Developer Manual
Operations
Separate tested behavior, host responsibility, and operational recommendations.
Operations guidance here separates tested package behavior from host responsibility and recommendation. AnswerUp packages do not supply hosted execution, provider credentials, a business database, or a complete monitoring service.
Required invariants
Keep provider and verifier credentials inside the host-controlled integration, bind every read and mutation to tenant and identity context, preserve lifecycle identities and bounded evidence, and prevent blind redispatch after UNKNOWN or process loss. User-facing claims must follow verified effect truth and claim permission.
Host and operator practice
The host should emit structured privacy-safe correlation records, monitor dispatch count and duplicate attempts, measure provider and verifier latency, alert on stuck or indeterminate actions, and define escalation for provider, verifier, policy, and process failures. Retention, redaction, access control, credential rotation, incident response, and rollback are operator decisions. These are recommendations, not guarantees supplied by the current packages.
Restart-safe workers, hosted Trace/evaluation, queue integrations, and automatic durable reconciliation remain unavailable or planned unless separately proven by current authority. Investigate UNKNOWN with the original identities and an independent read; do not report success or retry blindly.