","intouch-get-devices-deviceid-events-gets-the-historical-location-events-of-a-device"],"sampleSlug":"incident-dispatch","states":[{"id":"reported","label":"Reported","meaning":"A stable CAD or operations identifier, incident type, severity, caller reference, required capability, and location intent are recorded.","recovery":"Reconcile creation by external incident ID; never mint a second incident because a response timed out."},{"id":"located","label":"Located","meaning":"A provider-backed Mappls identity, coordinate, formatted address, confidence, and resolution method are committed.","recovery":"Require operator confirmation for weak or ambiguous candidates while retaining the original report."},{"id":"dispatched","label":"Dispatched","meaning":"A capable available unit is selected with matrix ETA, route identity, constraints, and attributable rationale.","recovery":"Reconcile unit availability and the incident version before any reassignment."},{"id":"en_route","label":"En route","meaning":"The assigned unit accepted and current event-time telemetry drives route progress and ETA.","recovery":"Retain late observations as evidence without allowing them to replace current progress."},{"id":"on_scene","label":"On scene","meaning":"Distance, speed, and dwell policy establish arrival; scene hazards and coordination remain active.","recovery":"If evidence is weak, keep the unit en route and request a deliberate operator override rather than inferring arrival."},{"id":"resolved","label":"Resolved","meaning":"Outcome, responsible responder, and external evidence references are committed.","recovery":"Corrections append evidence or create a linked follow-up incident; they do not erase the resolution event."},{"id":"reviewed","label":"Reviewed","meaning":"A commander signs off the replay, disposition, response timings, telemetry count, hazards, and evidence completeness.","recovery":"Keep review immutable and issue a supplemental review when later evidence changes conclusions.","terminal":true}],"transitions":[{"command":"report_incident","actor":"Call taker","from":[],"to":"reported","event":"incident.reported","idempotency":"Use the external CAD or operations identity across retries."},{"command":"resolve_location","actor":"Dispatcher","from":["reported"],"to":"located","event":"incident.located","idempotency":"Bind the accepted candidate, method, confidence, and operator decision to one command."},{"command":"dispatch","actor":"Dispatcher","from":["located"],"to":"dispatched","event":"incident.dispatched","idempotency":"Compare incident version and reserve the selected unit under the same command identity."},{"command":"accept_dispatch","actor":"Responder","from":["dispatched"],"to":"en_route","event":"dispatch.accepted","idempotency":"The assigned unit generates and persists a command ID before transmission."},{"command":"record_position","actor":"Telematics service","from":["en_route"],"to":"en_route","event":"unit.position_recorded","idempotency":"Use provider event identity and preserve event and receipt time."},{"command":"confirm_arrival","actor":"Responder","from":["en_route"],"to":"on_scene","event":"incident.arrived","idempotency":"Bind distance, speed, dwell, policy version, and incident version."},{"command":"resolve","actor":"Responder","from":["on_scene"],"to":"resolved","event":"incident.resolved","idempotency":"Commit outcome, responder, evidence manifest, and outbox atomically."},{"command":"review","actor":"Incident commander","from":["resolved"],"to":"reviewed","event":"incident.reviewed","idempotency":"Review identity and incident terminal version form the stable key."}],"invariants":["One external report maps to one incident aggregate.","Only available units with the required capability are eligible for ranking.","A unit is assigned to at most one active incident in the same operational context.","Only the assigned unit can accept dispatch and publish operational telemetry.","Raw telemetry preserves event and receipt time; late evidence never regresses latest state.","Arrival requires explicit distance, speed, and dwell evidence.","Resolution cannot occur without external evidence references."],"records":[{"name":"Incident aggregate","purpose":"Business identity, lifecycle, location, assignment, hazards, outcome, and review.","keyFields":["incidentId","externalIncidentId","state","version","severity","requiredCapability"]},{"name":"Location decision","purpose":"Provider-backed location and human confirmation evidence.","keyFields":["mapplsPin","coordinate","formattedAddress","method","confidence"]},{"name":"Assignment decision","purpose":"Capability, availability, matrix, route, constraints, and selection rationale.","keyFields":["unitId","routeId","capabilities","eta","selectedBy","reason"]},{"name":"Telemetry envelope","purpose":"Immutable responder position and vehicle evidence.","keyFields":["providerEventId","unitId","eventTime","receivedTime","position","quality"]},{"name":"Review record","purpose":"Attributable disposition and metrics derived from committed events.","keyFields":["reviewer","disposition","timings","positionCount","hazardCount"]}],"failures":[{"trigger":"Caller location is ambiguous","detection":"Search candidates are low-confidence, far apart, or conflict with caller/device context.","recovery":"Keep the report unresolved, ask a targeted confirmation question, and record the chosen candidate and reason."},{"trigger":"Two dispatchers select the same unit","detection":"Unit reservation or incident expected version conflicts.","recovery":"Return the current assignments and require an intentional new selection from refreshed availability."},{"trigger":"Telemetry is late or out of order","detection":"Event time is behind the incident position watermark.","recovery":"Store it, emit a late-evidence event, and do not replace latest route progress."},{"trigger":"Route becomes unsafe after dispatch","detection":"A new hazard, closure, or restriction intersects the current route or approach policy.","recovery":"Record the hazard, calculate a versioned replacement route, and keep the last safe guidance until accepted."},{"trigger":"Resolution side effects fail","detection":"Incident is resolved while notification or downstream outbox entries remain pending.","recovery":"Retry the outbox independently; never re-resolve the incident to trigger delivery."}],"observability":["Report-to-location and call-to-dispatch time","Eligible responder count and rejected capability reasons","Matrix ranking, selected unit, override, and route latency","Telemetry freshness, ordering lag, and route revision","Hazard age and approach-policy changes","Arrival evidence pass/fail and override rate","Scene-to-resolution time and evidence completeness","Outbox backlog and review completion"],"href":"/journeys/emergency-incident-response"},{"slug":"navigation-session","title":"Recoverable navigation session","eyebrow":"Navigation · device session lifecycle","productSlug":"routes-navigation","stateModel":"hybrid","summary":"Move from route intent through preview, guidance, reroute, arrival, and cleanup while surviving process, sensor, and network interruption.","aggregate":"navigation session","actors":["Driver","Navigation application","Mappls navigation SDK","Operations backend"],"sourceGuideSlugs":["mappls-android-sdk","mappls-ios-sdk","mappls-react-native-sdk","mapmyindia-maps-vectorsdk-android","mapmyindia-maps-vectorsdk-ios"],"contractSlugs":[],"sampleSlug":"trip-planner","states":[{"id":"draft","label":"Draft","meaning":"Origin, destination, stops, vehicle profile, and constraints are incomplete or editable.","recovery":"Persist intent separately from SDK runtime state."},{"id":"preview","label":"Preview","meaning":"Alternatives and trade-offs are visible but guidance and sensor use have not started.","recovery":"Refresh stale route and traffic inputs before starting."},{"id":"navigating","label":"Navigating","meaning":"Guidance owns an active route and consumes position, progress, traffic, and user commands.","recovery":"Checkpoint minimal resumable intent and progress; reinitialize SDK resources after process death."},{"id":"rerouting","label":"Rerouting","meaning":"The active route is temporarily superseded by a recalculation caused by deviation, traffic, or destination change.","recovery":"Continue safe guidance on the last valid route until the replacement is accepted."},{"id":"arrived","label":"Arrived","meaning":"Arrival policy passed and the application is waiting for confirmation or final trip actions.","recovery":"Require an explicit end or continue decision when multiple stops remain."},{"id":"ended","label":"Ended","meaning":"Sensors, audio, observers, foreground services, and SDK session resources are released.","recovery":"Cleanup is idempotent and safe after partial initialization.","terminal":true}],"transitions":[{"command":"calculate_route","actor":"Navigation application","from":["draft","preview"],"to":"preview","event":"route.calculated","idempotency":"Hash normalized intent and constraints for request deduplication and caching."},{"command":"start_guidance","actor":"Driver","from":["preview"],"to":"navigating","event":"navigation.started","idempotency":"Persist a session command ID before starting foreground resources."},{"command":"request_reroute","actor":"Navigation application","from":["navigating","rerouting"],"to":"rerouting","event":"reroute.requested","idempotency":"Coalesce equivalent deviations while one calculation is outstanding."},{"command":"accept_reroute","actor":"Mappls navigation SDK","from":["rerouting"],"to":"navigating","event":"route.updated","idempotency":"Apply only a response matching the latest route-intent version."},{"command":"confirm_arrival","actor":"Navigation application","from":["navigating"],"to":"arrived","event":"navigation.arrived","idempotency":"Arrival policy version and stop ID form the stable key."},{"command":"end_session","actor":"Driver","from":["preview","navigating","rerouting","arrived"],"to":"ended","event":"navigation.ended","idempotency":"Cleanup must tolerate repeated calls and partial startup."}],"invariants":["Only one guidance session owns foreground navigation resources at a time.","Every route result is applied only to the intent version that requested it.","The last valid route remains available while a reroute is pending.","Arrival requires an explicit distance, speed, dwell, and stop policy.","End releases every observer, sensor, audio, and service resource exactly once in effect."],"records":[{"name":"Route intent","purpose":"Portable origin, stops, profile, constraints, and version.","keyFields":["intentId","version","waypoints","profile","constraints"]},{"name":"Session checkpoint","purpose":"Minimal recoverable progress without persisting unsafe SDK internals.","keyFields":["sessionId","intentVersion","routeId","legIndex","lastPositionTime"]},{"name":"Navigation trace","purpose":"Privacy-bounded operational and quality evidence.","keyFields":["sessionId","eventType","occurredAt","routeVersion","quality"]}],"failures":[{"trigger":"Application process is killed","detection":"A persisted active checkpoint exists without a live runtime owner.","recovery":"Recreate resources, validate destination intent, recalculate if stale, and ask before resuming guidance."},{"trigger":"GNSS quality degrades","detection":"Accuracy, age, speed consistency, or map-matching confidence crosses policy.","recovery":"Surface degraded positioning, use supported dead-reckoning inputs, and avoid false reroutes."},{"trigger":"Reroute response arrives after destination changed","detection":"Response intent version is older than the active intent.","recovery":"Discard it and keep the latest calculation; never apply by arrival order alone."},{"trigger":"Network disappears","detection":"Online route, traffic, or search dependency fails while local guidance remains active.","recovery":"Keep last valid guidance, expose freshness, and use entitled offline capability when available."}],"observability":["Route calculation latency and alternative selection","Position age, accuracy, and map-matching confidence","Reroute cause, time, cancellation, and supersession","Guidance session starts without matching cleanup","Arrival false-positive and manual-override rate","Crash/restart recovery outcome"],"href":"/journeys/navigation-session"},{"slug":"governed-spatial-analysis","title":"Governed spatial analysis","eyebrow":"mGIS & Insight · asynchronous resource graph","productSlug":"gis-analytics","stateModel":"hybrid","summary":"Ingest versioned data, validate and publish it, execute reproducible analysis, review lineage, and share a governed decision layer.","aggregate":"analysis run","actors":["Data engineer","Spatial analyst","Workspace administrator","Decision consumer"],"sourceGuideSlugs":["mapmyindia-mgis-apis","mapmyindia-mgis-libraries","mappls-insight-sdk"],"contractSlugs":[],"sampleSlug":"retail-site-lab","states":[{"id":"draft","label":"Draft","meaning":"Inputs, schema, coordinate system, ownership, and processing intent are declared but not accepted.","recovery":"Keep uploads resumable and preserve the client dataset identity."},{"id":"validating","label":"Validating","meaning":"Format, schema, geometry, coordinate reference, limits, and policy are being checked.","recovery":"Return row- or feature-level diagnostics without discarding the original version."},{"id":"published","label":"Published","meaning":"An immutable dataset version is queryable with explicit workspace access and lineage.","recovery":"Create a corrected version rather than overwriting the published input."},{"id":"processing","label":"Processing","meaning":"An analysis job references fixed input versions, parameters, runtime, and output ownership.","recovery":"Retry from a durable job identity and checkpoint; never launch duplicate untracked computation."},{"id":"ready","label":"Ready","meaning":"Outputs, quality metrics, logs, lineage, and visualization metadata are complete.","recovery":"A failed visualization does not invalidate the output dataset; rebuild presentation independently."},{"id":"shared","label":"Shared","meaning":"A governed audience can view or embed a selected output version under explicit policy.","recovery":"Revoke the share without deleting the analysis or its audit history."},{"id":"failed","label":"Failed","meaning":"Validation or processing stopped with typed, attributable diagnostics and retained inputs.","recovery":"Fix intent or input and create a linked retry attempt.","terminal":true}],"transitions":[{"command":"create_dataset_version","actor":"Data engineer","from":[],"to":"draft","event":"dataset.version_created","idempotency":"Key by workspace, logical dataset, source hash, and intended version."},{"command":"validate","actor":"Spatial analyst","from":["draft"],"to":"validating","event":"dataset.validation_started","idempotency":"Reuse the same validation attempt for identical content and policy."},{"command":"publish","actor":"Workspace administrator","from":["validating"],"to":"published","event":"dataset.published","idempotency":"Commit immutable version and permissions atomically."},{"command":"run_analysis","actor":"Spatial analyst","from":["published","ready"],"to":"processing","event":"analysis.started","idempotency":"Hash input versions, parameters, runtime, and output owner."},{"command":"complete_analysis","actor":"Spatial processing service","from":["processing"],"to":"ready","event":"analysis.completed","idempotency":"One attempt identity can publish one immutable output manifest."},{"command":"create_share","actor":"Workspace administrator","from":["ready"],"to":"shared","event":"share.created","idempotency":"Key by output version, audience, policy, and expiry."}],"invariants":["Published input and output versions are immutable.","Every output records exact input versions, parameters, runtime, and actor.","Workspace authorization applies separately to source, job, output, visualization, and share.","A retry is linked to its previous attempt and never overwrites it.","Revoking a share does not destroy dataset or analysis lineage."],"records":[{"name":"Dataset version","purpose":"Immutable source or derived spatial asset.","keyFields":["datasetId","version","contentHash","crs","schema","owner"]},{"name":"Analysis attempt","purpose":"Reproducible execution and typed status.","keyFields":["analysisId","attempt","inputs","parameters","runtime","status"]},{"name":"Lineage manifest","purpose":"Auditable graph from source versions to outputs and shares.","keyFields":["outputVersion","inputVersions","operation","generatedAt","quality"]},{"name":"Share policy","purpose":"Audience, expiry, export, embedding, and revocation controls.","keyFields":["shareId","resourceVersion","audience","permissions","expiresAt"]}],"failures":[{"trigger":"Upload is interrupted","detection":"The client upload ID has incomplete acknowledged parts.","recovery":"Resume only missing parts and verify the final content hash before validation."},{"trigger":"Coordinate reference is missing or wrong","detection":"Extent, geometry validity, or known control points conflict with the declaration.","recovery":"Fail validation with actionable diagnostics; require an explicit corrected version."},{"trigger":"Analysis worker dies","detection":"Lease expires without a terminal attempt record.","recovery":"Resume from supported checkpoint or create a linked retry under the same analysis identity."},{"trigger":"Share is used after policy changes","detection":"Resource policy version or expiry no longer authorizes the audience.","recovery":"Deny access immediately, record the decision, and require a newly authorized share."}],"observability":["Upload completeness, validation failures, and feature-level error rate","Queue, execution, and total analysis time","Input/output size and spatial operation cost","Retry, cancellation, and orphaned-job rate","Lineage completeness and reproducibility checks","Share access, export, denial, expiry, and revocation"],"href":"/journeys/governed-spatial-analysis"},{"slug":"durable-weekend-itinerary","title":"Durable multi-stop itinerary","eyebrow":"Search + Routes · intent and route revisions","productSlug":"routes-navigation","stateModel":"hybrid","summary":"Discover provider-backed places, preserve their Mappls Pins in a versioned itinerary, preview the exact ordered route, invalidate stale plans on edits, and retain visit or skip progress through completion.","aggregate":"trip itinerary","actors":["Traveller","Collaborator","Mappls discovery service","Mappls routing service"],"sourceGuideSlugs":["mappls-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-rest-key-resources-profile-geopositions-routing-api"],"sampleSlug":"trip-planner","states":[{"id":"draft","label":"Draft","meaning":"An ordered, bounded set of provider-backed places represents current trip intent without claiming a valid route.","recovery":"Resolve edits by aggregate version and retain stable Mappls Pins; never merge by display label."},{"id":"planned","label":"Planned","meaning":"A route revision is bound to the exact ordered stop identities, travel profile, provider response, and planning time.","recovery":"Any stop, order, profile, or constraint change invalidates the revision and returns the itinerary to draft."},{"id":"active","label":"Active","meaning":"The traveller started the current route revision and each next stop receives an explicit visited or skipped outcome.","recovery":"Resume from durable progress; recalculate from current trusted context instead of replaying stale guidance."},{"id":"paused","label":"Paused","meaning":"An attributable interruption stops progress without discarding saved stops, outcomes, or route identity.","recovery":"Refresh time-sensitive context and require deliberate resume or cancellation."},{"id":"completed","label":"Completed","meaning":"Every stop is visited or explicitly skipped and the terminal itinerary, route revision, outcomes, and event history are retained.","recovery":"Later edits create a new trip or linked revision rather than rewriting completed history.","terminal":true},{"id":"cancelled","label":"Cancelled","meaning":"A named actor ended the itinerary with a reason while retaining all committed place, route, and progress evidence.","recovery":"Create a linked replacement trip when intent returns rather than reactivating terminal history.","terminal":true}],"transitions":[{"command":"create_trip","actor":"Traveller","from":[],"to":"draft","event":"trip.created","idempotency":"Use a client trip command ID before the first network attempt."},{"command":"add_or_reorder_stop","actor":"Traveller","from":["draft","planned"],"to":"draft","event":"trip.sequence_changed","idempotency":"Compare trip version and bind every saved item to a unique Mappls Pin."},{"command":"preview_route","actor":"Mappls routing service","from":["draft"],"to":"planned","event":"trip.route_previewed","idempotency":"Hash ordered pins, profile, constraints, departure intent, and aggregate version."},{"command":"start_trip","actor":"Traveller","from":["planned"],"to":"active","event":"trip.started","idempotency":"Bind start to the current trip and route revision."},{"command":"pause_trip","actor":"Traveller","from":["active"],"to":"paused","event":"trip.paused","idempotency":"Record the interruption reason once under a stable client command identity."},{"command":"resume_trip","actor":"Traveller","from":["paused"],"to":"active","event":"trip.resumed","idempotency":"Bind resume to the paused aggregate and current route revision."},{"command":"visit_or_skip_next","actor":"Traveller","from":["active"],"to":"active","event":"trip.stop_completed","idempotency":"Generate one command identity per stop outcome; require a reason for skip."},{"command":"complete_trip","actor":"Traveller","from":["active"],"to":"completed","event":"trip.completed","idempotency":"Terminal version and command ID identify one completion."},{"command":"cancel_trip","actor":"Traveller","from":["draft","planned","active","paused"],"to":"cancelled","event":"trip.cancelled","idempotency":"One command records actor, reason, previous state, and terminal version."}],"invariants":["Every saved stop originated from provider-backed discovery and retains its Mappls Pin and provenance.","A Mappls Pin occurs at most once in an itinerary.","A route revision is valid only for the exact ordered stop list and constraints that produced it.","Only the next pending stop may receive a visit or skip outcome.","Completion is impossible while any stop remains pending.","Commands are idempotent and compare the expected trip version."],"records":[{"name":"Trip aggregate","purpose":"Business identity, date, party, lifecycle, current route revision, and optimistic version.","keyFields":["tripId","state","version","date","partySize","routeRevision"]},{"name":"Itinerary stop","purpose":"Ordered provider-backed place and progress outcome.","keyFields":["mapplsPin","position","providerProvenance","status","completedAt","skipReason"]},{"name":"Route revision","purpose":"Immutable preview for one exact intent version.","keyFields":["routeId","revision","orderedPins","profile","legs","distance","duration","plannedAt"]},{"name":"Audit and outbox","purpose":"Attributable changes and reliable downstream collaboration or notification.","keyFields":["eventId","aggregateVersion","actor","commandId","outboxStatus"]}],"failures":[{"trigger":"A collaborator edits after route preview","detection":"Current stop identities or aggregate version differ from the route's intent version.","recovery":"Invalidate the route, show the edit, and require a new preview before start."},{"trigger":"Routing succeeds but response is lost","detection":"The same ordered intent and request identity has no committed route revision.","recovery":"Reconcile or repeat the same idempotent request; never attach a response to newer intent."},{"trigger":"A venue becomes unavailable during the trip","detection":"Traveller or fresh provider/business data marks the next stop unavailable.","recovery":"Record an explicit skip with reason, then offer a newly versioned replan from current context."},{"trigger":"Application restarts mid-trip","detection":"A durable active aggregate exists without current client state.","recovery":"Restore visit/skip progress and current revision, refresh stale operational data, and ask before resuming guidance."}],"observability":["Discovery-to-save rate and Mappls Pin continuity","Stop edits, duplicates, limits, and version conflicts","Route preview latency, failures, profiles, and revisions","Time from preview to start and stale-preview invalidation","Visited and skipped stops with reason","Active trips without recent progress","Idempotent replay, outbox backlog, and restart recovery"],"href":"/journeys/durable-weekend-itinerary"},{"slug":"consented-address-verification","title":"Consented address verification","eyebrow":"Search & Places · purpose-bound evidence decision","productSlug":"search-places","stateModel":"stateful","summary":"Normalize a declared service address, capture purpose-bound device evidence, apply an explainable versioned policy, require human review where evidence is weak, and retire precise data without erasing accountability.","aggregate":"address verification","actors":["Application user","Evidence capture application","Policy service","Human reviewer","Privacy service"],"sourceGuideSlugs":["mappls-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-rest-key-rev-geocode-reverse-geocode-api"],"sampleSlug":"address-verifier","states":[{"id":"entered","label":"Entered","meaning":"One external business reference, opaque subject reference, declared purpose, and raw address intent are recorded.","recovery":"Reconcile by external reference and idempotency key instead of minting a duplicate verification."},{"id":"normalized","label":"Normalized","meaning":"The declared address maps to a provider-backed Mappls Pin, coordinate, components, confidence, and provenance.","recovery":"Keep ambiguous candidates visible and request subject or operator confirmation before capture."},{"id":"capture_authorized","label":"Capture authorized","meaning":"A specific subject granted one purpose-bound, expiring, accuracy- and retention-governed evidence capture.","recovery":"Reject expired or withdrawn grants and issue a new consent event when purpose or policy changes."},{"id":"evidence_captured","label":"Evidence captured","meaning":"Immutable source identity, event and receipt time, coordinate, accuracy, provider context, and integrity hash are committed.","recovery":"Deduplicate by source event and preserve conflicting or late observations as separate evidence rather than overwriting them."},{"id":"compared","label":"Compared","meaning":"A versioned policy records distance, effective uncertainty, thresholds, and its verify, reject, or review recommendation.","recovery":"Recompute only as a new policy decision version and retain the earlier recommendation."},{"id":"review_required","label":"Review required","meaning":"Weak, conflicting, or policy-sensitive evidence is assigned to an attributable human decision.","recovery":"Keep the case pending with an SLA; never auto-verify merely because a review queue is unavailable."},{"id":"verified","label":"Verified","meaning":"A policy or human decision accepted the declared address for the exact recorded purpose.","recovery":"A later change creates a linked verification; it does not rewrite the evidence and policy that supported this outcome.","terminal":true},{"id":"rejected","label":"Rejected","meaning":"Evidence did not establish the declared address, with reason, recommendation, actor, and appeal path retained.","recovery":"Offer correction or a new independent attempt without exposing sensitive fraud or policy signals.","terminal":true},{"id":"cancelled","label":"Cancelled","meaning":"Consent was withdrawn before evidence capture and no precise observation may be accepted.","recovery":"A later attempt requires a fresh purpose-bound consent, not reactivation of the revoked grant.","terminal":true}],"transitions":[{"command":"enter_verification","actor":"Application user","from":[],"to":"entered","event":"address_verification.entered","idempotency":"Use the external application or case reference as durable business identity."},{"command":"normalize_address","actor":"Policy service","from":["entered"],"to":"normalized","event":"address_verification.normalized","idempotency":"Bind normalized provider response to address-input hash and request identity."},{"command":"authorize_capture","actor":"Application user","from":["normalized"],"to":"capture_authorized","event":"address_verification.capture_authorized","idempotency":"Consent identity, text version, subject, purpose, expiry, and retention policy form one grant."},{"command":"revoke_consent","actor":"Application user","from":["capture_authorized"],"to":"cancelled","event":"address_verification.consent_revoked","idempotency":"Commit withdrawal once and reject all later evidence under that grant."},{"command":"capture_evidence","actor":"Evidence capture application","from":["capture_authorized"],"to":"evidence_captured","event":"address_verification.evidence_captured","idempotency":"Use a device-generated source-event identity created before transmission."},{"command":"compare","actor":"Policy service","from":["evidence_captured"],"to":"compared","event":"address_verification.compared","idempotency":"Evidence hash, normalized-place version, and policy version identify the exact comparison."},{"command":"verify","actor":"Policy service","from":["compared"],"to":"verified","event":"address_verification.verified","idempotency":"Bind the terminal decision to comparison and aggregate version."},{"command":"reject","actor":"Policy service","from":["compared"],"to":"rejected","event":"address_verification.rejected","idempotency":"Bind the terminal decision to comparison and aggregate version."},{"command":"defer","actor":"Policy service","from":["compared"],"to":"review_required","event":"address_verification.review_required","idempotency":"Create one review case per comparison version."},{"command":"review_verify","actor":"Human reviewer","from":["review_required"],"to":"verified","event":"address_verification.verified","idempotency":"Reviewer decision records reason, independent evidence, and any override under one identity."},{"command":"review_reject","actor":"Human reviewer","from":["review_required"],"to":"rejected","event":"address_verification.rejected","idempotency":"Reviewer decision records reason, independent evidence, and any override under one identity."}],"invariants":["One external business reference maps to one verification aggregate.","Precise evidence is accepted only under active consent for the exact declared purpose and time window.","Provider normalization and application policy are identified separately.","An automated actor cannot override its own policy recommendation.","Every terminal outcome retains evidence hash, policy version, actor, and attributable reason.","Precise evidence can be redacted without erasing the audit trail or claiming that retained hashes can reconstruct it."],"records":[{"name":"Verification aggregate","purpose":"Business identity, purpose, lifecycle, selected evidence, comparison, decision, and version.","keyFields":["verificationId","externalReference","subjectReference","purpose","state","version"]},{"name":"Normalized address","purpose":"Provider-backed place identity and address interpretation.","keyFields":["mapplsPin","coordinate","formattedAddress","components","confidence","provenance"]},{"name":"Consent grant","purpose":"Attributable authority and privacy bounds for precise capture.","keyFields":["consentId","subject","purpose","textVersion","grantedAt","expiresAt","retentionUntil","status"]},{"name":"Evidence envelope","purpose":"Immutable device observation with quality, timing, provenance, and integrity identity.","keyFields":["evidenceId","sourceEventId","eventTime","receivedAt","coordinate","accuracy","contentHash"]},{"name":"Decision record","purpose":"Explainable recommendation, human disposition, override, and appeal context.","keyFields":["policyVersion","thresholds","recommendation","outcome","actor","reason"]}],"failures":[{"trigger":"Capture arrives after consent expiry or withdrawal","detection":"Receipt or evidence event falls outside the committed grant window or grant status is revoked.","recovery":"Reject it without retaining precise payload and require a fresh consent for another attempt."},{"trigger":"Device evidence is replayed","detection":"Source-event identity or content hash already belongs to an accepted evidence envelope.","recovery":"Return the original result for an idempotent retry or reject conflicting reuse as a security event."},{"trigger":"Address candidate is ambiguous or evidence accuracy is weak","detection":"Provider confidence, device accuracy, separation, or policy combination enters the review band.","recovery":"Request clarification or independent review; do not transform uncertainty into a definitive match."},{"trigger":"Retention deadline passes","detection":"Precise evidence remains present beyond purpose, tenant, or jurisdiction policy.","recovery":"Redact coordinate and place payloads, retain the minimum decision and integrity record, and audit completion."}],"observability":["Normalization confidence, ambiguity, latency, and provider failures","Consent grant, expiry, withdrawal, and out-of-window capture attempts","Evidence accuracy, age, source integrity, replay, and mock-location risk","Distance and recommendation distribution by versioned policy","Review queue age, outcome, override rate, and supporting-evidence class","False-match, false-reject, correction, and appeal outcomes","Precise-data access, export, retention expiry, redaction, and legal hold","Idempotency conflicts, version conflicts, outbox backlog, and restart recovery"],"href":"/journeys/consented-address-verification"},{"slug":"governed-spatial-agent-run","title":"Governed spatial agent run","eyebrow":"Mappls MCP · approval-bound tool orchestration","productSlug":"ai-location","stateModel":"stateful","summary":"Turn a natural-language spatial objective into an inspectable plan, obtain an exact least-privilege approval, execute allow-listed Mappls tools, and cite provider evidence without exposing credentials to the model.","aggregate":"agent run","actors":["Application user","Agent planner","Human approver","Execution service","Mappls MCP server"],"sourceGuideSlugs":["mappls-rest-apis","mappls-intouch-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-api-places-nearby-json-nearby-api","core-location-get-rest-key-resources-profile-geopositions-routing-api","intouch-get-devices-gets-the-live-data-of-devices"],"sampleSlug":"spatial-agent","states":[{"id":"asked","label":"Asked","meaning":"A stable run records the user's objective, scenario, actor, tenant, purpose, and bounded inputs before any provider access.","recovery":"Replay creation by client command identity and never create a second run merely because a response timed out."},{"id":"planned","label":"Planned","meaning":"A schema-valid allow-listed dependency graph, risk class, scopes, argument bounds, and canonical plan hash are available for inspection.","recovery":"Treat any change as a new plan version and invalidate prior approvals rather than editing an approved plan in place."},{"id":"approved","label":"Approved","meaning":"An attributable person approved the exact plan hash, every required scope, purpose, data boundary, policy version, and expiry.","recovery":"If scope, plan, policy, or context changes, expire the grant and request a fresh independent approval."},{"id":"executing","label":"Executing","meaning":"A service-side lease owns execution and calls each Mappls tool only after dependencies and authorization are satisfied.","recovery":"Reconcile ambiguous provider outcomes by stable request identity before retrying any step with side effects."},{"id":"completed","label":"Completed","meaning":"The grounded answer, structured outputs, exact tool evidence, provenance, citations, cost, and terminal audit event are committed.","recovery":"Corrections create a linked run or derived answer revision; they do not rewrite executed evidence.","terminal":true},{"id":"rejected","label":"Rejected","meaning":"A named approver denied the proposed plan with an attributable reason and no provider calls occurred.","recovery":"Revise the objective or reduce risk and scopes in a new plan; never silently resubmit the same grant.","terminal":true},{"id":"failed","label":"Failed","meaning":"Execution stopped with a typed, secret-safe error and retained evidence for every completed step.","recovery":"Classify retryability, reconcile completed calls, and create a linked retry attempt when policy permits.","terminal":true}],"transitions":[{"command":"ask","actor":"Application user","from":[],"to":"asked","event":"agent.question_received","idempotency":"Use a client-generated run command ID across network retries."},{"command":"create_plan","actor":"Agent planner","from":["asked"],"to":"planned","event":"agent.plan_created","idempotency":"Canonical objective, policy, planner version, and normalized plan produce one immutable hash."},{"command":"approve_plan","actor":"Human approver","from":["planned"],"to":"approved","event":"agent.plan_approved","idempotency":"Bind approver decision to run version, exact plan hash, scopes, purpose, and expiry."},{"command":"reject_plan","actor":"Human approver","from":["planned"],"to":"rejected","event":"agent.plan_rejected","idempotency":"Persist the review decision and reason under one command identity."},{"command":"start_execution","actor":"Execution service","from":["approved"],"to":"executing","event":"agent.execution_started","idempotency":"Acquire one lease only after recalculating plan hash and rechecking approval, scopes, expiry, and policy."},{"command":"complete_execution","actor":"Execution service","from":["executing"],"to":"completed","event":"agent.execution_completed","idempotency":"Commit terminal result, citations, audit, and outbox against the execution attempt identity."}],"invariants":["The model never receives Mappls or customer credentials.","Only schema-valid allow-listed tools and bounded arguments can enter a plan.","Approval names the canonical immutable plan hash and every required scope.","An expired, superseded, partially scoped, or self-approved plan cannot execute.","Every factual provider claim is traceable to retained Mappls provenance.","Tool failures and persisted evidence never expose secrets."],"records":[{"name":"Agent run","purpose":"Durable objective, lifecycle, version, risk, actor, tenant, and purpose boundary.","keyFields":["runId","state","version","tenantId","question","risk"]},{"name":"Plan manifest","purpose":"Canonical tool graph, dependencies, arguments, requested scopes, and integrity identity.","keyFields":["planVersion","planHash","plannerVersion","steps","requiredScopes","policyVersion"]},{"name":"Approval grant","purpose":"Independent attributable authority for one exact plan and bounded time window.","keyFields":["planHash","approvedBy","approvedScopes","purpose","approvedAt","expiresAt"]},{"name":"Tool evidence","purpose":"Resolved arguments, structured response, provider provenance, status, timing, and stable request identity.","keyFields":["toolCallId","stepId","tool","requestId","provenance","completedAt"]},{"name":"Grounded result","purpose":"Answer and machine-readable outputs with per-step citations and inference labels.","keyFields":["runId","answer","citations","generatedAt","modelVersion"]}],"failures":[{"trigger":"Prompt or retrieved content asks for an unapproved tool","detection":"The proposed tool, scope, host, or argument is absent from the validated plan policy.","recovery":"Reject the plan or stop execution and surface the exact policy denial for human review."},{"trigger":"Plan changes after approval","detection":"Recomputed canonical hash differs from the approved plan hash.","recovery":"Refuse execution, append a tamper or supersession event, and require a new review."},{"trigger":"Provider call succeeds but the worker loses its response","detection":"Execution lease expires with an ambiguous step and stable request identity.","recovery":"Reconcile by provider or application request identity before retrying, especially for side-effecting tools."},{"trigger":"Tool output lacks provenance or contains a secret","detection":"Response-envelope validation or redaction policy fails.","recovery":"Quarantine the output, stop the run safely, rotate any exposed secret, and retain only a sanitized incident record."}],"observability":["Runs and time spent in asked, planned, approved, and executing states","Approval, rejection, expiry, and scope-reduction rate by risk class","Plan hash mismatch, policy denial, and prompt-injection detection","Tool latency, quota, retry, reconciliation, and cost by operation","Provider provenance and citation coverage","Sensitive-location access by tenant, actor, purpose, and retention class","Execution leases, orphaned attempts, outbox backlog, and restart recovery"],"href":"/journeys/governed-spatial-agent-run"},{"slug":"offline-automotive-release","title":"Offline automotive release","eyebrow":"Embedded navigation · fleet control plane","productSlug":"offline-automotive","stateModel":"stateful","summary":"Manufacture, activate, install, operate, update, recover, and retire a navigation runtime and map-data release as one compatible system.","aggregate":"device release","actors":["Manufacturing system","Fleet release manager","Vehicle runtime","Support engineer"],"sourceGuideSlugs":[],"contractSlugs":[],"sampleSlug":"offline-release-control","states":[{"id":"manufactured","label":"Manufactured","meaning":"Hardware identity, target architecture, software edition, and vehicle configuration are recorded.","recovery":"Quarantine duplicate or unreadable hardware identity before activation."},{"id":"activated","label":"Activated","meaning":"The device has a scoped entitlement and trusted activation identity.","recovery":"Refresh or rotate activation without replacing the durable vehicle identity."},{"id":"installed","label":"Installed","meaning":"A verified compatible runtime, configuration, voice set, and base map package are staged.","recovery":"Reject incompatible manifests before touching the active slot."},{"id":"operational","label":"Operational","meaning":"The active slot passed startup, route, search, positioning, audio, storage, and health checks.","recovery":"Remain on or revert to the last-known-good slot when qualification fails."},{"id":"updating","label":"Updating","meaning":"A cohort release is downloading, verifying, staging, switching, and qualifying under a durable plan.","recovery":"Resume downloads by part and make the active-slot switch atomic across power loss."},{"id":"recovering","label":"Recovering","meaning":"Watchdog or health policy selected rollback, repair, or safe degraded operation.","recovery":"Record the failing manifest and recovery reason before switching to last known good."},{"id":"retired","label":"Retired","meaning":"Activation is revoked and the device no longer receives protected packages or service.","recovery":"Reactivation is a new controlled authorization event, not a local flag change.","terminal":true}],"transitions":[{"command":"register_device","actor":"Manufacturing system","from":[],"to":"manufactured","event":"device.registered","idempotency":"Hardware identity and manufacturing batch form the stable key."},{"command":"activate","actor":"Fleet release manager","from":["manufactured"],"to":"activated","event":"license.activated","idempotency":"Activation request and entitlement version must be replay-safe."},{"command":"stage_base_release","actor":"Vehicle runtime","from":["activated"],"to":"installed","event":"release.installed","idempotency":"Manifest digest identifies the exact runtime-data-config unit."},{"command":"qualify","actor":"Vehicle runtime","from":["installed","recovering"],"to":"operational","event":"release.qualified","idempotency":"Qualification result is bound to manifest and test-suite version."},{"command":"start_update","actor":"Fleet release manager","from":["operational"],"to":"updating","event":"release.update_started","idempotency":"Device, target manifest, and rollout campaign identify one plan."},{"command":"rollback","actor":"Vehicle runtime","from":["updating","operational"],"to":"recovering","event":"release.rollback_started","idempotency":"Watchdog incident ID prevents repeated rollback side effects."},{"command":"retire","actor":"Fleet release manager","from":["manufactured","activated","installed","operational","recovering"],"to":"retired","event":"device.retired","idempotency":"Revoke activation and package access under one retirement identity."}],"invariants":["Runtime, map data, configuration, and voice assets are qualified as one compatible manifest.","Only a verified inactive slot may replace the active slot.","Power loss at any update point leaves one bootable known-good slot.","Activation identity and secrets are distinct from vehicle business identity.","Retirement revokes protected access without erasing support and release history."],"records":[{"name":"Device identity","purpose":"Manufacturing, vehicle, activation, and hardware trust mapping.","keyFields":["deviceId","hardwareId","vehicleId","edition","activationState"]},{"name":"Release manifest","purpose":"Signed compatibility unit for runtime, data, configuration, and assets.","keyFields":["manifestId","digest","target","components","signature","compatibility"]},{"name":"Update plan","purpose":"Durable per-device progress through download, verify, stage, switch, and qualify.","keyFields":["planId","campaignId","deviceId","targetManifest","phase","checkpoint"]},{"name":"Health incident","purpose":"Watchdog evidence, recovery action, and support context.","keyFields":["incidentId","activeManifest","signal","action","outcome","occurredAt"]}],"failures":[{"trigger":"Power loss during update","detection":"Boot control sees an incomplete plan and unchanged or unqualified target slot.","recovery":"Boot the known-good slot and resume or discard staging from the durable checkpoint."},{"trigger":"Runtime and map package are incompatible","detection":"Manifest compatibility or startup qualification fails.","recovery":"Reject before activation and report exact component constraints."},{"trigger":"Activation cannot refresh while offline","detection":"Entitlement is near expiry and network is unavailable.","recovery":"Apply the licensed offline grace policy visibly; never extend entitlement by changing device time."},{"trigger":"New release causes route or crash regression","detection":"Cohort health breaches automated rollout thresholds.","recovery":"Halt the campaign, roll affected devices back, and retain incident-linked diagnostic bundles."}],"observability":["Fleet distribution by active and target manifest","Download, verification, switch, and qualification duration","Interrupted and resumed update phase","Activation refresh health and offline grace usage","Crash, watchdog, routing, positioning, and storage health by cohort","Rollback cause, success, and last-known-good age"],"href":"/journeys/offline-automotive-release"},{"slug":"widget-selection-session","title":"Application-owned widget selection","eyebrow":"Widgets · host-owned candidate lifecycle","productSlug":"app-widgets-deep-links","stateModel":"hybrid","summary":"Launch a Mappls widget, recover through a useful fallback, validate a narrow candidate, commit it deliberately, invalidate stale selection, and submit one durable business record.","aggregate":"widget selection session","actors":["Application user","Host application","Platform adapter","Mappls widget"],"sourceGuideSlugs":["mappls-app-widgets","mappls-android-sdk","mappls-ui-widget-ios-distribution","mappls-ui-widget-ios-distribution-base","mappls-flutter-sdk","mappls-react-native-sdk"],"contractSlugs":[],"sampleSlug":"widget-journey-host","states":[{"id":"draft","label":"Draft","meaning":"Host-owned address or place intent exists without an active provider surface or committed Mappls identity.","recovery":"Restore only the host draft; never serialize a widget view, controller, listener, Promise, or opaque provider result."},{"id":"widget_open","label":"Widget open","meaning":"One launch generation owns the provider surface, lifecycle callbacks, focus, cancellation, and timeout.","recovery":"Dispose the generation exactly once and either retry explicitly or activate the host-owned fallback."},{"id":"fallback_active","label":"Fallback active","meaning":"The provider surface is unavailable and a bounded manual or search-assisted host path remains operable.","recovery":"Preserve the same session identity and record why fallback was selected before returning a candidate."},{"id":"candidate_received","label":"Candidate received","meaning":"An exact-origin or native-adapter result passed schema validation but is not yet a business selection.","recovery":"Discard malformed, late, duplicated, or superseded candidates; retain only the narrow normalized value."},{"id":"selected","label":"Selected","meaning":"The user deliberately committed a normalized Mappls Pin and label against the current host draft version.","recovery":"Any material host edit clears selection and returns the aggregate to draft."},{"id":"submitted","label":"Submitted","meaning":"Host text and committed selection form one immutable, attributable business record with an outbox event.","recovery":"Treat submission as terminal; corrections create a new version or linked replacement rather than changing history.","terminal":true},{"id":"cancelled","label":"Cancelled","meaning":"A named actor ended the journey without submission and with a recorded reason.","recovery":"Start a new session for renewed intent; do not silently resurrect a cancelled provider generation.","terminal":true}],"transitions":[{"command":"create_session","actor":"Host application","from":[],"to":"draft","event":"host.session_created","idempotency":"The external checkout/form identity maps to one aggregate across retries."},{"command":"open_widget","actor":"Application user","from":["draft","fallback_active"],"to":"widget_open","event":"widget.opened","idempotency":"Persist one launch generation and ignore every callback belonging to an older generation."},{"command":"activate_fallback","actor":"Platform adapter","from":["widget_open"],"to":"fallback_active","event":"widget.fallback_activated","idempotency":"One failed generation produces at most one fallback transition and focus restoration."},{"command":"receive_candidate","actor":"Platform adapter","from":["widget_open","fallback_active"],"to":"candidate_received","event":"location.candidate_received","idempotency":"Deduplicate the terminal adapter result and bind it to session and launch generation."},{"command":"accept_selection","actor":"Application user","from":["candidate_received"],"to":"selected","event":"location.selected","idempotency":"Compare aggregate version and hash the normalized candidate before committing."},{"command":"edit_host_text","actor":"Application user","from":["draft","widget_open","fallback_active","candidate_received","selected"],"to":"draft","event":"host.text_edited","idempotency":"The edit command version determines whether candidate and selection invalidation already occurred."},{"command":"submit","actor":"Application user","from":["selected"],"to":"submitted","event":"host.submitted","idempotency":"Commit the record, audit event, processed command, and outbox entry atomically."},{"command":"cancel","actor":"Application user","from":["draft","widget_open","fallback_active","candidate_received","selected"],"to":"cancelled","event":"host.cancelled","idempotency":"Repeated cancellation returns the terminal record without rerunning cleanup side effects."}],"invariants":["A provider callback or browser message creates only a candidate, never a submitted business record.","Every browser message matches the exact reviewed origin and a versioned allow-listed schema.","Only a six-character alphanumeric Mappls Pin and bounded printable label enter durable selection state.","A host-text edit invalidates every candidate and committed selection from the previous draft version.","One launch generation produces at most one terminal adapter outcome; late callbacks are ignored.","Credentials, provider controllers, native views, bridge objects, and opaque response payloads are never persisted."],"records":[{"name":"Selection session","purpose":"Current host draft, lifecycle state, launch generation, candidate, selection, and optimistic version.","keyFields":["sessionId","externalId","state","version","launchGeneration","hostText"]},{"name":"Normalized selection","purpose":"Application-owned portable place identity independent of provider UI lifetime.","keyFields":["schemaVersion","mapplsPin","label","source","selectedAt","selectedBy"]},{"name":"Audit event","purpose":"Attributable state transition and recovery history.","keyFields":["eventId","aggregateVersion","type","actor","idempotencyKey","occurredAt"]},{"name":"Transactional outbox","purpose":"Exactly-once-in-effect notification and downstream form processing.","keyFields":["outboxId","eventId","status","attempts","nextAttemptAt"]}],"failures":[{"trigger":"Widget fails, is denied, or times out","detection":"The active generation reaches a typed failure without a valid terminal candidate.","recovery":"Dispose it, restore focus, record the reason, and activate a useful host-owned fallback."},{"trigger":"Message arrives from a wrong origin or with unknown fields","detection":"Exact origin or narrow schema validation fails before domain processing.","recovery":"Reject without changing aggregate state and emit a safe rejection metric without storing opaque content."},{"trigger":"Callback arrives after screen disposal or a newer launch","detection":"Owner is inactive or result generation differs from the current session generation.","recovery":"Ignore the late result and clean up its provider resources without committing state."},{"trigger":"User edits the address after selecting a place","detection":"Host draft version changes while a candidate or selection exists.","recovery":"Clear both values, return to draft, and require a new selection before submission."},{"trigger":"Submit response is lost","detection":"Client lacks acknowledgement but retains session and idempotency identity.","recovery":"Repeat the same command key or read the session; never create a second business record."}],"observability":["Widget launch, time-to-active, and terminal outcome by platform and component version","Origin and schema rejection counts without raw payload retention","Fallback activation, completion, and abandonment rate","Candidate-to-selection and selection-to-submit conversion","Stale selection invalidation after host edits","Duplicate, late, and superseded callback count","Idempotency replay and optimistic version conflict rate","Outbox backlog, retry, and dead-letter age"],"href":"/journeys/widget-selection-session"},{"slug":"ios-direction-planning-handoff","title":"iOS direction planning and navigation handoff","eyebrow":"MapplsDirectionUI · route candidate lifecycle","productSlug":"routes-navigation","stateModel":"hybrid","summary":"Own route intent and revisions in the host app, present MapplsDirectionUI for editing and calculation, validate the selected route callback, and hand off to navigation without confusing a UI request with a started or completed trip.","aggregate":"route planning session","actors":["Traveler","Host application","MapplsDirectionUI","Navigation adapter"],"sourceGuideSlugs":["mappls-direction-ui-ios-distribution","mappls-direction-ui-ios-distribution-base"],"contractSlugs":[],"sampleSlug":"deep-link-journey-host","tutorialSlugs":["ios-direction-geofence-handoffs"],"states":[{"id":"draft","label":"Draft","meaning":"The host owns one route intent, traveler context, and revision before presenting provider UI.","recovery":"Restore only normalized locations and host preferences; never serialize a view controller, delegate, or provider route object."},{"id":"editing","label":"Editing","meaning":"One presented controller generation owns source, destination, via points, options, delegates, dismissal, and accessibility focus.","recovery":"Dismiss and dispose the active generation once; a new presentation receives a new generation and route revision."},{"id":"calculating","label":"Calculating","meaning":"The provider surface is resolving route alternatives for the current immutable location and option revision.","recovery":"Retain the host draft and expose retry or edit; never reuse candidates calculated for an older revision."},{"id":"candidates_ready","label":"Candidates ready","meaning":"One or more provider route objects are visible for comparison but remain controller-scoped candidates.","recovery":"If stops or route options change, invalidate the full candidate set and calculate again."},{"id":"selected","label":"Selected","meaning":"The traveler selected an in-range route index and the adapter copied a bounded route handoff value plus the exact location revision.","recovery":"A subsequent edit invalidates selection; do not persist the opaque Route instance as application state."},{"id":"handoff_pending","label":"Handoff pending","meaning":"The documented start-navigation callback requested a host-owned navigation action, but no target navigator acknowledgement exists yet.","recovery":"Retry with the same handoff identity or return visibly to selection; never report navigation as active from the button callback alone."},{"id":"handed_off","label":"Handed off","meaning":"The configured navigation adapter accepted the normalized route request and returned its own attributable session identity or acknowledgement.","recovery":"Navigation progress and completion belong to the selected navigation product's separate lifecycle.","terminal":true},{"id":"cancelled","label":"Cancelled","meaning":"The traveler dismissed or backed out and the host recorded one terminal cancellation without a route handoff.","recovery":"Renewed intent creates a new planning session rather than resurrecting the disposed controller.","terminal":true}],"transitions":[{"command":"create_plan","actor":"Host application","from":[],"to":"draft","event":"route_plan.created","idempotency":"One external journey intent maps to one route-planning aggregate across retries."},{"command":"open_direction_ui","actor":"Traveler","from":["draft","selected"],"to":"editing","event":"route_plan.editor_opened","idempotency":"One command creates one presentation generation and one delegate ownership record."},{"command":"request_routes","actor":"Traveler","from":["editing"],"to":"calculating","event":"route_plan.calculation_requested","idempotency":"Hash normalized locations, options, and revision so duplicate requests share one logical calculation."},{"command":"receive_routes","actor":"MapplsDirectionUI","from":["calculating"],"to":"candidates_ready","event":"route_plan.candidates_received","idempotency":"Accept only the active generation and revision; repeated callbacks replace no committed state."},{"command":"select_route","actor":"Traveler","from":["candidates_ready"],"to":"selected","event":"route_plan.route_selected","idempotency":"Validate selectedRouteIndex against the returned collection and commit one normalized handoff value for the route revision."},{"command":"request_navigation","actor":"Traveler","from":["selected","candidates_ready"],"to":"handoff_pending","event":"route_plan.navigation_requested","idempotency":"Bind callback generation, route revision, selected index, and host command key to one handoff attempt."},{"command":"confirm_handoff","actor":"Navigation adapter","from":["handoff_pending"],"to":"handed_off","event":"route_plan.navigation_handed_off","idempotency":"Persist the target acknowledgement once and let its separate lifecycle own later progress."},{"command":"cancel_plan","actor":"Traveler","from":["draft","editing","calculating","candidates_ready","selected","handoff_pending"],"to":"cancelled","event":"route_plan.cancelled","idempotency":"Repeated back, dismissal, or cancel signals dispose once and return the same terminal outcome."}],"invariants":["Stops, options, route candidates, and selection share one explicit revision.","A selected index is validated before dereferencing its Route candidate.","The provider controller and opaque Route objects never become durable application records.","The start-navigation callback expresses intent, not proof that navigation started or completed.","One presentation generation produces at most one terminal handoff or cancellation.","Credentials and unrestricted location histories never enter route-planning audit events."],"records":[{"name":"Route plan","purpose":"Host-owned normalized stops, options, revision, lifecycle state, and optimistic version.","keyFields":["planId","externalId","state","routeRevision","version","owner"]},{"name":"Route handoff candidate","purpose":"Bounded portable value copied from the active route selection without retaining provider UI objects.","keyFields":["candidateId","routeRevision","selectedIndex","locationDigest","optionDigest","createdAt"]},{"name":"Handoff attempt","purpose":"Immutable request and target acknowledgement separating planning from navigation runtime.","keyFields":["attemptId","candidateId","target","status","targetSessionRef","requestedAt"]},{"name":"Audit and outbox","purpose":"Attributable transitions and exactly-once-in-effect downstream notification.","keyFields":["eventId","aggregateVersion","actor","idempotencyKey","outboxStatus"]}],"failures":[{"trigger":"Route calculation fails or returns no alternatives","detection":"The active controller reports an error or has no valid selected route for the current revision.","recovery":"Keep the editable draft, show a safe error, and allow option or stop revision before retry."},{"trigger":"A delegate callback arrives from an old controller","detection":"The callback presentation generation differs from the aggregate's active generation.","recovery":"Ignore it, dispose its resources, and leave the current route revision unchanged."},{"trigger":"Selected route index is stale or invalid","detection":"The index is outside the current route collection or belongs to a superseded calculation revision.","recovery":"Reject the handoff and require visible reselection from current candidates."},{"trigger":"Navigation target rejects or times out","detection":"No target acknowledgement exists for the handoff identity inside the bounded deadline.","recovery":"Remain handoff pending, expose retry or return-to-selection, and do not claim an active navigation session."}],"observability":["Editor presentation, dismissal, and terminal result by released component version","Calculation latency, failure, and zero-alternative rate","Stop and option revision count before selection","Candidate-to-selection and selection-to-handoff conversion","Invalid index, stale generation, duplicate callback, and late callback rejection","Handoff acknowledgement latency and target rejection rate","Idempotency replay and optimistic version conflict rate"],"href":"/journeys/ios-direction-planning-handoff"},{"slug":"ios-geofence-draft","title":"iOS geofence draft and publication boundary","eyebrow":"MapplsGeofenceUI · versioned application geometry","productSlug":"intouch-telematics","stateModel":"hybrid","summary":"Present the Mappls geofence editor, normalize circle or polygon output into a versioned application draft, validate geometry and policy, and stop at a review-ready artifact until a separately documented provider publication contract is selected.","aggregate":"geofence draft","actors":["Operations author","Host application","MapplsGeofenceUI","Geofence reviewer","Rule-publication adapter"],"sourceGuideSlugs":["mappls-geofence-ui-ios-distribution","mappls-geofence-ui-ios-distribution-base"],"contractSlugs":[],"sampleSlug":"deep-link-journey-host","tutorialSlugs":["ios-direction-geofence-handoffs"],"states":[{"id":"draft","label":"Draft","meaning":"The host owns name, purpose, subject scope, rule intent, and geometry revision before opening the editor.","recovery":"Restore normalized host fields only; no MapplsGeofenceView, delegate, map source, or layer is durable state."},{"id":"editing","label":"Editing","meaning":"One view and delegate generation owns mode, handles, slider, style, callbacks, dismissal, and cleanup.","recovery":"Dispose exactly once and reopen with a new generation; never accept callbacks from the superseded view."},{"id":"candidate","label":"Candidate","meaning":"Circle or polygon output has been copied into a portable geometry schema but is not yet an operational rule.","recovery":"Reject missing, malformed, self-intersecting, out-of-bounds, or policy-breaking geometry with actionable feedback."},{"id":"review_pending","label":"Review pending","meaning":"Valid geometry, purpose, scope, schedule intent, and policy version await an attributable application review.","recovery":"Reviewer changes create a new immutable geometry revision and reopen validation rather than editing evidence in place."},{"id":"approved_draft","label":"Approved draft","meaning":"The application has a review-approved portable artifact ready for a separately selected and entitled rule-publication contract.","recovery":"Approval does not claim that a Mappls geofence rule exists; publication records belong to the chosen adapter lifecycle.","terminal":true},{"id":"cancelled","label":"Cancelled","meaning":"The author ended editing without approving a new geometry revision and the UI lifecycle is fully disposed.","recovery":"A new edit command may start from the last committed host draft, not transient handles or callbacks.","terminal":true}],"transitions":[{"command":"create_geofence_draft","actor":"Host application","from":[],"to":"draft","event":"geofence_draft.created","idempotency":"One external rule intent maps to one draft aggregate across retries."},{"command":"open_editor","actor":"Operations author","from":["draft","review_pending"],"to":"editing","event":"geofence_draft.editor_opened","idempotency":"One command opens one view/delegate generation tied to the current draft revision."},{"command":"receive_geometry","actor":"MapplsGeofenceUI","from":["editing"],"to":"candidate","event":"geofence_draft.geometry_received","idempotency":"Normalize one terminal geometry result per generation and hash its canonical coordinate order."},{"command":"submit_for_review","actor":"Operations author","from":["candidate"],"to":"review_pending","event":"geofence_draft.review_requested","idempotency":"The geometry hash, purpose, scope, and policy version create at most one review case."},{"command":"approve_draft","actor":"Geofence reviewer","from":["review_pending"],"to":"approved_draft","event":"geofence_draft.approved","idempotency":"Commit reviewer, decision, exact geometry revision, audit event, and outbox atomically."},{"command":"cancel_edit","actor":"Operations author","from":["draft","editing","candidate","review_pending"],"to":"cancelled","event":"geofence_draft.cancelled","idempotency":"Repeated cancellation disposes the editor once and preserves the last committed draft revision."}],"invariants":["Editor output is an application candidate, not evidence of a published provider rule.","Only canonical validated circle or polygon geometry enters review.","Each geometry revision is immutable and linked to the editor generation that produced it.","Purpose, subject scope, schedule intent, and policy version travel with geometry review.","Publishing requires a separately documented, entitled rule contract and creates a separate provider identity mapping.","Provider views, delegates, map layers, credentials, and opaque callback objects are never persisted."],"records":[{"name":"Geofence draft","purpose":"Host-owned intent, current revision, lifecycle state, policy, and optimistic version.","keyFields":["draftId","externalId","purpose","scope","state","geometryRevision","version"]},{"name":"Geometry revision","purpose":"Immutable canonical circle or polygon independent of UI lifetime.","keyFields":["geometryId","mode","coordinates","radiusMeters","canonicalHash","sourceGeneration"]},{"name":"Review decision","purpose":"Attributable approval or rework request for an exact geometry and policy version.","keyFields":["reviewId","geometryId","reviewer","decision","reason","decidedAt"]},{"name":"Publication boundary","purpose":"Selection record for a future provider rule adapter without inventing a rule ID.","keyFields":["draftId","adapterStatus","entitlementReference","requiredContract","selectedAt"]}],"failures":[{"trigger":"Editor returns invalid or unsafe geometry","detection":"Canonical validation finds missing points, self-intersection, invalid radius, excessive area, or policy bounds failure.","recovery":"Keep the candidate uncommitted, explain the exact constraint, and reopen a new editor generation."},{"trigger":"Callback arrives after view disposal","detection":"The delegate generation is inactive or differs from the aggregate's editor generation.","recovery":"Ignore it and clean up provider resources without changing the current draft."},{"trigger":"Two authors edit the same draft","detection":"The submitted geometry references an older aggregate or geometry revision.","recovery":"Return a conflict with the current revision and require an intentional new edit."},{"trigger":"No authoritative publication contract is available","detection":"The selected environment lacks a documented provider command, entitlement, response, or rule identity contract.","recovery":"Keep the artifact approved_draft and route contract selection to an administrator; never fabricate publication success."}],"observability":["Editor open, cancel, and result by component version and geometry mode","Validation failures by bounded reason","Geometry revision count and review turnaround","Stale generation and optimistic version conflicts","Approved drafts awaiting publication-contract selection","Publication adapter outcome only after a separate authoritative contract is configured","Audit and outbox delivery health"],"href":"/journeys/ios-geofence-draft"},{"slug":"ios-feedback-report-review","title":"iOS feedback report and review","eyebrow":"Mappls Feedback Kit · evidence before resolution","productSlug":"capture-feedback","stateModel":"hybrid","summary":"Open one feedback UI generation, normalize a bounded report candidate, commit an application submission, reconcile provider acknowledgement separately, review evidence, and close only with an attributable resolution.","aggregate":"feedback report","actors":["Contributor","Host application","Mappls Feedback Kit","Provider adapter","Operations reviewer"],"sourceGuideSlugs":["mappls-feedback-kit-ios-distribution","mappls-feedback-kit-ios-distribution-base","mappls-feedback-uikit-ios-distribution","mappls-feedback-uikit-ios-distribution-base"],"contractSlugs":[],"sampleSlug":"place-contribution-desk","states":[{"id":"draft","label":"Draft","meaning":"The host owns purpose, category intent, reporter consent, location context, and retention policy before opening provider UI.","recovery":"Restore only bounded host fields; never serialize a view controller, delegate, credential, attachment body, or opaque provider object."},{"id":"capturing","label":"Capturing","meaning":"One presented feedback generation owns UI, focus, permission prompts, callbacks, cancellation, and cleanup.","recovery":"Dismiss and dispose once; a later attempt receives a new generation and cannot accept callbacks from the old one."},{"id":"candidate","label":"Candidate","meaning":"The adapter copied allow-listed category, bounded description, normalized location identity, and attachment references into application state.","recovery":"Reject malformed, oversized, stale, unexpected, or late output without retaining an opaque payload."},{"id":"submitted","label":"Submitted","meaning":"The contributor deliberately committed one immutable application report with idempotency, expected version, audit, and outbox evidence.","recovery":"Submission proves only the application's accepted record; provider receipt and publication or resolution remain separate facts."},{"id":"provider_pending","label":"Provider pending","meaning":"A separately selected adapter has an acknowledged or unknown provider submission outcome that requires reconciliation.","recovery":"Query or reconcile using the original application and provider identity; never blind-retry with a new command key."},{"id":"review_pending","label":"Review pending","meaning":"Submission evidence and any provider acknowledgement await an attributable quality, privacy, duplication, or policy decision.","recovery":"Request rework as a new immutable attempt or reject with a bounded reason; never overwrite the submitted evidence."},{"id":"resolved","label":"Resolved","meaning":"An authorized reviewer recorded the disposition and exact supporting evidence, with provider resolution only when independently proven.","recovery":"Corrections append a linked decision revision rather than mutating the terminal record.","terminal":true},{"id":"rejected","label":"Rejected","meaning":"Review found the report invalid, duplicate, out of scope, or unsupported and preserved the reason plus evidence lineage.","recovery":"A contributor may create a linked retry with a new attempt identity.","terminal":true},{"id":"cancelled","label":"Cancelled","meaning":"The contributor ended the active attempt before application submission and every UI resource was disposed.","recovery":"Renewed intent creates a new report aggregate or explicitly linked attempt.","terminal":true}],"transitions":[{"command":"create_report","actor":"Host application","from":[],"to":"draft","event":"feedback_report.created","idempotency":"One external case and purpose maps to one draft aggregate across retries."},{"command":"open_feedback_ui","actor":"Contributor","from":["draft"],"to":"capturing","event":"feedback_report.ui_opened","idempotency":"One command creates one active presentation generation and ownership record."},{"command":"receive_candidate","actor":"Mappls Feedback Kit","from":["capturing"],"to":"candidate","event":"feedback_report.candidate_received","idempotency":"Accept one terminal allow-listed result for the active generation and normalized content hash."},{"command":"commit_submission","actor":"Contributor","from":["candidate"],"to":"submitted","event":"feedback_report.submitted","idempotency":"Commit report, processed command, audit event, and outbox atomically under expected version."},{"command":"request_provider_submission","actor":"Provider adapter","from":["submitted"],"to":"provider_pending","event":"feedback_report.provider_requested","idempotency":"Persist application command and provider request identities before attempting the separately approved contract."},{"command":"queue_review","actor":"Host application","from":["submitted","provider_pending"],"to":"review_pending","event":"feedback_report.review_queued","idempotency":"One immutable submission revision creates at most one active review case."},{"command":"resolve_report","actor":"Operations reviewer","from":["review_pending"],"to":"resolved","event":"feedback_report.resolved","idempotency":"Bind actor, disposition, exact evidence revision, audit, and notification outbox in one commit."},{"command":"reject_report","actor":"Operations reviewer","from":["review_pending"],"to":"rejected","event":"feedback_report.rejected","idempotency":"One reviewer decision applies once to one immutable report revision."},{"command":"cancel_report","actor":"Contributor","from":["draft","capturing","candidate"],"to":"cancelled","event":"feedback_report.cancelled","idempotency":"Repeated cancellation returns the terminal result while cleanup remains exactly-once-in-effect."}],"invariants":["A UI callback creates only a candidate; it cannot prove application submission, provider receipt, publication, or resolution.","One presentation generation produces at most one accepted terminal result and all late callbacks are ignored.","Every submission revision is immutable and content-hashed; rework creates a new linked attempt.","Provider acknowledgement and reviewer disposition are separate attributable records.","Credentials, view controllers, delegates, attachment bodies, and opaque provider payloads never enter durable state.","Idempotency, optimistic concurrency, audit, outbox, privacy purpose, retention, and redaction apply to every committed transition."],"records":[{"name":"Feedback report","purpose":"Host-owned intent, lifecycle state, current immutable submission, and optimistic version.","keyFields":["reportId","externalId","purpose","state","submissionRevision","version"]},{"name":"Submission revision","purpose":"Allow-listed category, description, normalized location, consent, attachment references, and content identity.","keyFields":["submissionId","reportId","contentHash","locationIdentity","consentVersion","submittedAt"]},{"name":"Provider attempt","purpose":"Separately selected contract request, acknowledgement, unknown outcome, and reconciliation evidence.","keyFields":["attemptId","submissionId","providerRequestId","status","receiptReference","lastCheckedAt"]},{"name":"Review decision","purpose":"Attributable disposition against one exact submission and provider-evidence revision.","keyFields":["reviewId","submissionId","reviewer","decision","reason","decidedAt"]}],"failures":[{"trigger":"UI is denied, blocked, dismissed, or times out","detection":"The active generation ends without a valid allow-listed candidate.","recovery":"Dispose, restore focus, retain the draft, record a safe reason, and offer a purpose-appropriate manual fallback."},{"trigger":"A callback arrives after replacement or disposal","detection":"Its presentation generation differs from the report's active generation.","recovery":"Ignore it, release its resources, and keep current report state unchanged."},{"trigger":"Provider submission response is lost","detection":"The application has a durable request identity but no authoritative acknowledgement.","recovery":"Remain provider pending and reconcile under the same identity before any retry."},{"trigger":"Review rejects or requests corrected evidence","detection":"Policy, privacy, duplication, location, or content validation fails for the immutable revision.","recovery":"Preserve the decision and original revision; create a new linked attempt rather than editing history."}],"observability":["UI open, activation, cancellation, candidate, and terminal outcome by released component version","Schema, size, stale-generation, duplicate, and late-callback rejection","Draft-to-candidate and candidate-to-submit conversion","Provider pending age, acknowledgement, unknown outcome, and reconciliation","Review queue age, disposition, rework, and duplicate rate","Idempotency replay, version conflict, audit, and outbox health","Privacy retention and redaction completion without attachment-body logging"],"href":"/journeys/ios-feedback-report-review"},{"slug":"location-capture-evidence","title":"Consent-bound location capture evidence","eyebrow":"Location Capture SDK · application-owned evidence","productSlug":"capture-feedback","stateModel":"hybrid","summary":"Initialize and configure an entitled Location Capture SDK, acquire a bounded single or subscribed fix, preserve accuracy and timing as evidence, review weak results, and stop every native resource deterministically.","aggregate":"location capture attempt","actors":["Application user","Host application","Platform adapter","Evidence reviewer","Mappls Location Capture SDK"],"sourceGuideSlugs":["mappls-location-capture-android-sdk","mappls-location-capture-ios-sdk","mappls-location-capture-sdk-ios-distribution"],"contractSlugs":[],"sampleSlug":"address-verifier","states":[{"id":"draft","label":"Draft","meaning":"The host owns a business purpose, subject or case identity, capture policy, and retention class before requesting device access.","recovery":"Restore only host-owned intent; never persist a location manager, callback, permission prompt, or opaque SDK object."},{"id":"permission_pending","label":"Permission pending","meaning":"The user is deciding the minimum native permission for the declared purpose and visible capture behavior.","recovery":"Represent denial, restriction, and interruption separately; offer a purpose-appropriate manual path without repeatedly prompting."},{"id":"ready","label":"Ready","meaning":"SDK initialization, entitlement, permission, policy validation, and one launch generation have succeeded.","recovery":"If configuration changes or the app backgrounds, invalidate the generation before starting another acquisition."},{"id":"acquiring","label":"Acquiring","meaning":"Exactly one single-shot request or bounded subscription owns timeout, accuracy, distance, packet-size, callback, and cleanup responsibility.","recovery":"Stop the active request once on timeout, cancellation, owner disposal, or replacement; late callbacks cannot mutate the aggregate."},{"id":"candidate","label":"Candidate","meaning":"A returned event has normalized coordinates, horizontal accuracy, event time, receipt time, policy result, and source generation, but is not yet accepted evidence.","recovery":"Reject malformed, stale, impossible, duplicated, or superseded events and retain a safe reason without an opaque payload."},{"id":"review_pending","label":"Review pending","meaning":"The candidate is usable only with human review because accuracy, freshness, or policy confidence is below the automatic threshold.","recovery":"A reviewer may accept with an attributable reason, request a new immutable attempt, or choose an approved alternate evidence source."},{"id":"accepted","label":"Accepted","meaning":"An actor accepted one immutable normalized fix for the declared purpose and policy version, with an audit event and retention deadline.","recovery":"Corrections create a linked evidence revision or new attempt rather than changing the accepted observation.","terminal":true},{"id":"cancelled","label":"Cancelled","meaning":"The user or host ended the attempt and every active SDK resource was stopped or unsubscribed.","recovery":"Renewed intent creates a new attempt and permission decision where required; do not revive an old callback generation.","terminal":true}],"transitions":[{"command":"create_attempt","actor":"Host application","from":[],"to":"draft","event":"location_capture.attempt_created","idempotency":"Map one external case and capture-purpose identity to one attempt across retries."},{"command":"request_permission","actor":"Application user","from":["draft"],"to":"permission_pending","event":"location_capture.permission_requested","idempotency":"Record one visible request per policy decision and current native authorization state."},{"command":"prepare_sdk","actor":"Platform adapter","from":["permission_pending"],"to":"ready","event":"location_capture.sdk_ready","idempotency":"Bind initialization and validated configuration to one launch generation without persisting credentials or SDK instances."},{"command":"start_acquisition","actor":"Application user","from":["ready","review_pending"],"to":"acquiring","event":"location_capture.acquisition_started","idempotency":"A command key starts at most one single-shot request or subscription generation."},{"command":"receive_location","actor":"Platform adapter","from":["acquiring"],"to":"candidate","event":"location_capture.candidate_received","idempotency":"Normalize and hash one qualifying terminal event per single-shot generation, or deduplicate subscribed events by bounded source identity."},{"command":"queue_review","actor":"Host application","from":["candidate"],"to":"review_pending","event":"location_capture.review_queued","idempotency":"The evidence hash and policy version create at most one review case."},{"command":"accept_evidence","actor":"Application user","from":["candidate"],"to":"accepted","event":"location_capture.evidence_accepted","idempotency":"Commit evidence, policy result, processed command, audit event, and outbox record atomically."},{"command":"approve_weak_evidence","actor":"Evidence reviewer","from":["review_pending"],"to":"accepted","event":"location_capture.weak_evidence_approved","idempotency":"Bind the reviewer identity and bounded justification to the immutable candidate hash."},{"command":"cancel_attempt","actor":"Application user","from":["draft","permission_pending","ready","acquiring","candidate","review_pending"],"to":"cancelled","event":"location_capture.attempt_cancelled","idempotency":"Repeated cancellation returns the terminal record while stop and unsubscribe cleanup remain exactly-once-in-effect."}],"invariants":["A permission grant is not consent for every purpose; purpose, policy, and retention are recorded separately.","One acquisition generation owns one callback family, timeout, stop, and unsubscribe lifecycle.","Accuracy, event time, receipt time, and policy result remain attached to the normalized coordinates.","A callback creates a candidate, never an accepted business decision.","Weak or stale evidence cannot pass an automatic acceptance threshold by omitting quality fields.","Credentials, native manager instances, full opaque payloads, and callback closures never enter durable storage."],"records":[{"name":"Capture attempt","purpose":"Current host-owned purpose, policy, lifecycle state, generation, and optimistic version.","keyFields":["attemptId","externalId","purpose","policyVersion","state","generation","version"]},{"name":"Normalized location evidence","purpose":"Immutable accuracy-bearing observation independent of the SDK object's lifetime.","keyFields":["evidenceId","latitude","longitude","horizontalAccuracy","eventTime","receivedTime","sourceGeneration","contentHash"]},{"name":"Review decision","purpose":"Attributable disposition of evidence that cannot be accepted automatically.","keyFields":["reviewId","evidenceId","reviewer","decision","reason","decidedAt"]},{"name":"Audit and outbox","purpose":"Append-only transitions and exactly-once-in-effect downstream notification.","keyFields":["eventId","aggregateVersion","actor","idempotencyKey","outboxStatus"]}],"failures":[{"trigger":"Permission is denied or restricted","detection":"The native authorization result cannot satisfy the declared capture mode.","recovery":"Explain the affected outcome, offer settings or a manual fallback where appropriate, and keep the attempt non-acquiring."},{"trigger":"Initialization or entitlement fails","detection":"The documented initialize operation returns failure before the generation becomes ready.","recovery":"Expose a safe configuration or entitlement error, retain no credential value, and require a deliberate retry after correction."},{"trigger":"Acquisition times out or misses the accuracy budget","detection":"The configured deadline expires or every event remains outside policy.","recovery":"Stop or unsubscribe once, preserve the quality reason, and route to review, retry, or fallback rather than fabricating a precise fix."},{"trigger":"A callback arrives after cancellation or screen disposal","detection":"The owner is inactive or callback generation differs from the current attempt generation.","recovery":"Ignore the event, perform idempotent cleanup, and do not change the terminal or newer attempt."},{"trigger":"The app restarts during review","detection":"The immutable candidate exists but the review command lacks acknowledgement.","recovery":"Reload the attempt and replay the same command key; never reacquire or duplicate evidence merely to recover workflow state."}],"observability":["Initialization and configuration outcomes by SDK platform and released version","Permission denied, restricted, and settings-return rate","Time to first event and time to policy-acceptable event","Accuracy and freshness distributions without high-cardinality coordinate labels","Single-shot, subscription, timeout, stop, unsubscribe, and late-callback counts","Automatic acceptance, review, retry, fallback, and cancellation rate","Idempotency replay and optimistic version conflict rate","Outbox backlog, retry, and dead-letter age"],"href":"/journeys/location-capture-evidence"},{"slug":"place-contribution-publication","title":"Governed place contribution and publication","eyebrow":"App Widgets · contribution reconciliation","productSlug":"capture-feedback","stateModel":"stateful","summary":"Embed the credential-free Add a Place surface, record what the user reports, reconcile independently, and call a place published only when durable provider-backed evidence exists.","aggregate":"place contribution","actors":["Contributor","Host application","Operations reviewer","Mappls hosted widget and search"],"sourceGuideSlugs":["mappls-app-widgets","mappls-rest-apis"],"contractSlugs":["core-location-get-api-places-search-json-autosuggest-api","core-location-get-apis-o2o-entity-eloc-place-detail-api"],"sampleSlug":"place-contribution-desk","states":[{"id":"draft","label":"Draft","meaning":"The host owns a bounded contribution intent, business purpose, and external identity before any provider surface opens.","recovery":"Restore only host-owned fields and version; never persist the iframe DOM, browser session, or undocumented provider payload."},{"id":"widget_open","label":"Widget open","meaning":"The Mappls-hosted form is visible for one recorded attempt, while provider UI and submission remain outside the host contract.","recovery":"Let the contributor reopen or abandon the attempt; never infer success from frame navigation or inaccessible DOM state."},{"id":"submission_reported","label":"Submission reported","meaning":"The contributor says the hosted form showed success, which is useful testimony but not a receipt or publication result.","recovery":"Preserve actor, attempt, and report time, then queue an independent reconciliation check."},{"id":"publication_pending","label":"Publication pending","meaning":"An operations process is checking supported Mappls search or an approved provider receipt for a stable published identity.","recovery":"Retry under a bounded schedule and keep the case visibly pending when no result exists; do not manufacture a Mappls Pin."},{"id":"published","label":"Published","meaning":"A supported provider surface returned a six-character Mappls Pin with attributable observation evidence.","recovery":"Treat publication evidence as immutable; later corrections create a linked case or evidence revision.","terminal":true},{"id":"rejected","label":"Rejected","meaning":"A reviewer found a duplicate, invalid, unsafe, or otherwise non-publishable contribution and recorded why.","recovery":"Retain the failed attempt and allow an explicit retry that opens a new attempt rather than rewriting history."},{"id":"withdrawn","label":"Withdrawn","meaning":"The host stopped its own follow-up workflow at the contributor's request without claiming that the provider submission was deleted.","recovery":"Treat withdrawal as terminal application state; use a separately documented provider channel for any provider-side request.","terminal":true}],"transitions":[{"command":"create_contribution","actor":"Host application","from":[],"to":"draft","event":"place_contribution.created","idempotency":"Map one bounded external case identity to one aggregate across network retries."},{"command":"open_widget","actor":"Contributor","from":["draft"],"to":"widget_open","event":"place_contribution.widget_opened","idempotency":"Create at most one immutable attempt per command key and aggregate version."},{"command":"report_submission","actor":"Contributor","from":["widget_open"],"to":"submission_reported","event":"place_contribution.submission_reported","idempotency":"Record one acknowledgement for the active attempt without inventing a provider receipt."},{"command":"queue_reconciliation","actor":"Host application","from":["submission_reported"],"to":"publication_pending","event":"place_contribution.reconciliation_queued","idempotency":"The same scheduling key creates at most one pending transition and outbox event."},{"command":"confirm_publication","actor":"Operations reviewer","from":["submission_reported","publication_pending"],"to":"published","event":"place_contribution.published","idempotency":"Hash the supported evidence source, Mappls Pin, observation time, and source fingerprint before committing."},{"command":"reject","actor":"Operations reviewer","from":["submission_reported","publication_pending"],"to":"rejected","event":"place_contribution.rejected","idempotency":"Preserve the review decision, reason, and attempt version under the reviewer command key."},{"command":"retry","actor":"Contributor","from":["rejected"],"to":"widget_open","event":"place_contribution.retried","idempotency":"Create a new immutable attempt once while retaining the rejected attempt and decision in audit history."},{"command":"withdraw","actor":"Contributor","from":["draft","widget_open","submission_reported","publication_pending"],"to":"withdrawn","event":"place_contribution.withdrawn","idempotency":"Stop host follow-up once without representing this as provider-side deletion."}],"invariants":["A hosted success screen or contributor report never proves publication.","No callback, browser message, receipt, moderation status, or withdrawal capability is invented when the public source does not document it.","Only provider-backed evidence containing a valid Mappls Pin can close the aggregate as published.","Every widget attempt is immutable and linked to the aggregate version that opened it.","Commands are idempotent, compare expected version, and commit audit plus outbox atomically.","Contribution text, actor identity, and precise location follow declared purpose, access, and retention boundaries."],"records":[{"name":"Contribution aggregate","purpose":"Current host-owned state, business identity, purpose, ownership, and optimistic version.","keyFields":["contributionId","externalId","state","version","purpose","owner"]},{"name":"Widget attempt","purpose":"Immutable record of each frame launch and contributor-reported outcome without provider-internal data.","keyFields":["attemptId","aggregateVersion","openedAt","reportedAt","documentedSourceUrl"]},{"name":"Publication evidence","purpose":"Attributable supported-source proof that a stable Mappls identity is observable.","keyFields":["mapplsPin","evidenceSource","observedAt","sourceFingerprint","reviewer"]},{"name":"Audit and outbox","purpose":"Append-only transitions and exactly-once-in-effect downstream notifications.","keyFields":["eventId","aggregateVersion","actor","idempotencyKey","outboxStatus"]}],"failures":[{"trigger":"Hosted frame is blocked or unavailable","detection":"The host cannot load the established HTTPS source within its timeout and CSP boundary.","recovery":"Keep the contribution in draft, explain the boundary, and offer an external open or later retry without claiming a submission."},{"trigger":"User loses the success acknowledgement","detection":"No provider receipt exists and the contributor cannot confirm what the hosted surface showed.","recovery":"Leave the attempt unresolved and allow a deliberate new attempt; never infer completion from iframe navigation."},{"trigger":"Reconciliation finds an existing duplicate","detection":"Supported search resolves the same place identity or a reviewer establishes duplicate ownership.","recovery":"Reject with duplicate reason and link the known Mappls Pin as context, not as evidence that this attempt created it."},{"trigger":"No public result appears within the operating window","detection":"Every bounded supported-source check returns no qualifying Mappls identity before the stated review deadline.","recovery":"Keep pending or reject according to published host policy and expose the last check time without promising a provider SLA."},{"trigger":"Application restarts during review","detection":"An in-flight command lacks acknowledgement while aggregate, command key, and outbox state are durable.","recovery":"Reload the aggregate and replay the same command key; do not duplicate an attempt, decision, or notification."}],"observability":["Widget opens, contributor reports, and abandonment by attempt","Time from report to first reconciliation and terminal decision","Pending age and last supported-source check","Publication evidence source and Mappls Pin validity","Duplicate and rejection reasons without opaque provider payloads","Withdrawal count explicitly separated from provider-side deletion","Idempotency replay and optimistic version conflict rate","Outbox backlog, retry, and dead-letter age"],"href":"/journeys/place-contribution-publication"},{"slug":"realview-remote-inspection","title":"Entitled RealView remote inspection","eyebrow":"RealView · human observation and review","productSlug":"app-widgets-deep-links","stateModel":"stateful","summary":"Qualify paid RealView entitlement, open one browser-visible-token viewer attempt, handle the documented no-imagery signal safely, and turn human observations into a reviewed business record without inventing panorama metadata.","aggregate":"remote visual inspection","actors":["Inspector","Inspection reviewer","Platform administrator","Host application","Mappls RealView widget"],"sourceGuideSlugs":["mappls-app-widgets","mappls-web-maps-js"],"contractSlugs":[],"sampleSlug":"realview-inspection-desk","states":[{"id":"draft","label":"Draft","meaning":"The host owns an inspection purpose, external asset/site identity, Mappls Pin or coordinate, classification, and policy version.","recovery":"Restore only host-owned data; never persist a token, complete iframe URL, provider DOM, controller, or opaque imagery payload."},{"id":"entitlement_pending","label":"Entitlement pending","meaning":"Paid product access, exact host generation, browser credential class, restrictions, expiry, quota, and permitted use are being approved.","recovery":"Keep the case pending until an administrator records a current entitlement reference; do not substitute another Mappls credential."},{"id":"ready","label":"Ready","meaning":"The approved entitlement reference and bounded viewer configuration are current enough to open an attempt.","recovery":"If the entitlement expires or configuration changes, invalidate readiness before a browser-visible token is requested."},{"id":"viewing","label":"Viewing","meaning":"One browser lifecycle owns the iframe, exact origin, location/radius configuration, ephemeral token-handle reference, listener, timeout, and disposal.","recovery":"Dispose exactly once and ignore every message from a superseded attempt; return to entitlement pending on token expiry."},{"id":"coverage_unavailable","label":"Coverage unavailable","meaning":"The exact Auth2 origin emitted the documented schema-valid status 204 for this attempt and configuration.","recovery":"Adjust only a justified location/radius or choose field evidence; never generalize one 204 into permanent area-wide absence."},{"id":"observation_recorded","label":"Observation recorded","meaning":"An inspector saved a bounded human checklist and notes linked to the viewer attempt, without claiming provider metadata or copying imagery.","recovery":"Corrections create a linked observation revision; the source attempt and original observation remain immutable."},{"id":"review_pending","label":"Review pending","meaning":"An immutable observation set awaits a separately authorized reviewer under the declared purpose and policy.","recovery":"Reassign review explicitly and keep its SLA independent from provider availability."},{"id":"accepted","label":"Accepted","meaning":"A named reviewer accepted the observation set for the exact business decision and policy version.","recovery":"Later evidence creates a new inspection or linked revision rather than rewriting acceptance.","terminal":true},{"id":"rework_required","label":"Rework required","meaning":"Review retained the prior observation and reason while requiring a new viewer attempt or alternate field evidence.","recovery":"Open a new immutable attempt after requalifying entitlement and configuration."},{"id":"cancelled","label":"Cancelled","meaning":"An authorized actor ended the inspection with a bounded reason while preserving prior attempts and observations.","recovery":"Renewed business intent creates a new linked inspection.","terminal":true}],"transitions":[{"command":"create_inspection","actor":"Host application","from":[],"to":"draft","event":"realview_inspection.created","idempotency":"One external inspection identity maps to one aggregate across retries."},{"command":"request_entitlement","actor":"Inspector","from":["draft"],"to":"entitlement_pending","event":"realview_inspection.entitlement_requested","idempotency":"The product, environment, and account request identity is stable and contains no credential value."},{"command":"confirm_entitlement","actor":"Platform administrator","from":["entitlement_pending"],"to":"ready","event":"realview_inspection.entitlement_confirmed","idempotency":"Commit only entitlement reference, exact host, restrictions, and expiry metadata—not the issued token."},{"command":"open_viewer","actor":"Inspector","from":["ready","coverage_unavailable","rework_required"],"to":"viewing","event":"realview_inspection.viewer_opened","idempotency":"One command creates one immutable attempt and one ephemeral token-handle reference."},{"command":"record_no_coverage","actor":"Host application","from":["viewing"],"to":"coverage_unavailable","event":"realview_inspection.coverage_unavailable","idempotency":"Accept one exact-origin, one-field status 204 result for the active attempt only."},{"command":"record_observation","actor":"Inspector","from":["viewing"],"to":"observation_recorded","event":"realview_inspection.observation_recorded","idempotency":"Hash the bounded checklist, notes, attempt, actor, and observation time."},{"command":"submit_review","actor":"Inspector","from":["observation_recorded"],"to":"review_pending","event":"realview_inspection.review_requested","idempotency":"Freeze one observation set and enqueue review atomically."},{"command":"accept","actor":"Inspection reviewer","from":["review_pending"],"to":"accepted","event":"realview_inspection.accepted","idempotency":"Bind reviewer, reason, policy version, observation IDs, and command identity."},{"command":"request_rework","actor":"Inspection reviewer","from":["review_pending"],"to":"rework_required","event":"realview_inspection.rework_requested","idempotency":"Retain the reviewed evidence and create one attributable rework decision."},{"command":"record_entitlement_expired","actor":"Host application","from":["ready","viewing"],"to":"entitlement_pending","event":"realview_inspection.entitlement_expired","idempotency":"Invalidate the active attempt once and discard only its ephemeral token handle."},{"command":"cancel","actor":"Inspector","from":["draft","entitlement_pending","ready","viewing","coverage_unavailable","observation_recorded","review_pending","rework_required"],"to":"cancelled","event":"realview_inspection.cancelled","idempotency":"Commit actor, reason, cleanup, audit, and outbox exactly once."}],"invariants":["No server secret, browser token value, or complete token-bearing iframe URL is persisted, logged, analyzed, exported, or sent to a model.","The exact selected origin and narrow documented schema are checked before any browser message reaches domain state.","Status 204 proves only no imagery for one attempt and configuration; HTTP 200 and frame load prove only a delivered shell.","Human observation is distinct from provider imagery, panorama metadata, measurement, currentness, and inspection acceptance.","Imagery is not copied, screenshotted, exported, or retained without an explicit licensed product contract and purpose-specific policy.","Every command is idempotent, compares expected version, and commits snapshot, audit, receipt, and outbox atomically.","Reviewer acceptance is attributable and cannot be performed by the same automated actor that created the observation."],"records":[{"name":"Inspection aggregate","purpose":"Current purpose, asset/site and location identity, ownership, policy, state, and optimistic version.","keyFields":["inspectionId","externalId","assetId","mapplsPinOrCoordinate","purpose","state","version"]},{"name":"Entitlement reference","purpose":"Non-secret proof of the approved product generation and credential policy.","keyFields":["entitlementRef","product","host","environment","credentialClass","expiresAt","restrictionFingerprint"]},{"name":"Viewer attempt","purpose":"Immutable browser lifecycle and documented no-imagery outcome.","keyFields":["attemptId","configFingerprint","tokenHandleRef","openedAt","disposedAt","coverageStatus"]},{"name":"Observation and review","purpose":"Human-authored evidence and separately authorized decision without copied imagery.","keyFields":["observationId","attemptId","checklist","notes","observedAt","reviewer","decision","policyVersion"]},{"name":"Audit and outbox","purpose":"Append-only transitions and exactly-once-in-effect downstream delivery.","keyFields":["eventId","aggregateVersion","actor","idempotencyKey","outboxStatus"]}],"failures":[{"trigger":"Iframe returns a shell but no usable imagery","detection":"HTTP/frame load occurred without entitled viewing or the documented 204 signal.","recovery":"Keep viewing unresolved until a bounded timeout, then record a host technical outcome rather than coverage or completion."},{"trigger":"Message uses a lookalike origin or malformed payload","detection":"Exact origin, object shape, field count, or integer status validation fails.","recovery":"Reject before domain processing, retain only a safe rejection metric, and never store the opaque payload."},{"trigger":"Entitlement expires during viewing","detection":"The entitlement reference is expired/revoked or the account-approved broker reports token expiry.","recovery":"Dispose the viewer, remove the ephemeral handle, return to entitlement pending, and retain the incomplete attempt."},{"trigger":"Imagery is unavailable for the selected radius","detection":"The active attempt receives the documented exact-origin status 204 message.","recovery":"Record configuration-specific no coverage and offer justified radius/location retry or alternate field evidence."},{"trigger":"Reviewer cannot rely on the observation","detection":"Checklist is incomplete, limitations are missing, purpose changed, or stronger field evidence is required.","recovery":"Request rework without overwriting the observation or prior viewer attempt."},{"trigger":"Application restarts after an unknown command outcome","detection":"Client lacks acknowledgement while aggregate, command key, and outbox state are durable.","recovery":"Reload and replay the same command key; never create another attempt or review decision to recover transport uncertainty."}],"observability":["Entitlement request age, confirmation, expiry, revocation, and renewal without token values","Viewer open, time-to-first-useful-state, timeout, disposal, and superseded-attempt count","Exact-origin/schema rejection counts without raw payload retention","Status 204 rate by bounded configuration fingerprint, not generalized geography","Observation completeness, limitation flags, and review duration","Rework reason and new-attempt conversion","Credential-bearing URL log/screenshot/model-context prevention checks","Idempotency replay, optimistic conflict, audit, outbox backlog, retry, and dead-letter age"],"href":"/journeys/realview-remote-inspection"},{"slug":"vision-inference-review","title":"Governed SkyDNN inference review","eyebrow":"SkyDNN AI · synchronous inference, durable evidence","productSlug":"ai-location","stateModel":"stateful","summary":"Lock an entitled model to an immutable asset identity, call the documented synchronous prediction boundary, validate geometry and confidence, require independent review, and redact derived detections on schedule.","aggregate":"vision evidence case","actors":["Asset steward","Vision worker","Policy service","Independent reviewer","Privacy worker","Mappls SkyDNN API"],"sourceGuideSlugs":["skydnn-aiapi-docs"],"contractSlugs":["skydnn-ai-get-server-whoami-returns-the-current-models-in-port","skydnn-ai-get-models-api-model-key-returns-the-details-of-provided-model","skydnn-ai-post-predict-returns-the-prediction-as-response-in-form-of-json"],"sampleSlug":"vision-evidence-desk","states":[{"id":"registered","label":"Registered","meaning":"The application owns a purpose-bound case with opaque asset identity, SHA-256 content hash, media facts, capture time, location context, lawful-basis reference, and retention deadline.","recovery":"Reject raw media, URLs, credentials, sensitive labels, or incomplete authority before a provider call is possible."},{"id":"model_locked","label":"Model locked","meaning":"An entitled server-discovery result and one exact API model key, fingerprint, class vocabulary, and policy version are frozen for the case.","recovery":"Model drift creates a new lock and inference attempt; never reinterpret an old response under current metadata."},{"id":"inference_requested","label":"Inference requested","meaning":"One worker owns an idempotent synchronous provider-call attempt against the exact asset and model identities.","recovery":"An ambiguous transport outcome remains unresolved until reconciled or deliberately retried as a linked attempt."},{"id":"inferred","label":"Inferred","meaning":"A schema-valid provider response has normalized labels, confidence, bounded geometry, timing, provenance, and response hash without becoming a business decision.","recovery":"Malformed or unsafe output fails closed and retains only a safe error class plus hashes."},{"id":"review_pending","label":"Review pending","meaning":"Versioned policy places the immutable result in an uncertainty, sensitive-class, or mandatory-sampling review lane.","recovery":"Reassign under SLA without altering the model output, thresholds, or reason codes."},{"id":"accepted","label":"Accepted","meaning":"An independent reviewer accepted the derived evidence for the declared purpose and exact policy/model/output versions.","recovery":"Corrections create a linked revision or new case rather than rewriting inference or decision evidence.","terminal":true},{"id":"rejected","label":"Rejected","meaning":"An independent reviewer rejected the result with an attributable reason while retaining the immutable provider evidence.","recovery":"A new capture or model produces a linked case or attempt; rejection is never overwritten.","terminal":true},{"id":"redacted","label":"Redacted","meaning":"Derived labels and geometry were removed at the retention deadline while the minimum decision, hashes, policy, and audit record remain.","recovery":"Redaction is irreversible in the application store; a renewed purpose requires new source evidence.","terminal":true}],"transitions":[{"command":"register_case","actor":"Asset steward","from":[],"to":"registered","event":"vision.case_registered","idempotency":"One external reference and asset hash map to one case across retries."},{"command":"lock_model","actor":"Vision worker","from":["registered"],"to":"model_locked","event":"vision.model_locked","idempotency":"Server reference, model key, metadata fingerprint, and policy version identify one lock."},{"command":"request_inference","actor":"Vision worker","from":["model_locked"],"to":"inference_requested","event":"vision.inference_requested","idempotency":"One attempt identity binds the case version, asset hash, model fingerprint, and request policy."},{"command":"record_inference","actor":"Vision worker","from":["inference_requested"],"to":"inferred","event":"vision.inference_recorded","idempotency":"Provider status and response hash close one active attempt exactly once."},{"command":"submit_review","actor":"Policy service","from":["inferred"],"to":"review_pending","event":"vision.review_requested","idempotency":"Thresholds, reason codes, policy version, and attempt identity create one immutable review request."},{"command":"accept","actor":"Independent reviewer","from":["review_pending"],"to":"accepted","event":"vision.accepted","idempotency":"Reviewer, reason, policy, attempt, and expected aggregate version identify the terminal decision."},{"command":"reject","actor":"Independent reviewer","from":["review_pending"],"to":"rejected","event":"vision.rejected","idempotency":"Reviewer, reason, policy, attempt, and expected aggregate version identify the terminal decision."},{"command":"redact","actor":"Privacy worker","from":["inferred","review_pending","accepted","rejected"],"to":"redacted","event":"vision.redacted","idempotency":"One retention action removes derived detail while preserving the minimum integrity and audit record."}],"invariants":["No image bytes, media URL, bearer token, credential, face, number plate, or provider-internal file path enters the reference case store.","The provider POST /predict call is synchronous; application queue, review, retry, decision, and retention states are never attributed to SkyDNN.","Every attempt binds an immutable asset hash to one discovered model fingerprint and policy version.","Confidence and geometry are evidence, not a business outcome or live safety command.","Reviewer identity is independent from the fixture inference actor and every override or rejection has a reason.","Idempotency, optimistic versions, audit, receipts, and outbox commit atomically."],"records":[{"name":"Vision case","purpose":"Business purpose, external identity, lifecycle, policy, retention, and optimistic version.","keyFields":["caseId","externalId","purpose","state","version","policyVersion","retentionUntil"]},{"name":"Asset envelope","purpose":"Opaque, non-media identity and integrity facts for one captured source.","keyFields":["assetRef","sha256","mediaClass","width","height","capturedAt","lawfulBasisRef"]},{"name":"Model lock","purpose":"Exact entitled discovery evidence and immutable model selection.","keyFields":["serverRef","apiModelKey","modelFingerprint","classes","lockedAt"]},{"name":"Inference attempt","purpose":"Synchronous request lifecycle, normalized response, safe failure, timing, and provenance.","keyFields":["attemptId","assetHash","modelFingerprint","status","resultHash","regions","timings"]},{"name":"Review and retention","purpose":"Policy reasoning, attributable disposition, and derived-detail redaction evidence.","keyFields":["reviewId","reasonCodes","reviewer","decision","redactedAt"]},{"name":"Audit and outbox","purpose":"Append-only state evidence and exactly-once-in-effect downstream notification.","keyFields":["eventId","aggregateVersion","idempotencyKey","actor","outboxStatus"]}],"failures":[{"trigger":"Model discovery changes after the case is prepared","detection":"Current metadata fingerprint differs from the locked fingerprint.","recovery":"Stop, create a new model lock and attempt, and retain the original lock for comparison."},{"trigger":"Provider response is lost after a synchronous request","detection":"The active attempt has no terminal response hash and transport outcome is ambiguous.","recovery":"Reconcile with the approved provider boundary when possible or record a safe failed attempt before a deliberate linked retry."},{"trigger":"Geometry, label, or confidence is malformed","detection":"Schema, bounds, topology, vocabulary, or numeric validation fails.","recovery":"Quarantine derived detail, retain a safe error class, and do not send it to policy or review."},{"trigger":"Sensitive or uncertain inference reaches policy","detection":"A privacy class, low confidence, unsupported label, or mandatory sample rule matches.","recovery":"Require independent review and prevent automation from issuing a terminal business or safety action."},{"trigger":"Retention deadline passes while review is open","detection":"Derived output remains present after the committed policy deadline.","recovery":"Redact on schedule, close or fail the review with explicit expiry, and retain minimum audit evidence."},{"trigger":"Process restarts after a command timeout","detection":"The client lacks acknowledgement while snapshot, receipt, audit, and outbox are durable.","recovery":"Reload and replay the same idempotency key without duplicating attempts, decisions, or events."}],"observability":["Cases by state, purpose, media class, model fingerprint, and policy version","Model discovery drift, lock age, and incompatible input rate","Inference latency, safe error class, result-schema rejection, and ambiguous outcome","Confidence, label, geometry type, and review-reason distributions","Review queue age, disposition, override, disagreement, and sampling coverage","Sensitive-class access and derived-output retention/redaction deadlines","Idempotency replay, version conflict, restart recovery, audit, and outbox age"],"href":"/journeys/vision-inference-review"}],"eventCatalog":{"summary":{"contracts":138,"producerTransitions":140,"journeys":18,"providerPayloadClaims":0,"schemaVersion":"2020-12","eventVersion":1},"href":"/events","api":"/api/events","schema":"/events/schema.json"},"tutorials":[{"slug":"first-web-map","title":"Put your first Mappls map on the web","description":"Create a key, restrict it to localhost, load Web Maps JS, and add a marker.","level":"Beginner","duration":"10 min","platforms":["Web"],"products":["maps"],"outcome":"A responsive map with a styled point of interest.","scenario":"A property-search page needs one responsive map that remains usable with keyboard navigation and slow networks.","steps":[{"title":"Define the user and system contract","description":"A property-search page needs one responsive map that remains usable with keyboard navigation and slow networks. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Create a browser-owned application","description":"Create a development web application, restrict its public key to the exact localhost origin, and keep server credentials out of HTML and JavaScript."},{"title":"Mount and own the map lifecycle","description":"Load Web Maps JS once, give the container an explicit height, create the map after the DOM exists, and remove listeners when the page unmounts."},{"title":"Add one stable place","description":"Represent the point with a durable Mappls Pin or business ID, move the camera deliberately, and mirror the selected feature in accessible text outside the canvas."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when the map renders at mobile and desktop widths; keyboard users can reach the selected place; a blocked sdk produces a useful fallback. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["the map renders at mobile and desktop widths","keyboard users can reach the selected place","a blocked SDK produces a useful fallback"],"failureModes":["invalid or origin-restricted key","SDK load timeout","zero-size or detached container"]},{"slug":"address-autocomplete","title":"Build address autocomplete that users trust","description":"Debounce input, apply bias, handle keyboard selection, and retain the Mappls Pin.","level":"Beginner","duration":"20 min","platforms":["Web","REST"],"products":["search-places"],"outcome":"An accessible, resilient delivery-address field.","scenario":"A checkout address field must reduce typing without replacing the customer's intent or losing the selected place identity.","steps":[{"title":"Define the user and system contract","description":"A checkout address field must reduce typing without replacing the customer's intent or losing the selected place identity. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Separate text from selection","description":"Keep the free-form query distinct from the accepted suggestion. Invalidate the selected Mappls Pin whenever the user edits the text after selection."},{"title":"Bound the request stream","description":"Wait for a meaningful query, debounce input, cancel superseded requests, bias only with consented coarse context, and render a deterministic empty state."},{"title":"Commit an accessible selection","description":"Support arrows, enter, escape, focus return, and screen-reader announcements. Persist the display label and Mappls Pin, then validate serviceability on the server."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when stale responses never replace newer results; keyboard and pointer selection are equivalent; the submitted address includes a stable provider identity. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["stale responses never replace newer results","keyboard and pointer selection are equivalent","the submitted address includes a stable provider identity"],"failureModes":["out-of-order response","no suggestions or ambiguous address","quota or authentication denial"]},{"slug":"android-map","title":"Add Mappls to an Android app","description":"Configure the repository and BoM, initialize the SDK, and manage MapView lifecycle.","level":"Beginner","duration":"25 min","platforms":["Android"],"products":["maps"],"outcome":"A native Kotlin map screen with lifecycle-safe setup.","scenario":"A Kotlin application needs a native map screen that survives rotation, backgrounding, process recreation, and permission denial.","steps":[{"title":"Define the user and system contract","description":"A Kotlin application needs a native map screen that survives rotation, backgrounding, process recreation, and permission denial. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Configure the native boundary","description":"Use the documented repository and BoM, inject platform credentials through build configuration, and keep the release key restricted to the approved package and signing identity."},{"title":"Mirror Android lifecycle","description":"Forward creation, start, resume, pause, stop, low-memory, save-state, and destroy events to the map view exactly once."},{"title":"Own location permission separately","description":"Render the map without location access, request permission only when the user asks for location, and distinguish denied, approximate, unavailable, and stale fixes."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when rotation preserves intended camera state; permission denial does not blank the map; destroyed activities retain no listeners. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["rotation preserves intended camera state","permission denial does not blank the map","destroyed activities retain no listeners"],"failureModes":["dependency/version mismatch","permission revoked while active","activity recreated after process death"]},{"slug":"ios-map","title":"Add Mappls to an iOS app with Swift Package Manager","description":"Select distribution packages, configure credentials, and render the native map.","level":"Beginner","duration":"25 min","platforms":["iOS"],"products":["maps"],"outcome":"A native Swift map screen.","scenario":"A Swift application needs a native map installed through Swift Package Manager with explicit credential and view ownership.","steps":[{"title":"Define the user and system contract","description":"A Swift application needs a native map installed through Swift Package Manager with explicit credential and view ownership. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Select the supported distribution","description":"Pin an approved package version, resolve its transitive requirements, and keep credentials in build/runtime configuration rather than source control."},{"title":"Create the view on the main actor","description":"Own the map view from one view controller or SwiftUI wrapper, make constraints deterministic, and avoid duplicate initialization during view updates."},{"title":"Treat location as optional evidence","description":"Ask only when a user-visible feature needs it, retain accuracy and timestamp, and provide search or manual map movement when authorization is absent."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when cold and warm launches render once; layout changes preserve the selected feature; denied location has a complete alternate flow. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["cold and warm launches render once","layout changes preserve the selected feature","denied location has a complete alternate flow"],"failureModes":["package resolution conflict","view recreated with duplicate delegates","location authorization changes at runtime"]},{"slug":"route-preview","title":"Build a route preview with alternatives","description":"Resolve endpoints, request alternatives, decode geometry, and explain toll/time trade-offs.","level":"Intermediate","duration":"35 min","platforms":["Web","REST"],"products":["routes-navigation","maps"],"outcome":"A production-pattern route comparison view.","scenario":"A travel-planning page must compare route alternatives without presenting distance, toll, and ETA as timeless facts.","steps":[{"title":"Define the user and system contract","description":"A travel-planning page must compare route alternatives without presenting distance, toll, and ETA as timeless facts. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Resolve route endpoints once","description":"Convert user intent to stable Mappls Pins or validated coordinates before routing. Never geocode the same free-form text independently for each alternative."},{"title":"Request and normalize alternatives","description":"Choose an explicit profile, units, exclusions, and alternatives policy; retain provider route identity and request time with every decoded geometry."},{"title":"Explain the choice","description":"Draw alternatives with non-color cues, summarize distance/time/toll trade-offs, and mark the preview stale when endpoints, profile, traffic horizon, or itinerary change."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when all alternatives share identical endpoints and profile; unreachable routes produce an honest state; a stale preview cannot start navigation. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["all alternatives share identical endpoints and profile","unreachable routes produce an honest state","a stale preview cannot start navigation"],"failureModes":["one endpoint is unresolved","provider returns no route","late response targets an obsolete itinerary"]},{"slug":"nearby-discovery","title":"Create a nearby discovery experience","description":"Combine category search, viewport updates, result cards, and map selection.","level":"Intermediate","duration":"40 min","platforms":["Web"],"products":["search-places","maps"],"outcome":"A map-and-list place explorer.","scenario":"A health-services finder must keep map, result list, filters, and selected place synchronized while enforcing eligibility before distance ranking.","steps":[{"title":"Define the user and system contract","description":"A health-services finder must keep map, result list, filters, and selected place synchronized while enforcing eligibility before distance ranking. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Define the search area","description":"Use an explicit center and radius or visible viewport, cap repeated map-move searches, and show when results describe an older viewport."},{"title":"Apply eligibility before ranking","description":"Intersect category, service, opening, accessibility, and business constraints before sorting by distance or ETA."},{"title":"Preserve one selected identity","description":"Use the Mappls Pin as the shared key across marker, card, details, route preview, and deep-link hand-off; never join on display name."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when map and list expose the same eligible set; empty states explain the active constraints; selection survives reordering and viewport refresh. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["map and list expose the same eligible set","empty states explain the active constraints","selection survives reordering and viewport refresh"],"failureModes":["location unavailable","provider results outside requested radius","selected place disappears after filter change"]},{"slug":"delivery-eta","title":"Track a delivery with a trustworthy ETA","description":"Join asset telemetry, map matching, route progress, ETA refresh, and customer visibility.","level":"Advanced","duration":"90 min","platforms":["REST","Web"],"products":["intouch-telematics","routes-navigation"],"outcome":"A stateful live-delivery journey with recovery and replay.","scenario":"A customer tracking page must show a useful ETA while the operations system retains authoritative trip state and late telemetry evidence.","steps":[{"title":"Define the user and system contract","description":"A customer tracking page must show a useful ETA while the operations system retains authoritative trip state and late telemetry evidence. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Create a durable trip identity","description":"Bind order, route revision, provider trip, vehicle, and customer-safe tracking token before telemetry begins."},{"title":"Process observations by event time","description":"Deduplicate source events, store event and receipt time, reject state regression, map-match bounded fixes, and derive a new ETA revision only from eligible evidence."},{"title":"Separate customer view from control state","description":"Expose coarse progress and freshness without driver secrets or full history. Route exceptions to an owned operations queue before changing the promise."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when duplicate telemetry has one effect; late evidence remains auditable without rewinding progress; closure requires provider acknowledgement and delivery proof. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["duplicate telemetry has one effect","late evidence remains auditable without rewinding progress","closure requires provider acknowledgement and delivery proof"],"failureModes":["telemetry silence","route deviation or closed road","provider close succeeds after local timeout"]},{"slug":"workmate-task-lifecycle","title":"Automate a complete Workmate task lifecycle","description":"Provision workers, dispatch jobs, consume transitions, enforce proof, and reconcile closure.","level":"Advanced","duration":"2 hr","platforms":["REST","Android"],"products":["workmate"],"outcome":"An idempotent field-service integration.","scenario":"A utility operator must create, assign, execute, prove, review, and close work without losing responsibility during retries or offline periods.","steps":[{"title":"Define the user and system contract","description":"A utility operator must create, assign, execute, prove, review, and close work without losing responsibility during retries or offline periods. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Model task and provider identities","description":"Give the internal task, provider task, assignee, policy, and idempotency command independent durable IDs."},{"title":"Enforce explicit transitions","description":"Validate actor, current version, prerequisites, and evidence for assign, accept, travel, arrive, submit proof, approve, rework, and close."},{"title":"Reconcile asynchronous outcomes","description":"Persist an outbox command before provider calls, ingest provider callbacks idempotently, and keep ambiguous results pending until queried or replayed."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when every transition names actor and evidence; offline replay cannot duplicate work; terminal closure retains proof and provider acknowledgement. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["every transition names actor and evidence","offline replay cannot duplicate work","terminal closure retains proof and provider acknowledgement"],"failureModes":["assignee rejects or becomes unavailable","proof is incomplete or rejected","provider timeout after accepting a command"]},{"slug":"fleet-geofences","title":"Build fleet geofence operations","description":"Create zones, process enter/exit events, suppress noise, and power an exception queue.","level":"Advanced","duration":"75 min","platforms":["REST","Web"],"products":["intouch-telematics","maps"],"outcome":"An operations-ready geofence monitor.","scenario":"A fleet desk needs actionable zone exceptions without turning GPS jitter into hundreds of incidents.","steps":[{"title":"Define the user and system contract","description":"A fleet desk needs actionable zone exceptions without turning GPS jitter into hundreds of incidents. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Publish versioned geometry","description":"Validate coordinate order, closure, self-intersection, size, asset scope, schedule, and provider rule identity before activation."},{"title":"Keep raw evidence, derive cases","description":"Append every eligible enter/exit observation, order by event time, apply hysteresis and dwell policy, and suppress duplicates only in the derived exception view."},{"title":"Own resolution","description":"Assign each open case, retain acknowledgement SLA, require resolution evidence, and retire provider rules without deleting historical activity."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when boundary jitter opens at most one case; late observations cannot erase a newer state; retired rules preserve prior evidence. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["boundary jitter opens at most one case","late observations cannot erase a newer state","retired rules preserve prior evidence"],"failureModes":["invalid or oversized geometry","duplicate provider activity","rule retirement fails after local request"]},{"slug":"gis-site-selection","title":"Build a reproducible site-selection model","description":"Publish layers, generate catchments, join signals, score candidates, and share results.","level":"Advanced","duration":"2 hr","platforms":["REST","Web"],"products":["gis-analytics"],"outcome":"A governed retail expansion analysis.","scenario":"A retailer must compare candidate sites using a reproducible model that another analyst can rerun and challenge.","steps":[{"title":"Define the user and system contract","description":"A retailer must compare candidate sites using a reproducible model that another analyst can rerun and challenge. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Version every input","description":"Record immutable dataset versions, content hashes, CRS, schema, source, license, and observation date before analysis."},{"title":"Make scoring deterministic","description":"Persist catchment parameters, joined signal versions, normalization, weights, exclusions, and tie-breaking with each attempt."},{"title":"Govern sharing","description":"Publish a result revision with lineage, audience, expiry, export/embed policy, and revoke access without rewriting the decision record."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when the same inputs and parameters reproduce the score; invalid crs fails with actionable diagnostics; a shared result resolves to immutable lineage. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["the same inputs and parameters reproduce the score","invalid CRS fails with actionable diagnostics","a shared result resolves to immutable lineage"],"failureModes":["source schema or CRS drift","processing fails after partial compute","expired or revoked share is requested"]},{"slug":"offline-package-update","title":"Design an interruption-safe offline map update","description":"Verify packages, stage data, check compatibility, switch atomically, and roll back.","level":"Advanced","duration":"90 min","platforms":["Automotive","Linux"],"products":["offline-automotive"],"outcome":"A resilient embedded update state machine.","scenario":"An in-vehicle runtime must update regional map data across weak connectivity and sudden power loss without leaving an unusable active package.","steps":[{"title":"Define the user and system contract","description":"An in-vehicle runtime must update regional map data across weak connectivity and sudden power loss without leaving an unusable active package. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Validate compatibility before download","description":"Compare hardware, runtime, region, data epoch, storage, license, and signing requirements before reserving space."},{"title":"Stage without touching active data","description":"Download resumably, verify chunks and full signature, unpack into an inactive slot, and run structural and route smoke checks."},{"title":"Activate atomically","description":"Switch one durable pointer, boot-health the new package, acknowledge success, and roll back automatically when compatibility or health checks fail."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when power loss at every stage leaves one bootable package; corrupt content never becomes active; rollback retains failure evidence. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["power loss at every stage leaves one bootable package","corrupt content never becomes active","rollback retains failure evidence"],"failureModes":["insufficient storage","signature or compatibility mismatch","first boot fails after activation"]},{"slug":"mappls-mcp-agent","title":"Give an AI agent grounded Mappls tools","description":"Run the MCP server, scope credentials, call search and routing tools, and inspect provenance.","level":"Intermediate","duration":"30 min","platforms":["MCP"],"products":["ai-location","search-places","routes-navigation"],"outcome":"An agent that can reason about real places without inventing APIs.","scenario":"An assistant must research solutions and answer place or routing questions with governed Mappls tools instead of invented endpoints or unapproved live-location access.","steps":[{"title":"Define the user and system contract","description":"An assistant must research solutions and answer place or routing questions with governed Mappls tools instead of invented endpoints or unapproved live-location access. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Choose and isolate the transport","description":"Start with the downloadable Spatial Operations Agent in fixture mode. Use its local stdio client for a same-host server or authenticated Streamable HTTP client for a remote resource. Keep inbound and provider credentials independent; the client accepts an absolute stdio entrypoint or exact HTTPS MCP URL, never a shell string or credential-bearing URL."},{"title":"Prove offline research first","description":"Select solution_research and the offline profile. Negotiate advertised tools, retrieve capability and deterministic industry/platform plans without a provider credential, require explicit catalog provenance, and make unavailable live tools a visible state."},{"title":"Bind live-read authority","description":"Deploy live-read separately. Validate asymmetric signature, exact issuer and resource audience, subject, client, expiry, and profile scope. Keep provider credentials only in the MCP workload and publish protected-resource metadata without issuing tokens from the MCP service."},{"title":"Bound every result","description":"Allow-list planned tools, cap arguments, request time, transport buffers, and structured output, reject gateway-token reflection, and require valid provider provenance from live tools."},{"title":"Separate plan, approval, and execution","description":"Hash the proposed tool plan, require approval for sensitive scopes, expire approval, reject any execution whose plan or arguments changed, and close the client on shutdown."},{"title":"Ground the answer","description":"Store tool-call evidence without secrets, cite the provider or catalog result used for each claim, and surface uncertainty or unavailable tools instead of fabricating data."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when fixture, real stdio, and remote http paths preserve one client contract; offline solution research completes without provider credentials; both real transports negotiate the intended read-only profile; wrong-audience, expired, insufficient-scope, hidden-tool, oversized-output, and token-reflection paths fail closed; unapproved plans cannot execute; every location claim has tool provenance; tool and gateway errors redact credentials and response bodies. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["fixture, real stdio, and remote HTTP paths preserve one client contract","offline solution research completes without provider credentials","both real transports negotiate the intended read-only profile","wrong-audience, expired, insufficient-scope, hidden-tool, oversized-output, and token-reflection paths fail closed","unapproved plans cannot execute","every location claim has tool provenance","tool and gateway errors redact credentials and response bodies"],"failureModes":["remote client is rejected by auth, URL, host, origin, size, or capacity controls","authorization-server lifecycle or revocation is unavailable","configured profile does not advertise a planned tool","approval expires before execution","provider result lacks provenance or conflicts with prior context"]},{"slug":"a2a-solution-coordination","title":"Coordinate a complete Mappls A2A journey","description":"Validate fixture or OAuth A2A identity, select offline or purpose-bound live-read authority, delegate one exact structured task, reconcile a lost response, bind the server task identity, and review an immutable artifact.","level":"Advanced","duration":"90 min","platforms":["MCP"],"products":["ai-location","search-places","routes-navigation","intouch-telematics"],"outcome":"A restart-safe OAuth-capable host that keeps transport identity, provider-read purpose, protocol completion, human acceptance, entitlement, writes, and production approval separate.","scenario":"An application must coordinate exact offline planning or purpose-bound Mappls provider reads through A2A while retaining application-owned identity, intent, privacy purpose, recovery, review, and audit authority.","steps":[{"title":"Define the user and system contract","description":"An application must coordinate exact offline planning or purpose-bound Mappls provider reads through A2A while retaining application-owned identity, intent, privacy purpose, recovery, review, and audit authority. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Start with the maintained application","description":"Download A2A Solution Studio and run its credential-free zero-network fixture. Exercise the complete offline journey first; never accept a free-form prompt, file, URL, provider credential, OAuth token, provider write, or arbitrary skill name in the task model."},{"title":"Choose and pin the profile","description":"Fetch the well-known Agent Card under a bounded response, validate A2A v1 plus JSONRPC or HTTP+JSON, require the exact structured skill, infer offline or live-read from the advertised skills, and retain the canonical card fingerprint. Keep offline as default; require the stronger mappls:a2a:live-read resource scope for protected live reads."},{"title":"Bind live-read purpose and data class","description":"For one of the ten live commands, require the exact enumerated purpose and bounded operation fields. Record its data class and one-call authority before delegation. Keep Mappls provider credentials only in the A2A service; task payloads and the host never accept them."},{"title":"Bind transport identity without broadening skill authority","description":"Obtain a short-lived token for the exact A2A resource from an approved client store, inject it only in the Authorization header, and retain only the public scope plus a transport-authenticated boolean. Never persist or log the token, reuse a Mappls provider credential, or let a request tenant override the token-bound tenant."},{"title":"Delegate with correct identities","description":"Persist the command digest and client-owned message, context, attempt, and idempotency identities before transport. Leave task ID empty for a new A2A task, then bind the server-assigned task identity from the result."},{"title":"Reconcile an unknown outcome","description":"If the response is lost, keep the aggregate delegated. List the unique context across task states, require exactly one matching task, bind its server identity, and inspect it rather than creating a duplicate delegation."},{"title":"Validate and review the artifact","description":"Require completed state, matching context/task identity, one bounded structured artifact, the command’s exact zero-call offline or one-read live authority, no task-payload credentials or writes, and no production approval. Hash the canonical artifact and require an attributable reviewer to accept or reject that exact digest."},{"title":"Operate sensitive durable state","description":"Atomically commit snapshots, immutable events, idempotency receipts, and outbox messages; keep live provider payloads out of audit and outbox events; apply tenant authorization, encryption, minimization, expiry, and deletion before adapting the sample file store; recover reconciliation evidence after restart."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when fixture and official sdk paths preserve one host lifecycle; all three offline and ten live command contracts are explicit; agent card, profile, skill, protocol, oauth, purpose, and authority validation fail closed; missing-token, insufficient-scope, wrong-audience, and cross-tenant reads are denied; a lost response reconciles without a second task; server-assigned task identity and artifact digest survive restart; no transport token or provider payload appears in audit evidence; human acceptance never becomes entitlement, write authority, or production approval. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["fixture and official SDK paths preserve one host lifecycle","all three offline and ten live command contracts are explicit","Agent Card, profile, skill, protocol, OAuth, purpose, and authority validation fail closed","missing-token, insufficient-scope, wrong-audience, and cross-tenant reads are denied","a lost response reconciles without a second task","server-assigned task identity and artifact digest survive restart","no transport token or provider payload appears in audit evidence","human acceptance never becomes entitlement, write authority, or production approval"],"failureModes":["Agent Card changes profile, authority, protocol, skill, size, OAuth metadata, or scope","authorization is missing, expired, revoked, wrong-audience, or tenant-mismatched","purpose or data class is incompatible with the selected live skill","transport outcome is ambiguous and context resolves to zero or multiple tasks","task or context identity drifts","artifact is nonterminal, unstructured, oversized, or elevates provider calls or writes","review names a stale digest or aggregate version","exact idempotency key is replayed with changed intent"]},{"slug":"mcp-client-identity","title":"Provision and validate a remote MCP client","description":"Approve exact authority, deliver a signed pre-registration event, inspect discovery, validate PKCE and resource binding, then revoke without transporting a token or secret.","level":"Advanced","duration":"55 min","platforms":["MCP"],"products":["ai-location"],"outcome":"A replay-safe client identity journey with durable registration, request checks, revocation, and audit evidence.","scenario":"A platform team must provision a remote MCP client against an external authorization server, prove OAuth discovery and request binding, and revoke it without turning control-plane events into a credential channel.","steps":[{"title":"Define the user and system contract","description":"A platform team must provision a remote MCP client against an external authorization server, prove OAuth discovery and request binding, and revoke it without turning control-plane events into a credential channel. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Freeze the registration contract","description":"Bind one developer application to the exact client kind, callback, issuer, MCP resource audience, least scope, tool allowlist, purpose, and reviewer decision before provisioning begins."},{"title":"Deliver one authenticated effect","description":"Lease the durable outbox event, sign timestamp, event ID, and exact body with a managed HMAC key, reject stale or oversized deliveries, and deduplicate by event ID plus body hash."},{"title":"Persist the external identity","description":"Provision through the authorization server management seam, store only the non-secret external client ID and receipt, return the strict result contract, and reconcile a timeout before retrying any new effect."},{"title":"Prove discovery and request binding","description":"Publish RFC 9728 protected-resource metadata, discover RFC 8414 issuer metadata, require authorization code plus PKCE S256, and include the exact RFC 8707 resource in authorization and token requests."},{"title":"Revoke without erasing evidence","description":"Deliver a signed revocation for the same registration aggregate and external identity, disable it at the issuer, preserve receipts and audit, and verify that subsequent authorization checks fail closed."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when an exact retry returns the original registration result; event-id reuse with different bytes conflicts; redirect, issuer, resource, pkce, state, and least scope are validated; no code, token, client secret, or provider credential crosses the adapter callback; restart and revocation preserve attributable evidence. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["an exact retry returns the original registration result","event-ID reuse with different bytes conflicts","redirect, issuer, resource, PKCE, state, and least scope are validated","no code, token, client secret, or provider credential crosses the adapter callback","restart and revocation preserve attributable evidence"],"failureModes":["signature is wrong, stale, replayed with changed bytes, or too large","authorization-server mutation succeeds but the response is lost","callback, resource audience, PKCE method, or requested scope drifts","revocation targets an unknown or already retired external identity"]},{"slug":"webhook-reliability","title":"Consume Mappls events exactly once in effect","description":"Verify signatures, deduplicate deliveries, order per aggregate, retry, and replay safely.","level":"Advanced","duration":"55 min","platforms":["REST"],"products":["intouch-telematics","workmate","gis-analytics"],"outcome":"A production webhook ingestion pipeline.","scenario":"A consumer must apply each Mappls event once in business effect even when delivery is duplicated, delayed, reordered, or retried.","steps":[{"title":"Define the user and system contract","description":"A consumer must apply each Mappls event once in business effect even when delivery is duplicated, delayed, reordered, or retried. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Expose one safe receiver","description":"Deploy a public DNS hostname on HTTPS port 443 with a bounded path and no URL credential, query, redirect, fragment, IP literal, private name, or alternate port. Keep every A and AAAA answer public; Mappls validates and pins all answers on every attempt."},{"title":"Prove destination ownership","description":"Create the endpoint in pending state, validate the signed webhook.endpoint_verification.v1 envelope, compute the versioned challenge proof with the endpoint secret, and return it in x-mappls-verification-response before requesting business or synthetic events."},{"title":"Verify before parsing","description":"Read the exact raw body, validate timestamp freshness, event identity, and HMAC in constant time, then reject unknown versions or oversized payloads."},{"title":"Commit inbox and effect together","description":"Insert the event ID/content hash, validate aggregate version, apply the domain transition, and append downstream work in one transaction."},{"title":"Recover deliberately","description":"Return 2xx only after commit, retry transient dependencies out of band, quarantine conflicts, and replay from immutable evidence with an attributable operator reason. Issue a fresh ownership challenge after expiry; never replay one."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when every dns answer stays public and the receiver does not redirect; destination ownership is proven before business fan-out; the same event id and body is a replay; changed content under one id is rejected; out-of-order transitions do not regress state. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["every DNS answer stays public and the receiver does not redirect","destination ownership is proven before business fan-out","the same event ID and body is a replay","changed content under one ID is rejected","out-of-order transitions do not regress state"],"failureModes":["DNS changes to any non-public address","receiver returns a redirect","ownership challenge expires or is superseded","signature is stale or invalid","database commits but response is lost","event arrives before its prerequisite"]},{"slug":"oauth-server-integration","title":"Call Mappls safely from a trusted server","description":"Exchange OAuth client credentials, keep tokens in bearer headers, call typed Search and Route operations, preserve provenance, and bound retry.","level":"Intermediate","duration":"35 min","platforms":["REST"],"products":["search-places","routes-navigation","intouch-telematics"],"outcome":"A credential-safe live server boundary with typed errors, timeout, retry, and provider provenance.","scenario":"A trusted backend must call Search, Route, and InTouch without placing client credentials in URLs, logs, browsers, or retry queues.","steps":[{"title":"Define the user and system contract","description":"A trusted backend must call Search, Route, and InTouch without placing client credentials in URLs, logs, browsers, or retry queues. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Own credentials in one adapter","description":"Load client identity from the secret manager, exchange over HTTPS, cache the bearer token before expiry, and deduplicate concurrent refreshes."},{"title":"Wrap provider calls","description":"Validate inputs, send bearer headers, cap body and timeout, preserve provider request identity, and map status/body to redacted typed errors."},{"title":"Retry only safe work","description":"Retry bounded idempotent reads on transient status or timeout with jitter and Retry-After; reconcile writes by idempotency identity instead of blind retry."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when one token refresh serves concurrent calls; logs never contain credentials or provider bodies; timeouts and rate limits produce typed retry guidance. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["one token refresh serves concurrent calls","logs never contain credentials or provider bodies","timeouts and rate limits produce typed retry guidance"],"failureModes":["token endpoint denied or unavailable","provider returns 429 or 5xx","timeout occurs after a stateful provider commit"]},{"slug":"react-native-map","title":"Build a cross-platform React Native map","description":"Install the native wrapper, configure both platforms, add annotations, and handle cleanup.","level":"Intermediate","duration":"45 min","platforms":["React Native"],"products":["maps"],"outcome":"One map experience across Android and iOS.","scenario":"A React Native product needs one map feature across Android and iOS without hiding native lifecycle, permissions, or packaging differences.","steps":[{"title":"Define the user and system contract","description":"A React Native product needs one map feature across Android and iOS without hiding native lifecycle, permissions, or packaging differences. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Configure both native projects","description":"Install the documented wrapper and peer versions, apply Android package/signing and iOS bundle restrictions, and keep platform setup changes reviewable."},{"title":"Design a stable JavaScript boundary","description":"Pass serializable camera/features, use stable IDs, avoid high-frequency bridge chatter, and unsubscribe callbacks on unmount."},{"title":"Test native divergence","description":"Exercise permission, background/foreground, rotation, memory pressure, architecture, and release builds independently on both platforms."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when android and ios select the same feature identity; unmount releases native listeners; release builds work with restricted credentials. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["Android and iOS select the same feature identity","unmount releases native listeners","release builds work with restricted credentials"],"failureModes":["wrapper/native version skew","bridge receives events after unmount","one platform denies location permission"]},{"slug":"flutter-map","title":"Build a Flutter map and place picker","description":"Configure native keys, render the map, and return a validated place to your form.","level":"Intermediate","duration":"45 min","platforms":["Flutter"],"products":["maps","search-places"],"outcome":"A reusable cross-platform location field.","scenario":"A Flutter form needs a reusable place picker whose Dart state and native map lifecycle remain synchronized.","steps":[{"title":"Define the user and system contract","description":"A Flutter form needs a reusable place picker whose Dart state and native map lifecycle remain synchronized. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Configure platform runners","description":"Apply the documented Android and iOS requirements, restrict each platform key, and pin compatible plugin/native versions."},{"title":"Make selection explicit","description":"Keep query text, suggestion list, map camera, candidate marker, accepted Mappls Pin, and form value as separate states."},{"title":"Dispose and restore correctly","description":"Cancel searches, dispose controllers/subscriptions, restore the accepted place after recreation, and avoid treating a camera center as user consent."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when the form submits only an accepted place; back navigation releases native resources; platform permission denial still permits manual search. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["the form submits only an accepted place","back navigation releases native resources","platform permission denial still permits manual search"],"failureModes":["plugin/native SDK mismatch","late suggestion after widget disposal","camera moved after a prior selection"]},{"slug":"deep-link-campaign","title":"Create a zero-SDK location campaign","description":"Build safe place links, add fallback behavior, instrument hand-offs, and test every device.","level":"Beginner","duration":"15 min","platforms":["Deep links"],"products":["app-widgets-deep-links"],"outcome":"A campaign that opens a useful Mappls experience everywhere.","scenario":"A campaign must open one useful place experience from email, QR, social, and web without requiring an SDK or assuming the Mappls app is installed.","steps":[{"title":"Define the user and system contract","description":"A campaign must open one useful place experience from email, QR, social, and web without requiring an SDK or assuming the Mappls app is installed. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Build from stable location identity","description":"Use a documented place or navigation link, encode each parameter once, allow-list campaign metadata, and never embed credentials."},{"title":"Design the fallback chain","description":"Test installed-app, universal/app-link, mobile browser, desktop browser, and store outcomes while preserving only non-sensitive campaign context."},{"title":"Measure the hand-off honestly","description":"Record click and fallback class on your domain, avoid claiming downstream arrival without evidence, and keep a visible copy/open alternative."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when every target device reaches a useful destination; malformed input cannot change the target origin; analytics contain no precise user location. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["every target device reaches a useful destination","malformed input cannot change the target origin","analytics contain no precise user location"],"failureModes":["app not installed","link association misconfigured","messaging client strips or rewrites parameters"]},{"slug":"rest-geocode-service","title":"Build a server-side geocoding boundary","description":"Resolve addresses on a trusted server, retain provider identity, and return a narrow application contract.","level":"Beginner","duration":"25 min","platforms":["REST"],"products":["search-places"],"outcome":"A credential-safe geocoding service with typed errors and provenance.","scenario":"A backend must convert submitted addresses to candidates while keeping Mappls credentials and provider response complexity away from clients.","steps":[{"title":"Define the user and system contract","description":"A backend must convert submitted addresses to candidates while keeping Mappls credentials and provider response complexity away from clients. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Define a narrow request contract","description":"Accept bounded address text plus explicit region/bias fields, attach an application request ID, and reject markup or oversized input before the provider call."},{"title":"Call through the trusted adapter","description":"Acquire a bearer token, encode query parameters, cap timeout/body size, retain provider request identity, and return typed unavailable, denied, empty, or ambiguous outcomes."},{"title":"Return candidates, not false certainty","description":"Expose normalized label, Mappls Pin, coordinates, confidence/context available from the source, and require the caller to choose when multiple candidates remain."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when credentials appear only in bearer headers; ambiguous results stay explicit; provider identity follows the selected candidate. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["credentials appear only in bearer headers","ambiguous results stay explicit","provider identity follows the selected candidate"],"failureModes":["invalid address input","no candidate or multiple candidates","token, quota, or provider timeout"]},{"slug":"reverse-geocode-check-in","title":"Turn a device fix into a trustworthy check-in","description":"Reverse geocode accuracy-bearing coordinates, preserve consent, and distinguish evidence from an address label.","level":"Beginner","duration":"30 min","platforms":["REST"],"products":["search-places","capture-feedback"],"outcome":"A privacy-aware check-in that retains both raw evidence and human-readable context.","scenario":"A field check-in must attach readable place context to a consented device fix without pretending reverse geocoding proves physical presence.","steps":[{"title":"Define the user and system contract","description":"A field check-in must attach readable place context to a consented device fix without pretending reverse geocoding proves physical presence. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Capture purpose-bound evidence","description":"Record consent version, purpose, event and receipt time, latitude/longitude, accuracy, source, and expiry separately from the eventual address label."},{"title":"Reverse geocode on the server","description":"Validate coordinate and accuracy bounds, call with a trusted credential, retain provider identity, and store the raw evidence hash plus normalized response fields."},{"title":"Apply a versioned decision policy","description":"Compare fix accuracy, age, distance to target, and geofence policy; send weak evidence to review and permit consent revocation or precise-data redaction."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when address text never replaces raw accuracy evidence; weak fixes cannot auto-approve; redaction preserves decision lineage. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["address text never replaces raw accuracy evidence","weak fixes cannot auto-approve","redaction preserves decision lineage"],"failureModes":["permission or consent absent","stale or inaccurate fix","reverse geocoder returns no address"]},{"slug":"static-map-receipt","title":"Generate static maps for receipts and notifications","description":"Render bounded server-side map imagery with safe markers, caching, attribution, and fallback text.","level":"Beginner","duration":"20 min","platforms":["REST"],"products":["maps"],"outcome":"A deterministic map image pipeline for non-interactive surfaces.","scenario":"A receipt service needs a non-interactive location image that is deterministic, cacheable, attributable, and useful when images are blocked.","steps":[{"title":"Define the user and system contract","description":"A receipt service needs a non-interactive location image that is deterministic, cacheable, attributable, and useful when images are blocked. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Construct a bounded render request","description":"Use a known place/coordinate, fixed dimensions, scale, zoom, style, and marker count; reject user-controlled URLs, colors, and unbounded geometry."},{"title":"Fetch and cache server-side","description":"Keep credentials in the trusted service, key the cache by normalized render parameters and style/data version, cap bytes/time, and retain attribution requirements."},{"title":"Ship an accessible fallback","description":"Include the human-readable location and a safe place/navigation link so email clients, screen readers, and image-blocked users keep the essential information."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when identical parameters produce one cache identity; image failure leaves complete location text; no credential reaches generated html. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["identical parameters produce one cache identity","image failure leaves complete location text","no credential reaches generated HTML"],"failureModes":["render service timeout","unsupported or excessive geometry","email proxy strips the image"]},{"slug":"web-widget-place-picker","title":"Embed a place picker widget","description":"Mount a bounded widget, synchronize selection with your form, and preserve the selected Mappls Pin.","level":"Beginner","duration":"25 min","platforms":["Widgets","Web"],"products":["app-widgets-deep-links","search-places"],"outcome":"An accessible embedded place picker with explicit host-page ownership.","scenario":"A host form needs an embedded Mappls place experience while retaining control of validation, focus, persistence, and submission.","steps":[{"title":"Define the user and system contract","description":"A host form needs an embedded Mappls place experience while retaining control of validation, focus, persistence, and submission. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Set the trust boundary","description":"Load only the documented HTTPS widget origin, restrict browser configuration to the exact host, define allowed messages/events, and give the frame/container a clear title and size."},{"title":"Normalize one terminal result","description":"Bind one launch generation to the host lifecycle, treat widget output as an untrusted candidate, validate exact origin and schema, retain only Mappls Pin plus bounded label, and ignore late or duplicate results."},{"title":"Commit selection deliberately","description":"Keep candidate, accepted selection, and submitted record as separate states. Persist application selection only after a user decision with idempotency key and expected session version."},{"title":"Invalidate stale identity","description":"When host-owned address text changes, clear candidate and accepted Mappls Pin, return to draft, and block submit until the user selects again."},{"title":"Integrate fallback and accessibility","description":"Return focus after selection, cancel, or failure; mirror the accepted place in native form controls; announce errors; and keep a complete non-widget search/manual fallback."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when unexpected origins and opaque messages are ignored; a candidate cannot submit the form by itself; host edits invalidate stale selection; keyboard users can complete widget and fallback paths. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["unexpected origins and opaque messages are ignored","a candidate cannot submit the form by itself","host edits invalidate stale selection","keyboard users can complete widget and fallback paths"],"failureModes":["widget script or frame blocked","message schema/version changes","duplicate or late terminal callback","host text edited after widget selection"]},{"slug":"navigation-deep-link","title":"Hand off to navigation with a resilient deep link","description":"Encode a known place, protect campaign parameters, and provide browser and store fallbacks.","level":"Beginner","duration":"20 min","platforms":["Deep links"],"products":["app-widgets-deep-links","routes-navigation"],"outcome":"A tested app-to-navigation hand-off across installed and uninstalled states.","scenario":"A merchant app must hand a confirmed destination to navigation while surviving missing apps, unsupported modes, and rewritten links.","steps":[{"title":"Define the user and system contract","description":"A merchant app must hand a confirmed destination to navigation while surviving missing apps, unsupported modes, and rewritten links. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Freeze the destination","description":"Create the link only from an accepted Mappls Pin or validated coordinates, choose the documented navigation intent, and encode labels separately from identity."},{"title":"Own universal fallback","description":"Route through an HTTPS page that can open the supported app link, show the destination, offer browser navigation, and link to the correct store without redirect loops."},{"title":"Test and observe state classes","description":"Cover installed/uninstalled, Android/iOS/desktop, default-browser changes, offline state, and unsupported profiles; measure only the hand-off stage you can prove."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when destination identity survives every fallback; a failed app open returns control to the user; no secret or private payload is encoded. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["destination identity survives every fallback","a failed app open returns control to the user","no secret or private payload is encoded"],"failureModes":["app absent or association invalid","unsupported travel profile","device is offline at hand-off"]},{"slug":"cordova-map","title":"Ship a Mappls map in Cordova and Ionic","description":"Separate web and native configuration, wait for device readiness, and clean up plugin state safely.","level":"Intermediate","duration":"50 min","platforms":["Cordova"],"products":["maps","search-places"],"outcome":"A hybrid map screen with lifecycle-safe native bridge handling.","scenario":"A Cordova/Ionic application needs native Mappls capability while JavaScript, WebView, and native plugin lifecycles remain independently owned.","steps":[{"title":"Define the user and system contract","description":"A Cordova/Ionic application needs native Mappls capability while JavaScript, WebView, and native plugin lifecycles remain independently owned. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Align plugin and native projects","description":"Use the documented plugin version, apply Android/iOS credentials and permissions in platform configuration, and rebuild generated native projects after config changes."},{"title":"Wait for device and view readiness","description":"Call native features only after `deviceready`, serialize bridge inputs, avoid duplicate listeners across page navigation, and remove the native view before DOM ownership ends."},{"title":"Design a browser fallback","description":"Keep search/place identity in shared application state and provide a Web Maps or deep-link route for unsupported devices and plugin initialization failure."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when re-entering the page creates one native view; both native projects pass release configuration; plugin failure has a usable fallback. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["re-entering the page creates one native view","both native projects pass release configuration","plugin failure has a usable fallback"],"failureModes":["JavaScript calls before device readiness","native view survives page teardown","platform/plugin version mismatch"]},{"slug":"xamarin-map","title":"Integrate Mappls into a Xamarin application","description":"Configure platform projects, isolate credentials, bridge native lifecycle, and preserve location identity in shared code.","level":"Intermediate","duration":"55 min","platforms":["Xamarin"],"products":["maps","search-places"],"outcome":"A shared-code location feature backed by correctly owned native map views.","scenario":"A Xamarin application needs shared business state with native Android and iOS map ownership rather than an opaque lowest-common-denominator abstraction.","steps":[{"title":"Define the user and system contract","description":"A Xamarin application needs shared business state with native Android and iOS map ownership rather than an opaque lowest-common-denominator abstraction. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Split shared and platform concerns","description":"Keep place IDs, commands, and view models shared; configure credentials, permissions, native views, delegates, and package versions in each platform project."},{"title":"Bind lifecycle explicitly","description":"Create and dispose renderers predictably, forward native lifecycle callbacks, and detach events when pages disappear or are recreated."},{"title":"Normalize cross-platform results","description":"Map native selection/search callbacks into one bounded shared contract with Mappls Pin, label, coordinate, provenance, and optional accuracy/freshness."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when shared state never holds a native view; navigation releases delegates on both platforms; selection contracts are equivalent across platforms. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["shared state never holds a native view","navigation releases delegates on both platforms","selection contracts are equivalent across platforms"],"failureModes":["NuGet/native dependency conflict","renderer recreated without disposal","one platform returns a partial place result"]},{"slug":"distance-matrix-dispatch","title":"Rank responders with a distance matrix","description":"Batch eligible origins, interpret unreachable pairs, apply deterministic tie-breaks, and keep dispatch explainable.","level":"Intermediate","duration":"45 min","platforms":["REST"],"products":["routes-navigation","search-places"],"outcome":"An explainable ETA-based dispatch shortlist rather than a straight-line guess.","scenario":"An emergency dispatcher must rank capable available responders by network ETA without exceeding matrix bounds or hiding unreachable candidates.","steps":[{"title":"Define the user and system contract","description":"An emergency dispatcher must rank capable available responders by network ETA without exceeding matrix bounds or hiding unreachable candidates. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Filter before routing","description":"Select only capable, active, jurisdiction-eligible resources with fresh positions; cap the candidate set and retain the eligibility reasons."},{"title":"Build a bounded matrix","description":"Use one resolved incident destination, batch origins within documented limits, choose the correct vehicle profile, and preserve input/output index identity."},{"title":"Rank with policy, not ETA alone","description":"Exclude unreachable/stale pairs, then apply ETA, workload, capability priority, and deterministic tie-breaks; store the matrix request time and chosen explanation."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when every ranked unit was eligible before routing; unreachable pairs remain explicit; the dispatch decision is reproducible from evidence. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["every ranked unit was eligible before routing","unreachable pairs remain explicit","the dispatch decision is reproducible from evidence"],"failureModes":["candidate telemetry is stale","matrix returns partial/unreachable pairs","incident changes while ranking is in flight"]},{"slug":"traffic-aware-commute","title":"Build a traffic-aware commute assistant","description":"Compare departure choices, refresh bounded route alternatives, and explain when an ETA becomes stale.","level":"Intermediate","duration":"50 min","platforms":["Web","REST"],"products":["routes-navigation","maps"],"outcome":"A route comparison experience that communicates freshness and uncertainty.","scenario":"A commuter must compare leave-now choices using traffic-aware routes whose freshness and uncertainty are visible.","steps":[{"title":"Define the user and system contract","description":"A commuter must compare leave-now choices using traffic-aware routes whose freshness and uncertainty are visible. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Hold trip intent constant","description":"Resolve endpoints, profile, exclusions, arrival/departure semantics, and user preferences once so comparisons do not mix different requests."},{"title":"Version every refresh","description":"Store route/request identity, observation time, traffic horizon, geometry, duration, distance, and incidents; cancel obsolete requests and never merge alternatives across revisions."},{"title":"Communicate change","description":"Explain the meaningful delta, highlight changed segments accessibly, set a refresh threshold, and show the last successful estimate during temporary provider failure."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when alternatives are compared within one revision; stale estimates show their age; refresh does not flicker or reorder without explanation. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["alternatives are compared within one revision","stale estimates show their age","refresh does not flicker or reorder without explanation"],"failureModes":["traffic data becomes stale","route changes during user selection","provider returns a slower partial response"]},{"slug":"geojson-operations-layer","title":"Render a governed GeoJSON operations layer","description":"Validate geometry, assign stable feature IDs, style deterministically, and synchronize map and table selection.","level":"Intermediate","duration":"55 min","platforms":["Web"],"products":["maps","gis-analytics"],"outcome":"An accessible map layer whose visual state is reproducible from source data.","scenario":"An operations dashboard must turn source-disclosed GeoJSON into a reproducible accessible map-and-table view.","steps":[{"title":"Define the user and system contract","description":"An operations dashboard must turn source-disclosed GeoJSON into a reproducible accessible map-and-table view. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Validate before rendering","description":"Enforce feature count/bytes, supported geometry, CRS expectation, coordinate bounds, unique stable IDs, safe properties, source, date, and license."},{"title":"Compile deterministic style state","description":"Derive layers, filters, colors, sizes, labels, z-order, legend, and bounds from versioned rules rather than ad-hoc UI mutations."},{"title":"Synchronize interaction","description":"Use the feature ID across map hit-test, table row, URL, focus, details, and export; provide non-color cues and a table path for every actionable feature."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when the same input and rules produce identical style output; invalid features fail with diagnostics; map and table always share one selected id. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["the same input and rules produce identical style output","invalid features fail with diagnostics","map and table always share one selected ID"],"failureModes":["unsupported geometry or CRS","duplicate/missing feature identity","large collection exceeds render budget"]},{"slug":"linux-map-client","title":"Operate a Mappls client on embedded Linux","description":"Separate runtime and map-data compatibility, stage updates, survive power loss, and expose health signals.","level":"Advanced","duration":"2 hr","platforms":["Linux","Automotive"],"products":["offline-automotive","maps"],"outcome":"An embedded map runtime with atomic data activation and rollback evidence.","scenario":"An embedded Linux device must run and update a map client under constrained storage, intermittent connectivity, and supervised process recovery.","steps":[{"title":"Define the user and system contract","description":"An embedded Linux device must run and update a map client under constrained storage, intermittent connectivity, and supervised process recovery. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Pin the compatibility matrix","description":"Record CPU/GPU, OS image, runtime build, map-data epoch, region, license, storage, and cryptographic requirements as one release manifest."},{"title":"Supervise runtime health","description":"Run with bounded resources, expose liveness/readiness, persist only necessary state, isolate writable data, and restart without corrupting the active package."},{"title":"Use dual-slot updates","description":"Download into an inactive slot, verify signature/structure, smoke test, switch atomically, health-gate the boot, and retain the prior slot for rollback."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when cold boot works without network; power loss never removes the active package; health failure automatically restores the prior slot. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["cold boot works without network","power loss never removes the active package","health failure automatically restores the prior slot"],"failureModes":["GPU/runtime incompatibility","disk pressure during staging","power loss between switch and acknowledgement"]},{"slug":"intouch-trip-lifecycle","title":"Reconcile a complete InTouch trip lifecycle","description":"Create provider identity, consume event-time telemetry, own exceptions, and close only after provider acknowledgement.","level":"Advanced","duration":"2 hr","platforms":["REST","Web"],"products":["intouch-telematics","routes-navigation"],"outcome":"A restart-safe connected trip with replay, late evidence, and closure reconciliation.","scenario":"A logistics control tower must reconcile internal orders with provider trip and telemetry state across retries, late observations, exceptions, and closure.","steps":[{"title":"Define the user and system contract","description":"A logistics control tower must reconcile internal orders with provider trip and telemetry state across retries, late observations, exceptions, and closure. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Bind identities before movement","description":"Persist internal trip, provider trip, vehicle/device, route revision, idempotency request, and policy version in one aggregate."},{"title":"Separate commands from observations","description":"Send create/start/close through an outbox and reconcile acknowledgement; ingest telemetry/events with source/event/content identity and event-time ordering."},{"title":"Close through evidence","description":"Require destination/route progress, resolved exceptions, delivery proof, and provider close acknowledgement; retain late evidence as a derived revision without reopening terminal state."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when duplicate commands and events have one effect; late telemetry cannot regress progress; ambiguous provider close is reconciled before terminal success. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["duplicate commands and events have one effect","late telemetry cannot regress progress","ambiguous provider close is reconciled before terminal success"],"failureModes":["provider accepts command but response is lost","telemetry gap or route deviation","closure requested with open exception"]},{"slug":"workmate-proof-review","title":"Build proof review and rework for field jobs","description":"Capture purpose-bound evidence, route weak submissions to review, request rework, and preserve decision history.","level":"Advanced","duration":"90 min","platforms":["REST","Android"],"products":["workmate","capture-feedback"],"outcome":"An auditable proof workflow that cannot silently overwrite rejected evidence.","scenario":"A field-work organization must distinguish captured evidence, automated policy, human review, rework, approval, and final closure.","steps":[{"title":"Define the user and system contract","description":"A field-work organization must distinguish captured evidence, automated policy, human review, rework, approval, and final closure. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Define evidence policy","description":"Version required fields, media types, location accuracy/freshness, consent/purpose, checklist, signature, retention, and automatic-review thresholds."},{"title":"Append submissions","description":"Give each proof submission an immutable ID/content hash, event/receipt time, actor/device, task version, provider identity, and redaction state; never overwrite a rejected attempt."},{"title":"Make review a state machine","description":"Route weak evidence to a named reviewer, record approve/reject/rework reasons, issue a new attempt identity, and allow task closure only from an approved policy-compatible submission."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when rejected evidence remains auditable; automated policy cannot override human rejection; closure names the exact approved submission. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["rejected evidence remains auditable","automated policy cannot override human rejection","closure names the exact approved submission"],"failureModes":["offline duplicate submission","media upload succeeds but command times out","review policy changes during rework"]},{"slug":"cordova-release-hardening","title":"Qualify a Cordova location release","description":"Pin bridge and native dependencies, prove lifecycle disposal, automate both release builds, and operate a browser fallback.","level":"Advanced","duration":"80 min","platforms":["Cordova"],"products":["maps","search-places","routes-navigation"],"outcome":"A versioned hybrid release with reproducible native builds, safe teardown, and rollback.","scenario":"A hybrid application must remain supportable after plugin, WebView, Android, iOS, and operating-system versions move independently.","steps":[{"title":"Define the user and system contract","description":"A hybrid application must remain supportable after plugin, WebView, Android, iOS, and operating-system versions move independently. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Freeze the compatibility unit","description":"Record Cordova/Ionic, plugin, native SDK, Gradle, CocoaPods/SPM, WebView, OS target, credential restriction, and entitlement as one reviewed manifest."},{"title":"Prove lifecycle ownership","description":"Create one native view generation after device readiness, bound bridge messages, reject late callbacks, detach listeners, restore focus, and dispose before page ownership ends."},{"title":"Build and recover both targets","description":"Produce clean Android and iOS release archives, exercise denied/offline/blocked/plugin-missing paths, preserve a web or deep-link fallback, and rehearse version rollback."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when both clean release builds reproduce from the manifest; one page owns one native generation; fallback completes the core user intent; rollback restores the last qualified pair. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["both clean release builds reproduce from the manifest","one page owns one native generation","fallback completes the core user intent","rollback restores the last qualified pair"],"failureModes":["plugin and native SDK version drift","WebView survives route teardown","one store release rejects the configured entitlement"]},{"slug":"deep-link-attribution-resilience","title":"Operate deep links across every hand-off","description":"Govern destination identity, universal-link association, privacy-safe attribution, fallback, expiry, and campaign retirement.","level":"Advanced","duration":"70 min","platforms":["Deep links"],"products":["app-widgets-deep-links","routes-navigation","search-places"],"outcome":"A measurable zero-SDK journey that never confuses a click with arrival.","scenario":"A multi-channel campaign must preserve one location intent through messaging clients, browsers, installed apps, stores, and privacy controls.","steps":[{"title":"Define the user and system contract","description":"A multi-channel campaign must preserve one location intent through messaging clients, browsers, installed apps, stores, and privacy controls. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Sign the destination contract","description":"Allow-list documented place, route, or navigation shapes; bind a stable Mappls Pin or validated coordinate, campaign revision, expiry, and non-sensitive attribution fields."},{"title":"Operate association and fallback","description":"Monitor Android App Links and iOS Universal Links, prevent redirect loops, retain browser and store choices, and give users a visible copy/open destination."},{"title":"Measure only observable stages","description":"Separate impression, click, resolver decision, app hand-off, and application acknowledgement; minimize attribution, expire campaigns, and retire destinations without rewriting history."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when every device class reaches a useful destination; link rewriting cannot change the target origin; analytics make no unproved arrival claim; expired campaigns fail safely. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["every device class reaches a useful destination","link rewriting cannot change the target origin","analytics make no unproved arrival claim","expired campaigns fail safely"],"failureModes":["association file is stale or unavailable","messaging client strips parameters","app opens but does not acknowledge the intended destination"]},{"slug":"flutter-production-lifecycle","title":"Production-harden a Flutter location feature","description":"Lock Dart/native compatibility, control rebuilds and streams, test process recovery, and qualify Android and iOS independently.","level":"Advanced","duration":"90 min","platforms":["Flutter"],"products":["maps","search-places","routes-navigation","capture-feedback"],"outcome":"A cross-platform feature with stable identity, bounded bridge traffic, and deterministic disposal.","scenario":"A Flutter application must offer consistent location behavior while Dart, Android, iOS, native SDK, permission, and process lifecycles diverge.","steps":[{"title":"Define the user and system contract","description":"A Flutter application must offer consistent location behavior while Dart, Android, iOS, native SDK, permission, and process lifecycles diverge. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Lock the release graph","description":"Record Flutter/Dart, plugin, native SDK, Android/iOS targets, architecture, permission strings, keys, entitlements, and signing identities in one compatibility decision."},{"title":"Bound state and bridge traffic","description":"Separate draft, candidate, accepted identity, controller generation, stream subscriptions, and durable form state; debounce high-frequency events and reject callbacks after dispose."},{"title":"Qualify native divergence","description":"Test cold/warm launch, rotation, background, permission change, memory pressure, process recreation, offline state, accessibility, release archives, and rollback on both platforms."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when accepted mappls identity survives process recreation; no disposed widget receives native events; android and ios release paths are independently reproducible; fallback remains usable without location permission. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["accepted Mappls identity survives process recreation","no disposed widget receives native events","Android and iOS release paths are independently reproducible","fallback remains usable without location permission"],"failureModes":["plugin/native architecture mismatch","late stream event after disposal","one platform restores an obsolete controller generation"]},{"slug":"ios-sdk-production-readiness","title":"Qualify an iOS Mappls release","description":"Resolve package authority, bind credentials and entitlements, own controller generations, test privacy and background behavior, and prove rollback.","level":"Advanced","duration":"2 hr","platforms":["iOS"],"products":["maps","search-places","routes-navigation","intouch-telematics","workmate","capture-feedback","app-widgets-deep-links","offline-automotive","ai-location"],"outcome":"A clean-device iOS qualification record spanning SDK, widget, tracking, and distribution boundaries.","scenario":"An iOS portfolio uses SDKs, binary distributions, widgets, or tracking components whose source, package, entitlement, privacy, and lifecycle authority must stay explicit.","steps":[{"title":"Define the user and system contract","description":"An iOS portfolio uses SDKs, binary distributions, widgets, or tracking components whose source, package, entitlement, privacy, and lifecycle authority must stay explicit. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Resolve the exact distribution","description":"Bind repository fingerprint, released package/version/checksum, Swift toolchain, minimum iOS, architecture, transitive dependencies, account region, entitlement, credential class, bundle, team, and rollback owner."},{"title":"Own every presentation generation","description":"Create UI and delegates on the main actor, normalize only allow-listed results, reject stale callbacks, make background/location behavior purpose-bound, and dispose controllers and observers exactly once."},{"title":"Qualify on clean devices","description":"Automate denied/restricted/approximate permission, offline, entitlement expiry, background/foreground, memory pressure, process restart, accessibility, privacy manifest, archive/export, upgrade, downgrade, and rollback."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when a clean archive installs and launches on every supported target; no opaque provider object enters durable state; tracking and widget journeys survive restart safely; revoked access degrades without leaking credentials. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["a clean archive installs and launches on every supported target","no opaque provider object enters durable state","tracking and widget journeys survive restart safely","revoked access degrades without leaking credentials"],"failureModes":["package exists but owning product contract is unclear","delegate callback arrives after replacement","background permission or entitlement changes during an active journey"]},{"slug":"ios-direction-geofence-handoffs","title":"Build restart-safe iOS direction and geofence handoffs","description":"Own native editor generations, validate route and geometry candidates, provide an exact navigation-link fallback, separate target acknowledgement and application review, and recover safely after restart.","level":"Advanced","duration":"95 min","platforms":["iOS"],"products":["app-widgets-deep-links","routes-navigation","intouch-telematics"],"outcome":"Two tested, durable iOS handoff journeys with explicit provider and application evidence boundaries.","scenario":"A mobility application must let travelers choose a route and operations authors draft geofences through Mappls iOS UI surfaces without treating presentation, callback, deep-link opening, review, or publication as the same fact.","steps":[{"title":"Define the user and system contract","description":"A mobility application must let travelers choose a route and operations authors draft geofences through Mappls iOS UI surfaces without treating presentation, callback, deep-link opening, review, or publication as the same fact. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Freeze the evidence and adapter seams","description":"Select exact entitled MapplsDirectionUI and MapplsGeofenceUI releases from reviewed source guides, keep their native types behind separate translators, and label the host fixture envelope as application-owned rather than a provider wire contract."},{"title":"Own intent, revision, and presentation generation","description":"Persist bounded direction destination/profile or geofence purpose/scope/policy as the aggregate draft, increment one generation for each editor presentation, and reject callbacks from disposed controllers or superseded draft revisions."},{"title":"Complete the direction evidence ladder","description":"Validate route revision, candidate count, selected index, destination, and profile; require deliberate traveler selection; record navigation request separately from the target adapter acknowledgement; and use only the documented Mappls HTTPS/app-URI navigation shape for recovery."},{"title":"Complete the geofence review boundary","description":"Normalize a bounded circle or polygon, reject invalid coordinates, radius, duplicate or crossing vertices, hash the canonical geometry, bind it to purpose and policy, and require a reviewer other than the draft author."},{"title":"Commit and recover exactly once in effect","description":"Require an idempotency key and expected aggregate version, atomically store snapshot, processed-command receipt, immutable audit event, and outbox entry, then prove restart recovery without persisting controllers, delegates, route objects, layers, credentials, or opaque payloads."},{"title":"Qualify hostile paths on devices","description":"Exercise installed and missing apps, broken universal-link association, offline state, UI unavailability, cancellation, duplicate and late callbacks, invalid indexes, geometry attacks, process death, accessibility focus restoration, target timeout, entitlement drift, upgrade, and rollback."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when direction return, route selection, handoff request, and target acceptance are independently evidenced; the fallback emits only the documented navigation hosts and never claims a return callback; stale or opaque native results change no state; geofence approval remains an application draft until an authoritative publication contract exists; self-review and stale review are rejected; restart and replay preserve one aggregate truth. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["direction return, route selection, handoff request, and target acceptance are independently evidenced","the fallback emits only the documented navigation hosts and never claims a return callback","stale or opaque native results change no state","geofence approval remains an application draft until an authoritative publication contract exists","self-review and stale review are rejected","restart and replay preserve one aggregate truth"],"failureModes":["native UI is unavailable and the app link is not installed","a callback arrives from an old presentation or route revision","the route index or intent differs from the active draft","circle or polygon violates geometry policy","navigation target times out after request","no authoritative entitled geofence publication contract is selected"]},{"slug":"react-native-native-parity","title":"Qualify React Native native parity","description":"Freeze wrapper/native versions, normalize cross-platform results, constrain bridge traffic, recover process death, and release both native targets.","level":"Advanced","duration":"100 min","platforms":["React Native"],"products":["maps","search-places","routes-navigation","intouch-telematics","workmate","capture-feedback"],"outcome":"One JavaScript contract backed by independently qualified Android and iOS behavior.","scenario":"A React Native product must keep one JavaScript business contract while native wrappers, SDKs, permissions, and release behavior differ by platform.","steps":[{"title":"Define the user and system contract","description":"A React Native product must keep one JavaScript business contract while native wrappers, SDKs, permissions, and release behavior differ by platform. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Freeze wrapper and native authority","description":"Record React Native/New Architecture mode, wrapper, peer packages, Android/iOS SDK versions, build tools, restriction identities, permission policy, and entitlement in one manifest."},{"title":"Normalize the bridge contract","description":"Use serializable bounded inputs and results, stable Mappls/business IDs, explicit generation and cancellation, backpressure for location events, and no native object retention in JavaScript state."},{"title":"Prove platform parity honestly","description":"Run independent Android and iOS suites for cold/warm launch, background, permission changes, rotation, process death, bridge reload, offline, accessibility, release archive, upgrade, and rollback; document intentional divergence."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when both native targets implement the same portable result schema; bridge reload cannot duplicate tracking or listeners; late callbacks are rejected by generation; each store artifact has separate qualification evidence. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["both native targets implement the same portable result schema","bridge reload cannot duplicate tracking or listeners","late callbacks are rejected by generation","each store artifact has separate qualification evidence"],"failureModes":["wrapper compiles against only one native SDK line","JavaScript reload leaves a native session active","platform permission semantics produce different unhandled states"]},{"slug":"widget-host-production","title":"Operate widgets as untrusted lifecycle surfaces","description":"Validate origin and schema, separate candidate from commit, recover blocked embeds, preserve accessibility, and retire safely.","level":"Advanced","duration":"85 min","platforms":["Widgets"],"products":["app-widgets-deep-links","search-places","routes-navigation","intouch-telematics","capture-feedback"],"outcome":"A restart-safe host journey with exact-origin validation and a complete non-widget fallback.","scenario":"A host application embeds a provider-owned surface but must retain validation, persistence, accessibility, recovery, and business submission authority.","steps":[{"title":"Define the user and system contract","description":"A host application embeds a provider-owned surface but must retain validation, persistence, accessibility, recovery, and business submission authority. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Constrain the trust boundary","description":"Pin the documented origin/component/release, CSP and frame policy, exact message origin, versioned allow-list schema, credential class, entitlement, and one host generation."},{"title":"Separate candidate from commitment","description":"Treat every callback/message as untrusted candidate evidence, copy only bounded identity, require a deliberate user commit, invalidate selection after host edits, and persist with idempotency and expected version."},{"title":"Operate failure and retirement","description":"Handle blocked script/frame, timeout, denied access, duplicate/late messages, back navigation, bfcache, unmount, dependency upgrade, accessibility focus, useful manual fallback, telemetry minimization, and rollback."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when wrong-origin and unknown-schema input changes no state; candidate receipt cannot submit the business record; fallback supports keyboard and screen-reader completion; unmount and rollback leave no active generation. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["wrong-origin and unknown-schema input changes no state","candidate receipt cannot submit the business record","fallback supports keyboard and screen-reader completion","unmount and rollback leave no active generation"],"failureModes":["CSP or browser blocks the widget","message contract changes without version negotiation","late callback targets an edited or submitted host record"]},{"slug":"xamarin-maintenance-migration","title":"Harden and migrate a Xamarin location feature","description":"Inventory native dependencies, isolate shared state, qualify each renderer, add rollback, and prepare a controlled successor migration.","level":"Advanced","duration":"2 hr","platforms":["Xamarin"],"products":["maps","search-places","routes-navigation"],"outcome":"A supportable existing integration with explicit compatibility, teardown, and migration evidence.","scenario":"An existing Xamarin application must remain safe while its shared runtime and native dependencies age, and must move to a supported successor without a risky rewrite.","steps":[{"title":"Define the user and system contract","description":"An existing Xamarin application must remain safe while its shared runtime and native dependencies age, and must move to a supported successor without a risky rewrite. Record the region, data freshness, latency budget, privacy purpose, credential owner, and fallback before choosing an SDK or endpoint."},{"title":"Inventory the actual release graph","description":"Record Xamarin/Mono, NuGet, native Android/iOS SDKs, bindings, renderers, OS targets, credentials, entitlements, source fingerprints, binary checksums, and known workstation-only steps."},{"title":"Contain and qualify current behavior","description":"Keep native views and delegates platform-owned, normalize portable results, remove leaked listeners, automate cold/warm launch and permission failures, and produce clean signed archives with rollback."},{"title":"Migrate behind one contract","description":"Freeze the shared location interface, build the successor adapter alongside the existing one, compare identity/results/lifecycle telemetry, stage cohorts, retain reversible data and release paths, then retire bindings deliberately."},{"title":"Prove the production behavior","description":"Automate the happy path and every named failure. The release is ready only when current artifacts reproduce without a configured workstation; shared state contains no native object; old and successor adapters satisfy one contract suite; cohort rollback preserves user and business state. Capture provider request identity without logging credentials or unnecessary precise location."}],"acceptance":["current artifacts reproduce without a configured workstation","shared state contains no native object","old and successor adapters satisfy one contract suite","cohort rollback preserves user and business state"],"failureModes":["binding references an unavailable native symbol","renderer lifecycle differs across OS versions","successor adapter changes place identity or cancellation semantics"]}],"miniApps":[{"slug":"store-locator","name":"Store Locator","description":"Discover eligible branches, compare distance and ETA, preserve Mappls Pin identity, and hand off safely to navigation.","stack":["Node.js","Responsive map-and-list UI","Nearby adapter","Matrix adapter"],"products":["maps","search-places","routes-navigation","app-widgets-deep-links"],"journey":"Locate → discover → filter → rank → select → navigate","difficulty":"Starter","downloadPath":"/downloads/store-locator.zip","checksumPath":"/downloads/store-locator.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":6,"verifiedFeatures":["Responsive synchronized map and list","Credential-safe server boundary","Nearby and matrix contract provenance","Stable Mappls Pin continuity","Service intersection filters","Opening and accessibility eligibility","Distance, ETA, and name ranking","Honest radius and empty states","Validated navigation deep links","Canonical bounded cache","Defensive cache isolation"]},{"slug":"delivery-control-tower","name":"Delivery Control Tower","description":"Track live orders, explain ETA risk, replay a trip, and handle delivery exceptions.","stack":["Node.js","Browser UI","InTouch adapter"],"products":["intouch-telematics","routes-navigation","maps"],"journey":"Plan → ready → track → recover → close → replay","difficulty":"Advanced","downloadPath":"/downloads/delivery-control-tower.zip","checksumPath":"/downloads/delivery-control-tower.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":7,"verifiedFeatures":["Responsive fleet control tower","Durable trip aggregates","Immutable telemetry ledger","Event-time and receipt-time ordering","Late-event derived revisions","Owned exception recovery","Idempotent commands and observations","Optimistic concurrency","Transactional outbox","InTouch adapter boundary","Provider close reconciliation","Restart recovery"]},{"slug":"grid-restoration-desk","name":"Grid Restoration Desk","description":"Correlate an outage, govern independent switching approval, dispatch an assigned crew, preserve rework, and reconcile restoration from telemetry and customer-impact evidence.","stack":["Node.js","Responsive operations desk","Atomic evidence repository","Mappls fixture adapter"],"products":["gis-analytics","intouch-telematics","workmate","routes-navigation","capture-feedback"],"journey":"Report → correlate → approve switching → dispatch → prove → reconcile","difficulty":"Advanced","downloadPath":"/downloads/grid-restoration-desk.zip","checksumPath":"/downloads/grid-restoration-desk.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":14,"verifiedFeatures":["Responsive restoration operations desk","Complete eight-event outage journey","Role-scoped operational commands","Independent switching-plan approval","Assigned-crew enforcement","Independent restoration reconciliation","Telemetry and customer-impact recovery gate","Rejected-attempt retention and rework","Map and route evidence separated from electrical authority","Private evidence and credential rejection","Idempotent commands","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Credential-free zero-network fixture mode"]},{"slug":"care-transfer-desk","name":"Care Transfer Desk","description":"Confirm the correct receiving entrance, assign eligible transport, preserve courier custody, review condition exceptions, and reconcile receiver acceptance without retaining patient or clinical data.","stack":["Node.js","Responsive custody desk","Atomic evidence repository","Mappls care fixture adapter"],"products":["search-places","routes-navigation","intouch-telematics","capture-feedback","gis-analytics"],"journey":"Request → confirm facility → assign → custody → review exceptions → accept","difficulty":"Advanced","downloadPath":"/downloads/care-transfer-desk.zip","checksumPath":"/downloads/care-transfer-desk.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":17,"verifiedFeatures":["Responsive privacy-minimized custody desk","Complete ten-event exception-aware journey","Exact role-scoped commands","Confirmed clinical-entrance revision","Bounded transport eligibility and stability window","Assigned-courier custody enforcement","Independent condition-exception review","Arrival separated from completion","Custody-bound receiver acceptance","Independent quality reconciliation","Rejected receipt retention and rework","Patient and clinical evidence rejection","Idempotent commands","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Credential-free zero-network fixture mode"]},{"slug":"airside-turnaround-desk","name":"Airside Turnaround Desk","description":"Coordinate a revision-safe aircraft turnaround, pause for airside exceptions, preserve four service milestones, and require independent airline, airport, and safety readiness decisions.","stack":["Node.js","Responsive airside control desk","Atomic evidence repository","Mappls aviation fixture adapter"],"products":["gis-analytics","intouch-telematics","workmate","maps","capture-feedback"],"journey":"Draft → lock stand → plan → dispatch → evidence → review → ready","difficulty":"Advanced","downloadPath":"/downloads/airside-turnaround-desk.zip","checksumPath":"/downloads/airside-turnaround-desk.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":22,"verifiedFeatures":["Responsive aviation control desk","Complete sixteen-event exception-aware journey","Exact role-scoped operational commands","Immutable stand and zone revisions","Stale plan and assignment invalidation","Eligible vehicle and assigned-lead enforcement","Four independently evidenced service milestones","Independent airside exception investigation","Abort without invented readiness","Airline, airport, and safety authority separation","Map, route, task, and telemetry evidence separated from authority","Passenger, location, clearance, and credential rejection","Idempotent commands","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Credential-free zero-network fixture mode"]},{"slug":"field-service","name":"Field Service Console","description":"Create, assign, execute, and audit a technician visit with proof.","stack":["Node.js","Browser UI","Workmate adapter"],"products":["workmate","routes-navigation","capture-feedback"],"journey":"Create → assign → accept → travel → prove → close","difficulty":"Production pattern","downloadPath":"/downloads/field-service.zip","checksumPath":"/downloads/field-service.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":6,"verifiedFeatures":["Browser operations console","Durable task snapshots","Append-only audit history","Idempotent commands","Optimistic concurrency","Proof approval and rework","Transactional outbox","Mappls adapter boundary","Restart recovery"]},{"slug":"fleet-geofence","name":"Fleet Geofence Monitor","description":"Design zones and run an actionable live enter/exit event queue.","stack":["Node.js","Browser UI","InTouch adapter"],"products":["intouch-telematics","maps"],"journey":"Draft → publish → breach → acknowledge → resolve","difficulty":"Production pattern","downloadPath":"/downloads/fleet-geofence.zip","checksumPath":"/downloads/fleet-geofence.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":7,"verifiedFeatures":["Responsive exception queue","Validated geofence geometry","Versioned provider rule identity","Immutable source activity ledger","Jitter suppression without evidence loss","Asset-scope enforcement","Named case ownership and SLA","Evidence-backed resolution","Safe rule retirement","Idempotent activity ingestion","Optimistic concurrency","Transactional outbox","Restart recovery"]},{"slug":"retail-site-lab","name":"Retail Site Lab","description":"Compare candidate sites through immutable dataset versions, reproducible scoring, lineage, and governed sharing.","stack":["Node.js","Browser UI","mGIS adapter","Insight lineage"],"products":["gis-analytics","search-places"],"journey":"Version → validate → publish → process → share → revoke","difficulty":"Advanced","downloadPath":"/downloads/retail-site-lab.zip","checksumPath":"/downloads/retail-site-lab.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":8,"verifiedFeatures":["Responsive decision lab","Immutable dataset versions","Content-hash deduplication","CRS and feature diagnostics","Reproducible weighted scoring","Parameter and input lineage","Failed-attempt retry links","Audience, expiry, export, and embed policy","Share revocation without evidence loss","Idempotent commands","Optimistic concurrency","Transactional outbox","Restart recovery"]},{"slug":"trip-planner","name":"Weekend Trip Planner","description":"Preserve Mappls place identity through a durable ordered itinerary, route revisions, progress, and completion.","stack":["Node.js","Responsive itinerary UI","Search adapter","Routes adapter"],"products":["maps","search-places","routes-navigation","app-widgets-deep-links"],"journey":"Discover → save → sequence → preview → go → complete","difficulty":"Starter","downloadPath":"/downloads/trip-planner.zip","checksumPath":"/downloads/trip-planner.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":8,"verifiedFeatures":["Responsive itinerary planner","Provider-backed discovery provenance","Mappls Pin identity continuity","Bounded duplicate-free stops","Exact sequence validation","Profile-aware multi-leg routes","Immutable route revisions","Automatic stale-route invalidation","Ordered visit and explicit skip progress","Pause, resume, and deliberate cancellation","Completion invariants","Idempotent commands","Optimistic concurrency","Transactional outbox","Restart recovery"]},{"slug":"incident-dispatch","name":"Incident Dispatch","description":"Resolve an incident, choose a capable available responder, route, track evidence, enforce arrival, and review.","stack":["Node.js","Browser control room","Search adapter","Routes adapter","InTouch adapter"],"products":["search-places","routes-navigation","intouch-telematics","gis-analytics"],"journey":"Report → locate → dispatch → route → coordinate → resolve → review","difficulty":"Advanced","downloadPath":"/downloads/incident-dispatch.zip","checksumPath":"/downloads/incident-dispatch.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":8,"verifiedFeatures":["Responsive incident command UI","Stable CAD identity","Confidence-bearing location resolution","Capability and availability filtering","Matrix ETA responder ranking","Active-unit double-dispatch prevention","Assigned-unit acceptance","Vehicle-aware route identity","Event-time telemetry ordering","Late evidence without state regression","Hazard updates","Objective arrival policy","Resolution evidence","Attributable review metrics","Idempotent commands","Optimistic concurrency","Transactional outbox","Restart recovery"]},{"slug":"address-verifier","name":"Address Verifier","description":"Normalize an address, govern consented device evidence, apply versioned policy, and retain an attributable decision.","stack":["Node.js","Browser trust studio","Search adapter","Evidence ledger"],"products":["search-places","capture-feedback"],"journey":"Enter → normalize → consent → capture → compare → decide → redact","difficulty":"Production pattern","downloadPath":"/downloads/address-verifier.zip","checksumPath":"/downloads/address-verifier.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":8,"verifiedFeatures":["Responsive trust studio","Stable external business identity","Mappls Pin normalization and provenance","Purpose-bound expiring consent","Consent revocation","Immutable device-evidence ledger","Event and receipt time","Accuracy-bearing capture","Evidence content hashes","Versioned distance policy","Mandatory weak-evidence review","Automated override prevention","Precise-data redaction with audit retention","Idempotent commands","Optimistic concurrency","Transactional outbox","Restart recovery"]},{"slug":"map-story","name":"Map Story","description":"Compile validated GeoJSON into an accessible, deterministic, source-disclosed narrative map.","stack":["Node.js","Accessible scrollytelling UI","GeoJSON compiler"],"products":["maps","gis-analytics"],"journey":"Validate → compile → encode → narrate → share","difficulty":"Starter","downloadPath":"/downloads/map-story.zip","checksumPath":"/downloads/map-story.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":5,"verifiedFeatures":["Responsive scrollytelling experience","Bounded GeoJSON compiler","Geometry and coordinate validation","Unique feature and sequence identity","Numeric range enforcement","Markup-safe narrative content","Derived geographic bounds and metrics","Deterministic documented visual encoding","Keyboard-accessible map points","Scroll, focus, and URL synchronization","Required source, date, and license disclosure","Honest fixture labelling"]},{"slug":"spatial-agent","name":"Spatial Operations Agent","description":"Research, plan, approve, execute, and cite grounded Mappls MCP operations through fixture, local stdio, or authenticated remote transports.","stack":["Node.js","Browser agent lab","Mappls MCP SDK client"],"products":["ai-location","search-places","routes-navigation","intouch-telematics"],"journey":"Ask → plan → review → approve → execute → cite","difficulty":"Advanced","downloadPath":"/downloads/spatial-agent.zip","checksumPath":"/downloads/spatial-agent.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":15,"verifiedFeatures":["Responsive governed-agent UI","Six-pattern agent authority planner","Twelve conditional governance controls","Eight-dimension evaluation contract","Credential-free solution research","All sixteen industries and thirteen platform targets","Deterministic fixture boundary","Real local stdio MCP client","Authenticated Streamable HTTP MCP client","Offline and live-read profile isolation","HTTPS and exact endpoint validation","Bounded arguments, calls, buffers, and outputs","Advertised-tool enforcement","Gateway credential non-echo","Deterministic allow-listed plans","Immutable SHA-256 plan identity","Human approval as a state transition","Explicit least-privilege scopes","Expiring approvals","Sensitive live-location risk class","Dependency-bound tool execution","Provider provenance on every live result","Explicit catalog provenance for offline tools","Grounded per-step citations","Secret-safe failure persistence","Idempotent commands","Optimistic concurrency","Transactional outbox","Graceful MCP shutdown","Restart recovery"]},{"slug":"a2a-solution-studio","name":"A2A Solution Studio","description":"Discover the Mappls A2A v1 service, delegate exact offline or purpose-bound live-read work, reconcile ambiguous outcomes, and review immutable artifacts without elevating their authority.","stack":["Node.js","Responsive coordination UI","Official A2A SDK client","Durable evidence ledger"],"products":["ai-location","search-places","routes-navigation","intouch-telematics"],"journey":"Draft → discover profile → delegate → reconcile → review → accept or reject","difficulty":"Advanced","downloadPath":"/downloads/a2a-solution-studio.zip","checksumPath":"/downloads/a2a-solution-studio.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":21,"verifiedFeatures":["Responsive A2A coordination studio","Official A2A v1 SDK client","JSONRPC and HTTP+JSON negotiation","OAuth-protected A2A client","Transport token non-persistence","Agent Card OAuth contract validation","Offline and live-read profile discovery","All ten live-read command contracts","Exact live-read OAuth scope","Purpose and data-class evidence","One-read authority validation","Provider payload excluded from audit","Credential-free zero-network fixture","Agent Card SHA-256 fingerprint","Advertised-skill and protocol validation","Client-owned message and context identity","Server-assigned task identity","Unknown-outcome context reconciliation","Structured-only command allowlist","Canonical command and artifact digests","Offline authority non-escalation","Live authority non-escalation","Human accept and reject review","Explicit no provider writes","Explicit no production approval","Idempotent commands","Changed-intent replay rejection","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Bounded input and Agent Card","HTTPS outside loopback"]},{"slug":"mcp-identity-lab","name":"MCP Identity Interoperability Lab","description":"Provision, discover, validate, and revoke a remote MCP client through a signed, replay-safe control-plane adapter and a non-issuing OAuth interoperability sandbox.","stack":["Node.js","Signed pre-registration adapter","OAuth discovery validator","Durable audit UI"],"products":["ai-location"],"journey":"Approve → deliver → register → discover → validate → revoke","difficulty":"Advanced","downloadPath":"/downloads/mcp-identity-lab.zip","checksumPath":"/downloads/mcp-identity-lab.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":13,"verifiedFeatures":["Responsive identity boundary explorer","Worker-compatible HMAC-SHA256 envelope","Five-minute signature freshness window","Strict 32 KiB request bound","Secret-shaped field rejection","Public and confidential callback policy","Deterministic non-secret client identity","Signed retry contract compatibility","Exact replay and event conflict handling","Durable signed-event receipts","RFC 9728 protected-resource metadata","RFC 8414 authorization-server metadata","Exact OAuth resource indicator","PKCE S256 request validation","Exact redirect and least-scope checks","No authorization-code or token issuance","Idempotent conformance runs","Typed revocation outcomes","Append-only audit evidence","Atomic file persistence","Restart recovery"]},{"slug":"vision-evidence-desk","name":"Vision Evidence Desk","description":"Lock a SkyDNN model to an immutable asset identity, record a synchronous fixture inference, validate geometry and confidence, review independently, and redact derived detections on schedule.","stack":["Node.js","Responsive review UI","SkyDNN synchronous adapter","Evidence and retention ledger"],"products":["ai-location","gis-analytics","capture-feedback"],"journey":"Register → lock model → infer → validate → review → decide → redact","difficulty":"Advanced","downloadPath":"/downloads/vision-evidence-desk.zip","checksumPath":"/downloads/vision-evidence-desk.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":10,"verifiedFeatures":["Responsive vision-review desk","Public OpenAPI and marketing boundary separation","Synchronous provider contract separated from application workflow","No image body, media URL, credential, face, plate, or internal path input","Opaque asset references and SHA-256 identity","Purpose, lawful-basis, capture-time, and retention gates","Entitled model-discovery fixture","Immutable model fingerprint lock","Idempotent inference attempts","Normalized rectangle, polygon, and polyline validation","Confidence and sensitive-class review policy","Independent reviewer separation of duties","Attributable acceptance and rejection","Derived-output redaction with minimum audit retention","Secret-safe provider failures","Idempotent commands","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Credential-free fixture mode"]},{"slug":"widget-journey-host","name":"Widget Journey Host","description":"Own a complete place-selection journey around a Mappls widget: launch, recover through fallback, normalize a candidate, commit deliberately, invalidate stale selection, and submit exactly once in effect.","stack":["Node.js","Responsive host form UI","Widget message adapter","Durable evidence store"],"products":["app-widgets-deep-links","search-places"],"journey":"Draft → open → candidate → commit → submit","difficulty":"Production pattern","downloadPath":"/downloads/widget-journey-host.zip","checksumPath":"/downloads/widget-journey-host.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":8,"verifiedFeatures":["Responsive widget-host journey","Exact-origin postMessage validation","Versioned candidate schema","Mappls Pin normalization","Opaque provider result rejection","Application-owned durable selection","Useful manual fallback","Stale-selection invalidation after host edits","Deliberate cancellation","Idempotent commands","Optimistic concurrency","Append-only audit events","Transactional outbox","Restart recovery","Credential-free fixture mode"]},{"slug":"deep-link-journey-host","name":"Deep-link & Native UI Journey Host","description":"Run complete direction-planning and geofence-draft lifecycles around Mappls iOS UI adapters, with an exact documented navigation-link fallback and no invented callback or provider publication claim.","stack":["Node.js","Responsive two-lane journey UI","iOS native fixture adapters","Durable evidence store"],"products":["app-widgets-deep-links","routes-navigation","intouch-telematics"],"journey":"Draft → edit → validate → select or review → acknowledge","difficulty":"Production pattern","downloadPath":"/downloads/deep-link-journey-host.zip","checksumPath":"/downloads/deep-link-journey-host.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":11,"verifiedFeatures":["Responsive direction and geofence journey lab","Exact documented Mappls navigation HTTPS fallback","Validated Mappls app URI","Explicit no-return-callback evidence boundary","Versioned host-owned iOS adapter envelopes","Stale editor generation rejection","Immutable route and geometry draft revisions","Route-index and intent-match validation","Navigation request separated from target acceptance","Circle radius and coordinate bounds","Canonical non-crossing polygon validation","SHA-256 geometry identity","Independent geofence reviewer separation of duties","Approved application draft separated from provider publication","No invented geofence deep link or rule identity","Idempotent commands","Cross-aggregate replay rejection","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Credential-free fixture mode"]},{"slug":"place-contribution-desk","name":"Place Contribution Desk","description":"Embed the public Add a Place form, preserve contributor-reported submission as testimony, reconcile independently, and close only with attributable publication evidence.","stack":["Node.js","Responsive operations UI","Add a Place iframe","Reconciliation evidence ledger"],"products":["app-widgets-deep-links","capture-feedback","search-places"],"journey":"Draft → open → report → reconcile → publish, reject, or withdraw","difficulty":"Production pattern","downloadPath":"/downloads/place-contribution-desk.zip","checksumPath":"/downloads/place-contribution-desk.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":8,"verifiedFeatures":["Responsive contribution operations desk","Corrected public iframe query shape","No undocumented submission endpoint","No invented callback or receipt","Contributor testimony separated from provider evidence","Seven explicit lifecycle states","Immutable widget attempts","Mappls Pin evidence validation","Allow-listed evidence sources","Explicit application-side withdrawal boundary","Rejection and immutable retry","Idempotent commands","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Credential-free fixture mode"]},{"slug":"realview-inspection-desk","name":"RealView Inspection Desk","description":"Qualify paid RealView access, open bounded viewer attempts, validate the documented no-imagery signal, record human observations, and require separate review without persisting tokens or imagery.","stack":["Node.js","Responsive inspection UI","RealView Auth2 adapter","Human evidence and review ledger"],"products":["app-widgets-deep-links","maps","capture-feedback"],"journey":"Draft → entitle → view → observe → review → accept or rework","difficulty":"Advanced","downloadPath":"/downloads/realview-inspection-desk.zip","checksumPath":"/downloads/realview-inspection-desk.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":10,"verifiedFeatures":["Responsive remote-inspection desk","Paid-entitlement state separated from application state","No credential or token-bearing URL input","Non-secret entitlement references","Ephemeral token-handle model","Exact Auth2 origin equality","One-field status-204 schema validation","Lookalike-origin rejection","HTTP shell and coverage evidence separation","Immutable viewer attempts","Human observations without provider metadata","No imagery or screenshot persistence","Inspector-reviewer separation of duties","Entitlement expiry recovery","Immutable rework","Idempotent commands","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Credential-free fixture mode"]},{"slug":"offline-release-control","name":"Offline Release Control","description":"Operate an entitled offline or automotive runtime as one compatible, dual-slot release across manufacture, activation, installation, qualification, update, interruption, rollback, and retirement.","stack":["Node.js","Responsive fleet release UI","A/B slot controller","Manifest and qualification ledger"],"products":["offline-automotive","maps","routes-navigation"],"journey":"Manufacture → activate → install → qualify → update → recover → retire","difficulty":"Advanced","downloadPath":"/downloads/offline-release-control.zip","checksumPath":"/downloads/offline-release-control.zip.sha256","implementation":"full-stack-reference","verifiedTestCount":10,"verifiedFeatures":["Responsive fleet release console","Public and local evidence-generation separation","No runtime, map package, binary, license, activation key, credential, or URL input","Non-secret entitlement evidence","Runtime/data/configuration/voice manifest unit","Exact CPU/ABI/OS/graphics compatibility","SHA-256 manifest and component identities","Independent signature and observed-digest attestations","Dual-slot active and known-good invariants","Download, verify, stage, switch, and qualify checkpoints","Seven-lane deterministic qualification suite","Power-loss recovery before atomic switch","Power-loss rollback after switch","Post-qualification regression rollback","Activation expiry and offline-grace gate","Retirement without history deletion","Idempotent commands","Optimistic concurrency","Append-only audit events","Transactional outbox","Atomic restart recovery","Credential-free fixture mode"]}],"useCases":[{"slug":"last-mile-delivery","industry":"Logistics","title":"A delivery promise customers can trust","summary":"Validate addresses, allocate stops, guide drivers, stream progress, and prove completion.","outcome":"Fewer failed deliveries and a live, explainable ETA from checkout to doorstep.","products":["search-places","routes-navigation","intouch-telematics","capture-feedback"],"workflow":["Normalize the destination and retain its Mappls Pin","Optimize stops against capacity and time windows","Navigate with live rerouting","Stream driver and order state","Capture geotagged proof and reconcile exceptions"],"metrics":["First-attempt delivery rate","Cost per stop","ETA error","Distance per order"],"personas":["Checkout customer","Dispatch planner","Driver","Customer-support agent","Transport partner"],"scenario":"At 18:05 a customer places a same-evening grocery order to a loosely formatted apartment address. The promise engine has eight minutes to validate serviceability and a two-hour window; dispatch must combine it with 37 stops, the driver may lose connectivity, and support needs one explainable timeline when the entrance is hard to find.","architecture":[{"title":"Order system of record","description":"Owns order, customer promise, consent, service window, package constraints, payment, and terminal delivery outcome."},{"title":"Location normalization","description":"Search and address services produce candidates; the accepted Mappls Pin becomes the durable destination identity rather than repeatedly geocoding text."},{"title":"Planning and guidance","description":"Route and matrix boundaries sequence eligible stops, preserve route revisions, and provide driver guidance without making the map UI authoritative."},{"title":"Trip evidence","description":"InTouch observations are deduplicated by source identity and event time; ETA revisions and exceptions are derived without rewriting raw telemetry."},{"title":"Customer and operations views","description":"A privacy-reduced tracking projection serves the customer while dispatch/support retain the attributable full journey and proof-review queue."}],"dataContracts":["Order ↔ destination Mappls Pin and acceptance timestamp","Route revision ↔ ordered stop IDs, profile, constraints, provider request identity","Telemetry event ↔ source/event/content identity, event time, receipt time, accuracy","Proof submission ↔ consent purpose, media hashes, location evidence, reviewer decision"],"risks":[{"title":"Ambiguous apartment entrance","recovery":"Offer landmark/entrance candidates, let the customer confirm one stable pin, and preserve the original address plus every selection revision."},{"title":"Driver telemetry goes silent","recovery":"Show last verified progress and age, alert dispatch after policy threshold, and avoid inventing a moving ETA."},{"title":"Provider accepts a route/trip command after timeout","recovery":"Reconcile by idempotency/provider identity before issuing another command or closing locally."}],"rollout":["Pilot address capture and Mappls Pin continuity on one checkout flow","Add matrix-assisted planning in shadow mode and compare against dispatcher choices","Enable one depot with bounded live telemetry and exception ownership","Expose customer ETA only after freshness/error SLOs pass","Scale by region with cost, privacy, support, and failover reviews"]},{"slug":"ride-hailing","industry":"Mobility","title":"A pickup flow that survives the real world","summary":"Find entrances, match riders and drivers, route continuously, and resolve pickup ambiguity.","outcome":"Shorter pickup times with fewer calls, cancellations, and unsafe rendezvous points.","products":["maps","search-places","routes-navigation","intouch-telematics"],"workflow":["Bias search to the rider viewport","Confirm a precise pickup pin and landmark","Match with network-aware ETA","Track approach and reroute","Detect arrival and close the trip"],"metrics":["Pickup ETA","Cancellation rate","Driver idle distance","Pickup support contacts"],"personas":["Rider","Driver","Marketplace dispatcher","Safety operator","Customer support"],"scenario":"At a busy railway station, a rider searches for the station name but the legal vehicle pickup point is 420 metres away. The marketplace must suggest a safe entrance, match a driver by road ETA rather than straight-line distance, guide both parties, and preserve a reviewable record if either disputes arrival.","architecture":[{"title":"Trip marketplace","description":"Owns request, fare, rider/driver identities, eligibility, assignment, cancellation, safety state, and settlement."},{"title":"Pickup intent","description":"Autosuggest and map confirmation resolve human text and viewport context to a precise Mappls Pin with entrance/landmark explanation."},{"title":"ETA matching","description":"A bounded matrix ranks eligible fresh driver positions; marketplace policy adds workload, vehicle, safety, and deterministic tie-breaks."},{"title":"Approach journey","description":"Route revisions and event-time vehicle observations derive progress, rerouting, pickup-zone entry, and freshness."},{"title":"Shared rendezvous experience","description":"Rider and driver receive the same stable pickup identity with role-appropriate directions and a support-visible discrepancy trail."}],"dataContracts":["Ride request ↔ accepted pickup/drop Mappls Pins and selection revisions","Driver candidate ↔ capability, availability, position freshness, matrix ETA","Assignment ↔ aggregate version, chosen explanation, provider route revision","Arrival evidence ↔ event/receipt time, accuracy, zone policy, rider/driver acknowledgement"],"risks":[{"title":"Search resolves the building centre","recovery":"Present signed pickup zones/entrances as candidates and require explicit rider confirmation before matching."},{"title":"Driver location is stale","recovery":"Exclude it from ETA ranking, show marketplace capacity honestly, and request fresh evidence rather than extrapolating indefinitely."},{"title":"Rider and driver disagree on arrival","recovery":"Retain both event streams, accuracy, call/support actions, and apply a versioned human-review policy."}],"rollout":["Instrument current pickup corrections without changing dispatch","Introduce confirmed Mappls Pin pickup at a small set of complex venues","Shadow network-ETA ranking and measure pickup/cancellation outcomes","Enable approach progress and safety operations for one city","Expand only after bias, privacy, driver-experience, and incident reviews"]},{"slug":"field-service","industry":"Utilities","title":"Dispatch the right technician, with the right proof","summary":"Turn outages or service requests into skill-aware, route-efficient field jobs.","outcome":"Higher first-time-fix rates and auditable work from dispatch through customer sign-off.","products":["workmate","routes-navigation","capture-feedback","gis-analytics"],"workflow":["Geocode and classify the service location","Assign by skills, shift, inventory, and ETA","Guide the technician","Collect checklist, image, and signature proof","Analyze repeat faults spatially"],"metrics":["First-time-fix rate","Jobs per shift","SLA compliance","Repeat visit rate"],"personas":["Service requester","Dispatcher","Technician","Proof reviewer","Operations manager"],"scenario":"A utility receives a no-power complaint for a commercial unit. Dispatch must resolve the service point, choose a technician with the correct certification and inventory, survive an offline basement visit, collect readings and imagery, route weak proof to review, and close the job only after the provider and customer records agree.","architecture":[{"title":"Work-order system","description":"Owns customer/service asset, SLA, required skills, inventory, commercial outcome, and the authoritative terminal status."},{"title":"Spatial service context","description":"Search, asset layers, and mGIS context bind the request to a stable service location, access notes, network assets, and hazards."},{"title":"Workmate lifecycle","description":"Provider task identity mirrors explicit create, assign, accept, travel, arrive, prove, review/rework, and close transitions through an outbox/callback boundary."},{"title":"Technician experience","description":"Mobile guidance, offline command queue, checklists, evidence capture, and conflict UI operate under scoped task and consent policy."},{"title":"Operations and analytics","description":"Owned exception/review queues, audit, repeat-fault spatial analysis, and SLA metrics derive from immutable task/evidence history."}],"dataContracts":["Work order ↔ service asset/location ID, SLA, skill and inventory requirements","Assignment ↔ technician eligibility snapshot, ETA evidence, policy version","Offline command ↔ stable idempotency key, expected aggregate version, device time","Proof ↔ immutable submission ID/hash, consent, accuracy, checklist, reviewer decision"],"risks":[{"title":"Technician accepts while another assignment races","recovery":"Use optimistic aggregate versions and one active assignment invariant; surface conflict instead of last-write-wins."},{"title":"Offline commands replay after reassignment","recovery":"Validate actor, task version, and transition preconditions for every queued command; retain rejected evidence."},{"title":"Proof is incomplete","recovery":"Move to named review/rework with reason and a new submission identity; never overwrite the rejected attempt."}],"rollout":["Model task states and audit without provider mutation","Connect one Workmate sandbox team through outbox and signed reconciliation","Pilot offline-safe execution and proof review for one job type","Add skill/ETA-assisted assignment in recommendation mode","Scale with policy versioning, workforce consent, retention, and support certification"]},{"slug":"energy-grid-resilience","industry":"Energy","title":"Restore the grid from alarm to verified service","summary":"Correlate network alarms, weather exposure, switching plans, field crews, and restoration evidence.","outcome":"Faster, safer restoration with an explainable view of affected assets, customers, crews, and residual risk.","products":["gis-analytics","intouch-telematics","workmate","routes-navigation","capture-feedback"],"workflow":["Version the network and hazard context","Correlate alarms into bounded outage incidents","Approve a switching and crew plan","Guide crews and capture field evidence","Reconcile telemetry, customer impact, and restoration"],"metrics":["Customers restored per hour","SAIDI contribution","Crew travel time","Repeat outage rate"],"personas":["Grid control operator","Outage coordinator","Switching authority","Field crew","Customer-impact lead"],"scenario":"A monsoon storm trips feeders across two districts while flood exposure changes road access by the minute. Grid operations must correlate alarms against an exact network version, estimate affected service points, obtain an independently approved switching plan, dispatch capable crews, preserve every field observation, and avoid declaring restoration until telemetry and customer-impact evidence converge.","architecture":[{"title":"Network and hazard authority","description":"The utility system of record owns assets, connectivity, protection settings, switching authority and customer-service relationships; versioned mGIS layers add terrain, flood, access and vegetation context without replacing that authority."},{"title":"Outage correlation","description":"Append-only alarms and calls map to exact network versions and form bounded incidents under a versioned correlation rule with operator correction."},{"title":"Switching and dispatch","description":"An application-owned plan separates electrical safety approval from skill-, equipment- and ETA-aware Workmate assignments; no map or route result authorizes switching."},{"title":"Field execution","description":"Offline-safe tasks, route evidence, asset identity, observations and proof submissions preserve stable command IDs, expected versions and event/receipt time."},{"title":"Restoration reconciliation","description":"Closure requires authoritative device state, switching completion, crew evidence and customer-impact recovery; mismatches remain an owned exception."}],"dataContracts":["Grid asset ↔ topology/configuration version, owner and safety class","Alarm ↔ source/event/content identity, event/receipt time and mapped asset","Switching plan ↔ exact assets, sequence, approver, version and expiry","Crew task ↔ eligibility snapshot, route evidence, provider identity and proof","Restoration ↔ telemetry, customer-impact and operator reconciliation evidence"],"risks":[{"title":"Many alarms collapse onto the wrong feeder","recovery":"Retain each source alarm, topology version and correlation reason; require operator correction and create a new incident revision rather than rewriting prior evidence."},{"title":"A road route crosses a newly flooded segment","recovery":"Append the hazard revision, invalidate the route identity, keep the switching plan separate, and require dispatch to approve a safe replacement."},{"title":"Crew completion arrives before telemetry recovery","recovery":"Keep the task evidence complete but the outage in reconciliation; query authoritative device and customer-impact sources before closure."}],"rollout":["Reconcile one feeder model and its ownership","Replay historical storms through correlation in shadow mode","Pilot approved switching plus offline crew evidence","Require multi-source restoration reconciliation in one district","Expand after electrical-safety, privacy, resilience, workforce and regulatory review"]},{"slug":"retail-expansion","industry":"Retail","title":"Choose the next store with evidence","summary":"Combine catchments, demographics, competition, access, and existing performance.","outcome":"Faster site screening and investment decisions grounded in a reusable spatial model.","products":["gis-analytics","search-places","maps"],"workflow":["Publish candidate sites and performance data","Generate drive-time catchments","Join demand and competition signals","Score and compare candidates","Share an executive decision map"],"metrics":["Forecast accuracy","Cannibalization risk","Time to shortlist","Revenue per catchment"],"personas":["Expansion analyst","GIS data steward","Real-estate manager","Finance reviewer","Executive approver"],"scenario":"A retailer is comparing 60 candidate neighbourhoods for 12 stores. Analysts must combine travel-time catchments, competition, demographics, access and existing performance, explain every score, prevent data drift between committee meetings, and revoke a shared decision view after the acquisition window closes.","architecture":[{"title":"Enterprise data products","description":"Own approved store performance, candidate, demand, competition and financial datasets with source, license, observation date and steward."},{"title":"mGIS version registry","description":"Publishes immutable spatial dataset versions with content hash, schema, CRS, validation diagnostics and access policy."},{"title":"Analysis engine","description":"Creates parameterized catchments, joins exact input versions, normalizes signals and writes immutable scoring attempts and lineage."},{"title":"Analyst decision lab","description":"Compares candidates, sensitivity and exclusions without mutating source evidence; comments and selections name result revisions."},{"title":"Governed sharing","description":"Audience, expiry, export/embed rules, executive narrative and revocation wrap one immutable result rather than an untraceable screenshot."}],"dataContracts":["Dataset version ↔ source/license/date/schema/CRS/content hash","Catchment attempt ↔ route profile, threshold, input versions, engine version","Score attempt ↔ normalization, weights, exclusions, ties, output hash","Share ↔ result revision, audience, expiry, export/embed policy, revocation"],"risks":[{"title":"Demographic feed changes mid-analysis","recovery":"Publish a new immutable input version and rerun; retain both result revisions and prevent silent replacement."},{"title":"Candidate geometry has the wrong CRS","recovery":"Fail before processing with feature-level diagnostics and require a corrected dataset version."},{"title":"Executive link is forwarded","recovery":"Enforce audience/expiry, log access, prohibit export where required, and revoke the share without deleting lineage."}],"rollout":["Inventory and classify source datasets and licenses","Reproduce one historical store decision from immutable versions","Run model beside the existing spreadsheet for one region","Add governed collaboration and sensitivity review","Promote only after finance, data governance, fairness, and forecast back-testing"]},{"slug":"banking-address-risk","industry":"Financial services","title":"Make address risk explainable","summary":"Standardize applications, verify presence, enrich geography, and route cases for review.","outcome":"More straight-through approvals with a clear audit trail for ambiguous or high-risk addresses.","products":["search-places","capture-feedback","gis-analytics"],"workflow":["Normalize the entered address","Compare declared and captured locations","Join serviceability and risk zones","Score confidence with reasons","Escalate only unresolved cases"],"metrics":["Straight-through processing","False-positive review rate","Verification turnaround","Fraud loss"],"personas":["Applicant","Onboarding service","Risk analyst","Manual reviewer","Compliance auditor"],"scenario":"A small-business applicant enters an informal address and consents to a device-location check. The bank must normalize the address, compare accuracy-bearing evidence, join serviceability/risk geography, auto-approve only strong cases, redact precise evidence on schedule, and still explain the decision years later.","architecture":[{"title":"Onboarding system","description":"Owns application, declared address, consent, KYC identity, product eligibility, decision and regulatory retention."},{"title":"Address normalization","description":"Search/standardization returns candidates and a selected Mappls Pin with source provenance rather than a rewritten string presented as certainty."},{"title":"Evidence service","description":"Captures consented device fix, accuracy, event/receipt time and content hash separately from reverse-geocoded label."},{"title":"Risk policy engine","description":"Joins versioned zones and computes explainable features under a named policy; weak/contradictory evidence enters manual review."},{"title":"Audit and privacy controls","description":"Preserve input/policy/decision lineage while access controls, purpose limits and redaction remove precise data when no longer required."}],"dataContracts":["Declared address ↔ original text, normalized candidates, chosen Mappls Pin","Device evidence ↔ consent/purpose, coordinate, accuracy, times, source, hash","Risk enrichment ↔ zone dataset versions and feature values","Decision ↔ policy version, evidence IDs, reasons, reviewer and redaction state"],"risks":[{"title":"Device fix is weak or unavailable","recovery":"Do not infer presence; continue with alternate evidence or manual review and record the reason."},{"title":"Address and device evidence disagree","recovery":"Retain both, calculate distance under a versioned policy, and prohibit automated override of a reviewer rejection."},{"title":"Precise evidence reaches retention limit","recovery":"Redact payload while retaining hash, coarse result, consent/decision lineage and attributable deletion event."}],"rollout":["Normalize addresses and measure candidate ambiguity","Capture consent/evidence in shadow mode with no decision impact","Back-test a versioned policy against reviewed cases","Pilot reviewer tooling and redaction workflow","Enable bounded automation only after compliance, bias, security, and model-risk approval"]},{"slug":"insurance-claims","industry":"Insurance","title":"Evidence-led claims from incident to settlement","summary":"Capture location and imagery, use governed vision triage, dispatch assessors, and understand catastrophe exposure.","outcome":"Faster, more consistent claims decisions with tamper-aware spatial evidence.","products":["capture-feedback","ai-location","workmate","gis-analytics","routes-navigation"],"workflow":["Record consented incident location","Capture guided photo evidence","Run model-locked vision triage with human review bands","Dispatch an assessor when needed","Overlay hazard and policy context","Preserve decision lineage and redaction"],"metrics":["Settlement time","Assessor travel","Evidence completeness","Leakage rate"],"personas":["Policyholder","Claims intake","Assessor","Fraud analyst","Catastrophe manager"],"scenario":"After a severe storm, a policyholder submits vehicle-damage images and location evidence. The insurer must guide capture, detect missing or contradictory context without overclaiming authenticity, run model-locked vision triage with human review, dispatch scarce assessors by eligibility and ETA, join hazard exposure, and retain explainable evidence through settlement and appeal.","architecture":[{"title":"Claims system","description":"Owns policy, claimant, incident declaration, coverage, reserves, decisions, settlement and appeal."},{"title":"Consented capture and vision boundary","description":"Collects guided media, device/location accuracy, timestamps, hashes, capture policy and disclosure; an entitled SkyDNN adapter locks model identity, validates bounded derived geometry and confidence, and never treats metadata or inference as proof by itself."},{"title":"Spatial enrichment","description":"Normalizes incident place, joins versioned hazard/catastrophe layers and links every feature to its source and observation window."},{"title":"Assessment operations","description":"Routes incomplete, uncertain, sensitive, or high-risk claims to independent review and capable assessors, ranks eligible teams by network ETA and tracks field-task proof."},{"title":"Decision evidence","description":"Policy engine and reviewer actions name exact submissions, enrichments, model fingerprints, rule versions and reasons; later evidence creates a revision and retention policy redacts derived detections without erasing audit."}],"dataContracts":["Claim ↔ declared incident place and policy coverage snapshot","Evidence submission ↔ immutable media hashes, consent, times, accuracy, device/source","Vision attempt ↔ model fingerprint, asset hash, bounded detections, confidence, review policy","Hazard feature ↔ dataset/version, geometry relation, observation date","Assessment decision ↔ evidence IDs, rule/model version, reviewer, settlement revision"],"risks":[{"title":"Media upload partially succeeds","recovery":"Use per-object hashes and a submission manifest; keep the claim incomplete until all required evidence commits."},{"title":"Vision result is uncertain or sensitive","recovery":"Preserve model and input identities, route to an independent reviewer, and prohibit automatic settlement or fraud decisions."},{"title":"Location metadata conflicts with declaration","recovery":"Preserve both sources, lower automation confidence and route to review rather than silently choosing one."},{"title":"Catastrophe data is revised","recovery":"Publish a new dataset/version and derived claim revision without rewriting the evidence used in the original decision."}],"rollout":["Start with guided completeness checks only","Add entitled fixture-first vision triage with model provenance and mandatory review bands","Add spatial hazard enrichment with analyst-visible lineage","Pilot assessor eligibility/ETA recommendations","Introduce versioned triage rules with independent reviewer separation","Scale after consent, fraud, model-risk, fairness, retention, catastrophe, and appeal audits"]},{"slug":"hospital-care-logistics","industry":"Healthcare","title":"Coordinate time-critical care without losing custody","summary":"Resolve facilities and entrances, dispatch suitable transport, track hand-offs, and preserve privacy-minimized care logistics evidence.","outcome":"Shorter transfer and specimen journeys with fewer missed hand-offs and a complete chain of operational custody.","products":["search-places","routes-navigation","intouch-telematics","capture-feedback","gis-analytics"],"workflow":["Resolve the correct facility, campus, and entrance","Select an eligible vehicle and bounded route","Track custody and freshness through every hand-off","Escalate delay or temperature exceptions","Reconcile arrival, acceptance, and retained evidence"],"metrics":["Door-to-door transfer time","On-time specimen delivery","Custody exceptions","Privacy incidents"],"personas":["Transfer coordinator","Ambulance dispatcher","Driver or courier","Receiving clinician","Privacy and quality reviewer"],"scenario":"A district hospital needs to transfer a patient to a tertiary campus while a laboratory specimen travels separately under a strict stability window. The coordinator must resolve the correct clinical entrance, choose eligible transport, retain custody at every hand-off, detect route and temperature delay, reveal only the minimum operational location, and close each journey only after the receiving team accepts it.","architecture":[{"title":"Clinical and laboratory systems","description":"Authoritative systems own patient or specimen identity, clinical priority, consent, custody policy, stability window and receiving acceptance; the location workflow stores only opaque operational references."},{"title":"Facility and entrance resolution","description":"Search and governed campus data resolve a stable Mappls Pin or enterprise entrance identity while preserving candidate, confirmer and revision evidence."},{"title":"Eligibility and dispatch","description":"Application policy filters vehicle, equipment, staff, service area and availability before network ETA ranks eligible options."},{"title":"Privacy-minimized journey","description":"Event-time vehicle and custody observations derive progress and exceptions; role projections withhold clinical content and unnecessary precise history."},{"title":"Acceptance and quality review","description":"Every hand-off is versioned and attributable; arrival is not completion until the authorized receiver accepts the matching custody identity."}],"dataContracts":["Transfer ↔ opaque clinical reference, priority, consent and accepted entrance","Transport assignment ↔ eligibility snapshot, vehicle, route revision and expiry","Custody event ↔ item reference, from/to role, event/receipt time and acknowledgement","Condition exception ↔ sensor/source identity, threshold policy and reviewer outcome","Completion ↔ arrival evidence, receiver acceptance and retained audit policy"],"risks":[{"title":"Search selects the public entrance instead of emergency receiving","recovery":"Present approved campus entrances as explicit candidates, require coordinator confirmation, and retain the original query and selection revision."},{"title":"Location or condition evidence becomes stale","recovery":"Show last verified time and source, alert the responsible coordinator, and stop projecting an invented ETA or safe-condition claim."},{"title":"The receiver cannot match the custody identity","recovery":"Keep the journey at arrived-but-unaccepted, preserve both observations and escalate through a human reconciliation queue without exposing clinical data."}],"rollout":["Govern facility and entrance identities without patient data","Run fixture transfers with complete custody events","Pilot one non-emergency specimen lane with bounded telemetry","Add patient transfer only after clinical and privacy approval","Scale after accessibility, consent, retention, downtime, safety and quality drills"]},{"slug":"emergency-response","industry":"Public safety","title":"Route coordinated response under pressure","summary":"Resolve caller location, find capable resources, route around incidents, and maintain a common picture.","outcome":"Reduced time to scene and safer decisions across dispatch, responders, and command.","products":["search-places","routes-navigation","intouch-telematics","gis-analytics"],"workflow":["Resolve location from address, pin, or device","Find eligible nearby responders","Route with vehicle constraints","Track units and changing hazards","Replay the incident for review"],"metrics":["Call-to-dispatch time","Arrival time","Unit utilization","Coverage gaps"],"personas":["Caller","Emergency call taker","Dispatcher","Responder","Incident commander"],"scenario":"A caller reports a road collision near an informal landmark while multiple units are returning from other incidents. The control room must resolve location confidence, choose capable available responders using fresh positions and vehicle-aware ETA, update routes around hazards, prevent double dispatch, prove arrival, and replay the incident for review.","architecture":[{"title":"CAD incident record","description":"Owns call, incident identity, priority, location revisions, assigned resources, hazards, resolution and review."},{"title":"Location resolution","description":"Combines address, landmark, Mappls Pin and consented device evidence while retaining candidates, confidence and human confirmation."},{"title":"Resource and route service","description":"Filters capability/availability/jurisdiction first, then uses matrix/route evidence with freshness and deterministic dispatch policy."},{"title":"Live coordination","description":"Ingests event-time unit telemetry and hazard revisions, derives progress and arrival evidence, and blocks one unit from two active incidents."},{"title":"Command and review","description":"Role-specific views, immutable actions, communication references, late evidence and outcome metrics support command and after-action review."}],"dataContracts":["Incident location ↔ revision, source, confidence, confirmer","Unit eligibility ↔ capability, availability, jurisdiction, telemetry freshness","Dispatch ↔ matrix evidence, route revision, expected aggregate versions","Arrival/resolution ↔ objective evidence, actor, times, open-hazard/exception checks"],"risks":[{"title":"Caller description produces multiple locations","recovery":"Show ranked candidates and confidence to the call taker; record confirmation and every revision."},{"title":"Unit position is stale","recovery":"Exclude from automated ranking or mark ETA unavailable; request fresh evidence and let an accountable dispatcher decide."},{"title":"Hazard changes after dispatch","recovery":"Append a hazard revision, compute a new route identity, notify assigned units and retain both plans."}],"rollout":["Replay historical incidents through location-resolution tooling","Shadow capability/matrix recommendations beside dispatchers","Pilot one incident class with unit telemetry and double-dispatch protection","Add hazard rerouting and objective arrival policy","Expand only after safety case, resilience, accessibility, training, privacy and regulator review"]},{"slug":"smart-city-operations","industry":"Government","title":"A living operations map for the city","summary":"Unify assets, incidents, crews, citizen feedback, and long-term spatial analysis.","outcome":"One governed view from daily operations to infrastructure investment planning.","products":["gis-analytics","workmate","intouch-telematics","maps"],"workflow":["Catalog authoritative layers","Ingest live assets and citizen reports","Dispatch and monitor work","Publish role-specific dashboards","Analyze hotspots and service equity"],"metrics":["Resolution time","Asset downtime","Repeat incidents","Ward-level service equity"],"personas":["Citizen","Control-room operator","Department dispatcher","Field crew","City data steward"],"scenario":"A city receives reports of waterlogging, failed streetlights and waste overflow across different channels. It needs one governed map without collapsing department ownership, must deduplicate related reports, dispatch the correct crew, preserve citizen privacy, publish honest status, and analyze service equity using versioned ward and asset data.","architecture":[{"title":"Department systems of record","description":"Retain authoritative assets, work orders, ownership and service outcomes; the map does not become an ungoverned replacement master."},{"title":"Spatial data catalogue","description":"mGIS registers layers, schemas, CRS, stewards, update cadence, license/sensitivity and immutable versions."},{"title":"Event correlation","description":"Normalizes citizen reports and sensor alarms, preserves each source, and derives bounded incident clusters under a versioned rule."},{"title":"Work orchestration","description":"Creates department-specific tasks, routes capable crews, tracks progress/proof and reconciles closure to the owning system."},{"title":"Role and public projections","description":"Control room, department, executive and public views apply distinct access, aggregation, delay, accessibility and disclosure policy."}],"dataContracts":["Layer ↔ steward, source, schema, CRS, sensitivity, version","Report/alarm ↔ source identity, consent, event/receipt time, coarse/public projection","Derived incident ↔ member evidence IDs and correlation policy version","Work order ↔ owning department, asset, SLA, task/provider identity, closure proof"],"risks":[{"title":"Two departments claim the same incident","recovery":"Keep one coordinating incident with explicit owning/participating work orders; never transfer authority by map edit alone."},{"title":"Citizen report contains precise personal data","recovery":"Restrict raw evidence, derive a coarse operational/public location and apply purpose-specific retention/redaction."},{"title":"Public status lags internal resolution","recovery":"Version projections, display freshness, alert on reconciliation delay and correct with an attributable update."}],"rollout":["Catalogue high-value layers and authoritative owners","Unify read-only incident views for one ward","Add one department's task lifecycle and reconciliation","Introduce cross-channel correlation with human confirmation","Publish privacy/accessibility-reviewed public status and equity metrics before citywide expansion"]},{"slug":"connected-vehicle","industry":"Automotive","title":"Navigation built for intermittent connectivity","summary":"Ship an activated, updateable in-vehicle navigation lifecycle with online enhancement.","outcome":"Reliable guidance across coverage gaps without giving up traffic, search freshness, or safety.","products":["offline-automotive","routes-navigation","search-places","intouch-telematics"],"workflow":["Activate the head unit","Install compatible signed regional data","Plan and guide offline","Blend online traffic and search when available","Stage atomic map and runtime updates"],"metrics":["Route success offline","Guidance crash-free rate","Update adoption","Search success"],"personas":["Driver","Vehicle head unit","OEM cloud","Map-data operator","Dealer/support engineer"],"scenario":"A vehicle crosses a long connectivity gap after receiving a regional data update the night before. Navigation must boot with a compatible signed offline package, plan and guide locally, blend online traffic/search when available, protect driver attention, and recover automatically if the new package or runtime is unhealthy.","architecture":[{"title":"Vehicle/OEM identity","description":"Owns hardware, market/region, entitlement, runtime compatibility, privacy/consent, activation and update campaign."},{"title":"Dual-slot offline runtime","description":"Maintains one active and one staged signed package, atomic activation pointer, health acknowledgement and rollback evidence."},{"title":"Local navigation","description":"Search index, routing graph, guidance and map rendering operate without network under pinned runtime/data/profile versions."},{"title":"Online enhancement","description":"Trusted cloud boundary adds fresh search, traffic and telemetry only when entitled and available; responses carry freshness/provenance."},{"title":"Fleet operations","description":"Campaign, download, verification, activation, health, rollback and support diagnostics are stateful journeys with aggregate metrics."}],"dataContracts":["Vehicle manifest ↔ hardware/runtime/region/entitlement versions","Data package ↔ epoch, region, size, content/signature hash, compatibility","Route session ↔ offline/online sources, profile, data/traffic versions","Update event ↔ campaign, stage, evidence, event/receipt time, health/rollback outcome"],"risks":[{"title":"Power loss during update","recovery":"Write only the inactive slot and switch one atomic pointer after verification; boot always finds a previously acknowledged package."},{"title":"Online traffic disappears mid-route","recovery":"Keep guiding from the last valid local route, mark traffic freshness and avoid blocking safety-critical guidance."},{"title":"New package boots but fails route smoke test","recovery":"Fail health acknowledgement, restore the prior slot and upload privacy-safe diagnostics when connectivity returns."}],"rollout":["Prove offline boot/search/route on target hardware","Add signed dual-slot package staging and power-loss tests","Pilot online search/traffic as optional enhancement","Run canary update campaigns with automatic rollback","Scale after driver-distraction, functional-safety, privacy, cybersecurity and dealer-support approval"]},{"slug":"aviation-ground-operations","industry":"Aviation","title":"Run a safe, punctual airport turnaround","summary":"Coordinate stands, service vehicles, restricted zones, inspections, and turnaround milestones on one governed operating picture.","outcome":"More predictable departures with safer vehicle movement and attributable hand-offs across airport and airline teams.","products":["gis-analytics","intouch-telematics","workmate","maps","capture-feedback"],"workflow":["Publish the approved airside network and restricted zones","Create one versioned turnaround plan","Track eligible vehicles and milestone hand-offs","Capture inspection and exception evidence","Reconcile departure readiness across authorities"],"metrics":["On-time departure","Turnaround milestone variance","Airside safety exceptions","Ground-equipment utilization"],"personas":["Turnaround coordinator","Airport operations controller","Ground-service team","Airline station manager","Safety investigator"],"scenario":"A delayed inbound aircraft changes stand while fuel, catering, baggage and inspection teams are already moving. The airport must publish the current approved airside network, re-plan one versioned turnaround, prevent vehicles entering restricted or closed areas, preserve each milestone hand-off, and avoid declaring departure-ready until airline, airport and safety authorities agree.","architecture":[{"title":"Airport operational authority","description":"Airport and airline systems own stands, movement permissions, flight milestones, safety zones, people, equipment and departure decisions; Mappls-derived experiences do not grant aviation or airside authority."},{"title":"Versioned spatial operating picture","description":"Governed enterprise layers publish stands, service roads, closures, restricted zones and emergency access with source, steward, CRS, sensitivity and effective window."},{"title":"Turnaround aggregate","description":"One application-owned plan versions stand, tasks, dependencies, target milestones, responsible organizations and changes after disruption."},{"title":"Ground-team execution","description":"Workmate tasks and bounded vehicle observations track accepted assignments, corridor adherence, evidence, pauses and exceptions with offline-safe command identity."},{"title":"Readiness reconciliation","description":"Every required authority submits attributable milestone evidence; the coordinator derives readiness but never overwrites an authority's source record."}],"dataContracts":["Airside layer ↔ authority, version, effective window, sensitivity and closure state","Turnaround ↔ flight/stand references, milestone graph, version and accountable coordinator","Task ↔ organization, eligibility, equipment, zone policy and evidence","Vehicle event ↔ device/assignment identity, event/receipt time and approved-network version","Readiness ↔ required authority decisions, unresolved exceptions and final revision"],"risks":[{"title":"Stand changes after teams accept tasks","recovery":"Create a new turnaround revision, invalidate incompatible assignments and corridor evidence, and require explicit reacceptance rather than mutating in place."},{"title":"A vehicle appears outside its approved corridor","recovery":"Preserve accuracy and network version, alert operations, stop affected automation and require safety review; never infer culpability from a point alone."},{"title":"One supplier reports complete while another dependency is open","recovery":"Keep the supplier milestone complete but departure readiness blocked, showing the exact dependency and responsible authority."}],"rollout":["Catalogue airside layers and source authorities","Simulate one turnaround and disruption with synthetic identities","Pilot read-only milestone coordination at one stand","Add approved vehicle/task evidence under safety oversight","Scale only after airport, airline, regulator, cybersecurity, privacy and degraded-mode approval"]},{"slug":"travel-discovery","industry":"Travel","title":"Turn inspiration into an itinerary","summary":"Help travelers discover, sequence, visualize, and open rich place experiences.","outcome":"More confident trip planning and higher conversion from discovery to booking.","products":["search-places","maps","app-widgets-deep-links","routes-navigation"],"workflow":["Discover places by theme and proximity","Build a time-aware itinerary","Visualize routes and neighborhoods","Embed 3D or RealView context","Hand off to navigation"],"metrics":["Save-to-book rate","Itinerary completion","Search refinement","Navigation hand-offs"],"personas":["Traveler","Travel-content editor","Booking partner","Product merchandiser","Customer support"],"scenario":"A family planning a three-day city break saves attractions from editorial stories, nearby search and partner inventory. The product must preserve place identity across languages and sources, sequence a feasible itinerary, show neighbourhood and RealView context, avoid stale opening assumptions, and hand off to booking/navigation without losing the selected place.","architecture":[{"title":"Travel content and inventory","description":"Own editorial collections, commercial availability, pricing, disclosures and booking outcome while mapping every item to a stable place identity."},{"title":"Place discovery","description":"Search/nearby and curated sources resolve to Mappls Pins with provenance, language/display labels and duplicate reconciliation."},{"title":"Itinerary aggregate","description":"Owns ordered saved place IDs, day/time constraints, route revisions, visits/skips, sharing and deliberate cancellation."},{"title":"Map and rich context","description":"Renders routes, neighbourhoods, 3D/RealView or deep-linked experiences with accessible alternatives and explicit freshness."},{"title":"Partner hand-off","description":"Booking and navigation links bind place/offer identity, allow-list campaign data and distinguish click from confirmed downstream outcome."}],"dataContracts":["Travel item ↔ Mappls Pin, editorial/partner IDs, language and provenance","Itinerary ↔ ordered stable IDs, constraints, version and route revision","Place fact ↔ source and observation/freshness timestamp","Hand-off ↔ destination/offer identity, safe campaign fields, fallback and observed stage"],"risks":[{"title":"Two sources describe the same attraction","recovery":"Reconcile through stable place identity and retain source-specific content/availability rather than merging by name."},{"title":"Opening or availability data is stale","recovery":"Show source/time, confirm with the authoritative partner and avoid routing a day as guaranteed feasible."},{"title":"Navigation app is absent","recovery":"Use an HTTPS fallback that preserves the destination and offers browser navigation or store choice without redirect loops."}],"rollout":["Introduce stable Mappls Pin saves across existing discovery","Build a restart-safe ordered itinerary with fixture routing","Add route revisions and stale-plan invalidation","Pilot rich context and safe partner/deep-link hand-offs","Scale after content licensing, accessibility, partner attribution, privacy and conversion-incrementality review"]},{"slug":"agriculture-field-ops","industry":"Agriculture","title":"Coordinate field operations across every plot","summary":"Map parcels, schedule crews, track equipment, and compare observations over time.","outcome":"Less travel and better traceability for inspection, inputs, harvest, and compliance.","products":["gis-analytics","workmate","intouch-telematics","capture-feedback"],"workflow":["Publish parcel boundaries","Create seasonal field tasks","Optimize crews and equipment","Capture geotagged observations","Analyze yield and issue patterns"],"metrics":["Area serviced per day","Input variance","Equipment utilization","Issue recurrence"],"personas":["Farm manager","Agronomist","Field worker","Equipment operator","Compliance auditor"],"scenario":"A cooperative must inspect hundreds of plots before monsoon planting, route teams across poor connectivity, track shared equipment, capture geotagged observations under farmer consent, prevent reports from being assigned to the wrong parcel, and compare issue recurrence without exposing precise farm data broadly.","architecture":[{"title":"Farm/parcel registry","description":"Owns farmer relationship, parcel identity, consent, crop/season and authorized users; geometry versions are governed spatial assets."},{"title":"Seasonal planning","description":"Creates plot-specific work and inspection requirements, skills, windows, inputs and equipment eligibility."},{"title":"Offline field execution","description":"Mobile tasks, map packages, ordered commands and evidence manifests survive connectivity gaps with stable idempotency and versions."},{"title":"Equipment telemetry","description":"InTouch device observations derive utilization and exceptions by event time without replacing operator or maintenance records."},{"title":"Spatial agronomy analysis","description":"Joins exact parcel/evidence/weather/input versions, applies access controls and produces coarse shared insights with lineage."}],"dataContracts":["Parcel ↔ stable ID, geometry version, CRS, farmer consent and season","Task ↔ parcel/version, policy, assignee/equipment, offline command IDs","Observation ↔ evidence hash, accuracy, event/receipt time, source and reviewer","Analysis ↔ input versions, parameters, agronomist decision and audience policy"],"risks":[{"title":"Observation falls near a parcel boundary","recovery":"Retain accuracy and candidate parcels, require field-worker confirmation or review, and never snap silently."},{"title":"Offline task was reassigned","recovery":"Reject stale actor/version commands on sync, retain evidence and route it to an accountable reconciliation queue."},{"title":"Equipment telemetry is shared across farms","recovery":"Scope events to authorized device/time/operation assignments and prevent cross-farm projections at the data boundary."}],"rollout":["Govern parcel identities, geometry versions and consent","Pilot offline inspection for one crop and region","Add equipment utilization with explicit assignment boundaries","Build reproducible recurrence analysis for agronomists","Expand after farmer privacy, language/accessibility, agronomic validation and offline-support readiness"]},{"slug":"mining-haulage-safety","industry":"Mining","title":"Move material safely across a changing mine","summary":"Version haul roads and exclusion zones, dispatch compatible equipment, track cycles, and reconcile safety and production evidence.","outcome":"Higher productive haulage with fewer route conflicts, stale-map movements, and unexplained cycle losses.","products":["gis-analytics","intouch-telematics","workmate","offline-automotive","capture-feedback"],"workflow":["Publish the approved pit, road, and exclusion-zone version","Assign compatible equipment and operators","Guide and observe offline-capable haul cycles","Stop and review safety or geofence exceptions","Reconcile tonnes, cycles, maintenance, and shift closure"],"metrics":["Tonnes per operating hour","Cycle-time variance","Geofence exceptions","Unplanned equipment idle time"],"personas":["Mine dispatcher","Pit supervisor","Haul-truck operator","Geotechnical engineer","Safety and production reviewer"],"scenario":"A blast changes the active pit and closes a ramp midway through a shift. Dispatch must publish the newly approved road and exclusion-zone version, reassign compatible trucks and loaders, guide offline-capable cycles, distinguish telemetry delay from a stopped vehicle, preserve safety interventions, and reconcile production only from accepted load and dump evidence.","architecture":[{"title":"Mine plan and safety authority","description":"The mine system of record owns surveyed geometry, blast areas, geotechnical restrictions, road classes, equipment compatibility and operating authorization."},{"title":"Versioned offline map release","description":"Approved pit, road, zone and configuration manifests move through signed dual-slot qualification and rollback before vehicles activate them."},{"title":"Dispatch aggregate","description":"Application state owns shift, equipment/operator assignments, load/dump targets, priorities, expected versions and deliberate cancellation."},{"title":"Haul-cycle evidence","description":"InTouch observations and offline commands derive travel, queue, load and dump stages by event time while keeping raw source identity and freshness."},{"title":"Safety and production reconciliation","description":"Geofence or route exceptions stop automatic progress and require human review; tonnes and cycles close only against authoritative scale and dispatch evidence."}],"dataContracts":["Mine map package ↔ survey/version, region, signature, compatibility and approval","Assignment ↔ equipment/operator capability, shift, plan version and expected aggregate version","Cycle event ↔ source/content identity, event/receipt time, map version and stage","Safety exception ↔ zone/rule version, accuracy, intervention and reviewer decision","Production result ↔ accepted load/dump identities, tonnes, shift and reconciliation status"],"risks":[{"title":"A truck wakes with the previous pit map","recovery":"Block the changed operating zone, retain the compatible prior slot for recovery, and require a qualified signed update before dispatch."},{"title":"Telemetry silence looks like an idle vehicle","recovery":"Separate freshness from motion state, show last verified evidence, and ask dispatch to reconcile rather than charging productive-time loss automatically."},{"title":"Duplicate dump evidence inflates tonnes","recovery":"Deduplicate by source/content and cycle identity, reject conflicting replays, and reconcile against the authoritative scale record."}],"rollout":["Version one pit and equipment compatibility matrix","Prove offline package update and rollback on representative hardware","Run haul cycles in shadow mode with event-time reconciliation","Pilot safety exception review and authoritative scale matching","Expand after geotechnical, functional-safety, workforce, cyber, environmental and emergency-response approval"]},{"slug":"telecom-network-care","industry":"Telecommunications","title":"Operate the network from tower to doorstep","summary":"Link network assets, alarms, field teams, and customer impact spatially.","outcome":"Faster restoration with better prioritization and fewer repeat dispatches.","products":["gis-analytics","workmate","routes-navigation","capture-feedback"],"workflow":["Model towers, links, cabinets, and service areas","Correlate alarms with impacted customers","Create skill-aware repair tasks","Navigate and capture repair proof","Analyze chronic failure clusters"],"metrics":["Mean time to repair","Customers restored per action","Truck rolls","Repeat alarm rate"],"personas":["Network operations engineer","Alarm correlator","Field dispatcher","Technician","Customer-impact manager"],"scenario":"A fibre cut triggers alarms across cabinets and cell sites while customers report outages. Operations must correlate evidence to the affected topology, estimate customer impact, create skill/tool/access-aware repair work, route teams around road disruption, capture splice/test proof, and avoid declaring restoration until network telemetry and customer-impact projections reconcile.","architecture":[{"title":"Network inventory/topology","description":"Owns towers, fibre, links, cabinets, service areas, dependencies, maintenance windows and authoritative asset versions."},{"title":"Alarm and impact correlation","description":"Appends source alarms, maps them to exact inventory versions and derives incidents/affected customers under a versioned topology rule."},{"title":"Repair orchestration","description":"Creates Workmate tasks with skill, tools, access, safety and SLA requirements; eligible teams are ranked by fresh network ETA."},{"title":"Field evidence","description":"Offline-safe guidance, asset identity, images/readings/test results and reviewer decisions produce an immutable repair timeline."},{"title":"Restoration reconciliation","description":"Requires network alarm clearance, task proof and impact recovery before closure; chronic clusters derive from versioned evidence."}],"dataContracts":["Network asset ↔ topology/inventory version, geometry and owner","Alarm ↔ source/event/content identity, event/receipt time, mapped asset","Impact projection ↔ topology rule/version and affected service IDs/counts","Repair ↔ task/provider identity, required capability, evidence and restoration checks"],"risks":[{"title":"Many alarms represent one fibre cut","recovery":"Preserve every alarm, derive one incident using a versioned topology/correlation rule and allow operator correction."},{"title":"Inventory geometry/topology is stale","recovery":"Mark confidence, route to data-steward correction and never rewrite prior incident lineage after the new version."},{"title":"Technician closes before alarms clear","recovery":"Keep work proof submitted but incident in reconciliation; query authoritative telemetry and escalate mismatches."}],"rollout":["Reconcile inventory layers and data ownership","Replay historical outages through correlation in shadow mode","Pilot skill/ETA dispatch and immutable field proof","Require multi-source restoration reconciliation for one region","Scale after NOC runbooks, topology quality, safety, workforce, customer-communication and failover drills"]}],"endpoints":{"generatedAt":"2026-08-17T11:44:25Z","summary":{"operations":162,"families":7,"sourceFiles":67,"methods":{"GET":88,"POST":63,"DELETE":10,"PUT":1},"stateModels":{"stateless":22,"stateful":119,"hybrid":21},"sampleCount":810},"href":"/api/contracts"},"reference":{"generatedAt":"2026-08-18T03:05:03.406Z","summary":{"guides":82,"withSourceDocuments":79,"withReadmes":76,"withCodeSamples":50,"codeSamples":447,"kinds":{"Deep link":1,"Distribution":34,"Guide":7,"REST API":9,"SDK":24,"Sample":4,"Widget":3}},"href":"/api/reference"},"sources":{"generatedAt":"2026-08-18T03:05:03.406Z","summary":{"publicRepositories":82,"publicReadmes":76,"publicSourceDocuments":79,"upstreamEmptyRepositories":3,"localRepositories":81,"localDocuments":15437,"extractedEndpoints":4041,"codeLanguages":["Bash","C","C#","C++","CSS","Dart","Groovy","HTML","HTTP","JSON","JSX","Java","JavaScript","Kotlin","Mermaid","Objective-C","PowerShell","Python","Ruby","SQL","Swift","TOML","Text","TypeScript","XML","YAML","cURL"],"productAreas":{"ai-vision":34,"capture-feedback":91,"gis-analytics":89,"identity-platform":100,"maps":109,"offline-automotive":70,"other":51,"routes-navigation":93,"search-places":103,"tracking-telematics":97,"widgets-deep-links":86,"workforce":37},"platforms":{"AI/MCP":37,"Android":52,"Automotive":43,"Cordova/Ionic":11,"Flutter":7,"Linux/Embedded":28,"REST":75,"React Native":15,"Server/Compiler":90,"Unspecified":60,"Web":99,"Widgets/Deep links":76,"Xamarin/.NET":48,"iOS":82},"stateModels":{"stateless":111,"hybrid":13,"stateful":39},"maturity":{"current":64,"legacy":24,"deprecated":15,"sample":26,"distribution":34}},"href":"/api/sources"},"repositoryReconciliation":{"href":"/sources/reconciliation","api":"/api/reconciliation","summary":{"generatedAt":"2026-08-18T03:04:05.659Z","publicRepositories":82,"localRepositories":81,"exactMatches":22,"normalizedMatches":5,"unmatchedPublic":55,"publicWithLocalCandidates":27,"distinctMatchedLocalRepositories":23,"localOnlyRepositories":58,"classifications":{"current":23,"sample":3,"legacy":7,"deprecated":15,"distribution":34}}},"releaseIntelligence":{"href":"/changelog","api":"/api/releases","releases":4,"summary":{"generatedAt":"2026-08-18T03:05:03.406Z","repositories":82,"classifications":{"current":23,"deprecated":15,"distribution":34,"legacy":7,"sample":3},"freshness":{"active":29,"aging":30,"historical":23},"matchQuality":{"exact":22,"normalized":5,"unmatched":55},"oldestRepositoryActivity":"2020-02-07T06:28:14Z","newestRepositoryActivity":"2026-08-05T12:18:11Z"}},"statefulOperationsPlanner":{"href":"/tools/stateful","api":"/api/stateful-plan","summary":{"products":9,"providerStateful":3,"hybrid":4,"applicationStateful":2,"journeys":18,"states":132,"transitions":140,"failurePlans":80,"verifiedApps":14},"products":[{"slug":"search-places","name":"Search & Places","stateModel":"stateless","ownership":"application-stateful","accent":"#00a88f","journeyCount":1},{"slug":"routes-navigation","name":"Routes & Navigation","stateModel":"hybrid","ownership":"hybrid-provider-application","accent":"#ff7a45","journeyCount":4},{"slug":"intouch-telematics","name":"InTouch Telematics","stateModel":"stateful","ownership":"provider-stateful","accent":"#e052a0","journeyCount":3},{"slug":"workmate","name":"Workmate","stateModel":"stateful","ownership":"provider-stateful","accent":"#3478f6","journeyCount":1},{"slug":"gis-analytics","name":"GIS & Analytics","stateModel":"hybrid","ownership":"hybrid-provider-application","accent":"#17a8e3","journeyCount":1},{"slug":"app-widgets-deep-links","name":"App Widgets & Deep Links","stateModel":"stateless","ownership":"application-stateful","accent":"#ff4f64","journeyCount":2},{"slug":"offline-automotive","name":"Offline & Automotive","stateModel":"stateful","ownership":"provider-stateful","accent":"#d6a600","journeyCount":1},{"slug":"ai-location","name":"AI & Location","stateModel":"hybrid","ownership":"hybrid-provider-application","accent":"#845ef7","journeyCount":2},{"slug":"capture-feedback","name":"Capture & Feedback","stateModel":"hybrid","ownership":"hybrid-provider-application","accent":"#1c9c62","journeyCount":3}]}}