Control API Decision Lifecycle

Control API Decision Lifecycle A sequence diagram generated by Archify. POST /engine/v1/queries (inspect) authenticate + authorize(inspect) controlRead(workOrderId): pinned revision projection, approvalSubject, binding POST /engine/v1/approval-challenges controlChallenge(session, revision, binding) challenge id, expires in 2 min POST /engine/v1/commands (approve) verify + recapture deliverable digest controlCommand: consume challenge, apply, audit, receipt receipt (accepted, not executed) retry identical file: REPLAYED or REQUEST_ID_CONFLICT Inspect Approval challenge Command in one transaction Uncertain response Operator · CLI / web · Sequence participant Operator CLI / web Control HTTP · control-http.ts · Sequence participant Control HTTP control-http.ts ControlService · control-service.ts · Sequence participant ControlService control-service.ts Identity Adapter · host trust boundary · Sequence participant Identity Adapter host trust boundary Artifact Store · immutable bytes · Sequence participant Artifact Store immutable bytes Engine SQLite · worker thread, WAL · Sequence participant Engine SQLite worker thread, WAL Legend request return security async trace default message

Trust Boundary

  • • The host identity adapter alone establishes a verified HUMAN session
  • • Authorization leases last at most 5 s and are rechecked inside the SQLite transaction

Exact Material

  • • Challenges bind session, principal, revision and material for at most 2 min
  • • expectedRevisions must name the exact WORK_ORDER revision

Durable Receipts

  • • Challenge consumption, decision, audit event and receipt commit together
  • • A receipt proves the database accepted the decision, not that execution finished