Architecture Decision Records
ADRs record durable architectural choices and their consequences. Existing decisions are numbered in chronological order and remain in Git when superseded.
Format
# ADR-XXXX: Title
## Status
Proposed | Accepted | Deprecated | Superseded
## Context
...
## Decision
...
## Consequences
...
Use Proposed when implementation or repository evidence does not establish a settled choice. Never rewrite an accepted ADR to conceal a later decision; add a new ADR and mark the old one superseded.
Catalog
- ADR-0001 — Start with a modular monolith
- ADR-0002 — Local JSON default, PostgreSQL target
- ADR-0003 — Microsoft.Extensions.AI boundary
- ADR-0004 — Standalone scheduler before Quartz
- ADR-0005 — REST, UI, and MCP share application services
- ADR-0006 — Agentstration is the independent Management Plane
- ADR-0007 — SQLite control-plane storage for standalone mode
- ADR-0008 — Reconstructible Microsoft Agent Framework runtime
- ADR-0009 — Independent Work Plane with local Runtime dispatch
- ADR-0010 — Independent Flow definition module
- ADR-0011 — Dedicated Management module
- ADR-0012 — Runtime Run resource and observable execution
- ADR-0013 — Model-provider boundary and local Ollama adapter
- ADR-0014 — Configuration-backed model resolution into MAF
- ADR-0015 — Persisted model profiles and provider APIs
- ADR-0016 — Real model invocation from Agent Runner
- ADR-0017 — Canonical runtime/model options and capabilities
- ADR-0018 — Persisted model-provider declarations and dynamic clients
- ADR-0019 — Flow-owned Run resource and execution Console
- ADR-0020 — Workplace Entry, Interaction, and Task vertical
- ADR-0021 — Standalone Workplace and Work API hosts
- ADR-0022 — Interaction as durable conversation and FlowRun continuation
- ADR-0023 — Console supervision of WorkTasks through Work API
- ADR-0024 — Entries always target executable Flows
- ADR-0025 — Tenant, workspace, and identity foundation
- ADR-0026 — Out-of-process model-provider extensions through AEP
- ADR-0027 — AEP tool contributions resolve to MCP
- ADR-0028 — Tool Providers materialize a governed catalog
- ADR-0029 — Aspire consumes an existing local Ollama installation
- ADR-0030 — AEP is an autonomous SDK and Inspector repository
- ADR-0031 — Agentstration-native declarative resource envelope
- ADR-0032 — Use one authoritative standalone server
- ADR-0033 — Canonical resource names and explicit execution identities
- ADR-0034 — Seal MAF Flow orchestration behind the runtime adapter
- ADR-0035 — Resource names are scoped by explicit namespaces
- ADR-0036 — Runtime resolution and control-plane hardening
- ADR-0037 — Packs are Management and distribution artifacts
- ADR-0038 — Pack Projects retain sources and produce local immutable builds
- ADR-0039 — Pack manifests use the native definition envelope
- ADR-0040 — Secrets and Vaults V1
- ADR-0041 — Pack resource bindings are logical and installation-scoped
- ADR-0042 — Authentication and authorization boundaries
- ADR-0043 — Console API calls propagate only an explicitly trusted Web session
- ADR-0044 — Identity schema and Web key material are durable
- ADR-0045 — Security events are an append-only Management log
- ADR-0046 — Platform administration is explicitly transferable
- ADR-0047 — External identities are explicitly linked to Principals
- ADR-0048 — FlowRuns carry a durable execution scope
- ADR-0049 — Workplace Dashboards own Entry composition
- ADR-0050 — Background Control Plane access is explicit
- ADR-0051 — Pack Projects can originate from reviewed workspace snapshots
- ADR-0052 — Pack composition distinguishes contained model configuration from bindings
- ADR-0053 — Workspace scope is part of durable identity
- ADR-0054 — Durable interactive Flow execution preserves exact runtime identity
- ADR-0055 — Agentstration owns the Tool execution boundary
- ADR-0056 — Tool execution hooks are ordered Runtime guards
- ADR-0057 — Tool execution Hook resources select built-in Runtime handlers
- ADR-0058 — Tool governance decisions are traced per physical attempt
- ADR-0059 — Tool arguments require explicit bounded retention
- ADR-0060 — Entry owns Workplace execution presentation
- ADR-0061 — llama.cpp is an AEP provider and capabilities are resolved effectively
- ADR-0062 — Extension options use immutable versioned contracts
- ADR-0063 — Extension registrations are managed discovery sources
- ADR-0064 — Extension option migrations are explicit
- ADR-0065 — Model Providers bind registered extension contributions
- ADR-0066 — Pack Runtime Profile bindings drive local deployment
- ADR-0067 — LocalAI is an independent AEP provider
- ADR-0068 — Triggers submit Work through a reconstructible Quartz projection
- ADR-0069 — Built-in resources have explicit provenance
- ADR-0070 — Personal access tokens are revocable Workspace delegations
- ADR-0071 — Remove the legacy content and mission vertical
- ADR-0072 — Pack updates reconcile stable resources and preserve Work history
- ADR-0073 — Bootstrap is a declarative initial-state source
- ADR-0074 — Initial topology is declarative and Platform administration is global
- ADR-0075 — Bootstrap files are an ordered profile catalog
- ADR-0076 — UI localization uses RESX and Principal culture preferences
- ADR-0077 — Bootstrap profiles are explicit administrative applications
- ADR-0078 — PostgreSQL is an optional server storage profile
- ADR-0079 — Management resources use explicit hierarchical scopes
- ADR-0080 — Management resource kinds have an initial scope policy
- ADR-0081 — Source Providers are bounded AEP contributions
- ADR-0082 — Sources have immutable versioned definitions
- ADR-0083 — Git Source Provider pins and archives exact commits
- ADR-0084 — Source Provider bindings are local version-aware configuration
- ADR-0085 — Source Channel snapshots pin provider provenance
- ADR-0086 — Source catalogs resolve inside pinned snapshots
- ADR-0087 — Source Channel compatibility uses Semantic Version intervals
- ADR-0088 — Source verification binds exact definitions and snapshots
- ADR-0089 — Source Bootstrap profiles reuse administrative applications
- ADR-0090 — AEP credentials are scope-owned and late-bound
- ADR-0091 — Orchestrators own development AEP shared keys
- ADR-0092 — Pair manually hosted AEP extensions with workspace-bound codes
- ADR-0093 — AEP enrollment lifecycle is explicit and audited
- ADR-0094 — AEP extensions initiate enrollment
- ADR-0095 — Source Pack installation reuses the Pack lifecycle
- ADR-0096 — The official Source registry uses last-known-good observations
- ADR-0097 — Source and Channel refresh are scheduled independently
- ADR-0098 — Source registry registrations are instance-owned policies
- ADR-0099 — Provider-specific Compose owns inference services
- ADR-0100 — AEP unenrollment is an explicit recoverable transition
- ADR-0101 — Source registry refresh joins the shared local scheduling lifecycle
- ADR-0102 — Source Providers follow hierarchical resource visibility
- ADR-0103 — Source registry trust evaluates independent evidence dimensions
- ADR-0104 — Source registry discovery imports retained observations exactly
- ADR-0105 — Flows compose reusable Flows and governed Tools
- ADR-0106 — ToolDefinitions publish Flow-backed MCP Tools
- ADR-0107 — Notification channels are delivery Flows
- ADR-0108 — Flow Run causality is a bounded read model
- ADR-0109 — The Control Plane composes plural resource-family modules
- ADR-0110 — API transport is composed from family-owned modules
- ADR-0111 — The operations Console has an independent process shell
- ADR-0112 — The Console BFF authenticates with instance-bound signed requests
- ADR-0113 — Entry exposure separates ownership from presentation
- ADR-0114 — Console Entry discovery projects canonical execution readiness
- ADR-0115 — The Console BFF owns opaque server-side sessions
- ADR-0116 — The Console BFF delegates short-lived API requests
- ADR-0117 — Browser journeys are product-owned reusable automation assets
- ADR-0118 — Browser campaigns use dedicated Workspaces
- ADR-0119 — Descendant use grants govern Secrets and Vaults
- ADR-0120 — Resource ChangeSet application is durable and ordered
- ADR-0121 — AEP Secret access uses one-use capabilities
- ADR-0122 — AEP contributions declare protected Value Requirements
- ADR-0123 — AEP Value Requirements may constrain invariant allowed values
- ADR-0126 — Foundry model deployments use an isolated AEP extension
- ADR-0127 — Foundry local Aspire discovery is explicitly opt-in
- ADR-0128 — Foundry non-streaming chat uses the existing AEP runtime path
- ADR-0129 — Foundry streaming preserves governed Tool execution
- ADR-0130 — Foundry advanced options follow deployment capabilities
- ADR-0131 — Foundry egress and diagnostics are bounded
- ADR-0132 — Foundry operator workflow reuses model resources
- ADR-0133 — Foundry provider Secret binding covers discovery
- ADR-0134 — Foundry connections are provider-owned AEP values
- ADR-0135 — Work conversations and tasks are principal-owned
- ADR-0136 — Model specifications are typed and resolved deterministically
- ADR-0137 — AEP publishes bounded typed Model observations
- ADR-0138 — Provider discovery reconciles governed Model resources
- ADR-0139 — Model Providers own exact Model specification overrides
- ADR-0140 — Console command fallback is a presentation role
- ADR-0141 — Console Entry interactions reuse durable Work
- ADR-0142 — Console conversation browsing projects durable Interactions
- ADR-0143 — Instance initialization uses a durable fenced lease
- ADR-0144 — Resource Plans are reviewed proposals
- ADR-0145 — Resource Plan Agent bindings are explicit
- ADR-0146 — Resource Plan profile choices are durable review drafts
- ADR-0147 — The official Assistant is a Workspace-owned composition