Current architecture status and handoff

This page distinguishes the implemented closed-language rewrite from the remaining review, packaging and rollout work. It does not authorize publication or a production cutover.

Implemented endpoint

The organizing groups are Platform, Integrations, UI, Domain and Applications. Platform owns the SDK and executor together. Templates are inspectable descriptions; a Process is one execution. Simple and composed templates share the same compositional interface.

The application API, worker, editor, generic frontend and bespoke applications consume compiled registrations and canonical Process views. Native provider handlers, callback-based expression registries, arbitrary script execution, old Domain algorithm implementations and obsolete SDK provider-step unions have been removed. Application graph source is owned by the small app-authoring library; Integrations owns provider configuration shapes, Domain owns field macros, and Platform owns only generic fields, closed syntax and generic effects.

All 13 shipped templates compile to serialized executable definitions. The thirteen attested historical script bodies and the known app display IIFEs have explicit closed replacements. Domain regression evidence includes 384 source-hashed frozen synthetic outcomes plus independent EVM/Solana codec checks. Frozen evidence is test data, not a second executable implementation.

Named visits, interaction permissions, sparse field audit, raw state changes, lifecycle commands, files, records, and detached children use one canonical application service. Child creation has occurrence receipts and pinned definitions. Offline conversion preserves recorded history and human/wait continuations without replay; uncertain automatic work is held for reconciliation.

See language model, coverage, boundaries and deployment bindings.

Explicit safety corrections

Four changes were approved separately from compatibility preservation:

  • Uncertain external outcomes stop for reconciliation rather than risk duplication.
  • Invalid uint64 Solana amounts are rejected; valid-input floating rounding is preserved.
  • Automatic work cannot be bypassed by manually completing its activity through the API.
  • Executable HTML is removed at render boundaries; stored values and download bytes are unchanged.

Host-dependent datetime parsing is a recorded generic effect. It is not an ambient timezone read inside a pure expression. Known definitive failure policies are expressed by closed recovery/backoff composition, separately from uncertain transport outcomes.

Local evidence and remaining acceptance

The complete npm run verify gate passed locally on the frontend endpoint at 1cb0803, using synthetic fixtures across all 27 verification stages:

  • Fresh builds and public dependency/ownership checks for all 16 library workspaces.
  • 879 library tests and 583 main tests with coverage, plus source/configuration/script typechecks.
  • Packed SDK, runtime, language and headless browser-session consumers without sibling source imports.
  • Main production build, owned documentation assets, direct/external-cwd CSS parity, 24 compiled HTTP checks and four real browser journeys covering Spell and independent generic application mounts.
  • Independently installed Main, Spell, Allocation Risk, generic frontend and backend projects using packed public dependencies. Bespoke artifacts reject generic/other frontend dependencies; the generic artifact excludes bespoke, Domain and Integration packages.
  • Canonical-backend start/save/reload/completion/audit/export journeys; actual 31-activity Allocation Risk execution with role/field permissions and file upload/download; controlled-worker and app-owned question/routing/private-note extension probes.
  • Signed synthetic OAuth mount/code-exchange checks and deterministic delayed-response regressions.
  • Chromium execution of the portable reducer and browser/SSR sanitizer fixtures.

Default and Allocation Risk legacy deployments also passed their own production builds, CSS checks and 24 compiled HTTP checks each. The Spell deployment was restored and its four browser journeys passed again. The final documentation-only checkpoint records this evidence; it does not alter the tested implementation.

Independent reviews also checked the retired native paths, template-author capability compatibility, immutable cache safety and mechanical folder/cwd changes. This is local evidence, not hosted CI, live-provider or production-data certification. See verification.

The physical five-group layout is present: platform/, integrations/, ui/, domain/ and applications/. Main is a separate application workspace; the root owns orchestration only. The follow-up architecture review approved independent Spell and Allocation Risk frontends and a bounded generic frontend. That ownership slice is implemented and locally verified; see frontend ownership.

Previously unfulfilled product features remain distinct: Spell capability probes cover review/Q&A, private notes and cycle-move requirements without claiming those features are fully mounted. Platform follow-ups include stronger durability, reconciliation, bounded retries, retention and parallel execution.

Review and rollout gates

  • Review the final diff and verify the exact candidate using hosted checks or the approved manual release gate, with separate hosted acceptance.
  • Dependency remediation upgrades Next/React and affected build/editor dependencies. The September 23 clean-lock audit reports zero runtime advisories, with nine development-only Solana reference-test package entries retained under a documented exposure assessment. See dependency security. Rerun the audit and exact-head gate before release; local results do not replace real hosted acceptance or independent approval.
  • Publication is a separate maintainer action; local success does not authorize a merge or deployment.
  • Verify hosting build roots, workspace installation and artifacts on the deployment host.
  • Verify actual Auth0 origins, callbacks, organizations and session/impersonation settings in an authorized environment. Synthetic identity fixtures do not establish real tenant behavior.
  • The authorized rehearsal export is fully convertible and has passed isolated Mongo import/readback and repeat-import checks. A final quiesced export and attachment-byte backup remain required. Preserve original evidence; do not run old and new writers together.
  • Provision explicit capabilities, encryption keys, the intended registration-authority policy and shared durable storage. The standalone backend has no built-in application registry.
  • Document reconciliation, rollout and rollback, including irreversible external actions. Code rollback is not data rollback. No production records have been migrated by this development work.

Migration compatibility follow-up

The authorized September 23 rehearsal export exposed older script variants, display IIFEs, obsolete metadata and a retired Notion record step not covered by the original synthetic snapshot matrix. Offline adaptations now preserve these as closed definitions rather than executing historical source. The rehearsal converter accepts all 122 exported processes and 13 latest templates without holds or rejects. These counts describe that snapshot only, not a final quiesced production backup.

The CLI reports all template/process failures together, blocks import for unresolved records, and supports explicit create-only Mongo import with redacted driver errors. See closed-runtime cutover. All 122 aggregates and 13 latest registrations passed canonical-hash readback in an authenticated loopback Mongo rehearsal; a repeat created no records. All 54 running processes retain their awaiting-input visits and historical context/results/timestamps remain preserved. No external effects ran in that rehearsal.

Real configuration/key provisioning, attachment backup, final exact-head verification, hosted CI, and coordinated activation remain separate acceptance gates. No production migration or deployment has been performed.

September 23 release-preparation verification

The dependency/framework slice passed the complete 27-stage local gate on Node 22.23.2, including 881 library tests and 619 main tests with coverage, packed consumers, production HTTP/browser checks and independently installed Main, Spell, Allocation Risk, generic frontend and backend projects. The final RPC-preflight parser correction was reviewed separately and passed both affected suites (17 tests). After that correction, Main typechecks and all 620 tests with coverage passed again; default, Allocation Risk and Spell profiles each passed a production build, CSS parity and 24 compiled HTTP checks. The final Spell build also passed all four browser journeys. Boundary and documentation checks passed. These are synthetic/local proofs, not live tenant or provider acceptance.

The non-mutating preflight was also run inside each of the four existing production services. It reports the two new protected-store keys as missing and no other configuration-shape failure for the selected roles/capabilities. Sealed Railway credentials are present at runtime even when omitted from control-plane listings. No keys or production configuration were changed.

Default-only application access and review remediation

The required application-access model separates deployment ownership from participant affiliation. Main, independent backend and worker share it; the opt-in/legacy branch has been removed. The CLI requires an explicit ownership map and uses owner-aware stores. Provider accounts remain in place. App grants are scoped email-to-role declarations; operator grants are separate.

The candidate also adds browser-bound OAuth state, stream-bounded uploads and activity/field-aware file deletion. Legacy attachments require reviewed ownership metadata before deletion can be enabled. These changes are local candidates, not production fixes. Production additionally needs the required access policy and reviewed migration, beyond the earlier protected-key preflight findings.

See review disposition for Lako's items and remaining activation gates. Current verification evidence is recorded per candidate; earlier green gates do not certify subsequent uncommitted edits.