Architecture
How the software is put together, and — more importantly — where each rule is actually enforced. Start with the overview; it is the page that changes how you write code here.
| Page | What it answers |
|---|---|
| Where enforcement lives | Why src/lib/api.ts is not a security boundary, and what is |
| Stack | The concrete technology choices |
| Data model | The core entities and their states |
| Permissions system | How a gate is applied, layer by layer |
| Row-level security | Policy shapes, naming, pitfalls |
| Lists, paging and search | The cursor contract, and why exports throw |
| Frontend routing | Every URL and the permission that gates it |
| Releases and testing | The four test stacks and how a change ships |
| Performance: what loads when | What the browser downloads at sign-in and later, what it caches, and the first-load budget (PRF-005) |
Read the rules first
These pages describe the software. The rulebook describes the business the software has to implement, and wins when the two disagree.