Enterprise feature traceability
This is the acceptance ledger for the enterprise ShamBus program. It converts the supplied FlixBus feature inventory into individually verifiable capabilities. A feature is not complete because a page or table exists; it is complete only when its domain model, authorization, API, user flow, failure states, tests, documentation, deployment, and production verification are evidenced.
Benchmark provenance and coverage honesty
The numbered 1–154 benchmark and the beyond-benchmark backlog were supplied by the product owner on 2026-08-22 as the target product inventory. They are requirements and comparison criteria, not independently verified claims about FlixBus and not evidence that ShamBus already provides them.
The 2026-08-22 PostgreSQL verification slice proves the connected transport core, journey discovery, atomic multi-leg inventory, Journey Order confirmation/hold lifecycle, driver operations control, partner quality/settlements, and cash reconciliation in an isolated database with real migrations and seeded roles. Those backend results do not mark customer, company, admin, or mobile surfaces complete and do not count as production release evidence.
Status vocabulary
| Status | Meaning |
|---|---|
U | Unverified. No completeness claim is allowed yet. |
G | Gap confirmed during audit. |
P | Partially implemented; acceptance evidence is incomplete. |
B | Blocked only by a named external dependency or credential. |
V | Verified locally across the required layers. |
R | Released and production-verified for the applicable roles and devices. |
Every row begins as U. Auditing may move it to G or P; implementation and local verification move it to V; only production evidence moves it to R.
Canonical operating model
Journey → Journey Leg → Trip → Stop Calls → Vehicle Configuration
→ Inventory (seats and extras) → Quote → Booking → Passengers
→ Tickets → Check-in → Telemetry → Disruptions → Completion
→ Feedback → Quality → Settlement
The same identifiers and state transitions power every application. Platform, company, driver, traveler, reseller, support, and finance roles receive different projections and commands over the same operational records; they do not own divergent copies.
Traveler and commerce capabilities
| ID | Capability | Primary owner | Status | Evidence |
|---|---|---|---|---|
| 1 | Search-led home and travel-day home | Traveler experience | P | Customer web/mobile prioritize the active or nearest upcoming canonical Journey and select the correct round-trip/connection leg; focused local contracts pass, browser/device/production evidence pending |
| 2 | Hierarchical city, station, stop, and airport search | Network + discovery | P | Shared directory/combobox on landing, web search, and customer mobile; local contracts pass; browser/device/prod verification pending |
| 3 | Origin, destination, departure, return, and passenger search | Discovery | P | Typed URL + canonical Journey request on web/mobile; full deployed matrix pending |
| 4 | Comparable result cards with time, duration, stops, operator, availability, and price | Discovery | P | Canonical web/mobile result cards expose the comparison contract; live browser/device/performance evidence pending |
| 5 | Direct and connecting journeys | Journey engine | P | 00227 atomic multi-leg quote/confirmation plus web/mobile connection selection and leg disclosure; deployed end-to-end evidence pending |
| 6 | Journey detail with legs, transfers, stops, operator, amenities, and conditions | Journey engine | P | Expandable web/mobile leg detail now exposes exact transfer, service, operator, vehicle, seats, and amenities; full conditions/device matrix pending |
| 7 | Passenger categories and region/route rules | Booking | P | Canonical categories; regional policy engine pending |
| 8 | Demand/capacity/date-aware dynamic pricing | Revenue management | U | — |
| 9 | Guaranteed seat inventory | Inventory | P | Atomic cross-leg holds/expiry verified; callers pending |
| 10 | Interactive vehicle-specific seat map | Inventory + traveler UI | U | — |
| 11 | Classic, table, panorama, front, extra-space, and extensible seat products | Fleet + inventory | U | — |
| 12 | Distance-, vehicle-, and seat-specific pricing | Pricing | P | Vehicle/seat quote pricing; distance engine pending |
| 13 | Multiple passengers and seat assignment per booking | Booking | P | 00227 aggregate behavior contract; surfaces pending |
| 14 | Traveler/contact data collection | Booking | P | Server validation + guest ownership; UI migration pending |
| 15 | Additional baggage inventory and post-booking purchase | Extras | P | Capacity/checkout implemented; post-booking action pending |
| 16 | Oversized/special baggage inventory | Extras | P | Canonical inventory/holds; policies and UI pending |
| 17 | Bicycle capacity and booking | Extras | P | Bicycle quote/hold/confirmation verified; UI pending |
| 18 | Stroller declaration and policy | Extras | P | Canonical resource exists; declaration policy pending |
| 19 | Assistance, wheelchair, companion, service-animal, vehicle, and stop eligibility | Accessibility | P | Passenger requirements + capacity; eligibility pending |
| 20 | Authoritative quote and checkout summary | Checkout | P | Atomic priced quote snapshot; checkout surface pending |
| 21 | Pluggable regional payment methods and cash channels | Payments | U | — |
| 22 | Voucher balance, expiry, partial redemption, combinations, and recovery | Credits | U | — |
| 23 | Confirmation page and multi-channel confirmation | Booking | P | Web/mobile canonical confirmation and issued-ticket projections exist; full event/channel production fanout pending |
| 24 | Digital ticket with signed QR | Ticketing | P | Per-Passenger/per-leg signed QR is validated and rendered online/offline; physical scanner and production key evidence pending |
| 25 | Offline ticket availability | Mobile ticketing | P | Encrypted versioned wallet, confirmation caching, network-failure fallback, and complete offline boarding context pass locally; device/process-death evidence pending |
| 26 | Driver QR boarding/check-in | Check-in | P | 00225 check-in + 00227 ticket; integration pending |
| 27 | Upcoming, active, completed, and cancelled trips | Traveler account | P | Owner-scoped lifecycle projection and keyset-paginated mobile history with offline fallback pass locally; web/prod matrix pending |
| 28 | Self-service booking management | Booking service | P | Policy-aware whole-Journey cancellation is implemented on web/mobile; remaining change actions are open |
| 29 | Policy-aware partial cancellation | Booking service | U | — |
| 30 | Grace-window correction/cancellation | Booking policy | P | Company policy model and correction-window quote path implemented; transactional regression added but Docker rerun pending |
| 31 | Rebooking with seats and extras reconciliation | Booking service | U | — |
| 32 | Policy cutoff cancellation | Booking policy | P | Company-owned cutoff/refund tiers, exact quote, atomic cancellation, web/mobile terms UI, and local contracts exist; production verification pending |
| 33 | Cancellation credit vouchers | Credits | U | — |
| 34 | Billing address and invoice download | Financial documents | U | — |
| 35 | Live position, progress, ETA, and delay tracking | Live journey | P | 00225; PostgreSQL operations contract |
| 36 | Guest tracking by secure booking reference | Live journey | P | get_public_trip_tracking; privacy contract |
| 37 | Multi-channel delay notifications | Notifications | U | — |
| 38 | Automated disruption detection and passenger actions | Disruption management | P | 00225; detection/fanout contract |
| 39 | Complete live operational trip statuses | Operations | P | Trip/Stop Call state contract; surfaces pending |
| 40 | Station and stop finder | Discovery | U | — |
| 41 | Stop address, map, and directions integration | Discovery | U | — |
| 42 | Public connection/service number | Network | P | 00224 unique sequence backfill; surface audit pending |
| 43 | Operating-company disclosure across booking and documents | Marketplace trust | P | Every discovery leg discloses its operating company on web/mobile, including mixed-operator connections; issued document audit pending |
| 44 | Transactional event notification matrix | Notifications | P | Operational templates/fanout verified; full matrix pending |
| 45 | Favorite routes | Traveler account | P | Canonical private API, CSRF mutations, web saved-route workspace, mobile offline guest cache, first-login migration, per-account isolation, strict parsing, and desktop/mobile-width Chromium contracts pass; native-device and production evidence pending |
| 46 | Personal data, journeys, tickets, passengers, preferences, and history | Traveler account | U | — |
| 47 | Arabic/English localization with Turkish-ready architecture | Localization | U | — |
| 48 | Region-sensitive currency and payment behavior | Commerce | U | — |
| 49 | SEO destination, city-pair, airport, and route pages | Discovery + marketing | U | — |
| 50 | Exploratory network route map | Discovery | U | — |
| 51 | Airport service modeling and discovery | Network | U | — |
| 52 | Night-service discovery | Discovery | U | — |
| 53 | Family, child, stroller, and minor rules | Booking policy | U | — |
| 54 | Accessible-travel rules integrated into search and booking | Accessibility | U | — |
| 55 | Vehicle-specific Wi-Fi capability | Fleet | U | — |
| 56 | Vehicle-specific outlets and USB capability | Fleet | U | — |
| 57 | Vehicle-specific toilet capability | Fleet | U | — |
| 58 | Vehicle-specific air-conditioning capability | Fleet | U | — |
| 59 | Vehicle-specific reading-light capability | Fleet | U | — |
| 60 | Recline, comfort, and legroom capability | Fleet | U | — |
| 61 | Route/vehicle-specific refreshments capability | Fleet + extras | U | — |
| 62 | Structured lost-and-found intake and tracking | Support | U | — |
| 63 | Structured disruption, baggage, seat, and refund claims | Support | U | — |
| 64 | Refund case lifecycle and ledger integration | Refunds | U | — |
| 65 | Guardrailed AI traveler-support assistant | Support | U | — |
| 66 | Taxonomized self-service help center | Support content | U | — |
| 67 | Post-trip multidimensional feedback feeding quality | Quality | U | — |
Company and partner capabilities
| ID | Capability | Primary owner | Status | Evidence |
|---|---|---|---|---|
| 68 | Legal, operational, finance, licensing, insurance, and fleet onboarding | Partner management | U | — |
| 69 | Draft-to-suspension company verification workflow | Platform compliance | U | — |
| 70 | Public, legal, operational, billing, document, and agreement company profile | Company | U | — |
| 71 | Multi-user organizations with enterprise roles | Identity + company | U | — |
| 72 | Resource/action-scoped role permissions | Authorization | U | — |
| 73 | Partner portal for rides, drivers, quality, and billing | Company portal | U | — |
| 74 | Operational partner dashboard KPIs | Company portal | U | — |
| 75 | Prioritized operational alerts | Operations | P | 00225 + 00239; SQL behavior verified, UI pending |
| 76 | Platform-assigned routes with instructions | Network operations | U | — |
| 77 | Scheduled and assigned service runs | Scheduling | P | Trip Assignment bridge verified; planner surfaces pending |
| 78 | Deep trip operational detail | Operations | P | Stop/manifest/GPS/alert snapshot verified; detail UI pending |
| 79 | Auditable trip event timeline | Operations | P | Immutable trip_operation_events; UI pending |
| 80 | Fleet lifecycle management | Fleet | U | — |
| 81 | Complete vehicle profile | Fleet | U | — |
| 82 | Vehicle availability and lifecycle statuses | Fleet | U | — |
| 83 | Versioned multi-deck vehicle layouts | Fleet | P | Canonical validated layout documents; full multi-deck UX pending |
| 84 | Configurable company seat categories | Fleet + inventory | P | Company defaults/backfill implemented; full settings UX pending |
| 85 | Per-vehicle amenity and capacity configuration | Fleet | P | Vehicle/resource capacity model; complete surfaces pending |
| 86 | Planned maintenance, repairs, cleaning, faults, history, and downtime | Maintenance | U | — |
| 87 | Vehicle documents with expiry and renewal alerts | Compliance | U | — |
| 88 | Driver list, account, status, assignments, documents, and performance | Workforce | U | — |
| 89 | Complete driver profile | Workforce | U | — |
| 90 | Driver qualification/document expiry management | Compliance | U | — |
| 91 | Driver availability and duty statuses | Workforce | U | — |
| 92 | Primary/secondary driver assignment | Dispatch | U | — |
| 93 | Individually accountable Driver App accounts | Driver identity | P | Role seed + Driver/Assignment identity verified; app audit pending |
Driver application capabilities
| ID | Capability | Primary owner | Status | Evidence |
|---|---|---|---|---|
| 94 | Individual driver authentication | Driver identity | P | Individually linked auth identities; device/session matrix pending |
| 95 | Today and upcoming duty list | Driver app | U | — |
| 96 | Pre-departure trip briefing | Driver app | U | — |
| 97 | Stop-aware passenger manifest and progress | Manifest | U | — |
| 98 | Camera QR scanning for digital and paper tickets | Check-in | U | — |
| 99 | Trip/date/stop/status/duplicate/seat/extras validation | Check-in | P | Caller/trip/status/duplicate contract; stop/extras pending |
| 100 | Unambiguous scan result states | Driver UX | U | — |
| 101 | Manual passenger search and authorized check-in | Check-in | P | Atomic authorized code check-in; search UX pending |
| 102 | Minimal operational passenger detail | Manifest | U | — |
| 103 | Boarded/expected/missing progress | Manifest | P | Operations snapshot contract; mobile UX pending |
| 104 | Boarding and alighting by stop | Manifest | U | — |
| 105 | Resilient live GPS telemetry | Telemetry | P | Idempotent offline replay + health contract |
| 106 | Bus-suitable turn-by-turn navigation | Navigation | U | — |
| 107 | Ordered stop navigation and next-stop ETA | Navigation | P | Stop Call ordering/ETA contract; navigation UI pending |
| 108 | Live ETA propagation | Telemetry | P | Future Stop Call propagation verified locally |
| 109 | Schedule-versus-telemetry delay detection | Disruptions | P | Delay/disruption/alert contract |
| 110 | Structured delay-cause reporting | Disruptions | P | Cause vocabulary/RPC verified; complete surfaces pending |
| 111 | Driver-to-control-center messaging | Operations communication | U | — |
| 112 | Break announcement propagated to passengers | Operations communication | P | Bilingual durable fanout contract; device delivery pending |
| 113 | Stop closure, detour, road closure, and alternative-stop reporting | Disruptions | P | Domain/RPC contract; complete UX pending |
| 114 | Structured incident reports with location and attachments | Incidents | U | — |
| 115 | Vehicle issue reporting and replacement escalation | Maintenance + dispatch | U | — |
| 116 | Trip completion record and metrics | Operations | U | — |
Company operations, quality, and finance capabilities
| ID | Capability | Primary owner | Status | Evidence |
|---|---|---|---|---|
| 117 | Live fleet operations map | Control center | P | Tenant-safe live-location projection; map/browser audit pending |
| 118 | Exception-oriented active-trip control center | Control center | P | 00239 active-risk-first bounded snapshot; UI integration pending |
| 119 | Prioritized trip exception queue | Control center | P | Alert/disruption/delay/GPS ranking verified; UI integration pending |
| 120 | Capacity/amenity/accessibility-safe vehicle replacement | Dispatch | U | — |
| 121 | Audited primary/secondary driver replacement | Dispatch | U | — |
| 122 | Sold, boarded, capacity, and occupancy truth | Operations | P | Drift-resistant operations snapshot contract |
| 123 | Seat, vehicle, route, slot, and empty-seat utilization | Analytics | U | — |
| 124 | Multidimensional quality management | Quality | P | Six-metric period snapshot + SLA contract; surfaces pending |
| 125 | Explainable aggregate quality score | Quality | P | Weighted evidence/hash contract; surfaces pending |
| 126 | Punctuality analysis by route, vehicle, driver, stop, and time | Analytics | U | — |
| 127 | Driver operational and quality analytics | Analytics | U | — |
| 128 | Vehicle utilization, issue, downtime, complaint, and cost analytics | Analytics | U | — |
| 129 | Route volume, occupancy, punctuality, revenue, and quality analytics | Analytics | U | — |
| 130 | Configurable partner revenue-sharing model | Finance | P | Versioned effective Commercial Terms; admin UI pending |
| 131 | Gross/share/adjustment/bonus/penalty/tax/payment dashboard | Finance | U | — |
| 132 | Settlement period and trip-line lifecycle | Settlement | P | Exact transactional settlement contract; UI pending |
| 133 | Idempotent automated monthly billing | Settlement | P | pg_cron queue/retry/dead-letter contract; production pending |
| 134 | Billing history and status | Finance | P | Tenant-safe paginated RPC; UI pending |
| 135 | Professional invoice, statement, breakdown, tax, and payment documents | Documents | U | — |
| 136 | Scheduled/operated/cancelled/paid reconciliation | Finance | P | Per-Trip reconciliation/payment contract; UI pending |
| 137 | Configurable performance incentives and deductions | Settlement | P | Terms + audited adjustment contract; UI pending |
| 138 | Role-aware company document center | Documents | U | — |
| 139 | License, inspection, insurance, and missing-document alerts | Compliance | U | — |
| 140 | Courses, requirements, completion, certification, and acknowledgment | Training | U | — |
| 141 | Operational notices and acknowledgments | Company communication | U | — |
Central platform capabilities
| ID | Capability | Primary owner | Status | Evidence |
|---|---|---|---|---|
| 142 | Platform-controlled cities, stops, routes, frequencies, timetables, and expansion | Network planning | U | — |
| 143 | Demand forecasting inputs and outputs | Revenue management | U | — |
| 144 | Demand-based capacity/production planning | Network planning | U | — |
| 145 | Platform fare authority with tenant-safe operator inputs | Pricing | U | — |
| 146 | Capacity/lead-time/seasonality-aware revenue optimization | Pricing | U | — |
| 147 | One authoritative channel-neutral inventory | Inventory | P | 00227 atomic seats/extras; all channel callers pending |
| 148 | Central brand, campaigns, SEO, promotions, and acquisition | Marketing | U | — |
| 149 | Central omnichannel ticket sales | Distribution | U | — |
| 150 | Travel-agent/reseller booking and commission portal | Distribution | U | — |
| 151 | Affiliate, widget, GTFS, API, white-label, metasearch, and attribution integrations | Distribution | U | — |
| 152 | Cross-company central traffic control | Platform operations | U | — |
| 153 | Cross-company support CRM with booking context | Support | U | — |
| 154 | Comparable operator SLA and quality oversight | Platform quality | P | Cross-Company quality comparison RPC; admin UI pending |
Beyond-benchmark backlog
These requirements are part of the requested target, not optional ideas. They receive stable IDs so they can be traced like the numbered benchmark.
| ID | Capability | Primary owner | Status | Evidence |
|---|---|---|---|---|
| BT-01 | Interactive network and live-journey maps | Traveler | U | — |
| BT-02 | Nearby stations and proximity-aware discovery | Traveler | U | — |
| BT-03 | Approaching-bus visualization and vehicle photo/model | Traveler | U | — |
| BT-04 | Transfer guidance | Traveler | U | — |
| BT-05 | Apple Wallet and Google Wallet tickets | Ticketing | U | — |
| BT-06 | Smart favorites and price alerts | Traveler | U | — |
| BT-07 | Departure alerts and family live-trip sharing | Traveler | U | — |
| BT-08 | Loyalty, travel credits, student accounts, family profiles, and saved passengers | Traveler | U | — |
| BT-09 | Saved payment methods behind compliant provider tokenization | Payments | U | — |
| BT-10 | Accessibility filters, in-app support chat, and AI travel assistant | Traveler | U | — |
| BC-01 | Drag-and-drop dispatch and utilization planning | Company | U | — |
| BC-02 | Driver scheduling, hours compliance, and conflict prevention | Company | U | — |
| BC-03 | Vehicle assignment conflict prevention | Company | U | — |
| BC-04 | Maintenance planning, fuel/energy, depots, and cost per kilometer | Company | U | — |
| BC-05 | Route profitability, payroll export, custom reports, SLA, incident center, and full audit | Company | U | — |
| BD-01 | Offline manifest, QR validation, and deterministic synchronization | Driver | U | — |
| BD-02 | Stop checklist, headcount, missing-passenger warning, and rest timer | Driver | U | — |
| BD-03 | Pre/post-trip inspection and damage photo workflow | Driver | U | — |
| BD-04 | Emergency contact, voice announcements, and multilingual templates | Driver | U | — |
| BP-01 | Contract management and central route/network builder | Platform | U | — |
| BP-02 | Forecasting, pricing, inventory, and revenue-management workbench | Platform | U | — |
| BP-03 | Settlement, risk, fraud, reconciliation, and BI warehouse | Platform | U | — |
Product-owner additions
These items record requirements that are not fully represented by the numbered benchmark. They are mandatory and follow the same evidence rules.
| ID | Capability | Primary owner | Status | Evidence |
|---|---|---|---|---|
| PO-01 | Isolated, expiring, resettable company demos with role accounts, seeded scenarios, and a deterministic traveler launch | Demo platform | P | Tenant isolation and deterministic bookable launch contracts exist; complete role/browser/production matrix pending |
| PO-02 | Strict public, internal-QA, and demo inventory scopes across discovery, quote, booking, operations, and analytics | Inventory + authorization | P | Discovery/quote isolation contracts exist; every downstream projection and production role still requires verification |
| PO-03 | Company-configurable manual confirmation with distinct requested, confirmed, rejected, expired, ticket-issued states | Booking policy | V | Migration 00305, shared web/mobile/Driver projections, tenant settings and decision APIs, immutable-document/QR guards, notification fanout, and rollback-only PostgreSQL plus focused app contracts pass locally; production role/browser/device evidence pending |
| PO-04 | Cash-first payment policy, provider-neutral online-payment adapters, and development-only online channels until activated | Payments | P | Cash-first and disabled-provider foundations exist; end-to-end reconciliation and release gates pending |
| PO-05 | Professional ticket, receipt, reservation, invoice, statement, and settlement PDFs with QR, audit, retry, and delivery | Documents | P | Versioned document registry/renderer foundations exist; complete document matrix and all-app integration pending |
| PO-06 | Versioned SMS, email, push, in-app, and printable communication templates for the complete operational event taxonomy | Notifications | P | Delivery/template foundations exist; event coverage, provider evidence, previews, and production reliability pending |
| PO-07 | Centralized, versioned legal center linked from every app with consent evidence and counsel-reviewed market variants | Legal + compliance | U | — |
| PO-08 | Minimal role-correct login and signup flows, traveler Google identity, phone/email methods, recovery, and account linking | Identity + design system | P | Local traveler identity foundation exists; final visual/device matrix and external Google credentials pending |
| PO-09 | Company-owned loyalty configuration, earning, redemption, liability, reporting, and customer presentation | Company commerce | U | — |
| PO-10 | Custom demo offers with safe predefined scenario packs plus optional company-specific seeded data | Sales engineering | U | — |
| PO-11 | Information-rich approval review workspace with side-panel detail, documents, risk, decision history, and audit | Admin compliance | P | Existing approval flow is partial; complete evidence pending |
| PO-12 | Explicit no-show state at passenger/segment level with manifest, reporting, policy, communication, and settlement effects | Operations | U | — |
| PO-13 | Secret-safe ecosystem service catalog with URLs, seeded-role instructions, health, ownership, and Slack alert routing | Platform operations | P | Operational foundations exist; canonical catalog and end-to-end Slack event verification pending |
| PO-14 | One coherent responsive design system across every surface, with professional icons, motion, RTL/LTR, and native mobile UX | Design system | P | Shared packages exist; exhaustive source/browser/device migration remains open |
| PO-15 | Measured performance budgets for search, trip lists, navigation, images, APIs, low-end devices, and degraded networks | Performance engineering | U | — |
| PO-16 | Unique, operator-managed trip media with realistic Syria-context imagery, provenance, optimization, crop, and fallbacks | Media + traveler experience | U | — |
| PO-17 | Company-managed trip pickup and drop-off locations with map coordinates, landmarks, instructions, and per-trip overrides | Company operations | P | Initial pickup-location domain/UI exists; edit lifecycle, drop-off parity, and complete app propagation pending |
| PO-18 | Controlled driver pickup/drop-off changes with reason, GPS/time evidence, dispatch approval policy, audit, and notifications | Driver + dispatch | U | — |
| PO-19 | Onboard/walk-up booking for unplanned passengers with exact boarding/alighting segment, seat/capacity truth, and offline sync | Driver sales | U | — |
| PO-20 | Driver-entered fare under company policy with limits, reason codes, cash collection, shift reconciliation, and fraud controls | Driver sales + finance | U | — |
| PO-21 | In-bus ticket/receipt/invoice printing through an adapter for Bluetooth thermal printers with PDF/share fallback | Driver documents | U | — |
| PO-22 | Secure booking retrieval by authenticated ownership or booking code plus family name, with rate limits and privacy controls | Traveler self-service | P | Guest-access foundation exists; complete channel and production verification pending |
| PO-23 | Secure in-person document copy through an expiring, purpose-scoped QR exchange; explicit recipient preview/acceptance; revocation, replay protection, signed offline display, and channel fallbacks; Booking ownership transfer remains a separate authenticated flow | Driver + traveler documents | P | Migrations 00298–00303, customer-web grant/preview/accept/revoke/download flow, two-phase delivery evidence, customer-mobile native PDF sharing, and assigned-Driver document delivery exist; verified native app-link entry, mobile recipient wallet, and signed offline nearby transfer remain open |
| PO-24 | Professional billing details remain optional for cash and are requested only when an enabled payment method or applicable legal rule requires them | Checkout + finance | P | Migrations 00276–00278 and 00281 separate traveler billing data, card requirements, development-only online providers, and cash-first policy; complete surface and jurisdiction-policy verification pending |
Research-backed additions beyond the supplied inventory
The enterprise transport capability research uses official transport, identity, security, accessibility, payment, mobile-platform, and printer sources to stress-test the supplied benchmark. These rows are separate from the product-owner additions so a recommendation cannot silently become a claim about a competitor or about current ShamBus behavior.
| ID | Capability | Priority | Status | Current evidence and dependency | Minimum acceptance |
|---|---|---|---|---|---|
| E-01 | Versioned Trip Stop Call pickup/drop-off override | P0 | P | Migrations 00279–00286 establish initial pickup/location projections; canonical override lifecycle and full app propagation remain dependencies | A dated Stop Call can override the reusable Stop without mutating other Trips; old/new values, actor, reason, version, effective time, and authorization are preserved |
| E-02 | Pickup-change propagation and acknowledgment | P0 | P | 00282 and notification projections provide partial foundations; channel delivery, crew/passenger acknowledgment, and control escalation remain open | Every affected passenger and crew member receives the exact changed rendezvous; delivery/acknowledgment is observable and unacknowledged high-risk changes escalate |
| E-03 | Driver, reseller, and office point-of-sale channels | P0 | P | Customer and office booking paths exist; driver/reseller channel parity, delegated authority, and shared transaction evidence are missing | Every channel creates the same authoritative Journey transaction with actor, channel, pricing, inventory, payment, fulfillment, audit, and idempotency semantics |
| E-04 | Per-passenger boarding and alighting rights for walk-up sales | P0 | U | Depends on canonical Passenger × Journey Leg/Stop Call rights and onboard-sale commands | Each traveler in a group has explicit board/alight Stop Calls, fare, seat/extras, ticket rights, and manifest visibility |
| E-05 | Versioned fare catalogue and governed driver override | P0 | U | Depends on fare authority, company policy, role limits, reason codes, and immutable price-version snapshots | Driver-entered prices cannot bypass floors/ceilings or approval rules and always retain quoted, overridden, tax, currency, reason, actor, and audit values |
| E-06 | Cash shift, drawer, variance, and reconciliation | P0 | P | Migrations 00211, 00234, 00241, and 00242 provide cash/settlement foundations; driver-sales custody and closeout parity remain dependencies | Opening float + collections − refunds/change produces expected cash; driver declares close, variance is recorded, exceptions are reviewed, and settlement is traceable |
| E-07 | Confirmation separated from fulfillment | P0 | P | Confirmation-policy foundations exist; a single enforced state machine across every booking channel and boarding projection remains incomplete | Requested/approved/rejected/expired states are distinct from ticket issuance; no valid-looking boarding credential exists before approval |
| E-08 | Booking, reservation confirmation, ticket, receipt, and invoice semantics | P0 | P | Versioned document registry/renderer foundations exist; complete type-specific authority, numbering, delivery, and all-surface integration remain open | Each document has one defined legal/operational purpose, immutable source snapshot, version/hash, access policy, lifecycle, rendering contract, and audit trail |
| E-09 | Hybrid signed boarding QR plus online control registry | P0 | P | Signed ticket and check-in primitives exist; production key rotation, revocation/use registry, offline freshness, and device evidence remain dependencies | Offline validation proves authenticity and scope while online control resolves current issue/use/revoke/refund/reissue state without embedding unnecessary PII |
| E-10 | Bounded offline inventory leases for guaranteed sales | P0 | U | Depends on device/shift/Trip/segment/resource lease allocation and reconciliation | Offline-capable devices receive non-overlapping, expiring inventory authority; oversell is impossible under tested partition, retry, expiry, reassignment, and recovery |
| E-11 | Idempotent offline command and reconciliation ledger | P0 | U | General offline queues exist, but the financial/inventory command envelope and deterministic conflict ledger are not verified | Every command has stable identity, actor/device/shift/Trip/Stop context, sequence, trusted-time evidence, hash chain, result, retry, conflict, and reconciliation outcome |
| E-12 | Versioned legal center and consent evidence | P0 | U | Depends on counsel-approved market content, immutable versions, publication rules, acceptance events, and centralized app links | Each app resolves the same applicable immutable document version and can prove who accepted which content/hash, when, in what locale/context, and what superseded it |
| E-13 | Printer adapter, spooler, health, and audited reprint | P1 | U | Depends on device-neutral printer contract, selected hardware adapters, spool persistence, and physical-device tests | Booking commit is independent of print outcome; jobs expose pending/accepted/printed/failed/unknown, retry the same document, audit reprints, and offer PDF/share fallback |
| E-14 | Secure document copy versus authenticated ownership transfer | P1 | P | Purpose-scoped document grants, explicit acceptance, revocation, one-use recipient sessions, and immutable delivery evidence are implemented; authenticated ownership-transfer ceremony is intentionally separate and remains open | Sharing grants least-privilege access to one immutable artifact; changing booking ownership requires separate authenticated authorization and never occurs by scanning |
| E-15 | Verified offline phone-to-phone ticket delivery | P1 | U | Depends on mutually verified nearby transport, signed artifact package, freshness policy, duplicate handling, and platform adapters | Sender and receiver compare a verification value, transfer only the intended signed artifact, preserve provenance, and safely reconcile duplicates after connectivity |
| E-16 | Trusted time and offline freshness policy | P1 | U | Depends on server time anchors, monotonic device intervals, keyset/package expiry rules, and clock-tamper handling | Editable wall-clock time never solely determines fare, credential, lease, or legal validity; stale and rollback-clock cases fail predictably and recover safely |
| E-17 | Ticket-control and fraud lifecycle | P1 | P | QR/check-in/token contracts provide a foundation; unified issue/use/duplicate/revoke/refund/reissue/key-rotation operations and analytics remain open | One ledger explains every credential state transition, supports offline/online decisions, prevents replay, and gives authorized support/control users actionable evidence |
| E-18 | Device, keyset, and package freshness control center | P1 | U | Depends on device registry, app/key/config/package versions, health telemetry, policy enforcement, and operations UI | Operations can identify stale/offline/compromised devices, prevent unsafe use, rotate keys/config, and verify recovery without exposing cross-tenant data |
| E-19 | Standards adapters with internal-model isolation | P1 | U | Depends on stable internal Journey/Stop Call/fare/document contracts plus explicit GTFS/GTFS-Realtime/OSDM mappings and conformance tests | Imports are validated/quarantined, exports are reproducible, experimental external fields cannot redefine internal truth, and adapter versions are observable |
| E-20 | Connected data-quality, lineage, and quarantine workflow | P1 | U | Depends on provenance metadata, validation rules, quarantine/correction workflow, ownership, and quality metrics | Invalid or conflicting Stop, fare, Trip, identity, and operational data cannot silently publish; correction preserves source, decision, impact, and audit history |
Sequential execution program
Work proceeds in this order. A later phase may be researched while an earlier phase runs, but no later phase can be declared complete before the earlier gate is closed.
| Phase | Scope | Exit gate |
|---|---|---|
| 0 | Stabilize the current release: booking/Journey correctness, inventory scope, CSRF, CSP, demo launch, identity, profile prefill, driver demo access, critical responsive defects | Focused and full regression suites pass; migrations are safe; affected apps build; authenticated browser flows pass locally and in production; release is documented and rollback-ready |
| 1 | Exhaustive inventory and evidence-based research: every route, component, API, table, job, template, document, notification, role, device flow, competitor capability, and Syria-specific constraint | Every requirement has a stable ID, confirmed current status, dependencies, acceptance criteria, and authoritative research where applicable |
| 2 | Canonical domain and data model: Journey/legs/stop calls, pickup/drop-off, inventory, booking/passenger segments, identities, operations, finance, documents, notifications, audit, and isolation | Versioned terminology/ADR, safe migrations/backfills, constraints/indexes/RLS, typed contracts, and database behavior tests pass |
| 3 | Shared experience infrastructure: icon registry, no-emoji guard, Latin digits, i18n, custom select/date/time/phone/filter/data-table/entity/media primitives, motion and adaptive navigation | Competing primitives are removed, source guards are green, accessibility/RTL/LTR/responsive component suites pass |
| 4 | Traveler web and customer mobile parity: discovery, direct/connecting Journey, seats/extras, identity, checkout, confirmation, tickets, self-service, tracking, companies, support, legal, and offline | Same capability/state matrix on web and mobile; browser/device/low-network/guest/authenticated tests pass |
| 5 | Driver operating product: duty, briefing, manifest, scan/manual check-in, pickup changes, walk-up sales, price controls, cash, printing, offline sync, telemetry, navigation, incidents, completion | Real device and printer-adapter tests, offline/conflict recovery, permissions, audit, reconciliation, and production role checks pass |
| 6 | Company transportation OS: operations, routes/schedules/trips, fleet/wizard/maintenance, drivers, bookings, confirmations, pickup points, loyalty, quality, finance, documents, team, public profile | Tenant/role matrix, cross-entity navigation, server filtering, workflows, reports, and production company-role tests pass |
| 7 | Admin/control/support platform: onboarding, approvals, demos, network/pricing/inventory, live control, compliance, support CRM, quality, settlements, audit, and feature operations | Cross-company authorization, four-eyes/high-risk controls, audit, performance, and production admin-role tests pass |
| 8 | Enterprise services: notification providers/templates, PDFs and printing, payments adapters, legal/consent, Slack/observability, credentials/runbooks, media pipeline, analytics/BI, integrations | Provider failure/retry/idempotency/audit/security tests pass; all external blockers are explicitly named; operational runbooks are current |
| 9 | Release certification: clean worktree, full CI-equivalent suites, database reset/migration proof, builds, desktop/tablet/mobile browsers, physical devices, accessibility, RTL/LTR, performance, security, backup/rollback, deploy, and production role matrix | Only evidence-backed R rows remain; unresolved external dependencies stay B; release commit is pushed and the server revision, migrations, services, and user-visible flows are verified |
Within every phase, implementation order is deterministic: audit → model/acceptance criteria → failing tests → backend/data → shared components → app surfaces → edge/offline/error states → documentation → full local verification → commit/push → deploy/migrate → production verification → ledger status update.
Cross-cutting global standards
The thirteen ecosystem standards are independent acceptance gates. A source-level foundation is not sufficient to mark a standard verified across every app.
| ID | Standard | Status | Current evidence and remaining dependency |
|---|---|---|---|
| GS-01 | Professional iconography; no emoji in any product UI | P | lint:product-standards and the web/mobile icon foundations pass locally; exhaustive visual, notification-template, generated-artifact, and production-device evidence remains |
| GS-02 | No native web Select; shared accessible selection system | P | Shared React Aria Combobox/MultiSelect and source guard exist; advanced async/large-data/mobile behavior and complete production interaction matrix remain |
| GS-03 | No native browser date picker; shared date/time system | P | Shared single/range/date-time/time controls and source guard exist; all presets, disabled-date policy, mobile overlays, and device/browser accessibility evidence remain |
| GS-04 | Advanced server-side filtering, sorting, and saved views | P | Shared FilterBar exists and Routes is migrated; canonical collection-query backend, all meaningful collections, URL persistence, saved views, and index evidence remain |
| GS-05 | Connected contextual entity graph and state-preserving links | P | Core foreign keys and some detail links exist; shared entity-reference/read-model/navigation contract and complete cross-resource coverage remain |
| GS-06 | Latin digits in every locale, surface, input, and document | P | packages/utils/src/latin-digits.ts, Flutter formatters, and source guard exist; PDF/email/push/chart/input and production-device proof remain |
| GS-07 | Shared international E.164 phone input, Syria default, LTR | P | Web and Flutter shared controls use maintained parsers, SVG flags, +963, LTR isolation, and tests; exhaustive caller/API/database/device verification remains |
| GS-08 | Configurable default seat types for every company | P | 00219_global_product_foundation.sql and database tests provision four editable types; safe live backfill and full dashboard/booking production evidence remain |
| GS-09 | Complete, recoverable, high-capability New Bus wizard | P | Existing staged wizard and advanced layout editor are substantial; metadata depth, versioned autosave, recovery, mobile UX, validation, and production evidence remain |
| GS-10 | Operator-managed custom Trip media domain | P | 00220_public_company_profiles_and_trip_media.sql defines media, variants, and focal data; upload/crop pipeline and complete dashboard/customer integration remain |
| GS-11 | Managed and polished public Company profiles | P | 00220, public profile query tests, and customer API foundation exist; tenant editor, moderation, gallery/policies/routes UI, and full production verification remain |
| GS-12 | Native-quality customer and driver mobile products | P | Shared Flutter architecture, route gate, and broad tests exist; remaining desktop-shaped flows, physical Android/iOS, accessibility, low-end/offline, and visual QA remain |
| GS-13 | Traveler-only Google identity and account linking | B | Web/native verified-token and identity-linking foundations pass locally; production Web/Android/iOS OAuth clients and real-device provider evidence are externally blocked |
The detailed baseline and migration findings remain in Global product standards audit.
Phase 1 evidence register
| Evidence ID | Artifact | State | What it proves | What it does not prove |
|---|---|---|---|---|
| A-01 | Generated ecosystem surface inventory | Current | Deterministic source inventory of web routes/APIs, resolved Flutter routes/screens, shared modules, migration declarations, workers, Compose services, and test-file roots | Live database shape, runtime reachability, permissions, UX quality, or production correctness |
| A-02 | tests/e2e/route-flows/manifest.ts plus pnpm --filter @shambus/e2e-tests audit:coverage | Current | Every discovered Next page and resolved Flutter route has an explicit route-flow manifest entry | That every command, role, device, deep link, or exceptional outcome works |
| A-03 | Enterprise transport capability research | Current | Primary-source capability/edge-case baseline, Syria-context recommendations, legal boundary, and E-01–E-20 additions | ShamBus implementation status or Syrian legal approval |
| A-04 | Global product standards audit | Current | Original occurrence inventory, shared-seam analysis, migration rules, and known local source/test evidence | Complete live visual review or production/native-device certification |
| A-05 | Live schema audit | Production | Matching local and production ledgers contain 287 files through 00297; every Company has one durable cash-only policy row; both environments report the same 473 application functions; production has RLS on 156/156 public tables, healthy runtime posture, 720 valid indexes, 1,200 validated constraints, and 46/46 rollback-only database contracts passing in one session | This proves the deployed database shape and its database-level contracts, not every API authorization path, external integration, browser/device flow, performance target, or user-experience state |
| A-06 | Mobile station deep-link contract | Production web | /station/:stationId resolves from a real public city identifier after refresh or copied-link entry; its API unit contract and customer-mobile analysis pass; a read-only production Chromium regression resolves Damascus from the live API with no HTTP, console, font, or horizontal-overflow failure | Physical Android/iOS deep-link behavior, slow-network behavior, and native map-app handoff remain unverified |
Phase 1 remains in progress. The generated inventory closes source discovery coverage and A-05 closes the matching local/production database-shape and security slice, including the exact service-only table allowlist. Per-capability dependency review, runtime behavior, and user-experience audits remain open.
Required evidence per capability
A row can move to V only when applicable evidence includes:
- domain terminology and state-transition rules;
- schema, foreign keys, constraints, indexes, migrations, and backfill;
- tenant/role authorization and privacy tests;
- typed command/query API contracts and failure modes;
- every applicable web/mobile surface and connected navigation;
- loading, empty, error, conflict, stale, offline, and retry behavior;
- Arabic RTL and English LTR behavior with Latin digits;
- desktop, tablet, phone, keyboard, screen-reader, and low-end-device checks;
- unit, database, API, integration, and end-to-end tests;
- operational metrics, logs, audit events, and notification/document effects;
- updated user and internal documentation;
- production migration, smoke evidence, and rollback readiness.
External credentials or approvals may move a capability to B, but they never justify marking it verified or released.