Skip to content

Architecture

How the software is put together, and — more importantly — where each rule is actually enforced. Start with the overview; it is the page that changes how you write code here.

Page What it answers
Where enforcement lives Why src/lib/api.ts is not a security boundary, and what is
Stack The concrete technology choices
Data model The core entities and their states
Permissions system How a gate is applied, layer by layer
Row-level security Policy shapes, naming, pitfalls
Lists, paging and search The cursor contract, and why exports throw
Frontend routing Every URL and the permission that gates it
Releases and testing The four test stacks and how a change ships
Performance: what loads when What the browser downloads at sign-in and later, what it caches, and the first-load budget (PRF-005)

Read the rules first

These pages describe the software. The rulebook describes the business the software has to implement, and wins when the two disagree.