Health, Education & Government Government & Public Sector Government IT & Digital Services

Government Case Management Systems

Multi-agency, multi-stakeholder programs where procurement, compliance, and mission alignment determine success.

Example organizations in this space: Tyler Technologies Oracle Microsoft Deloitte

This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.

Inside this journey
  1. Qualification

    Confirm budget, decision authority, procurement timeline, and the triggering mandate or audit before investing in full discovery.

    Qualification Questions

    Fit: Security, Configurability, Migration, and 5‑year TCO requirements (quick check to confirm core constraints before full discovery)

    • Which formal security authorization or compliance baseline must be in place for procurement to proceed? Options: FedRAMP Moderate / FISMA Moderate (ATO required), FedRAMP Low / FISMA Low (ATO required), State or local security certification only (no federal ATO), No formal ATO required, but an agency security review will occur, Unsure
    • Will the solution need to process or store regulated data that affects compliance (for example CUI, PII, or PHI)? Options: Yes — CUI/PII only, Yes — PHI included (HIPAA considerations), No regulated data, Unsure
    • Which best describes your expected implementation approach: do you require configuration-only, or will significant custom development be needed? Options: Configuration only (no custom code), Primarily configuration with minor customizations, Significant custom development required, Unsure
    • Do you expect data migration from legacy sources, and which option best matches the scope? Options: No migration required, Single legacy system with structured data, Multiple legacy systems or significant unstructured documents, Extensive archives (greater than 1,000,000 records/documents), Unsure
    • Briefly describe the single biggest risk or constraint that would prevent you from committing to a full discovery conversation (one or two sentences).

    Budget

    • Is there an allocated budget range for this initiative that we should align to? Options: Yes — under $250,000, Yes — $250,000 to $1,000,000, Yes — $1,000,000 to $3,000,000, Yes — over $3,000,000, No allocated budget yet, Prefer not to say / Unsure

    Decision Authority

    • Who is the decision owner for selecting a platform, and which roles must sign the final procurement? (select all that apply) Options: Program / Business Owner, Chief Information Officer (CIO), Chief Information Security Officer (CISO), Procurement Officer / Contracting Officer, Legal / General Counsel, Other (please specify in discovery)

    Timeline & Trigger

    • What is your target procurement or go-live timeframe? Options: Immediate — 0 to 3 months, Near-term — 3 to 9 months, Planning — 9 to 18 months, Exploratory / no firm timeline
    • What is the primary trigger driving this timeline (select the one most applicable)? Options: Legislative mandate, Audit finding requiring remediation, System end-of-life or vendor sunset, Operational backlog / service risk, Budget or strategic planning cycle, Other, Unsure
  2. Outcome Discovery

    Align on desired outcomes, current workflows, data sources, stakeholders, and success criteria for modernizing case management.

    Discovery Questions

    Getting oriented: the program you want to change

    • Tell us briefly which program or service this case management solution will support.
    • How many active cases does your program handle in a typical month? Options: Under 100, 100–499, 500–2,499, 2,500–9,999, 10,000 or more
    • Which case types make up the majority of your workload, choose all that apply. Options: Investigations, Licensing/permits, Benefits adjudication, Constituent service requests, Compliance reviews, Other (explain below)
    • Who are the primary day-to-day users and their roles (for example: intake clerks, investigators, adjudicators, analysts)?
    • Describe your current approach to storing case attachments, evidence, and audit logs.
    • Approximately what share of your cases contain sensitive or controlled information that requires restricted access? Options: 0–10%, 11–30%, 31–60%, 61–90%, 91–100%

    Where the current process breaks and why it matters

    • If you could fix one recurring failure that most frequently causes rework or audit findings, what would it be?
    • When a case slips or is delayed, what downstream consequence costs you most in time, budget, or compliance risk? Options: Investigation rework, Missed statutory deadlines, Increased FOIA or discovery burden, Staff overtime, Reputational damage, Other
    • Which manual steps in intake, evidence handling, or adjudication create the highest error rate or delay? Options: Intake data entry, Evidence indexing, Assignment routing, Notification and approvals, Final certification/release, Other (explain)
    • How often do oversight reviews or audits identify recordkeeping, access control, or chain-of-custody gaps? Options: Every review, Often, Sometimes, Rarely, Never
    • In your last external or internal review, which single finding concerned leadership the most?

    If you could redesign the lifecycle, what would actually change

    • What single change to your case lifecycle would deliver the biggest reduction in time to resolution?
    • Name the people or roles who must see outcome dashboards to act on backlog and trends. Options: Program director, CISO/security lead, Procurement officer, Supervising investigator, Data analyst, Other (list)
    • Name the two or three metrics you would expect to see improve within three months of launch.
    • Walk me through a recent case that shows the outcome you want the platform to enable, from intake to closure.
    • List the workflows that must be configurable without developer changes because policy or law updates them frequently.

    Who's involved, who decides, and how fast they'll move

    • If this reaches procurement, who will be the named decision authority and what proof will they require to sign?
    • Identify the reviewers from CISO, legal, program office, and procurement and the single concern each will raise.
    • Name the person who will act as agency product owner embedded in sprints and the person who will provide final acceptance.
    • Estimate weekly hours each approver can commit to sprint activities during implementation. Options: Under 2 hours, 2–5 hours, 6–10 hours, 11–20 hours, 20+ hours
    • Should any of these decision roles be vacant, describe the hiring or assignment plan and expected timeline.

    Data and integrations, and the one thing that will stop cutover

    • What integration failure or missing data source would prevent you from cutting over to a new system?
    • List the systems that must integrate at go-live and indicate whether an API is available for each. Options: Identity provider (Yes/No), Legacy case store (Yes/No), Document repository (Yes/No), Reporting/data warehouse (Yes/No), External law enforcement or licensing systems (Yes/No)
    • For each required integration, provide the owning team, the expected API availability, and a contact for test credentials.
    • Rate the migration readiness of your legacy records. Options: Largely standardized and exportable, Partially tagged and exportable with work, Unstructured and requires significant curation
    • Identify the data elements or indexed fields that must retain exact parity for reporting and legal discovery.
    • Should a required API lack documentation or test access within 4 weeks, what contingency would you accept (for example, manual extract, temporary connector, or delayed integration)? Options: Manual extract and staged migration, Temporary connector built by agency, Delay integration until API available, Other (explain)

    Risks, constraints, and the things that will stop procurement

    • Point to the regulatory or policy constraint that could force you to abandon a vendor solution and remain on the current system.
    • Provide the office or role that can grant an exception to that requirement and the typical time to decision.
    • Are there pending legal reviews, data sharing MOUs, or legislative approvals that could stall the project? Options: Yes, legal review pending, Yes, MOU or data sharing pending, Yes, legislative approval pending, No major gating items
    • Describe the conditions under which your team would choose to keep the current approach rather than change.
    • Would failing to meet your Authority to Operate prerequisites within your procurement window stop the procurement? Options: Yes, it would stop procurement, No, procurement would continue with mitigations, Depends on which prerequisite is unmet

    The other paths you are weighing

    • Imagine the incumbent or a different path keeps the program running—what would they need to demonstrate to prevent you from switching?
    • Select the options you have evaluated or are still considering. Options: Replace with commercial platform, Extend incumbent system, Rebuild internally, Open source solution, Hybrid approach, Other
    • For any internal-build proposals, who owns the plan and what are the current budget and timeline estimates?
    • State the single proof point the procurement officer would require to favor staying with the incumbent.
    • Is anyone on staff actively proposing to build this without an external partner, and if so, what is their timeline? Options: Yes, timeline under 6 months, Yes, timeline 6–12 months, Yes, timeline over 12 months, No internal build proposal

    Acceptance criteria, success signals, and the kill switch

    • Imagine your five-year total cost projection exceeds your internal threshold by 20 percent, would that stop the project? Options: Yes, stop the project, No, seek additional funds or scope reduction, Depends on offsetting benefits
    • Provide the concrete acceptance criteria that will allow your program office to sign off on pilot and production.
    • Define the minimum pilot size and the quantitative success threshold that would qualify the pilot for production.
    • Assuming the pilot proves the expected reduction in case resolution time, what internal approval would accelerate signature and within what timeframe?
    • Select the reporting formats and frequency procurement and the program office require for the first year post-launch. Options: Weekly executive summary, Monthly program dashboard, Quarterly technical reports, Ad-hoc incident reports, Real-time API feed

    Operational readiness, environments, and named approvers

    • Point to the Authority to Operate prerequisites that remain incomplete and the date you expect them cleared.
    • Choose the environments you can provide for testing within 4 weeks. Options: Sandbox with masked data, Full test environment with synthetic data, Production read-only access, No test environment available in 4 weeks
    • Tell us the person or role who will act as data owner and the approver for data extracts during migration testing.
    • Rate your internal technical capacity to support integrations during deployment. Options: Dedicated integration engineers available, Part-time support from IT, Contractor support required, No internal support available
    • Would the absence of named approvers and committed weekly hours for sprints prevent you from proceeding on the proposed timeline? Options: Yes, it would prevent proceeding, No, timeline can be adjusted, Maybe, depending on which approvers are missing

    Migration specifics, records preservation, and discovery

    • Suppose legacy data lacks consistent metadata or key fields, would legal hold and discovery requirements block migration? Options: Yes, migration would be blocked, No, staged migration with access controls is acceptable, Depends on the percentage of affected records
    • Choose the content types that must be migrated and searchable in the new platform. Options: Structured forms and fields, Scanned documents and images, Audio and video evidence, External case notes and emails, Third-party documents stored offsite
    • How many years of historical records must be fully searchable in the new system? Options: None, 1–3 years, 4–7 years, 8–12 years, 12+ years
    • Summarize your retention and destruction policies that the new platform must enforce or support.
    • Can the agency accept staged migration with read-only legacy access for legal discovery if a subset of records cannot be migrated intact? Options: Yes, staged migration acceptable, No, all records must be migrated intact, Only for specific record classes

    Next steps, timing, and the evidence that speeds decisions

    • Which single deliverable or proof—pilot result, security package, or migration plan—would most accelerate internal approval? Options: Pilot demonstrating time reduction, Completed ATO artifact set, Validated migration plan and sample migration, Total cost model within threshold
    • Select your target procurement window for award and go-live sequencing. Options: Award in <3 months, go-live <6 months, Award 3–6 months, go-live 6–12 months, Award 6–12 months, go-live 12–18 months, Longer than 12 months
    • Describe the single, manageable first step your team is willing to commit to in the next 30 days to move this forward.
    • Who should we invite to the next technical working session to unblock the first milestone? Options: CISO/security lead, Program product owner, Integration lead/API owner, Procurement representative, Data owner, Other (list)
  3. Solution Experience

    Walk through how the platform will deliver the buyer's outcomes using real workflows, migration scenarios, and ATO/security requirements.

    Solution Experience

    • Solution Experience Session
    • Confirm the current state and its cost to your team
    • You confirm the demonstrated workflow eliminates the manual handoffs and rework you described in Discovery.
    • Provide a representative extract of legacy records (up to 1,000 rows) and a description of how records should map to case types for the migration dry run.
    • You accept the migration approach shown as viable for reconciling legacy records without interrupting operations.
    • Walk an end-to-end workflow using your process
    • Provide the list of current stakeholders and the specific acceptance criteria your procurement team will use for ATO and data migration evaluation.
    • Prepare and deliver a tailored migration runbook and sample reconciliation report from the dry run within 7 business days of receiving the extract.
    • You agree that the presented ATO/security artifacts and control mappings meet the CISO review criteria or identify the exact remaining gaps.
    • Run a migration dry run with a sample extract
    • Compile and share the ATO/security artifacts already available and clearly note any outstanding artifacts or control gaps within 5 business days.
    • You commit to the next evidence deliverables and a target decision window for procurement.
    • Map ATO and security evidence to your CISO requirements
    • Validate the demonstrated outcomes against your needs
    • Confirm the target decision date and the named approver list required for procurement to proceed.
    • Agree remaining evidence and decision timeline
    • Solution Experience Session
    • Solution Experience Deck
    • Solution Brief
    • meeting
    • slides
    • document
  4. Security & Compliance Questionnaire

    Collect security artifacts, ATO prerequisites, identity integration needs, and data residency requirements the buyer's CISO and procurement will evaluate.

    Compliance Questions

    Security & Compliance Contacts and Timeline

    • Who is the primary security contact (name, role, email) we should work with for artifact review and technical questions?
    • Who is the procurement or contract contact (name, role, email) responsible for handling document exchange and legal attachments?
    • What is your target date for an Authority to Operate decision or equivalent security acceptance? Options: Within 2 weeks, 2-6 weeks, 6-12 weeks, 3+ months
    • Are there any hard regulatory or audit deadlines we should align to for delivering artifacts? Options: Yes, specify below, No
    • If you answered Yes above, please state the deadline and the related mandate or audit identifier.

    Authorization and Compliance Baseline

    • Which authorization baseline must the system meet for your acceptance? Options: FedRAMP Low, FedRAMP Moderate, FedRAMP High, FISMA Moderate, FISMA High, NIST 800-53 tailored, Other
    • Will the system be expected to store or process Controlled Unclassified Information or other regulated data types? Options: No, Yes, CUI, Yes, PII, Yes, PHI, Other regulated data
    • Do you expect to accept the vendor-provided authorization package, or will your agency require a custom SSP or integration into an existing ATO package? Options: Accept vendor package, Require agency-tailored SSP, Hybrid approach, Undecided
    • Are there specific standards, laws, or frameworks beyond the baseline above that we should document for your reviewers?

    Required Security Artifacts

    • Which of the following artifacts do you require from the seller as part of initial review? Options: System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), Penetration test report, Vulnerability scan reports, Architecture and network diagrams, Data flow diagrams, Configuration baselines, ATO package or Authorization Letter
    • Are there additional artifact formats or evidence types you expect that are not listed above?
    • Do you require artifacts to be delivered via a secure portal, or do you accept encrypted attachments? Options: Secure portal only, Encrypted attachments accepted, SFTP, Other
    • What file formats are preferred for artifacts (for example PDF, DOCX, CSV)? Options: PDF, DOCX, CSV, XLSX, Other

    Identity and Access Management

    • Which identity providers or federation protocols must the platform integrate with for authentication? Options: SAML 2.0, OpenID Connect (OIDC), LDAP, Azure AD, PIV/CAC, ADFS, Other
    • Do you require automated user provisioning/deprovisioning (for example SCIM)? Options: Yes, SCIM or equivalent, No, manual provisioning only, Not required initially, desired later
    • Is multi-factor authentication (MFA) required for users accessing the system? Options: Yes, No, Conditional for privileged users only
    • Which authentication methods are acceptable for MFA? Options: Authenticator app, PIV/CAC or smart card, Hardware token, SMS one-time code, Biometric, Other
    • Who is the agency IAM contact for technical integration and testing?

    Data Residency and Handling

    • Where must production data be physically located to meet your residency requirements? Options: Within United States, Within a specific state, specify below, Within agency-controlled infrastructure, No restriction beyond US
    • If data must be in a specific state or region, please name the state or region.
    • Do backups and disaster recovery copies need to follow the same residency constraints as primary data? Options: Yes, No, backups can be elsewhere, Specify exceptions
    • What data retention period applies to records in the system? Options: Under 1 year, 1-3 years, 3-7 years, 7+ years, Agency-specific schedule - specify below
    • If you selected agency-specific schedule, please summarize retention and disposition rules.
    • Are there any data handling or redaction requirements we should know about (for example masking in exports, restricted reporting)?

    Encryption and Key Management

    • Is encryption at rest required for all stored data? Options: Yes, No, Required for regulated data only
    • Is encryption in transit required for all communication channels? Options: Yes, No
    • Do you require customer-managed keys or bring-your-own-key (BYOK) capabilities? Options: Yes, BYOK required, Optional, No, vendor-managed keys acceptable
    • If BYOK is required, which key management service or HSM specification must be supported?
    • Are FIPS 140-2 or FIPS 140-3 validated cryptographic modules required? Options: Yes, No, Required for certain data types

    Logging, Monitoring, and SIEM Integration

    • What log retention period do you require for system and access logs? Options: 30 days, 90 days, 1 year, 3 years, Agency-specific, specify below
    • Do you require integration with an agency SIEM or logging endpoint? Options: Yes, SIEM ingestion required, Optional, No
    • Which log formats or protocols must the platform support for integration? Options: Syslog, CEF, JSON over HTTPS, S3 log export, Other
    • Do you require real-time alerting and an escalation path for high-severity security events? Options: Yes, No, Conditional
    • Please provide the technical contact or endpoint details for log transfer or SIEM onboarding.

    Vulnerability Management and Testing

    • How often must vulnerability scans or automated assessments be run against the system? Options: Weekly, Monthly, Quarterly, On demand, Other
    • How often do you require formal penetration testing for the platform? Options: Annually, Semi-annually, After major releases, Only before ATO, Other
    • Do you require the seller to share penetration test and vulnerability reports with your team? Options: Yes, full reports, Yes, executive summaries only, No
    • Do you expect remediation SLAs for high-severity findings, and if so what is the desired SLA in calendar days? Options: 30 days, 7 days, 14 days, Custom - specify below, No SLA required
    • If you selected Custom above, please specify the remediation SLA and any reporting cadence.

    Incident Response and Notification

    • What is your required vendor breach notification timeframe after discovery? Options: Within 24 hours, Within 48 hours, Within 72 hours, As soon as practicable
    • Do you require the vendor to align to your incident response plan or to participate in joint tabletop exercises? Options: Yes, align to agency plan, Yes, participate in exercises, No
    • Who should be notified for incidents (name, role, email, phone)?
    • Are there specific regulatory reporting obligations triggered by breaches we should document?

    Operational and Network Prerequisites

    • Which connectivity models are required or preferred for integration (for example VPN, private link, dedicated circuit)? Options: IPsec VPN, Private link / private endpoint, Dedicated circuit, HTTPS over internet, Other
    • Will you require IP allowlisting or fixed egress IPs from the vendor? If yes, will you provide a maintenance window for changes? Options: Yes, allowlist required, No, Yes, allowlist and maintenance window required
    • Are there network ports or protocols that must be explicitly opened for integration? If so, list them.
    • Do you require separate environments for production, staging, and development under the same residency and control rules? Options: Yes, separate environments required, No, shared non-production acceptable, Undecided

    Access, Approvals, and Artifact Review Process

    • Who is the authorized approver for accepting security artifacts and granting final acceptance (name, role, email)?
    • What is your preferred method for reviewing artifacts and evidence (secure portal, SFTP, encrypted email, in-person review)? Options: Secure portal, SFTP, Encrypted email, In-person / onsite review
    • How much time does your security team typically need to review an initial artifact package? Options: Under 1 week, 1-2 weeks, 2-4 weeks, 4+ weeks
    • Are there contractual or classification restrictions that limit how artifacts can be shared or stored? Options: Yes, restrictions apply, No restrictions, Unsure
    • If restrictions apply, please summarize them or attach guidance in the shared workspace.

    Final Check and Next Steps

    • Can you provide any of the requested artifacts immediately to accelerate review? Options: Full artifact package available now, Partial package available, No, not available yet
    • If partial or full artifacts are available, please list which items you can share first.
    • Would you like to schedule a technical onboarding call to walk through integration requirements and artifact expectations? Options: Yes, within 1 week, Yes, within 2-3 weeks, Maybe later, No
    • Are there any known blockers or high-risk items we should be aware of before beginning the authorization work?
    • Any other notes or constraints for the security and procurement teams to consider?
  5. Solution Scope

    Define modules, configurable workflows, migration scope, integrations, responsibilities, and five-year total cost of ownership assumptions.

    Scope Configuration

    • Provision FedRAMP-authorized platform instance
    • Deploy pre-built investigation, licensing, and benefits templates
    • Configure case types, stages, and automated workflows
    • Implement FISMA-compliant role-based access controls
    • Integrate agency identity provider (SSO/SAML/SCIM)
    • Migrate legacy case data and attachments
    • Ingest and OCR paper records and scanned documents
    • Validate and reconcile migrated records
    • Build API integrations to agency systems and endpoints
    • Configure reporting dashboards and scheduled exports
    • Configure audit logging and compliance reporting
    • Train end users and administrators

    Scope Questions

    Provision FedRAMP-authorized platform instance

    • Confirm the FedRAMP authorization level required for your agency instance (Moderate or High) and any Authority to Operate (ATO) deadline. Options: FedRAMP Moderate, FedRAMP High, Undecided / Need recommendation
    • Which cloud regions or agency-approved cloud tenancy must the instance be provisioned in to meet your data residency requirements?
    • Do you require the Authority to Operate package and System Security Plan (SSP) as procurement deliverables (evidence for security review)? Options: Yes, include full ATO package and SSP, No, we already have equivalent documentation, We need guidance on ATO deliverables
    • How many distinct environments do you need provisioned (development, test, staging, production) and what target dates do you have for each?
    • Are dedicated network isolation, customer-managed encryption keys, or private connectivity (VPN/direct connect) required for your instance? Options: None, Private connectivity only, Customer-managed keys required, Both connectivity and keys required

    Deploy pre-built investigation, licensing, and benefits templates

    • List which pre-built templates you plan to deploy first (investigations, licensing, benefits) and estimated active user counts for each template.
    • Do you require template customization for legally mandated workflow steps such as evidence chain-of-custody, statutory review periods, or external board signoffs? Options: Yes - customization required, No - use stock templates, Some templates require customization
    • How many distinct case variants per template will you operate (for example, fraud investigation vs administrative investigation)? Options: 1-3, 4-10, More than 10
    • Provide any regulator-prescribed forms, intake PDFs, or statutory timelines that must be embedded into templates at go-live.
    • Will you require role-filtered template views for investigators, adjudicators, clerks, and external reviewers? Options: Yes, No, Partial - only specified roles

    Configure case types, stages, and automated workflows

    • Define the full list of case types to be configured and attach existing case type definitions, policy maps, or statutory decision trees.
    • Specify the number of stages and sub-stages for your primary investigation workflow and the standard SLA (in days or hours) expected at each stage.
    • Are automated actions required at stage transitions such as evidence intake triggers, reassignment rules, statutory notice generation, or automatic calendar holds? Options: Yes - multiple automated actions, Yes - limited actions, No automation required
    • Identify decision points in your licensing workflow that must be enforced by system validations (for example, eligibility checks, fee receipt, supervisory approval).
    • List mandatory intake fields that must be enforced to maintain auditability for case triage (for example, case number, reporter SSN or masked identifier, incident date).

    Implement FISMA-compliant role-based access controls

    • State the user roles and short job descriptions that require unique permission sets (investigator, adjudicator, records clerk, auditor, system admin).
    • Indicate whether separation of duties restrictions tied to NIST 800-53 controls (for example AC-5) must be enforced between roles. Options: Yes - strict separation required, Partial - selected controls, No
    • Will privileged administrator actions require multi-factor authentication and just-in-time elevation workflows? Options: Yes - required, Optional, No
    • Specify the audit trails and user activity reports required for internal and external auditors and include required retention periods in months.
    • Attach any existing role matrix spreadsheets or CSV mappings to import as the initial permission baseline.

    Integrate agency identity provider (SSO/SAML/SCIM)

    • Share the identity provider type and configuration artifacts (SAML (Security Assertion Markup Language) metadata, SCIM (System for Cross-domain Identity Management) endpoints, or OAuth2 discovery documents).
    • Detail required claim mappings (for example email, employeeID, agencyUnit) that must populate case ownership and audit fields.
    • Confirm whether you require user provisioning via SCIM and a real-time deprovisioning service-level agreement (SLA). Options: Yes - SCIM provisioning and real-time deprovision, No - manual provisioning, SCIM provisioning only
    • When integrating SSO, state the certificate rotation window and signature algorithm your identity provider mandates.
    • Who will serve as the named identity integration approver and the technical contact for SAML metadata exchanges?
    • Indicate any service provider allowlists or IP ranges we must register for SSO health checks and metadata endpoints.

    Migrate legacy case data and attachments

    • Inventory the legacy systems and file formats that contain case records and attachments (for example, CSV exports, SQL database dumps, enterprise document management exports).
    • Estimate the total record count and total attachment storage size in gigabytes to be migrated. Options: Less than 10K records / <50 GB, 10K-100K records / 50-500 GB, More than 100K / >500 GB
    • State whether attachments include scanned PDFs, multimedia files (audio/video), or proprietary document formats that require conversion before import. Options: Scanned PDFs only, Includes multimedia, Includes proprietary formats, Mixed - see details
    • Describe how legacy unique identifiers should map to new case IDs and whether crosswalk tables exist for ID translation.
    • Detail the retention schedules and legal holds that apply to migrated records and which retention metadata fields must be preserved.
    • Should any records be sanitized or redacted prior to import for privacy, HIPAA, or Freedom of Information Act (FOIA) considerations? Options: Yes - redaction required, No, Partial - only specified record classes

    Ingest and OCR paper records and scanned documents

    • Name the types of paper records requiring OCR processing (for example, evidence intake forms, handwritten witness statements, intake PDFs) and list languages present.
    • Approximate the total page count for OCR and the average pages per document to size OCR throughput. Options: Less than 10K pages, 10K-100K pages, More than 100K pages
    • Require handwritten text recognition and specify confidence threshold percentages that should route pages to manual review queues.
    • For indexing, which fields must be extracted from scanned forms to populate case metadata (case number, claimant name, incident date)?
    • Should original scanned images be retained alongside OCR text, and do you mandate image compression or specific archival file formats? Options: Retain originals uncompressed, Retain originals compressed, Do not retain originals
    • Who will be responsible for manual quality assurance of low-confidence OCR batches and what SLA for QA turnaround do you require (hours or days)?

    Validate and reconcile migrated records

    • Declare your required migration acceptance thresholds that will define successful migration (for example, 99% record match rate, 98% attachment reconciliation).
    • Outline how duplicate or partial-match records should be handled during reconciliation (merge, flag for manual review, create new version). Options: Auto-merge with rules, Flag for manual review, Create duplicate record
    • Name the reconciliation reports and reconciliation fields you need for auditors and indicate sample report recipients.
    • Would you like automated data quality rules applied during validation (for example, date range checks, mandatory fields, controlled vocabulary enforcement)? Options: Yes - enable rules, No - manual validation only, Partial - selected rules
    • When should the migration reconciliation certificate be issued relative to cutover and what evidence must accompany it (sample records, checksums, export files)?
    • Forecast the time window and internal resources your team can allocate to reconciliation activities during cutover week.

    Build API integrations to agency systems and endpoints

    • Enumerate the target agency systems to integrate with (for example case reporting, financials, records management, GIS) and attach current API documentation or Swagger/OpenAPI files.
    • Require any endpoints to use FIPS 140-2 validated encryption or client certificate authentication for data exchange? Options: Yes - FIPS/client cert required, No special requirements, Partial - some endpoints
    • Attach data schemas or sample payloads (XSD/JSON contracts) for each endpoint that must be honored during integration.
    • Define the required sync frequency for each integration (real-time, hourly batch, nightly batch) and any backlog processing windows. Options: Real-time, Near real-time (minutes), Hourly batch, Nightly batch
    • Supply API credentials, test sandboxes, and technical points of contact necessary for endpoint certification and testing.
    • Does any integration require throughput or latency SLAs such as <500ms average response for lookup APIs? Options: Yes - provide SLA, No, Not sure

    Configure reporting dashboards and scheduled exports

    • Select the KPIs and audit metrics that must appear on dashboards (case backlog, time-to-resolution, evidence processing time). Options: Case backlog, Time-to-resolution, Evidence processing time, Custom metrics
    • Would you like role-filtered dashboards for executive leadership, program managers, and auditors? Options: Yes - role-filtered required, No - shared dashboard, Partial - specific roles only
    • Outline the preferred schedule and secure formats for exports (for example, nightly SFTP XML, daily CSV) and required recipients.
    • Supply the intended recipients of scheduled export feeds and indicate the authentication method recipients must use (SFTP key, TLS client cert, API token). Options: SFTP key, TLS client certificate, API token, Other
    • Explain any legal, FOIA, or privacy redaction rules that must be applied automatically prior to export.
    • Forecast expected dashboard query concurrency and maximum acceptable refresh latency for executive views.

    Configure audit logging and compliance reporting

    • Explain which NIST 800-53 controls or agency-specific logging requirements must be covered by audit logs and compliance reports.
    • Give the required log retention durations in months for system, application, and access logs and note any differences for audit versus operational logs.
    • Assign the compliance reviewer(s) who will receive scheduled compliance reports and define the distribution cadence (daily, weekly, monthly). Options: Daily, Weekly, Monthly, Quarterly
    • Does the agency require tamper-evident log storage such as write-once-read-many (WORM) or cryptographically signed log chains? Options: Yes - WORM or signed logs required, No, Need recommendation
  6. Mutual Commit

    Finalize commercial and legal terms, acceptance criteria, data handling obligations, and procurement deliverables required to proceed.

    Agreement Modules

    • Subscription Order Form
    • Master Services Agreement (MSA)
    • Statement of Work (SOW)
    • Data Processing Agreement (DPA)
    • Public Sector Procurement & Security Addendum
    • Acceptance Certificate
    • Purchase Order & Procurement Deliverables
    • ATO Evidence Package Delivery
    • Change Order Agreement
  7. Deployment

    Lock readiness facts and configuration values before execution begins.

    1. Pre-Deployment Readiness

      Confirm concrete readiness facts — environments, data owners, migration windows, access, and named approvers required before execution.

      Pre-Deployment Questions

      Environment and site access

      • Which systems and environment types will this deployment touch? Select all that apply (we use this to build environment-specific runbooks). Options: Single production case management environment, Separate production and staging environments, On‑premises database or servers, Agency identity provider (IdP) / SSO, External analytics / data warehouse, File shares / document repository, Other (please specify), None of the above — limited sandbox only
      • Is the buyer's production environment provisioned and available for deployment now? (If no, we'll need the target ready date in the next question.) Options: Yes — production environment available now, No — not yet provisioned
      • If production environment is not yet available, what is the target date for production readiness? (date)

      Data and configuration

      • Which data sources require migration or ingestion into the platform? Select all that apply (so we can size export and validation tasks). Options: Legacy case management database, Shared spreadsheets or CSV exports, File shares / scanned documents, Third‑party system via API (CRM, RMS, etc.), Paper records requiring digitization, No data migration required, Other (please specify)
      • Have named data owner(s) been assigned who can approve exports and perform validation for each selected source? Options: Yes — all sources have named owners, Partially — some sources assigned, No — data owners not assigned yet
      • List the named data owner(s) and their role title for each source selected (role title and name only — this lets us schedule export approvals and data validation).

      People and ownership

      • Who is the named approver with final sign-off authority to proceed to migration (name and role)?
      • Are dedicated agency product owner(s) and technical lead(s) assigned and committed to sprint participation and acceptance testing? Options: Yes — both product owner and technical lead assigned, Partial — only product owner assigned, Partial — only technical lead assigned, No — not assigned yet
      • Who will coordinate identity/integration approvals (IdP, API access, firewall exceptions)? Provide the role title and name.

      Timing and constraints

      • What is the target migration/cutover window (select one) — this schedules the migration weekend or phased cutover. Options: Fixed date or fixed date range (we will provide dates below), Flexible within a 60‑day window, No window defined yet — need to align
      • If you selected a fixed date or range, provide the migration start and end dates (or expected cutover date).
      • Are there blackout dates or regulatory/compliance milestones that would prevent cutover (e.g., fiscal close, audits, elections)? Options: No known blackout dates, Yes — blackout dates exist (we will provide dates below)
      • If yes, list blackout dates or compliance milestones (brief) so we can schedule around them.
    2. Configuration Details

      Capture exact configuration values the deployment team will use — identity provider settings, API endpoints, field mappings, and cutover plan.

      Configuration Details

      Environments & Endpoints

      • Enter your production instance host URL (format: https://your-agency-subdomain.example — exact host the deployment will use)
      • Enter your staging/test instance host URL (format: https://... — Default: none; enter N/A if not used)
      • Select the deployment cloud region the buyer has approved (Default: US-GOV (FedRAMP High)) Options: US-GOV (FedRAMP High), US-COMMERCIAL (FedRAMP Moderate), EU-COMMERCIAL, Other — specify

      Identity & Access (SSO / Provisioning)

      • Primary identity provider (IdP) type to integrate (select one) Options: SAML-based IdP, OIDC-based IdP, SCIM-only provisioning (no SSO), Local platform accounts only
      • Enter your IdP issuer/entity ID or OIDC issuer URL (format: https://...) — enter exact issuer/EntityID the platform will reference
      • Enter the SSO application/client identifier (Client ID or App ID) the buyer has registered for the platform (do NOT paste secrets)
      • Credential owner for the SSO/integration secret (enter person or team name who will deliver the secret via the buyer's secrets manager at kickoff)
      • Enable SCIM user provisioning from the buyer's IdP to the platform? Options: Yes, No

      Integrations & API Endpoints

      • Primary external system category for case/data integration (select one) Options: Source case database / legacy DB, Agency reporting warehouse / BI, Single production CRM org, Agency identity provider (IdP) — for auth only, Other — specify
      • Enter the API endpoint URL for the primary external system above (format: https://... — enter N/A if no API endpoint)

      Field & Identifier Mappings

      • Exact source-system field name to use as the case unique identifier for migration (enter the source field name verbatim)

      Cutover & Migration Plan

      • Target production cutover date (format: YYYY-MM-DD — enter TBD if date not confirmed)
      • Preferred data migration sequencing approach (select one) Options: Big-bang (single cutover), Phased by module (e.g., investigations first), Phased by business unit/agency office, Other — specify

      Operational Limits & Retention

      • Retention period for case attachments stored in the platform (enter numeric months — Default: 60 months)
    3. Deployment

      Execute the rollout with named owners, sprint tasks, data migration sequencing, integration validation, and security acceptance checkpoints.

  8. Success

    Validate outcomes against agreed success signals, run recurring reviews, and maintain a shared channel for issues and enhancement requests.

    Success Reviews

    • Go-live Health Check (weeks 1-4)
    • First Measurement Review (weeks 4-10)
    • Acceptance Gate Review (around day 90)
    • Quarterly Success Review (ongoing quarterly)
    • Annual Outcomes Validation

    Issues & Enhancements

    • Agree the prioritized list of enhancements and the expected delivery window for each item in the backlog.
    • Publish a timeline that maps corrective actions to expected metric improvement windows ahead of the Acceptance Gate.
    • Restate acceptance criteria and numeric targets recorded in Solution Scope
    • Produce a documented acceptance decision for each numeric criterion recorded in Solution Scope with a named signatory for the buyer where enterprise sign-off is required.
    • Establish remediation plans and verification steps for any criterion that is conditional or failed, with dates for re-verification.
    • Publish the acceptance record showing pass/fail per criterion and include the buyer signatory details where applicable.
    • Issue a prioritized remediation plan for any failed or conditional criteria with completion dates and verification tests.
    • Provide evidence of legacy system decommissioning or read-only status and an archival manifest for migrated data.
    • KPI trend review
    • Confirm whether the two named metrics are on target or require prioritized corrective work and record the next steps.
    • Re-confirm committed success criteria and owners
    • Deliver the quarterly KPI deck showing metric trends, root-cause notes for deviations, and expected impact of planned fixes.
    • Publish the prioritized enhancement list with proposed scheduling for the upcoming quarter.
    • Provide an updated compliance findings tracker with remediation status and target close dates.
    • Present year-long outcome summary vs Solution Scope assumptions
    • Validate whether actual five-year TCO assumptions and average case resolution time align with Solution Scope targets and document any variances.
    • Confirm the operational sustainment plan and the quarterly review cadence for the next year.
    • Produce an annual outcomes report comparing TCO assumptions and key metrics to Solution Scope targets with variance explanations.
    • Provide a timeline for closing any remaining high-severity audit findings identified during the year.
    • Publish the confirmed meeting cadence and the owner of the shared issues and enhancement channel for the next 12 months.
    • Confirm that the deployment completed to the baseline configuration defined in Solution Scope and surface any deviations.
    • Have a named remediation plan with deadlines for all critical blockers discovered during the session.
    • Produce and share a deployment validation checklist showing migration job statuses and integration health for the next 72 hours.
    • Publish the list of critical user onboarding issues and the remediation timeline for each item.
    • Circulate training completion report and recommend immediate remedial training for any low-proficiency user cohorts.
    • Present first measurement data vs targets recorded in Solution Scope
    • Decide whether average case resolution time and data migration completeness are sufficiently trending to meet Solution Scope targets or require prioritized remediation.
    • Produce a short list of corrective actions with completion dates to close metric gaps before the Acceptance Gate.
    • Deliver a detailed migration-completeness report listing remaining record sets, missing mappings, and remediation steps.
    • Create a root-cause analysis for the top metric shortfall and propose configuration or training fixes.
    • Present outcome data against each acceptance criterion
    • Review recurring issues, audit findings, and their resolution rates
    • Deployment and migration validation
    • Diagnose root causes for any gaps
    • Security and compliance posture review
    • Enhancement request backlog and prioritization
    • Early adoption signals and usage patterns
    • Document pass, conditional pass, or fail per criterion and capture signatory decision
    • Review status of remediation actions from go-live
    • Operational sustainment and support health
    • Agree remediation items, timelines, and escalation for any unmet criteria
    • Agree the recurring review cadence and ownership for the coming year
    • Agree corrective actions, owners, and dates
    • Persistent issues burn-down
    • Blockers and open issues triage
    • Confirm shared communication channel health
    • Agree immediate remediation actions and short-term timeline
    • Confirm timeline to Acceptance Gate
    • Incumbent system wind-down verification
First-Party AI

1-2 minutes please — Your AI agent is working

First-Party AI™ can make mistakes. Always check important information.