Most new behavior should be a reusable closed Template composition, not a new Platform opcode or provider handler. Read the language model first.
Provider protocol belongs in Integrations; shared business/chain concepts in Domain; application policy in Applications. Platform remains independent of all three. Decide whether a known failure returns a warning, fails the process, or enters explicit recovery/backoff. Uncertain external outcomes must remain held; a recovery branch is not permission to replay uncertain writes.
A library authoring function returns Template/Expression data. For example:
import { compose, pure, input, operation, literal } from '@processos/contracts/language';
const increment = pure(operation('add', input, literal(1)));
const twice = compose(increment, increment);
// JSON.stringify(twice) contains the complete executable description.
Use generic effects for HTTP, protected signing/derivation, records and child creation. Credential contents never enter ordinary expressions. Configure approved references and endpoint policies at deployment; see bindings. A genuine new primitive requires precise semantics, validation, resource bounds and tests—not an escape hatch for arbitrary code.
The app-owned graph model in applications/authoring-model/src/index.ts may expose convenient source notation.
Provider configuration-only types live in integrations/providers/src/authoring.ts; generic field types
live in platform/contracts/src/authoring-fields.ts. Do not add provider unions to Platform.
Wire author-time lowering in the app compiler, then presentation metadata in
applications/main/src/operator-ui/metadata.ts and editor conversion/configuration controls. An inline
template activity already accepts closed syntax, so every reusable process need not introduce
a new editor discriminant. Preserve source→editor→source round trips and compile before save.
Test serialized execution through only Platform packages, success/failure paths, credentials, uncertain outcomes, resource bounds, context/audit shape and editor round trips. Use synthetic transports and independent byte encoders where relevant. Run package gates and the full verification guide. Do not call live providers or publish a definition simply to make a local test pass.