Storage

Canonical registrations and process aggregates use explicit repositories; file bytes and global documents remain separate resources. There is no legacy whole-file process service.

Repositories and drivers

The runtime host and non-seeding operator tooling in applications/main/src/composition/application-stores.ts select owner-aware memory, file or Mongo factories from platform/storage. AggregateRepository provides revisioned read/list/compare-and-set/delete; RegistrationRepository retains immutable versions separately from latest-template pointers. The app honors STORAGE_DRIVER, otherwise chooses Mongo when configured and files for local use. Memory is for applications/main/tests/ephemeral use. Importing composition does not seed or migrate data.

File aggregates use encoded records, atomic replacement and filesystem coordination rather than rewriting one unguarded process array. Mongo uses conditional version updates. Tests cover bounded contention/fault windows, but real Mongo configuration and deployment durability require their own verification. Crash-held file locks are deliberately not stolen without operator recovery.

What is persisted

An aggregate retains its immutable execution binding/program, continuation, memory, visit history, field/state audit, public details, pending delivery/hold and child receipts. Registration versions are retained so historical runs do not silently adopt edited execution. Current presentation may be overlaid on public reads while execution and original process mode stay pinned.

A newly saved presentation receives a host modification timestamp and its own identity. Saving presentation does not change execution authority. Edited execution gets a distinct digest; the trusted deployment/registration policy determines its allowed capability scope.

Values, programs and aggregates have explicit size limits and reserve effect-completion headroom. These limits are not retention or compaction. Large real histories need sizing and migration review.

Provisioning and migration

Application initialization publishes each repository registration whose compiled digest differs from the stored latest (templates are code-owned); running processes keep their pinned execution. Reads do not reseed. The standalone backend starts without a shipped app registry; trusted explicit configuration supplies definitions/assets/capabilities. See deployment bindings.

Old process exports are converted offline, create-only by default. Human visits and recorded waits resume without replay; uncertain automatic work is held. Preserve original evidence and copy attachment bytes separately. Do not point old and new writers at the same cutover dataset.

Separate resources

ResourceStorage boundary
Users, organizations, rolesAuth0 adapter/directory
Uploaded file bytesConfigured process-file repository; aggregates contain references
Global JSON collectionsDocument repository, not per-process memory
Protected tokens/signaturesEncrypted capability-bound repository, never ordinary context
Public records/audit/export viewsDerived from canonical process/registration data
Browser sessionsBrowser session adapter

Known gaps

Aggregate listing and scheduler selection still perform scans. Indexed scheduling, retention, operational claim recovery and deployment-specific storage guarantees remain explicit work.