Skip to content
DRAFT⚠OIML SMART pilot programme · internal use only · all documents and specifications are drafts and may change without notice

The authority's intake

The application has landed. At the issuing authority it enters a review queue, not an inbox folder: reviewed, honestly rejected or accepted, and on acceptance it becomes the evaluation project, the shared dataspace the samples, the dispatch, the reports, and the certificate all live on. Twenty minutes to walk it yourself.

Try this flow now

Assume the Issuing Authority persona through the identity service (the instance resets nightly) and the review queue below is yours.

→

The flow at a glance

The actor is the authority's officer (Ms. Emily Irving of the Brobdingnag Legal Metrology Authority, EX1, a fictional authority) in the IA console at /app/ia. The arc: the queue, the review, the acceptance that opens the Type Evaluation Project (the TEP), the samples, the test assignment, the routing decision, and the send that lands the request in the laboratory's inbox, where flow 03 begins.

FIG. THE INTAKEFIG. THE INTAKE5 ACTORSSTEP 01Review queueoldest firstopensthe whole fileSTEP 02The reviewreject or acceptcreatesone recordSTEP 03Evaluation Projectthe shared dataspaceassignsone request per labSTEP 04Dispatchtests × samples × labssendscustody recordedSTEP 05To the labthe routing decision

The walkthrough

S1

The review queue, oldest first

The moment the applicant submits (flow 01, S6), the application appears here: the Recommendation it cites, the applicant, a summary, and how long it has waited. The queue is ordered oldest first, so nothing waits silently at the bottom of a pile. This is the authority's desk at its most honest: every application that needs a decision, visible, with its age on the row.

Try it:sign in as Issuing Authority, then work in/app/iaon the demo instance.

The IA console's review queue holding the waiting application, oldest first, with its Recommendation, applicant, and age.
The IA console's review queue holding the waiting application, oldest first, with its Recommendation, applicant, and age. Live surface · captured 2026-09-01 by the scripted apparatus.
S2

Open it: the whole file, and only the acts the state allows

One click and the whole file is there: the applicant, the instrument with its classified attributes, the samples declared, the documentation checklist as submitted, and the timeline of every act so far. The action bar offers exactly the acts the state machine allows at this moment (request samples, accept, reject), never a button the record would refuse. Nothing is re-typed anywhere in this flow: what the applicant bound in the wizard is what the officer reviews.

Try it:sign in as Issuing Authority, then work in/app/ia/applications/…on the demo instance.

The application review page: the applicant, the instrument chain, the documentation, the timeline, and the review acts the state machine currently allows.
The application review page: the applicant, the instrument chain, the documentation, the timeline, and the review acts the state machine currently allows. Live surface · captured 2026-09-01 by the scripted apparatus.
S3

The honest reject: the reason is required

Rejection is a first-class act, not a deletion. Try to reject without a reason and the act refuses: the scheme requires the reason (PD-05 §4.2.2/§4.2.4, whose refusal grounds run to "other clearly identified reasons"), the form stays open, and nothing happens silently. With the reason typed, the rejection lands on the audit chain and the applicant is notified with the reason attached. Try it on the demo: open any waiting application from the queue, choose Reject, and try to confirm empty; the warning names the clause.

Try it:sign in as Issuing Authority, then work in/app/ia/applications/…on the demo instance.

Open this step's live surface on the demo ↗

S4

The samples: requested, shipped, received, before any acceptance

Type evaluation needs physical samples (PD-05 §4.2.5), so the officer issues the sample request from the review with its particulars. The applicant ships (their side of this act is in flow 05), the officer registers each arriving receipt with its serial and condition, and the accept act stays closed until the samples are received: the pre-acceptance sample stop, so no application is ever accepted on paper alone.

Try it:sign in as Issuing Authority, then work in/app/ia/applications/…on the demo instance.

The sample request form on the review page: particulars typed, the decision acts honestly closed until the samples are received.
The sample request form on the review page: particulars typed, the decision acts honestly closed until the samples are received. Live surface · captured 2026-09-01 by the scripted apparatus.
S5

Accept: the Evaluation Project opens

The accept is the pivot of the whole scheme. It creates the Evaluation Project, the shared dataspace every later act lives on: the application record, the samples, the laboratories, the test requests, the test reports, the evaluation, and at the end the certificate. The applicant gains the view of their project's record at this moment (the cone: their own project, the restricted fields honestly hidden), and the laboratory will join it on the accepted assignment in flow 03. One project, three parties, no parallel copies.

Try it:sign in as Issuing Authority, then work in/app/ia/projects/…on the demo instance.

The Evaluation Project hub after acceptance: one record linking the application, the samples, the test requests, the reports, the verdicts, and the certificate-to-be.
The Evaluation Project hub after acceptance: one record linking the application, the samples, the test requests, the reports, the verdicts, and the certificate-to-be. Live surface · captured 2026-09-01 by the scripted apparatus.
S6

The fee agreement's evidence goes on the record

The fee negotiation between the authority and the applicant runs outside the system, as it does today: by email, by phone, by procurement. What the platform keeps is the evidence of the agreement: the signed contract or quotation uploads to the record as a document with its attested SHA-256, marked as the agreement's evidence, visible to exactly the parties and the scheme's oversight. Today the upload anchors on the pre-application engagement; the project-anchored upload (the agreement evidence on the Evaluation Project itself) is built and in review on the platform's integration branch, and this page will carry its capture when it ships. The doctrine never changes either way: the negotiation stays human, the evidence stays on the record.

Try it:sign in as Issuing Authority, then work in/app/ia/engagementson the demo instance.

Open this step's live surface on the demo ↗

S7

Assign the tests on a matrix

Which tests, on which samples, at which laboratory: the dispatch builder crosses the model's test forms with the samples selected for the evaluation (R 60-3 §4.7, the selection recorded with its justification) and assigns each cell to a laboratory. One test request is composed per laboratory, the plan names every assignment it makes, and out-of-round rows are reported, never silently dropped. The laboratory picker answers from the laboratories' scopes, so a request cannot land where it cannot be performed.

Try it:sign in as Issuing Authority, then work in/app/ia/dispatch/…on the demo instance.

The dispatch builder: the test-forms by samples matrix with per-laboratory assignment, one test request composed for the Blefuscu Central Laboratory.
The dispatch builder: the test-forms by samples matrix with per-laboratory assignment, one test request composed for the Blefuscu Central Laboratory. Live surface · captured 2026-09-01 by the scripted apparatus.
S8

The routing decision, then send

The samples have to travel too, and the scheme is honest about who carries them: the authority ships them to the laboratory, or the applicant ships them directly. The decision is a recorded act on the project (who ships, with what custody), and the custody chain then tracks every hop: shipped, in transit, received at the bench. With the request issued and the samples in transit, the laboratory's inbox has the work, which is the first scene of flow 03.

Try it:sign in as Issuing Authority, then work in/app/ia/projects/…on the demo instance.

The project's laboratories card: the selected samples shipped to the laboratory, the custody chain recording who shipped what.
The project's laboratories card: the selected samples shipped to the laboratory, the custody chain recording who shipped what. Live surface · captured 2026-09-01 by the scripted apparatus.

The presenter scripts

Two lengths, keyed to the steps above (S1 to S8). Print this page for a clean copy of the scripts.

The 5-minute presenter script · the committee slot

  1. 0:00The application the manufacturer submitted is now the authority's problem. Watch how an authority works when the file is one record instead of an email thread. Simulated cast, nightly reset.
  2. 0:30S1The review queue: every application waiting on you, oldest first, with its age on the row. Nothing sinks.
  3. 1:15S2-S3Open one: the whole file, and only the acts the state allows. And watch the reject: no reason, no rejection. The scheme's due process is enforced by the software, not by a procedure manual.
  4. 2:15S4Samples first: the request, the shipment, the receipts, and the accept stays closed until the samples physically arrive. No paper acceptances.
  5. 3:00S5Accept, and the Evaluation Project opens: one shared dataspace for the samples, the requests, the reports, the certificate-to-be. The applicant sees their project; the laboratory joins it on assignment.
  6. 3:45S7-S8The dispatch: tests crossed with samples on a matrix, one request per laboratory, and the routing decision recorded (who ships the samples, with what custody). Send, and the laboratory has the work.
  7. 4:30Try it: the Issuing Authority account on demo.oimlsmart.org, /app/ia. The queue is real work you can do.

The 20-minute presenter script · the working visit

  1. 0:00Frame: this is the authority's own desk, the console an IA officer would live in. The promise: by the end the room believes intake is a workflow, not a correspondence. Simulated cast, nightly reset.
  2. 1:00S1The queue: ordering, aging, the summary. Contrast with the shared mailbox. Ask how applications are triaged today and who knows what is waiting.
  3. 3:00S2The whole file: the instrument chain as bound by the model, the checklist as submitted, the timeline. Point at the action bar: the state machine offers only the acts the record allows, which is the end of invalid-state mistakes.
  4. 5:00S3Perform the reject posture: open the form, try to confirm empty, watch the refusal name PD-05 §4.2.2/§4.2.4. The reason is required, it lands on the audit chain, the applicant is notified with it. Due process as software behavior.
  5. 7:00S4The sample leg: the request with particulars, the applicant's shipment act, the receipts registered with serial and condition, and the pre-acceptance stop. The physical world is tracked with the same rigor as the data.
  6. 9:30S5The accept: the Evaluation Project as the shared dataspace. Walk the hub cards. The cone: the applicant views their project now, restricted fields hidden; the laboratory joins on assignment. One record, three parties, no copies to reconcile.
  7. 12:00S6The fee evidence: the negotiation stays outside the system (as today), the agreement document goes on the record with its attested hash, visible to exactly the parties. Be honest about the current anchor (the engagement) and the project-anchored upload in review.
  8. 14:00S7The dispatch builder in depth: the test set comes from the model's conformance classes, the matrix crosses forms with the selected samples, one request per laboratory. Change the Recommendation and the test set changes; the authority cannot dispatch a test the Recommendation does not declare.
  9. 16:30S8The routing decision and the custody chain: who ships, tracked hops, received at the bench. Then send, and preview the laboratory's inbox for flow 03.
  10. 18:30Questions. The usual two: liability (the platform does digitally what the authority does today; the decision and the signature stay human) and partial adoption (records mode for paper, covered on the audience pages). Close on the try-it path.

Today (SMART) and the vision (SMART+)

Today · SMART

  • The review queue, the whole-file review, the reasoned reject, the samples gate, the acceptance that opens the Evaluation Project. the IA console ↗
  • The dispatch builder: the model's test set crossed with the selected samples, one request per laboratory, the routing decision recorded. see it live ↗
  • The agreement-evidence doctrine: the negotiation outside, the attested document on the record (the project-anchored upload in review). the engagements ↗

The vision · SMART+

  • The completion gate's surface on the project: settle-first completion with the named open items (in review on the integration branch; the audit page tracks it). roadmap ↗
  • Cross-authority evaluation intake: verifying another authority's evidence chain cryptographically instead of trusting letterhead (roadmap). roadmap ↗

The honest questions

Does the platform decide for the authority?

No. The review, the acceptance, the assignment, and every rejection are human acts, recorded as such with the officer's name. The software's discipline is narrower: it refuses invalid acts (the reasonless reject, the acceptance before the samples) and it never lets work wait invisibly.

What does the applicant see of all this?

Their own project, per the cone: the record of their application and its stages, with the authority's internal fields honestly hidden. They are notified at every stage. The cone is the mechanism that makes one shared dataspace safe: everybody sees exactly what the scheme entitles them to, no more.

Can a dispatch be wrong?

The test set comes from the Recommendation's model, so the builder cannot offer a test the Recommendation does not declare, and the laboratory picker filters by scope. What remains is judgment: which samples, which laboratory. That judgment is the officer's, and the record carries it with the justification.

Is the negotiation really outside the system?

Yes, deliberately: fees are commercial and the scheme does not fix them. What the record holds is the evidence that agreement was reached (the attested document, the parties-only visibility), so the audit chain never depends on someone's inbox. The completion doctrine later refuses to close a project with fees unmarked; flow 05 tells that half.

Verified 2026-09-01: every step above was performed headlessly against the live demo by scripts/capture-walkthroughs.ts (one real application reviewed, sampled, accepted, and dispatched in the drive; the reject posture proven and cancelled) and each capture carries its assertion record in public/img/walkthroughs/manifest.json. The step names and machine states match the engineering record (DEMO_FLOWS/02) in the smart repository; where the built shape differs from the flow text, the step says so (S6).