A department editor starts from approved content types with required metadata.
CMS and Platform
A platform behind every page.
Attachment D asks for more than a website. It asks for a platform: editor workflow, search, accessibility, hosting, security, records, meetings, integrations, domains, support, and room to grow. Here is how Stoa keeps them working together.
Editor Workflow
Non-technical publishing, with guardrails.
A reviewer checks facts, accessibility, records retention, and translation needs.
Scheduled release, with an audit trail, rollback, and linked source records.
Search misses, broken links, and stale pages become editorial tasks.
Who Publishes
Broad departmental publishing, no per-seat cost.
WordPress gives the City unlimited user accounts with no per-seat license, so every department team can publish without procurement overhead.
Integration Map
Named systems get named ownership.
Not every system needs a full bi-directional API. The right connection type (secure link, embed, or API) is confirmed in discovery once API documentation and sandbox access are available from the City's vendors.
Stoa method: Secure link/embed of the public portal at launch; API for status later.
Stoa method: Embed or link intake; optional status API.
Stoa method: Secure link to the hosted payment portal; no card data in the CMS.
Stoa method: API or connector where available; managed linking otherwise.
Stoa method: Embed or deep link the registration portal.
Stoa method: Embedded code and ordinance lookup.
Stoa method: Coexist: surface subscribe links and active alerts; not replaced.
Stoa method: Integrate lists; add a unified on-site subscription center.
Notifications and Access
One subscription center. One sign-on path.
- CodeRedDover's emergency SMS provider stays in place for life-safety alerts. The website surfaces CodeRed subscription links and active-alert banners alongside other channels without replacing the system.
- Constant ContactIntegrated with the website so list management, Dover Download signups, and campaign sends work from one place rather than multiple disconnected interfaces.
- On-site subscription centerA unified notification hub reduces fragmentation: residents subscribe to topics, boards, departments, or the full Dover Download in one place instead of hunting across the site.
- Staff single sign-onSSO via SAML/OIDC (Microsoft Entra/Azure AD, Google Workspace, or Okta) with MFA enforced and role-based access matched to each editor's department scope. No shared passwords; every login is logged.
- Secured resident content area Phase 2A future expansion, not a launch-day item. Proposed purposes: partner secure large-file transfer, public-body collaboration under NH transparency law, and resident access to secured personal files. Scope and authentication model confirmed with the City prior to Phase 2 build.
Security and Hosting
Evidence, without overclaiming.
The prototype shows the control model the proposal has to substantiate: MFA, audit logs, secure SDLC, backups, breach-notice workflow, data ownership, export, and continuity.
- AlignmentSOC 2 evidence and FedRAMP/GovRAMP principles mapped, without claiming authorization.
- CapacityAt least twice the stated current scale: 25 GB, roughly 2,000 folders, and roughly 35,000 files, including approximately 11,500 CAMA property-record PDFs refreshed annually via an automated ingestion path, and roughly 450 web log-analysis files. No one-time manual migration for the annual CAMA batch.
- DomainsThe main Dover site plus named related domains, with SSL/certificate tracking and routing ownership.
- SupportWarranty, monitoring, incident response, training, and a content-governance cadence.
Domain Stewardship
A multi-domain city web estate.
The domain spellings above follow Attachment D, including the listed doverarean.com string. The intended domain inventory would be confirmed with the City during discovery.