← Back to Master Legal Governance Manual

ShepherdSync User Manual — Appendix A

Master Scheduling Protocol & Automation Specification · Version 1.6 (Production Edition) · August 10, 2026

A Product of The Shepherd Network LLC

SHEPHERDSYNC SCHEDULER SYSTEM

USER MANUAL — APPENDIX A

Master Scheduling Protocol & Automation Specification

Version 1.6 (Production Edition) | Approved for Implementation | August 10, 2026

A Product of The Shepherd Network LLC


1. Authority, Scope, and Source Hierarchy

SSP-001 — Authority of Appendix A

Appendix A is an integral part of the ShepherdSync Scheduler System User Manual and carries the same ruling and controlling authority as the body of the Manual. Where this Appendix establishes detailed scheduling, automation, eligibility, gap-resolution, emergency, publication, audit, or implementation requirements, those requirements govern ShepherdSync system behavior.

SSP-002 — Source Hierarchy

The ShepherdSync User Manual, including all approved appendices and revisions, is the highest operational authority. Training, developer materials, interface behavior, automations, and future implementation changes must conform to the User Manual and its appendices.

SSP-003 — Conflict Rule

If a training slide, earlier presentation, speaking point, legacy instruction, interface behavior, or code path conflicts with the approved User Manual or Appendix A, the User Manual and Appendix A control. The conflicting subordinate material must be corrected rather than treated as an alternate rule.

SSP-004 — Version Control

A material change to scheduling logic, authority, eligibility, timing, fairness, gap handling, emergency procedures, or publication shall create a new approved Appendix version. Historical records shall retain the protocol version under which they were created.

2. Core System Principles

COPY/PASTE FOR BASE44 — CORE SCHEDULING DIRECTIVE

3. Role Identity vs. Scheduling Treatment

SSP-010 — Actual Role Is Preserved

A user's actual system role and permission set shall remain distinct from temporary scheduling treatment. ADM, TL, and ATL are not redesignated as RW merely because the Phase 1 fairness engine temporarily treats them as RW-equivalent candidates.

SSP-011 — Phase 1 Temporary RW-Equivalent Treatment

During Phase 1, ADM, TL, and ATL retain their actual roles and permissions but are temporarily included in the Phase 1 RW-equivalent availability and fairness pool.

SSP-012 — End of Temporary Treatment

The temporary RW-equivalent treatment ends immediately after the initial fair schedule generation is completed. Any valid assignment created during Phase 1 remains in effect after the user returns to normal role-specific scheduling treatment.

4. Phase 1 — Availability Through Initial Fair Schedule Generation

SSP-020 — Phase 1 Boundaries

Phase 1 begins when the availability window opens and ends only after the initial fair schedule has been generated.

SSP-021 — Availability Codes

TAG1 means available. TAG2 means unavailable. These definitions are controlling.

SSP-022 — PIN Requirement

Phase 1 availability submission and any final acceptance/confirmation that creates or materially changes a worker commitment shall require the worker's personal PIN. PINs are personal, confidential, and must never be shared.

SSP-023 — Default Availability

At T-60 days before the upcoming quarter, when the Phase 1 availability window opens, ShepherdSync shall initialize every applicable Sunday/service date for every active eligible worker as TAG1 (AVAILABLE). A worker becomes unavailable only by deliberately changing the applicable date/service to TAG2 (UNAVAILABLE). Failure to enter or edit the availability screen does not convert the worker to TAG2; the system-generated TAG1 remains effective unless changed to TAG2 before the deadline.

SSP-024 — Eligibility Before Fairness

The fairness engine may rank only workers who first satisfy active status, role/team eligibility, recorded availability, hard exclusions, couple rules when applicable, and non-conflict requirements.

SSP-025 — Deterministic Fairness

The fairness engine shall use a rolling three-quarter service-load model. For each eligible individual, calculate Fairness Load Score = current-quarter service credits + the average of service credits from the immediately preceding two quarters. Lower Fairness Load Score ranks ahead of higher score. When scores are equal, use least-recent individual service date as the first tie-breaker, followed by a deterministic stable identifier. Random selection is prohibited. For an active Phase 1 CouplePair, apply the same three-quarter history window to both members; the pair's least-recent-service-date tie-break is the least-recent individual date among the two members.

4A. Phase 1 Quarter-Wide Fairness & Coverage Optimization

SSP-026 — Whole-Quarter Optimization

Phase 1 shall evaluate the entire upcoming quarter as one scheduling problem rather than permanently assigning each Sunday in isolation. After eligibility, CouplePair treatment, and Fairness Load calculations are available, ShepherdSync shall construct and optimize a tentative quarter-wide assignment plan before final Phase 1 persistence.

SSP-027 — Coverage Is the Primary Optimization Objective

The optimizer's first objective is to maximize the number of required positions that can be filled while honoring TAG1 availability, hard exclusions, CouplePair rules, required role rules, and assignment-conflict rules.

SSP-028 — Protect Limited Availability

When one eligible worker can serve several dates and another eligible worker can serve only one or fewer of those dates, ShepherdSync shall prefer an arrangement that preserves the limited-availability worker for the date(s) that worker can cover when doing so increases total quarter coverage or prevents a foreseeable gap.

SSP-029 — Fairness Remains Controlling Within Valid Coverage Solutions

Coverage optimization does not eliminate fairness. Among arrangements that achieve the same maximum valid coverage, ShepherdSync shall prefer the arrangement that best preserves the approved Fairness Load model, followed by least-recent service date and deterministic stable user_id tie-breaking.

SSP-029A — Tentative Before Persistent

The optimizer should build tentative assignments before final database persistence. A tentative assignment is not an official Assignment and must not be counted as persisted coverage. Only the final optimized assignment set shall be committed, subject to the assignment-persistence and reconciliation requirements of this Appendix.

SSP-029B — Permitted Rearrangement

Before Phase 1 is finalized, ShepherdSync may move or swap tentative assignments across dates when the resulting arrangement remains valid and improves total coverage, prevents a foreseeable gap, protects a more limited-availability worker, or produces an equally complete schedule with better approved fairness.

SSP-029C — Optimization Priority Order

The Phase 1 optimizer shall apply this priority order: (1) maximize filled required positions; (2) protect limited-availability workers for dates they uniquely or more narrowly cover; (3) preserve CouplePair and all hard eligibility/role requirements; (4) minimize unnecessary assignment movement; (5) optimize the approved Fairness Load; (6) use least-recent service date; and (7) use stable user_id as the final deterministic tie-breaker.

SSP-029D — No TAG2 Override

Phase 1 optimization may never override TAG2. Availability override authority remains exclusively within the separately authorized BREAK THE GLASS Level 2 protocol.

SSP-029E — Optimization Completion Gate

Phase 1 shall not be declared complete until ShepherdSync has confirmed that no better valid availability-respecting arrangement exists that would fill more required positions under the approved constraints. Any remaining uncovered position shall become a ScheduleGap and advance to the post-Phase-1 protocol.

SSP-029F — Distinction From BREAK THE GLASS

Phase 1 Quarter-Wide Fairness & Coverage Optimization may use rearrangement techniques similar to BREAK THE GLASS Level 1, but it is not an emergency action and shall not be labeled BREAK THE GLASS. BREAK THE GLASS remains a later emergency protocol with its own prerequisites, authority, and audit states.

4B. Phase 1 Fairness Rebalance, Participation Floor, and Four-Date Soft Maximum

SSP-029G — Participation Floor

When a valid zero-gap schedule is feasible, ShepherdSync shall attempt to provide every eligible Phase 1 scheduling unit at least one scheduled service date before repeatedly assigning additional dates to already-used scheduling units. A scheduling unit is one independently schedulable individual worker or one active CouplePair during Phase 1. The participation floor never authorizes a TAG2 assignment, hard-exclusion violation, CouplePair violation, role violation, or avoidable gap.

SSP-029H — Four-Date Soft Maximum

No individual worker should receive more than four system-generated scheduled service dates in a quarter when a valid zero-gap schedule can be produced without exceeding four. Before assigning a fifth date to any worker, ShepherdSync shall determine whether another eligible worker or CouplePair with fewer scheduled dates can cover the position, including through quarter-wide rearrangement.

SSP-029I — Above-Four Exception

During Phase 1, the optimizer shall first exhaust all valid zero-gap solutions that keep every worker at four or fewer scheduled dates. If a fifth system-generated date is unavoidable, the Phase 1 fifth-date exception is restricted to ADM, TL, or ATL only, as a last resort, while still honoring TAG1, hard exclusions, CouplePair rules, and conflicts. A Phase 1 fifth-date exception shall be specifically justified and audit logged. Ordinary RW candidates shall not receive a system-generated fifth Phase 1 date. Voluntary post-Phase-1 EFP or other authorized voluntary emergency coverage may later cause an individual to exceed four without violating this Phase 1 rule.

SSP-029J — Scarcity as Constraint Only

Availability scarcity shall be used only to protect future coverage and prevent a limited-availability worker from being consumed on a date that a more flexible worker could cover when doing so would create a foreseeable later gap. Scarcity shall not operate as a recurring positive scheduling bonus that causes a limited-availability worker to outrank others on every eligible date.

SSP-029K — Dynamic Current-Quarter Fairness

Tentative current-quarter assignment credits shall update dynamically during optimization. Each tentative service-date assignment immediately changes that scheduling unit's current-quarter load for subsequent decisions. The optimizer shall not use a stale fairness score calculated only once at the start of the run.

SSP-029L — CouplePair Fairness Load

For Phase 1 ranking, each spouse's Individual Fairness Load shall be calculated separately using the approved formula. The CouplePair Fairness Load shall equal the average of the two members' Individual Fairness Loads, not the sum. Couple Fairness Load = (Member A Fairness Load + Member B Fairness Load) / 2. The previously approved least-recent-individual service date remains the pair's service-date tie-breaker.

SSP-029M — Revised Optimization Priority

The Phase 1 optimizer shall apply this controlling priority order: (1) maximize required-position coverage and achieve zero gaps whenever possible; (2) enforce TAG1/TAG2, hard exclusions, CouplePair rules, required-role rules, and assignment conflicts; (3) use scarcity only where needed to protect future quarter coverage; (4) provide every eligible scheduling unit at least one service opportunity when feasible; (5) keep every individual worker at four or fewer scheduled dates whenever a valid zero-gap solution permits it; (6) prefer scheduling units with fewer current-quarter dates; (7) apply dynamically updated Fairness Load; (8) apply least-recent service date; and (9) apply immutable stable user_id as the final deterministic tie-breaker.

SSP-029N — Routine Rearrangement Comparable to BTG Level 1

Phase 1 Quarter-Wide Fairness & Coverage Optimization may use the same class of quarter-wide search, swap, and rearrangement techniques used by BREAK THE GLASS Level 1. However, Phase 1 optimization is routine scheduling, not emergency authority, and may never override TAG2. BREAK THE GLASS Level 2 remains the only separately authorized protocol that may override recorded unavailability under its extraordinary prerequisites.

5. Couples Protocol

SSP-030 — CouplePair Entity

Couples shall remain separate individual users but may be linked through an ADM-managed CouplePair record. Only ADM may create, modify, deactivate, or dissolve the pairing. All pair changes shall be audit logged.

SSP-030A — Initial Production CouplePair Records

Before the next Phase 1 generation, ADM shall create active CouplePair records for Craig Cooper + Tammy Cooper and John Crowe + Melissa Crowe. These are the only currently approved married-couple pairings. CouplePair enforcement applies during Phase 1 only; after Phase 1, each individual may volunteer separately under the applicable gap protocol.

SSP-030B — Cooper CouplePair Communion Split

Craig Cooper + Tammy Cooper are an active Phase 1 CouplePair. When communion is scheduled on the last Sunday of the month, Craig's hard communion exclusion prevents the Cooper pair from serving together on that date. Tammy may be scheduled individually on that last Sunday when TAG1 and otherwise eligible. This is an approved Phase 1 CouplePair split exception tied specifically to Craig's communion responsibility; it does not dissolve the CouplePair relationship.

SSP-031 — Phase 1 Indivisible Pair

During Phase 1 only, an active CouplePair is an indivisible scheduling unit. Both individuals must independently submit TAG1 for a date before the pair is eligible for automatic Phase 1 scheduling.

SSP-032 — Conflicting Couple Availability

If one spouse submits TAG1 and the other TAG2, the couple is unavailable for Phase 1 on that date and ShepherdSync shall flag the mismatch for correction before the deadline.

SSP-033 — Couple Fairness Date

The couple's Phase 1 fairness date shall be the least-recent individual service date among the two members. Example: one spouse last served 2 weeks ago and the other 6 weeks ago; the pair is ranked using 6 weeks.

SSP-034 — Couple Assignment Accounting

A scheduled couple represents two individual workers, fills two required worker positions, and creates one assignment/service-date credit in each individual's personal service history.

SSP-035 — Both Regular Services

A Phase 1 couple assignment covers both regular Sunday services for that service date. Operational release after second-service check-in may occur approximately 15–20 minutes after the final parent check-in.

SSP-035A — One CouplePair Per Sunday

During Phase 1, ShepherdSync shall not schedule more than one active CouplePair on the same Sunday when ordinary staffing requires only two worker positions. A CouplePair fills both normal worker positions. This rule does not prevent additional individually required leadership or special-event staffing where the configured event requires more than two workers.

SSP-036 — Post-Phase-1 Volunteering

After Phase 1, mandatory pairing does not control gap volunteering. Each spouse receives and responds to EFP individually. Either spouse may volunteer separately, or both may independently volunteer for two openings on the same date.

COPY/PASTE FOR BASE44 — COUPLE PAIRING LOGIC

6. Last-Sunday Communion Restrictions

SSP-040 — Hard Exclusions

Craig/ADM and Beth Powers are normally ineligible for worker assignment on the last Sunday of each month because of communion responsibilities. The exclusion is a hard eligibility rule and must not be defeated by an accidental TAG1 entry.

SSP-041 — Tammy Last-Sunday Eligibility

Tammy is not subject to the hard last-Sunday exclusion and may be scheduled independently on the last Sunday when her submitted availability permits.

SSP-042 — No-Communion Exception

If communion will not occur and Craig or Beth voluntarily wants to serve, the system may grant a date-specific exception only after displaying the communion warning, obtaining affirmative confirmation that no communion service is scheduled, obtaining voluntary availability confirmation, and verifying the user's PIN.

SSP-043 — Audit of Exception

The no-communion exception must be date-specific and permanently audit logged.

6A. Authoritative Five-Phase Workflow — Protocol v1.5

SSP-047A — Phase 1: Optimizer

Phase 1 consists of availability processing, eligibility and fairness calculations, tentative scheduling, quarter-wide rearrangement/swap optimization, and the restricted fifth-date last-resort exception. The Phase 1 optimizer shall not perform the ATL/TL post-Phase-1 rotation. If Phase 1 persists a complete zero-gap schedule, workflow becomes INITIAL_SCHEDULE_GENERATED and advances to FINALIZATION. If persisted gaps remain, workflow becomes GAPS_PRESENT.

SSP-047B — Phase 2: No-Gap Workers / Skipped Stage

Phase 2 is the no-gap-workers stage and is skipped when there is no applicable work to perform. It shall not absorb, duplicate, or execute the ATL/TL rotation assigned to Phase 3.

SSP-047C — Phase 3: Leadership Rotation

From GAPS_PRESENT, advance_gaps transitions the workflow to LEADERSHIP_ROTATION. The standalone run_leadership_rotation action then attempts to fill remaining gaps using the approved ATL → TL → ATL → TL rotation. If all gaps are filled, advance to FINALIZATION. If gaps remain after leadership rotation is exhausted, advance to EFP_ACTIVE.

SSP-047D — Phase 4: Emergency Fill Protocol

Phase 4 begins at EFP_ACTIVE. EFP proceeds under the approved secure outreach, individual response, eligibility, and PIN-confirmation rules. When the EFP is exhausted and a gap remains, workflow becomes EFP_EXHAUSTED and then advances to BTG_LEVEL1.

SSP-047E — Phase 5: BREAK THE GLASS

Phase 5 begins at BTG_LEVEL1. BREAK THE GLASS Level 1 performs the approved availability-respecting emergency rearrangement. If Level 1 fails, workflow becomes BTG_LEVEL1_FAILED and then BTG_LEVEL2_AVAILABLE. Level 2 may be used only under its separately approved ADM emergency prerequisites. When all required positions are resolved, workflow advances to FINALIZATION.

SSP-047F — Phase Separation Is Mandatory

No implementation may collapse the five phases, execute Phase 3 leadership rotation inside Phase 1, or bypass required workflow states merely because the same worker is eligible in more than one phase. Each phase has separate authority, eligibility treatment, audit meaning, and transition conditions.

SSP-047G — Invocation Order

The approved operational sequence is: run_phase1 → when GAPS_PRESENT, advance_gaps → run_leadership_rotation → advance_gaps → EFP processing when EFP_ACTIVE → BREAK THE GLASS Level 1 when EFP is exhausted → Level 2 only when Level 1 fails and Level 2 prerequisites are satisfied → FINALIZATION.

SSP-047H — Phase 1 Replacement and Published-Quarter Safeguards

A corrective Phase 1 rerun shall use REPLACE behavior for the applicable Phase 1-generated assignment set and shall not layer duplicate assignments over a prior run. A quarter already marked/published as the official schedule shall be protected from an ordinary Phase 1 rerun unless ADM uses an expressly authorized correction/override procedure.

SSP-047I — Legacy Rotation Workflow Deactivated

Any legacy, embedded, automatic, or Phase-1-integrated leadership-rotation workflow is deactivated. The only approved ATL/TL gap rotation is the standalone Phase 3 run_leadership_rotation action operating from LEADERSHIP_ROTATION state.

SSP-047J — Immutable Process Definition Audit

The Phase 1–5 process definition shall be represented by the immutable PHASE_PROCESS_DEFINITION_LOCKED audit event under protocol version 1.5. The audit event records the authoritative phase boundaries, workflow transitions, REPLACE behavior, published-quarter protection, deactivated legacy rotation workflow, and restricted Phase 1 fifth-date exception.

7. Phase 3 — Standalone ATL/TL Leadership Rotation

SSP-050 — Fairness Ends for TL/ATL

Phase 3 is a standalone post-Phase-1 gap-filling action. It shall never execute inside the Phase 1 optimizer. Phase 3 begins only when Phase 1 has closed with persisted ScheduleGap records and the workflow has advanced from GAPS_PRESENT to LEADERSHIP_ROTATION.

SSP-051 — Leadership Gap Rotation

The standalone run_leadership_rotation action shall rotate eligible leadership candidates in this sequence: ATL, then TL, then ATL, then TL, continuing as needed across remaining gaps. Each assignment must honor the leader's recorded availability and all hard exclusions. Phase 1 fairness is not used in Phase 3.

SSP-052 — Unavailable Leadership

If the next leadership candidate is TAG2 for the gap date, the system shall skip that candidate, audit the unavailability, and continue to the next permitted step.

SSP-053 — EFP Trigger

If Phase 3 fills every remaining ScheduleGap, the workflow advances to FINALIZATION. If one or more gaps remain after the ATL/TL rotation is exhausted, the workflow advances to EFP_ACTIVE and Phase 4 begins.

SSP-054 — Leadership Reachability

TL and ATL/AcTL are expected to remain reachable for every service for urgent decisions, communications, short-notice sickness, and leadership matters, whether or not they occupy a worker slot.

8. Acting Team Leader (AcTL)

SSP-060 — Authority State

AcTL is a temporary leadership authority state, not a staffing slot.

SSP-061 — Activation

When TL is TAG2/unavailable for the applicable upcoming service period and ATL is needed to exercise TL authority, ATL shall assume AcTL rights and responsibilities.

SSP-062 — Continuation

AcTL authority may continue through consecutive upcoming Sundays in which TL remains TAG2/unavailable.

SSP-063 — Reversion

When the next applicable upcoming Sunday shows TL as TAG1/available, AcTL authority expires, the person returns to ATL status, and TL resumes ordinary TL authority.

SSP-064 — Official Record

AcTL activation and expiration shall be driven by the official ShepherdSync schedule/availability record and shall be audit logged.

9. ADM Eligibility After Phase 1

SSP-070 — No Automatic ADM Gap Assignment

After Phase 1, ADM shall not be automatically considered for ordinary gap filling.

SSP-071 — Voluntary ADM Participation

ADM may participate in an EFP or another authorized gap opportunity only by self-assignment or voluntary response for the specific date/service.

SSP-072 — No Ordinary Fairness After Phase 1

ADM shall not re-enter Phase 1 fairness logic after Phase 1 closes. Post-Phase-1 volunteer or emergency participation follows the protocol applicable to that gap.

9A. Identity, Service-History, and Data Integrity

SSP-075 — Immutable User Identity

Service history, fairness calculations, assignments, CouplePair membership, availability, and audit records shall be keyed to the immutable ShepherdSync user_id, never to display name, email prefix, username text, or another mutable label.

SSP-076 — Display Name Standard

User-facing display names shall contain the person's approved actual/preferred name only. Email prefixes or email-style usernames shall not be used as display names.

SSP-077 — Melissa Crowe Legacy Merge

Melissa Crowe is the approved current identity/display name. Any legacy record associated with 'melissacrowe78' may be migrated to Melissa Crowe only when an authoritative ShepherdSync identity record independently and reliably establishes that the record belongs to Melissa Crowe's immutable user_id. Name, username, or email-prefix similarity alone is insufficient. Unverified legacy Assignment records are subject to the ADM-authorized cleanup rules in SSP-079G through SSP-079L.

SSP-078 — No Name-Based Fairness

getServiceHistory() and all equivalent fairness functions shall query by immutable user_id and quarter identifiers. Name-string matching is prohibited for fairness or service-credit calculations.

SSP-079 — Fairness History Window

Fairness shall use only the current quarter plus the average of the immediately preceding two quarters. Older quarters may remain in historical/audit storage but shall not affect active Phase 1 fairness.

SSP-079A — Phase 1 Generation Gate

The Phase 1 availability window opens at T-60 days with eligible dates/services defaulted to TAG1, but initial fair schedule generation must not run until the configured availability deadline has passed and the availability window is locked.

SSP-079B — Assignment Persistence Integrity

The system shall never treat a planned assignment as successfully created until the Assignment record is confirmed persisted in the authoritative database. Assignment creation errors must not be silently swallowed.

SSP-079C — Create Failure Handling

If Assignment.create or equivalent persistence fails, ShepherdSync shall record ASSIGNMENT_CREATE_FAILED, retry only under a safe/idempotent policy, and if the record remains uncreated, create or preserve the corresponding ScheduleGap. Phase 1 shall not report complete while required positions and successfully persisted assignments are inconsistent.

SSP-079D — Actual-Persisted Gap Calculation

Gap calculations shall use successfully persisted Assignment records from the authoritative database, not an in-memory planned count. After Phase 1 generation, reconcile required positions against persisted assignments and create ScheduleGap records for every uncovered position.

SSP-079E — Inactive/Test Worker Exclusion

Inactive workers shall not participate in production availability, fairness, assignment, leadership rotation, EFP, or gap resolution unless ADM explicitly places them into authorized test mode. Darry L. Dummy is an inactive test worker. Test scheduling records shall be expunged after testing and the test worker returned to inactive status.

SSP-079F — Blocking Data-Integrity Preflight

Before each production Phase 1 generation, detect duplicate/legacy identities, missing volunteer_role values, inactive/test workers with production assignments, stale/test target-quarter assignments, anomalous overstaffing, and orphaned service-history records. Critical findings shall block production generation until resolved.

SSP-079G — Legacy Assignment Identity Rule

Historical or current Assignment records that lack a valid immutable user_id shall not be attributed to a worker solely from display name, username, email prefix, free-text name, or another mutable text value. If ownership cannot be independently verified from an authoritative ShepherdSync identity source, the Assignment is identity-unverified and shall not contribute to active fairness or service-history calculations.

SSP-079H — ADM-Authorized Cleanup of the 68 Unkeyed Assignments

ADM has authorized removal of the 68 currently identified Assignment records that lack user_id because their worker ownership cannot be reliably established. This cleanup includes stale/broken-run records and identified legacy/test records. Before deletion, ShepherdSync shall preserve an administrative audit snapshot sufficient to document the records removed and the reason for removal. The snapshot is audit/recovery evidence only and shall not become active fairness or service-history data.

SSP-079I — No Guessing During Cleanup

Base44/ShepherdSync shall not reconstruct or assign ownership of the 68 unkeyed Assignment records by guessing from names, usernames, email prefixes, or similar text. A record may be retained or migrated only if another authoritative ShepherdSync record independently and reliably establishes the immutable user_id.

SSP-079J — Mandatory user_id for New Assignments

Every newly created production Assignment shall require a valid immutable user_id at the server/data layer. An Assignment creation request without a valid user_id shall be rejected, shall not count as coverage, and shall generate a visible system/audit failure rather than being silently swallowed.

SSP-079K — Clean Service-History Baseline

After the authorized cleanup, active fairness shall use only service-history records reliably associated with immutable user_id. If no independently verifiable historical record exists for a worker, ShepherdSync shall begin from the clean keyed baseline rather than manufacture or infer service credits.

SSP-079L — Post-Cleanup Reconciliation

After deletion of the authorized unkeyed records, ShepherdSync shall verify that no active production Assignment remains without user_id, rerun the blocking production data-integrity preflight, and report all remaining blockers to ADM. Production Phase 1 shall not run until ADM separately authorizes it after reviewing the cleanup/preflight report.

10. Persistent ScheduleGap Entity

SSP-080 — Gap as First-Class Record

Every uncovered required worker position shall create or update a persistent ScheduleGap object. A blank calendar cell alone is not sufficient.

SSP-081 — Gap Continuation

A gap must continue automatically to the next authorized protocol until resolved or formally carried into the applicable emergency/finalization state.

11. Phase 4 — Emergency Fill Protocol (EFP)

SSP-090 — Activation

When the normal scheduling process and applicable leadership processing leave an unresolved gap, ShepherdSync shall create an EFP event.

SSP-091 — Recipients

EFP outreach may be sent to eligible individual RW, ATL, TL, and ADM users. ADM participation remains voluntary after Phase 1.

SSP-092 — Channels

EFP shall use SMS where the user has valid SMS consent, email, and in-app messaging. A person's decision not to receive SMS must not affect volunteer eligibility or access.

SSP-093 — Assignment Rule

EFP does not use Phase 1 fairness. The first valid eligible acceptance recorded by the authoritative server process receives the open assignment.

SSP-094 — Atomic Claim

Acceptance must be committed atomically so two workers cannot receive the same gap because of near-simultaneous responses.

12. Secure EFP Direct-Access Links

SSP-100 — Direct Access

SMS and email may contain a secure individualized link that takes the intended worker directly to the applicable EFP response screen without the ordinary sign-in flow.

SSP-101 — Link Is Not Authorization

The secure link identifies the intended user and gap context but is not sufficient to create an assignment.

SSP-102 — PIN Confirmation

An EFP acceptance must require the intended worker's personal PIN before ShepherdSync commits the assignment.

SSP-103 — Token Controls

The EFP token shall be individualized, cryptographically secure, time-limited, gap-specific, revocable, and invalidated when the gap is filled or the response event closes.

SSP-104 — PIN Secrecy

A PIN must never appear in the URL, SMS, email, analytics data, browser storage intended for telemetry, logs, or ordinary audit metadata.

COPY/PASTE FOR BASE44 — EFP SECURE DIRECT LINK

13. Phase 5 — BREAK THE GLASS — Level 1

SSP-110 — Purpose

BREAK THE GLASS Level 1 is a quarter-wide emergency optimization and rearrangement process used after the applicable EFP and required preceding protocols are exhausted.

SSP-111 — Availability Preserved

Level 1 must preserve recorded availability and shall not override TAG2.

SSP-112 — Search Objective

Level 1 shall search for a complete quarter solution rather than merely filling the nearest gap. The preferred order is direct fill, one-step reassignment, multi-step reassignment, then broader quarter-wide valid rearrangement.

SSP-113 — Least-Served Optimization

Where multiple valid rearrangements exist, the solver should continue honoring the approved least-served/fewest-assignment fairness objective while minimizing unnecessary disruption.

SSP-114 — Rearrangement Example

If Worker A is least-served, TAG2 for the current gap, but TAG1 for a later Sunday held by Worker B, and Worker B is TAG1 for the current gap, ShepherdSync may move Worker B into the current gap and place Worker A into Worker B's vacated later assignment. The process may continue across the quarter until all gaps are filled or no availability-preserving complete solution exists.

SSP-115 — Failure State

Level 1 is considered failed only when the solver determines that no complete schedule can be produced using recorded availability and permitted rearrangements.

14. BREAK THE GLASS — Level 2 ADM Emergency Availability Override

SSP-120 — Extraordinary Authority

Level 2 is an extraordinary ADM/Super Admin emergency authority. It is not an ordinary scheduling method.

SSP-121 — Prerequisites

Level 2 may become available only after the applicable EFP is exhausted, required leadership processing is complete, Level 1 is complete, and Level 1 finds no complete availability-respecting solution.

SSP-122 — TAG2 Override

Level 2 may override a worker's recorded TAG2/unavailable status only when ADM determines that doing so is the most appropriate necessary emergency action.

SSP-123 — Required Safeguards

Before committing a Level 2 assignment, ShepherdSync shall require ADM/Super Admin authentication, ADM PIN, a second confirmation screen, exact worker/date/service/gap identification, a written emergency justification, acknowledgment that the worker is recorded TAG2, confirmation of EFP exhaustion, confirmation of Level 1 failure, and final confirmation.

SSP-124 — Warning

The confirmation screen shall prominently display: EMERGENCY AVAILABILITY OVERRIDE — THIS WORKER IS RECORDED AS UNAVAILABLE.

SSP-125 — Preserve Original Availability

The system shall never rewrite the historical TAG2 record as TAG1 merely to make the resulting schedule appear ordinary.

SSP-126 — Level 2 Audit

The permanent audit record shall include ADM identity and role, PIN verification event, selected worker, original availability, service/date/gap, written justification, exhaustion state, Level 1 result, before/after snapshots, timestamp, protocol version, and resulting schedule state.

SSP-127 — Re-Evaluate Quarter

After every Level 2 action, ShepherdSync shall rerun gap analysis and continue finalization until every required position is resolved or another separately documented Level 2 action is necessary.

COPY/PASTE FOR BASE44 — BREAK THE GLASS LEVEL 2 — ADM EMERGENCY AVAILABILITY OVERRIDE

15. Special Event and Holiday Staffing

SSP-130 — Configuration-Driven Staffing

Special-event staffing shall be configuration-driven. Event templates may provide defaults, but the system shall store the actual required worker count and any required leadership-role positions for each configured event/service.

SSP-131 — Couple Count

A scheduled couple counts as two workers toward the configured event requirement.

SSP-132 — TL/ADM Event Configuration

TL or ADM may configure an approved special event's worker requirement and role requirements where operational needs differ from the default template.

16. VBS Classification

SSP-140 — All-Worker Requirement

VBS is a separate special-event protocol and is not processed as an ordinary Sunday minimum-staff event. Its default staffing population is all active eligible workers.

SSP-141 — Worker Conflict

A worker who cannot serve VBS must notify TL according to the VBS protocol. Detailed VBS handling may be maintained in a separate approved special-event appendix or section.

17. Finalization, Authorization, and Publication

SSP-150 — Distinct Finalization States

Lock, review, authorization, and publication shall remain separate system states. Do not use one generic APPROVED state to represent all finalization actions.

SSP-151 — Official Schedule

At publication, the online ShepherdSync calendar becomes the official schedule of record for the upcoming quarter.

SSP-152 — Final Gap Alert

ShepherdSync shall issue the Final Gap Alert 96 hours before the beginning of the upcoming quarter, exactly 24 hours before the 72-hour Force Lock. The alert shall identify all unresolved required positions and initiate or continue the applicable final pre-lock gap-resolution and emergency protocols. All former references to a "36-Hour Final Gap Alert" are obsolete and shall be removed from the User Manual, training materials, developer documentation, interface text, notification templates, automations, and application code.

COPY/PASTE FOR BASE44 — FINALIZATION TIMELINE

18. Required Workflow States

[Workflow states managed within ShepherdSync application.]

19. Post-Publication Change Requests

SSP-160 — Auto-Approval

A valid Change Request for a locked assignment is automatically approved; no ordinary leadership approval is required.

SSP-161 — Required Explanation

The worker shall enter the approved minimum meaningful explanation of at least 50 characters unless a later User Manual revision changes this threshold.

SSP-162 — Automatic Recovery Flow

Upon a valid Change Request, ShepherdSync shall release the worker, preserve the request/audit record, create a ScheduleGap, determine the correct recovery protocol, update the official calendar status, and initiate the applicable gap-filling process.

SSP-163 — Official Record

Any private explanation by phone, text, or email does not replace the required ShepherdSync Change Request.

20. Scheduling Invariants

INV-01 — Invariant

Never assign an inactive user.

INV-02 — Invariant

Never use TAG2 in ordinary scheduling.

INV-03 — Invariant

Never separate an active couple during Phase 1.

INV-04 — Invariant

Never consider a Phase 1 couple available unless both members are TAG1.

INV-05 — Invariant

Never automatically assign ADM after Phase 1.

INV-06 — Invariant

Never apply Phase 1 fairness to EFP.

INV-07 — Invariant

Never apply Phase 1 fairness to post-Phase-1 TL/ATL rotation.

INV-08 — Invariant

Never bypass a functioning required protocol phase.

INV-09 — Invariant

Never permit BREAK THE GLASS Level 2 before its prerequisites are satisfied.

INV-10 — Invariant

Never erase the original TAG2 when Level 2 is used.

INV-11 — Invariant

Never alter the official schedule solely through a private text, phone call, email, or verbal agreement.

INV-12 — Invariant

Never publish before authorization or auto-authorization.

INV-13 — Invariant

Never treat an EFP direct link alone as sufficient authority to accept a service assignment.

INV-14 — Invariant

Never expose, transmit in a URL, or log a worker PIN in plain text.

21. Audit and Event Requirements

SSP-170 — Immutable Event History

Every meaningful scheduling event shall create an immutable audit event with actor, role/authority state, entity, protocol phase, protocol version, server timestamp, and before/after state when applicable.

22. Notification Separation and SMS Compliance

SSP-180 — Event-Driven Notifications

Scheduling logic shall emit system events; a separate notification service shall determine SMS, email, and in-app delivery.

SSP-181 — SMS Consent

SMS may be sent only to users with valid affirmative SMS consent. Declining SMS shall not prevent use of ShepherdSync or volunteer participation.

SSP-182 — Delivery Audit

Notification attempts and delivery outcomes shall be recorded without storing PINs or other secret authentication data.

23. Production Preflight

SSP-190 — Block on Critical Failure

If a required preflight item fails, ShepherdSync shall block automated quarter generation and display a configuration error to ADM rather than silently proceeding with incomplete rules.

24. Acceptance Testing Before Production

SSP-200 — Desktop and Mobile

The production implementation is not complete until all applicable acceptance tests pass on both desktop and mobile.

25. Base44 Consolidated Implementation Directive

COPY/PASTE FOR BASE44 — CONSOLIDATED PRODUCTION BUILD

25A. Q4 2026 Phase 1 Production Validation

VAL-001 — Coverage

The Q4 2026 Phase 1 v1.4 production rerun persisted 26 of 26 required positions across 13 Sundays and created zero ScheduleGap records.

VAL-002 — Four-Date Soft Maximum

No worker exceeded the four-date soft maximum. The production distribution ranged from two to three scheduled dates per eligible worker.

VAL-003 — Participation Floor

All nine eligible Phase 1 workers received at least one assignment.

VAL-004 — CouplePair Fairness

The Crowe CouplePair was scheduled together with identical paired counts. The Cooper CouplePair was scheduled together where applicable, while Tammy also received an approved individual last-Sunday assignment under the communion split exception.

VAL-005 — Communion Exclusions

Craig Cooper and Beth Powers were not assigned as workers on communion-restricted last Sundays.

VAL-006 — Data Integrity

All 26 persisted production Assignment records contain valid immutable user_id values and the run reported zero Assignment creation failures.

VAL-007 — Phase 1 Completion

The Q4 2026 workflow reached initial_schedule_generated with zero gaps. Phase 1 was therefore successfully completed under Protocol Version 1.4, and ADM/TL/ATL may revert from temporary Phase 1 RW-equivalent scheduling treatment to their normal post-Phase-1 roles and protocols.

25B. Early Official Publication Upon Successful Finalization

SSP-120 — Publish Upon Successful Finalization

A quarterly schedule shall not be required to remain unpublished solely to wait for T-30 when the applicable scheduling process has already reached FINALIZATION and all publication-readiness requirements have passed. Once the schedule is finalized, verified complete, and authorized under this section, ShepherdSync may immediately publish it to the online calendar as the Official Schedule.

SSP-121 — Zero-Gap Publication Gate

Early official publication requires zero active ScheduleGap records for the quarter and successful reconciliation showing that every required staffing position is represented by a successfully persisted Assignment record.

SSP-122 — Publication-Readiness Validation

Before early publication, ShepherdSync shall verify: valid immutable user_id on all assignments; no unresolved Assignment creation failure; TAG1/TAG2 compliance; all hard exclusions; CouplePair rules; required staffing and leadership rules; applicable Phase 1 fairness and optimization requirements; successful completion or legitimate skipping of later phases; passing data-integrity checks; and no unresolved blocking condition.

SSP-123 — Applicable Phases May Be Legitimately Skipped

When Phase 1 concludes with zero gaps, Phase 3 Leadership Rotation, Phase 4 EFP, and Phase 5 BREAK THE GLASS are not prerequisites to publication and shall be skipped. When gaps existed, any applicable later phase must be completed according to protocol before the schedule may satisfy the zero-gap publication gate.

SSP-124 — T-30 Is Latest Normal Publication Deadline

T-30 is the latest normal publication deadline, not a mandatory waiting date. ShepherdSync should publish the Official Schedule as soon as successful finalization and publication-readiness validation are complete. An otherwise complete, verified, zero-gap schedule shall not be intentionally held until T-30 solely because T-30 has not yet arrived.

SSP-125 — T-96 and T-72 Do Not Delay an Already Finalized Zero-Gap Schedule

The T-96 Final Gap Alert and T-72 Force Lock remain required protective checkpoints for schedules that are still unresolved or not yet officially published. They shall not force an already finalized, verified, zero-gap schedule to remain unpublished merely so those checkpoints can occur first.

SSP-126 — Early Publication Workflow Transition

When all early-publication requirements pass, the approved workflow transition is FINALIZATION → OFFICIAL_PUBLISHED. The publication event shall record the publication timestamp, protocol version, quarter, assignment count, gap count, validation result, and authorizing system/ADM state.

SSP-127 — Published Schedule Remains Governed

Official publication does not make the schedule immune from later legitimate changes. Illness, withdrawal, approved change requests, emergencies, or other authorized events may create a post-publication scheduling issue. ShepherdSync shall preserve the official publication audit history and process subsequent changes through the applicable post-publication change/gap protocol rather than silently rewriting history.

SSP-128 — Published-Quarter Protection

After OFFICIAL_PUBLISHED, ordinary Phase 1 generation or rerun actions shall not overwrite the published quarter. Any authorized correction, replacement, or post-publication assignment change must use the approved change/override workflow and retain an auditable record of the prior official schedule state.

SSP-129 — Online Calendar Publication

Official publication shall make the finalized schedule available through the ShepherdSync online calendar or other configured official schedule surface. The system shall publish only the validated final persisted assignment set and shall not publish tentative, planned, failed, or unreconciled assignments.

26. Revision-Control Note

Version 1.6 production revision authorizes immediate official online-calendar publication once a quarterly schedule reaches FINALIZATION, has zero active gaps, reconciles all required positions to persisted assignments, and passes all applicable protocol and integrity checks. T-30 is now the latest normal publication deadline rather than a mandatory waiting date. T-96 and T-72 remain protective checkpoints for unresolved/unpublished schedules but do not delay an already finalized zero-gap schedule. Published schedules remain auditable and protected from ordinary Phase 1 overwrite; subsequent legitimate changes must use the applicable post-publication change/gap protocol. All nonconflicting Version 1.5 five-phase architecture, fairness, CouplePair, communion, identity, persistence, and audit requirements remain controlling.

END OF APPENDIX A — VERSION 1.6

Questions about this document? Contact support@theshepherdnetwork.org

Give Here SECURED