{"generatedAt":"2026-10-03T18:54:22.287Z","product":{"slug":"offline-automotive","name":"Offline & Automotive","summary":"Offline maps, search, routing, guidance, compilers, and embedded navigation runtimes.","stateModel":"stateful","platforms":["Automotive","Linux","Android"],"auth":{"type":"Device activation and licensed data package","guidance":"Design for activation, entitlement refresh, package compatibility, rollback, and long periods without network access."}},"ownership":{"classification":"provider-stateful","boundary":"Offline & Automotive exposes durable operational resources. Mirror provider identity and lifecycle evidence in an application aggregate; an accepted request is not a completed business outcome.","applicationRule":"The application owns business identity, expected version, command idempotency, evidence receipts, audit, reconciliation, and downstream side effects even when Mappls owns provider resource state."},"coverage":{"slug":"offline-automotive","name":"Offline & Automotive","stateModel":"stateful","ownership":"provider-stateful","accent":"#d6a600","journeyCount":1,"boundary":"Offline & Automotive exposes durable operational resources. Mirror provider identity and lifecycle evidence in an application aggregate; an accepted request is not a completed business outcome.","aggregates":["device release"],"journeySlugs":["offline-automotive-release"],"sampleSlugs":["offline-release-control"],"tutorialSlugs":["offline-package-update","linux-map-client","ios-sdk-production-readiness"],"useCaseSlugs":["connected-vehicle","mining-haulage-safety"],"contractSlugs":[],"sourceGuideSlugs":[],"totals":{"states":7,"transitions":7,"failurePlans":4,"durableRecords":4,"operationalSignals":6}},"controlLayers":[{"id":"identity","title":"Identity and aggregate boundary","question":"What durable thing is being operated?","implementation":"Use stable business and provider identifiers for device release; never infer identity from display text or the latest coordinates.","proof":"Duplicate creation, resource rebinding, tenant isolation, and retirement tests."},{"id":"authority","title":"Actor authority","question":"Who may advance each transition?","implementation":"Authorize every command against the named journey actors: Manufacturing system, Fleet release manager, Vehicle runtime, Support engineer. Persist the attributable actor, tenant, purpose, and policy decision.","proof":"Role, resource, tenant, purpose, and human-approval denial tests."},{"id":"commands","title":"Commands and concurrency","question":"How are retries and races made safe?","implementation":"Require a command idempotency key and expected aggregate version. Cache the canonical result, reject key reuse with different intent, and reconcile ambiguous timeouts before retry.","proof":"Exact replay, stale-version rejection, concurrent-writer, timeout, and restart tests."},{"id":"evidence","title":"Evidence and durable records","question":"What proves each state?","implementation":"Persist immutable receipts and revisions around these catalog records: Device identity, Release manifest, Update plan, Health incident. Keep event time, receipt time, source identity, hashes, and retention policy separate.","proof":"Missing, malformed, late, duplicate, conflicting, and redacted-evidence tests."},{"id":"events","title":"Events and side effects","question":"How do downstream systems learn what committed?","implementation":"Commit aggregate state, audit, and a transactional outbox together. Sign deliveries, bound retries, dead-letter exhaustions, and preserve delivery attempts without changing business history.","proof":"Atomic commit, signature, retry, lease fencing, dead-letter, replay, and ordering tests."},{"id":"recovery","title":"Recovery and reconciliation","question":"What happens when systems disagree?","implementation":"Treat timeouts as unknown outcomes, poll or consume authoritative evidence, compare versions, append a reconciliation decision, and use compensation instead of destructive history edits.","proof":"Provider timeout, callback-before-response, delayed event, outage, restart, and manual-recovery drills."},{"id":"privacy","title":"Privacy and human control","question":"Which data and decisions are sensitive?","implementation":"Minimize precise location and media, scope retention, redact derived data deliberately, and require attributable approval for dispatch, publication, access, closure, and destructive change where consequential.","proof":"Least-privilege, consent expiry, separation-of-duties, retention, export, revocation, and redaction tests."},{"id":"operations","title":"Operations and release","question":"Can operators see and recover the journey?","implementation":"Expose state age, source freshness, stuck commands, retries, reconciliation lag, outbox depth, terminal outcomes, and per-aggregate audit. Roll out behind explicit acceptance gates.","proof":"SLO alerts, support lookup, bulk reconciliation, rollback, backup restore, regional failover, and incident drills."}],"journeys":[{"slug":"offline-automotive-release","title":"Offline automotive release","eyebrow":"Embedded navigation · fleet control plane","productSlug":"offline-automotive","stateModel":"stateful","summary":"Manufacture, activate, install, operate, update, recover, and retire a navigation runtime and map-data release as one compatible system.","aggregate":"device release","actors":["Manufacturing system","Fleet release manager","Vehicle runtime","Support engineer"],"sourceGuideSlugs":[],"contractSlugs":[],"sampleSlug":"offline-release-control","states":[{"id":"manufactured","label":"Manufactured","meaning":"Hardware identity, target architecture, software edition, and vehicle configuration are recorded.","recovery":"Quarantine duplicate or unreadable hardware identity before activation."},{"id":"activated","label":"Activated","meaning":"The device has a scoped entitlement and trusted activation identity.","recovery":"Refresh or rotate activation without replacing the durable vehicle identity."},{"id":"installed","label":"Installed","meaning":"A verified compatible runtime, configuration, voice set, and base map package are staged.","recovery":"Reject incompatible manifests before touching the active slot."},{"id":"operational","label":"Operational","meaning":"The active slot passed startup, route, search, positioning, audio, storage, and health checks.","recovery":"Remain on or revert to the last-known-good slot when qualification fails."},{"id":"updating","label":"Updating","meaning":"A cohort release is downloading, verifying, staging, switching, and qualifying under a durable plan.","recovery":"Resume downloads by part and make the active-slot switch atomic across power loss."},{"id":"recovering","label":"Recovering","meaning":"Watchdog or health policy selected rollback, repair, or safe degraded operation.","recovery":"Record the failing manifest and recovery reason before switching to last known good."},{"id":"retired","label":"Retired","meaning":"Activation is revoked and the device no longer receives protected packages or service.","recovery":"Reactivation is a new controlled authorization event, not a local flag change.","terminal":true}],"transitions":[{"command":"register_device","actor":"Manufacturing system","from":[],"to":"manufactured","event":"device.registered","idempotency":"Hardware identity and manufacturing batch form the stable key."},{"command":"activate","actor":"Fleet release manager","from":["manufactured"],"to":"activated","event":"license.activated","idempotency":"Activation request and entitlement version must be replay-safe."},{"command":"stage_base_release","actor":"Vehicle runtime","from":["activated"],"to":"installed","event":"release.installed","idempotency":"Manifest digest identifies the exact runtime-data-config unit."},{"command":"qualify","actor":"Vehicle runtime","from":["installed","recovering"],"to":"operational","event":"release.qualified","idempotency":"Qualification result is bound to manifest and test-suite version."},{"command":"start_update","actor":"Fleet release manager","from":["operational"],"to":"updating","event":"release.update_started","idempotency":"Device, target manifest, and rollout campaign identify one plan."},{"command":"rollback","actor":"Vehicle runtime","from":["updating","operational"],"to":"recovering","event":"release.rollback_started","idempotency":"Watchdog incident ID prevents repeated rollback side effects."},{"command":"retire","actor":"Fleet release manager","from":["manufactured","activated","installed","operational","recovering"],"to":"retired","event":"device.retired","idempotency":"Revoke activation and package access under one retirement identity."}],"invariants":["Runtime, map data, configuration, and voice assets are qualified as one compatible manifest.","Only a verified inactive slot may replace the active slot.","Power loss at any update point leaves one bootable known-good slot.","Activation identity and secrets are distinct from vehicle business identity.","Retirement revokes protected access without erasing support and release history."],"records":[{"name":"Device identity","purpose":"Manufacturing, vehicle, activation, and hardware trust mapping.","keyFields":["deviceId","hardwareId","vehicleId","edition","activationState"]},{"name":"Release manifest","purpose":"Signed compatibility unit for runtime, data, configuration, and assets.","keyFields":["manifestId","digest","target","components","signature","compatibility"]},{"name":"Update plan","purpose":"Durable per-device progress through download, verify, stage, switch, and qualify.","keyFields":["planId","campaignId","deviceId","targetManifest","phase","checkpoint"]},{"name":"Health incident","purpose":"Watchdog evidence, recovery action, and support context.","keyFields":["incidentId","activeManifest","signal","action","outcome","occurredAt"]}],"failures":[{"trigger":"Power loss during update","detection":"Boot control sees an incomplete plan and unchanged or unqualified target slot.","recovery":"Boot the known-good slot and resume or discard staging from the durable checkpoint."},{"trigger":"Runtime and map package are incompatible","detection":"Manifest compatibility or startup qualification fails.","recovery":"Reject before activation and report exact component constraints."},{"trigger":"Activation cannot refresh while offline","detection":"Entitlement is near expiry and network is unavailable.","recovery":"Apply the licensed offline grace policy visibly; never extend entitlement by changing device time."},{"trigger":"New release causes route or crash regression","detection":"Cohort health breaches automated rollout thresholds.","recovery":"Halt the campaign, roll affected devices back, and retain incident-linked diagnostic bundles."}],"observability":["Fleet distribution by active and target manifest","Download, verification, switch, and qualification duration","Interrupted and resumed update phase","Activation refresh health and offline grace usage","Crash, watchdog, routing, positioning, and storage health by cohort","Rollback cause, success, and last-known-good age"],"website":"/journeys/offline-automotive-release"}],"evidence":{"contracts":[],"guides":[],"samples":[{"slug":"offline-release-control","name":"Offline Release Control","description":"Operate an entitled offline or automotive runtime as one compatible, dual-slot release across manufacture, activation, installation, qualification, update, interruption, rollback, and retirement.","stack":["Node.js","Responsive fleet release UI","A/B slot controller","Manifest and qualification ledger"],"implementation":"full-stack-reference","verifiedTestCount":10,"downloadPath":"/downloads/offline-release-control.zip","website":"/samples/offline-release-control"}],"tutorials":[{"slug":"offline-package-update","title":"Design an interruption-safe offline map update","outcome":"A resilient embedded update state machine.","level":"Advanced","duration":"90 min","website":"/tutorials/offline-package-update"},{"slug":"linux-map-client","title":"Operate a Mappls client on embedded Linux","outcome":"An embedded map runtime with atomic data activation and rollback evidence.","level":"Advanced","duration":"2 hr","website":"/tutorials/linux-map-client"},{"slug":"ios-sdk-production-readiness","title":"Qualify an iOS Mappls release","outcome":"A clean-device iOS qualification record spanning SDK, widget, tracking, and distribution boundaries.","level":"Advanced","duration":"2 hr","website":"/tutorials/ios-sdk-production-readiness"}],"useCases":[{"slug":"connected-vehicle","title":"Navigation built for intermittent connectivity","industry":"Automotive","outcome":"Reliable guidance across coverage gaps without giving up traffic, search freshness, or safety.","website":"/use-cases/connected-vehicle"},{"slug":"mining-haulage-safety","title":"Move material safely across a changing mine","industry":"Mining","outcome":"Higher productive haulage with fewer route conflicts, stale-map movements, and unexplained cycle losses.","website":"/use-cases/mining-haulage-safety"}]},"releaseGates":["Every command has tenant, actor, purpose, idempotency, expected-version, and authorization evidence.","Every state transition has an objective evidence rule and an explicit recovery path.","Provider and business identities remain distinct, versioned, and reconcilable.","Timeout, retry, duplicate, late, out-of-order, conflict, restart, and outage paths are tested.","Sensitive location, media, identity, and operational evidence has consent, access, retention, and redaction policy.","Audit and outbox commit atomically; signing, delivery, dead-letter, replay, and lease fencing are verified.","Operators can find one aggregate, explain its state, repair safely, and prove who acted.","Live Mappls entitlement, quota, regional behavior, callbacks, and exact provider contracts are validated before production."],"handoffs":{"website":"https://developer.mappls.com/tools/stateful?product=offline-automotive","api":"https://developer.mappls.com/api/stateful-plan?product=offline-automotive","console":"https://developer.mappls.com/console/apps","resource":"mappls://catalog/stateful","tool":"mappls_plan_stateful_integration"},"credentialRule":"The planner accepts no credential, token, secret, precise location, media, or provider resource identifier."}