WebMobileMCPREADER · Web, Mobile, MCP · asks · opens the instruction · says it was not enoughKNOWLEDGE MANAGER · Web, as a role · users, groups · sets · grants · sources · reads the dashboard · fixes the sourcePOST /ask {session, question} · /rate · GET /dashboard · the administrator's setup{answer, source} or not found · the org rides the session, never the callPlatform admin · ours, across organisationsPLATFORM BACKENDours · the control planeorgs minted here · licences · meteringown operators · not tenant Identitystatus in · control out · no contentstatus {org, version, health, counts, import} · reported outward, bufferedcontrol {licence, updates, organisations} · never contentPRODUCT BACKENDone organisation's product · the only thing the apps callreads knowledge only through Retrieval, never around itowns the question ledger and the dashboardthe answer model is outside · pieces in, answer outGET /session{org, user, role}/read {session, org, question | docId} · /feedback{evidence | document, who, scopeWidth, eventId}EMAILtemplates · queue · deliveryone queue for both backendssend {org, template, to, values}queued · {messageId}send {template, to, values}queuedLOGGERexceptions · eventswritten by every boxread logscodes · ids · timingsIDENTITYwho are you?users · groups · roles{session}{org, user, groups}RETRIEVALwhat may you read, and finding itthe only door a person reads throughgrants · search events · feedbackVECTOR ENGINEpieces into vectors, and the nearest for a question · derived from Documentsonly Retrieval may search here · scope in the WHERE, then the nearest vectorsa question becomes a vector with the same model that made the piecesrebuilt from Documents, never repaired · never a user, a source or a cursorsearch {org, scope, question}[{docId, page, text, score}]{org, scope: all, question}hit or none · audit onlyDOCUMENTSdocuments · identity · setstheir id in, our id out · new, changed or goneraw, precious · a unified form, deriveda set is a named group of documents, kept hereImport writes · Vector Engine and Retrieval readGET /documents/{org, id | scope}unified form · raw file · titlesGET /changes {org, mark}changes · sets · nextMarkGET /documents/{org, id}/unified{title, pages[{n, blocks}]}POST /sets {org, name} · PUT /sets/{org, id}/documents {docId}created · Documents owns itPOST /source-connections {org, type, settings}created · Import owns itPUT /documents {org, sourceRef, hash, bytes} · DELETE {org, sourceRef}{docId, new | changed | unchanged}IMPORTthe runnerconnections · cursorsrun the one that is dueonly writer to Documentschanged? · the file · valid?changes · cursor | failureADAPTERSone per source typenever told an orgSharePoint · Graph deltaDropbox · cursor APIcustom API · two callsDBthe ledgerDBorgs · licences · meteringDBtemplates · queue · sentDBlogs · local to the runtimeDBorgs · users · groupsDBgrants · search eventsPRECIOUSbytes · ids · setsbacked upDERIVEDpieces · vectorsrebuildableDBconnections · cursorsthe customer's own: a SharePoint site, a Dropbox folder, their own systema manager fixes an instruction there; the next import sees it
AN INSTALLATION, AND ONE UPGRADEa box is a container, an image pinned by its digest · a cylinder is a volume, outside the containers · a line crosses a network, or is the Updater's hand on a container · the same picture on our machine and in a customer's buildingGITHUB · BUILD AND TESTevery push: tests → 7 images → the dev installationcandidate: install · upgrade · rollback · questionswatch here: every step of every commit, green or redpush7 digestsREGISTRYGitHub's · the images, pinned by digestproduct-backend · documents · vector-engine · importemail · logger · updater · tags move, digests neverregister {digests, kind, schema, changed, notes} · edge → candidate → stablePLATFORM BACKENDours · the release catalogue · never an image1.5.0 stable · 1.6.0-rc1 candidate · edge never offeredwatch here: the fleet · deployment 123 runs 1.4.0AN INSTALLATION · ONE MACHINEours on Hetzner serving A, B, C, D · or theirs in the building serving X · same containers, same release, same Updaterwho presses Upgrade is the whole difference: on our machine, us · in their building, their IT, in their window · their IT also owns the hardware, the network and the routine backupsUPDATERpull · stop · start · migrate · restoreits own page: Releases · Upgrade · Restorepull 7 images by digestthe exact binaries that passedstatus {orgs, release, health, counts, import, upgrade} · anything newer? · hourly, bufferedcontrol {licence, releases: 1.5.0 migrating} · never content · never dialled inMAINTENANCE MODEstops · starts, in order: documents → backend, email, logger → vector engine → import · health checks gate the doorPRODUCT BACKENDidentity · retrieval insideproduct-backend @ 9f2e…DOCUMENTSparsers insidedocuments @ 41c0…VECTOR ENGINErebuild worker · modelvector-engine @ b77a…IMPORTadapters insideimport @ 5d19…EMAILtemplates · queueemail @ c2f4…LOGGERcodes · never contentlogger @ 08ab…POSTGRES 16 · pinned by version and extensionsone database and one user per owner: ledger · identity · retrieval · documents · import · emailPOSTGRES 16 + PGVECTOR 0.8the Vector Engine's alone · droppable · outside the backupCONFIGserves: A · B · C · Dtheirs: serves X onlyrelease: 1.4.0SECRETSmodel credential · ours or theirssource-credential keyservice tokens · Updater pagenever in an image or the cataloguePRECIOUSpostgres data · six ownersdumped before a migrating upgradeDERIVEDvectors · indexes · built by 1.4.0model files, pinned by id · rebuilt, never restored