Outbound-only connection
The gateway initiates encrypted communication over normal secured web transport.
Campus Integration Gateway
The planned gateway is an outbound-only Windows service that carries approved events and controlled commands between the campus and Indelo cloud services.
Network model
Schools will not need a static public IP, router port forwarding, direct mobile SQL credentials, or a permanent VPN for normal cloud/mobile workflows.
The gateway initiates encrypted communication over normal secured web transport.
Committed campus changes create durable integration events in the same local transaction.
Mobile-originated intentions are validated, recorded, retried safely, and applied by fixed Indelo handlers.
Repeating the same verified command must not duplicate a payment, receipt, attendance entry, or request.
Interrupted work resumes from durable state; local transactions either commit completely or roll back for safe retry.
Authorized operations can see version, last synchronization, queue age, credential expiry, and redacted diagnostics.
Business-rule boundary
A mobile payment becomes a command such as PostVerifiedSchoolFeePayment. The campus applies it through the same fee ledger, cashbook, receipt, reversal, authorization, and audit rules used by local work.
Gateway pilot
CABS will review the supported Indelo version, SQL Server environment, Windows host, connectivity, campus identity, support ownership, and recovery practices.