ePRO × CitiPark InforceMate
Revision 2026-09-10 · Updated 10 September 2026 · Reflects feedback of 2 and 9 September
Partner integration status: not released
The flat feed and 2–5 minute polling approach are accepted in principle, subject to the requested clarifications. The read endpoint, closure lookup and acknowledgement interface below are proposed contracts. Endpoint availability and credentials will be confirmed separately before integration begins.
Still to agree: closure delivery, acknowledgement and notice handoff, rule/tariff context, evidence arrangements, and the named test site. Examples are illustrative.
This Stage One workflow concerns sites using physical officer attendance and an affixed notice. The entry observation starts the clock. ePRO evaluates presence, applicable rules and session, permit or whitelist coverage. An opportunity may open after the entry grace without valid cover, or when the applicable maximum stay is exceeded.
Getapark
Parking operator. Operates the car park and provides the parking platform; engages its enforcement division, Enforcify, to provide enforcement.
Enforcify
Enforcement division. Uses ePRO and enforcifyPRO to deliver its enforcement service.
ePRO
Rules and integration engine, and companion app to enforcifyPRO. Manages location rules, operating hours, camera and parking-platform/meter integrations, sessions, permits and whitelists. Evaluates events and coverage against those rules to identify exceptions and violations.
enforcifyPRO
Notice issuance and lifecycle platform. Accepts violations through its API and already supports both retrospective ticket-by-mail and affixed-notice workflows, including review, correspondence, payments, appeals and debt collection.
CitiPark / InforceMate
Field enforcement partner and application. Supports the officer's verification, field evidence and notice issuance. CitiPark's issuance/lifecycle system can manage the resulting notice; the lifecycle platform is agreed for each deployment.
An opportunity records current potential actionability. The officer remains responsible for verifying the plate, presence and circumstances before issuance. An exit observation closes the opportunity to attend and also provides departure evidence and observed stay duration. Departure does not itself cancel a notice already issued.
ePRO is the proposed integration point with CitiPark. Its opportunity interface can support different operators and enforcement providers; using it does not require every deployment to use enforcifyPRO.
InforceMate handles the officer's verification and field issuance. The subsequent ticket lifecycle belongs to the system nominated for that deployment.
CitiPark deployments
The field-issued notice can pass into CitiPark's own issuance and lifecycle system. ePRO receives the agreed opportunity outcome and notice reference for correlation.
Getapark / Enforcify deployments
Enforcify will likely use enforcifyPRO for the subsequent lifecycle, although CitiPark's system remains an option. The destination and handoff are agreed before the test.
Two related return requirements
Opportunity acknowledgement: records what the officer observed or did, correlated by opportunity_ref. It updates actionability where appropriate.
Issued-notice handoff: carries the notice reference, issuance details, applicable rule and field evidence needed by the nominated lifecycle platform. A notice_issued acknowledgement alone is not that complete handoff.
enforcifyPRO already accepts both retrospective and affixed-notice workflows through its API. For an InforceMate notice already issued and affixed, the integration must send the information required by that existing affixed flow, including the field notice reference, so enforcifyPRO continues the correct lifecycle. The remaining work is to agree and implement the CitiPark-to-API mapping and transfer route; a new affixed lifecycle capability is not required in enforcifyPRO.
CitiPark's field enforcement decision and the choice of downstream lifecycle platform are separate responsibilities. Camera evidence, officer observations and the issued notice must remain linked whichever lifecycle platform is selected.
Vehicle enters
The fixed camera captures the plate, entry timestamp and available imagery. ePRO establishes the initial observation and parking session.
Rules and cover are evaluated
ePRO evaluates applicable location rules and operating hours together with session, permit and whitelist information. The entry grace gives the driver time to pay or be registered.
Opportunity opens
Once the applicable rule conditions are met, ePRO exposes a potential opportunity with its reference, site, plate, entry time and reason: no valid cover or maximum stay exceeded.
Officer verifies
InforceMate presents the information to the officer. The arrival scan is an officer verification observation. Time since entry is elapsed time on site; it does not establish continuous stationary time in a particular bay.
Officer acts and records the outcome
The officer confirms the circumstances, captures field evidence and decides the appropriate action. Where a notice is issued, it is printed and affixed, with supporting evidence. Other observations or outcomes are also returned.
State and lifecycle are updated
ePRO records the acknowledgement and closes actionability where appropriate. An exit or qualifying cover can also close the opportunity. Existing officer observations remain linked. Issued-notice details pass to the nominated lifecycle system.
Responsibility boundary
ePRO evaluates rules, integrations and opportunity state. InforceMate supports field verification, attendance decisions, officer allocation, field evidence and issuance. Subsequent correspondence, payments, appeals and recovery belong to the nominated lifecycle platform.
Later payment or a permit closes an opportunity only where it resolves the applicable rule exception. It does not automatically resolve a maximum-stay issue or cancel an already-issued notice.
Entry observation and applicable rules, operating hours and coverage establish a potential opportunity, including no-cover and maximum-stay cases.
The feed carries the reference, timing, rule context and available evidence. InforceMate supports the field workflow.
The officer verifies the vehicle and circumstances, records evidence and takes the appropriate action.
The acknowledgement is correlated to the opportunity. Observations and terminal outcomes have explicit, different effects on actionability.
Where a notice is issued, the agreed notice/evidence handoff reaches CitiPark's system or enforcifyPRO, with the existing field notice reference preserved.
Closure and officer outcome
Closure records why actionability ended. Officer observations and outcomes record what happened in the field. A vehicle exit closes actionability; any observations or outcomes already recorded remain associated with the opportunity.
An attended observation alone does not close the opportunity. A notice-issued outcome must preserve the existing notice and its subsequent lifecycle. Later exit imagery may supplement that evidence; retrieval after closure is part of the proposed evidence contract.
Stage One is a single-site proof of concept. The current preparation uses shadow mode; POC-derived records must not enter the live enforcement mailhouse. Before field testing, both teams will agree the test site's rules, who attends, how test issuance is handled and which lifecycle environment receives the outcome.
Accepted in principle
Flat opportunity feed, a single-site POC and polling every 2–5 minutes, subject to CitiPark's requested clarifications.
Implemented internally
Opportunity state model, coverage sweep, exit-closure logic and camera-evidence fields. These form the ePRO foundation for the integration.
Proposed for agreement
Explicit closure lookup, acknowledgement semantics and notice handoff, rule/tariff context, evidence access and the lifecycle destination.
Not released to CitiPark
Partner read/lookup/acknowledgement interfaces and site-scoped credentials. Availability will be stated explicitly when issued.
Later phases
Open/close webhooks, richer routing and zone information, expanded status handling and potential vehicle-mounted LPR integration.
Internal capability and partner availability are tracked separately. A proposed response example does not indicate that an endpoint or the complete field workflow is already available. Credentials and the agreed test-site configuration are supplied separately.
Discussion draft — endpoints not released
All examples below are synthetic proposals, including field names added for the September feedback. Required fields, routes and validation behaviour are to be confirmed together. Null tariff and maximum-stay values in the example are illustrative, not the agreed test-site rules.
/functions/apiOpenOpportunitiesProposed authentication: a CitiPark-specific X-Api-Key scoped to the agreed site. Poll every 2–5 minutes. A successful complete response represents current open opportunities for that scope. generated_at is response time; it does not itself reconfirm cover or physical presence.
Disappearance from a successful complete snapshot means the item is no longer listed as open. Obtain its explicit closure status using the proposed lookup below. A failed, partial or unauthorised response must not be treated as an empty snapshot.
opportunity_refRequired. Stable identifier for the life of the opportunity; links reads, officer observations and the notice handoff.
site_ref / plateRequired. Anonymised site reference and camera-read plate. The real test-site mapping is supplied separately.
entry_timestampRequired. Entry observation, UTC ISO 8601. Derive elapsed time on site from this value.
reasonRequired. no_session_or_permit or max_duration_exceeded; the officer verifies enforceability.
opened_atRequired. Time the opportunity record opened, UTC. May follow the exact eligibility threshold because evaluation is periodic.
last_checked_atProposed meaning: last successful rules/coverage recheck, UTC. It must not be advanced merely because a lookup was attempted. Uncertain or stale records must be distinguishable; the delivery behaviour remains to be agreed.
rule_contextProposed addition. Rule reference/version, applicable operating-hours context, entry grace and maximum stay. Use the rules applicable to the entry observation. Tariff information or a tariff reference is to be agreed.
entry_image_url / entry_full_image_urlNullable when an image was not captured. Proposed signed access with expiry metadata. Signing, access renewal and retention arrangements must be confirmed before release.
{
"generated_at": "2026-09-10T09:00:00Z",
"open_count": 1,
"opportunities": [
{
"opportunity_ref": "EO-DEMO-001",
"site_ref": "SITE-A",
"plate": "TEST001",
"entry_timestamp": "2026-09-10T08:40:00Z",
"reason": "no_session_or_permit",
"opened_at": "2026-09-10T08:52:00Z",
"last_checked_at": "2026-09-10T08:57:00Z",
"rule_context": {
"rule_ref": "DEMO-RULE-1",
"rule_version": "1",
"operating_hours_ref": "DEMO-HOURS-1",
"entry_grace_minutes": 10,
"max_stay_minutes": null,
"tariff_ref": null
},
"entry_image_url": "https://example.invalid/evidence/entry-crop",
"entry_full_image_url": null,
"entry_image_expires_at": "2026-09-10T09:15:00Z"
}
]
}Proposed Stage One approach: keep the open snapshot and add a lookup by known opportunity references, including closed opportunities. This supplies the reason and retained officer outcome without requiring webhooks. The route, retention window and treatment of unavailable references are still to be agreed.
Illustrative request
{
"opportunity_refs": [
"EO-DEMO-001"
]
}Illustrative response — attended, then vehicle exited
{
"opportunities": [
{
"opportunity_ref": "EO-DEMO-001",
"status": "closed",
"closed_at": "2026-09-10T09:04:00Z",
"closure_reason": "vehicle_exited",
"last_officer_outcome": {
"status": "attended",
"observed_at": "2026-09-10T09:02:00Z"
},
"exit_timestamp": "2026-09-10T09:04:00Z",
"exit_image_url": "https://example.invalid/evidence/exit-crop"
}
]
}Proposed closure values: vehicle_exited, now_covered, notice_issued, session_orphaned and manually_closed. now_covered groups qualifying payment, permit or whitelist cover; confirm whether a separate coverage subtype is needed for the audit trail. Map officer dismissal outcomes explicitly before release. Manual closure must remain distinguishable from a camera-observed exit.
Closed records retain prior observations. Later outcomes and exit evidence remain retrievable under the same opportunity reference. Agree how late acknowledgements are reconciled with an existing closure, using observation time rather than arrival order.
CitiPark proposed these five statuses. The transition descriptions below are ePRO's proposed interpretation for agreement; they are not released behaviour.
attendedObservation only; proposed to leave actionability open until a terminal outcome or another closure event.
vehicle_not_foundProposed to close actionability and retain this outcome. Establish the cause separately; departure after the last update is possible.
notice_issuedProposed to close as notice_issued and retain the notice reference. The complete notice handoff is tracked separately.
not_enforceableProposed to close actionability and retain the officer's reason. Detailed closure mapping to be agreed.
plate_mismatchProposed to close actionability and retain the observed discrepancy. It is feedback for review, not an automatic attribution of detection error.
Proposed required fields: acknowledgement_ref, opportunity_ref, status and observed_at. notice_ref is additionally required for notice_issued. Notes and field evidence references are optional in the acknowledgement; the full issuance/evidence requirements belong to the nominated lifecycle API's notice handoff.
Illustrative request — separate issuance example
{
"acknowledgement_ref": "ACK-DEMO-001",
"opportunity_ref": "EO-DEMO-001",
"status": "notice_issued",
"observed_at": "2026-09-10T09:02:00Z",
"notice_ref": "NOTICE-DEMO-001",
"notes": "Officer verified the vehicle and affixed the notice.",
"field_evidence_refs": [
"FIELD-EVIDENCE-DEMO-001"
]
}Illustrative acknowledgement response
{
"acknowledgement_ref": "ACK-DEMO-001",
"opportunity_ref": "EO-DEMO-001",
"accepted": true,
"opportunity_status": "closed",
"closure_reason": "notice_issued",
"notice_handoff_status": "pending"
}Proposed retry contract: preserve acknowledgement_ref for retries of the same observation. Repeating identical content returns the existing result; conflicting content under that reference is rejected. Each later observation uses a new acknowledgement_ref while preserving opportunity_ref. Acknowledgement acceptance does not prove completion of the separate notice handoff.
Agree signed-URL expiry, renewal, evidence retention and permission to retain external copies. Entry and later exit imagery must be accessible to the authorised lifecycle owner after opportunity closure, within those agreed rules. Missing imagery must be represented explicitly, not replaced by a claim that a full evidence bundle exists.
For enforcifyPRO, use its existing affixed-notice API flow with the required notice and evidence data. For CitiPark's issuance system, agree the equivalent handoff and return reference. Exact destination-specific schemas and transfer routes are a working-session item; the acknowledgement examples above do not replace either lifecycle API contract.
Proposed errors: 400 for invalid payloads, 401/403 for missing credentials or scope, 404 for an unavailable reference, 409 for conflicting retry content, and 429/5xx for rate limits or temporary failures. Final error bodies, retry guidance, rate limits and lookup visibility rules will be documented before release. Failed reads must not clear the officer's list or silently certify its freshness.
Reconciled with CitiPark's emails of 2 and 9 September 2026. These labels distinguish partner acceptance in principle from ePRO's proposals and work still required for release.
CitiPark requested explicit closure reasons on 2 September. The proposed snapshot plus reference lookup supplies those reasons and retains officer outcomes after closure. Confirm the lookup contract and whether payment, permit and whitelist need separate audit subtypes beneath now_covered.
CitiPark confirmed site_ref is sufficient for the POC. The actual test-site mapping, rules, access and attendance arrangements will be supplied separately. Richer site routing and zone information remain later-phase work.
CitiPark requested grace, maximum stay and tariff, included or referenced. ePRO proposes applicable rule/version and operating-hours context, with a simple tariff reference where suitable. Tariff exclusion has not been agreed. Finalise which fields the officer needs and how entry-time rules are preserved.
Signed URLs with expiry are the proposed access model. Confirm signing availability, expiry and renewal, retention duration, permission for external evidence copies, and retrieval of later exit imagery after closure. These are outstanding arrangements, not assurances that the partner interface is already released.
The five statuses requested by CitiPark are incorporated. Agree their transition effects, retry handling and the notice/evidence handoff. vehicle_not_found and plate_mismatch are feedback for review; their cause is not automatically attributed to detection error. enforcifyPRO already supports an affixed-notice API flow; the CitiPark mapping to that flow remains integration work.
CitiPark accepted polling every 2–5 minutes for Stage One. Preserve an extension path for opportunity open/close webhooks. Richer webhooks and expanded status handling can follow the POC.
Use officer verification observation consistently. CitiPark's field team verifies the circumstances and decides the field action. ePRO supplies rule and opportunity context; subsequent ticket management belongs to the nominated lifecycle platform.
Reshay's 9 September email asks for the updated specification and POC access, followed by a short technical session. Walk one attended-and-issued vehicle and one that exits before attendance, confirm each system's responsibilities and agree a target for the first opportunity reaching InforceMate.
Before partner integration begins
Agree the proposed contract; complete and verify the partner read, lookup and acknowledgement interfaces; confirm evidence arrangements and the notice handoff; and issue credentials against the agreed test-site configuration. Record endpoint availability and the test target explicitly when confirmed.
The operator, enforcement provider and lifecycle platform are distinct. Getapark operates parking, Enforcify provides its enforcement service, ePRO supplies rules and integrations, and enforcifyPRO supports both mailed and affixed notice lifecycles. CitiPark deployments may use CitiPark's own issuance system.
Prepared for CitiPark. Public examples use anonymised site references. Test-site details and credentials are supplied separately to the authorised team.