wiki: valet / over-capacity mode; 'full' is a soft operator policy
Capture that refusing at capacity is the default, not absolute: an operator may opt into valet over-capacity (customer hands over keys, operator stacks the car into custody). Manned-only, new custody/session shape. Deferred; not built into the entry flow. Made capacity-occupancy's FULL gate a soft policy knob.
This commit is contained in:
@@ -33,8 +33,16 @@ editable and drifts; the chain is the truth). Spaces-free = `capacity − occupa
|
|||||||
loop count, or the [[opencv-anpr-service|vision]] count) reconciles it — surfaced as an anomaly,
|
loop count, or the [[opencv-anpr-service|vision]] count) reconciles it — surfaced as an anomaly,
|
||||||
not silently corrected.
|
not silently corrected.
|
||||||
|
|
||||||
|
## "Full" is a soft, operator-configurable policy
|
||||||
|
|
||||||
|
Refusing at capacity is the **default**, not an absolute. An operator may opt into
|
||||||
|
**[[valet-overcapacity|valet over-capacity]]** — accept the car into operator custody (keys handed
|
||||||
|
over, stacked beyond the marked count) instead of refusing. So the FULL gate is a policy knob
|
||||||
|
(refuse vs. valet-accept), set by the operator per site. Valet is a manned-mode feature with its
|
||||||
|
own custody/session shape — see [[valet-overcapacity]] (deferred).
|
||||||
|
|
||||||
## Open
|
## Open
|
||||||
|
|
||||||
- Whether "FULL" is a hard block or a soft warning (operator can wave one in) — operator policy.
|
|
||||||
- Zone/level granularity at launch vs. single capacity number.
|
- Zone/level granularity at launch vs. single capacity number.
|
||||||
- Reserve-for-permits threshold.
|
- Reserve-for-permits threshold.
|
||||||
|
- The valet over-capacity mode + custody model ([[valet-overcapacity]]).
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
---
|
||||||
|
type: concept
|
||||||
|
tags: [parking, domain, business, capacity, manned]
|
||||||
|
sources: []
|
||||||
|
updated: 2026-06-15
|
||||||
|
status: open
|
||||||
|
---
|
||||||
|
|
||||||
|
# Valet / Over-Capacity Mode
|
||||||
|
|
||||||
|
"Full" is **not** necessarily a hard stop. If the operator opts in, a lot at nominal capacity can
|
||||||
|
still accept cars via **valet**: the customer hands over the keys and leaves, and the operator
|
||||||
|
stacks/double-parks the vehicle beyond the marked space count. (User direction, 2026-06-15.)
|
||||||
|
|
||||||
|
## "Full" is a soft, operator-configurable policy
|
||||||
|
|
||||||
|
The [[capacity-occupancy]] FULL gate is therefore a **policy knob**, not a physical absolute:
|
||||||
|
|
||||||
|
- **Refuse** — hard stop at nominal capacity (the default/strict behaviour).
|
||||||
|
- **Valet over-capacity** — accept beyond capacity into operator custody.
|
||||||
|
|
||||||
|
The choice is the operator's, per site (and possibly per time/condition).
|
||||||
|
|
||||||
|
## Valet is a manned-mode feature with a different session shape
|
||||||
|
|
||||||
|
Valet only exists when there's an operator (cf. [[shift]] — manned-only). It adds a **custody**
|
||||||
|
dimension the normal [[parking-session]] doesn't have:
|
||||||
|
|
||||||
|
- The **operator takes custody** of the car — identity is a **claim/valet ticket**, and the
|
||||||
|
operator (not the driver) is accountable for the vehicle between handover and return.
|
||||||
|
- New facts to record (as signed [[append-only-event-chain]] events when built): **key handover**,
|
||||||
|
where/when parked, and **return** to the customer. The operator's accountability ties into the
|
||||||
|
[[shift]] Z-report and [[reconciliation]] (a valet car with no return record is an anomaly).
|
||||||
|
- Payment still flows through the normal [[tariff]] (duration-based) unless a separate valet fee
|
||||||
|
applies.
|
||||||
|
|
||||||
|
## Status — deferred
|
||||||
|
|
||||||
|
Captured now so the [[capacity-occupancy]] design treats "full" as soft and the entry flow leaves a
|
||||||
|
clean seam. **Not** built into the current transient entry flow (decision 2026-06-15). Full design —
|
||||||
|
the valet session/custody model, the claim ticket, the over-capacity accept path — is future work.
|
||||||
|
|
||||||
|
## Open
|
||||||
|
|
||||||
|
- Valet session/custody data model (claim ticket, parked location, return event).
|
||||||
|
- Whether a distinct valet fee/tariff applies, or normal duration pricing.
|
||||||
|
- Operator UI for handover/return; how it ties to the [[shift]] accountability record.
|
||||||
+3
-2
@@ -7,7 +7,7 @@ updated: 2026-06-14
|
|||||||
# Index
|
# Index
|
||||||
|
|
||||||
Content catalog for the wiki. Start at [[overview]]. Maintained on every ingest.
|
Content catalog for the wiki. Start at [[overview]]. Maintained on every ingest.
|
||||||
Counts: 1 source · 18 entities · 23 concepts · 5 decision records.
|
Counts: 1 source · 18 entities · 24 concepts · 5 decision records.
|
||||||
|
|
||||||
## Overview & navigation
|
## Overview & navigation
|
||||||
- [[overview]] — the top-level synthesis and entry point.
|
- [[overview]] — the top-level synthesis and entry point.
|
||||||
@@ -75,7 +75,8 @@ Counts: 1 source · 18 entities · 23 concepts · 5 decision records.
|
|||||||
- [[parking-session]] — the core domain entity; a projection over the signed log, never a mutable table.
|
- [[parking-session]] — the core domain entity; a projection over the signed log, never a mutable table.
|
||||||
- [[tariff]] — fee model; pure, data-driven, offline; pay-on-foot adds a walk-back grace window.
|
- [[tariff]] — fee model; pure, data-driven, offline; pay-on-foot adds a walk-back grace window.
|
||||||
- [[shift]] — manned-only accountability period; explicit Start/End (not time-based); End → signed + printed Z-report (cash + POS).
|
- [[shift]] — manned-only accountability period; explicit Start/End (not time-based); End → signed + printed Z-report (cash + POS).
|
||||||
- [[capacity-occupancy]] — live count = open sessions; refuse entry + FULL sign when full; exit never blocked.
|
- [[capacity-occupancy]] — live count = open sessions; refuse entry + FULL sign when full (soft policy); exit never blocked.
|
||||||
|
- [[valet-overcapacity]] — "full" is soft: operator may valet-accept over capacity (keys handed over, custody). Manned, deferred.
|
||||||
- [[validation-discounts]] — merchant validates a ticket → signed discount event applied at fee time.
|
- [[validation-discounts]] — merchant validates a ticket → signed discount event applied at fee time.
|
||||||
- [[reporting-analytics]] — revenue/occupancy/stay reports + plate-search, all projections over the signed log.
|
- [[reporting-analytics]] — revenue/occupancy/stay reports + plate-search, all projections over the signed log.
|
||||||
- [[clock-integrity]] — fees depend on the host clock; detect/flag backdating on an offline box.
|
- [[clock-integrity]] — fees depend on the host clock; detect/flag backdating on an offline box.
|
||||||
|
|||||||
+14
@@ -486,3 +486,17 @@ guarantee. Recorded in [[dingtian-relay]] (new Hardening section).
|
|||||||
- NEXT (schema): rename events→ledger_events; add device_events; split ParkingEventType in shared;
|
- NEXT (schema): rename events→ledger_events; add device_events; split ParkingEventType in shared;
|
||||||
then tariffs/versions, permits, blocklist, sessions projection. EventLog/canonicalize/verifyChain
|
then tariffs/versions, permits, blocklist, sessions projection. EventLog/canonicalize/verifyChain
|
||||||
+ /api/events follow the rename (code refactor, separate from this wiki commit).
|
+ /api/events follow the rename (code refactor, separate from this wiki commit).
|
||||||
|
|
||||||
|
## [2026-06-15] design+build | Entry flow (start) + valet/over-capacity captured
|
||||||
|
- Building the entry flow: device input → signed `vehicle_entry` → print ticket → pulseOpen.
|
||||||
|
- DECISION (print failure): **hold** — if all printers are down, sign an `anomaly` (entry attempt,
|
||||||
|
ticket unprinted) and do NOT open (no unticketed transient — couldn't pay on exit; operator
|
||||||
|
handles the held car). The `vehicle_entry` is appended ONLY on the success path, right before
|
||||||
|
pulseOpen — preserving "signed before open" and never logging an entry for a car that didn't get in.
|
||||||
|
- DECISION (capacity): wire transient entry now; the FULL gate comes later (needs capacity config +
|
||||||
|
occupancy fold).
|
||||||
|
- VALET / OVER-CAPACITY (user): "full" is a **soft, operator-configurable** policy — operator may
|
||||||
|
valet-accept over capacity (customer hands over keys + leaves, operator stacks the car). Manned-only,
|
||||||
|
new custody/session shape. Captured as [[valet-overcapacity]] + made [[capacity-occupancy]] FULL a
|
||||||
|
soft policy; NOT built into the entry flow (clean seam left). Deferred.
|
||||||
|
- New page [[valet-overcapacity]]; updated [[capacity-occupancy]], [[index]].
|
||||||
|
|||||||
Reference in New Issue
Block a user