A Process is one execution with pinned authority, mutable memory, occurrence history and explicit pending effects. The public Process view is not the stored machine representation.
Each named activity visit has its own id. Commands address that visit id rather than the shared activity key. Rework/reopen creates another visit, while values still live in a step-key bucket. The canonical service tracks the active visit explicitly. Historical imported visits may lack entry or completion actor timestamps; conversion preserves absence rather than inventing evidence.
// Public step projection: completion fields are present only with actual completion evidence.
{ id: 'visit-id', processId: 'process-id', stepKey: 'review', updatedUTC: '2026-01-01T00:00:00Z' }
Context is JSON memory keyed by activity key. Authorized human updates and explicit template state operations change it. Past edits do not replay external effects. Protected secrets/signatures/tokens are not context values. Completion results and generic resource storage are separate concepts.
The service writes sparse field audit for meaningful changes and retains raw state changes as
execution evidence. Legacy full-bucket audit is reduced once by offline conversion; new public
stepContextAudit is empty. This is not an immutable compliance log, compaction policy, or a promise
that current presentation reconstructs every old screen.
The machine distinguishes success/failure/waiting. The compatibility API still presents running
or completed plus error; records derive failed outcome from the error. Reconciliation/resource
holds surface attention and prevent normal bypass. Check both status and error when summarizing outcomes.
Failed/partial notifications appear in canonical automationWarnings; UI/backend no longer parse
provider-specific context buckets for warning policy. Offline conversion materializes old warnings,
including undated entries. New annotations get verified host time. Successful delivery may remain
visible through compiled audit presentation, not native provider dispatch in the UI.
The public template is presentation over a pinned execution binding. Current presentation may be overlaid, but execution and original process mode stay fixed. Stored registrations retain immutable versions separately from current-template pointers. See templates.
Process ownership, explicit sharing, permissions and activity/field contracts decide access. Contributor links do not authorize unauthenticated writes. Impersonation uses the effective identity; consult roles and sharing.
Start, edit, complete, abandon, reopen and sharing changes use the canonical command service and revision-checked persistence. Only real human interaction points may be completed manually; an automatic visit is not a shortcut around a provider action. The worker drives automatic effects.
Context holds metadata references; attachment bytes live separately and access is authorized by the service. Offline migration preserves references, not bytes: transfer and verify the file repository independently. See deployment migration.
History has explicit size bounds, not unlimited retention. Transparent recovery, claim reconciliation and compaction remain follow-up work. Public two-state status still requires consumers to inspect error.