Processes

A Process is one execution with pinned authority, mutable memory, occurrence history and explicit pending effects. The public Process view is not the stored machine representation.

Step instances, not step keys

Each named activity visit has its own id. Commands address that visit id rather than the shared activity key. Rework/reopen creates another visit, while values still live in a step-key bucket. The canonical service tracks the active visit explicitly. Historical imported visits may lack entry or completion actor timestamps; conversion preserves absence rather than inventing evidence.

// Public step projection: completion fields are present only with actual completion evidence.
{ id: 'visit-id', processId: 'process-id', stepKey: 'review', updatedUTC: '2026-01-01T00:00:00Z' }

Context — where answers accumulate

Context is JSON memory keyed by activity key. Authorized human updates and explicit template state operations change it. Past edits do not replay external effects. Protected secrets/signatures/tokens are not context values. Completion results and generic resource storage are separate concepts.

The audit trail

The service writes sparse field audit for meaningful changes and retains raw state changes as execution evidence. Legacy full-bucket audit is reduced once by offline conversion; new public stepContextAudit is empty. This is not an immutable compliance log, compaction policy, or a promise that current presentation reconstructs every old screen.

Status

The machine distinguishes success/failure/waiting. The compatibility API still presents running or completed plus error; records derive failed outcome from the error. Reconciliation/resource holds surface attention and prevent normal bypass. Check both status and error when summarizing outcomes.

Delivery warnings

Failed/partial notifications appear in canonical automationWarnings; UI/backend no longer parse provider-specific context buckets for warning policy. Offline conversion materializes old warnings, including undated entries. New annotations get verified host time. Successful delivery may remain visible through compiled audit presentation, not native provider dispatch in the UI.

The embedded template

The public template is presentation over a pinned execution binding. Current presentation may be overlaid, but execution and original process mode stay fixed. Stored registrations retain immutable versions separately from current-template pointers. See templates.

Who can see it

Process ownership, explicit sharing, permissions and activity/field contracts decide access. Contributor links do not authorize unauthenticated writes. Impersonation uses the effective identity; consult roles and sharing.

Lifecycle

Start, edit, complete, abandon, reopen and sharing changes use the canonical command service and revision-checked persistence. Only real human interaction points may be completed manually; an automatic visit is not a shortcut around a provider action. The worker drives automatic effects.

Files

Context holds metadata references; attachment bytes live separately and access is authorized by the service. Offline migration preserves references, not bytes: transfer and verify the file repository independently. See deployment migration.


Known gaps

History has explicit size bounds, not unlimited retention. Transparent recovery, claim reconciliation and compaction remain follow-up work. Public two-state status still requires consumers to inspect error.