- Source and state authority
- Define which event can start work, which system owns each field and status, how freshness and version are checked, how conflicting observations are represented, and which authorized correction can change the record.
- Identity and least privilege
- Preserve user, service, tenant, and delegated identity; grant only the fields and actions required for the current transition; keep credentials out of model context; expire authority; and record privileged activity independently.
- Concurrency, idempotency, and retry
- Use version preconditions, correlation and idempotency keys, explicit command semantics, bounded attempts, backoff and rate limits, duplicate receipts, partial-effect checks, and reconciliation before retrying consequential or non-idempotent work.
- Exception ownership and recovery
- Make validation failure, rejection, timeout, partial result, dependency loss, ambiguous input, policy conflict, and human delay visible with severity, named owner, due state, escalation, safe recovery options, communication, and closure criteria.
- Change and release control
- Version workflows, rules, prompts, models, schemas, connectors, credentials, dependencies, and runbooks; test representative and failure paths; stage exposure; monitor effects; preserve rollback; and revalidate material change before expansion.
- Observability and reconciliation
- Join technical, workflow, human, cost, security, and outcome evidence by correlation; protect audit records; detect stuck or divergent state; reconcile authoritative systems; retain residuals; and test that alerts and recovery work in practice.