Factory docs, home
Page navigation

Reference document, shown as written except that local paths appear as placeholders. Where it describes the Factory as intended, read it as design, not current state: only local infrastructure is accepted, no release, customer value or scheduled automation is established, and all 27 customer-value epics remain open. Current state: Factory model.

Read in order: value lifecycle, decision domains, durable runtime, safe release, Capability evolution and uncertain external effects. All are proposals. Architecture contracts describe the same six views.

01 Value through the whole lifecycle

Discover, deliver, observe and change course. The factory follows this lifecycle too.

01  Value through the whole lifecycle

Open diagram 1 at full size.

Read the diagram: What is the next useful change? A Slice pins scope and the intended benefit. What proves value? An Assessment compares observations with that intent. Where can it loop back? Failed checks repair the Candidate; learning changes the next Slice.

02 Decision domains and recovery

One modular application; independent recovery remains available when it fails.

02  Decision domains and recovery

Open diagram 2 at full size.

Read the diagram: Who owns the decision? Five domains decide; shared foundations execute and record. What survives a failure? Independent recovery can restore the factory and product availability. What is not a service? These are module boundaries, not five separately deployed services.

03 Durable facts and execution

The database owns facts and public Run state. Temporal owns execution position.

03  Durable facts and execution

Open diagram 3 at full size.

Read the diagram: Where is the durable truth? The database commits facts, public Run state, results and outbox together. What can repeat? Outbox delivery and a Command with the same stable identity. What must not repeat? A projection rebuild cannot dispatch an external effect.

04 Safe exposure and observed availability

Verify before protected integration. Risk decides the release path.

04  Safe exposure and observed availability

Open diagram 4 at full size.

Read the diagram: What is allowed to move? Only the exact Candidate that independent checks verified. What proves availability? A channel Receipt plus a probe through the customer path. What happens on harm? Disable, restore or repair. Monitoring continues after delivery closure.

05 Capability disposition and health

Retirement is a decision; regression is an observation. Keep both facts.

05  Capability disposition and health

Open diagram 5 at full size.

Read the diagram: What do we still need? Disposition records required, retiring or deliberately retired behaviour. What do we currently know? Health records healthy, unknown or degraded evidence separately. What should recovery restore? Safe required behaviour or an approved replacement; never blind revival.

06 An uncertain external effect

A timeout is not proof that an external change failed.

06  An uncertain external effect

Open diagram 6 at full size.

Read the diagram: What does a timeout mean? The effect is Unknown. It may already have happened remotely. When is another dispatch safe? Prove non-application, retain the Action key and recheck current guards. What closes the uncertainty? Independent confirmation produces a Receipt; replay itself cannot dispatch.

Source: docs/diagrams.md