pelagia-portal/Docs/03-open-questions.md

1.8 KiB

Pelagia Portal — Open Questions & Decisions Log

Track decisions that need sign-off before the corresponding feature is built. Update the Status column when resolved.

# Question Raised By Status Decision
1 Should a manager be able to directly edit a PO (bypass the submitter edit cycle) in exceptional circumstances? Design review Open
2 Is dual sign-off required for POs above a certain value threshold? If so, what is the threshold and how is the second approver selected? Design review Open
3 Is the vendor registry Admin-only, or can Managers also add/edit vendors? Design review Open
4 Is SSO (Azure AD / Google Workspace) required for login, or is internal credential management sufficient for v1? Architecture review Open
5 What currency / currencies does the system need to support? Is multi-currency (with FX rates) in scope? Design review Open
6 Should rejected POs be hard-deleted after a retention period or permanently archived? How long is the retention window? Legal / compliance Open
7 Should documents (PO attachments, receipts) be publicly accessible via URL, or always served through a signed/authenticated download? Security review Open
8 Are there specific vessels or accounts that certain submitters are restricted to (i.e., row-level vessel permissions), or is any submitter able to raise a PO against any vessel? Design review Open
9 What is the expected volume? (POs per day, concurrent users) — affects connection-pool sizing and whether Vercel serverless is sufficient. Architecture review Open
10 Should Manager analytics (spend by vessel/month) include only CLOSED POs, or all POs from MGR_APPROVED onwards? Design review Open