No-Code SaaS Automation Platform · View 09 of 21 · Data
Decisions
- Exactly two stores are authoritative. Everything right of the step ledger can be deleted and rebuilt, which is what makes a schema change to run history a routine operation.
- Validation happens before the durable commit, so a payload that cannot be mapped is quarantined rather than poisoning the partition behind it.
- Replay reads the trigger event log, never the provider — which is what makes the 30-day retention a recovery commitment rather than a storage preference.
Assumptions
- Trigger payloads retained 30 days; step ledger 90 days hot and 400 days archived; run history 30 days free, 12 months paid.
- RTO 2 h to rebuild the full run-history projection from the ledger, with author queries degraded but available during the rebuild.
Risks
- Retaining 30 days of payloads makes the platform the custodian of a month of its customers' data from every connected product — the privacy cost of exact replay, and the subject of Core Architecture Question 5.