Nova Generation Technologies  ·  Sprint Uganda Limited {{ statusLabel }}
ODPP Complaints Management & File Lifecycle System — Technical & Commercial Proposal JLOS House, Katalima Road, Naguru, Kampala

Technical & Commercial Proposal

ODPP Complaints Management & File Lifecycle System

An immutable, CRB-anchored digital platform that tracks public and internal complaints, enforces statutory turnaround times, and preserves a cryptographic audit trail behind every prosecutorial directive.

Prepared for The Director of Public Prosecutions and the ICT Directorate, Office of the DPP, JLOS House, Katalima Road, Naguru, Kampala
Submitted by Nova Generation Technologies, in partnership with Sprint Uganda Limited
Engagement 18-day Proof of Concept, followed by a 13-week production build and national-readiness handover
Companion documents Complaint Flow Algorithm · Project Schedule (ODPP) · Delivery Schedule (Internal)

1. Executive summary

A complaint against a prosecutorial decision is, today, a piece of paper. It moves by hand from a public desk to a Resident State Attorney, and from there — if it moves at all — to a Regional Officer. Nothing in that chain records when the file arrived, who held it, how long they held it, or why the outcome was what it was. When a citizen asks for the status of their petition, there is no system that can answer.

We propose to close that gap with a platform anchored on the one identifier that already binds every case in the justice chain: the Police CRB number. Every complaint received — through the public web portal, the toll-free line, the walk-in desk at JLOS House, or by email — is bound to a CRB reference at the moment of intake, triaged automatically by category, routed to the officer with statutory authority to act, and monitored against a hard SLA clock. Where the clock expires, the file escalates without anyone having to ask for it.

Three outcomes define success: no complaint is lost, no statutory deadline passes unnoticed, and every directive issued by the Directorate is permanently attributable to the officer who issued it.

This proposal opens with a tightly scoped 18-day Proof of Concept run entirely from a single point of contact inside the Directorate. It requires no broad access to sensitive files and no disruption to current operations. At its close, the DPP sees a working system handling a real escalation scenario end to end, on an offline demonstration stack, with no dependency on venue connectivity.

2. The operational problem

Current condition Consequence System response
Physical docket movement is unrecorded Files go missing with no accountable custodian; recovery is informal and undocumented Append-only File Movement Ledger records every hand-off cryptographically
No SLA clock on petitions A complaint can sit at station level indefinitely without breaching any visible rule Background monitors auto-escalate on expiry of the {{ slaDays }}-day window
Conduct complaints route through the officer complained against Structural conflict of interest; suppression is possible and untraceable Conduct category bypasses the station entirely and lands at HQ Inspections
Dockets exist only on paper No search across charge sheets, perusal minutes or suspect names OCR pipeline indexes scanned dockets for full-text retrieval
Complainants receive no reference Repeat visits and calls to the Directorate simply to ask "where is my file" Unique tracking code issued at intake, checkable without an account

3. The four subsystems

Subsystem 01

Multi-Channel Ingestion Gateway

A public web form, a toll-free call-centre capture console, an internal desk intake for paper petitions, and a monitored email inbox — all four converge on one intake schema. Every submission is bound to a CRB reference and returned to the complainant as a single tracking code. Where a citizen has no CRB number, the intake officer resolves it against the station ledger before the record can leave triage.

Subsystem 02

Automated Escalation Matrix

A state machine enforcing the statutory hierarchy: Resident State Attorney, then Regional Officer, then the DPP Executive Office at JLOS House. Escalation is time-driven, not discretionary. Conduct complaints are exempted from the station tier entirely and route straight to the Directorate of Inspections & Quality Assurance. Each transition is written to the ledger with its trigger — expiry, dissatisfaction, or direct recall.

Subsystem 03

Docket Digitization Engine

An asynchronous queue accepting multi-page scans of dockets and petition letters. Optical character recognition extracts text and indexes CRB references, suspect names, charge particulars and perusal minutes for full-text search. Scanning does not block the officer: the file is queued, the officer moves on, and the extracted index appears against the record when processing completes.

Subsystem 04

Immutable Movement Ledger

An append-only table recording every physical docket location change and every administrative order. Entries cannot be edited or deleted — a correction is itself a new entry. Each row is chained to its predecessor, so any tampering with the history is detectable. This is the evidentiary backbone of the platform and the reason an audit of any complaint can be reconstructed years later.

4. How a complaint moves

The full decision logic is set out in the companion document, Complaint Flow Algorithm. In summary:

  1. Ingestion and anchor registration. The complaint enters through one of four channels and binds immediately to crb_number. A tracking code is issued to the complainant.
  2. Category triage. Conduct complaints — misconduct, bribery, file suppression — route directly to HQ Inspections, bypassing the local station to prevent tampering. Process-decision complaints — disagreement with a sanction or a withdrawal — route to the local Resident State Attorney for re-examination of the docket.
  3. SLA monitoring. Background tasks track every open complaint. Where the RSA has not resolved the petition within the {{ slaDays }}-day window, the state advances to ESCALATED_REGIONAL automatically.
  4. Regional review. The Regional Officer either issues a directive and closes, or — on a second expiry or a recorded dissatisfaction — the matter escalates to the DPP Executive Office.
  5. Recall and binding directive. The DPP issues a File Recall Order. The order is written to the ledger and the master docket status updates to REINSTATED or SANCTIONED.

5. Engagement model

The engagement is deliberately front-loaded with proof. We do not ask the Directorate to commit to a production programme on the strength of a document. We ask for eighteen days and a single point of contact.

Window Stage Tangible output
Days 1–3 SPOC alignment & discovery scope 2-page Scope Alignment Document; complete Data Schema Draft; Data Flow Diagram and Domain Field Dictionary
Days 4–8 Core database & escalation engine CRB-anchored data models, routing logic for both complaint categories, immutable audit ledger
Days 9–13 Ingestion, OCR & public gateway Document scanning pipeline, text extraction and indexing, public submission interface, RSA triage console
Days 14–16 Lifecycle stress testing & RBAC Full simulated escalation from station to DPP directive; role-based access controls locked down and tested
Days 17–18 Presentation preparation Seeded regional dataset, offline-capable demonstration stack, rehearsed walkthrough for the DPP
Weeks 4–13 Production build & handover Hardened platform, User Acceptance Testing with ICT and Inspections, pilot deployment, training and operations handover

The Days 1–3 execution model is worth stating plainly, because it protects both parties. We do not enter a high-security government facility asking to audit registers. All access is mediated by the SPOC — the officer who invited us in — against a scope agreed in writing before any work begins. At the 72-hour mark the Directorate holds two finished documents it can circulate internally, whether or not the engagement proceeds.

6. Security & access control

Role-based access control is not a configuration detail here — it is a substantive safeguard. An officer who is the subject of an active conduct complaint cannot view or edit the associated investigation file. That rule is enforced at the data layer, not the interface, so it cannot be circumvented by a direct query or an exported report.

Beyond conflict isolation: all complaint data remains within infrastructure controlled by the Directorate; the demonstration stack is fully offline and isolated; personally identifying complainant details are visible only to intake and the assigned handling officer; and every read of a sensitive record is logged alongside every write. The full-text search index inherits the same access boundaries as the records it points at.

7. What we ask of the Directorate

Four artefacts, requested through the SPOC on Day 1. Nothing else is required of ODPP staff during the Proof of Concept.

Artefact Why it is needed
Standard complaint intake schema The exact data fields recorded today when a citizen or attorney lodges a petition, so the digital form matches existing practice rather than replacing it
Three redacted forms A Complaint Lodgement Form, a Perusal Minute Sheet and a File Recall Order — the templates the system must reproduce faithfully
Sanitized sample docket A redacted multi-page file — charge sheet, Police Form 3, perusal sheet — to calibrate and test the OCR extraction pipeline against real documents
Nomenclature & station directory CRB and SD reference formats, plus the official naming codes and hierarchy for the 18 Regional Offices and their attached RSA court stations
Target service delivery SLAs Official turnaround timelines — the maximum days for RSA perusal before escalation triggers. Our working assumption of {{ slaDays }} days is a placeholder pending confirmation

8. Team & equipment

Human resources

1 × Solution Architect / Lead Presenter
SPOC engagement, domain modelling, architecture, executive presentation
2 × Full-Stack Developers
Backend models, escalation state machine, OCR pipeline, frontend interfaces
1 × Legal / Domain Advisor
Legal terminology, statutory SLA windows, procedural compliance review

Technical equipment

2 × High-performance workstations
Local development, database hosting, asynchronous worker execution
1 × Portable high-speed document scanner
Live paper-to-OCR demonstration during the presentation
1 × Staging server environment
Fully isolated, offline-capable demonstration stack

9. Assumptions & dependencies

  • A named SPOC is confirmed before Day 1 and is available for a 30-minute structured interview within the first 72 hours.
  • The statutory SLA window is confirmed by the Directorate; the {{ slaDays }}-day figure used throughout is a working assumption.
  • The Proof of Concept runs on our own equipment and requires no ODPP network access, credentials, or production data.
  • Sample dockets are provided redacted. No unredacted case material is handled at any point during the PoC.
  • Production hosting location — on-premises at JLOS House or within government cloud — is a decision for the ICT Directorate and is priced separately.

10. Approval

Countersignature below constitutes agreement to the scope, engagement model and access arrangements set out in this document, and authorises commencement of the Days 1–3 discovery window.

For the Office of the Director of Public Prosecutions

Name · Title · Date

For Nova Generation Technologies & Sprint Uganda Limited

Name · Title · Date