Specira sample artefact. Rendered from the governed default template on a fictional company. Names, figures and dates are illustrative.All artefacts →
SAMPLE
seeded demo data · specira.ai
Specira Integration Inventory: Governed Template Rendering
Governed template rendering reference: Integration Inventory default v2 (draft) definition 9b0ef262…6aed
Integration Inventory · Project artifact SPECIRA

Integration Inventory: Dispatch Modernization

Meridian Field Services: instructional example, not project evidence

Draft · watermark policy: draft_only template integration_inventory v2 · pack: specira_default_delivery the architecture designed these seams; this register is how operations lives with them
§1

Integration Register

mandatory 1 decision1 evidence rule validators: every_integration_has_named_counterpart_owner · every_vendor_integration_has_sunset_or_null_confirmed · every_integration_cites_data_classification_not_redefines · update_trigger_law_stated_in_register_header

This register rots faster than any other: renewals and version bumps happen outside the authoring team's calendar. The update-trigger law is the header, not a footnote.

Scope: full register, as of 2026-09-15 · live register at workspace registers[1]. Update-trigger law: renewal, version change, or counterpart-owner change updates the row within 5 business days; the quarterly review is the backstop only.

IdDirection · pattern (cites design)Counterpart · ownerData crossingAuth (pointer)SLAContact · renewalSunset
INT-1
positions
Inbound webhook: event push per ADR-6[2] Telematics vendor · K. Osei (vendor side) RESTRICTED (labels[3]) vendor signature[4] 99.5% monthly Vendor desk, weekdays 06:00 to 20:00 · renews Mar 2027 (contract extracts[5]) null-confirmed
INT-2
notifications
Outbound: queued delivery (INT-2[6]) Gateway vendor · T. Brandt CONFIDENTIAL assignment content vault key[4] 99.9% Vendor portal, 24×7 · renews Jan 2027 null-confirmed
INT-3
job master
Inbound nightly batch (INT-3[6]) Enterprise IT · R. Singh CONFIDENTIAL job data internal transfer best-effort nightly Internal: renewal n/a SUNSET · cutover
INT-4
model provider
Outbound, gateway-only (SR-014[7]) Model provider · platform team INTERNAL, anonymized codes only vault key[4] 99.5%, degradation designed Provider console, 24×7 · renews on usage terms null-confirmed
INT-5
HR roster
Inbound sync: system of record (sourcing[6]) Enterprise IT · R. Singh CONFIDENTIAL identity directory sync 4 business hours (leaver SLA) Internal null-confirmed
INT-6
SSO
Federation (sso integration[4]) Identity team · J. Okafor Auth assertions OIDC code + PKCE 99.9% Identity desk, business hours null-confirmed
§2

Dependency Map & Criticality

mandatory 1 decision1 evidence rule validators: every_high_criticality_integration_has_dependency_map_entry · map_edges_resolve_to_register_rows · every_map_edge_names_class_protocol_and_auth_mechanism · map_edge_connects_counterpart_to_the_node_that_terminates_it

The map is generated from the table and stays a curated view; the table is always authoritative. Eleven nodes here, under the readability ceiling.

TierIntegrationsBlast radius (one sentence, citing design)
System-tier INT-1 · INT-5 · INT-6 INT-1 fails: the board degrades to stale-marked positions and manual assignment beyond the feed-loss window (quality scenarios[6]); INT-5 fails: roster changes stop propagating, sessions unaffected; INT-6 fails: no new sign-ins, active sessions ride their ceilings (session management[4])
Process-tier INT-2 · INT-3 · INT-4 Delivery, ingest, and suggestion paths, each with a designed fallback
EdgenoneNone this project

MERIDIAN · AWS ca-central-1 · Canada residency (PIPEDA + clause 13)

UNTRUSTED · external parties · PB-1 / PB-2 / enterprise + mobile edges

DATA TIER · private subnets · KMS CMK at rest

APPLICATION TIER · ECS Fargate · private subnets · TLS 1.3

INT-1 · vehicle_id, lat, lon, observed_at · RESTRICTED
HTTPS :443 · HMAC-SHA256 + timestamp, 300 s (SR-021) · PB-1 · TLS 1.3

INT-5 · technician_id, name, skills, status · CONFIDENTIAL
HTTPS :443 · directory sync · TLS 1.3

INT-6 · OIDC sign-in assertions
HTTPS :443 · OIDC code + PKCE (SR-001) · TLS 1.3

INT-3 · nightly job master file · CONFIDENTIAL
SFTP · key auth · sunset at cutover

INT-4 · anonymized ranking codes ONLY · no identity, no coordinates · INTERNAL
HTTPS :443 · provider gateway · provider key (SR-014) · PB-2 · TLS 1.3

INT-2 · technician's own assignment · CONFIDENTIAL
HTTPS :443 via NAT · vendor API key (SR-027) · TLS 1.3

position.observed · RESTRICTED
:443 · IAM task role · TLS 1.3

assignment.created · assignment_id, technician_id · CONFIDENTIAL
:443 · IAM task role · TLS 1.3

ordered per vehicle_id · RESTRICTED

assignment fan-out · CONFIDENTIAL

read model · own hub scope only · CONFIDENTIAL

Telematics vendor
INT-1

Notification gateway
INT-2

Model provider
INT-4 · gateway-only egress

Legacy scheduler
INT-3 · retires at cutover

HR directory
INT-5

Meridian SSO
INT-6

dispatch-api
api.meridianfield.example

dispatch-board
dispatch.meridianfield.example

telematics-adapter
fixed 1 · ordered per vehicle_id

notification-worker

dispatch-events
Amazon SQS

Dependency map, generated from the register, under the specificity law. Fallback text: an untrusted external group (telematics INT-1, notification gateway INT-2, model provider INT-4, legacy scheduler INT-3 with its sunset chip, HR directory INT-5, Meridian SSO INT-6) connects into the Meridian boundary (AWS ca-central-1, Canada residency); INT-1's webhook lands on dispatch-api (vehicle_id, lat, lon, observed_at · RESTRICTED · HMAC-SHA256, SR-021 · PB-1), which publishes to dispatch-events for the fixed-one telematics-adapter; INT-5 syncs the roster to dispatch-api; INT-6 signs staff in at dispatch-board; the notification-worker pushes INT-2 to the gateway (vendor API key, SR-027); dispatch-api sends INT-4 anonymized ranking codes only to the provider gateway (INTERNAL · SR-014 · PB-2). Every edge names its payload as fields, class, protocol, and auth, and resolves to a register row.

§3

Failure Modes & Operational Response

mandatory 1 decision1 evidence rule validators: every_integration_has_failure_semantics_pointer · failure_rows_cite_verification_check · no_integration_duplicates_architecture_design_content

Pointer-first rows: the design lives in the architecture; who is paged and what the business runs on is the only content owned here. A row that starts explaining retry semantics is a defect.

IdSemantics (pointer)Operational responseVerified by
INT-1 INT-1 failure semantics[6] On-call paged at 15 min of feed gap; dispatchers switch to manual assignment (the contingency: RSK-04 plan[8]) DV-5[9]
INT-2 INT-2[6] Flagged on the board exception view; manual call tree at 30 min notification drill[9]
INT-3 checksum-and-rerun[6] On-call paged; quarantine and rerun. Realized once: ISS-2 changed this row (checksum verification added after the truncated file: ISS-2[10], RSK-08[8]) DV-3[9]
INT-4 model-provider fallback[6] None paged; the board proceeds with the full list suggestions_unavailable[11]

No retry parameters or backoff designs restated anywhere; the pointers own them.

§4

Open Questions

mandatory1 decision
QuestionOwnerAnswer byBlocks
Does the vendor sandbox mirror production signature keys for the rotation drill, or does the drill need a second key pair (shared with the API contracts' question[11])? E. SandovalSep 5, 2026 The INT-1 rotation runbook only
Refs

References & Package Contents

In this export package

package [5] Contract extracts: telematics renewal terms ./compliance/contract-extracts.pdf

In the Specira workspace

specira [1] Workspace integration register: the live source of truth app.specira.ai/projects/dispatch-modernization/registers/integrations
specira [2] Decision log: ADR-6 (webhook push) app.specira.ai/projects/dispatch-modernization/artifacts/decision-log#adr-6
specira [3] Data classification: labels the crossing column cites app.specira.ai/projects/dispatch-modernization/artifacts/data-classification#labels
specira [4] Auth & authz policy: machine identity, SSO, session ceilings app.specira.ai/projects/dispatch-modernization/artifacts/auth-authz-policy
specira [6] Architecture: integration design semantics INT-1…INT-3, sourcing, quality scenarios app.specira.ai/projects/dispatch-modernization/artifacts/architecture
specira [7] Security requirements: SR-014 gateway-only egress app.specira.ai/projects/dispatch-modernization/artifacts/security-requirements#sr-014
specira [8] Risk register: RSK-04 contingency, RSK-08 realized app.specira.ai/projects/dispatch-modernization/artifacts/risk-register
specira [9] Deployment verification: DV-3, DV-5, drills app.specira.ai/projects/dispatch-modernization/artifacts/deployment-verification
specira [10] Issues: ISS-2 truncated-file incident app.specira.ai/projects/dispatch-modernization/issues/iss-2
specira [11] API contracts: degradation contract, shared open question app.specira.ai/projects/dispatch-modernization/artifacts/api-contracts
Generated by Specira · template integration_inventory v2 (draft) · pack specira_default_delivery lineage 9b0ef262…6aed · page 1 of 5