# Data Flow ## Primary Flows | Flow | Source | Destination | Notes | |---|---|---|---| | Business directive | Manual workbench or AgentBus | Route orchestrator | Source changes input/reply adaptation, not parser or confirmation policy | | Parsing | Route orchestrator | AI Skill or deterministic Program parser | AI/Shadow/Auto/Program mode is frozen per task | | Operation | Parser | Control-plane task and confirmation | Must validate against the same final contract | | ERP execution | Confirmed task | Chrome extension and logged-in ERP page | Requires unique object, page identity, ownership, and write preflight | | Completion evidence | ERP response/requery | Control-plane receipt and business reply | Evidence is action-specific; uncertain writes fail closed | | Passenger workbook | Single `.xls/.xlsx` attachment | Deterministic encrypted canonical TSV | First row ignored, second row fixed header, exact leader-contact rules | | Confirmation export | ERP source file | Archived source plus mobile delivery artifact | Visitor XLS becomes real XLSX; other types prefer PDF | | Release | Editable source | `dist/release-manifest.json` and versioned artifacts | Manifest owns current hashes and filenames | ## State Ownership - PostgreSQL owns durable control-plane task, session, confirmation, channel, audit, and outcome state. - Production attachment bytes use the configured OSS provider; normalized sensitive fields remain encrypted. - Chrome extension local state is bounded execution/reconciliation support, not canonical business history. - `.project-docs/30-worklog/tasks/` owns task-local project memory; canonical project state is an integrated projection. ## External Interfaces - Operator workbench at the control-plane service. - AgentBus WebSocket channels and attachment delivery. - Logged-in ERP browser pages under the Chrome extension host permissions. - PostgreSQL, OSS, deployment gateway, and authenticated artifact download. ## Last Updated 2026-08-28