5018 Strategic Management · emploidai Marketplace
emploidai Marketplace
Add-onsAppletsPlugins
Search tools, teams, and capabilitiesPublish
MarketplacePlugins5018 Strategic Management
Plugin
Verified
Limited listing

5018 Strategic Management

by agentron · v1.0.38

Strategic planning, performance, internal control, risk and pre-financial control workspace.

0 installsUpdated Sep 22, 2026
Publisher information is incomplete

This community listing does not yet include every recommended support, privacy, pricing, and permission disclosure. Review the available package permissions before installing.

Category

business

Version

1.0.38agentron

Requirements

Maximum memory 256MB

Pricing

Not disclosed by publisher

Security & access

Review before installing

CompatibleRequires emploidai +

Permissions

No permissions were declared by the publisher.

Dependencies

No additional dependencies

emploidai Marketplace

Discover capabilities. Review access. Install inside your workspace.

DocumentationSecuritySupportPrivacyTerms

5018 Strategic Management iframe plugin

Version 1.0.37

  • Target cards support evidence selection/upload, variance explanations and corrective actions, with versioned actuals and independent approval/return.
  • Indicators support increasing/decreasing ratios, baseline progress, thresholds and restricted custom formulas, annual/period targets and aggregation rules.
  • The calculation examples workspace previews editable scenarios without saving records. Actual entry shows the same server-calculated result and explanation.
  • Objective and plan performance use weighted, year-scoped calculations with explicit missing-data policies. Saved actuals retain their calculation settings.

This Dify-compatible plugin contributes two independently discoverable items to Emploid AI: the isolated iframe applet com.agentron.app.sp and the specialist Emploid Strategy com.agentron.strategy.sp. The endpoint serves only the compiled SPA under /app/. Emploid AI provisions the declared managed backend, lists the strategy in the worker strategy picker, and exposes the applet's scoped API on the iframe runtime origin; the plugin never receives or declares the platform-managed backend signing secret.

Build the package assets from the repository root:

SP_PLUGIN_BACKEND_IMAGE='realmocean/com.agentron.app.sp@sha256:<new-published-digest>' \
  EMPLOID_PLUGIN_SIGNING_PRIVATE_KEY='/secure/path/plugin-signing.private.pem' \
  npm run build:plugin

build:plugin fails closed for a missing, mutable, malformed, or all-zero image digest and renders the package-only emploid-apps.json from emploid-apps.template.json. The same immutable image is bound independently to the applet backend and the Emploid Strategy contribution. Publish the current backend source first; do not reuse the previous digest, which predates baseline user principal support. The command packages, signs, and verifies the plugin in a temporary directory, then leaves only dist/com.agentron.app.sp-<version>.signed.empkg. It fails closed when the signing key is missing. Local development defaults to ~/.config/emploid/plugin-signing/emploid-local-development-v2.private.pem; release and CI environments should set EMPLOID_PLUGIN_SIGNING_PRIVATE_KEY to their protected trusted-key path. The managed runtime activation probe uses /ready, so database/schema readiness is required before Employee AI exposes the app.

Employee AI accepts this package's supported iframe capability declaration after the package signature is verified. The exact set and its integrity fingerprint are stored with the staged contribution; there is no app-specific Compose/environment allowlist. A signed upgrade may change the declared set without requiring an Employee deployment change.

The descriptor deliberately does not allow plugin-controlled SP_STORAGE_QUOTA_BYTES; Employee AI must inject a positive quota from its installation policy. The backend reports aggregate SQLite/blob utilization in health responses and rejects over-quota writes with 507. In production, persistent managed apps also require Employee AI to be configured with a quota-capable Docker volume driver through EMPLOID_PLUGIN_APP_VOLUME_DRIVER and quota-bound EMPLOID_PLUGIN_APP_VOLUME_DRIVER_OPTIONS_JSON; the default local Docker volume driver is deliberately not treated as a hard quota.

The current managed-container declaration also does not claim a malware-scan adapter. When its internal network cannot reach a platform-provided ClamAV endpoint, production documentUpload readiness is explicitly false and the iframe disables every upload entry point. Do not enable an unscanned bypass; provision an internal scanner or a narrow platform-mediated scan adapter first.

The iframe obtains instance_id from its token-free launch URL, establishes the emploid.applet v1 MessageChannel, consumes host.session.grant through the runtime session exchange, and keeps the resulting scoped token only in memory.