An offline-first audit app must behave as if the network never existed, and then make the network's return invisible. That requirement shapes the entire stack - not as a "sync feature," but as the default mode of operation.
The local-first contract
Everything the auditor touches lives locally first. Checklist definitions, template structure, and prior progress cache on the device as soon as the worklist loads, so a site with no signal is a non-event. Answers persist to the device on every save - not buffered in a queue to be sent later, but stored as the durable record, with the sync as a reflection of that durability. The auditor can close the app, lose the network, even kill the phone, and resume exactly where they left off.
Capture is device-native
Evidence capture is the strain test. Photos, audio clips, signature strokes, scans, and GPS fixes all capture and store on-device, each with its capture timestamp attached at the moment of creation - so the record reflects when the evidence was taken, not when the device happened to upload it. Media is transcoded and constrained at capture (size caps, dimension downscaling) so the eventual upload is efficient rather than heroic.
Reconciliation without ceremony
The sync engine's job is to make the network's return anticlimactic. Completed answers upload in the background, in order, resumable and idempotent - a retried upload can never duplicate an answer. Conflicts are designed out at the model level for the field's actual usage: an audit's answers are owned by its instance, and submission is a one-way gate, so "two devices editing the same checklist simultaneously" does not exist as a scenario the platform must arbitrate. The only user-visible artifact is a state dot: synced, pending, queued - and even that is informational, because nothing about the workflow changes while it is pending.
What it costs to get right
Offline-first is not a mode; it is a testing posture. The test suites exercise capture and submission with the network dead - the client, the service worker, and the server all run against offline scenarios as a first-class case, not an afterthought. The result: an app whose offline behavior is not "a limited version," but the identical product minus the latency.
For the auditor at the bottom of the basement with a dying signal and a checklist to complete, the architecture's entire ambition is to be un-noticed. That invisibility is the feature.