Define the operating boundary
A useful definition names the triggering event, required inputs, governing source, accountable owner, decision or action, exception path, evidence retained, and downstream handoff. Buyers should adapt those elements to their own population, jurisdictions, policies, systems, and control model before writing requirements.
The most important distinction is between a label and an operational capability. A provider may document fee calculation payments and reconciliation while depending on customer-supplied policy, licensed content, third-party data, integration partners, manual review, or services. The demonstration should expose those dependencies rather than hiding them behind a completed interface.
What a demonstration should prove
- Begin with representative source records and a named policy, standard, or controlled rule.
- Show the normal path, an ambiguous case, missing data, an exception, an override, and a material source change.
- Identify who can change rules, who can approve or reject, and how accountability is preserved.
- Trace every output back to inputs, versions, timestamps, user actions, and governing evidence.
- Export the resulting record and reconcile it with downstream systems and retained obligations.
Authority and operating context
DOJ Title II web and mobile accessibility rule
The Title II rule establishes specific accessibility requirements for covered state and local government web content and mobile applications and identifies WCAG 2.1 Level AA as the technical standard subject to the rule's scope and exceptions. Permit portals, plan-upload interfaces, payment flows, maps, status tools, and mobile inspection or resident applications must be evaluated as public digital services rather than optional front-end decoration.
WCAG 2.1
WCAG 2.1 provides testable success criteria organized around perceivable, operable, understandable, and robust digital content. It gives buyers a technical vocabulary for testing applicant, reviewer, payment, map, document, and mobile experiences without treating a vendor statement as proof of conformance.
NIST CSF 2.0
CSF 2.0 organizes cybersecurity outcomes under Govern, Identify, Protect, Detect, Respond, and Recover. Permit and licensing systems hold public-service, applicant, property, financial, inspection, credential, and enforcement data and require explicit governance, identity, access, resilience, incident, and supplier controls.
NIST Privacy Framework
The Privacy Framework supports identifying and managing privacy risk through organizational and system activities. Civic systems combine identities, addresses, project documents, payment data, credentials, complaints, inspections, and public records, making purpose, minimization, access, retention, disclosure, and redaction material design questions.
Operating domains
Building-permit intake and review
The controlled workflow from project scope and applicant identity through application, completeness, fee, technical review, correction, permit decision, conditions, and issuance.
Business, contractor, and property licensing
The recurring regulatory workflow for application, identity, qualification, supporting evidence, fee, review, issuance, renewal, condition, inspection, suspension, and enforcement across distinct license programs.
Fees, payments, refunds, and reconciliation
The financial control chain from adopted fee authority and calculation inputs through estimate, assessment, waiver, payment, settlement, refund, receivable, reconciliation, and audit.
Evidence and comparison limits
Official provider documentation can establish product positioning. Provider confirmation can clarify package or availability. Independent observation requires a disclosed scenario, environment, date, inputs, and reproducible result. None of those sources alone establishes buyer-specific legal, clinical, regulatory, quality, or operational fitness.
Buyer questions
- What exact outcome and evidence should fee calculation payments and reconciliation produce?
- Which source, version, and customer facts govern the workflow?
- Which decisions remain human and who is accountable for them?
- What is native, configured, integrated, service-delivered, or planned?
- How does a changed source affect open and historical records?