Canonical registrations and process aggregates use explicit repositories; file bytes and global documents remain separate resources. There is no legacy whole-file process service.
The runtime host and non-seeding operator tooling in
applications/main/src/composition/application-stores.ts select owner-aware memory, file or Mongo factories from
platform/storage. AggregateRepository provides revisioned read/list/compare-and-set/delete;
RegistrationRepository retains immutable versions separately from latest-template pointers.
The app honors STORAGE_DRIVER, otherwise chooses Mongo when configured and files for local use.
Memory is for applications/main/tests/ephemeral use. Importing composition does not seed or migrate data.
File aggregates use encoded records, atomic replacement and filesystem coordination rather than rewriting one unguarded process array. Mongo uses conditional version updates. Tests cover bounded contention/fault windows, but real Mongo configuration and deployment durability require their own verification. Crash-held file locks are deliberately not stolen without operator recovery.
An aggregate retains its immutable execution binding/program, continuation, memory, visit history, field/state audit, public details, pending delivery/hold and child receipts. Registration versions are retained so historical runs do not silently adopt edited execution. Current presentation may be overlaid on public reads while execution and original process mode stay pinned.
A newly saved presentation receives a host modification timestamp and its own identity. Saving presentation does not change execution authority. Edited execution gets a distinct digest; the trusted deployment/registration policy determines its allowed capability scope.
Values, programs and aggregates have explicit size limits and reserve effect-completion headroom. These limits are not retention or compaction. Large real histories need sizing and migration review.
Application initialization publishes each repository registration whose compiled digest differs from the stored latest (templates are code-owned); running processes keep their pinned execution. Reads do not reseed. The standalone backend starts without a shipped app registry; trusted explicit configuration supplies definitions/assets/capabilities. See deployment bindings.
Old process exports are converted offline, create-only by default. Human visits and recorded waits resume without replay; uncertain automatic work is held. Preserve original evidence and copy attachment bytes separately. Do not point old and new writers at the same cutover dataset.
| Resource | Storage boundary |
|---|---|
| Users, organizations, roles | Auth0 adapter/directory |
| Uploaded file bytes | Configured process-file repository; aggregates contain references |
| Global JSON collections | Document repository, not per-process memory |
| Protected tokens/signatures | Encrypted capability-bound repository, never ordinary context |
| Public records/audit/export views | Derived from canonical process/registration data |
| Browser sessions | Browser session adapter |
Aggregate listing and scheduler selection still perform scans. Indexed scheduling, retention, operational claim recovery and deployment-specific storage guarantees remain explicit work.