Security
Least privilege, approved identities, credential references, environment separation, access review, logging, incident routing, revocation.
ZoikoTime Data Migration helps qualified organizations move approved workforce records through governed source discovery, deterministic mapping, rehearsal, validation, reconciliation, controlled cutover, and evidence-preserving handover.
No silent value invention. No broadened access on failure. Human approval remains required.
Source, object, region, scale, timing, and service availability require assessment and approved terms.
.png)
Know the source. Define the contract. Rehearse the move. Reconcile the result. Approve the cutover. Preserve the evidence.
Each card describes a control we apply, not a deliverable we include. Inclusions live in approved commercial documents.
Identify accountable owners, systems of record, object meanings, authority, restrictions, and conflicts before any extraction.
Version every mapping and transformation. Unknown values stay visible instead of being guessed.
Run representative rehearsals with privacy-safe evidence and reviewable exit criteria.
Compare counts, relationships, time, policy context, approvals, corrections, and evidence, not just file delivery.
Carry forward attribution, open corrections, access boundaries, and operational ownership through handover.
Not seamless. Not one click. Not any system, all history, zero downtime, or guaranteed accuracy. Migration is assessed, not universally promised.
Workforce records carry meaning, attribution, correction rights, and evidence. Eight ways a technically successful transfer destroys all four.
Risk: The wrong system becomes authoritative by convenience.
Response - Source authority, precedence, conflict states, and human resolution.
Risk: Fields look similar but mean different things across systems or periods.
Response - Versioned object and field contracts with effective dates and transformation evidence.
Risk: Import tools silently default or discard records.
Response - Visible exceptions, no guessing, named ownership, approved disposition.
Risk: Worked time, dates, and periods shift incorrectly.
Response - Explicit temporal rules, source time zone, effective dates, boundary validation.
Risk: Migration freezes an unresolved or contested record.
Response - Correction, dispute, approval, and evidence continuity.
Risk: Sensitive data moves without a current purpose.
Response - Purpose limitation, minimization, exclusion, retention, and deletion gates.
Risk: Users gain or lose access unexpectedly.
Response - Identity mapping, least privilege, access validation, blocked fallback.
Risk: Teams accept incomplete results to meet a date.
Response - Readiness gates, go/no-go authority, accepted exceptions, rollback, stabilization.
Each object carries its own state. When a critical object is blocked, the program does not show green. No summary can average away a blocker.
Source health - authority, access, owner, version, restriction review, extraction test
Mapping status - approved, needs review, source conflict, unsupported semantic, changed since rehearsal
Validation proof - passed, failed, warning, not run, accepted exception, dataset version
Cutover readiness - authority, freeze, runbook, communications, support, rollback, evidence pack
Identity references are blocked on 6 ambiguous matches. Four of five objects are ready. The program is still not ready. There is no partial-green state.
| Category | Object | Owner | Age | Status |
|---|---|---|---|---|
| Identity | People references | Customer data owner | 9d | Blocked |
| Semantic | Break codes | Business owner | - | Accepted exception |
| Temporal | Overnight shifts, 2019 | Migration lead | 4d | Needs review |
| Structural | Duplicate keys, batch 7 | Source owner | 2d | Needs review |
| Privacy | Out-of-scope field | Privacy reviewer | 1d | Pending approval |
| Unsupported | Legacy attachment type | Migration lead | - | Unavailable |
Exception queue, synthetic. Categories are technical conditions, never judgments about workers or administrators.
This helps you prepare and helps us route responsibly. It returns a preparedness summary showing missing owners, decisions, and evidence. It never calculates a success likelihood, risk score, price, or duration.
Workforce files, schemas, credentials, API keys, screenshots, record samples, employee names, payroll values, health data, union data, disciplinary data, incident narratives, or confidential source details. This form has no file upload, by design.
A source appears here only as an approved registry record or under the neutral category "requires assessment." We do not publish a list of systems we have not verified.
| Registry | Required fields | Public treatment |
|---|---|---|
| Source system | Canonical name, version or mode, owner, objects, direction, authentication, region, limitations, status, evidence, review date. | Approved records only, or a neutral "requires assessment" category. |
| Object family | Object meaning, required fields, relationships, temporal rules, correction treatment, retention. | Named families only where currently supported. |
| History and scale | Period support, volume band, performance constraint, dependency. | Bands and constraints - never "all history". |
| Region | Data location context, transfer path, support access, restrictions. | Shown only when registry-verified. |
| Exclusion | Object, reason, alternative, owner, review date. | Exclusions are published, not omitted. |
A mapping is a reviewable artifact with an author, a reviewer, test cases, and a version — not a hidden script.
Field mapping — source and destination object and field, semantic definition, data type, required status, authority.
Code mapping — source value, destination value, unmapped behavior, owner, effective dates, version, approval.
Transformation — deterministic rule, inputs, output, null and error behavior, reversibility, test cases, evidence.
Temporal treatment — source time zone, local date, UTC where applicable, DST ambiguity, period boundary, ordering.
Identity mapping — stable identifier, matching rule, ambiguity state, merge prohibition, access consequence, approval.
Attachments — reference versus copy decision, integrity check, metadata preservation, retention, unsupported-type handling.
An unknown value stays unresolved, or maps to an approved neutral state. The system never infers attendance, approval, reason, identity, or policy outcome to fill a gap.
Any mapping change invalidates the affected rehearsal and validation evidence, and requires a re-run before cutover. Evidence does not survive the thing it was evidence for.
.png)
A finding needs a decision, not a rating. Every category below routes to a named human with a defined set of options.
| Category | Examples | Required disposition |
|---|---|---|
| Structural | Missing column, invalid type, duplicate key, broken relationship. | Correct the source or export, apply an approved transform, exclude, or block. |
| Semantic | Ambiguous code, changed meaning, undocumented field, mixed units. | Business owner decision and a versioned mapping. |
| Temporal | Missing time zone, DST ambiguity, invalid period, out-of-order event. | Approved temporal rule, correction, exclusion, or block. |
| Identity | No match, multiple matches, recycled identifier, inactive identity. | Human review. Ambiguous people are never auto-merged. |
| Policy / approval | Missing policy version, unresolved approval, disputed record. | Preserve the unresolved state and route to authorized review. |
| Privacy / security | Out-of-scope sensitive field, overbroad access, insecure transfer path. | Remove, restrict, redesign, or block until approved. |
| Correction / evidence | Open correction, missing attribution, unavailable attachment, broken evidence link. | Map, reference, exclude with approved treatment, or block. |
| Unsupported | Object, format, source version, volume, or behavior outside verified support. | Mark unavailable and route to assessment or controlled custom review. |
No composite blame score. Source quality and migration readiness are never reduced to a hidden number that ranks teams, workers, or administrators. We show findings, evidence, ownership, and gates.
Rehearsal proves repeatability and meaning before production cutover. Validation and reconciliation stay reviewable at object and rule level.
Authorized source, version, filters, checkpoint, object counts, integrity control where approved, exclusions, errors.
Schema, types, required fields, uniqueness, references, attachments, encoding, size and format boundaries.
Code meaning, units, status meaning, policy references, approval state, correction state, unsupported values.
Time zone, DST, effective dates, period boundaries, sequence, overlap, source and destination display.
Identity matches, ambiguous matches blocked, role mapping, least privilege. Denied access remains denied.
Deterministic classification boundary, policy application, neutral states, human review, worker-visible correction route.
Source attribution, extraction ID, mapping and transform version, reviewer, approval, event timeline, artifact integrity.
Expected, extracted, transformed, loaded, excluded, duplicate, failed, corrected, accepted difference, unresolved.
The same approved input and versions produce the same governed output. A re-run does not duplicate accepted records.
| Object | Expected | Extracted | Loaded | Excluded | Failed | Accepted diff. | Unresolved | State |
|---|---|---|---|---|---|---|---|---|
| Time records | 184,206 | 184,206 | 183,910 | 296 | 0 | 296 | 0 | Verified |
| Attendance | 61,044 | 61,044 | 61,044 | 0 | 0 | 0 | 0 | Verified |
| Breaks | 78,510 | 78,510 | 77,984 | 508 | 18 | 508 | 18 | Accepted exception |
| People references | 4,120 | 4,120 | 4,114 | 0 | 6 | 0 | 6 | Blocked |
| Corrections | 1,338 | 1,338 | 1,338 | 0 | 0 | 0 | 0 | Pending approval |
6 unresolved identity records block their object. They are not written as "no match" placeholders, and they do not reduce to a percentage that makes the program look complete.
Nine controls, designed before the window opens. Rollback is planned while there is still time to plan it.
| Control | Required content |
|---|---|
| Cutover scope | Exact objects, periods, entities, locations, source versions, mapping version, exclusions, accepted exceptions. |
| Freeze strategy | What freezes, who authorizes, the window only when approved, late-change handling, and communication. |
| Runbook | Ordered actions, owners, checkpoints, verification, pause and resume, escalation, rollback, evidence capture. |
| Go / no-go | Named authority, quorum or conditions, evidence summary, blockers, accepted exceptions, recorded decision. |
| Operational continuity | Source-of-truth transition, read-only period, user access, critical process continuity, support, communication. |
| Rollback | Trigger, authority, restoration point, destination handling, source reactivation, communication, post-event review. |
| Stabilization | Observation window where contractually approved, exception queue, correction routing, reconciliation refresh, support ownership. |
| Partial success | Object-level state and independence. No global green status while a critical object is blocked. |
| Closure | Final reconciliation, evidence pack, access review, staging deletion, source disposition, open items, operational acceptance. |
Continuity and cutover design depend on the source, scope, interfaces, operating model, and approved plan. Any organization promising no downtime before seeing your source landscape is guessing.
Migration touches historical records about real people. These domains hold gates, and an incident pauses movement rather than pushing through it.
No hidden productivity scoring. No covert observation. No silent value invention. No broader access on failure, under any tier or configuration.
Least privilege, approved identities, credential references, environment separation, access review, logging, incident routing, revocation.
Purpose limitation, minimization, sensitive-field inventory, region and transfer context, retention, staging deletion, rights routing.
Plain-language notice, visibility into applicable records, a correction route, human review, neutral states, and no retrospective repurposing.
WCAG 2.2 AA across the page, readiness form, tables, filters, mapping review, exception queues, approvals, and exported summaries.
Region, residency, transfer, support access, backup, and subprocessor statements appear only when registry-verified.
Pause affected movement, preserve evidence, notify approved owners. Never broaden access, retry blindly, or conceal a partial failure.
Evidence links outcome to source, mapping, validation, approval, and cutover context without exposing unnecessary workforce data.
| Evidence object | Minimum content |
|---|---|
| Source snapshot | Source ID, version, authority, owner, extraction scope, time, actor or service identity, integrity reference, restriction. |
| Mapping evidence | Mapping set and version, field contract, transformation rule and version, test cases, author, reviewer, approval, effective date. |
| Rehearsal record | Dataset reference, minimized scope, environment, run ID, versions, results, exceptions, decision, rerun lineage. |
| Validation record | Check definition and version, object, expected, actual, result, limitation, reviewer, accepted exception, evidence link. |
| Reconciliation record | Expected, extracted, loaded, excluded, failed and corrected counts, differences, owners, disposition, approval. |
| Cutover decision | Scope version, evidence summary, blockers, exceptions, authority, decision, conditions, timestamp, rollback readiness. |
| Correction lineage | Original record, migrated record, correction request, decision, changed values, attribution, downstream acknowledgement. |
| Closure pack | Final scope, reconciliation, accepted differences, open items, access review, deletion and retirement evidence, runbooks, ownership. |
| Controlled export | Purpose, requester, approver, fields, minimization, format, protection, expiry, revocation, download evidence. |
Until a formal offer exists, this is a current-state truth panel, not packages, timelines, fixed inclusions, or connector logos.
Migration acceptance depends on source authority, data quality, scope, mapping decisions, validation, and required approvals. Pricing, entitlement, timeline, responsibilities, and support are defined in approved commercial and service documents.
Already a customer? Sign in to request migration support, review an open engagement, report an issue, or request a scope change.
Review your source landscape, scope, ownership, mapping needs, validation expectations, cutover requirements, and evidence obligations with an enterprise specialist.
.png)