Contracts and data · Replica and authority
Local work remains responsive while shared history is accepted exactly once
Every client authors against a durable local graph and outbox. Synchronization transports canonical mutations to a deployment authority, then reconciles accepted journal history back into each authorized replica without turning caches or queues into a second semantic store.
Contracts and data · Replica and authority
Local work remains responsive while shared history is accepted exactly once
Every client authors against a durable local graph and outbox. Synchronization transports canonical mutations to a deployment authority, then reconciles accepted journal history back into each authorized replica without turning caches or queues into a second semantic store.
What this view establishes
The architectural commitments
- The local graph is a real durable replica, not a disposable UI cache, so capture and play do not wait on the network.
- Only authority-accepted journal history becomes shared history; replay never re-enqueues remote writes.
- Blob queues, leases and caches coordinate bytes while semantic identity remains in ordinary graph records.
- A mutation keeps its identity across the store's own schema migration, and the authority names itself, so a new hostname is a rename rather than a re-offered journal.
Replica swimlanes
Local replica
Local command
The product writes immediately against local contracts
SQLite graph
Durable record heads and local query semantics
Durable outbox
Ordered local mutation envelopes awaiting acceptance
Authority checkpoint
Last accepted journal sequence applied locally
Verified local blobs
Content-addressed bytes, cache policy and durable leases
Sync pump
Pushes outbox pages and pulls accepted changes
Portable boundary
Authority
Gateway acceptance
Authenticates, authorizes, validates and deduplicates
Record heads
Current authoritative entity and relationship revisions
Append-only journal
Monotonic accepted history and high-water sequence
Object authority
Authorized content-addressed upload and retrieval
Push, acceptance and checkpoint return
Connections and evidence
Open the 10-relationship source key
Numbers set an explanatory reading order. They do not measure runtime timing.
Connections and evidence
Open the 10-relationship source key
- 01implemented
Local command→SQLite graph
commits
- 02implemented
Local command→Durable outbox
enqueues atomically
- 03implemented
Durable outbox→Sync pump
ordered push
- 04implemented
Sync pump→Canonical HTTP
portable pages
- 05implemented
Canonical HTTP→Gateway acceptance
authenticated request
- 06implemented
Gateway acceptance→Record heads
atomic head
- 07implemented
Gateway acceptance→Append-only journal
appends once
- 08implemented
Append-only journal→Authority checkpoint
accepted pull
- 09implemented
Authority checkpoint→SQLite graph
applies without echo
- 10implemented
Verified local blobs→Object authority
verified transfer
Connections and evidence
10 directed, source-backed relationships
Numbers set an explanatory reading order. They do not measure runtime timing.
- 01implemented
Local command→SQLite graph
commits
- 02implemented
Local command→Durable outbox
enqueues atomically
- 03implemented
Durable outbox→Sync pump
ordered push
- 04implemented
Sync pump→Canonical HTTP
portable pages
- 05implemented
Canonical HTTP→Gateway acceptance
authenticated request
- 06implemented
Gateway acceptance→Record heads
atomic head
- 07implemented
Gateway acceptance→Append-only journal
appends once
- 08implemented
Append-only journal→Authority checkpoint
accepted pull
- 09implemented
Authority checkpoint→SQLite graph
applies without echo
- 10implemented
Verified local blobs→Object authority
verified transfer
What this view establishes
The architectural commitments
- The local graph is a real durable replica, not a disposable UI cache, so capture and play do not wait on the network.
- Only authority-accepted journal history becomes shared history; replay never re-enqueues remote writes.
- Blob queues, leases and caches coordinate bytes while semantic identity remains in ordinary graph records.
- A mutation keeps its identity across the store's own schema migration, and the authority names itself, so a new hostname is a rename rather than a re-offered journal.
Follow the live system
Move from explanation to inspection
The Atlas is static and source-backed. The Observatory shows authenticated environment state.
15 repository sources behind this view
README.mdSources/NeoStoryCore/GraphMutationExecutor.swiftSources/NeoStoryHTTP/HTTPAuthorityTransport.swiftSources/NeoStoryHTTP/HTTPBlobClient.swiftSources/NeoStorySQLite/LocalBlobStore.swiftSources/NeoStorySQLite/SQLiteGraphStore.swiftSources/NeoStorySync/GraphSync.swiftdocs/cross-platform-sync.mddocs/delegation/sync-dialect-results-2026-09-03.mddocs/scalable-authority-foundation.mdgateway/README.mdgateway/src/neostory_gateway/app.pygateway/src/neostory_gateway/authentication.pygateway/src/neostory_gateway/blob_store.pygateway/src/neostory_gateway/postgres.py