Drop Srbija v2 — Team Roster
Drop Srbija v2 — Team Roster
Last Updated: 2026-04-17
Core Team
| Role | Agent/Company | Contribution |
|---|---|---|
| Product Owner | Alem Basic (CEO) | Vision, funding decisions, bank partnership |
| Chief Architect | Petter Graff (CodeCraft) | Backend architecture, Kotlin/Ktor implementation |
| Frontend Lead | Brad Frost (Vizu) | Drop Norway 1:1 port, Serbian localization |
| QA Lead | Angie Jones (Proveo) | Test pyramid, E2E journeys, validation evidence |
| Security Lead | Parisa Tabriz (Securion) | Phase 0 security hardening, CORS, rate limiting |
| DevOps Lead | Kelsey Hightower (FlowForge) | Terraform, Caddy, Azure Container Apps, backup/DR |
| Fintech Advisor | Markos Zachariadis (Finverge) | NBS IPS integration, bank partnership strategy |
| Legal Compliance | Thaer (Lexicon) | ZZPL compliance, NBS PI license application |
| Documentation | Skillforge | BookStack docs, runbooks, decision log |
| Orchestrator | John (ALAI Director) | Task routing, progress tracking, evidence collection |
Specialist Agents by Phase
Phase 0: Security Hardening (Securion)
- Parisa Tabriz — Security architect
- sentinel-architect — Threat modeling
Deliverables:
- 5 P0 fixes (CORS, EnvGuard, rate limiting, AuditLogger, security CI)
- Security.yml workflow
- EnvGuard validation (12 required env vars)
Phase 1: Frontend Port (Vizu)
- Brad Frost — Atomic Design, component library
- Lea Verou — CSS architecture, Tailwind optimization
Deliverables:
- 30 pages adapted (NOK→RSD, BankID→OTP, Vipps→NBS IPS)
- 6 Serbian components (JMBGInput, PhoneSRInput, IBANSRInput, PIBInput, NBSIPSButton, OTPVerifyForm)
- 145 i18n keys (sr + en)
- 2 new pages (onboarding/jmbg, onboarding/nbs-ips)
- 1721/1777 vitest pass (97%)
Phase 2: Backend Modules (CodeCraft)
- Petter Graff — Kotlin/Ktor architecture
- Martin Kleppmann — Database schema design
- Bruce Momjian — PostgreSQL optimization
Deliverables:
- 20 modules ported (auth, user, transactions, recipients, merchants, accounts, ips, kyc, aml, disclosure, complaints, idempotency, rates, notifications, audit, metrics, webhooks, cron, admin, reports, consents, settings, openapi, withdrawal, cards, disputes, dataaccess, health, sms, flags)
- 22 Flyway migrations (V1-V22)
- 617 tests passing (79 test files)
- Koin DI pattern
- Exposed ORM integration
Phase 3: Testing & Observability (Proveo + AgentForge)
- Angie Jones — Test pyramid strategy
- James Bach — Exploratory testing
- Lisa Crispin — Integration test design
- Dorota Huizinga — Accessibility testing (axe-core)
Deliverables:
- Test pyramid: 617 unit, 11 integration, 15 E2E, 4 k6 scenarios, 23 axe-core rules, 12 Pact interactions
- Visual regression baseline (Playwright)
- OpenTelemetry (backend + frontend OTLP)
- Sentry (client + server + edge)
- LGTM stack (Prometheus + Grafana + Loki + Tempo)
- 3 Grafana dashboards (overview, infra, errors)
- JaCoCo 52% coverage gate
Phase 4: Infrastructure (FlowForge)
- Kelsey Hightower — Kubernetes/container orchestration
- Hadi Hariri — Kotlin backend deployment optimization
Deliverables:
- 11 Terraform modules (network, postgres, redis, container-apps, ACR, DNS, secrets, monitoring, backup, IAM, CDN)
- Caddy reverse proxy (prod/staging/dev profiles)
- Backup/DR (RPO 1h, RTO 4h)
- 16 Prometheus alerting rules
- semantic-release + commitlint
- deploy-production.yml workflow
- Vaultwarden secrets (16 secrets + rotation schedule)
- 12 CI/CD workflows
Domain Experts (Advisory)
| Expert | Company | Domain | Consulted On |
|---|---|---|---|
| Markos Zachariadis | Finverge | Fintech regulation | NBS IPS integration, bank partnership strategy |
| Thaer | Lexicon | Legal compliance | ZZPL, ZPNFTM, NBS PI license |
| Parisa Tabriz | Securion | Security | Phase 0 hardening, security CI |
| Angie Jones | Proveo | QA | Test pyramid, validation evidence |
Supporting Teams
| Company | Role | Deliverables |
|---|---|---|
| CodeCraft | Backend development | Kotlin/Ktor modules, database schema, tests |
| Vizu | Frontend development | Next.js 15 port, Serbian localization, components |
| Proveo | Quality assurance | Test pyramid, E2E journeys, validation matrix |
| Securion | Security | Phase 0 hardening, CORS, rate limiting, audit logging |
| FlowForge | DevOps | Terraform, Caddy, Azure deployment, backup/DR |
| Finverge | Fintech advisory | Bank partnership pitch, regulatory strategy |
| Lexicon | Legal compliance | ZZPL, ZPNFTM, NBS PI license application |
| Skillforge | Documentation | BookStack pages, runbooks, decision log |
| AgentForge | AI/ML (future) | Fraud detection (Phase 7), credit scoring (Phase 8) |
Communication Channels
- Task Management: MC CLI (
node ~/system/tools/mc.js) - Documentation: BookStack (https://docs.basicconsulting.no/books/drop-srbija)
- Code Repository: GitHub (
~/ALAI/products/DropSrbija) - Decision Log:
docs/05-decision-log.md(synced to BookStack) - Slack: #drop-srbija (agent notifications)
Escalation Path
- Tactical Issues (bugs, test failures): → John → Specialist agent
- Architectural Decisions (D10-D14): → Petter Graff → Alem (CEO approval)
- Legal/Compliance: → Thaer (Lexicon) → Alem (final sign-off)
- Regulatory Strategy: → Markos (Finverge) → Alem
- Security Incidents: → Parisa (Securion) → John → Alem (within 4h)
Agent Autonomy Levels
| Level | Description | Examples |
|---|---|---|
| L0: Query | Answer questions, no code changes | Documentation lookup, status check |
| L1: Execute | Run commands, tests, builds | ./gradlew test, npm run build |
| L2: Edit | Modify code, commit changes | Bug fixes, test additions |
| L3: Design | Propose architecture, review PRs | New module design, tech stack choice |
| L4: Decide | Make binding decisions (CEO-gated) | Legal entity, bank partnership, budget |
Drop Srbija Agent Levels:
- Petter Graff: L3 (architecture decisions within ALAI standard)
- Brad Frost: L3 (frontend architecture, component design)
- Angie Jones: L2 (test design, no architecture changes)
- Parisa Tabriz: L3 (security architecture)
- Kelsey Hightower: L3 (infra architecture)
- Markos Zachariadis: L3 (fintech strategy, no binding commitments)
- Thaer (Lexicon): L3 (legal advice, CEO final sign-off)
- John: L2 (orchestration, no architecture decisions)
Team Principles
- Evidence Over Claims: All "done" reports include L2+ machine-verified evidence
- Specialist Routing: John routes tasks to company/agent with domain expertise
- No Generic Builders: Every task goes to named specialist agent, not "builder" or "minion"
- Documentation Required: Skillforge creates BookStack page for every system built
- Validation Required: Proveo validates every "done" claim with real evidence
- CEO Gates Major Decisions: D10+ architectural decisions require Alem approval
Org Chart: ~/ALAI/org/ORGCHART.md
Specialist Mapping: ~/system/agents/specialist-mapping.json
Agent Permissions: ~/.claude/projects/-Users-makinja/memory/project_agent_permission_system.md
No comments to display
No comments to display