Home Symposium Campaign Resources Governance Roadmap Traceability Sign in with WSI/CES IAM
Gate 2 PASS · Protected Pilot Active · Accepted 2026-06-17

Gate 2 Delivery Map

Governance and delivery map for the MAF ICF Participation Program v0. All six participation steps accepted. MCP Governance Gateway operational. Gate 3 locked.

Gate Progression

Programme gates are sequential. Each gate requires explicit governance authorization before the next may open. Gate 3 (matching and exchange) requires a separate authorization not yet granted.

Complete

Gate 0

Control Note
Programme authorization baseline

Complete

Gate 1

Tier A Public Site
Static public read · Live 2026-06-13

PASS ✓

Gate 2

Protected Pilot · v0 accepted
All 6 steps delivered · 2026-06-17

Locked

Gate 3

Matching & Exchange
Requires separate authorization

Identity & Consent Prerequisites

Phase 1 established the identity, consent, and governance baseline required before any authenticated surface or personal data collection could proceed. All Phase 1 prerequisites completed and signed off 2026-06-15.

  • Keycloak IAM configuration for maf.timebank.tw — documented and approved in km-base
  • Seven consent trigger artifacts (#1–#7) — each with written consent artifact, privacy impact review, and named approval on file
  • Privacy review baseline — on file in km-base
  • Data retention policy baseline — on file in km-base
  • Integration approvals and data routes — on file in km-base
  • Operating organisation baseline — named and on file
  • Evidence model updated for Gate 2 types
  • UI/UX governance gate — approved before authenticated surface activation
  • App gate enforcement — exit code 0 (PROCEED) confirmed before implementation
  • Breach and incident response policy — on file in km-base
  • Role model baseline — on file (Self, Family, Professional, Organisation)
  • Minor linkage decision — on file; minor linkage remains unauthorized at v0
  • Keycloak realm choice decision — on file in km-base
  • Phase 1 prerequisites checklist signed off — 2026-06-15
  • Phase 1 identity and consent baseline signed off — 2026-06-15
  • Phase 1 P1–P10 gate check execution evidence — on file 2026-06-16
  • Phase 1 signoff — kce2ces (Daniel Chen), 2026-06-15

Six-Step Participation Model

Six mandatory steps must be completed in order before any matching is permitted. No step may be skipped, bypassed, or reordered. All six steps delivered and accepted at v0 (2026-06-17). Matching is not permitted until all six steps are complete for a given participant record.

Step 1

Identity & Role (IAM)

Keycloak authentication required before any write surface. Role assignment (Self / Family / Professional / Organisation) recorded in participant record and reviewed by a named human before evidence submission is permitted.

v0 live
Delivered with Phase 1 · 2026-06-15
Step 2

Consent Capture

Explicit, revocable, purpose-specific consent recorded before any personal data is stored. Seven consent trigger events — account, card data, profile, evidence, family linkage, content, ICF self-report. Human review required; no automated consent processing.

v0 live
Delivered with Phase 1 · 2026-06-15
Step 3

ICF-Aligned Classification

Participant self-reported classification across ICF domains (d1, d4, d7, d9). Unused capacities staged by type (time, skills, knowledge, space, tools, goods, networks, professional support, lived experience). Non-clinical; does not constitute diagnosis or eligibility determination.

v0 accepted
Professional Review Bridge: designed, not built — coordinator triage → designated professional review → institutional authority confirmation. Formal ICF/ICHI codes require designated professional or institutional authority; participant self-report and app suggestions are not formal code assignment.
n8n Workflow Integration: designed, not activated.
Accepted 2026-06-16
Step 4

Staging (Before Any Matching)

Participant record staged into appropriate support pathway after classification. Determines which matching and exchange options may be presented. No matching occurs at this step. Protected case pathway triggers safeguarding procedure; human review required before vulnerable participant record advances.

v0 accepted
Accepted 2026-06-17
Step 5

Exchange Readiness Assessment

Records what forms of exchange the participant is willing and able to use: six CES transaction types (time, gift, exchange/SWAP, barter, mixed, shared) plus conventional currency. Mixed time + currency (type 5) disabled at v0 — requires separate approval and clear fiat disclosure.

v0 accepted
Accepted 2026-06-17
Step 6

Evidence Intake

Participation record created after Steps 1–5 complete. Governed by MAF-Evidence-Model-v0.1.yaml. Human verification required for all verified evidence types. No clinical claims, eligibility determinations, or diagnostic inferences may be recorded or derived.

v0 accepted
Runs in pilot_notice_mode: true — Artifact #4 Part B text remains blocked by R-4 external PDPA legal review. card_reference and story_reference evidence types deferred (Artifacts #2 and #6 not yet approved).
Accepted 2026-06-17

Design principle: Do not match too early. The correct sequence is: Identify → Classify → Protect → Stage → Consent → then Match. No automated matching, recommendation, or eligibility determination may be introduced at any step. All matching proposals require human review before activation.

MCP Governance Gateway

The MCP Governance Gateway provides Claude AI and authorized MCP clients with structured, read-only access to programme governance records and context. Qdrant participant-data search is intentionally disabled by configuration.

Verified

OAuth Connector

MCP OAuth authentication connector verified and operational.

Verified

ChatGPT MCP Integration

ChatGPT MCP connector verified. External AI client access to governance tools confirmed.

Active

km-base Federation

Live read access to km-base governance records. km-base is authoritative; Qdrant is derived retrieval only.

Active · 5 tools

Governance Tools

Five active governance tools: programme status, control status, execution brief, final review checklist, context listing, km-base search.

Disabled by config

Qdrant Governance Search

One Qdrant governance search tool intentionally disabled by configuration. No participant data may be ingested into Qdrant at Gate 2.

Active

Protected Pilot Testing

Protected pilot testing permitted under existing consent and privacy controls. Audit log is append-only.

What Remains Locked or Blocked

The following boundaries are governance controls on file in km-base. They are not technical limitations — they are programme authorization limits that require explicit governance decisions before they may be changed.

🔒

Gate 3 — Matching & Exchange

Gate 3 requires a separate explicit governance authorization not yet granted. All six steps must be individually completed per participant before Gate 3 consideration.

Pilot → Active — Blocked by R-4

External PDPA legal review (R-4) remains a hard blocker for Pilot → Active. No counsel review has occurred as of 2026-06-17. Gate 2 v0 protected pilot testing may continue under existing on-file controls.

🔒

Participant-Data Qdrant

No personal data may be ingested into Qdrant. Registry status: qdrant_status: not_indexed_no_upsert_authorized. Aggregate de-identified counts require separate approval.

🔒

Minor Linkage

Minor linkage is unauthorized at v0. This decision is on file in km-base and does not change without explicit governance approval.

📐

Professional Review Bridge — Designed, Not Built

The Step 3 workflow (participant self-report → coordinator triage → designated professional review → institutional authority confirmation → audit/provenance) is designed, not built. Formal ICF/ICHI codes require designated professional or institutional authority.

📐

n8n Workflow Integration — Designed, Not Activated

n8n integration for Step 3 professional review workflow is designed but not activated. No webhook or workflow is live.

🔒

Matching, Exchange, CES Transaction

/match and /exchange return 404. No CES transaction, marketplace/store handoff, ERPNext integration, or payment processing is authorized at Gate 2.

Acceptance Records

All acceptance records are on file in km-base and accessible via the governance portal. Authoritative source: km-base. MCP governance tools provide live read access.

maf-gate2-v0-final-closeout-v1

Gate 2 v0 Final Validation and Closeout

Final validation pass: 9 PASS, 1 PASS-with-flag, 1 mechanism-level PASS, 2 not independently verified (accepted on existing evidence). Option A signed: Gate 2 v0 accepted for continued protected pilot testing only. Does not grant Pilot → Active. Does not open Gate 3.

Accepted: 2026-06-16 Approved by: kce2ces (Daniel Chen) Type: Validation closeout
MAF-Gate2-Phase2-AllSteps-v0-Final-Acceptance-2026-06-17.md

Phase 2 All-Steps v0 Final Acceptance

All six Phase 2 participation steps accepted at v0 as of 2026-06-17. Gate 3, participant-data Qdrant, n8n, and Pilot → Active remain locked/blocked. Registry updated with gate2_phase2_status: all_steps_v0_accepted.

Accepted: 2026-06-17 Programme: maf-icf-participation-2026 Type: Phase acceptance
maf-gate2-pdpa-status-decision-v1

PDPA Legal Review Status Decision

R-4 external PDPA legal review remains required before Pilot → Active. No counsel review has occurred as of 2026-06-17. Gate 2 v0 protected pilot testing may continue under existing on-file consent and privacy controls. This decision does not waive, shorten, or substitute for external legal review.

Signed: 2026-06-16 Approved by: kce2ces (Daniel Chen) Type: Status/deferral decision
MAF-Gate2-Phase1-Signoff-2026-06-15.md

Gate 2 Phase 1 Signoff

Phase 1 identity, consent, and governance prerequisites completed and signed off. Keycloak IAM, seven consent artifacts (#1–#7), privacy review, data retention, integration approvals, and evidence model baseline all on file in km-base.

Signed: 2026-06-15 Approved by: kce2ces (Daniel Chen) Type: Phase 1 signoff

Authoritative governance records: governance.timebank.tw · km-base is the source of truth. MCP records are authoritative. Qdrant is derived retrieval only.

Governance Traceability Matrix

The traceability matrix connects each Gate 2 block — gate, stage, step, connector, and open item — to its delivery page, evidence note, governance decision, MCP/km-base context, and current status. 16 rows. 5 public pages pending (authenticated routes).

View Gate 3 Roadmap Preview →

View Traceability Matrix →

IP Notice · 版權聲明

「我的優勢卡」(ABID)版權屬於廖華芳教授及財團法人中華民國發展遲緩兒童基金會。WSI/CES 為社區實施合作夥伴,不持有授權,不製作、複製或衍生優勢卡內容。

官方工具:https://www.fcdd.org.tw/AbilityCard/info  ·  官方平台:https://www.maf4p.com

ABID / My Abilities First copyright belongs to Prof. Liao Hua-Fang and 財團法人中華民國發展遲緩兒童基金會 (FCDD). WSI/CES holds no license and does not reproduce, adapt, or generate ABID content.

This governance map is a public-safe status record only. It does not constitute a legal opinion, clinical assessment, eligibility determination, diagnosis, or ABID card service. No matching, exchange, or Pilot → Active approval is implied by this page.

Gate 3 Governance Update — 2026-06-19

The MAF/CES team has completed a synthetic governance validation round (Gate 3 v0) to test the structures, controls, and scenario coverage for future community matching and exchange planning.

What Was Tested (Synthetic Only)

Using 10 synthetic scenarios and 30 SDG11-aligned community planning simulations — with no real participant data — the team validated that governance fixtures for needs/capacity matching, exchange, and CES 1+6 structures are in place; all safety, consent, reviewer, dispute, and cancellation controls are correctly represented; and private evidence files are not publicly accessible.

294 validators passed, 0 failed across MAF and CES repositories.

🔒

Current Status

Gate 3 remains locked. No live matching, exchange, or CES transactions are operating. The programme is at the governance preparation stage.

Gate 2 PASS · Gate 3 LOCKED · No matching or exchange authorized

What Comes Next

Before any live matching or exchange service can begin, the programme requires separate authorization, external privacy review, and human-reviewed consent processes for each participant. No timeline for live services is confirmed.

This is a governance progress note, not a service announcement.