What
A SignalConnector for ERP (generic adapter) (kind ERP), so an operator can add it on the Signal sources page, collect from it, and forward what it yields to the Decionis Protocol. Plan: docs/SignalConnectors.md (S4); the framework (interface, registry, demo connectors, the Sources page, forwarding) is already in infra/connectors/ and application/signals/.
A generic adapter: an endpoint or export, a field mapping and a credential, producing TRANSACTION and USAGE signals (invoices, payments, volumes) keyed by the account reference the ERP holds. SAP, Oracle ERP and Dynamics adapters are separate issues once an operator names one.
Scope
infra/connectors/ErpConnector.ts implementing SignalConnector: source (never a credential in it) and collect() returning CapturedSignal[] parsed through CapturedSignalSchema.
- Configuration for the source: target, credential reference, and any mapping the connector needs; credentials are read on the server at the moment of use and never serialised.
- Egress: the connector reaches only the host its configuration names; a test proves a different host is refused.
- A demo fixture for the connector following the fixture conventions, so demo mode shows it.
- Tests for the mapping into
CapturedSignal, for the egress rule, and for the failure path (source down: reported, not stored, nothing fabricated).
- A row in the connector catalogue in
docs/SignalConnectors.md, a paragraph in docs/Docker.md on configuring it, and the threat-model note if the connector adds an asset.
Done when
- The source appears on
/signals, "Collect now" yields signals that forward and report their count, and a wrong credential or host produces a clear error with nothing stored.
- Any new dependency passes
pnpm licenses:check.
How to pick this up
- Comment on this issue so nobody else starts it, then branch from
master with one branch per issue; the bot opens the pull request when you push.
- Follow CONTRIBUTING.md:
pnpm verify green, every commit signed off with -s (DCO), no telemetry, no dependency outside the license policy in scripts/CheckLicensePolicy.mjs.
- Fixtures and samples follow the demo conventions: organisations from the NATO alphabet, people surnamed Example, references shaped
CRM-DEMO-000n, no real host, email, phone or URL. The tests enforce it.
- Update the documents that make a claim about what you changed in the same pull request: README, the Docker guide, ThreatModel, and the discovery files
public/llms*.txt (with pnpm discovery).
What
A
SignalConnectorfor ERP (generic adapter) (kindERP), so an operator can add it on the Signal sources page, collect from it, and forward what it yields to the Decionis Protocol. Plan: docs/SignalConnectors.md (S4); the framework (interface, registry, demo connectors, the Sources page, forwarding) is already ininfra/connectors/andapplication/signals/.A generic adapter: an endpoint or export, a field mapping and a credential, producing
TRANSACTIONandUSAGEsignals (invoices, payments, volumes) keyed by the account reference the ERP holds. SAP, Oracle ERP and Dynamics adapters are separate issues once an operator names one.Scope
infra/connectors/ErpConnector.tsimplementingSignalConnector:source(never a credential in it) andcollect()returningCapturedSignal[]parsed throughCapturedSignalSchema.CapturedSignal, for the egress rule, and for the failure path (source down: reported, not stored, nothing fabricated).docs/SignalConnectors.md, a paragraph indocs/Docker.mdon configuring it, and the threat-model note if the connector adds an asset.Done when
/signals, "Collect now" yields signals that forward and report their count, and a wrong credential or host produces a clear error with nothing stored.pnpm licenses:check.How to pick this up
masterwith one branch per issue; the bot opens the pull request when you push.pnpm verifygreen, every commit signed off with-s(DCO), no telemetry, no dependency outside the license policy inscripts/CheckLicensePolicy.mjs.CRM-DEMO-000n, no real host, email, phone or URL. The tests enforce it.public/llms*.txt(withpnpm discovery).