docs: reconcile account-scoped execution decisions

This commit is contained in:
inman committed 2026-09-03 09:56:19 +08:00
1 parent d09b3032c0
commit b7bb1d6b52
11 files changed
+101 -24

No files matched your search

@@ -2,7 +2,7 @@
## Current Architecture
Authenticated manual or account-bound AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns account, channel owner, immutable task assignee, browser worker, session, task-type authorization, confirmation, audit, and archive state. The Chrome extension verifies the expected ERP account, resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
Authenticated manual or account-bound AgentBus input is routed through task-scoped AI/Shadow/Auto/Program orchestration into one validated operation contract. The control plane owns account, channel owner, immutable task assignee, account-scoped execution queue, browser worker, session, task-type authorization, confirmation, audit, reversible archive, and explicit force-delete behavior. The Chrome extension verifies the expected ERP account, resolves the unique ERP object, enforces page and write gates, performs native actions, and returns action-specific evidence.
## Main Components
@@ -26,8 +26,9 @@ Authenticated manual or account-bound AgentBus input is routed through task-scop
- The leadership dashboard is an aggregate-first projection across task, person, original input, final output, time, task type, and completion state. Summary cards are display-only; filtering is explicit and defaults to all results. List reads use one bounded read-only database transaction, SQL prefiltering, selective historical-message hydration, and full detail projection only for the current 20-row page. Its drill-through stays business-facing; technical payloads, internal identifiers, machine-shaped historical input, and technical failure text remain in separate authorized audit/engineering surfaces.
- Authorization is enforced in server and service paths, not by navigation visibility. A denied or unresolved non-admin business route stops before parsing, plugin dispatch, and ERP execution; creator authorization is rechecked at confirmation and browser claim.
- Each enabled AgentBus channel owns one active non-admin employee account. Inbound work uses that account and route allowlist, persists the same account as immutable task assignee, and is returned only to that account's executable feed.
- Each employee account has one expected ERP identity and at most one fresh browser execution worker. Mismatched ERP identity, concurrent fresh workers, unbound channels, or unassigned tasks fail closed; stale-worker failover does not weaken organization-wide ERP FIFO serialization.
- Creator and manual input-turn attribution remain durable while business input stays encrypted at rest. Routine removal is reversible archive/restore; physical purge is not an operator capability.
- Each employee account has one expected ERP identity and at most one fresh browser execution worker. Mismatched ERP identity, concurrent fresh workers, unbound channels, or unassigned tasks fail closed. Browser claims, active-execution checks, and confirmed FIFO are serialized per immutable task assignee, so one account cannot block or occupy another account's queue.
- Administrator-wide task visibility is a read model, not an executable feed. Task SSE history/live events, browser claims, plugin-result ingestion, and browser cleanup commands are always scoped to the authenticated account matching `assigned_user_id`, including for administrators.
- Creator and manual input-turn attribution remain durable while business input stays encrypted at rest. Routine removal is reversible archive/restore. Separately confirmed force delete physically removes an authorized task regardless of lifecycle state, retains only a minimal non-content deletion audit marker, and cannot undo an ERP write that already occurred.
- Unknown, ambiguous, unverified, or post-write-uncertain states fail closed; automatic retries must not create duplicate writes.
- PostgreSQL is the sole required durable database/state middleware, and the production artifact provider is OSS. Redis, message queues, MongoDB, and search services are not runtime dependencies.
- Migrations through `018_agentbus_account_workers` must complete before the updated application starts. The current ACK topology starts with one application replica because AgentBus listeners and SSE emission are process-local; horizontal scale requires explicit coordination first.
@@ -44,7 +45,8 @@ Authenticated manual or account-bound AgentBus input is routed through task-scop
- SAFETY-001
- NETWORK-001
- AUTH-001
- AUTH-002
## Last Updated
2026-09-02
2026-09-03