[
 {
  "id": "01-system-context",
  "title": "SaaS Automation Platform — System Context",
  "layout": "context",
  "system": {
   "label": "SaaS Automation Platform",
   "sub": "trigger to effect"
  },
  "colWidth": 260,
  "groups": [
   {
    "side": "left",
    "title": "People",
    "nodes": [
     {
      "id": "author",
      "label": "Automation author",
      "kind": "actor",
      "rel": "builds, repairs",
      "dir": "in"
     },
     {
      "id": "wsadmin",
      "label": "Workspace admin",
      "kind": "actor",
      "rel": "policy, approval",
      "dir": "in"
     },
     {
      "id": "operator",
      "label": "Platform operator",
      "kind": "actor",
      "rel": "runs the fleet",
      "dir": "in"
     }
    ]
   },
   {
    "side": "right",
    "title": "Third-party SaaS — not ours",
    "nodes": [
     {
      "id": "crm",
      "label": "CRM, forms, ticketing",
      "sub": "trigger capable",
      "kind": "external",
      "rel": "both ways",
      "kind2": "bidirectional"
     },
     {
      "id": "sheets",
      "label": "Sheets, storage, docs",
      "kind": "external",
      "rel": "records",
      "dir": "out"
     },
     {
      "id": "chat",
      "label": "Chat and mail",
      "kind": "external",
      "rel": "messages",
      "dir": "out"
     },
     {
      "id": "billing",
      "label": "Billing and finance",
      "sub": "unsafe writes",
      "kind": "external",
      "rel": "invoices",
      "dir": "out"
     }
    ]
   },
   {
    "side": "top",
    "title": "Trust",
    "nodes": [
     {
      "id": "idp",
      "label": "Workspace IdP",
      "sub": "SAML / OIDC",
      "kind": "external",
      "rel": "author sign-in",
      "dir": "in"
     },
     {
      "id": "consent",
      "label": "Provider consent",
      "sub": "OAuth grant",
      "kind": "external",
      "rel": "delegated scopes",
      "dir": "in"
     }
    ]
   },
   {
    "side": "bottom",
    "title": "Adjacent, out of scope",
    "nodes": [
     {
      "id": "oos1",
      "label": "Own-service DAG orchestration",
      "kind": "external"
     },
     {
      "id": "oos2",
      "label": "Outbound webhook fan-out",
      "kind": "external"
     }
    ]
   }
  ],
  "note": "Bottom row is deliberately unconnected: adjacent documents in this practice own it.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "02-high-level-architecture",
  "title": "High-Level Architecture — Trigger to Effect",
  "layout": "flow",
  "chain": true,
  "align": "middle",
  "stages": [
   {
    "title": "Providers",
    "nodes": [
     {
      "id": "prov",
      "label": "Third-party SaaS",
      "sub": "8,000 connectors",
      "kind": "external"
     }
    ]
   },
   {
    "title": "Trigger ingest",
    "nodes": [
     {
      "id": "hook",
      "label": "Push endpoints",
      "sub": "signature checked",
      "kind": "integration"
     },
     {
      "id": "poll",
      "label": "Poll fleet",
      "sub": "2 M connections",
      "kind": "app"
     }
    ]
   },
   {
    "title": "Durable record",
    "nodes": [
     {
      "id": "elog",
      "label": "Trigger event log",
      "sub": "30-day replay",
      "kind": "queue"
     }
    ]
   },
   {
    "title": "Admission",
    "nodes": [
     {
      "id": "adm",
      "label": "Run admission",
      "sub": "dedup, fair share",
      "kind": "app"
     }
    ]
   },
   {
    "title": "Execution",
    "nodes": [
     {
      "id": "exec",
      "label": "Step runners",
      "sub": "resumable",
      "kind": "app"
     },
     {
      "id": "ledger",
      "label": "Step ledger",
      "sub": "our own SoR",
      "kind": "store"
     }
    ]
   },
   {
    "title": "Egress",
    "nodes": [
     {
      "id": "gov",
      "label": "Quota governor",
      "sub": "park, not fail",
      "kind": "integration"
     },
     {
      "id": "cust",
      "label": "Credential custody",
      "sub": "short-lived tokens",
      "kind": "security"
     }
    ]
   }
  ],
  "edges": [
   {
    "from": "exec",
    "to": "ledger",
    "label": "intent, outcome",
    "kind": "bidirectional"
   },
   {
    "from": "gov",
    "to": "prov",
    "label": "governed call",
    "route": "gutter"
   },
   {
    "from": "cust",
    "to": "gov",
    "label": "run token"
   }
  ],
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "03-actors-and-journeys",
  "title": "Who It Is For, and What They Get To Do",
  "layout": "actors",
  "cardWidth": 300,
  "groups": [
   {
    "title": "The people who build and depend on automations",
    "kind": "boundary",
    "actors": [
     {
      "id": "author",
      "label": "Automation author",
      "goal": "I work in ops, sales or finance. Make the busywork between my tools disappear without asking engineering, and let me trust it is still running next quarter.",
      "journeys": [
       {
        "id": "j-build",
        "label": "Build and publish one",
        "sub": "12 M live"
       },
       {
        "id": "j-repair",
        "label": "Repair one that stopped"
       },
       {
        "label": "Replay a run that failed"
       }
      ]
     },
     {
      "id": "wsadmin",
      "label": "Workspace admin",
      "goal": "I own IT and security here. Know which of our SaaS accounts this platform can reach, on whose authority, and cut any of it off in a minute.",
      "journeys": [
       {
        "label": "Review connected accounts"
       },
       {
        "label": "Revoke a connection"
       },
       {
        "label": "Approve a shared-connection automation"
       }
      ]
     }
    ]
   },
   {
    "title": "The people and machines that keep it running",
    "kind": "cloud",
    "actors": [
     {
      "id": "operator",
      "label": "Platform operator",
      "goal": "I am the SRE on call. Tell me within a minute whether the backlog is our fault or a provider's, and shed the right load either way.",
      "journeys": [
       {
        "label": "Triage a rising backlog"
       },
       {
        "label": "Trip a provider breaker"
       }
      ]
     },
     {
      "id": "cdev",
      "label": "Connector developer",
      "sub": "partner or in-house",
      "kind": "app",
      "goal": "Ship a connector for my product and have its replay safety stated honestly rather than guessed.",
      "journeys": [
       {
        "label": "Publish a connector version"
       },
       {
        "label": "Deprecate an old version"
       }
      ]
     },
     {
      "id": "prov",
      "label": "Provider API",
      "sub": "quota owner",
      "kind": "external",
      "goal": "Not be hammered. Have one caller I can identify, allowlist and rate-limit predictably.",
      "journeys": [
       {
        "label": "Receive governed traffic"
       },
       {
        "label": "Signal backoff and be obeyed"
       }
      ]
     },
     {
      "id": "clock",
      "label": "Scheduler",
      "sub": "clock-driven",
      "kind": "platform",
      "goal": "Fire the scheduled and polled triggers on time without aligning a million connections on the minute.",
      "journeys": [
       {
        "label": "Advance a connection cursor"
       }
      ]
     }
    ]
   }
  ],
  "note": "Goals are in each actor's own voice; the two journeys with ids get their own map.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "04-journey-build-automation",
  "title": "Journey — Building and Publishing a First Automation",
  "layout": "journey",
  "actor": {
   "label": "Automation author",
   "goal": "Wire my form, my sheet and my chat channel together in one sitting, with no code",
   "trigger": "Doing the same copy-paste for the third week running",
   "success": "It runs unattended, and I believe it will keep running"
  },
  "phases": [
   {
    "title": "Connect",
    "sub": "grant scopes"
   },
   {
    "title": "Describe"
   },
   {
    "title": "Test",
    "moment": true
   },
   {
    "title": "Publish",
    "moment": true
   },
   {
    "title": "Trust"
   }
  ],
  "lanes": [
   {
    "title": "What they do",
    "kind": "step",
    "cells": [
     [
      {
       "label": "Signs into provider"
      },
      {
       "label": "Approves scopes"
      }
     ],
     [
      {
       "label": "Picks trigger"
      },
      {
       "label": "Maps fields"
      }
     ],
     [
      {
       "label": "Runs a test"
      },
      {
       "label": "Confirms each write"
      }
     ],
     [
      {
       "label": "Publishes v1"
      }
     ],
     [
      {
       "label": "Checks run history"
      }
     ]
    ]
   },
   {
    "title": "What the platform does",
    "kind": "system",
    "cells": [
     [
      {
       "label": "Narrowest scopes"
      },
      {
       "label": "Vaults credential"
      }
     ],
     [
      {
       "label": "Validates bindings"
      }
     ],
     [
      {
       "label": "Reads for real"
      },
      {
       "label": "Writes only on OK"
      }
     ],
     [
      {
       "label": "Freezes definition"
      },
      {
       "label": "Subscribes trigger"
      }
     ],
     [
      {
       "label": "Classified history"
      }
     ]
    ]
   },
   {
    "title": "How it feels",
    "kind": "emotion",
    "levels": [
     "Confident",
     "Fine",
     "Anxious"
    ],
    "points": [
     1,
     1,
     0,
     1,
     2
    ]
   },
   {
    "title": "Where it hurts",
    "kind": "pain",
    "cells": [
     [
      {
       "label": "Scope list is jargon"
      }
     ],
     [
      {
       "label": "Field names unfamiliar"
      }
     ],
     [
      {
       "label": "Will a test email send?"
      }
     ],
     [],
     []
    ]
   },
   {
    "title": "What answers it",
    "kind": "gain",
    "cells": [
     [],
     [],
     [
      {
       "label": "Per-write confirmation"
      }
     ],
     [
      {
       "label": "Publish-time validation"
      }
     ],
     [
      {
       "label": "60-second rollback"
      }
     ]
    ]
   }
  ],
  "chain": true,
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "05-journey-repair-automation",
  "title": "Journey — The Automation That Quietly Stopped",
  "layout": "journey",
  "actor": {
   "label": "Automation author",
   "goal": "Find out why nothing happened, and get the missed work through",
   "trigger": "A colleague asks why last week's leads never reached the sheet",
   "success": "Reconnected, backlog released, and told next time before anyone asks"
  },
  "phases": [
   {
    "title": "Unaware",
    "sub": "token revoked"
   },
   {
    "title": "Notice",
    "moment": true
   },
   {
    "title": "Diagnose"
   },
   {
    "title": "Reconnect"
   },
   {
    "title": "Recover",
    "moment": true
   }
  ],
  "lanes": [
   {
    "title": "What they do",
    "kind": "step",
    "cells": [
     [],
     [
      {
       "label": "Hears from colleague"
      }
     ],
     [
      {
       "label": "Opens run history"
      }
     ],
     [
      {
       "label": "Re-grants the scopes"
      }
     ],
     [
      {
       "label": "Releases the backlog"
      }
     ]
    ]
   },
   {
    "title": "What the platform does",
    "kind": "system",
    "cells": [
     [
      {
       "label": "401 classified"
      },
      {
       "label": "Runs parked"
      }
     ],
     [
      {
       "label": "Owner notified"
      },
      {
       "label": "Automation paused"
      }
     ],
     [
      {
       "label": "Cause in plain words"
      }
     ],
     [
      {
       "label": "Credential re-vaulted"
      }
     ],
     [
      {
       "label": "Replay from event log"
      }
     ]
    ]
   },
   {
    "title": "How it feels",
    "kind": "emotion",
    "levels": [
     "Confident",
     "Fine",
     "Alarmed"
    ],
    "points": [
     1,
     0,
     0,
     1,
     2
    ]
   },
   {
    "title": "Where it hurts",
    "kind": "pain",
    "cells": [
     [
      {
       "label": "Silence looks like health"
      }
     ],
     [
      {
       "label": "Found out by a human"
      }
     ],
     [
      {
       "label": "Was the row written?"
      }
     ],
     [],
     [
      {
       "label": "Backlog may fire at once"
      }
     ]
    ]
   },
   {
    "title": "What answers it",
    "kind": "gain",
    "cells": [
     [
      {
       "label": "Quiet-period alarm"
      }
     ],
     [
      {
       "label": "Credential-death notice"
      }
     ],
     [
      {
       "label": "Repair inbox by cause"
      }
     ],
     [],
     [
      {
       "label": "Rate-limited release"
      }
     ]
    ]
   }
  ],
  "chain": true,
  "note": "The trough is phase 2: the platform knew before the author did. Closing it is the point of Section 9.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "06-layered-architecture",
  "title": "Layered Architecture",
  "layout": "bands",
  "layerHeaderWidth": 160,
  "bands": [
   {
    "name": "Author surfaces",
    "nodes": [
     {
      "id": "editor",
      "label": "Automation editor",
      "sub": "reference binding",
      "kind": "app"
     },
     {
      "id": "hist",
      "label": "Run history",
      "kind": "app"
     },
     {
      "id": "inbox",
      "label": "Repair inbox",
      "kind": "app"
     },
     {
      "id": "cat",
      "label": "Connector gallery",
      "kind": "app"
     }
    ]
   },
   {
    "name": "Control plane",
    "nodes": [
     {
      "id": "defs",
      "label": "Definition registry",
      "sub": "immutable versions",
      "kind": "app"
     },
     {
      "id": "creg",
      "label": "Connector catalogue",
      "kind": "app"
     },
     {
      "id": "ten",
      "label": "Tenancy and quotas",
      "kind": "app"
     },
     {
      "id": "audit",
      "label": "Audit log",
      "kind": "security"
     }
    ]
   },
   {
    "name": "Ingest",
    "nodes": [
     {
      "id": "hook",
      "label": "Push endpoints",
      "kind": "integration"
     },
     {
      "id": "poll",
      "label": "Poll fleet",
      "kind": "app"
     },
     {
      "id": "sched",
      "label": "Scheduler",
      "kind": "platform"
     },
     {
      "id": "elog",
      "label": "Trigger event log",
      "kind": "queue"
     }
    ]
   },
   {
    "name": "Execution",
    "nodes": [
     {
      "id": "adm",
      "label": "Run admission",
      "sub": "fair share",
      "kind": "app"
     },
     {
      "id": "run",
      "label": "Step runners",
      "kind": "app"
     },
     {
      "id": "ledger",
      "label": "Step ledger",
      "kind": "store"
     }
    ]
   },
   {
    "name": "Egress and trust",
    "nodes": [
     {
      "id": "gov",
      "label": "Quota governor",
      "kind": "integration"
     },
     {
      "id": "crt",
      "label": "Connector runtime",
      "sub": "sandboxed",
      "kind": "platform"
     },
     {
      "id": "cust",
      "label": "Credential custody",
      "kind": "security"
     }
    ]
   },
   {
    "name": "Providers",
    "nodes": [
     {
      "id": "prov",
      "label": "Third-party SaaS APIs",
      "sub": "not ours",
      "kind": "external"
     }
    ]
   }
  ],
  "edges": [
   {
    "from": "editor",
    "to": "defs",
    "label": "publish"
   },
   {
    "from": "hook",
    "to": "elog"
   },
   {
    "from": "poll",
    "to": "elog"
   },
   {
    "from": "elog",
    "to": "adm",
    "route": "gutter"
   },
   {
    "from": "adm",
    "to": "run",
    "label": "lease"
   },
   {
    "from": "run",
    "to": "ledger",
    "label": "attempt"
   },
   {
    "from": "run",
    "to": "gov",
    "label": "effect"
   },
   {
    "from": "gov",
    "to": "prov",
    "label": "governed call"
   }
  ],
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "07-container-view",
  "title": "Container View — Platform Internals",
  "layout": "nested",
  "boxes": [
   {
    "title": "AWS eu-west-1 — platform account",
    "kind": "cloud",
    "dir": "col",
    "children": [
     {
      "title": "Author and control plane",
      "kind": "boundary",
      "nodes": [
       {
        "id": "api",
        "label": "Author API",
        "sub": "API Gateway",
        "kind": "integration"
       },
       {
        "id": "editor",
        "label": "Editor and repair UI",
        "sub": "Fargate",
        "kind": "app"
       },
       {
        "id": "defs",
        "label": "Definition registry",
        "sub": "Aurora",
        "kind": "store"
       },
       {
        "id": "creg",
        "label": "Connector catalogue",
        "sub": "DynamoDB + S3",
        "kind": "store"
       }
      ]
     },
     {
      "title": "Ingest plane",
      "kind": "boundary",
      "nodes": [
       {
        "id": "hook",
        "label": "Push endpoints",
        "sub": "ALB + Fargate",
        "kind": "integration"
       },
       {
        "id": "poll",
        "label": "Poll workers",
        "sub": "Fargate",
        "kind": "app"
       },
       {
        "id": "cur",
        "label": "Cursors and subs",
        "sub": "DynamoDB",
        "kind": "store"
       },
       {
        "id": "elog",
        "label": "Trigger event log",
        "sub": "MSK",
        "kind": "queue"
       }
      ]
     },
     {
      "title": "Execution plane",
      "kind": "boundary",
      "nodes": [
       {
        "id": "adm",
        "label": "Run admission",
        "sub": "SQS queue classes",
        "kind": "queue"
       },
       {
        "id": "run",
        "label": "Step runners",
        "sub": "Fargate",
        "kind": "app"
       },
       {
        "id": "ledger",
        "label": "Step ledger",
        "sub": "DynamoDB",
        "kind": "store"
       }
      ]
     },
     {
      "title": "Egress and connector plane",
      "kind": "trust",
      "nodes": [
       {
        "id": "gov",
        "label": "Quota governor",
        "sub": "Fargate",
        "kind": "integration"
       },
       {
        "id": "crt",
        "label": "Connector sandbox",
        "sub": "Lambda",
        "kind": "platform"
       },
       {
        "id": "nat",
        "label": "NAT, static range",
        "kind": "platform"
       }
      ]
     }
    ]
   },
   {
    "title": "Credential account — separate blast radius",
    "kind": "trust",
    "nodes": [
     {
      "id": "cust",
      "label": "Credential custody",
      "sub": "Fargate",
      "kind": "security"
     },
     {
      "id": "kms",
      "label": "Workspace keys",
      "sub": "KMS",
      "kind": "security"
     }
    ]
   }
  ],
  "outside": [
   {
    "id": "prov",
    "label": "Third-party SaaS APIs",
    "sub": "not ours",
    "kind": "external"
   }
  ],
  "edges": [
   {
    "from": "api",
    "to": "defs",
    "label": "publish"
   },
   {
    "from": "hook",
    "to": "elog",
    "label": "commit"
   },
   {
    "from": "elog",
    "to": "adm",
    "label": "admit"
   },
   {
    "from": "adm",
    "to": "run",
    "label": "lease"
   },
   {
    "from": "run",
    "to": "ledger",
    "label": "attempt"
   },
   {
    "from": "run",
    "to": "gov",
    "label": "effect"
   },
   {
    "from": "gov",
    "to": "cust",
    "label": "run token"
   },
   {
    "from": "nat",
    "to": "prov",
    "label": "allowlisted",
    "route": "gutter"
   }
  ],
  "note": "Custody sits in its own account: a compromise of the execution plane must not be a compromise of the customers' other SaaS products.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "08-connector-catalogue",
  "title": "Interface Catalogue — Triggers In, Effects Out",
  "layout": "hub",
  "left": {
   "title": "Trigger sources",
   "nodes": [
    {
     "id": "chg",
     "label": "Provider change",
     "sub": "push 20%, poll 80%",
     "kind": "external",
     "rel": "ingested"
    },
    {
     "id": "sched",
     "label": "Schedule",
     "kind": "platform",
     "rel": "clock"
    },
    {
     "id": "inb",
     "label": "Catch-hook and mail",
     "sub": "public endpoint",
     "kind": "integration",
     "rel": "anything"
    }
   ]
  },
  "centre": {
   "title": "Platform",
   "nodes": [
    {
     "id": "core",
     "label": "Connector runtime and quota governor",
     "sub": "40,000 actions",
     "kind": "app"
    }
   ]
  },
  "right": {
   "title": "Effects out, by replay safety",
   "nodes": [
    {
     "id": "idem",
     "label": "Idempotent actions",
     "sub": "provider honours key",
     "kind": "external",
     "rel": "effect key",
     "dir": "out"
    },
    {
     "id": "chk",
     "label": "Checkable actions",
     "sub": "read-back possible",
     "kind": "external",
     "rel": "verify first",
     "dir": "out"
    },
    {
     "id": "uns",
     "label": "Unsafe actions",
     "sub": "no key, no read-back",
     "kind": "external",
     "rel": "author decides",
     "dir": "out",
     "kind2": "error"
    }
   ]
  },
  "note": "Cataloguing by replay safety rather than by vendor is the choice that makes Section 5 enforceable.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "09-data-flow",
  "title": "Data Flow — Payload to Projection",
  "layout": "flow",
  "chain": true,
  "align": "middle",
  "stages": [
   {
    "title": "Source",
    "nodes": [
     {
      "id": "pay",
      "label": "Provider payload",
      "sub": "untrusted",
      "kind": "external"
     }
    ]
   },
   {
    "title": "Accept",
    "nodes": [
     {
      "id": "val",
      "label": "Authenticate, validate",
      "sub": "size and schema",
      "kind": "integration"
     },
     {
      "id": "dd",
      "label": "Deduplicate",
      "sub": "(conn, event id)",
      "kind": "app"
     }
    ]
   },
   {
    "title": "Authority",
    "nodes": [
     {
      "id": "elog",
      "label": "Trigger event log",
      "sub": "30 d, replayable",
      "kind": "queue"
     }
    ]
   },
   {
    "title": "Execute",
    "nodes": [
     {
      "id": "bind",
      "label": "Bind and call",
      "sub": "by reference",
      "kind": "app"
     }
    ]
   },
   {
    "title": "Authority",
    "nodes": [
     {
      "id": "ledger",
      "label": "Step ledger",
      "sub": "90 d, append only",
      "kind": "store"
     }
    ]
   },
   {
    "title": "Projections",
    "nodes": [
     {
      "id": "hist",
      "label": "Run history",
      "sub": "rebuildable",
      "kind": "store"
     },
     {
      "id": "an",
      "label": "Cost and analytics",
      "kind": "store"
     }
    ]
   }
  ],
  "edges": [
   {
    "from": "ledger",
    "to": "hist"
   },
   {
    "from": "elog",
    "to": "bind",
    "label": "replay",
    "kind": "async",
    "route": "gutter"
   },
   {
    "from": "val",
    "to": "pay",
    "label": "reject",
    "kind": "error"
   }
  ],
  "note": "Only two stores are authoritative. Everything right of the ledger can be dropped and rebuilt.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "10-data-architecture",
  "title": "Data Architecture — Ownership and Rebuildability",
  "layout": "nested",
  "boxes": [
   {
    "title": "Authoritative — nothing else can reproduce it",
    "kind": "boundary",
    "nodes": [
     {
      "id": "elog",
      "label": "Trigger event log",
      "sub": "30 d, by connection",
      "kind": "queue"
     },
     {
      "id": "ledger",
      "label": "Step ledger",
      "sub": "90 d, sync replicated",
      "kind": "store"
     }
    ]
   },
   {
    "title": "Strongly consistent control state",
    "kind": "boundary",
    "nodes": [
     {
      "id": "defs",
      "label": "Definition versions",
      "kind": "store"
     },
     {
      "id": "creg",
      "label": "Connector catalogue",
      "kind": "store"
     },
     {
      "id": "ten",
      "label": "Tenancy and plans",
      "kind": "store"
     },
     {
      "id": "audit",
      "label": "Audit log",
      "sub": "7 y, immutable",
      "kind": "security"
     }
    ]
   },
   {
    "title": "Rebuildable projections — droppable",
    "kind": "plain",
    "nodes": [
     {
      "id": "hist",
      "label": "Run index",
      "kind": "store"
     },
     {
      "id": "an",
      "label": "Analytics",
      "kind": "store",
      "icon": "fa5_chart_bar"
     },
     {
      "id": "qc",
      "label": "Quota counters",
      "sub": "RPO 60 s",
      "kind": "store"
     }
    ]
   },
   {
    "title": "Hot operational state — loss means duplicates or gaps",
    "kind": "boundary",
    "nodes": [
     {
      "id": "cur",
      "label": "Trigger cursors",
      "kind": "store"
     },
     {
      "id": "subs",
      "label": "Subscriptions",
      "kind": "store"
     },
     {
      "id": "lease",
      "label": "Run leases",
      "kind": "store"
     }
    ]
   },
   {
    "title": "Separate custody",
    "kind": "trust",
    "nodes": [
     {
      "id": "cred",
      "label": "Credentials",
      "sub": "per-workspace key",
      "kind": "security",
      "icon": "fa5_key"
     },
     {
      "id": "kms",
      "label": "Key service",
      "kind": "security"
     }
    ]
   }
  ],
  "edges": [
   {
    "from": "ledger",
    "to": "hist",
    "label": "rebuild"
   },
   {
    "from": "cred",
    "to": "kms",
    "label": "envelope"
   }
  ],
  "note": "Cursor and subscription state is small, hot, and the one store whose loss is not recoverable from the two above it.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "11-data-model",
  "title": "Data Model — Core Entities",
  "layout": "er",
  "canvas": {
   "width": 1620,
   "cols": 4
  },
  "rowGap": 240,
  "entities": [
   {
    "id": "ws",
    "name": "workspace",
    "row": 0,
    "col": 0,
    "attrs": [
     "workspace_id  PK",
     "plan",
     "residency_region",
     "retention_policy"
    ]
   },
   {
    "id": "cv",
    "name": "connector_version",
    "row": 0,
    "col": 2,
    "attrs": [
     "connector_id  PK",
     "version  PK",
     "replay_class",
     "rate_limit_profile",
     "eol_date"
    ]
   },
   {
    "id": "conn",
    "name": "connection",
    "row": 1,
    "col": 0,
    "attrs": [
     "connection_id  PK",
     "workspace_id  FK",
     "connector_id  FK",
     "scopes",
     "state"
    ]
   },
   {
    "id": "av",
    "name": "automation_version",
    "row": 1,
    "col": 2,
    "attrs": [
     "automation_id  PK",
     "version  PK",
     "workspace_id  FK",
     "trigger_ref",
     "published_at"
    ]
   },
   {
    "id": "cred",
    "name": "credential",
    "row": 2,
    "col": 0,
    "attrs": [
     "credential_id  PK",
     "connection_id  FK",
     "ciphertext",
     "key_id",
     "expires_at"
    ]
   },
   {
    "id": "te",
    "name": "trigger_event",
    "row": 2,
    "col": 1,
    "attrs": [
     "event_id  PK",
     "connection_id  FK",
     "provider_event_id",
     "payload_ref",
     "received_at"
    ]
   },
   {
    "id": "run",
    "name": "run",
    "row": 2,
    "col": 2,
    "attrs": [
     "run_id  PK",
     "event_id  FK",
     "automation_id  FK",
     "version",
     "state"
    ]
   },
   {
    "id": "sa",
    "name": "step_attempt",
    "row": 2,
    "col": 3,
    "attrs": [
     "run_id  PK",
     "step_id  PK",
     "attempt  PK",
     "effect_key",
     "outcome"
    ]
   }
  ],
  "relations": [
   {
    "from": "ws",
    "to": "conn",
    "label": "1 : N",
    "from_side": "s",
    "to_side": "n"
   },
   {
    "from": "cv",
    "to": "av",
    "label": "1 : N",
    "from_side": "s",
    "to_side": "n"
   },
   {
    "from": "conn",
    "to": "cred",
    "label": "1 : 1",
    "from_side": "s",
    "to_side": "n"
   },
   {
    "from": "av",
    "to": "run",
    "label": "1 : N",
    "from_side": "s",
    "to_side": "n"
   },
   {
    "from": "conn",
    "to": "te",
    "label": "1 : N",
    "from_side": "e",
    "to_side": "n"
   },
   {
    "from": "te",
    "to": "run",
    "label": "1 : 1",
    "from_side": "e",
    "to_side": "w"
   },
   {
    "from": "run",
    "to": "sa",
    "label": "1 : N",
    "from_side": "e",
    "to_side": "w"
   }
  ],
  "note": "effect_key is derived from (run_id, step_id, logical attempt) - the uniqueness that keeps a retry from duplicating an effect.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "12-run-execution-sequence",
  "title": "Critical Flow — One Run, With a Rate Limit In It",
  "layout": "sequence",
  "lifelines": [
   {
    "id": "prov",
    "label": "CRM",
    "kind": "external"
   },
   {
    "id": "hook",
    "label": "Push endpoint",
    "kind": "integration"
   },
   {
    "id": "elog",
    "label": "Event log",
    "kind": "queue"
   },
   {
    "id": "adm",
    "label": "Admission",
    "kind": "app"
   },
   {
    "id": "run",
    "label": "Step runner",
    "kind": "app"
   },
   {
    "id": "ledger",
    "label": "Step ledger",
    "kind": "store"
   },
   {
    "id": "gov",
    "label": "Quota governor",
    "kind": "integration"
   },
   {
    "id": "tgt",
    "label": "Sheets API",
    "kind": "external"
   }
  ],
  "messages": [
   {
    "from": "prov",
    "to": "hook",
    "label": "signed delivery",
    "kind": "call"
   },
   {
    "from": "hook",
    "to": "hook",
    "label": "verify signature",
    "kind": "self"
   },
   {
    "from": "hook",
    "to": "elog",
    "label": "commit event",
    "kind": "call"
   },
   {
    "from": "hook",
    "to": "prov",
    "label": "200 OK",
    "kind": "return"
   },
   {
    "from": "elog",
    "to": "adm",
    "label": "admit once",
    "kind": "async"
   },
   {
    "from": "adm",
    "to": "run",
    "label": "lease run",
    "kind": "call"
   },
   {
    "from": "run",
    "to": "ledger",
    "label": "step 1 intent",
    "kind": "call"
   },
   {
    "from": "run",
    "to": "gov",
    "label": "effect and key",
    "kind": "call"
   },
   {
    "from": "gov",
    "to": "tgt",
    "label": "governed write",
    "kind": "call"
   },
   {
    "from": "tgt",
    "to": "gov",
    "label": "429 Retry-After",
    "kind": "error"
   },
   {
    "from": "gov",
    "to": "run",
    "label": "park until T",
    "kind": "error"
   },
   {
    "from": "run",
    "to": "ledger",
    "label": "parked, not failed",
    "kind": "call"
   },
   {
    "from": "run",
    "to": "gov",
    "label": "retry, same key",
    "kind": "call"
   },
   {
    "from": "gov",
    "to": "tgt",
    "label": "governed write",
    "kind": "call"
   },
   {
    "from": "tgt",
    "to": "gov",
    "label": "201 Created",
    "kind": "return"
   },
   {
    "from": "gov",
    "to": "run",
    "label": "outcome",
    "kind": "return"
   },
   {
    "from": "run",
    "to": "ledger",
    "label": "step 1 done",
    "kind": "call"
   }
  ],
  "note": "The park consumes no worker and no retry budget, and the second attempt reuses the effect key - so the row is written once.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "13-trigger-ingestion",
  "title": "Trigger Ingestion — Push and Poll",
  "layout": "flow",
  "chain": false,
  "align": "top",
  "stages": [
   {
    "title": "Provider capability",
    "nodes": [
     {
      "id": "push",
      "label": "Push capable",
      "sub": "~20% of catalogue",
      "kind": "external"
     },
     {
      "id": "nopush",
      "label": "Poll only",
      "sub": "~80% of catalogue",
      "kind": "external"
     }
    ]
   },
   {
    "title": "Own the lifecycle",
    "nodes": [
     {
      "id": "subs",
      "label": "Subscription manager",
      "sub": "renew before expiry",
      "kind": "app"
     },
     {
      "id": "cur",
      "label": "Cursor store",
      "sub": "watermark per conn",
      "kind": "store"
     }
    ]
   },
   {
    "title": "Receive",
    "nodes": [
     {
      "id": "hook",
      "label": "Signed endpoint",
      "sub": "p99 ack 250 ms",
      "kind": "integration"
     },
     {
      "id": "pollw",
      "label": "Poll worker",
      "sub": "jittered interval",
      "kind": "app"
     }
    ]
   },
   {
    "title": "Admit",
    "nodes": [
     {
      "id": "dd",
      "label": "Deduplicate",
      "sub": "(conn, event id)",
      "kind": "app"
     },
     {
      "id": "pq",
      "label": "Poison quarantine",
      "sub": "30 d, typed reason",
      "kind": "risk"
     }
    ]
   },
   {
    "title": "Commit",
    "nodes": [
     {
      "id": "elog",
      "label": "Trigger event log",
      "sub": "durable, 30 d",
      "kind": "queue"
     },
     {
      "id": "quiet",
      "label": "Quiet-period alarm",
      "sub": "a silent source",
      "kind": "platform"
     }
    ]
   }
  ],
  "edges": [
   {
    "from": "push",
    "to": "subs",
    "label": "create, renew"
   },
   {
    "from": "nopush",
    "to": "cur",
    "label": "read since"
   },
   {
    "from": "subs",
    "to": "hook",
    "label": "delivery"
   },
   {
    "from": "cur",
    "to": "pollw",
    "label": "watermark"
   },
   {
    "from": "hook",
    "to": "dd"
   },
   {
    "from": "pollw",
    "to": "dd"
   },
   {
    "from": "dd",
    "to": "elog",
    "label": "accepted"
   },
   {
    "from": "dd",
    "to": "pq",
    "label": "unparseable",
    "kind": "error"
   },
   {
    "from": "elog",
    "to": "quiet",
    "label": "liveness",
    "kind": "async"
   }
  ],
  "note": "A subscription that expired unnoticed is this platform's most common invisible failure, which is why renewal and the quiet-period alarm are components rather than settings.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "14-step-lifecycle-by-class",
  "title": "Step Lifecycle by Replay-Safety Class",
  "layout": "swimlane",
  "laneHeaderWidth": 150,
  "stages": [
   "Bind inputs",
   "Mint effect key",
   "Call provider",
   "Ambiguous outcome",
   "Terminal state"
  ],
  "lanes": [
   {
    "title": "Idempotent",
    "cells": [
     [
      {
       "label": "By reference"
      }
     ],
     [
      {
       "label": "Provider honours key"
      }
     ],
     [
      {
       "label": "Key on the request"
      }
     ],
     [
      {
       "label": "Retry, same key"
      }
     ],
     [
      {
       "label": "Done exactly once",
       "kind": "opportunity"
      }
     ]
    ]
   },
   {
    "title": "Checkable",
    "cells": [
     [
      {
       "label": "By reference"
      }
     ],
     [
      {
       "label": "Natural key"
      }
     ],
     [
      {
       "label": "Plain request"
      }
     ],
     [
      {
       "label": "Read back first"
      }
     ],
     [
      {
       "label": "Done, verified",
       "kind": "opportunity"
      }
     ]
    ]
   },
   {
    "title": "Unsafe",
    "cells": [
     [
      {
       "label": "By reference"
      }
     ],
     [
      {
       "label": "No key available",
       "kind": "risk"
      }
     ],
     [
      {
       "label": "Plain request"
      }
     ],
     [
      {
       "label": "Park, ask the author",
       "kind": "decision"
      }
     ],
     [
      {
       "label": "Gap or duplicate",
       "kind": "risk"
      }
     ]
    ]
   }
  ],
  "note": "The third lane is the honest one: the platform cannot make it safe, so it surfaces the choice instead of guessing.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "15-deployment",
  "title": "Deployment — Region, Zones and Egress",
  "layout": "nested",
  "boxes": [
   {
    "title": "AWS eu-west-1 — platform account",
    "kind": "cloud",
    "dir": "col",
    "children": [
     {
      "title": "Ingest tier — three AZs",
      "kind": "boundary",
      "nodes": [
       {
        "id": "alb",
        "label": "ALB",
        "sub": "TLS, per-conn secret",
        "kind": "integration"
       },
       {
        "id": "hookf",
        "label": "Push service",
        "sub": "Fargate, autoscaled",
        "kind": "app"
       },
       {
        "id": "pollf",
        "label": "Poll service",
        "sub": "Fargate",
        "kind": "app"
       },
       {
        "id": "msk",
        "label": "MSK",
        "sub": "3 brokers, 3 AZ",
        "kind": "queue"
       }
      ]
     },
     {
      "title": "Execution tier — three AZs",
      "kind": "boundary",
      "nodes": [
       {
        "id": "sqs",
        "label": "Queue classes",
        "sub": "SQS x 4",
        "kind": "queue"
       },
       {
        "id": "runf",
        "label": "Step runners",
        "sub": "Fargate",
        "kind": "app"
       },
       {
        "id": "ddb",
        "label": "Step ledger",
        "sub": "DynamoDB, 3 AZ",
        "kind": "store"
       }
      ]
     },
     {
      "title": "Controlled egress",
      "kind": "trust",
      "nodes": [
       {
        "id": "govf",
        "label": "Quota governor",
        "sub": "Fargate",
        "kind": "integration"
       },
       {
        "id": "nat",
        "label": "NAT gateways",
        "sub": "published range",
        "kind": "platform"
       }
      ]
     }
    ]
   },
   {
    "title": "Credential account — separate blast radius",
    "kind": "trust",
    "nodes": [
     {
      "id": "custf",
      "label": "Custody service",
      "sub": "Fargate",
      "kind": "security"
     },
     {
      "id": "kms",
      "label": "KMS",
      "sub": "per-workspace keys",
      "kind": "security"
     }
    ]
   }
  ],
  "outside": [
   {
    "id": "prov",
    "label": "Provider APIs",
    "sub": "internet",
    "kind": "external"
   }
  ],
  "edges": [
   {
    "from": "alb",
    "to": "hookf",
    "label": "deliveries"
   },
   {
    "from": "hookf",
    "to": "msk",
    "label": "commit"
   },
   {
    "from": "msk",
    "to": "sqs",
    "label": "admit"
   },
   {
    "from": "sqs",
    "to": "runf",
    "label": "lease"
   },
   {
    "from": "runf",
    "to": "ddb",
    "label": "attempt"
   },
   {
    "from": "runf",
    "to": "govf",
    "label": "effect"
   },
   {
    "from": "govf",
    "to": "nat"
   },
   {
    "from": "nat",
    "to": "prov",
    "label": "static range",
    "route": "gutter"
   }
  ],
  "note": "Residency-pinned workspaces run the whole stack in their own region with no cross-region failover; this view is one such region.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "16-cicd-connector-release",
  "title": "Delivery — Platform Code and Connector Versions",
  "layout": "flow",
  "chain": true,
  "align": "middle",
  "stages": [
   {
    "title": "Source",
    "nodes": [
     {
      "id": "git",
      "label": "Platform code",
      "sub": "Git",
      "kind": "app"
     },
     {
      "id": "man",
      "label": "Connector manifests",
      "sub": "declarative",
      "kind": "app"
     }
    ]
   },
   {
    "title": "Build",
    "nodes": [
     {
      "id": "img",
      "label": "Container image",
      "sub": "signed",
      "kind": "app"
     },
     {
      "id": "lint",
      "label": "Manifest lint",
      "sub": "schemas resolvable",
      "kind": "app"
     }
    ]
   },
   {
    "title": "Gates",
    "nodes": [
     {
      "id": "ct",
      "label": "Contract tests",
      "sub": "provider sandbox",
      "kind": "decision"
     },
     {
      "id": "rc",
      "label": "Replay class declared",
      "sub": "blocks publish",
      "kind": "decision"
     },
     {
      "id": "sec",
      "label": "Sandbox policy scan",
      "kind": "decision"
     }
    ]
   },
   {
    "title": "Environments",
    "nodes": [
     {
      "id": "stg",
      "label": "Staging",
      "sub": "provider sandboxes",
      "kind": "app",
      "icon": "fa5_vials"
     },
     {
      "id": "can",
      "label": "Production canary",
      "sub": "1% of runs",
      "kind": "app"
     }
    ]
   },
   {
    "title": "Catalogue",
    "nodes": [
     {
      "id": "pub",
      "label": "Version published",
      "sub": "immutable",
      "kind": "store"
     },
     {
      "id": "dep",
      "label": "Deprecation notice",
      "sub": "per-workspace impact",
      "kind": "platform"
     }
    ]
   }
  ],
  "edges": [
   {
    "from": "rc",
    "to": "man",
    "label": "reject",
    "kind": "error",
    "route": "gutter"
   },
   {
    "from": "pub",
    "to": "dep",
    "label": "supersedes",
    "kind": "async"
   }
  ],
  "note": "An action cannot be published without its replay-safety class, because every execution guarantee downstream is derived from it.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "17-observability",
  "title": "Observability — Signals by Pipeline Stage",
  "layout": "grid",
  "laneHeaderWidth": 140,
  "stages": [
   "Ingest",
   "Admission",
   "Execution",
   "Egress",
   "Author-facing"
  ],
  "lanes": [
   {
    "title": "Latency",
    "cells": [
     [
      {
       "label": "Ack p99 250 ms",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Queue age by class",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Step duration",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Provider RTT",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Start latency p95 3 s",
       "kind": "platform"
      }
     ]
    ]
   },
   {
    "title": "Saturation",
    "cells": [
     [
      {
       "label": "Deliveries per second",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Queue depth",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Runner concurrency",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Quota lease use",
       "kind": "platform"
      }
     ],
     []
    ]
   },
   {
    "title": "Errors",
    "cells": [
     [
      {
       "label": "Rejected deliveries",
       "kind": "risk"
      }
     ],
     [
      {
       "label": "Admission drops",
       "kind": "risk"
      }
     ],
     [
      {
       "label": "Failures by class",
       "kind": "risk"
      }
     ],
     [
      {
       "label": "429 rate, SLO 0.1%",
       "kind": "risk"
      }
     ],
     [
      {
       "label": "Unclassified rate",
       "kind": "risk"
      }
     ]
    ]
   },
   {
    "title": "Correctness",
    "cells": [
     [
      {
       "label": "Dedup gaps",
       "kind": "security"
      }
     ],
     [
      {
       "label": "Double admissions",
       "kind": "security"
      }
     ],
     [
      {
       "label": "Duplicate effects",
       "kind": "security"
      }
     ],
     [
      {
       "label": "Breaker trips",
       "kind": "security"
      }
     ],
     [
      {
       "label": "Parked by cause",
       "kind": "security"
      }
     ]
    ]
   },
   {
    "title": "Silence",
    "cells": [
     [
      {
       "label": "Quiet connections",
       "kind": "risk"
      }
     ],
     [],
     [
      {
       "label": "Runs past deadline",
       "kind": "risk"
      }
     ],
     [],
     [
      {
       "label": "Automations idle too long",
       "kind": "risk"
      }
     ]
    ]
   },
   {
    "title": "Cost",
    "cells": [
     [
      {
       "label": "Poll cost per connector",
       "kind": "store"
      }
     ],
     [],
     [
      {
       "label": "$ per 100k steps",
       "kind": "store"
      }
     ],
     [
      {
       "label": "Egress per provider",
       "kind": "store"
      }
     ],
     [
      {
       "label": "Idle automation cost",
       "kind": "store"
      }
     ]
    ]
   }
  ],
  "note": "The silence row is the one most monitoring omits: nothing happening looks identical to health.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "18-automation-health-loop",
  "title": "The Loop That Closes — Automation Health",
  "layout": "cycle",
  "centre": {
   "label": "Automation health"
  },
  "rx": 430,
  "ry": 215,
  "nodes": [
   {
    "id": "detect",
    "label": "Detect",
    "sub": "quiet period, error rate",
    "kind": "platform",
    "icon": "fa5_eye"
   },
   {
    "id": "classify",
    "label": "Classify",
    "sub": "typed, author-facing",
    "kind": "app",
    "icon": "fa5_tags"
   },
   {
    "id": "hold",
    "label": "Hold the work",
    "sub": "park, then pause",
    "kind": "queue",
    "icon": "fa5_pause"
   },
   {
    "id": "notify",
    "label": "Notify the owner",
    "sub": "not a support ticket",
    "kind": "integration",
    "icon": "fa5_bell"
   },
   {
    "id": "repair",
    "label": "Repair",
    "sub": "reconnect, replay",
    "kind": "app",
    "icon": "fa5_wrench"
   },
   {
    "id": "observe",
    "label": "Observe recovery",
    "sub": "did the backlog clear?",
    "kind": "platform",
    "icon": "fa5_search"
   }
  ],
  "ringLabels": [
   "typed cause",
   "hold, do not drop",
   "who to tell",
   "what to do",
   "work released",
   "new baseline"
  ],
  "note": "The loop exists because the default failure of this platform is silence, and silence has no natural end.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "19-security-zones",
  "title": "Security — Trust Zones and Crossings",
  "layout": "zones",
  "zones": [
   {
    "title": "Internet — untrusted",
    "kind": "trust",
    "nodes": [
     {
      "id": "pub",
      "label": "Provider push callers",
      "kind": "external"
     },
     {
      "id": "aut",
      "label": "Author browser",
      "kind": "actor"
     },
     {
      "id": "prov",
      "label": "Provider APIs",
      "kind": "external"
     }
    ]
   },
   {
    "title": "Perimeter",
    "kind": "trust",
    "nodes": [
     {
      "id": "waf",
      "label": "WAF and ALB",
      "kind": "integration"
     },
     {
      "id": "hook",
      "label": "Signed push endpoint",
      "kind": "integration"
     },
     {
      "id": "api",
      "label": "Author API",
      "sub": "SSO",
      "kind": "integration"
     }
    ]
   },
   {
    "title": "Application — platform VPC",
    "kind": "trust",
    "nodes": [
     {
      "id": "adm",
      "label": "Admission",
      "kind": "app"
     },
     {
      "id": "run",
      "label": "Step runners",
      "kind": "app"
     },
     {
      "id": "crt",
      "label": "Connector sandbox",
      "sub": "no credentials",
      "kind": "platform"
     }
    ]
   },
   {
    "title": "Controlled egress",
    "kind": "trust",
    "nodes": [
     {
      "id": "gov",
      "label": "Quota governor",
      "kind": "integration"
     },
     {
      "id": "nat",
      "label": "NAT, static range",
      "kind": "platform"
     }
    ]
   },
   {
    "title": "Custody — separate account",
    "kind": "trust",
    "nodes": [
     {
      "id": "cust",
      "label": "Credential custody",
      "kind": "security"
     },
     {
      "id": "kms",
      "label": "Key service",
      "kind": "security"
     }
    ]
   },
   {
    "title": "Data",
    "kind": "trust",
    "nodes": [
     {
      "id": "elog",
      "label": "Trigger event log",
      "kind": "store"
     },
     {
      "id": "ledger",
      "label": "Step ledger",
      "kind": "store"
     }
    ]
   }
  ],
  "edges": [
   {
    "from": "pub",
    "to": "hook",
    "label": "signature only"
   },
   {
    "from": "hook",
    "to": "elog",
    "label": "commit"
   },
   {
    "from": "run",
    "to": "crt",
    "label": "sandboxed"
   },
   {
    "from": "run",
    "to": "gov",
    "label": "effect"
   },
   {
    "from": "gov",
    "to": "cust",
    "label": "token"
   },
   {
    "from": "nat",
    "to": "prov",
    "label": "allowlist",
    "route": "gutter"
   }
  ],
  "note": "Author-supplied URLs in generic HTTP steps are resolved and re-checked after redirect, so the platform cannot be used as a proxy into these zones.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "20-credential-flow",
  "title": "Identity and Access — Grant, Use, and Death",
  "layout": "sequence",
  "lifelines": [
   {
    "id": "author",
    "label": "Author",
    "kind": "actor"
   },
   {
    "id": "api",
    "label": "Author API",
    "kind": "integration"
   },
   {
    "id": "cust",
    "label": "Custody",
    "kind": "security"
   },
   {
    "id": "kms",
    "label": "Key service",
    "kind": "security"
   },
   {
    "id": "oauth",
    "label": "Provider OAuth",
    "kind": "external"
   },
   {
    "id": "gov",
    "label": "Governor",
    "kind": "integration"
   },
   {
    "id": "run",
    "label": "Step runner",
    "kind": "app"
   }
  ],
  "messages": [
   {
    "from": "author",
    "to": "api",
    "label": "connect account",
    "kind": "call"
   },
   {
    "from": "api",
    "to": "oauth",
    "label": "narrowest scopes",
    "kind": "call"
   },
   {
    "from": "oauth",
    "to": "author",
    "label": "consent screen",
    "kind": "call"
   },
   {
    "from": "author",
    "to": "oauth",
    "label": "approves",
    "kind": "call"
   },
   {
    "from": "oauth",
    "to": "api",
    "label": "grant code",
    "kind": "return"
   },
   {
    "from": "api",
    "to": "cust",
    "label": "exchange and store",
    "kind": "call"
   },
   {
    "from": "cust",
    "to": "kms",
    "label": "encrypt, workspace key",
    "kind": "call"
   },
   {
    "from": "cust",
    "to": "api",
    "label": "connection id only",
    "kind": "return"
   },
   {
    "from": "run",
    "to": "gov",
    "label": "effect and key",
    "kind": "call"
   },
   {
    "from": "gov",
    "to": "cust",
    "label": "run-scoped token",
    "kind": "call"
   },
   {
    "from": "cust",
    "to": "cust",
    "label": "single-flight refresh",
    "kind": "self"
   },
   {
    "from": "cust",
    "to": "gov",
    "label": "short-lived token",
    "kind": "return"
   },
   {
    "from": "gov",
    "to": "oauth",
    "label": "call with token",
    "kind": "call"
   },
   {
    "from": "oauth",
    "to": "gov",
    "label": "401 revoked",
    "kind": "error"
   },
   {
    "from": "gov",
    "to": "cust",
    "label": "mark dead",
    "kind": "async"
   },
   {
    "from": "cust",
    "to": "run",
    "label": "non-retryable",
    "kind": "error"
   }
  ],
  "note": "The refresh token never leaves custody, and the runner never holds a credential it could reuse - only a token scoped to one connection and one run.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 },
 {
  "id": "21-failure-taxonomy",
  "title": "Assurance — Failure Classes and Their Handling",
  "layout": "grid",
  "laneHeaderWidth": 180,
  "stages": [
   "Detect",
   "Hold",
   "Resolve",
   "What the author sees"
  ],
  "lanes": [
   {
    "title": "Transient 5xx",
    "cells": [
     [
      {
       "label": "Timeout or reset",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Retry budget",
       "kind": "queue"
      }
     ],
     [
      {
       "label": "Same effect key",
       "kind": "opportunity"
      }
     ],
     [
      {
       "label": "Nothing",
       "kind": "journey"
      }
     ]
    ]
   },
   {
    "title": "Rate limit",
    "cells": [
     [
      {
       "label": "429, Retry-After",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Park with release",
       "kind": "queue"
      }
     ],
     [
      {
       "label": "Resume, budget intact",
       "kind": "opportunity"
      }
     ],
     [
      {
       "label": "Running slowly",
       "kind": "journey"
      }
     ]
    ]
   },
   {
    "title": "Provider outage",
    "cells": [
     [
      {
       "label": "Sustained error rate",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Breaker, shed to floor",
       "kind": "queue"
      }
     ],
     [
      {
       "label": "Probe for recovery",
       "kind": "opportunity"
      }
     ],
     [
      {
       "label": "Provider is down",
       "kind": "journey"
      }
     ]
    ]
   },
   {
    "title": "Credential death",
    "cells": [
     [
      {
       "label": "401 or revoked",
       "kind": "risk"
      }
     ],
     [
      {
       "label": "Park, then pause",
       "kind": "queue"
      }
     ],
     [
      {
       "label": "Author reconnects",
       "kind": "decision"
      }
     ],
     [
      {
       "label": "Reconnect your account",
       "kind": "journey"
      }
     ]
    ]
   },
   {
    "title": "Schema drift",
    "cells": [
     [
      {
       "label": "Schema validation",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Connector degraded",
       "kind": "queue"
      }
     ],
     [
      {
       "label": "Pin or update version",
       "kind": "decision"
      }
     ],
     [
      {
       "label": "One impact notice",
       "kind": "journey"
      }
     ]
    ]
   },
   {
    "title": "Ambiguous effect",
    "cells": [
     [
      {
       "label": "Acknowledgement lost",
       "kind": "risk"
      }
     ],
     [
      {
       "label": "Park if unsafe",
       "kind": "queue"
      }
     ],
     [
      {
       "label": "Read back, or ask",
       "kind": "decision"
      }
     ],
     [
      {
       "label": "An explicit choice",
       "kind": "journey"
      }
     ]
    ]
   },
   {
    "title": "Author logic error",
    "cells": [
     [
      {
       "label": "Publish-time check",
       "kind": "platform"
      }
     ],
     [
      {
       "label": "Fail fast",
       "kind": "queue"
      }
     ],
     [
      {
       "label": "Fix the binding",
       "kind": "decision"
      }
     ],
     [
      {
       "label": "A named cause",
       "kind": "journey"
      }
     ]
    ]
   },
   {
    "title": "Runaway automation",
    "cells": [
     [
      {
       "label": "10x its baseline",
       "kind": "risk"
      }
     ],
     [
      {
       "label": "Throttle, then pause",
       "kind": "queue"
      }
     ],
     [
      {
       "label": "Author edits the loop",
       "kind": "decision"
      }
     ],
     [
      {
       "label": "Paused, with reason",
       "kind": "journey"
      }
     ]
    ]
   }
  ],
  "note": "Every row ends in a sentence the author can act on; a failure with no fourth column is an unfinished feature.",
  "meta": {
   "v": "1.0",
   "owner": "Integration Platform Architecture",
   "date": "2026-10"
  }
 }
]