Progress needs a path. So does recovery.
A workflow should explain what happens when everything goes well—and when it doesn’t. Explore the transitions, review points and recovery choices in our runtime design.
Overview
Successful run
Ready → Claimed → Running → Verify → Human gate → Done
Work is claimed, executed and checked. The owner reviews the proposed action before the workflow is marked complete.
An endless loop
A budget and stop rule bound the number of attempts.
A duplicated action
Idempotency and ownership checks help prevent the same effect from being applied twice.
Context goes missing
Named outputs and shared state preserve the information a handoff needs.
A confident error
Independent checks and an approval gate challenge the result.
Too many approvals
Risk-based review focuses attention on the decisions that warrant it.
A partial change
Declared compensation describes how reversible effects can be unwound.
Thirty building blocks for orchestration.
The runtime design vocabulary: small, explicit operations that can be combined into a workflow.
01Condition
Pick a branch on an expression, a status or a judgment.
02Budgeted loop
Repeat a subgraph until a criterion, with a cap on iterations.
03Subworkflow
Call another workflow, including one from another OS, with its own budget.
04Diff-bound gate
The approval covers this exact diff by hash, not a paragraph.
05Declared effects
Every outside effect is declared, with live, dry-run and shadow modes.
06Durable wait
Wait for a date, an SLA or an outside event, then wake on its own.
07Scheduled trigger
Cron, including precompute outside working hours.
08Event trigger
Webhook, threshold, anomaly.
09Governed memory
Write only stable lessons; one durable file per case.
10Retry and escalation
Retry, backoff, then promotion to the next level.
11Judgment node
A typed score, choice or yes-no with its confidence; the threshold lives in code.
12Dynamic fan-out
One branch per item of a list, bounded by maxItems.
13Select and prune
Keep the best, the top k, or the winner of a vote.
14Join policy
Continue on any, a quorum of k of n, or a majority, not only all.
15Executable plan
A node emits a typed graph; the engine validates it, then runs it.
16Batched gates
A queue of gates and a scheduled review window.
17Follow a human tool
Follow the person's work in their own tool, without writing.
18Shared board
One typed workspace plus a control node that decides who runs next.
19Variants
Assign variants by rule and collect the results.
20Acknowledged handoff
A typed packet; the sender is released only once receipt is acknowledged.
21Two-person gate
Two different approvers before an effect lands.
22Compensation
Each effect carries the step that undoes it.
23Memoization
Skip a deterministic subgraph when its inputs have not changed.
24Retrieval with citations
Write only from retrieved passages, with checked citations.
25Circuit breaker
After N failures the branch opens and falls back to a safe path.
26Provider fallback
Try providers in order; this one lives on the host, outside the engine.
27Batch window
Collect for a period, then handle as one batch.
28Failure queue
Work that ran out of retries is parked with its context for inspection.
29Rate-limited queue
Buffer and drain at the rate the connected tools can take.
30Questions first
Ask the person before starting (input_required).