إنتقل إلى المحتوى الرئيسي

Enterprise feature traceability

This is the acceptance ledger for the enterprise ShamBus program. It converts the supplied FlixBus feature inventory into individually verifiable capabilities. A feature is not complete because a page or table exists; it is complete only when its domain model, authorization, API, user flow, failure states, tests, documentation, deployment, and production verification are evidenced.

Benchmark provenance and coverage honesty

The numbered 1–154 benchmark and the beyond-benchmark backlog were supplied by the product owner on 2026-08-22 as the target product inventory. They are requirements and comparison criteria, not independently verified claims about FlixBus and not evidence that ShamBus already provides them.

The 2026-08-22 PostgreSQL verification slice proves the connected transport core, journey discovery, atomic multi-leg inventory, Journey Order confirmation/hold lifecycle, driver operations control, partner quality/settlements, and cash reconciliation in an isolated database with real migrations and seeded roles. Those backend results do not mark customer, company, admin, or mobile surfaces complete and do not count as production release evidence.

Status vocabulary

StatusMeaning
UUnverified. No completeness claim is allowed yet.
GGap confirmed during audit.
PPartially implemented; acceptance evidence is incomplete.
BBlocked only by a named external dependency or credential.
VVerified locally across the required layers.
RReleased and production-verified for the applicable roles and devices.

Every row begins as U. Auditing may move it to G or P; implementation and local verification move it to V; only production evidence moves it to R.

Canonical operating model

Journey → Journey Leg → Trip → Stop Calls → Vehicle Configuration
→ Inventory (seats and extras) → Quote → Booking → Passengers
→ Tickets → Check-in → Telemetry → Disruptions → Completion
→ Feedback → Quality → Settlement

The same identifiers and state transitions power every application. Platform, company, driver, traveler, reseller, support, and finance roles receive different projections and commands over the same operational records; they do not own divergent copies.

Traveler and commerce capabilities

IDCapabilityPrimary ownerStatusEvidence
1Search-led home and travel-day homeTraveler experiencePCustomer web/mobile prioritize the active or nearest upcoming canonical Journey and select the correct round-trip/connection leg; focused local contracts pass, browser/device/production evidence pending
2Hierarchical city, station, stop, and airport searchNetwork + discoveryPShared directory/combobox on landing, web search, and customer mobile; local contracts pass; browser/device/prod verification pending
3Origin, destination, departure, return, and passenger searchDiscoveryPTyped URL + canonical Journey request on web/mobile; full deployed matrix pending
4Comparable result cards with time, duration, stops, operator, availability, and priceDiscoveryPCanonical web/mobile result cards expose the comparison contract; live browser/device/performance evidence pending
5Direct and connecting journeysJourney engineP00227 atomic multi-leg quote/confirmation plus web/mobile connection selection and leg disclosure; deployed end-to-end evidence pending
6Journey detail with legs, transfers, stops, operator, amenities, and conditionsJourney enginePExpandable web/mobile leg detail now exposes exact transfer, service, operator, vehicle, seats, and amenities; full conditions/device matrix pending
7Passenger categories and region/route rulesBookingPCanonical categories; regional policy engine pending
8Demand/capacity/date-aware dynamic pricingRevenue managementU
9Guaranteed seat inventoryInventoryPAtomic cross-leg holds/expiry verified; callers pending
10Interactive vehicle-specific seat mapInventory + traveler UIU
11Classic, table, panorama, front, extra-space, and extensible seat productsFleet + inventoryU
12Distance-, vehicle-, and seat-specific pricingPricingPVehicle/seat quote pricing; distance engine pending
13Multiple passengers and seat assignment per bookingBookingP00227 aggregate behavior contract; surfaces pending
14Traveler/contact data collectionBookingPServer validation + guest ownership; UI migration pending
15Additional baggage inventory and post-booking purchaseExtrasPCapacity/checkout implemented; post-booking action pending
16Oversized/special baggage inventoryExtrasPCanonical inventory/holds; policies and UI pending
17Bicycle capacity and bookingExtrasPBicycle quote/hold/confirmation verified; UI pending
18Stroller declaration and policyExtrasPCanonical resource exists; declaration policy pending
19Assistance, wheelchair, companion, service-animal, vehicle, and stop eligibilityAccessibilityPPassenger requirements + capacity; eligibility pending
20Authoritative quote and checkout summaryCheckoutPAtomic priced quote snapshot; checkout surface pending
21Pluggable regional payment methods and cash channelsPaymentsU
22Voucher balance, expiry, partial redemption, combinations, and recoveryCreditsU
23Confirmation page and multi-channel confirmationBookingPWeb/mobile canonical confirmation and issued-ticket projections exist; full event/channel production fanout pending
24Digital ticket with signed QRTicketingPPer-Passenger/per-leg signed QR is validated and rendered online/offline; physical scanner and production key evidence pending
25Offline ticket availabilityMobile ticketingPEncrypted versioned wallet, confirmation caching, network-failure fallback, and complete offline boarding context pass locally; device/process-death evidence pending
26Driver QR boarding/check-inCheck-inP00225 check-in + 00227 ticket; integration pending
27Upcoming, active, completed, and cancelled tripsTraveler accountPOwner-scoped lifecycle projection and keyset-paginated mobile history with offline fallback pass locally; web/prod matrix pending
28Self-service booking managementBooking servicePPolicy-aware whole-Journey cancellation is implemented on web/mobile; remaining change actions are open
29Policy-aware partial cancellationBooking serviceU
30Grace-window correction/cancellationBooking policyPCompany policy model and correction-window quote path implemented; transactional regression added but Docker rerun pending
31Rebooking with seats and extras reconciliationBooking serviceU
32Policy cutoff cancellationBooking policyPCompany-owned cutoff/refund tiers, exact quote, atomic cancellation, web/mobile terms UI, and local contracts exist; production verification pending
33Cancellation credit vouchersCreditsU
34Billing address and invoice downloadFinancial documentsU
35Live position, progress, ETA, and delay trackingLive journeyP00225; PostgreSQL operations contract
36Guest tracking by secure booking referenceLive journeyPget_public_trip_tracking; privacy contract
37Multi-channel delay notificationsNotificationsU
38Automated disruption detection and passenger actionsDisruption managementP00225; detection/fanout contract
39Complete live operational trip statusesOperationsPTrip/Stop Call state contract; surfaces pending
40Station and stop finderDiscoveryU
41Stop address, map, and directions integrationDiscoveryU
42Public connection/service numberNetworkP00224 unique sequence backfill; surface audit pending
43Operating-company disclosure across booking and documentsMarketplace trustPEvery discovery leg discloses its operating company on web/mobile, including mixed-operator connections; issued document audit pending
44Transactional event notification matrixNotificationsPOperational templates/fanout verified; full matrix pending
45Favorite routesTraveler accountPCanonical private API, CSRF mutations, web saved-route workspace, mobile offline guest cache, first-login migration, per-account isolation, strict parsing, and desktop/mobile-width Chromium contracts pass; native-device and production evidence pending
46Personal data, journeys, tickets, passengers, preferences, and historyTraveler accountU
47Arabic/English localization with Turkish-ready architectureLocalizationU
48Region-sensitive currency and payment behaviorCommerceU
49SEO destination, city-pair, airport, and route pagesDiscovery + marketingU
50Exploratory network route mapDiscoveryU
51Airport service modeling and discoveryNetworkU
52Night-service discoveryDiscoveryU
53Family, child, stroller, and minor rulesBooking policyU
54Accessible-travel rules integrated into search and bookingAccessibilityU
55Vehicle-specific Wi-Fi capabilityFleetU
56Vehicle-specific outlets and USB capabilityFleetU
57Vehicle-specific toilet capabilityFleetU
58Vehicle-specific air-conditioning capabilityFleetU
59Vehicle-specific reading-light capabilityFleetU
60Recline, comfort, and legroom capabilityFleetU
61Route/vehicle-specific refreshments capabilityFleet + extrasU
62Structured lost-and-found intake and trackingSupportU
63Structured disruption, baggage, seat, and refund claimsSupportU
64Refund case lifecycle and ledger integrationRefundsU
65Guardrailed AI traveler-support assistantSupportU
66Taxonomized self-service help centerSupport contentU
67Post-trip multidimensional feedback feeding qualityQualityU

Company and partner capabilities

IDCapabilityPrimary ownerStatusEvidence
68Legal, operational, finance, licensing, insurance, and fleet onboardingPartner managementU
69Draft-to-suspension company verification workflowPlatform complianceU
70Public, legal, operational, billing, document, and agreement company profileCompanyU
71Multi-user organizations with enterprise rolesIdentity + companyU
72Resource/action-scoped role permissionsAuthorizationU
73Partner portal for rides, drivers, quality, and billingCompany portalU
74Operational partner dashboard KPIsCompany portalU
75Prioritized operational alertsOperationsP00225 + 00239; SQL behavior verified, UI pending
76Platform-assigned routes with instructionsNetwork operationsU
77Scheduled and assigned service runsSchedulingPTrip Assignment bridge verified; planner surfaces pending
78Deep trip operational detailOperationsPStop/manifest/GPS/alert snapshot verified; detail UI pending
79Auditable trip event timelineOperationsPImmutable trip_operation_events; UI pending
80Fleet lifecycle managementFleetU
81Complete vehicle profileFleetU
82Vehicle availability and lifecycle statusesFleetU
83Versioned multi-deck vehicle layoutsFleetPCanonical validated layout documents; full multi-deck UX pending
84Configurable company seat categoriesFleet + inventoryPCompany defaults/backfill implemented; full settings UX pending
85Per-vehicle amenity and capacity configurationFleetPVehicle/resource capacity model; complete surfaces pending
86Planned maintenance, repairs, cleaning, faults, history, and downtimeMaintenanceU
87Vehicle documents with expiry and renewal alertsComplianceU
88Driver list, account, status, assignments, documents, and performanceWorkforceU
89Complete driver profileWorkforceU
90Driver qualification/document expiry managementComplianceU
91Driver availability and duty statusesWorkforceU
92Primary/secondary driver assignmentDispatchU
93Individually accountable Driver App accountsDriver identityPRole seed + Driver/Assignment identity verified; app audit pending

Driver application capabilities

IDCapabilityPrimary ownerStatusEvidence
94Individual driver authenticationDriver identityPIndividually linked auth identities; device/session matrix pending
95Today and upcoming duty listDriver appU
96Pre-departure trip briefingDriver appU
97Stop-aware passenger manifest and progressManifestU
98Camera QR scanning for digital and paper ticketsCheck-inU
99Trip/date/stop/status/duplicate/seat/extras validationCheck-inPCaller/trip/status/duplicate contract; stop/extras pending
100Unambiguous scan result statesDriver UXU
101Manual passenger search and authorized check-inCheck-inPAtomic authorized code check-in; search UX pending
102Minimal operational passenger detailManifestU
103Boarded/expected/missing progressManifestPOperations snapshot contract; mobile UX pending
104Boarding and alighting by stopManifestU
105Resilient live GPS telemetryTelemetryPIdempotent offline replay + health contract
106Bus-suitable turn-by-turn navigationNavigationU
107Ordered stop navigation and next-stop ETANavigationPStop Call ordering/ETA contract; navigation UI pending
108Live ETA propagationTelemetryPFuture Stop Call propagation verified locally
109Schedule-versus-telemetry delay detectionDisruptionsPDelay/disruption/alert contract
110Structured delay-cause reportingDisruptionsPCause vocabulary/RPC verified; complete surfaces pending
111Driver-to-control-center messagingOperations communicationU
112Break announcement propagated to passengersOperations communicationPBilingual durable fanout contract; device delivery pending
113Stop closure, detour, road closure, and alternative-stop reportingDisruptionsPDomain/RPC contract; complete UX pending
114Structured incident reports with location and attachmentsIncidentsU
115Vehicle issue reporting and replacement escalationMaintenance + dispatchU
116Trip completion record and metricsOperationsU

Company operations, quality, and finance capabilities

IDCapabilityPrimary ownerStatusEvidence
117Live fleet operations mapControl centerPTenant-safe live-location projection; map/browser audit pending
118Exception-oriented active-trip control centerControl centerP00239 active-risk-first bounded snapshot; UI integration pending
119Prioritized trip exception queueControl centerPAlert/disruption/delay/GPS ranking verified; UI integration pending
120Capacity/amenity/accessibility-safe vehicle replacementDispatchU
121Audited primary/secondary driver replacementDispatchU
122Sold, boarded, capacity, and occupancy truthOperationsPDrift-resistant operations snapshot contract
123Seat, vehicle, route, slot, and empty-seat utilizationAnalyticsU
124Multidimensional quality managementQualityPSix-metric period snapshot + SLA contract; surfaces pending
125Explainable aggregate quality scoreQualityPWeighted evidence/hash contract; surfaces pending
126Punctuality analysis by route, vehicle, driver, stop, and timeAnalyticsU
127Driver operational and quality analyticsAnalyticsU
128Vehicle utilization, issue, downtime, complaint, and cost analyticsAnalyticsU
129Route volume, occupancy, punctuality, revenue, and quality analyticsAnalyticsU
130Configurable partner revenue-sharing modelFinancePVersioned effective Commercial Terms; admin UI pending
131Gross/share/adjustment/bonus/penalty/tax/payment dashboardFinanceU
132Settlement period and trip-line lifecycleSettlementPExact transactional settlement contract; UI pending
133Idempotent automated monthly billingSettlementPpg_cron queue/retry/dead-letter contract; production pending
134Billing history and statusFinancePTenant-safe paginated RPC; UI pending
135Professional invoice, statement, breakdown, tax, and payment documentsDocumentsU
136Scheduled/operated/cancelled/paid reconciliationFinancePPer-Trip reconciliation/payment contract; UI pending
137Configurable performance incentives and deductionsSettlementPTerms + audited adjustment contract; UI pending
138Role-aware company document centerDocumentsU
139License, inspection, insurance, and missing-document alertsComplianceU
140Courses, requirements, completion, certification, and acknowledgmentTrainingU
141Operational notices and acknowledgmentsCompany communicationU

Central platform capabilities

IDCapabilityPrimary ownerStatusEvidence
142Platform-controlled cities, stops, routes, frequencies, timetables, and expansionNetwork planningU
143Demand forecasting inputs and outputsRevenue managementU
144Demand-based capacity/production planningNetwork planningU
145Platform fare authority with tenant-safe operator inputsPricingU
146Capacity/lead-time/seasonality-aware revenue optimizationPricingU
147One authoritative channel-neutral inventoryInventoryP00227 atomic seats/extras; all channel callers pending
148Central brand, campaigns, SEO, promotions, and acquisitionMarketingU
149Central omnichannel ticket salesDistributionU
150Travel-agent/reseller booking and commission portalDistributionU
151Affiliate, widget, GTFS, API, white-label, metasearch, and attribution integrationsDistributionU
152Cross-company central traffic controlPlatform operationsU
153Cross-company support CRM with booking contextSupportU
154Comparable operator SLA and quality oversightPlatform qualityPCross-Company quality comparison RPC; admin UI pending

Beyond-benchmark backlog

These requirements are part of the requested target, not optional ideas. They receive stable IDs so they can be traced like the numbered benchmark.

IDCapabilityPrimary ownerStatusEvidence
BT-01Interactive network and live-journey mapsTravelerU
BT-02Nearby stations and proximity-aware discoveryTravelerU
BT-03Approaching-bus visualization and vehicle photo/modelTravelerU
BT-04Transfer guidanceTravelerU
BT-05Apple Wallet and Google Wallet ticketsTicketingU
BT-06Smart favorites and price alertsTravelerU
BT-07Departure alerts and family live-trip sharingTravelerU
BT-08Loyalty, travel credits, student accounts, family profiles, and saved passengersTravelerU
BT-09Saved payment methods behind compliant provider tokenizationPaymentsU
BT-10Accessibility filters, in-app support chat, and AI travel assistantTravelerU
BC-01Drag-and-drop dispatch and utilization planningCompanyU
BC-02Driver scheduling, hours compliance, and conflict preventionCompanyU
BC-03Vehicle assignment conflict preventionCompanyU
BC-04Maintenance planning, fuel/energy, depots, and cost per kilometerCompanyU
BC-05Route profitability, payroll export, custom reports, SLA, incident center, and full auditCompanyU
BD-01Offline manifest, QR validation, and deterministic synchronizationDriverU
BD-02Stop checklist, headcount, missing-passenger warning, and rest timerDriverU
BD-03Pre/post-trip inspection and damage photo workflowDriverU
BD-04Emergency contact, voice announcements, and multilingual templatesDriverU
BP-01Contract management and central route/network builderPlatformU
BP-02Forecasting, pricing, inventory, and revenue-management workbenchPlatformU
BP-03Settlement, risk, fraud, reconciliation, and BI warehousePlatformU

Product-owner additions

These items record requirements that are not fully represented by the numbered benchmark. They are mandatory and follow the same evidence rules.

IDCapabilityPrimary ownerStatusEvidence
PO-01Isolated, expiring, resettable company demos with role accounts, seeded scenarios, and a deterministic traveler launchDemo platformPTenant isolation and deterministic bookable launch contracts exist; complete role/browser/production matrix pending
PO-02Strict public, internal-QA, and demo inventory scopes across discovery, quote, booking, operations, and analyticsInventory + authorizationPDiscovery/quote isolation contracts exist; every downstream projection and production role still requires verification
PO-03Company-configurable manual confirmation with distinct requested, confirmed, rejected, expired, ticket-issued statesBooking policyVMigration 00305, shared web/mobile/Driver projections, tenant settings and decision APIs, immutable-document/QR guards, notification fanout, and rollback-only PostgreSQL plus focused app contracts pass locally; production role/browser/device evidence pending
PO-04Cash-first payment policy, provider-neutral online-payment adapters, and development-only online channels until activatedPaymentsPCash-first and disabled-provider foundations exist; end-to-end reconciliation and release gates pending
PO-05Professional ticket, receipt, reservation, invoice, statement, and settlement PDFs with QR, audit, retry, and deliveryDocumentsPVersioned document registry/renderer foundations exist; complete document matrix and all-app integration pending
PO-06Versioned SMS, email, push, in-app, and printable communication templates for the complete operational event taxonomyNotificationsPDelivery/template foundations exist; event coverage, provider evidence, previews, and production reliability pending
PO-07Centralized, versioned legal center linked from every app with consent evidence and counsel-reviewed market variantsLegal + complianceU
PO-08Minimal role-correct login and signup flows, traveler Google identity, phone/email methods, recovery, and account linkingIdentity + design systemPLocal traveler identity foundation exists; final visual/device matrix and external Google credentials pending
PO-09Company-owned loyalty configuration, earning, redemption, liability, reporting, and customer presentationCompany commerceU
PO-10Custom demo offers with safe predefined scenario packs plus optional company-specific seeded dataSales engineeringU
PO-11Information-rich approval review workspace with side-panel detail, documents, risk, decision history, and auditAdmin compliancePExisting approval flow is partial; complete evidence pending
PO-12Explicit no-show state at passenger/segment level with manifest, reporting, policy, communication, and settlement effectsOperationsU
PO-13Secret-safe ecosystem service catalog with URLs, seeded-role instructions, health, ownership, and Slack alert routingPlatform operationsPOperational foundations exist; canonical catalog and end-to-end Slack event verification pending
PO-14One coherent responsive design system across every surface, with professional icons, motion, RTL/LTR, and native mobile UXDesign systemPShared packages exist; exhaustive source/browser/device migration remains open
PO-15Measured performance budgets for search, trip lists, navigation, images, APIs, low-end devices, and degraded networksPerformance engineeringU
PO-16Unique, operator-managed trip media with realistic Syria-context imagery, provenance, optimization, crop, and fallbacksMedia + traveler experienceU
PO-17Company-managed trip pickup and drop-off locations with map coordinates, landmarks, instructions, and per-trip overridesCompany operationsPInitial pickup-location domain/UI exists; edit lifecycle, drop-off parity, and complete app propagation pending
PO-18Controlled driver pickup/drop-off changes with reason, GPS/time evidence, dispatch approval policy, audit, and notificationsDriver + dispatchU
PO-19Onboard/walk-up booking for unplanned passengers with exact boarding/alighting segment, seat/capacity truth, and offline syncDriver salesU
PO-20Driver-entered fare under company policy with limits, reason codes, cash collection, shift reconciliation, and fraud controlsDriver sales + financeU
PO-21In-bus ticket/receipt/invoice printing through an adapter for Bluetooth thermal printers with PDF/share fallbackDriver documentsU
PO-22Secure booking retrieval by authenticated ownership or booking code plus family name, with rate limits and privacy controlsTraveler self-servicePGuest-access foundation exists; complete channel and production verification pending
PO-23Secure in-person document copy through an expiring, purpose-scoped QR exchange; explicit recipient preview/acceptance; revocation, replay protection, signed offline display, and channel fallbacks; Booking ownership transfer remains a separate authenticated flowDriver + traveler documentsPMigrations 0029800303, customer-web grant/preview/accept/revoke/download flow, two-phase delivery evidence, customer-mobile native PDF sharing, and assigned-Driver document delivery exist; verified native app-link entry, mobile recipient wallet, and signed offline nearby transfer remain open
PO-24Professional billing details remain optional for cash and are requested only when an enabled payment method or applicable legal rule requires themCheckout + financePMigrations 0027600278 and 00281 separate traveler billing data, card requirements, development-only online providers, and cash-first policy; complete surface and jurisdiction-policy verification pending

Research-backed additions beyond the supplied inventory

The enterprise transport capability research uses official transport, identity, security, accessibility, payment, mobile-platform, and printer sources to stress-test the supplied benchmark. These rows are separate from the product-owner additions so a recommendation cannot silently become a claim about a competitor or about current ShamBus behavior.

IDCapabilityPriorityStatusCurrent evidence and dependencyMinimum acceptance
E-01Versioned Trip Stop Call pickup/drop-off overrideP0PMigrations 0027900286 establish initial pickup/location projections; canonical override lifecycle and full app propagation remain dependenciesA dated Stop Call can override the reusable Stop without mutating other Trips; old/new values, actor, reason, version, effective time, and authorization are preserved
E-02Pickup-change propagation and acknowledgmentP0P00282 and notification projections provide partial foundations; channel delivery, crew/passenger acknowledgment, and control escalation remain openEvery affected passenger and crew member receives the exact changed rendezvous; delivery/acknowledgment is observable and unacknowledged high-risk changes escalate
E-03Driver, reseller, and office point-of-sale channelsP0PCustomer and office booking paths exist; driver/reseller channel parity, delegated authority, and shared transaction evidence are missingEvery channel creates the same authoritative Journey transaction with actor, channel, pricing, inventory, payment, fulfillment, audit, and idempotency semantics
E-04Per-passenger boarding and alighting rights for walk-up salesP0UDepends on canonical Passenger × Journey Leg/Stop Call rights and onboard-sale commandsEach traveler in a group has explicit board/alight Stop Calls, fare, seat/extras, ticket rights, and manifest visibility
E-05Versioned fare catalogue and governed driver overrideP0UDepends on fare authority, company policy, role limits, reason codes, and immutable price-version snapshotsDriver-entered prices cannot bypass floors/ceilings or approval rules and always retain quoted, overridden, tax, currency, reason, actor, and audit values
E-06Cash shift, drawer, variance, and reconciliationP0PMigrations 00211, 00234, 00241, and 00242 provide cash/settlement foundations; driver-sales custody and closeout parity remain dependenciesOpening float + collections − refunds/change produces expected cash; driver declares close, variance is recorded, exceptions are reviewed, and settlement is traceable
E-07Confirmation separated from fulfillmentP0PConfirmation-policy foundations exist; a single enforced state machine across every booking channel and boarding projection remains incompleteRequested/approved/rejected/expired states are distinct from ticket issuance; no valid-looking boarding credential exists before approval
E-08Booking, reservation confirmation, ticket, receipt, and invoice semanticsP0PVersioned document registry/renderer foundations exist; complete type-specific authority, numbering, delivery, and all-surface integration remain openEach document has one defined legal/operational purpose, immutable source snapshot, version/hash, access policy, lifecycle, rendering contract, and audit trail
E-09Hybrid signed boarding QR plus online control registryP0PSigned ticket and check-in primitives exist; production key rotation, revocation/use registry, offline freshness, and device evidence remain dependenciesOffline validation proves authenticity and scope while online control resolves current issue/use/revoke/refund/reissue state without embedding unnecessary PII
E-10Bounded offline inventory leases for guaranteed salesP0UDepends on device/shift/Trip/segment/resource lease allocation and reconciliationOffline-capable devices receive non-overlapping, expiring inventory authority; oversell is impossible under tested partition, retry, expiry, reassignment, and recovery
E-11Idempotent offline command and reconciliation ledgerP0UGeneral offline queues exist, but the financial/inventory command envelope and deterministic conflict ledger are not verifiedEvery command has stable identity, actor/device/shift/Trip/Stop context, sequence, trusted-time evidence, hash chain, result, retry, conflict, and reconciliation outcome
E-12Versioned legal center and consent evidenceP0UDepends on counsel-approved market content, immutable versions, publication rules, acceptance events, and centralized app linksEach app resolves the same applicable immutable document version and can prove who accepted which content/hash, when, in what locale/context, and what superseded it
E-13Printer adapter, spooler, health, and audited reprintP1UDepends on device-neutral printer contract, selected hardware adapters, spool persistence, and physical-device testsBooking commit is independent of print outcome; jobs expose pending/accepted/printed/failed/unknown, retry the same document, audit reprints, and offer PDF/share fallback
E-14Secure document copy versus authenticated ownership transferP1PPurpose-scoped document grants, explicit acceptance, revocation, one-use recipient sessions, and immutable delivery evidence are implemented; authenticated ownership-transfer ceremony is intentionally separate and remains openSharing grants least-privilege access to one immutable artifact; changing booking ownership requires separate authenticated authorization and never occurs by scanning
E-15Verified offline phone-to-phone ticket deliveryP1UDepends on mutually verified nearby transport, signed artifact package, freshness policy, duplicate handling, and platform adaptersSender and receiver compare a verification value, transfer only the intended signed artifact, preserve provenance, and safely reconcile duplicates after connectivity
E-16Trusted time and offline freshness policyP1UDepends on server time anchors, monotonic device intervals, keyset/package expiry rules, and clock-tamper handlingEditable wall-clock time never solely determines fare, credential, lease, or legal validity; stale and rollback-clock cases fail predictably and recover safely
E-17Ticket-control and fraud lifecycleP1PQR/check-in/token contracts provide a foundation; unified issue/use/duplicate/revoke/refund/reissue/key-rotation operations and analytics remain openOne ledger explains every credential state transition, supports offline/online decisions, prevents replay, and gives authorized support/control users actionable evidence
E-18Device, keyset, and package freshness control centerP1UDepends on device registry, app/key/config/package versions, health telemetry, policy enforcement, and operations UIOperations can identify stale/offline/compromised devices, prevent unsafe use, rotate keys/config, and verify recovery without exposing cross-tenant data
E-19Standards adapters with internal-model isolationP1UDepends on stable internal Journey/Stop Call/fare/document contracts plus explicit GTFS/GTFS-Realtime/OSDM mappings and conformance testsImports are validated/quarantined, exports are reproducible, experimental external fields cannot redefine internal truth, and adapter versions are observable
E-20Connected data-quality, lineage, and quarantine workflowP1UDepends on provenance metadata, validation rules, quarantine/correction workflow, ownership, and quality metricsInvalid or conflicting Stop, fare, Trip, identity, and operational data cannot silently publish; correction preserves source, decision, impact, and audit history

Sequential execution program

Work proceeds in this order. A later phase may be researched while an earlier phase runs, but no later phase can be declared complete before the earlier gate is closed.

PhaseScopeExit gate
0Stabilize the current release: booking/Journey correctness, inventory scope, CSRF, CSP, demo launch, identity, profile prefill, driver demo access, critical responsive defectsFocused and full regression suites pass; migrations are safe; affected apps build; authenticated browser flows pass locally and in production; release is documented and rollback-ready
1Exhaustive inventory and evidence-based research: every route, component, API, table, job, template, document, notification, role, device flow, competitor capability, and Syria-specific constraintEvery requirement has a stable ID, confirmed current status, dependencies, acceptance criteria, and authoritative research where applicable
2Canonical domain and data model: Journey/legs/stop calls, pickup/drop-off, inventory, booking/passenger segments, identities, operations, finance, documents, notifications, audit, and isolationVersioned terminology/ADR, safe migrations/backfills, constraints/indexes/RLS, typed contracts, and database behavior tests pass
3Shared experience infrastructure: icon registry, no-emoji guard, Latin digits, i18n, custom select/date/time/phone/filter/data-table/entity/media primitives, motion and adaptive navigationCompeting primitives are removed, source guards are green, accessibility/RTL/LTR/responsive component suites pass
4Traveler web and customer mobile parity: discovery, direct/connecting Journey, seats/extras, identity, checkout, confirmation, tickets, self-service, tracking, companies, support, legal, and offlineSame capability/state matrix on web and mobile; browser/device/low-network/guest/authenticated tests pass
5Driver operating product: duty, briefing, manifest, scan/manual check-in, pickup changes, walk-up sales, price controls, cash, printing, offline sync, telemetry, navigation, incidents, completionReal device and printer-adapter tests, offline/conflict recovery, permissions, audit, reconciliation, and production role checks pass
6Company transportation OS: operations, routes/schedules/trips, fleet/wizard/maintenance, drivers, bookings, confirmations, pickup points, loyalty, quality, finance, documents, team, public profileTenant/role matrix, cross-entity navigation, server filtering, workflows, reports, and production company-role tests pass
7Admin/control/support platform: onboarding, approvals, demos, network/pricing/inventory, live control, compliance, support CRM, quality, settlements, audit, and feature operationsCross-company authorization, four-eyes/high-risk controls, audit, performance, and production admin-role tests pass
8Enterprise services: notification providers/templates, PDFs and printing, payments adapters, legal/consent, Slack/observability, credentials/runbooks, media pipeline, analytics/BI, integrationsProvider failure/retry/idempotency/audit/security tests pass; all external blockers are explicitly named; operational runbooks are current
9Release certification: clean worktree, full CI-equivalent suites, database reset/migration proof, builds, desktop/tablet/mobile browsers, physical devices, accessibility, RTL/LTR, performance, security, backup/rollback, deploy, and production role matrixOnly evidence-backed R rows remain; unresolved external dependencies stay B; release commit is pushed and the server revision, migrations, services, and user-visible flows are verified

Within every phase, implementation order is deterministic: audit → model/acceptance criteria → failing tests → backend/data → shared components → app surfaces → edge/offline/error states → documentation → full local verification → commit/push → deploy/migrate → production verification → ledger status update.

Cross-cutting global standards

The thirteen ecosystem standards are independent acceptance gates. A source-level foundation is not sufficient to mark a standard verified across every app.

IDStandardStatusCurrent evidence and remaining dependency
GS-01Professional iconography; no emoji in any product UIPlint:product-standards and the web/mobile icon foundations pass locally; exhaustive visual, notification-template, generated-artifact, and production-device evidence remains
GS-02No native web Select; shared accessible selection systemPShared React Aria Combobox/MultiSelect and source guard exist; advanced async/large-data/mobile behavior and complete production interaction matrix remain
GS-03No native browser date picker; shared date/time systemPShared single/range/date-time/time controls and source guard exist; all presets, disabled-date policy, mobile overlays, and device/browser accessibility evidence remain
GS-04Advanced server-side filtering, sorting, and saved viewsPShared FilterBar exists and Routes is migrated; canonical collection-query backend, all meaningful collections, URL persistence, saved views, and index evidence remain
GS-05Connected contextual entity graph and state-preserving linksPCore foreign keys and some detail links exist; shared entity-reference/read-model/navigation contract and complete cross-resource coverage remain
GS-06Latin digits in every locale, surface, input, and documentPpackages/utils/src/latin-digits.ts, Flutter formatters, and source guard exist; PDF/email/push/chart/input and production-device proof remain
GS-07Shared international E.164 phone input, Syria default, LTRPWeb and Flutter shared controls use maintained parsers, SVG flags, +963, LTR isolation, and tests; exhaustive caller/API/database/device verification remains
GS-08Configurable default seat types for every companyP00219_global_product_foundation.sql and database tests provision four editable types; safe live backfill and full dashboard/booking production evidence remain
GS-09Complete, recoverable, high-capability New Bus wizardPExisting staged wizard and advanced layout editor are substantial; metadata depth, versioned autosave, recovery, mobile UX, validation, and production evidence remain
GS-10Operator-managed custom Trip media domainP00220_public_company_profiles_and_trip_media.sql defines media, variants, and focal data; upload/crop pipeline and complete dashboard/customer integration remain
GS-11Managed and polished public Company profilesP00220, public profile query tests, and customer API foundation exist; tenant editor, moderation, gallery/policies/routes UI, and full production verification remain
GS-12Native-quality customer and driver mobile productsPShared Flutter architecture, route gate, and broad tests exist; remaining desktop-shaped flows, physical Android/iOS, accessibility, low-end/offline, and visual QA remain
GS-13Traveler-only Google identity and account linkingBWeb/native verified-token and identity-linking foundations pass locally; production Web/Android/iOS OAuth clients and real-device provider evidence are externally blocked

The detailed baseline and migration findings remain in Global product standards audit.

Phase 1 evidence register

Evidence IDArtifactStateWhat it provesWhat it does not prove
A-01Generated ecosystem surface inventoryCurrentDeterministic source inventory of web routes/APIs, resolved Flutter routes/screens, shared modules, migration declarations, workers, Compose services, and test-file rootsLive database shape, runtime reachability, permissions, UX quality, or production correctness
A-02tests/e2e/route-flows/manifest.ts plus pnpm --filter @shambus/e2e-tests audit:coverageCurrentEvery discovered Next page and resolved Flutter route has an explicit route-flow manifest entryThat every command, role, device, deep link, or exceptional outcome works
A-03Enterprise transport capability researchCurrentPrimary-source capability/edge-case baseline, Syria-context recommendations, legal boundary, and E-01–E-20 additionsShamBus implementation status or Syrian legal approval
A-04Global product standards auditCurrentOriginal occurrence inventory, shared-seam analysis, migration rules, and known local source/test evidenceComplete live visual review or production/native-device certification
A-05Live schema auditProductionMatching local and production ledgers contain 287 files through 00297; every Company has one durable cash-only policy row; both environments report the same 473 application functions; production has RLS on 156/156 public tables, healthy runtime posture, 720 valid indexes, 1,200 validated constraints, and 46/46 rollback-only database contracts passing in one sessionThis proves the deployed database shape and its database-level contracts, not every API authorization path, external integration, browser/device flow, performance target, or user-experience state
A-06Mobile station deep-link contractProduction web/station/:stationId resolves from a real public city identifier after refresh or copied-link entry; its API unit contract and customer-mobile analysis pass; a read-only production Chromium regression resolves Damascus from the live API with no HTTP, console, font, or horizontal-overflow failurePhysical Android/iOS deep-link behavior, slow-network behavior, and native map-app handoff remain unverified

Phase 1 remains in progress. The generated inventory closes source discovery coverage and A-05 closes the matching local/production database-shape and security slice, including the exact service-only table allowlist. Per-capability dependency review, runtime behavior, and user-experience audits remain open.

Required evidence per capability

A row can move to V only when applicable evidence includes:

  1. domain terminology and state-transition rules;
  2. schema, foreign keys, constraints, indexes, migrations, and backfill;
  3. tenant/role authorization and privacy tests;
  4. typed command/query API contracts and failure modes;
  5. every applicable web/mobile surface and connected navigation;
  6. loading, empty, error, conflict, stale, offline, and retry behavior;
  7. Arabic RTL and English LTR behavior with Latin digits;
  8. desktop, tablet, phone, keyboard, screen-reader, and low-end-device checks;
  9. unit, database, API, integration, and end-to-end tests;
  10. operational metrics, logs, audit events, and notification/document effects;
  11. updated user and internal documentation;
  12. production migration, smoke evidence, and rollback readiness.

External credentials or approvals may move a capability to B, but they never justify marking it verified or released.