Project Governance & Digital Asset Control Platform
Compliance Platform for the 53.5 MW Upper Myagdi-1 Hydropower Project
1. Executive Summary
Proposing for 53.5 MW Upper Myagdi-1 (UMHL):
- Public portal: approved technical repository, bilingual disclosures, generation summaries.
- Admin enclave: maker-checker-approver publishing, O and M sealed bidding with AES-256-GCM, 5x5 risk register, WORM audit ledger.
- Build: single Cloudflare Worker. Air-gapped from OT/SCADA. Manual batch uploads only.
- Cutover includes inventory and migration from uppermyagdi.com.np.
Note: demo is working prototype, not UMHL production.
Proposed Next Step
Next step: walkthrough to check fit. Scope, timeline, support and terms follow only on fit. Covers:
- Project disclosure: Public technical repository with approval before publication.
- Procurement: Browser-encrypted bidding with client-side AES-256-GCM.
- Records: Maker-checker-approver transitions with verifiable WORM audit history. See Technical Appendix for the state machine and enforcement.
- Generation & Risk Tracking: Air-gapped dashboard for metrics and risks. No OT/SCADA connection.
2. Why a Dedicated Project Platform
When disclosures, procurement files, and governance records sit across websites, email, and spreadsheets, control and audit get harder.
One controlled system:
- Reporting support: Drawdown histories, environmental records, and compliance registers for lender, shareholder, and management review.
- Generation tracking: Logs paired with applicable seasonal PPA baselines.
- Operational Records & Logs: Governed ledger for daily generation, transmission performance and environmental compliance. Air-gapped from plant automation. Manual batch uploads only, no live connection.
- Listed-Market Readiness Disclosures: Append-only records for compliance registries and regulatory notices.
3. What Is Proposed
One codebase, two layers:
A. Public Portal and Technical Repository
- Salient features: Specs, Myagdi River catchment hydrology, headworks, main tunnel and powerhouse on the Upper Myagdi alignment. Covers Malika and Dhaulagiri geological settings.
- Bilingual archive: Linked English and Nepali notices, EIA updates, and Malika and Dhaulagiri community notices. Next.js SSR.
- Generation Dashboard: Air-gapped view of historic and daily generation logs against seasonal PPA baselines (Dry vs. Wet tariffs).
Public PortalProject Landing & Disclosure Surface

Figure 3.1: Public surface: parameters, air-gapped metrics, approved regulatory disclosures. Prototype illustration.
B. Protected Administrative Enclave
Restricted workspace behind a deployment-specific secret slug (ADMIN_SECRET_SLUG), not a guessable /admin path.
- Authentication: MFA with server-enforced 15-minute inactivity timeout.
- Separation of duties: Server and database enforced. No self review or self approval.
Admin EnclaveExecutive Management Workspace & Operational Queues

Figure 3.2: Enclave: reviews, risk posture, procurement pipeline. Prototype illustration.
Screenshots are from the working prototype. They show function and layout. Production would use Upper Myagdi-1 operational parameters, UMHL / Urja Developers corporate roles, and localized bilingual content.
4. Governance and Operational Capabilities
Controlled Procurement Workflows
Sealed Two-Envelope Bidding for Operational & Maintenance. Financial envelopes are encrypted in the bidder browser with AES-256-GCM. The server stores ciphertext only and holds no decryption keys.
Opening-date rules are enforced server side. Result: controlled, verifiable bidding with an audit trail and reduced early-access exposure.
ProcurementSealed Bid Envelopes

Figure 4.1: Sealed envelopes: ciphertext only, no server keys, opening-date locks. Prototype illustration.
5x5 Risk Register
Live 5x5 register. Examples below are illustrative only. Final catalogue is set during discovery:
- Geological Tunnel Squeeze & Siltation (Construction-to-Operational): Tracking tunnel squeeze hazards following the main tunnel breakthrough on the Upper Myagdi alignment, plus quartz-rich sediment/siltation mitigation and turbine abrasion management during high-velocity monsoon flows on the Myagdi River axis.
- Grid & Transmission (Evacuation): Logistical tracking of line trips, capacity limitations, and variance logging along the transmission alignment to the Dana Substation.
- Community & Regulatory (Compliance): Local resource shares, public notices in Malika and Dhaulagiri, and compliance timelines for Upper Myagdi-1.
Nightly Cron escalates overdue mitigations. Scoring anchors, control checks, KRI thresholds, and three-person rules: see Technical Appendix.
Risk Engine5x5 Enterprise Risk Posture

Figure 4.2: 5x5 heat map, control health, escalation. Prototype illustration.
Verifiable Audit History (WORM Ledger)
Governance events go into an append-only WORM chain. Each entry links to the prior one with SHA-256 and is checked against an external checkpoint. Alteration is detectable, not claimed impossible.
Audit LedgerCryptographic WORM Execution Ledger

Figure 4.3: Hash-chained ledger with external checkpoints. Prototype illustration.
5. Platform Architecture and Capability Comparison
Architecture Diagram
| Capability area | Common approach | What the platform demonstrates |
|---|---|---|
| Audit records | Email and spreadsheets, hard to verify. | WORM ledger with verifiable history and tamper detection. |
| Project identity | Buried in a corporate site. | Dedicated 53.5 MW Upper Myagdi-1 portal with compliance registries and air-gapped asset registries. |
| Bidding | General channels. | Two-envelope bidding, AES-256-GCM, opening-date enforcement. |
| Risk tracking | Files, no escalation. | 5x5 register, 3-person separation at database layer. |
| Infrastructure | Varies by provider. | Serverless Cloudflare Worker architecture. The public surface has zero data-exchange pipelines or connections routing back to the physical powerhouse SCADA network, providing permanent cryptographic isolation. |
Engineering detail (five-layer enforcement, RLS, trigger-level Maker-Checker, sealed-bid crypto, fail-closed): see Technical Architecture Appendix.
6. Myagdi Regional Coordination
I am based in Beni Bazaar, Myagdi, which enables easier coordination with the regional teams in Malika and Dhaulagiri.
7. Indicative Implementation
Prototype exists. Configuration follows discovery and scope agreement. Indicative plan:
| Phase | Delivered | Duration |
|---|---|---|
| Discovery | Reporting needs, PPA baselines, roles | 10 days |
| Configuration | 5x5 risk templates, AES bidding gateway | 22 days |
| Validation and cutover | Tamper tests, walkthroughs, DNS cutover prep | 28 days |
8. Closing and Walkthrough Request
A working prototype is already operational and demonstrates WORM audit chains, sealed bidder key handling, and automated 5x5 heatmap calculations. You can see it and test it.
A brief 15-minute walkthrough, online or in Beni, allows us to verify operational fit. A fixed implementation plan, timeline, and commercial terms will be structured immediately following that scoping discussion.
Working prototype (not UMHL production):
- Governance portal: https://durbang.aashikbaruwal.com.np/
- More work: https://www.aashikbaruwal.com.np/arc-and-civ
Video DemoWorking Prototype in Action
Video walkthrough: Comparable hydro deployment. Prototype only.
Submitted by
Aashik Baruwal
Beni Bazaar, Myagdi
Email: workwithaa.sik@gmail.com