docs: reconcile account-scoped execution decisions
This commit is contained in:
1 parent
d09b3032c0
commit
b7bb1d6b52
11 files changed
+101
-24
No files matched your search
@@ -17,12 +17,15 @@
|
||||
| Operational diagnostics | Service, request, task, parser, AgentBus, attachment, database, and cleanup stages | Structured stdout/stderr and bounded Docker logs | Correlation identifiers, codes, outcomes, and durations only; no secrets or business payloads. |
|
||||
| Platform operations oversight | Manual task creator, encrypted instruction history, and readable outcome | Team-lead/administrator leadership projection | Display-only summaries plus explicit filters drive an aggregate-first task/person/input/output/time/type/completion view; list reads are bounded to one read-only connection and hydrate full details only for the current page. |
|
||||
| Browser worker selection | Immutable task assignee | One fresh account-bound browser connection | The heartbeat must match the account's expected ERP identity; a second fresh worker or identity mismatch is non-executable, with failover only after staleness. |
|
||||
| Account-scoped ERP queue | Confirmed task assignee | Assigned account's browser worker | Organization-plus-account advisory locking preserves FIFO and at most one active execution for that account; another account's active, queued, stale, or uncertain work is outside this queue. |
|
||||
| Executable event and result routing | Immutable task assignee | Matching authenticated platform page and plugin | SSE history/live events, claims, plugin results, and browser cleanup commands never use administrator-wide visibility and fail closed when the authenticated account is not the assignee. |
|
||||
| Task removal | Authorized operator | Archive/restore or permanent force delete | Archive/restore remains reversible and state-gated. Explicit force delete has no lifecycle-state gate, removes task-owned platform records atomically, retains a minimal deletion audit marker, and performs post-commit artifact/plugin cleanup best effort. |
|
||||
| Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF |
|
||||
| Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames |
|
||||
|
||||
## State Ownership
|
||||
|
||||
- PostgreSQL owns durable control-plane account, role, expected ERP identity, task-route grant, AgentBus channel owner, immutable task assignee, browser worker, session, confirmation, audit, archive, and outcome state.
|
||||
- PostgreSQL owns durable control-plane account, role, expected ERP identity, task-route grant, AgentBus channel owner, immutable task assignee, account-scoped queue/lease state, browser worker, session, confirmation, audit, archive, and outcome state. A force-deleted task no longer exists in task state; only its minimal non-content deletion audit marker remains.
|
||||
- Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted.
|
||||
- Chrome extension local state is bounded execution/reconciliation support, not canonical business history.
|
||||
- `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection.
|
||||
@@ -36,4 +39,4 @@
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-09-01
|
||||
2026-09-03
|
||||
Reference in new issue
Block a user