Execution and state
Separate commands, canonical rows, durable events, workflow history, and live delivery.
Four different records
- A REST command expresses intent and carries a command ID plus idempotency key.
- PostgreSQL current state answers what is true now.
- An immutable domain event records an accepted change and gives clients an opaque replay cursor.
- Temporal workflow history durably coordinates work but is not a second semantic database.
SSE delivers authorized persisted events after a cursor and then follows new events. A cursor is opaque and strictly ordered within the delivered stream; gaps are legal and clients never do cursor arithmetic.
Independent control dimensions
Run, task, and attempt control separates execution phase, desired state, wait reason, generation, and plan revision. This prevents “waiting for approval,” “paused,” “cancelled,” and “failed” from becoming ambiguous values in one oversized enum. Temporal reconciliation reads those canonical dimensions and starts or cancels fenced child workflows; it does not infer product state from its own history. See the generated state reference for exact categorical values.
A task's execution profile is not a mutable tool policy. Immediately before an attempt starts, Lumen resolves the fixed local harness and current trusted workspace policy into one immutable runtime manifest. Its digest fences the build, image, environment, Pi/model/reasoning identities, local tools and limits, trusted definition digests and remote provenance, context bundle, and subagent caps. A retry gets a new attempt and may therefore get a newly resolved manifest; an existing attempt never silently changes harness.
Failure semantics
A retry creates a new immutable attempt. A late success can remain diagnostic evidence but cannot resurrect a cancelled or newer generation. An external side effect with an ambiguous response is reconciled before retry; the system never assumes a timeout means nothing happened.