Skip to main content

Architecture Decision Records

ADRs record durable architectural choices and their consequences. Existing decisions are numbered in chronological order and remain in Git when superseded.

Format​

# ADR-XXXX: Title

## Status

Proposed | Accepted | Deprecated | Superseded

## Context

...

## Decision

...

## Consequences

...

Use Proposed when implementation or repository evidence does not establish a settled choice. Never rewrite an accepted ADR to conceal a later decision; add a new ADR and mark the old one superseded.

Catalog​

  1. ADR-0001 — Start with a modular monolith
  2. ADR-0002 — Local JSON default, PostgreSQL target
  3. ADR-0003 — Microsoft.Extensions.AI boundary
  4. ADR-0004 — Standalone scheduler before Quartz
  5. ADR-0005 — REST, UI, and MCP share application services
  6. ADR-0006 — Agentstration is the independent Management Plane
  7. ADR-0007 — SQLite control-plane storage for standalone mode
  8. ADR-0008 — Reconstructible Microsoft Agent Framework runtime
  9. ADR-0009 — Independent Work Plane with local Runtime dispatch
  10. ADR-0010 — Independent Flow definition module
  11. ADR-0011 — Dedicated Management module
  12. ADR-0012 — Runtime Run resource and observable execution
  13. ADR-0013 — Model-provider boundary and local Ollama adapter
  14. ADR-0014 — Configuration-backed model resolution into MAF
  15. ADR-0015 — Persisted model profiles and provider APIs
  16. ADR-0016 — Real model invocation from Agent Runner
  17. ADR-0017 — Canonical runtime/model options and capabilities
  18. ADR-0018 — Persisted model-provider declarations and dynamic clients
  19. ADR-0019 — Flow-owned Run resource and execution Console
  20. ADR-0020 — Workplace Entry, Interaction, and Task vertical
  21. ADR-0021 — Standalone Workplace and Work API hosts
  22. ADR-0022 — Interaction as durable conversation and FlowRun continuation
  23. ADR-0023 — Console supervision of WorkTasks through Work API
  24. ADR-0024 — Entries always target executable Flows
  25. ADR-0025 — Tenant, workspace, and identity foundation
  26. ADR-0026 — Out-of-process model-provider extensions through AEP
  27. ADR-0027 — AEP tool contributions resolve to MCP
  28. ADR-0028 — Tool Providers materialize a governed catalog
  29. ADR-0029 — Aspire consumes an existing local Ollama installation
  30. ADR-0030 — AEP is an autonomous SDK and Inspector repository
  31. ADR-0031 — Agentstration-native declarative resource envelope
  32. ADR-0032 — Use one authoritative standalone server
  33. ADR-0033 — Canonical resource names and explicit execution identities
  34. ADR-0034 — Seal MAF Flow orchestration behind the runtime adapter
  35. ADR-0035 — Resource names are scoped by explicit namespaces
  36. ADR-0036 — Runtime resolution and control-plane hardening
  37. ADR-0037 — Packs are Management and distribution artifacts
  38. ADR-0038 — Pack Projects retain sources and produce local immutable builds
  39. ADR-0039 — Pack manifests use the native definition envelope
  40. ADR-0040 — Secrets and Vaults V1
  41. ADR-0041 — Pack resource bindings are logical and installation-scoped
  42. ADR-0042 — Authentication and authorization boundaries
  43. ADR-0043 — Console API calls propagate only an explicitly trusted Web session
  44. ADR-0044 — Identity schema and Web key material are durable
  45. ADR-0045 — Security events are an append-only Management log
  46. ADR-0046 — Platform administration is explicitly transferable
  47. ADR-0047 — External identities are explicitly linked to Principals
  48. ADR-0048 — FlowRuns carry a durable execution scope
  49. ADR-0049 — Workplace Dashboards own Entry composition
  50. ADR-0050 — Background Control Plane access is explicit
  51. ADR-0051 — Pack Projects can originate from reviewed workspace snapshots
  52. ADR-0052 — Pack composition distinguishes contained model configuration from bindings
  53. ADR-0053 — Workspace scope is part of durable identity
  54. ADR-0054 — Durable interactive Flow execution preserves exact runtime identity
  55. ADR-0055 — Agentstration owns the Tool execution boundary
  56. ADR-0056 — Tool execution hooks are ordered Runtime guards
  57. ADR-0057 — Tool execution Hook resources select built-in Runtime handlers
  58. ADR-0058 — Tool governance decisions are traced per physical attempt
  59. ADR-0059 — Tool arguments require explicit bounded retention
  60. ADR-0060 — Entry owns Workplace execution presentation
  61. ADR-0061 — llama.cpp is an AEP provider and capabilities are resolved effectively
  62. ADR-0062 — Extension options use immutable versioned contracts
  63. ADR-0063 — Extension registrations are managed discovery sources
  64. ADR-0064 — Extension option migrations are explicit
  65. ADR-0065 — Model Providers bind registered extension contributions
  66. ADR-0066 — Pack Runtime Profile bindings drive local deployment
  67. ADR-0067 — LocalAI is an independent AEP provider
  68. ADR-0068 — Triggers submit Work through a reconstructible Quartz projection
  69. ADR-0069 — Built-in resources have explicit provenance
  70. ADR-0070 — Personal access tokens are revocable Workspace delegations
  71. ADR-0071 — Remove the legacy content and mission vertical
  72. ADR-0072 — Pack updates reconcile stable resources and preserve Work history
  73. ADR-0073 — Bootstrap is a declarative initial-state source
  74. ADR-0074 — Initial topology is declarative and Platform administration is global
  75. ADR-0075 — Bootstrap files are an ordered profile catalog
  76. ADR-0076 — UI localization uses RESX and Principal culture preferences
  77. ADR-0077 — Bootstrap profiles are explicit administrative applications
  78. ADR-0078 — PostgreSQL is an optional server storage profile
  79. ADR-0079 — Management resources use explicit hierarchical scopes
  80. ADR-0080 — Management resource kinds have an initial scope policy
  81. ADR-0081 — Source Providers are bounded AEP contributions
  82. ADR-0082 — Sources have immutable versioned definitions
  83. ADR-0083 — Git Source Provider pins and archives exact commits
  84. ADR-0084 — Source Provider bindings are local version-aware configuration
  85. ADR-0085 — Source Channel snapshots pin provider provenance
  86. ADR-0086 — Source catalogs resolve inside pinned snapshots
  87. ADR-0087 — Source Channel compatibility uses Semantic Version intervals
  88. ADR-0088 — Source verification binds exact definitions and snapshots
  89. ADR-0089 — Source Bootstrap profiles reuse administrative applications
  90. ADR-0090 — AEP credentials are scope-owned and late-bound
  91. ADR-0091 — Orchestrators own development AEP shared keys
  92. ADR-0092 — Pair manually hosted AEP extensions with workspace-bound codes
  93. ADR-0093 — AEP enrollment lifecycle is explicit and audited
  94. ADR-0094 — AEP extensions initiate enrollment
  95. ADR-0095 — Source Pack installation reuses the Pack lifecycle
  96. ADR-0096 — The official Source registry uses last-known-good observations
  97. ADR-0097 — Source and Channel refresh are scheduled independently
  98. ADR-0098 — Source registry registrations are instance-owned policies
  99. ADR-0099 — Provider-specific Compose owns inference services
  100. ADR-0100 — AEP unenrollment is an explicit recoverable transition
  101. ADR-0101 — Source registry refresh joins the shared local scheduling lifecycle
  102. ADR-0102 — Source Providers follow hierarchical resource visibility
  103. ADR-0103 — Source registry trust evaluates independent evidence dimensions
  104. ADR-0104 — Source registry discovery imports retained observations exactly
  105. ADR-0105 — Flows compose reusable Flows and governed Tools
  106. ADR-0106 — ToolDefinitions publish Flow-backed MCP Tools
  107. ADR-0107 — Notification channels are delivery Flows
  108. ADR-0108 — Flow Run causality is a bounded read model
  109. ADR-0109 — The Control Plane composes plural resource-family modules
  110. ADR-0110 — API transport is composed from family-owned modules
  111. ADR-0111 — The operations Console has an independent process shell
  112. ADR-0112 — The Console BFF authenticates with instance-bound signed requests
  113. ADR-0113 — Entry exposure separates ownership from presentation
  114. ADR-0114 — Console Entry discovery projects canonical execution readiness
  115. ADR-0115 — The Console BFF owns opaque server-side sessions
  116. ADR-0116 — The Console BFF delegates short-lived API requests
  117. ADR-0117 — Browser journeys are product-owned reusable automation assets
  118. ADR-0118 — Browser campaigns use dedicated Workspaces
  119. ADR-0119 — Descendant use grants govern Secrets and Vaults
  120. ADR-0120 — Resource ChangeSet application is durable and ordered
  121. ADR-0121 — AEP Secret access uses one-use capabilities
  122. ADR-0122 — AEP contributions declare protected Value Requirements
  123. ADR-0123 — AEP Value Requirements may constrain invariant allowed values
  124. ADR-0126 — Foundry model deployments use an isolated AEP extension
  125. ADR-0127 — Foundry local Aspire discovery is explicitly opt-in
  126. ADR-0128 — Foundry non-streaming chat uses the existing AEP runtime path
  127. ADR-0129 — Foundry streaming preserves governed Tool execution
  128. ADR-0130 — Foundry advanced options follow deployment capabilities
  129. ADR-0131 — Foundry egress and diagnostics are bounded
  130. ADR-0132 — Foundry operator workflow reuses model resources
  131. ADR-0133 — Foundry provider Secret binding covers discovery
  132. ADR-0134 — Foundry connections are provider-owned AEP values
  133. ADR-0135 — Work conversations and tasks are principal-owned
  134. ADR-0136 — Model specifications are typed and resolved deterministically
  135. ADR-0137 — AEP publishes bounded typed Model observations
  136. ADR-0138 — Provider discovery reconciles governed Model resources
  137. ADR-0139 — Model Providers own exact Model specification overrides
  138. ADR-0140 — Console command fallback is a presentation role
  139. ADR-0141 — Console Entry interactions reuse durable Work
  140. ADR-0142 — Console conversation browsing projects durable Interactions
  141. ADR-0143 — Instance initialization uses a durable fenced lease
  142. ADR-0144 — Resource Plans are reviewed proposals
  143. ADR-0145 — Resource Plan Agent bindings are explicit
  144. ADR-0146 — Resource Plan profile choices are durable review drafts
  145. ADR-0147 — The official Assistant is a Workspace-owned composition