INNOVA Global Mobility Platform

Source: MVP Requirements Brief v0.1 March 2026 Gallagher GMS
6
MVP Epics
35
P0 Requirements
14
Blocking Questions
63
Linear Tickets
34
MVP Tickets
Epic Breakdown
LDO-11 · General
Platform Foundation & Role-Based Access Control
Establish the secure, multi-tenant platform base with layered RBAC, audit trail, SSO, MFA, data residency, retention, and configurable policy templates so every downstream capability sits on a controlled and flexible foundation. View STOA Scenario →
14 tickets 9 MVP
Primary Users
System Admin
Configures the platform, manages users and access, maintains policy templates
Mobility Coordinator
Primary day-to-day user — initiates cases, manages workflows, uses policy templates
HR Manager
Views and approves assignments, accesses employee data within their scope
Finance / Approver
Reviews cost estimates and approves assignments, read-only on case data
Vendor / Provider
Updates only assigned provider screens or milestones where portal access is enabled
IT / Security
Manages SSO configuration, reviews audit logs, enforces compliance standards
P0 Requirements — Must Have for Launch
  • P0
    RBAC — Layered Role Families
    Platform supports system, client/tenant, consultant, finance, assignee, and optional vendor/provider access layers. Each role has a defined permission set, cannot self-escalate, and must be scoped by tenant, client, case, provider screen, or assignee as appropriate.
  • P0
    Policy Template Library
    Admins and coordinators can create, edit, duplicate and version-control policy templates. Each template defines entitlements by assignment type and triggers automated cost calculation.
  • P0
    Immutable Audit Log
    Every sensitive action (login, data view, record edit, export, permission change, provider update, deletion/retention event) is logged with timestamp, user ID, action type, affected record, tenant, and before/after state. Logs cannot be edited or deleted. Exportable for compliance reporting.
  • P0
    SSO / OAuth2
    Platform integrates with corporate identity providers via SAML 2.0 / OAuth2. Failed SSO attempts are logged. Coordinator can view which users are SSO-authenticated vs. password-based.
  • P0
    Multi-Factor Authentication
    MFA enforced for all user roles. Supports authenticator apps and SMS. Can be mandated at organisation level by admin.
  • P0
    Multi-Entity Support
    Platform supports multiple client organisations and legal entities in a single instance with full data segregation, region-aware residency metadata, and role-scoped API access. An admin in Organisation A cannot access Organisation B data.
P1 Requirements — High Priority Fast-Follow
  • P1
    Bulk User Import via CSV
    Assign roles and entities in bulk rather than one-by-one.
  • P1
    Role Assignment by Organisational Group
    All members of a team inherit a default role.
  • P1
    Configurable Notification Preferences
    Each role defaults to relevant alerts, configurable by admin.
  • P1
    Session Timeout Configuration
    Admin can set inactivity timeout per security policy.
Guardrails — Must Not Happen
Must Not Happen
Cross-Tenant Data Leakage
An admin or user in Organisation A must never be able to access, view, export, or infer data belonging to Organisation B. Data segregation must be enforced at the query, API, and UI layer.
Must Not Happen
Role Self-Escalation
No user may escalate their own role permissions. A Coordinator cannot grant themselves Admin access. Role changes require an existing Admin and must be logged.
Open Questions — Blocking
Open Question · Owner: Gallagher IT
Which identity providers must be supported on day one?
Azure AD, Okta, Google Workspace? This is a blocking question that affects SSO implementation scope.
Open Question · Owner: Legal / Compliance
Which regulatory frameworks must the audit log satisfy?
GDPR, ISO 27001, SOC 2? Determines log retention, format, and export requirements.
Open Question · Owner: Product
Which vendor and assignee portal roles are in MVP?
Should vendor/provider users and assignee portal users be included in the first release, and if so which screens, tasks, and assignment data can they access?
Open Question · Owner: Legal / IT
Audit log data retention policy?
What is the required data retention policy for audit logs? Drives storage architecture and compliance.
Success Metrics
Metric Target Measurement Timeline
New user onboarding time < 15 minutes from invite to correct access Coordinator-reported survey 3 months
Unauthorised access incidents 0 incidents in first 6 months Audit log + security incident log Monthly, 6 months
Policy template adoption 100% of new assignments use platform template % cases with template applied 6 months
SSO adoption > 90% via SSO within 60 days User management dashboard 60 days
Linear Tickets — MVP First
LDO-11
UrgentMVP
General — Core Platform & Authentication
LDO-31
UrgentMVP
Team Visibility with Permission-Based Access Controls
LDO-55
UrgentMVP
Tiered Login with RBAC and Assignable Role Profiles
LDO-56
UrgentMVP
Customisable Client Branding — Logos, Colours and Visual Identity
LDO-57
UrgentMVP
Configurable Home Dashboard with Core Widgets
LDO-58
UrgentMVP
Case Overview Page — Status, Priority and Task Lists
LDO-59
UrgentMVP
Notes and Documents Widget on Case and Dashboard Views
LDO-61
UrgentMVP
PII Security Measures and Data Protection Controls
LDO-60
HighMVP
User-Friendly Navigation Guidance and Onboarding Help
LDO-16 · Case Initiation
Assignment Lifecycle Management
Enable coordinators to initiate, configure, route, approve, and track global mobility assignments through a structured workflow — from case creation through policy application, approvals, and status tracking.
28 tickets 16 MVP
P0 Requirements
  • P0
    Case Creation Workflow
    Coordinator creates a new case with assignee details, selects assignment type (short-term, long-term, permanent transfer), applies policy template, and the system generates an initial entitlement package and cost estimate.
  • P0
    Configurable Approval Chains
    Cases follow a configurable approval chain: coordinator submits, HR reviews, finance approves costs. Each step has configurable rules, escalation timeouts, and notification triggers.
  • P0
    Assignment Status Lifecycle
    Each case moves through defined states: Draft, Pending Approval, Approved, In Progress, Completed, Cancelled. State transitions are logged. Real-time status visible on coordinator dashboard.
  • P0
    Policy Template Application
    When a policy template is applied to a case, entitlements and cost parameters are pre-populated. Templates are versioned so historical cases reference the policy version in effect at creation.
Guardrails
Must Not Happen
Case Progresses Without Required Approvals
An assignment must not advance past approval gates without the required sign-offs. The system must enforce the approval chain and block progression if approvals are missing.
Risks
Risk
Approval Bottleneck Delays Assignments
If approval chains are too rigid or approvers are unavailable, cases stall. Need configurable escalation rules and delegation so the process does not block on a single person.
Open Questions
Open Question · Owner: Product / Operations
What assignment types are in scope for MVP?
Short-term, long-term, permanent transfer, commuter, business travel? Each type drives different policy templates and entitlement packages.
LDO-18 · Information Sharing
Data Exchange & Visibility
Provide secure, role-scoped data sharing between coordinators, HR, finance, and assignees so that each stakeholder sees exactly the assignment information they need without manual distribution.
7 tickets 7 MVP
P0 Requirements
  • P0
    Role-Scoped Data Visibility
    RBAC determines what data each user can see. Documents, case fields, and reports are filtered by role and organisational scope. No manual access management needed per case.
  • P0
    Secure Document Sharing with Version Control
    Documents attached to cases are versioned, access-controlled by role, and downloadable by authorised users. Upload triggers notification to relevant stakeholders. All document access is logged.
  • P0
    Real-Time Assignment Visibility
    Each stakeholder sees up-to-date assignment status, relevant documents, and action items within their scope. Dashboard widgets show assignment counts, pending actions, and recent updates.
Guardrails
Must Not Happen
Unauthorised Data Exposure via Reports or Exports
Reports and data exports must respect RBAC. A user cannot export data outside their role scope. Export actions are logged in the audit trail.
Risks
Risk
Data Sync Lag Creates Stale Views
If data updates are not real-time, stakeholders may act on outdated information. Need clear update timestamps and refresh indicators.
Open Questions
Open Question · Owner: Product / Engineering
What data sharing integrations are needed for MVP?
Email notifications, in-platform messaging, external HRIS sync? Need to define the boundary between in-platform visibility and external data exchange.
LDO-19 · Cost Estimate & Balance Sheet
Financial Modelling & Cost Estimation
Generate approval-ready cost estimates, balance sheets, what-if scenarios, budget-vs-actual views, expense/payroll outputs, and total-cost reporting using refreshed source data and human validation. View STOA Scenario →
1 ticket 1 MVP
P0 Requirements
  • P0
    Approval-Ready Cost Estimate Generation
    When a move or what-if scenario is requested, the system assembles an itemised cost estimate using current rates, policy allowances, relocation, immigration, compensation, housing, vendor, and tax-engine inputs. A Gallagher analyst or case manager validates the output before client release.
  • P0
    Budget, Actuals, and Total-Cost Reporting
    System compares approved estimates with actual payroll, expense, vendor, relocation, and assignment costs over time. Total-cost reporting gives clients the full programme view, not just the original estimate.
Guardrails
Must Not Happen
AI-Mined or Manual Data Released Without Validation
No cost estimate, feasibility input, payroll-impacting value, or reporting output may be released without source freshness, versioning, and human validation.
Risks
Risk
Moving Costs and Policy Updates Drift from the Baseline
Shipping, vendor, compensation, exchange rate, policy allowance, and payroll-related values can change throughout an assignment. Without versioning and alerts, the approved estimate can drift away from actuals.
Decisions
Decision
Cost Estimates Support Approval, Then Actuals Tracking
The estimate helps the client budget and approve or cancel the move. If approved, the same baseline supports provider initiation, actuals tracking, balance sheet, payroll/expense outputs, and total-cost reporting.
Open Questions
Open Question · Owner: Finance / Product
How should what-if estimates be packaged?
Confirm who can run chargeable what-if estimates, how long scenarios persist, how pricing works, and how a what-if converts into a formal cost estimate and service initiation.
LDO-17 · Employee Touchpoints
Assignee Experience & Touchpoints
Give assignees a self-service portal to view their assignment status, access documents, complete tasks, and receive notifications throughout their mobility journey. View STOA Scenario →
1 ticket 1 MVP
P0 Requirements
  • P0
    Assignee Self-Service Portal
    Assignee authenticates via SSO, sees their assignment dashboard with current status, pending tasks (visa application, housing selection, tax briefing), documents to review, and key dates.
  • P0
    Task Completion and Document Upload
    Assignee can mark tasks as complete, upload required documents, view their entitlement package, and see assignment timeline. Notifications alert them to new tasks or status changes.
  • P0
    Coordinator-Assignee Communication
    In-platform messaging between coordinator and assignee. Messages attached to the case record. Assignee can ask questions without email. Coordinator sees all interactions in one place.
Guardrails
Must Not Happen
Assignee Sees Other Assignees' Data
An assignee must only see their own assignment data. They must never see other employees' assignments, cost estimates, or documents, even within the same organisation.
Risks
Risk
Low Assignee Adoption of Self-Service Portal
If the portal is not intuitive or mobile-friendly, assignees will default to email and phone, defeating the purpose. Need strong onboarding UX and mobile-responsive design.
Open Questions
Open Question · Owner: Product / Engineering
Mobile app or responsive web for assignee portal?
Native mobile app vs. responsive web portal for MVP? Affects development scope, timeline, and assignee experience quality.
NEW · GMS Call 30 Apr 2026
AI Integration for Data Mining, Feasibility & Employee Support
Deploy AI mining agents and employee-facing assistance to collect current source data, support cost estimates and feasibility studies, detect issues, and answer basic employee questions while escalating sensitive work to humans. View STOA Scenario →
63/100 13 cards
Competitive Landscape
Strategic Decision
Mining Agents as Competitive Differentiator
The GMS team identified external mining agents as a strategic priority based on competitive pressure from The Cozm and AIRINC Navi. INNOVA needs comparable or superior automated data capabilities to compete.
The Cozm
AI-first compliance automation. Files EU Posted Worker Notifications and A1 certificates in under 60 seconds. 28-country coverage, 25+ system integrations. Clients include Cisco. Products: Cozm Travel (compliance), Cozm Unity (operations), Cozm Nemo (talent planning — coming soon).
AIRINC Navi
Mobility decision platform with 70+ years of benchmarked data. Cost estimates, scenario planning, policy comparison, compensation management. Pre-loaded with researched allowances and policies. Global offices in Boston, Brussels, London, Hong Kong.
P0 Requirements
  • P0
    AI Mining Agent Infrastructure
    Agents collect, structure, and timestamp source data for cost estimates, feasibility studies, policy monitoring, immigration requirements, housing costs, posted worker directives, and other country-pair inputs. Runs on schedule or on demand.
  • P0
    Structured, Validated Data Output
    Mining agents return structured outputs with source URLs, collection timestamps, confidence scores, and validation status. Human validation is required before mined data affects client-facing estimates, compliance considerations, payroll, or reporting.
  • P0
    Employee AI Triage and Escalation
    AI can answer approved basic employee questions about process, status, documents, and appointments, then escalate tax, legal, immigration, compensation, or uncertain questions to the human case owner with context.
Guardrails
Must Not Happen
Unverified AI Output Used in High-Stakes Decisions
Mined data and AI responses must not flow into financial calculations, compliance decisions, payroll-impacting outputs, or employee legal/financial guidance without confidence, provenance, and human validation where required.
Risks
Risk
Source Websites Change Structure or Block Scrapers
Government portals frequently change their HTML structure or implement bot protection. Agents need resilient parsing, fallback sources, and alerting when a source becomes unreachable. The Cozm has 25+ integrations already.
Risk
Regulatory Data Accuracy Has Legal Consequences
Incorrect tax rates or missed posted worker obligations could result in fines, penalties, or compliance failures. Bad external data feeds compound across all assignments. Need clear provenance and human-in-the-loop for critical regulatory data.
Open Questions — Blocking
Open Question · Owner: Product / Engineering / Partnerships
Build vs. buy vs. partner for mining agents?
Build custom agents in-house, license from a data provider, or partner with an existing player like AIRINC? The Cozm has 25+ integrations and 35+ years combined experience. What is the fastest path to parity?
Open Question · Owner: GMS Operations
Which data sources are highest priority for MVP?
Tax rates, cost-of-living, immigration requirements, EU Posted Worker Directives, housing? Need to rank by frequency of coordinator lookup and impact on cost estimate accuracy.

Recommended Next Steps

  1. Validate all problem statements with Gallagher's GMS operations team — confirm that the inferred pain points match reality and adjust where needed
  2. Resolve all 16 blocking open questions across the six Epics — these represent genuine build blockers
  3. Prioritise the P0 requirements list — if everything is P0, nothing is P0; be deliberate about what the absolute minimum viable launch looks like
  4. Assign Epic owners — each Epic should have a named accountable owner on both the Gallagher and product sides
  5. Establish the governance forum — a regular forum with decision-making authority is needed to keep requirements unblocked as build begins