Connect, auto-map, preview, pull, nightly opt-in. CSV still works.
IMP — KoboToolbox connection (what is live)
Audience: MERL / data leads and IT reviewers Status: Connect → map → preview → pull is live. Nightly pull is live (Admin opt-in).
What a buyer can do today
- Connect — Admin pastes the Kobo host + API token on Team / Import. Token is stored encrypted server-side. Never in the browser after save.
- Discover — IMP lists forms and guesses a field map (site, date, method, notes, numeric actual).
- Preview — First rows shown as they will land. Human checks the map.
- Pull — Submissions upsert into evaluation events or indicator actuals. Idempotent by submission id. IMP does not write back to Kobo.
- Nightly pull — Admin turns it on after a trusted map. Cron reads saved maps; IMP never writes to Kobo.
- CSV still works — air-gapped teams keep the file path.
Value: field data lands in the same programme as the matrix, ethics holds, and board pack. No second spreadsheet.
What is not live yet
| Item | Status |
| Nightly / scheduled pull | Live — Admin toggle on Import. Cron /api/cron/kobo-sync. |
| Push labels or forms back to Kobo | Not planned (pull-only by design) |
| Multi-form auto-routing without a saved map | Manual map per form |
Security notes for IT
- Token is org-scoped, Admin-only to save.
- Encrypted at rest; used only on the server.
- Scope the Kobo token to the minimum project set.
- Pull is read-only against Kobo.
- Mapping mistakes do not invent findings — Auto-eval still requires human Accept.
Success test (pilot week 1)
- Admin connects one project in under 10 minutes.
- One form maps to events or indicator actuals.
- Preview matches a known Kobo row.
- Pull does not duplicate on a second run.
Help
In-app: Help → Kobo path and Import. CSV templates remain on Import if the token cannot be issued yet.
Document version: 2026-08 · Live connect / map / pull / nightly opt-in