Repository navigation
Architecture decision records
Accepted by the repository owner on 8 September 2026. These are design decisions, not claims of implemented features or production clearance. Changes require a superseding ADR; preserve decision history.
Roadmap: #49. Cross-cutting prerequisite: #50.
-
ADR-0001: Critical: cost efficiency without weakened correctness
-
ADR-0002: Owner ceilings, delegated budgets and strict admission
-
ADR-0006: Every configured support-channel thread creates a ticket
-
ADR-0007: One active direct-message ticket and conservative gratitude handling
-
ADR-0010: Policy-gated actions and controlled reference validation
-
ADR-0011: Architectural milestones and API/portal-first private beta
Current schedules and ownership: approved architectural roadmap. Earlier ADR principles remain; #50 is not a first-beta blocker and the narrow beta guardrails are tracked separately.
- ADR-0012 — Canonical conversations and channel adapters
- ADR-0013 — Authentication mail and support-email conversations are separate capabilities
- ADR-0014 — Living delivery state uses baseline, forecast and actual evidence
- ADR-0015 — Privacy metadata is not an access-control authority
Accepted decisions describe architecture; implementation status remains governed by current code and the linked roadmap issues.
The owner-approved Post-beta-master-baseline reconciles source number collisions by topic. ADR-0001–0015 remain preserved; explicit addenda supersede changed scheduling/release guidance.
- ADR-0016 — Tocyn is a helpdesk, not a CRM or marketing-engagement platform
- ADR-0017 — Persistent operator workspace replaces route-driven ticket handling
- ADR-0018 — Durable operator attention state is distinct from canonical conversation state
- ADR-0019 — Cognitive accessibility and attention control are product architecture requirements
- ADR-0020 — Operator AI augments existing human workflows instead of creating a parallel UI
- ADR-0021 — Operational observability and service-level objectives
- ADR-0022 — Deployment residency and jurisdiction boundaries
- ADR-0023 — Realtime support communications use conversation-linked support sessions
- ADR-0024 — Operator applets are declarative views over governed Tocyn capabilities
- ADR-0025 — Tenant AI is a logical retrieval boundary, not a separately trained model
- ADR-0026 — Cloudflare Access authenticates workforce entry; Tocyn authorises application capabilities
- ADR-0027 — Customer tickets, back-office work and service problems are distinct linked records
- ADR-0028 — Service feedback and reporting are bounded, event-derived support operations
- System-architecture
- Architecture-and-tenant-isolation
- Channels-and-conversation-model
- AI-and-autonomous-operations
- Architecture-decision-records