ENGINEERING ARCHIVE·GovTech / Security
2025 · PRODUCTION RECORD

e-PMSSS

Paperless scholarship disbursement and verification platform

STACK:React.jsNode.jsExpress.jsMongoDBJWTBcrypt.jsRESTful APIs
01
PROBLEM & MOTIVATION
FAILURE MODES & INVARIANTS

“Developed during the Smart India Hackathon where I served as the technical lead of a student engineering team, addressing a national-level challenge to modernize public scholarship disbursement through transparent digital workflows.”

— e-PMSSS Architecture Brief

e-PMSSS is a paperless scholarship administration system developed as part of the Smart India Hackathon (SIH). It streamlines the end-to-end disbursement workflow for the Prime Minister's Special Scholarship Scheme, replacing slow, physical paper trails with an authenticated, multi-tier digital verification pipeline.

THE ARCHITECTURAL FAILURE POINT:

The traditional PMSSS scholarship disbursement process involved physical paper forms, manual multi-departmental stamping, and physical courier transit between colleges, nodal verification centers, and state administrative offices. This resulted in processing backlogs of several months, lost documents, and lack of transparency for student beneficiaries.

02
SYSTEM PIPELINE
DETERMINISTIC FLOW
ENGINEERING SOLUTION:

Engineered an authenticated digital pipeline with role-tailored dashboards and sequential state-enforced approval checkpoints.

STEP-BY-STEP EXECUTION TRACE:
01APPLICATION SUBMISSION

Student submits academic proofs and banking details via React frontend.

02COLLEGE TIER

College nodal officer reviews records; signs off with verified status.

03STATE TIER

State administrator audits cross-college batches and authorizes disbursement.

04AUDIT & DISBURSEMENT

Immutable timestamped audit entries generated for every state change.

03
IMPLEMENTATION
TECHNICAL CHAPTERS
CHAPTER 01

Multi-Role RBAC & Middleware Guards

Engineered secure Express.js middleware pipelines validating role claims from cryptographically signed JWTs, ensuring officials can only access and approve applications within their jurisdiction.

—Strict separation between Student, College Officer, and State Admin privilege tiers
—Bcrypt.js password hashing and secure HTTP-only session cookies
—Express-async-errors integration ensuring zero unhandled promise rejections
CHAPTER 02

State Machine for Approval Workflows

Modeled application lifecycles as a formal state machine in MongoDB, ensuring applications cannot skip intermediate verification steps or be approved without preceding audit sign-offs.

—Deterministic status transitions: Draft -> Submitted -> Verified -> Approved -> Disbursed
—Immutable audit logs recording reviewer identity, action, and timestamp
04
TRADEOFFS
ARCHITECTURAL DECISIONS
DECISION 01:Strict State Machine Enforcement at API Layer
RATIONALE:

Relying on frontend UI guards to enforce sequential approvals creates security vulnerabilities if an API endpoint is hit directly.

OUTCOME & ARCHITECTURAL IMPACT:

Enforced validation in Express controllers ensuring state transitions can only execute if the application is in the exact prerequisite state.

05
RESULT
VALIDATION & LESSONS
KEY LESSONS LEARNED:
✓Leading a technical team to design and ship an MVP under intense hackathon deadlines.
✓Architecting multi-role authorization state machines and tamper-resistant audit logs.
✓Translating complex governmental administrative workflows into intuitive digital software systems.
FUTURE HORIZON:
—Automated document OCR verification against government databases (DigiLocker integration).
—Direct Bank Transfer (DBT) payment gateway integration for automated disbursement.
HIMANSHU PATRO

Building systems. Learning in public.
Based in Jamshedpur, Jharkhand, India.

© 2026 HIMANSHU PATRO