RFQ B26085 · Website Redesign & Development · City of Dover, New Hampshire
A modern dover.nh.gov
on a platform, not a project.
Drupal — the proven open-source government CMS — on managed, SOC 2 hosting. Configured for Dover, easy for department staff to run, and built to stay accessible and secure without a standing custom-development budget. And it's already standing: you can click through it today.
Josh Tate · Jay Callicott · Lee Quessenberry
(870) 530-4565 · onesimplespark.com
Today's conversation
Your eight questions, in your order — with the working site alongside.
- 01
Platform fit
Why Drupal suits a city of Dover’s size — and keeps custom code small.
- 02
Design, IA + UX
Organized around what residents need to do, not the org chart.
- 03
Migration + governance
500+ pages, 3,372 PDFs, and how content stays current after launch.
- 04
Accessibility
WCAG 2.2 AA at launch, and kept there afterward.
- 05
Security + reliability
Hosting, access control, support and uptime.
- 06
Integrations
Tyler, Harris, VueWorks, WebTrac, e360, DocuPhase, Viebit…
- 07
Meetings, records + modules
RSA 91-A notice, Right-to-Know requests, alerts and notifications.
- 08
Timeline + training
Live within six months; staff confident on day one.
Who you'd work with
Creative delivery, senior Drupal, government at scale.
Josh Tate
Client & Delivery Lead — 20+ yrs brand & marketing
Founder & Creative Director, Simple Spark. Prior: SVP / Chief Marketing Officer, First Community Bank; Principal Brand Strategist, The Solutions Group; Director of Marketing & Communications, Lyon College.
On Dover: Single point of contact — stakeholder communication, design direction, training, and handoff through launch and support.
Jay Callicott
Senior Drupal Architect — 20+ yrs enterprise Drupal & PHP
Senior Backend / AI Engineer, MMGY Global. Prior: Head of Engineering / VP Tech Ops, Mediacurrent — Lead Architect for Georgia.gov (55+ agency sites), Vanderbilt Medical Center, the NFL Clubs Platform. Certified Acquia Developer.
On Dover: Owns the platform architecture, hosting and security.
Lee Quessenberry
Senior Drupal Developer — 18+ yrs content-managed web
Senior Drupal Architect, Quest Software. Prior: Drupal Developer, Esteemed Inc.; Software Engineer III (Drupal). Deep focus on content-rich, accessible (WCAG) front-ends, with a focus on document-heavy public-sector sites.
On Dover: Owns the content model, integration wiring, and the content + document migration.
One in-house team, no sub-consultants. Georgia.gov — 55+ agency sites on one accessible, content-managed Drupal platform — is the closest analog to Dover's mix of departments, boards and services.
01 · Recommended platform
Drupal: the established government CMS — sized right for Dover.
You asked for a proven, supported platform over a custom build. Drupal is that platform: open source, maintained by a global community with a dedicated Security Team, and running federal, state and municipal sites across the country — including Georgia.gov, which Jay architected.
Hundreds of pages, dozens of editors
Structured content types for departments, meetings, news, services and documents. Scales from 500 pages to 5,000 without re-platforming.
Department editors + approval
Roles, department-scoped access and a draft → review → publish workflow are standard modules — configured, not coded.
Seven domains, one site
Arena, pools, youth, wireless, Driving Dover and Locate in Dover come in as sections, with permanent redirects from the old domains.
No license, no lock-in
No per-seat or per-module fees. The City owns the code, content and data; any Drupal firm can maintain it.
01 · Minimizing custom development
Almost everything Dover needs is already built — and someone else maintains it.
The site is four layers. Only the thin top layer is ours to write — the City's look and templates. Everything beneath it is supported platform that updates through standard, security-covered releases.
- Workflow, permissions, revisions, media, search, forms, redirects, scheduling — all supported core or contributed modules.
- Dover’s content types and roles are configuration, exported and version-controlled — not code.
- Upgrades are routine: Drupal 10 → 11 was an in-place update, not a rebuild.
- Adding a department, board, service or page never needs a developer.
Ours — the thin layer
Dover design + page templates
Brand, layout and components — accessible by construction, documented in a style guide.
Configuration
Dover’s content model, roles + workflow
Departments, meetings, news, services, alerts, documents; editor and approver roles.
Supported modules
Drupal core + contributed modules
Content Moderation, Workflows, Media, Views, Webform, Search API, Redirect, Scheduler, Workbench Access, Editoria11y, Metatag, TFA.
Managed platform
Pantheon managed hosting
Servers, CDN, backups, patching and monitoring — run by the host, not by the City or by us.
02 · Design + user experience
A resident's top tasks, answered above the fold.
The pilot is built from a crawl of dover.nh.gov — real departments, real services, Dover green and civic gold, and the City seal. It's a working starting point for discovery, not a final design.
- Pay a Bill and Report a Problem in the header on every page.
- Resident-service grid: permits, meetings, records, recreation, jobs.
- One-click alert banner for closures and emergencies.
- Mobile-first: the same templates at every screen size.
02 · Information architecture
Five resident-first sections — reachable by task or by department.
The crawl found 500+ pages in a deep tree with no navigation landmark. The same content is reachable from Services (by task) and Government (by department), so nobody needs to know the org chart to get help.
Services — by task
Pay, permit, report, register — each a plain-language card, tagged with the portal it opens.
Government — by department
Council, boards and every department on one consistent template.
Directory — by person
A searchable staff and department directory replaces scattered contact pages.
Discovery confirms it with you: stakeholder interviews, a card sort with department webmasters, and top-task analysis from your analytics before a single template is locked.
03 · Content migration + documents
We've already inventoried your site. Migration starts from data, not guesswork.
- 0+
- pages crawled and mapped to the new structure
- 0
- PDFs found — each one triaged, not blindly copied
- 0
- secondary domains consolidated with redirects
- 0
- broken links at launch — every old URL redirects
Document triage
Keep + convert
High-traffic PDFs that are really web content (forms guides, fee schedules, how-tos) become accessible web pages.
Document triage
Keep + remediate
Documents that must stay documents are tagged, checked for accessibility, and remediated or flagged.
Document triage
Archive
Outdated items move to an archive per the RSA 33-A retention schedule, or stay in DocuPhase as the system of record.
Document triage
Retire
Duplicates and superseded files are retired, and their old URLs redirect, so nothing breaks.
Documents live in Drupal's Media Library with department, type and date metadata, so they're searchable and reusable; replacing a file updates it everywhere it's linked. Pages and documents migrate by script, and each department signs off on its own section before launch.
03 · Long-term content governance
Launch is easy. Year three is the test.
Most city sites decay because nobody owns a page and nothing tells anyone when it's stale. The governance model is built into the CMS, not kept in a binder.
Every page has an owner
Each page belongs to a department, and only that department’s editors can change it.
Nothing publishes unreviewed
Editors draft, approvers publish. Every change is a revision with who and when, and can be rolled back.
Stale content surfaces itself
A “not updated in 12 months” report per department, and scheduled unpublish dates for time-bound content.
Guardrails, not blank pages
Structured fields and a component library keep pages consistent and accessible, whoever writes them.
A written playbook
Web style guide, roles and responsibilities, and a publishing checklist, handed to Media Services.
Quarterly health check
We review accessibility, broken links, stale pages and analytics with Media Services every quarter.
04 · Accessibility
WCAG 2.2 AA at launch — and a system that keeps it there.
The DOJ's ADA Title II rule requires WCAG 2.1 AA for city websites and documents, with April 2028 as the date for a city of Dover's size. We build to 2.2 AA, which goes beyond that.
- Build gate: automated axe-core checks run on every change. A violation blocks the release.
- Editor gate: Editoria11y flags missing alt text, skipped headings and vague link text while staff are writing.
- Human gate: keyboard and screen-reader testing on every template before launch.
- Ongoing: a compliance dashboard in the CMS, re-audited continuously, and reviewed with you every quarter.
- Documents: PDF triage and remediation are part of migration, not left for later.
500/500
current pages with no main landmark or skip link
~1,000
current form inputs with no label
0
axe violations on the pilot · 14/14 pages
05 · Security + hosting
Managed, audited hosting — and a CMS with a security team behind it.
Hosting
Pantheon managed cloud
SOC 2 Type II audited and TX-RAMP Level 1 certified. Global CDN, isolated containers, automated platform patching, built-in dev/test/live environments.
Platform
Drupal Security Team
Coordinated security advisories for core and covered modules. We apply them under the support plan, tested first, usually within days.
Access
MFA, roles + audit trail
Two-factor login for all staff, single sign-on through the City’s identity provider (e.g. Microsoft Entra ID) where wanted, least-privilege roles, a full revision log.
Data
The City owns it
Encrypted in transit and at rest. Nightly backups with retention, a documented data location, and a full export available at any time, including on termination.
Continuity
Built to stay up
Redundant infrastructure with an uptime SLA, CDN caching that keeps pages serving through traffic spikes, a tested restore procedure, and monthly traffic reports.
Agreement
Attachment C, signed
Vendor Cybersecurity Agreement accepted: 24-hour breach notification, encryption and audit logging. The public site holds no CJIS, HIPAA or sensitive PII.
Hosting is the City's choice, not a lock-in: the same Drupal site runs on Pantheon, on Acquia (including its FedRAMP-authorized government cloud), or in a City-managed AWS or Azure account.
05 · Support + reliability
After launch, you talk to the people who built it.
The ongoing plan covers hosting, security and core updates, accessibility monitoring and a block of content and enhancement hours. It's priced in the cost proposal.
- 30 days of hands-on post-launch support included.
- Security and core updates included, tested on a staging copy before going live.
- Uptime and error monitoring with alerts to us, not to your staff.
- Escalation path: support desk → Lee → Jay, with named people and no call center.
| Severity | Example | Response |
|---|---|---|
| 1 · Critical | Site down, security incident, emergency alert can't publish | 1 hour, 24/7 |
| 2 · High | Key feature broken (meetings, forms, search) | 4 business hours |
| 3 · Normal | Bug or editor question | 1 business day |
| 4 · Request | Enhancement or new content type | Scheduled with you |
Proposed targets. Final SLAs are set in the cost proposal and support agreement.
06 · Integration with your systems
Keep the systems that work. Make the website the front door to all of them.
We don't rebuild Tyler or Harris. Residents get one consistent entry point, and we connect more deeply through APIs only where it clearly helps.
Tyler Enterprise Permitting
Permits + inspections
Linked portal · SSO where supported
Harris eGovern
Online payments
Pay a Bill, sitewide
VueWorks
Report a Problem
Linked portal
Vermont Systems WebTrac
Recreation registration
Linked from Recreation pages
e360
Charter + Code of Ordinances
Deep links / embed
OnPhase (DocuPhase)
Document repository
Links + API search where feasible
Viebit
Meeting video
Embedded on each meeting
Constant Contact + SMS
Email + text alerts
Signup + publish-to-notify via API
Sitewide search covers every page and document, and can extend into connected systems where they expose search. The RFP invites platform-native alternatives: forms and the alert banner are built in, and anything else we'd replace is a discussion, not a default.
07 · Meeting management
One record per meeting. The calendar, homepage and archive update themselves.
- Council, Planning, Zoning, Conservation, School Board: every body has the same structure.
- Agenda, packet, minutes and Viebit video attach to the meeting record.
- Scheduled publishing: post the agenda now, and it goes public at the notice time you set (RSA 91-A).
- A searchable archive across years, kept to the RSA 33-A retention schedule.
- Residents can subscribe to a board and get an email when its agenda posts.
- Already use, or plan to adopt, an agenda-management system? We pull from its feed instead of duplicating it.
07 · Public records, notifications + modules
Capabilities you turn on — not features we have to write.
Right-to-Know (RSA 91-A)
Public records requests
Light volume: a Webform request with routing to the right department, a confirmation and a five-business-day reminder, built in.
Full lifecycle (tracking, redaction, delivery, a public archive): we integrate a dedicated records platform, and the site publishes completed requests where appropriate.
Notifications
Alerts that reach people
One switch turns on the sitewide alert banner. The same publish can push to Constant Contact and your SMS service, so residents opted in by topic (road closures, trash schedule, a specific board) hear about it without staff posting three times.
Forms + services
Forms without developers
Webform lets Media Services build accessible forms (contact, applications, sign-ups, surveys) with routing, file uploads and spam protection. No code and no per-form fees.
Supported Drupal core and contributed modules: open source, security-covered, and maintained by the Drupal community.
For department webmasters
Editing is filling in a form. Publishing is a click by the right person.
- Labelled fields instead of a blank page: date, board, agenda, packet, video.
- A Planning editor sees and edits Planning content only.
- Draft → Needs Review → Published, with notes back to the author.
- Preview before publishing; schedule publish and unpublish dates.
- Every revision kept and comparable, so any change can be undone.
08 · Timeline + implementation
Live within six months, starting from a working site rather than a blank page.
- 1
Month 1
Discovery + IA
Kickoff, stakeholder and webmaster interviews, content inventory against the crawl, IA and card sort, plus the domain and redirect plan.
- 2
Months 2–3
Design + CMS
Visual design reviewed on the working site; content model, roles, workflow and department access configured on the platform.
- 3
Months 3–5
Build + migrate + connect
Templates built; pages and documents migrated with department sign-off; Tyler, Harris, VueWorks, WebTrac, e360, Viebit, DocuPhase and notifications connected.
- 4
Month 6
Beta, train + launch
Beta for City review, accessibility and screen-reader QA, staff training, DNS cutover, redirects live, monitored launch.
How we work with you: one point of contact (Josh), a standing weekly check-in, a shared project board the City can see, and a working staging site from week one, so feedback is on real pages and never on static comps.
08 · Training approach
Training by role, on your own content, before launch day.
Department editors
Write, update, submit
Hands-on in a training copy of the real site: edit your department page, post a meeting, add a document, submit for review.
Approvers + Media Services
Review, publish, govern
The approval queue, scheduling, alerts, forms, menus, the compliance dashboard and stale-content reports. Train-the-trainer, so Dover can onboard new staff itself.
IT
Run and own it
Hosting, access and SSO, backups and restore, the update process, and the full handoff of code, credentials and documentation.
Recorded walkthroughs for every common task, for new hires later.
One-page quick-reference cards, printable, for each role.
Office hours through the 30-day post-launch period.
Let's click through it
Draft, review, publish — live.
- 1 A resident looks for the next City Council meeting and its packet.
- 2 A Planning editor adds an upcoming meeting and submits it for review.
- 3 An approver reviews it, schedules it and publishes it.
- 4 It appears on the meetings page and in the archive, with no developer involved.
Thank you
A great place to live, work, and play — online, too.
A proven platform, configured for Dover, that your staff can run and your IT team can trust, live within six months. The pilot is open to everyone on the panel: click through every page.
Josh Tate · Founder & Creative Director
(870) 530-4565 · josh@onesimplespark.com · onesimplespark.com