Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Architecture Decision Records

This directory contains Architecture Decision Records (ADRs) for agent-assembly. Each ADR documents a significant architectural choice — the context that drove the decision, the alternatives considered, and the consequences accepted.

The format follows a lightweight variant of Michael Nygard’s template. New ADRs are numbered sequentially and never rewritten; superseded decisions are recorded by adding a new ADR that links back.

An ADR records only durable product or system decisions — product and business semantics, user-visible behaviour, security and enforcement semantics, public API and data contracts, OSS-vs-SaaS boundaries, durable architecture and component boundaries, and long-term direction that constrains future implementations. Development-process instructions are not ADR material: CI, review, release and test-execution procedure, merge and branch policy, and contributor workflow conventions belong in CONTRIBUTING.md, .claude/, a runbook, a PR template, or a CI workflow. Being technical is not the test — the test is whether the primary subject is a decision or a procedure.

Numbers are permanent identifiers. A number, once used, is never reassigned — so the gaps below are deliberate and must stay empty: 0005 was used and later retired (created in 90679f35, reframed in 643700e5, its number withdrawn thereafter), and 0028 is retired (its CI trigger-scoping rule moved to CONTRIBUTING.md as development process). There are 32 active ADRs.

Index

ADRTitleStatus
0001Storage Architecture — SQLite (local) / PostgreSQL + TimescaleDB (production)Accepted
0002SDK Security Boundary, Shared-Crate Layout & DistributionAccepted
0003Cross-Repo Dependency Pinning on the Core CratesAccepted
0004Governance Enforcement Flow — SDK → aa-sdk-client → core (gRPC / UDS)Accepted
0006Limited-Function Self-Host — Kubernetes (Helm) / Terraform SupportAccepted
0007Public Domain & URL ContractProposed
0008SaaS Host Routing, Auth & Cookie BoundariesProposed
0009Versioned Base-Image Tags & Reproducible SDK PinningProposed
0010Gateway Distribution for Self-Host & ExamplesProposed
0011Cross-Process Op-Control Delivery via a NATS Subject (durable JetStream)Accepted
0012WebSocket & Browser Credential Handling (OSS vs SaaS)Accepted
0013Version Metadata Source-of-Truth & Drift GateProposed
0014Canonical Metadata Registry & Drift GateProposed
0015DLP Trust Boundary, Redaction Fail-Safety & Heuristic Detection LimitsAccepted
0016Organization-wide Default Branch — mastermainAccepted
0017Dashboard Design-Parity — Ratified EvolutionsAccepted
0018Canonical Runtime Verdict & Enriched Decision RecordAccepted
0019Agent Trust-Score DerivationAccepted
0020Rolling vs Calendar Monthly Budget Windows — and the Missing Team TierAccepted (rolling window still decision-gated)
0021Topology Enforcement-Mode Mutation — Authorization, Blast Radius & ReversibilityAccepted
0022Agent-Detail Config Projection & Quantified Posture RecommendationsAccepted
0023Is aa-api Meant to Carry a Policy Cascade?Accepted
0024Semantics of an Empty or Unavailable Policy CascadeAccepted
0025design/v2/ Is the Authoritative Visual SpecificationProposed
0026Seven Open Dashboard Product-Semantics DecisionsProposed (Decision 2 Accepted)
0027The Accessibility Floor Overrides the Visual SpecificationAccepted
0029Capability Over-Permission DerivationProposed
0030Developer Integration Boundaries, Capability Model & Local Trust ModelAccepted
0031OSS Native Account AuthenticationAccepted
0032Local-First Sensitive-Data Provider ArchitectureAccepted
0033Canonical Governance & Enforcement ArchitectureAccepted
0034One Product Truth & Cross-Repository Documentation GovernanceAccepted