TFD Flows and Events

Durable writes, past-tense facts, staff projections, and versioned live/on-demand media streams

TFD Flows and Events Durable writes, past-tense facts, staff projections, and versioned live/on-demand media streams 01 / Owning Context 02 / In-process Facts 03 / Consumers + Projections 04 / Delivery Channels EX / Media Streams + Results Commit React Project + deliver Commit state · P0 includes Audit · Owning Context › Commit · Source of truth Commit state P0 includes Audit Source of truth Domain Fact · past tense · in process · In-process Facts › Commit · In process Domain Fact past tense · in process In process Listeners · typed · idempotent · Consumers + Projections › React Listeners typed · idempotent Projection · policy · durable inbox · Consumers + Projections › React Projection policy · durable inbox Realtime · staff room · Delivery Channels › Project + deliver Realtime staff room Staff Client · Socket.IO · HTTP · Delivery Channels › Project + deliver Staff Client Socket.IO · HTTP VIP Timeline · follow-ups · append-only · Delivery Channels › React VIP Timeline follow-ups · append-only Outbox Worker · claim · dispatch · retry · Consumers + Projections › Project + deliver Outbox Worker claim · dispatch · retry Media Jobs · Zoom + AddPipe v1 · Media Streams + Results › Commit · Redis Streams Media Jobs Zoom + AddPipe v1 Redis Streams Finalizer · remux · normalize · Media Streams + Results › React Finalizer remux · normalize Result v1 · stored/failed · Media Streams + Results › React Result v1 stored/failed Stored · AddPipe row · Media Streams + Results › Project + deliver Stored AddPipe row Available · original availableAt · Media Streams + Results › Project + deliver · After stored Available original availableAt After stored Legend User UI Agent logic Policy Tool action Context / trace

Domain event contract

  • • Events describe completed facts and use past-tense names
  • • Source state is durable before publication
  • • on_demand.video.available follows the stored AddPipe projection and carries the provider's original availableAt
  • • Notification source listeners are non-blocking; MVP delivery stays in process
  • • In-process delivery is best effort across termination; durable recovery requires a future outbox

Projection + disclosure

  • • Consumers are idempotent and recoverable
  • • VIP note facts contain identifiers and revision only
  • • Clinical note activity requires its explicit read grant

Durable async paths

  • • Per-staff inbox state is distinct from the provider-delivery outbox
  • • Role eligibility, mandatory rules, and per-staff overrides gate notification materialization; staff-access changes are always enabled
  • • Identity, Delivery, Engagement, Sales, Integrations, and scheduled due facts are projected asynchronously by Notifications; vip.renewal.weekly_digest.identified carries matched 90-day renewals and creates one subscribed financials-authorized inbox summary per staff/UTC week, with retry dedupe and no Slack output
  • • Disabled and ineligible targets are skipped independently; source writes remain committed and existing inbox items are unchanged
  • • notification.projection.committed is emitted only after create, refresh, read, read-all, or explicit expiration persists
  • • An asynchronous bridge turns committed inbox facts into local and Redis-backed notification.projection.changed signals
  • • Only staff:{staffUserId} receives inbox and unread-count invalidation events
  • • Zoom finalization and AddPipe storage use independent schema-versioned Redis Stream consumer groups
  • • AddPipe requests carry identifiers and an allowlisted HTTPS source; stored/failed results carry metadata and media bytes stay out of Redis
  • • Repeated invalid AddPipe results move to a bounded dead-letter stream; retryable work remains reclaimable and idempotent
  • • Failed work is retried without duplicating domain facts

Evidence precedes projection

  • • Cataloged P0 and P1 critical changes commit owner state and Audit together; Audit is not a VIP Activity listener
  • • Owner events publish after commit. Nested transaction failure rolls back state, evidence and deferred publication
  • • Protected reads await a sanitized access entry. Denials append through a separate non-recursive path
  • • Integrations MediaDeletionJob persists intent before an event; recovery scans pending and abandoned work, uses bounded retries and fenced completion, and exposes authorized repair. Final owner state and evidence commit together without an audit-only outbox (ADR 0068)
  • • P1 VIP and assignment histories publish only after commit; assignment capacity and replacement decisions serialize in Identity. Previously audited video decisions are not recorded a second time