← Back to Pitch

Operations & Operational Readiness
แผนปฏิบัติการและความพร้อม — Babigon Operations Audit Response

เอกสารนี้ตอบทุกช่องว่างด้านปฏิบัติการที่พบจากการตรวจสอบของ Babigon — ครอบคลุม Call Center, การรองรับภาษา, การเข้าถึงของประชาชน, SOP สำหรับเหตุการณ์สำคัญ, การเข้าถึงข้อมูล Easy Pass, การทดสอบ Failure Mode, และ Timeline ที่ปรับตามความเป็นจริง This document addresses all operational gaps identified by Babigon's audit — covering Call Center, language coverage, citizen accessibility, critical SOPs, Easy Pass data access, failure mode testing, and a revised realistic timeline.

1. Call Center 2. Language Coverage 3. Accessibility & Inclusion 4. SOP Gap Analysis 5. Easy Pass Data Access 6. Failure Mode Testing 7. Timeline Revision

1. Call Center Staffing Model รูปแบบการจัดเจ้าหน้าที่ Call Center

📊 Call Volume Estimates ประมาณการปริมาณสาย

POC BaselineFirst-Week Spike
POC Usersจำนวนผู้ใช้ POC 22,40022,400
Call Rateอัตราการโทร 0.5%3–5%
Calls / Dayสายต่อวัน 112 672–1,120
Avg Handle Timeเวลาเฉลี่ยต่อสาย 8 min12 min
Agent Hours / Dayชั่วโมงเจ้าหน้าที่/วัน ~15 hrs~134–224 hrs

👥 Recommended Staffing จำนวนเจ้าหน้าที่ที่แนะนำ

  • Minimum: 6 bilingual agents (TH/EN)ขั้นต่ำ 6 คน
  • Target: 8 agents for surge absorptionเป้าหมาย 8 คนเพื่อรองรับช่วง spike
  • Supervisor: 1 team lead + 1 QAหัวหน้าทีม 1 + QA 1
  • Escalation: Tier-2 technical support (shared with IT)Tier-2 แชร์กับทีม IT
  • Surge strategy: Overflow to outsourced BPO during first 2 weeksOverflow ไป BPO ช่วง 2 สัปดาห์แรก

🎓 5-Day Agent Training Curriculum หลักสูตรอบรม 5 วัน

DayTopicหัวข้อKey Contentเนื้อหาหลักDuration
Day 1 Billing Model รูปแบบการเรียกเก็บเงิน Postpaid vs prepaid, daily/threshold billing, spending caps, statement structure, fee disclosure เปรียบเทียบ Postpaid/Prepaid, รอบบิล, เพดานค่าใช้จ่าย, โครงสร้างใบแจ้งหนี้, การเปิดเผยค่าธรรมเนียม 6 hrs
Day 2 System Navigation การใช้งานระบบ Agent dashboard, citizen lookup, trip ledger, payment status, notification history, token masking หน้าจอ Agent, การค้นหาประชาชน, ประวัติการเดินทาง, สถานะการชำระเงิน, ประวัติการแจ้งเตือน, การปกปิด Token 6 hrs
Day 3 Dispute Handling การจัดการข้อโต้แย้ง Dispute reason codes, evidence package retrieval, toll lane photo matching, refund/adjustment workflow, SLA per category รหัสเหตุผลข้อโต้แย้ง, การเรียกดูหลักฐาน, การจับคู่ภาพถ่ายช่องทาง, ขั้นตอนการคืนเงิน/ปรับปรุง, SLA ตามประเภท 6 hrs
Day 4 Escalation & Edge Cases การยกระดับและกรณีพิเศษ Card expiry, vehicle sale, death of holder, stolen tag, system outage procedures, fraud indicators, PDPA data requests บัตรหมดอายุ, การขายรถ, การเสียชีวิต, ป้าย被盗, ขั้นตอนระบบล่ม, ตัวบ่งชี้ทุจริต, คำขอข้อมูลตาม PDPA 6 hrs
Day 5 Shadowing & Simulation การฝึกปฏิบัติและจำลองสถานการณ์ Live shadowing with trainer, simulated calls (normal, dispute, angry citizen, system-down), QA calibration, certification quiz ฝึกปฏิบัติกับเทรนเนอร์, จำลองสาย (ปกติ, โต้แย้ง, ประชาชนไม่พอใจ, ระบบล่ม), สอบเทียบ QA, ข้อสอบรับรอง 6 hrs

⚠️ 24/7 vs Business Hours Tradeoff การตัดสินใจ 24/7 vs เวลาทำการ

Recommendation: Business hours (8:00–20:00) with IVR/chatbot after-hours for POC. True 24/7 requires 3 shifts × 8 agents = 24+ staff — disproportionate for 22,400 POC users. Escalate to 24/7 only at national scale (Phase 3). After-hours: self-service portal + automated dispute submission + critical-outage-only emergency line. แนะนำเวลาทำการ (8:00–20:00) พร้อม IVR/แชทบอทนอกเวลา True 24/7 ต้องใช้ 3 กะ × 8 คน = 24+ คน — ไม่คุ้มสำหรับผู้ใช้ POC 22,400 ราย ขยายเป็น 24/7 เมื่อขยายระดับประเทศ (Phase 3)

2. Language Coverage การรองรับภาษา

✅ Currently Covered ภาษาที่รองรับในปัจจุบัน

LanguageScopeRationale
🇹🇭 Thai (TH)Full (UI + legal + IVR + statements)Primary — all citizens
🇬🇧 English (EN)Full (UI + legal + IVR + statements)Tourists, expats, business
🇨🇳 Chinese (ZH)Core (UI + consent + statements)#1 tourist nationality, significant toll road users
🇯🇵 Japanese (JA)Core (UI + consent + statements)#2 tourist nationality by toll road usage

❌ Currently Missing — Critical Gap ภาษาที่ยังขาด — ช่องว่างสำคัญ

LanguageWhy Needed
🇲🇲 Burmese (MY) ~2M+ migrant workers in Thailand — significant toll road users (construction, logistics, services)
🇰🇭 Khmer (KM) ~600K+ Cambodian workers — concentrated in eastern provinces, frequent cross-border travel
🇱🇦 Lao (LO) ~300K+ Lao workers — concentrated in northeastern corridor, Friendship Bridge routes
🇲🇾 Malay (MS) ~200K+ Malaysian border commuters — southern toll corridors

🗺️ Phased Language Rollout Plan แผนการเพิ่มภาษาตามระยะ

PhaseLanguagesApproachวิธีการTimeline
Phase 1
(POC)
TH + EN + ZH + JA In-house translation + legal review แปลภายใน + ตรวจสอบกฎหมาย Week 15–20
Phase 2
(Scale)
+ Burmese (MY) + Khmer (KM) Outsourced BPO provides Burmese/Khmer-speaking agents; UI translated via certified agency BPO ให้เจ้าหน้าที่ภาษาพม่า/เขมร; UI แปลโดยหน่วยงานรับรอง Week 37+
Phase 3
(National)
+ Lao (LO) + Malay (MS) Full multilingual support; community outreach in migrant worker communities รองรับหลายภาษาเต็มรูปแบบ; เข้าถึงชุมชนแรงงานข้ามชาติ National rollout

⚠️ Mitigation for Phase 1 Gap การบรรเทาช่องว่างใน Phase 1

  • Icon-driven UI reduces text dependency for core actions (pay, view statement, dispute)UI แบบ icon ลดการพึ่งพาข้อความสำหรับการทำงานหลัก
  • Pictorial quick-start guide in Burmese, Khmer, Lao, Malay (printable PDF)คู่มือเริ่มต้นแบบรูปภาพในภาษาพม่า เขมร ลาว มาเลย์ (PDF)
  • Call Center triage: if caller speaks unsupported language, offer callback within 24h via BPO interpreterCall Center: หากผู้โทรใช้ภาษาที่ไม่รองรับ เสนอบริการโทรกลับภายใน 24 ชม. ผ่านล่าม BPO

3. Citizen Accessibility & Inclusion การเข้าถึงและการมีส่วนร่วมของประชาชน

Card-First ≠ Card-Only — ระบบต้องรองรับประชาชนทุกกลุ่ม ไม่ใช่เฉพาะผู้มีบัตรเครดิต Card-First ≠ Card-Only — the system must serve all citizens, not only credit card holders.

🏦 UNBANKED — 30%+ of Thai Adults ประชากรที่ไม่มีบัญชีธนาคาร — 30%+ ของผู้ใหญ่ไทย

PromptPay Integrationการผสาน PromptPay

PromptPay is the most important missing feature for financial inclusion. Every Thai citizen with a national ID and bank account has PromptPay by default. Integration allows:

  • Direct debit via PromptPay (citizen ID ↔ bank account)หักบัญชีโดยตรงผ่าน PromptPay
  • QR-based payment for postpaid settlementชำระผ่าน QR สำหรับยอด Postpaid
  • No card required — only national ID + bank accountไม่ต้องมีบัตร — ใช้แค่บัตรประชาชน + บัญชีธนาคาร

Prepaid Wallet Fallbackตัวเลือกกระเป๋าเงินเติมเงิน

For citizens without any bank account:

  • Top-up at 7-Eleven / counter service (Boonterm, Tesco Lotus)เติมเงินที่ 7-Eleven / เคาน์เตอร์เซอร์วิส
  • Prepaid wallet with auto-top-up thresholdกระเป๋าเงินเติมเงินพร้อมตั้งค่าเติมเงินอัตโนมัติ
  • Cash-in at DOH/EXAT service countersเติมเงินที่เคาน์เตอร์บริการ

👴 ELDERLY — Digital Divide ผู้สูงอายุ — ช่องว่างดิจิทัล

No-App-Required Optionตัวเลือกไม่ต้องใช้แอป

  • USSD/SMS-based notification (*123# style menu)แจ้งเตือนผ่าน USSD/SMS
  • IVR phone support — full self-service via phone keypadIVR รองรับบริการตนเองผ่านแป้นโทรศัพท์
  • SMS confirmation for opt-in/opt-out (no data required)ยืนยันสมัคร/ยกเลิกผ่าน SMS

Accessibility Featuresคุณสมบัติการเข้าถึง

  • Large-print statements (physical mail option)ใบแจ้งหนี้ตัวอักษรใหญ่ (ส่งทางไปรษณีย์)
  • High-contrast UI modeโหมดความคมชัดสูง
  • Simple-language consent (plain Thai, no legal jargon)ภาษายินยอมที่เข้าใจง่าย
  • Family/guardian delegate accessการมอบอำนาจให้ครอบครัว/ผู้ดูแล

🌾 RURAL — Intermittent Connectivity ชนบท — การเชื่อมต่อที่ไม่ต่อเนื่อง

Offline-First Designออกแบบ Offline-First

  • Toll events buffered at lane level — no real-time connectivity required from vehicleข้อมูลค่าผ่านทางถูกเก็บบัฟเฟอร์ที่ช่องทาง — ไม่ต้องเชื่อมต่อจากรถ
  • App caches statement data for offline viewingแอปเก็บบันทึกข้อมูลสำหรับดูแบบออฟไลน์
  • Batch-sync when connectivity restoredซิงค์ข้อมูลเมื่อเชื่อมต่ออีกครั้ง

SMS FallbackSMS สำรอง

  • SMS works on 2G — covers 99%+ of populated ThailandSMS ทำงานบน 2G — ครอบคลุม 99%+ ของพื้นที่ที่มีประชากร
  • Balance inquiry: send SMS → receive current balanceสอบถามยอดคงเหลือ: ส่ง SMS → รับยอดปัจจุบัน
  • Transaction alert via SMS (no smartphone required)แจ้งเตือนรายการผ่าน SMS
  • Batch processing for intermittent deliveryประมวลผลแบบกลุ่มสำหรับการส่งที่ไม่ต่อเนื่อง

♿ DISABLED — Universal Access ผู้พิการ — การเข้าถึงที่เป็นสากล

  • WCAG 2.1 AA compliance commitment — all citizen-facing interfaces meet Level AAปฏิบัติตาม WCAG 2.1 ระดับ AA
  • Screen reader support: ARIA labels, semantic HTML, focus management, skip-navigation linksรองรับ Screen Reader
  • TTS (Text-to-Speech) for statements: statements available as audio summary via IVR or appTTS สำหรับใบแจ้งหนี้
  • Keyboard-only navigation: all functions accessible without mouse/touchนำทางด้วยคีย์บอร์ดเท่านั้น
  • Color contrast: minimum 4.5:1 for normal text, 3:1 for large textความคมชัดของสี
  • Accessibility audit: third-party WCAG audit before POC go-live gateตรวจสอบการเข้าถึงโดยบุคคลที่สามก่อนเริ่ม POC

💡 Card-First ≠ Card-Only Card-First ≠ Card-Only

PromptPay integration is the single most important missing feature for citizen inclusion. Without PromptPay, ~30% of Thai adults are structurally excluded. With PromptPay, any citizen with a national ID and bank account can participate — no credit card, no smartphone app, no data plan required. This must be prioritized during POC scoping as a hard requirement, not a nice-to-have. การผสาน PromptPay เป็นคุณสมบัติที่สำคัญที่สุดที่ยังขาดสำหรับการมีส่วนร่วมของประชาชน หากไม่มี PromptPay ประชาชน ~30% จะถูกกีดกันเชิงโครงสร้าง

4. SOP Gap Analysis — Critical Lifecycle Events การวิเคราะห์ช่องว่าง SOP — เหตุการณ์สำคัญในวงจรชีวิต

แต่ละ SOP ระบุ trigger → flow → resolution → audit trail สำหรับเหตุการณ์ที่ต้องจัดการในระบบ Postpaid Tolling ทุกรายการ Each SOP defines trigger → flow → resolution → audit trail for every critical lifecycle event.

💳 4.1 Card Expiry บัตรหมดอายุ

Account Updater auto-refresh attempt (60d before expiry) Notification to citizen (30d before) Reminder (14d before) Final notice (7d before) Grace period (7d post-expiry) Auto-suspend
  • Account Updater: PSP automatically attempts card refresh via network token / Account Updater service 60 days before expiryPSP พยายามรีเฟรชบัตรอัตโนมัติ 60 วันก่อนหมดอายุ
  • Grace period: 7 days post-expiry — tolls continue but flagged; citizen can update card without interruptionระยะผ่อนผัน 7 วัน — ค่าผ่านทางดำเนินต่อแต่ถูกแจ้งเตือน
  • Auto-suspend: If no valid card after grace, account suspended — citizen cannot use postpaid until card updatedหากไม่มีบัตรที่ถูกต้องหลังระยะผ่อนผัน — ระงับบัญชี

🚗 4.2 Vehicle Sale การขายรถ

Vehicle/tag de-link request Account freeze (pending verification) Final statement issued Data retention 90 days Purge
  • De-link: Citizen or DLT notification triggers vehicle/tag de-link from postpaid accountการแจ้งจากประชาชนหรือ DLT เริ่มการยกเลิกการผูก
  • DLT integration (future): Ideally, DLT ownership transfer auto-triggers de-linkในอนาคต: การโอนกรรมสิทธิ์ DLT เริ่มการยกเลิกโดยอัตโนมัติ
  • Retention: Trip/billing data retained 90 days for dispute resolution, then purgedเก็บข้อมูล 90 วันเพื่อแก้ไขข้อโต้แย้ง แล้วลบ

🕯️ 4.3 Death of Account Holder การเสียชีวิตของผู้ถือบัญชี

Death certificate received Verification (civil registry / DOPA) Account freeze Executor/heir access granted Final statement issued Account closure
  • Executor access: Authorized executor/administrator receives read-only access + final statementผู้จัดการมรดกได้รับสิทธิ์อ่านอย่างเดียว + ใบแจ้งหนี้สุดท้าย
  • Verification: Death certificate validated against DOPA civil registry (or certified copy)ตรวจสอบใบมรณบัตรกับทะเบียนราษฎร์ DOPA

🔑 4.4 Stolen Tag ป้ายถูกขโมย

Theft report (citizen / police) Tag blacklisted immediately New tag issued Old tag transactions flagged for fraud review Citizen not liable for post-report charges
  • Blacklist: Tag blacklisted at lane level within 1 hour of verified reportป้ายถูกขึ้นบัญชีดำที่ระดับช่องทางภายใน 1 ชม. หลังรายงาน
  • Fraud review: Any transactions on blacklisted tag flagged for investigationรายการใดๆ บนป้ายที่ขึ้นบัญชีดำถูกตั้งค่าสอบสวน
  • Liability cutoff: Citizen not liable for charges after verified report timestampประชาชนไม่รับผิดชอบค่าใช้จ่ายหลังเวลารายงานที่ตรวจสอบแล้ว

🔌 4.5 System Outage ระบบล่ม

Outage detected (monitoring) Toll events buffered at lane level No billing during outage Queue drained on restoration Post-restoration catch-up billing
  • Lane-level buffer: Each toll lane stores events locally — minimum 72h buffer capacityแต่ละช่องทางเก็บบัฟเฟอร์เหตุการณ์เฉพาะที่ — ความจุขั้นต่ำ 72 ชม.
  • No billing during outage: Citizens are not charged during outage window — catch-up billing only after reconciliationไม่มีการเรียกเก็บเงินระหว่างระบบล่ม — เรียกเก็บเมื่อกู้คืนแล้ว
  • Catch-up reconciliation: All buffered events verified against lane logs before billingตรวจสอบเหตุการณ์ที่เก็บบัฟเฟอร์ทั้งหมดกับบันทึกช่องทางก่อนเรียกเก็บ

🔄 4.6 PSP Switch การเปลี่ยนผู้ให้บริการชำระเงิน

New PSP onboarding Token migration plan Dual-running period Old PSP decommission Audit trail preserved
  • Token migration: Network tokens may not be portable between PSPs — plan for re-tokenization windowNetwork token อาจไม่สามารถย้ายระหว่าง PSP ได้ — วางแผนหน้าต่าง re-tokenization
  • Dual-running: Minimum 30-day overlap where both PSPs active — old PSP handles existing tokens, new PSP handles new enrollmentsทำงานคู่ขั้นต่ำ 30 วัน
  • Audit trail: All transaction logs from old PSP archived for 10 years per PDPA/financial regulationบันทึกธุรกรรมทั้งหมดจาก PSP เก่าเก็บถาวร 10 ปีตาม PDPA

🔓 4.7 Data Breach การรั่วไหลของข้อมูล

Detection Containment (72h max) PDPA notification (affected citizens) Media response Regulator reporting (PDPC + BoT if payment) Post-incident review
  • Containment SLA: 72 hours from detection to containment — system isolation, credential rotation, forensic imagingSLA กักกัน: 72 ชม. จากการตรวจจับถึงการกักกัน
  • PDPA notification: Affected citizens notified within 72h of confirmation (per PDPA §37/4)แจ้งประชาชนที่ได้รับผลกระทบภายใน 72 ชม. ตาม PDPA มาตรา 37/4
  • Regulator reporting: PDPC + Bank of Thailand (if payment data involved) + NCSCรายงานต่อ PDPC + แบงก์ชาติ + NCSC
  • Post-incident review: Root cause analysis, control improvement, public summary published within 30 daysวิเคราะห์สาเหตุ ปรับปรุงมาตรการ เผยแพร่สรุปสาธารณะภายใน 30 วัน

5. Easy Pass Data Access — The Honest Answer การเข้าถึงข้อมูล Easy Pass — คำตอบที่ตรงไปตรงมา

🚨 Honest Assessment การประเมินอย่างตรงไปตรงมา

The original pitch states "No immediate Easy Pass integration required." This is misleading. Toll event data from Easy Pass / EXAT / BEM is absolutely required for postpaid billing to function. Without toll event data, there is nothing to bill. The statement should be rephrased: "No modification to lane-level Easy Pass hardware is required — data access can be achieved via API, batch export, or manual CSV." ข้อความใน pitch เดิมที่ว่า "ไม่ต้องผสาน Easy Pass ทันที" นั้นทำให้เข้าใจผิด ข้อมูลเหตุการณ์ค่าผ่านทางจาก Easy Pass/EXAT/BEM จำเป็นอย่างยิ่งสำหรับการเรียกเก็บ Postpaid — หากไม่มีข้อมูล ก็ไม่มีอะไรให้เรียกเก็บ

Option A: API Pull ตัวเลือก A: ดึงผ่าน API

Best option. Real-time or near-real-time API from Easy Pass / EXAT / BEM toll event system.

  • ✅ Real-time trip data
  • ✅ Automated reconciliation
  • ⚠️ Requires EXAT/BEM cooperation
  • ⚠️ Needs MoU / data-sharing agreement
  • ⚠️ May need BOT queue approval

Option B: Daily Batch Export ตัวเลือก B: ส่งออกเป็นชุดรายวัน

Pragmatic option. EXAT/BEM exports toll events as CSV/SFTP daily.

  • ✅ No API development needed
  • ✅ Lower EXAT dependency
  • ⚠️ 24h billing delay
  • ⚠️ Manual reconciliation risk
  • ⚠️ Weekend/holiday gaps

Option C: Manual CSV via DOH ตัวเลือก C: CSV ผ่าน DOH

Fallback only. DOH manually requests CSV from EXAT and forwards to M-Pass team.

  • ✅ No technical integration
  • ⚠️ High latency (3–7 days)
  • ⚠️ Error-prone
  • ⚠️ Not viable for POC scale
  • ⚠️ Manual effort per cycle

🎯 Discovery Deliverable — Before POC Gate ผลลัพธ์การสำรวจ — ก่อนเริ่ม POC

Before the POC go/no-go gate, the working group MUST confirm: ก่อนการตัดสินใจ POC go/no-go คณะทำงานต้องยืนยัน:

  1. Data mechanism confirmed: Which of Options A/B/C — with written confirmation from EXAT/BEM กลไกข้อมูลที่ยืนยันแล้ว — พร้อมเอกสารยืนยันจาก EXAT/BEM
  2. Data fields confirmed: Tag ID, timestamp, lane ID, toll amount, entry/exit plazas — minimum required schema ฟิลด์ข้อมูลที่ยืนยันแล้ว — schema ขั้นต่ำที่ต้องการ
  3. Latency SLA: Agreed data delivery timeline from event to M-Pass system (target: <1 hour for Option A, <24 hours for Option B) SLA ความล่าช้า — ระยะเวลาส่งข้อมูลที่ตกลง
  4. Data-sharing agreement: Signed MoU or data-sharing agreement between DOH and EXAT/BEM ข้อตกลงการแบ่งปันข้อมูล — MoU ระหว่าง DOH และ EXAT/BEM
  5. PDPA compliance: Legal review of data flow (DOH ← EXAT → M-Pass → PSP) การปฏิบัติตาม PDPA — การตรวจสอบทางกฎหมายของการไหลของข้อมูล

6. Failure Mode Testing Plan แผนการทดสอบ Failure Mode

6 การทดสอบที่ต้องผ่านก่อนเริ่ม POC จริง — แต่ละการทดสอบมีเกณฑ์ผ่าน/ไม่ผ่านที่ชัดเจน 6 tests required before live POC — each with clear pass/fail criteria.

🧪 Test 1: Payment Gateway Outage Simulation การจำลอง Payment Gateway ล่ม

Scenarioสถานการณ์

PSP payment gateway goes offline for 30 minutes during peak toll hours (07:00–09:00). Multiple toll events accumulate while gateway is down.

Pass Criteriaเกณฑ์ผ่าน

  • All toll events queued without loss
  • Retry logic activates automatically on restoration
  • All queued events processed within 24 hours
  • No duplicate charges
  • Citizens see "pending" status (not "failed")
  • Call center dashboard shows outage status

🧪 Test 2: Mass Card Expiry Simulation การจำลองบัตรหมดอายุจำนวนมาก

Scenarioสถานการณ์

100 tokens set to expire simultaneously (simulates end-of-month batch expiry). Account Updater must process all 100 + notifications sent + grace period tracked.

Pass Criteriaเกณฑ์ผ่าน

  • Account Updater processes 100% of expiring tokens
  • ≥90% successfully refreshed (industry benchmark)
  • All citizens receive notification at 30d, 14d, 7d
  • Grace period correctly applied (7 days post-expiry)
  • Auto-suspend only triggers after grace period exhaustion
  • No citizen billed on expired card after expiry date

🧪 Test 3: Fraud Ring Simulation การจำลองขบวนการทุจริต

Scenarioสถานการณ์

1 compromised card used across 20+ different vehicle tags within 48 hours — simulates card-testing or fraudulent tag linkage.

Pass Criteriaเกณฑ์ผ่าน

  • Fraud detection triggers alert within 2 hours of 10th unique vehicle
  • Card automatically flagged and suspended
  • All linked vehicles flagged for investigation
  • Fraud case created in backoffice with evidence package
  • Call center notified within 30 minutes of alert
  • No further charges processed on flagged card

🧪 Test 4: Data Breach Tabletop Exercise การฝึกซ้อม Data Breach บนโต๊ะ

Scenarioสถานการณ์

Walk through a complete data breach scenario: masked PAN + trip data for 5,000 citizens exposed via misconfigured S3 bucket. Full incident response timeline exercised.

Pass Criteriaเกณฑ์ผ่าน

  • Detection → alert within 4 hours (simulated)
  • Containment plan executed within 72h (simulated)
  • PDPA notification draft ready within 72h
  • Media response statement drafted and approved
  • Regulator notification package prepared (PDPC + BoT)
  • Post-incident review timeline defined
  • All stakeholders identified and contactable

🧪 Test 5: Call Center Surge Test การทดสอบ Call Center รับปริมาณสูง

Scenarioสถานการณ์

Simulate 5× normal call volume (560 calls/day) — representing a billing error that causes widespread citizen concern. Queue, wait times, and escalation paths tested.

Pass Criteriaเกณฑ์ผ่าน

  • IVR handles first-level triage (balance check, status inquiry) without agent
  • Wait time ≤ 15 minutes for 90th percentile
  • Abandonment rate < 20%
  • Overflow to BPO activates within 30 minutes of threshold breach
  • Callback queue offered when wait > 15 minutes
  • Supervisor dashboard correctly shows real-time queue depth

🧪 Test 6: Reconciliation Breakage การทดสอบ Reconciliation ผิดพลาด

Scenarioสถานการณ์

Deliberately inject mismatch between toll event feed and billing ledger: 200 toll events in lane log but only 195 in billing ledger. Layer 1 reconciliation must detect and flag the 5 missing events.

Pass Criteriaเกณฑ์ผ่าน

  • Layer 1 reconciliation detects mismatch within 1 hour of batch completion
  • All 5 missing events identified with specific lane/timestamp
  • Alert generated with severity classification
  • Reconciliation dashboard shows gap visually
  • Manual or automatic remediation workflow triggered
  • No citizen billed incorrectly as a result of mismatch

⚠️ Testing Gate ประตูการทดสอบ

All 6 tests must pass before POC go-live. Any test failure requires root cause analysis, remediation, and re-test. The Testing Gate is a hard stop — no POC citizens are exposed to untested failure modes. Test results are documented in the POC Readiness Report and reviewed at the go/no-go gate meeting. ต้องผ่านทั้ง 6 การทดสอบก่อนเริ่ม POC จริง การไม่ผ่านต้องวิเคราะห์สาเหตุ แก้ไข และทดสอบใหม่ Testing Gate เป็นจุดหยุดที่เข้มงวด

7. Timeline Realism — Revised Estimate ความเป็นจริงของไทม์ไลน์ — ประมาณการที่ปรับปรุง

📅 Timeline Adjustment การปรับไทม์ไลน์

Original estimate: 22–30 weeks → Revised estimate: 30–38 weeks ประมาณการเดิม: 22–30 สัปดาห์ → ประมาณการใหม่: 30–38 สัปดาห์

The original timeline omitted three critical real-world constraints: (1) Government procurement lead time (PSP selection via e-bidding), (2) BOT regulatory sandbox application queue (payment innovation approval), (3) Agent hiring and training lead time (6–8 bilingual agents). These add 8 weeks to the critical path. ไทม์ไลน์เดิมละเลยข้อจำกัดสำคัญ 3 ประการ: การจัดซื้อภาครัฐ, คิว Sandbox ของแบงก์ชาติ, และการจ้าง/อบรมเจ้าหน้าที่ — เพิ่ม 8 สัปดาห์ใน critical path

Week 1–2
Working Group Formation + Procurement Prep จัดตั้งคณะทำงาน + เตรียมจัดซื้อ
Week 3–8
Legal + Payment Feasibility — including BOT sandbox application queue กฎหมาย + ความเป็นไปได้ด้านการชำระเงิน — รวมคิว Sandbox แบงก์ชาติ
Week 9–10
PSP Selection + Contract — government procurement timeline (e-bidding) การคัดเลือก PSP + สัญญา — ตามไทม์ไลน์จัดซื้อภาครัฐ (e-bidding)
Week 11–14
Agent Hiring + Training — 6–8 bilingual agents + 5-day curriculum การจ้าง + อบรมเจ้าหน้าที่ — 6–8 คน + หลักสูตร 5 วัน
Week 15–20
Integration + Failure Testing — all 6 failure mode tests completed การผสานระบบ + ทดสอบ Failure Mode — ผ่านทั้ง 6 การทดสอบ
Week 21–36
Controlled POC — 12–16 weeks (unchanged from original estimate) POC แบบควบคุม — 12–16 สัปดาห์ (ไม่เปลี่ยนแปลงจากประมาณการเดิม)
Week 37–38
Assessment + TOR — POC results, recommendations, national rollout TOR การประเมิน + TOR — ผล POC, ข้อเสนอแนะ, TOR สำหรับ rollout ระดับประเทศ

📊 Critical Path Dependencies การพึ่งพา Critical Path

# Dependencyการพึ่งพา Ownerเจ้าของ Risk if Delayedความเสี่ยงหากล่าช้า
1 BOT sandbox approvalการอนุมัติ Sandbox แบงก์ชาติ DOH + PSP Blocks payment innovation — POC cannot proceed
2 PSP e-bidding + contracte-bidding + สัญญา PSP DOH Procurement Government procurement can add 4–8 weeks beyond estimate
3 EXAT/BEM data-sharing agreementข้อตกลงข้อมูล EXAT/BEM DOH + EXAT + BEM No toll data = no billing — complete blocker
4 Agent hiring (bilingual TH/EN)การจ้างเจ้าหน้าที่สองภาษา DOH HR Bilingual talent pool limited — 4–6 weeks hiring realistic
5 DPIA + PDPA compliance reviewDPIA + ตรวจสอบ PDPA DOH DPO + Legal PDPA non-compliance = regulatory/criminal risk
6 PromptPay technical integrationการผสาน PromptPay PSP + DOH Without PromptPay, ~30% citizens excluded

✅ Risk Buffer บัฟเฟอร์ความเสี่ยง

The revised 30–38 week estimate includes a 4-week float buffer (Weeks 35–38). If all dependencies resolve on schedule, the assessment phase starts earlier and the buffer converts to additional POC run time or early TOR preparation. This is a realistic government project timeline — not a commercial startup sprint. ประมาณการ 30–38 สัปดาห์รวมบัฟเฟอร์ 4 สัปดาห์ — หากทุกอย่างเป็นไปตามกำหนด การประเมินเริ่มเร็วขึ้น และบัฟเฟอร์เปลี่ยนเป็นเวลา POC เพิ่มหรือเตรียม TOR ล่วงหน้า