No-Code SaaS Automation Platform  ·  View 02 of 21  ·  Context and scope

High-Level Architecture

The whole path in one line: a provider event becomes a durable record, becomes a leased run, becomes a governed call back out.

Editable source SVG draw.io All views
Providers Third-party SaaS 8,000 connectors Trigger ingest Push endpoints signature checked Poll fleet 2 M connections Durable record Trigger event log 30-day replay Admission Run admission dedup, fair share Execution Step runners resumable Step ledger our own SoR Egress Quota governor park, not fail Credential custody short-lived tokens intent, outcome governed call run token High-Level Architecture — Trigger to Effect External / third party Interface / broker Application we own Queue / topic Data store Security / platform two-way synchronous v 1.0 · owner Integration Platform Architecture · date 2026-10

Decisions

  • Acceptance and execution are separated by a durable log, so a total execution outage still loses no trigger — the two fail independently.
  • No step runner calls a provider directly. Every outbound call passes the quota governor, which is also where the short-lived credential is exchanged.
  • The step ledger is drawn inside the execution stage because it is not a side-effect store: it is the run's state.

Assumptions

  • 4,000 trigger events/second accepted at steady state, 16,000/second for ten minutes.
  • 12,000 step attempts/second steady state, 48,000/second at burst.
  • Roughly a fifth of the 8,000-connector catalogue can push; the rest is polled.

Deliberately omitted

  • The control plane, author surfaces and observability are absent here and carry their own views — this one is the hot path only.