HR & Payroll UAT Remediation v0.38.0-UAT Update 1 Project Reference: HRPAY-BMD-20260911-01 This package is a QA-remediation UAT build, not a final production acceptance release. The 18 Critical/P0 findings have implementation evidence in source and pass the included static verifier. They remain formally open until the Local Django/PostgreSQL runtime scenarios pass; FO-M1 punch integration additionally requires the physical device test. HR & Payroll Complete Trial v0.37.1-trial Project Reference: HRPAY-BMD-20260911-01 This release converts the earlier browser-review package into a final-style Local UAT handover package for the maintenance team. Included in this trial: - Complete Django/Python source tree and PostgreSQL connection configuration. - Real login/logout/password-change and role/permission foundation. - Employee, attendance, leave, unified HR request/workflow, salary, OT, bonus, deduction, payroll, loans/advances, exit/clearance, payslip/reports, audit and administration backend paths. - ZKTeco FO-M1 device profile, employee mapping, raw punch ingestion and duplicate protection path. - PostgreSQL backup/verify/guarded restore commands. - Windows Local UAT setup/check/smoke/start scripts and private-LAN start script. - Local UAT demo users by role and Shohoj Shop sample data. - UAT scenarios, bug log, payroll reconciliation, FO-M1 test files and import templates. - Bengali Installation & Maintenance Guide, User Manual and Developer Orientation in DOCX + PDF. Known trial boundaries: 1. Full Django/PostgreSQL runtime verification is intentionally performed on the Local UAT server because the build environment has no installable Django runtime/dependency network. 2. Update 1 uses an explicit migration-freeze gate. Run the freeze script on the exact reviewed source, retain generated migration files + hashes, then use a FRESH UAT database. Normal setup must not create migrations ad hoc. 3. FO-M1 CSV/USB ingestion is prepared. Direct TCP/IP/ADMS connector behavior must be verified against the actual device. 4. Django development server is used only for Local UAT. Final live deployment will use a hardened production application server/reverse proxy/HTTPS setup. 5. Demo UAT accounts/data must be removed or disabled before production go-live.