RL
Active regulatory rulesPublished
1,284
42 scheduled future changes
Countries governedAPAC
18
4 countries require review this month
ERP sync health92%
57/62
5 connectors waiting for retry window
Compliance exposureMedium
12
3 high priority alerts

Enterprise governance operating model

CQRS-ready command flow, event bus, scheduler, retry queue, tenant isolation, and websocket notification health.

Enterprise-ready
CQRSCommand bus
Rule changes, approvals, publication, rollback
EventsDomain bus
rule.approved, rule.published, sync.failed
JobsScheduler
Effective-date publish windows
RetryQueue
Exponential backoff and dead-letter lane
RealtimeWebsocket
Approval and sync notifications
RBACRow policy
Tenant, country, domain scoping

Regulatory change pipeline

Monthly volume by domain and status

React Query mock feed

Compliance score

On track
Published
Scheduled
Review
Risk

Country pack compliance heatmap

i18n + local rules
Country
Tax
Social
Labor
Sync
i18n
Flags
Audit
Indonesia
98
94
86
92
ID
12
OK
Philippines
84
91
89
76
EN
9
OK
Malaysia
93
95
82
90
MS
8
OK
Singapore
97
96
94
96
EN
7
OK

Governance SLA widgets

2 watch
92
Approval SLA
8 pending
88
Sync SLA
5 retries
96
Audit coverage
All writes logged
84
Conflict risk
3 overlaps

Critical effective dates

Governance activity

Input perubahan tax bracket tahunan

Untuk contoh perubahan tax bracket tahun 2025: klik tombol di kanan, isi effective date 2025, update bracket rows, lalu simpan sebagai Draft Version.

Rule Country Domain Effective period Version Workflow Sync Action
Rule code
ID.PAYROLL.PPH21.BRACKET
Value type
JSON array
Effective from
2026-07-01
Effective to
Open ended
Version
v4.0
Source reference
DGT Regulation Draft 2026
Current published v3.2
[
  {"max": 60000000, "rate": 0.05},
  {"max": 250000000, "rate": 0.15},
  {"max": 500000000, "rate": 0.25},
  {"max": 5000000000, "rate": 0.30},
  {"max": null, "rate": 0.35}
]
Scheduled v4.0
[
  {"max": 75000000, "rate": 0.05},
  {"max": 260000000, "rate": 0.15},
  {"max": 520000000, "rate": 0.25},
  {"max": 5000000000, "rate": 0.30},
  {"max": null, "rate": 0.35}
]
Draft
Created by analyst
Under Review
Legal checked
Approved
Payroll owner
Scheduled
2026-07-01
Published
Waiting effective date
Synced
ERP targets pending
ConnectorERPLegal entitiesStrategyStatus
HM3 Indonesia PayrollHM318WebhookScheduled
Novea Lite PayrollNovea7REST APIMapped
HMX Core HRHMX22Event stream readyReady

Effective dating

Future scheduled
2025-01-01

v3.2 published

Current production tax bracket.

2026-05-18

v4.0 approved

Government draft reflected and locked.

2026-07-01

v4.0 goes live

ERP sync window opens 72 hours before effective date.

Version history

ID.PAYROLL.PPH21.BRACKET
VersionEffective fromEffective toStatusApproved byChange reasonAction

Approval matrix

Country + domain + risk
Domain
Low risk
Medium risk
High risk
Emergency
Payroll Tax
Country Owner
Country + Finance
Country + Legal + Finance
CFO override + audit
Social Security
Country Owner
Country + HR
Country + Legal + HR
COO override + audit
Indirect Tax
Tax Analyst
Finance Lead
Finance + Legal
CFO override + audit
Labor Law
HR Ops
HR Lead
HR + Legal
CHRO override + audit

Sync log

5 failures
TimestampConnectorRuleStrategyStatusResponse

Distributed sync architecture

Event-driven ready
Command

Publish rule

Validated against optimistic version and row-level policy.

Event

rule.published

Emitted to domain event bus with tenant scope.

Queue

Sync jobs

Connector-specific background jobs with retry policy.

SDK

Connector adapters

Novea, HM3, and HMX adapters with governed mapping.

Notify

Websocket

Live sync result pushed to approval owners.

Connector setup flow

Create or edit a connector by defining the target server, endpoint, authentication method, sync strategy, retry policy, and mapping profile.

Connector SDK pattern

Pluggable adapters
interface RegulatoryConnector {
  validate(payload): Promise<ValidationResult>
  map(rule): Promise<ConnectorPayload>
  publish(payload): Promise<SyncResult>
  rollback(version): Promise<SyncResult>
  healthCheck(): Promise<ConnectorHealth>
}
BaseConnector
  NoveaConnector
  HM3Connector
  HMXConnector

RetryPolicy
  maxAttempts: 5
  backoff: exponential
  deadLetter: enabled
TimeEntityActionPerformed byOld valueNew value
ERP systems
3
Novea, HM3, HMX
Countries
1
Indonesia only
Legal entities
47
Across 11 tenants
Employees
128k
Payroll recalculation required

Dependency chain

Medium risk
Rule

PPh21 brackets

Feeds payroll tax computation and employee payslip statutory summary.

Payroll

Monthly payroll close

Open payroll periods need recalculation preview before publication.

Report

Statutory filing

Withholding report parameters map to existing DGT report templates.

Recommended controls

AI-ready
1

Require country owner sign-off

Material employee tax impact above threshold.

2

Stage sync to non-live tenants

Validate Novea, HM3, and HMX payload compatibility.

3

Schedule rollback candidate

Keep v3.2 payload available for controlled rollback.

API rate limit budgetHealthy
82%
Per tenant and connector class
Retry queue depthWatch
143
17 dead-letter items
Websocket subscribersLive
2.7k
Approvers and integration owners
Feature flags activeControlled
26
Scoped by tenant, country, domain

Security and isolation controls

Zero-trust API boundary
Tenant

Tenant context resolver

Resolves tenant from API key, JWT claims, or connector token.

Rows

Row-level permission filter

Scopes rules by tenant, country, domain, and legal entity ownership.

Keys

API key management

Rotatable hashed keys with scopes, expiry, rate tier, and audit metadata.

Audit

Audit middleware

Captures old/new payload, actor, tenant, request id, and idempotency key.

Background job lanes

Eventual consistency
Lane
Queued
Running
Failed
Retry
DLQ
SLA
Owner
Effective publish
12
4
0
2
0
99
Core
ERP sync
88
19
5
31
17
86
Ops
Alert scan
9
2
0
0
0
98
Risk
AI monitor
34
6
1
8
1
90
AI

Configuration governance

Environment + feature flags + i18n
EnvConfig schema
DATABASE_URL, queues, storage, websocket, connector endpoints
FlagsFeature rollout
Tenant, country, role, and domain scoped flags
i18nLocalization
Labels, currencies, date formats, legal wording
LockingOptimistic version
Prevents stale edits and version conflicts
RateThrottling
Per tenant, API key, IP, and endpoint class
ConflictResolver
Overlapping effective dates and duplicate version detection

Indonesia pack

Ready

PPh21, BPJS, VAT, THR, overtime rules, ID locale, IDR currency, DGT source references.

Philippines pack

Review

SSS, PhilHealth, Pag-IBIG, TRAIN tax, PHP currency, statutory report mapping.

Malaysia pack

Ready

EPF, SOCSO, EIS, PCB tax, MYR currency, English and Malay label bundles.

Singapore pack

Ready

CPF, GST, foreign worker levy, SGD currency, IRAS and CPF source templates.

Country pack contract

SDK
CountryPack {
  metadata
  domains
  ruleTemplates
  validators
  calendars
  localization
  connectorMappings
}

Localization strategy

i18n
locales/
  id-ID.json
  en-PH.json
  ms-MY.json
  en-SG.json

formatters:
  currency
  date
  percent
  statutory labels

Domain-driven bounded contexts

DDD-ready
CoreRegulatory Rules
Aggregate root, immutable versions, effective dating
WorkflowApprovals
Approval matrix, escalation, SLA, delegation
IntegrationERP Sync
Connectors, jobs, retry, dead-letter queue
SecurityTenant Access
API keys, row permissions, rate limiting
AssuranceAudit + Alerts
Evidence, compliance scans, notification rules
ExtCountry Packs
Templates, validators, i18n, source mappings

Backend folder structure

NestJS
apps/api/src
  app.module.ts
  config/
    env.schema.ts
    feature-flags.service.ts
  common/
    auth/rbac.guard.ts
    auth/api-key.guard.ts
    auth/rate-limit.guard.ts
    tenancy/tenant-context.ts
    tenancy/tenant-isolation.interceptor.ts
    audit/audit.interceptor.ts
    events/domain-event.bus.ts
    jobs/scheduler.service.ts
    jobs/retry-queue.service.ts
    realtime/notification.gateway.ts
  modules/
    countries/
    country-packs/
    regulation-domains/
    rule-categories/
    regulatory-rules/
      application/commands/
      application/queries/
      domain/regulatory-rule.aggregate.ts
    effective-dating/
    versioning/
    approvals/
    erp-connectors/
      sdk/base-connector.ts
      adapters/hm3.connector.ts
    sync-monitoring/
    audit-trail/
    impact-analysis/
    notifications/
    api-keys/
    compliance-monitoring/
    ai-readiness/
prisma/
  schema.prisma
  seed.ts

Prisma schema excerpt

Normalized
model Country {
  id        String  @id @default(uuid())
  code      String  @unique
  name      String
  currency  String
  rules     RegulatoryRule[]
}

model RegulationDomain {
  id          String @id @default(uuid())
  code        String @unique
  name        String
  categories  RuleCategory[]
}

model RuleCategory {
  id       String @id @default(uuid())
  domainId String
  code     String
  name     String
  domain   RegulationDomain @relation(fields: [domainId], references: [id])
  rules    RegulatoryRule[]
  @@unique([domainId, code])
}

model RegulatoryRule {
  id              String   @id @default(uuid())
  tenantId        String
  countryId       String
  categoryId      String
  ruleCode        String
  ruleName        String
  description     String?
  valueType       String
  valueJson       Json
  effectiveFrom   DateTime
  effectiveTo     DateTime?
  version         String
  status          RuleStatus
  approvalStatus  ApprovalStatus
  sourceReference String?
  createdBy       String
  approvedBy      String?
  createdAt       DateTime @default(now())
  updatedAt       DateTime @updatedAt
  country         Country @relation(fields: [countryId], references: [id])
  category        RuleCategory @relation(fields: [categoryId], references: [id])
  syncLogs        SyncLog[]
  @@unique([tenantId, ruleCode, version])
  @@index([countryId, categoryId, effectiveFrom])
}

API contracts

API-first
GET    /v1/countries
POST   /v1/countries
GET    /v1/regulation-domains
GET    /v1/rule-categories?domainId=
GET    /v1/regulatory-rules
POST   /v1/regulatory-rules
GET    /v1/regulatory-rules/:id
POST   /v1/regulatory-rules/:id/versions
GET    /v1/regulatory-rules/:id/versions
POST   /v1/regulatory-rules/:id/compare
POST   /v1/regulatory-rules/:id/submit
POST   /v1/approvals/:id/approve
POST   /v1/approvals/:id/reject
GET    /v1/erp-connectors
POST   /v1/sync-jobs
POST   /v1/sync-jobs/:id/retry
GET    /v1/audit-trails
POST   /v1/impact-analysis/simulate
GET    /v1/compliance-alerts

Seed data excerpt

Sample countries
countries = [
  { code: "ID", name: "Indonesia", currency: "IDR" },
  { code: "PH", name: "Philippines", currency: "PHP" },
  { code: "MY", name: "Malaysia", currency: "MYR" },
  { code: "SG", name: "Singapore", currency: "SGD" }
]

domains = [
  { code: "PAYROLL_TAX", name: "Payroll Tax" },
  { code: "SOCIAL_SECURITY", name: "Social Security" },
  { code: "INDIRECT_TAX", name: "VAT/GST" },
  { code: "LABOR_LAW", name: "Labor Law" }
]

connectors = [
  { connectorType: "HM3", syncStrategy: "WEBHOOK" },
  { connectorType: "Novea", syncStrategy: "REST_API" },
  { connectorType: "HMX", syncStrategy: "SCHEDULED" }
]

Document parsing

Ingest gazettes, tax circulars, and ministry notices into structured candidate rule changes.

AI impact analysis

Rank affected countries, legal entities, employees, reports, and ERP mappings before approval.

Anomaly detection

Detect unusual parameter deltas, overlapping effective dates, or rates outside statutory patterns.