Templates describe behavior; processes execute a pinned compiled definition. Authoring source, executable syntax and presentation are related but different data contracts.
The application editor uses steps[], firstStepKey and explicit links as convenient graph
notation. Its types live in @processos/app-authoring, not Platform. Graph links determine control
flow; array order still affects presentation and compatibility metadata, so do not treat reordering
as a universal no-op.
The authoring compiler expands field macros and integrations into the closed compositional Template language. Primitive and composed templates have the same interface; a provider activity is not a special engine extension. See language model.
A registration separates immutable execution (program, startup expressions, interaction contracts, policy) from versioned presentation. Starting a process pins execution authority. Editing executable behavior does not change existing runs. Capability authority comes from the trusted host registration/provisioning policy, never source or presentation metadata. The main-app compatibility decision preserves existing template-author authority; standalone hosts remain operator-explicit. See the implementation status in deployment bindings.
Public reads may overlay current presentation, while retaining original execution and process mode.
Therefore public process.template is a view, not the authoritative executable snapshot. This does
not promise historical reconstruction of every rendered screen or external response.
Repo source and the editor both produce validated app authoring data, then compile it. The template API accepts a registration, not arbitrary JavaScript or an uncompiled provider graph. AI assistance returns a validated draft; the user still reviews and saves it. See template editor.
An inline template activity carries closed syntax. Historical raw script nodes are accepted only
by the explicit attested migration path; they cannot run as server-side source.
applications/main/src/templates/registry.ts lists the shipped sources. Application initialization inserts missing
registrations without replacing editor changes; reads do not reseed. Explicit seed/update tooling
controls publication of changed definitions. Historical versions remain retained without becoming
latest pointers. See manage templates.
The API checks process-write access and compiled start policy. The compatibility compiler does not
newly enforce source permissions, runInputs or startExpression as start gates. Do not rely on
those authoring fields as security boundaries. First-step defaults and explicit initial values are
handled by compiled startup expressions and authorized service commands.
roles[] maps presentation labels/colors to permission names. Auth0 supplies users, organization
membership and permissions. Step/field contracts and process sharing enforce access; visual role
labels grant nothing on their own.
Applications may import shared constants and public Domain/Integration builders while authoring. Those builders produce data. Credential contents stay in deployment provisioning, never constants, source metadata or compiled ordinary values.
Active/draft/archived is presentation metadata for discovery. Existing process execution remains pinned independently. Saving presentation stamps host modification time without changing execution.
Compiled result controls render public context using the same pure language as other presentation. Safe HTML is sanitized at render boundaries; raw stored/download content is not rewritten.
See expressions. Supported syntax compiles before save; no runtime
Function, eval or native helper registry is available. A source field being round-tripped by the
editor does not mean its product semantics have been enabled.
Source belongs to Applications; generic syntax/contracts to Platform; reusable protocols to Integrations/Domain. The boundary map gives package ownership.
enabledExpression remains compatibility metadata without execution gating. External/editor-created
historical definitions require offline validation before migration; repository coverage is not their census.