Before and afterRe-contract the integration
Resolve each dimension explicitly. “It compiled” does not prove identity, lifecycle, failure, privacy, or operational compatibility.
DimensionLegacy exposureCandidate targetRequired proof
Journey modelTasks, attendance, tracking, and proof can be coupled inside one SDK or API surface.
Model worker, task, assignment, visit, proof, and exception aggregates with explicit ownership and transitions.
State diagrams, invariants, event schemas, and recovery test per journey.
Offline workLocal callback success can be mistaken for authoritative completion.
Persist commands, evidence hashes, observed time, sync state, and server acknowledgement separately.
Multi-day offline, duplicate sync, clock skew, rejected proof, and device replacement tests.
Module selectionOne product credential may have implied several capabilities.
Entitle tracking, capture, search, routing, or workflow modules independently and keep least authority.
Capability-by-role matrix plus negative authorization and revocation tests.