Handover Pack — Day 28 Deliverables & Retention Support
What SOQ receives at source handoff, documentation deliverables, acceptance checklist, and 3-month best-effort support under Plan SOQ-25K retention.
Document control
| Field | Value |
|---|---|
| Plan | Plan SOQ-25K — US$25,000 complete package |
| Handoff gate | Day 28 — go-live + source delivery (15% / US$3,750) |
| Retention gate | End of month 3 post-handover — 10% / US$2,500 release |
| Full payment schedule | 2.1 Plan SOQ-25K 4 |
Handoff (Day 28)
15%
US$3,750 at source delivery
Retention
10%
US$2,500 after 3 months
Support window
3 mo
Best-effort — not Care SLA
Source code
100%
SOQ owns IP at Day 28
1. What SOQ receives at Day 28
Day 28 is source delivery and operational handoff — not the end of all AIEE.DEV involvement. SOQ receives full ownership of the codebase and the documentation pack below. A 10% retention (US$2,500) remains held until the 3-month best-effort support period ends.
Technical deliverables
| # | Deliverable | Detail |
|---|---|---|
| 1 | Full source repository | Monorepo: apps/*, services/api, packages/*, migrations, CI configs — per 5.9 Directory |
| 2 | Production deploy | Deployed to SOQ-agreed environment (staging or production per 3.1 Server spec) |
| 3 | Environment configuration | .env.example templates - documented required vars (no secrets in repo) |
| 4 | Database | PostgreSQL schema + migration history - seed data for reference (non-PII where possible) |
| 5 | Third-party credentials handoff | Secure transfer of SWDA sandbox keys, Xero OAuth tokens, AWS/IAM roles — via SOQ-approved secret store (1Password / AWS Secrets Manager / hPanel notes) |
| 6 | Domain & TLS | DNS/TLS checklist — SOQ-owned domains; AIEE.DEV documents current routing |
| 7 | Walkthrough session | Live handover (>= 2 hours): architecture tour, deploy demo, SWDA Hub ops dashboard, admin RBAC |
Credentials handoff process
| Step | Owner | Action |
|---|---|---|
| 1 | AIEE.DEV (CTO) | Inventory all integration credentials (SWDA, Xero, email, SMS, payment if configured) |
| 2 | SOQ ops | Nominate secret custodian + production admin accounts |
| 3 | Joint | Rotate any shared dev/staging secrets before production cutover |
| 4 | AIEE.DEV | Transfer via encrypted channel only — never email plain text |
| 5 | SOQ | Confirm receipt; revoke AIEE.DEV access to production within 5 business days of handoff sign-off |
IP: SOQ owns the codebase from Day 28. AIEE.DEV retains no licence lock-in. Retention covers support, not continued ownership.
2. Documentation deliverables
AIEE.DEV delivers a handover documentation pack alongside the repo. Minimum set:
| Document | Purpose | Location (typical) |
|---|---|---|
| README | Quick start, prerequisites, local dev, project structure | README.md (repo root) |
| Deploy guide | Build, migrate, seed, release steps for staging/production | docs/runbooks/deploy.md |
| Environment runbook | Env vars, secrets, service dependencies, health checks | docs/runbooks/environment.md |
| API documentation | OpenAPI spec + generated reference for domain + integration endpoints | docs/api/openapi.yaml |
| SWDA Hub ops notes | Outbox replay, retry/DLQ, sandbox vs prod, field mapping | docs/runbooks/swda-hub.md |
| Xero mapping guide | Order -> invoice mirror, account codes, reconciliation checks | docs/runbooks/xero-sync.md |
| RBAC matrix | Roles, permissions, portal access by persona | docs/security/rbac-matrix.md |
| Architecture summary | System context, module map, integration boundaries | docs/architecture/overview.md + 5.7 Architecture |
| Known limitations | MVP depth gaps, phased items, sandbox-only integrations | docs/handover/known-limitations.md |
| Support contact (retention) | Channel, hours, escalation during 3-month window | docs/handover/support-during-retention.md |
This CRD site remains the living specification. The repo runbooks are the operator's day-2 reference after AIEE.DEV access is revoked.
3. SOQ acceptance checklist (Day 28)
SOQ sign-off on the Go-live + source handoff milestone (15%) when the items below are satisfied:
| # | Check | SOQ sign-off |
|---|---|---|
| 1 | Repository access granted to SOQ-nominated owners | ☐ |
| 2 | README + deploy guide — SOQ can build and run locally or on agreed host | ☐ |
| 3 | Staging/production deploy matches agreed scope (2.1 3) | ☐ |
| 4 | Admin - Student - Trainer - Public surfaces reachable with test accounts | ☐ |
| 5 | SWDA Hub ops dashboard accessible; sample outbox/retry flow demonstrated | ☐ |
| 6 | Xero sync path demonstrated (test org or sandbox) | ☐ |
| 7 | RBAC matrix delivered; SOQ admin role assigned | ☐ |
| 8 | Credentials inventory signed off; production secrets rotated | ☐ |
| 9 | Handover walkthrough completed; SOQ ops lead nominated for retention period | ☐ |
| 10 | Known limitations document reviewed — no surprise on phased scope | ☐ |
Disputes: Material defects blocking checklist items pause the 15% invoice until remediated. Cosmetic or out-of-scope items are logged for retention or change order.
4. Three-month best-effort support (retention period)
US$2,500 (10%) is held as retention and released at the end of calendar month 3 after Day 28 handoff sign-off, when release criteria in 5 are met.
This is best-effort support — not a Care retainer, Hypercare SLA, or 24/7 maintenance contract.
15% at source delivery - 10% retention at month 3
In scope (best-effort)
| # | Item | Notes |
|---|---|---|
| 1 | Defect fixes | Bugs in delivered MVP scope — reproducible on agreed environment |
| 2 | Handover doc clarifications | Questions on README, runbooks, RBAC, deploy steps |
| 3 | Integration troubleshooting | SWDA Hub / Xero issues traceable to delivered adapter (not SOQ env drift) |
| 4 | Security patches (critical) | CVEs in direct dependencies — patch guidance or PR if trivial |
| 5 | Office-hours channel | Email / agreed ticket channel - business hours SGT - target response 2 business days |
Out of scope (requires change order or SOQ/vendor)
| # | Item |
|---|---|
| 1 | Care Lite / Standard / Plus retainers - 24/7 SLA - dedicated on-call |
| 2 | New features, portals, or modules (4.11 Ops modules) |
| 3 | Heavy data migration - Privyr bulk history |
| 4 | Production hosting ops, AWS patching, backup DR — SOQ-owned after handoff |
| 5 | SWDA production API entitlement changes on SOQ's side |
| 6 | Third-party vendor incidents (Xero outage, Singpass, payment gateway) |
After month 3: SOQ (or a chosen vendor) owns all day-2 operations. Future work = fixed-scope add-ons quoted separately.
5. Retention release criteria
AIEE.DEV invoices the final 10% (US$2,500) when all of the following are true:
| # | Criterion |
|---|---|
| 1 | 90 calendar days elapsed since Day 28 handoff sign-off (or end of month 3 — whichever the contract specifies) |
| 2 | No open P1 defects in delivered MVP scope (P2/P3 may remain documented with SOQ acceptance) |
| 3 | SOQ has had reasonable opportunity to raise handover-doc or defect items during the window |
| 4 | SOQ confirms retention release in writing (email sign-off sufficient) |
If SOQ and AIEE.DEV disagree on a blocking defect, parties escalate via Pei Han (CCO) and SOQ authorised representative before withholding retention beyond 30 days past month 3 without documented cause.
6. Timeline (handoff -> retention release)
Milestone IDs MS-013–MS-016: 5.1 Project control plan.
| Phase | When | Payment |
|---|---|---|
| Pre-handoff | Days 1–28 | 30% + 25% + 25% per 2.1 schedule |
| Handoff | Day 28 | 15% - US$3,750 |
| Retention window | Months 1–3 post-handoff | 0% (support included in retention hold) |
| Retention release | End month 3 | 10% - US$2,500 |
Related sections
| # | Link |
|---|---|
| 1 | 2.1 Plan SOQ-25K pricing — full payment schedule & scope |
| 2 | 2.3 Post-go-live support — Care retainer vs retention |
| 3 | 1.3 CRD control plane — delivery authorities |
| 4 | 3.1 Discovery & server spec — deploy target |
| 5 | 5.9 Directory structure — repo layout |