# INTEGRATION STRATEGY v0.1 — APPROVED PLANNING BASELINE **Phase 0 · 3 October 2026 · provider-neutral documentary contracts** **Owner adoption: PASS WITH CONDITIONS**, Owner Planning Disposition §§1–2, 3 October 2026. Governing integration planning contract; unresolved providers remain unselected and optional services conditional. Sources: Owner §8; Constitution XI–XIII; Technical Direction C/F/G/H; Architecture §§5–6/8–16/24; preceding Brand/Design/Security/Data candidates. **Sanity = candidate. Drizzle = candidate. PostgreSQL provider, email, analytics and anti-abuse = unselected. Astro/Node/Autoscale provisional pending H1.** CRM/booking/additional storage conditional; no providers/accounts/resources/SDKs created or installed, no integration tested. ## Common contract, inherited by every integration below Inbound data is untrusted and bounded, validated by contract/version/environment; least-privilege authentication and environment-specific secret boundary. Exact credentials/rotation/quotas/timeout/retry limits await selection and verified capabilities. Never publish secrets or private input through client config/logs. Durable intent owns necessary delivery recovery. Retrying a mutating external operation requires explicit idempotency/unknown-result policy; read-only retries bounded as well. Record attributable safe correlation/outcome/latency/retry/error, not contact/free text/tokens. Provider acknowledgement, actual delivery and staff response remain different facts. Each integration needs appointed operational owner/backup, approved account/domain and cost ceiling, processor/privacy review, documented exit/export and cleanup authority. Roles below are requirements—not appointments. Approve routine reversible details through actual delegated authority; escalate material spend, contractual/rights/privacy/security/geography consequences. Gate evidence informs selection; never grants procurement or publication authority. The tables jointly form each integration's full contract: purpose/truth/data/auth/secret plus retries/idempotency/failure/observability/ownership/cost/exit/gate. ## Boundary and data contracts | ID | Purpose / authoritative source | Inbound / outbound data | Authentication class / secret boundary | |---|---|---|---| | I-CMS | Approved editorial truth and permitted media; public release derived | Approved structured revision/metadata/media → content adapter/build; draft ↔ protected editor preview | Scoped provider/editor access; read/build/publish roles separated; server-only sensitive preview/build credentials | | I-JOURNAL | Durable accepted inquiry + required intent, minimal delivery state | Validated private intake/intent → atomic transaction; restricted record/attempt reads → authorized staff recovery | Scoped server DB connection/trusted staff-tool access; no browser DB credentials/public lookup | | I-EMAIL | Provider delivery events, not acceptance truth | Minimal authorized message/contact data + internal correlation → provider; verified event → journal delivery state | Scoped server send credential; verified callback signatures/auth; dedicated environment/domain destinations | | I-ANALYTICS | Non-private measurement, not acceptance truth | Approved page/practice/conversion events only; consent-aware reports → operating review | Only genuinely public non-secret event config in browser if selected; administrative/API credentials server/staff-only | | I-ABUSE | Shared enforcement supporting acceptance security | Minimal approved signals → selected shared controls; allow/challenge/deny/dependency status → intake | Selected server/client split; browser site key only if truly public, sensitive verification credential server-only | | I-CRM | Conditional commercial follow-up truth after website acceptance | Minimal approved accepted inquiry handoff → CRM; bounded transfer acknowledgement → journal | Scoped server adapter/vendor staff access; no public/custom CRM API product | | I-BOOKING | Conditional managed calendar/booking truth | Approved availability/link/booking flow; minimal explicitly approved contact/context | Vendor-managed access; server-only tokens where needed; embedded/public link class reviewed | | I-SEARCH | Search Console verification/indexing readiness, not content truth | Actual approved origin/site verification/sitemap/indexing observations | Verified domain ownership/vendor staff account; verification material assessed by class; private credentials never public | | I-MONITOR | Safe health/error/queue/operational alert evidence | Non-private health/count/error/delivery-age signals → alert; incident acknowledgment → runbook | Scoped collectors/alert destination credentials server-side; restricted operational views | | I-RELEASE | Revision-specific checked build/promotion/provenance | Approved revision + app/assets → checked release; authenticated trigger/event → controlled promotion | Scoped build/publish roles, verified callbacks; no browser publish secret | ## Operational and exit contracts | ID | Retries / idempotency / failure semantics | Observability / ownership | Cost / exit / validation | |---|---|---|---| | I-CMS | Bounded content reads; revision pinned; repeat build must not silently consume unapproved edits. API failure retains last approved release; asset CDN failure separately degrades media | Revision/build/approval/media provenance and safe errors; editorial/publisher + backup | Quotas, seats, assets/build requests/processors; usable content/revision/media export; H2/H10, preview H9 | | I-JOURNAL | Atomic inquiry+intent before success; safe dedup/concurrency/conflict/ambiguous commit policy; DB rejection never success. Shared pool bounded; restart/republish persists | Transaction/result/intent/attempt correlation without payload; journal/recovery owner + restricted staff | Connection/storage/restore/export limits; portable data and coordinated code compatibility; H3/H7/H8/H9 | | I-EMAIL | Durable scheduled retry with backoff/limits, provider idempotency verified; timeout may mean accepted externally. Replay-safe signed events; failures cannot erase committed inquiry | Distinguish queued/attempted/provider-accepted/delivered/bounced/manual attention; response/delivery owner | Domain ownership/SPF/DKIM/DMARC, volume/retry cost/processor terms; replace adapter and reconcile in-flight effects; H4/H3/H9 | | I-ANALYTICS | Drop/degrade nonessential events when blocked/unavailable; never delay or reverse journal acceptance; duplicate-event policy documented | Request payload audit, conversion source, consent/blocker/sample limits; measurement/privacy owner | Events/seats/processor/retention; export non-private reports and remove scripts safely; H6/H9 and quality | | I-ABUSE | Shared concurrent/replica controls; fail/degrade policy explicit, no silent false acceptance; bounded verification timeout, no blind expensive retries | Safe rejection/availability counts, legitimate user/shared-network false positives; security/operations owner | Verification/request cost and privacy exposure; replace controls without weakening mandatory acceptance security; H5/H3 | | I-CRM | Durable minimal handoff, correlation/dedup, unknown-result/manual recovery; unavailable CRM cannot invalidate journal acceptance | Transfer acknowledgment and exception visibility, not all later sales activity; commercial owner | Conditional seats/API/processors/export; Owner adoption; preserve journal independent, export CRM truth; H3 + approved integration proof/H9 | | I-BOOKING | Optional scheduling separate from inquiry acceptance; do not claim appointment or inquiry unless actually confirmed; retries delegated to proven vendor semantics | Availability/embed failure fallback, actual booking source; calendar owner | Conditional subscriptions/embed/privacy/a11y/script impact; Owner adoption; retain approved contact fallback; approved proof/H9/quality | | I-SEARCH | Bounded inspection/indexing operations; outage cannot affect site acceptance/content; no indexing guarantee | Domain verification/sitemap/robots/indexing observations; publishing/SEO owner | Actual domain ownership, access and tooling terms; export settings/observations, remove safely; production readiness and launch approval | | I-MONITOR | Bounded alert retries/dedup/no storm; collector failure never journal prerequisite; threshold and missed-alert escalation explicit | Release health, journal/intent aging, dependency/restore alerts and assigned acknowledgment; incident/recovery owner | Sampling/log/retention/request cost, alert privacy; export safe evidence/runbooks and replace agent; integrated failure/recovery/H8/H9 | | I-RELEASE | Authenticated replay-safe trigger; explicit approved revision; failed fetch/build/check cannot promote. Correction/rollback uses rights-valid release only | App/content/assets/approval/time provenance; authorized publisher/rights lead | Build/media/cache/history cost and removal constraints; recover/rebuild/export usable release; H2/H10/H9 and production gates | ## Journal-driven dispatch and callback detail Requirements: acceptance persists independently of provider availability; outstanding intents become discoverable across process restart/idle/replicas; minimal staff can inspect/recover safely. Activation/lease/trigger mechanism **UNRESOLVED**—do not assume post-response tasks, process timers or fire-and-forget survive. No message broker/scheduler/custom dashboard is selected merely to make this document complete. Bound attempts, concurrency, backoff, maximum elapsed retry and manual-attention thresholds against actual provider/hosting/database limits and operating ceiling. Exact values require later proof. A lease alone is not exactly-once delivery; reconcile unknown provider outcomes before replay. Callbacks validate signature/authentication over correct bounded bytes, event timestamp/replay/identity/environment and permitted state transition; duplicates/out-of-order events must not create contradictory truth. Signature failures do not log raw sensitive headers/payloads. Staff intervention is authorized/restricted and auditable; no public retrieval portal. ## Publication and content independence Protected preview of identified revision → explicit claim/media approval → authorized build/check → controlled successful promotion with versioned app/content/media/approval metadata. CMS API failure must not break previously published text; media/CDN dependency remains separate and must be measured. Export includes necessary assets/references and documented permissions, not just JSON. Define urgent correction/withdrawal path, caching/removal limitations, rollback rights validity and incident escalation. Preserve public content during technical failure but never treat it as permission to retain withdrawn material indefinitely. ## Conditional storage and selected-provider record No extra storage service required by default. If justified later, apply H11 project/environment/public-private/location/export/recovery and no cross-venture coupling; record selection before applying N/A or a PASS. CRM and booking may be deferred without blocking the base intake path when the Owner explicitly dispositions their launch scope. For every eventual selected provider record: version/service, accountable account/owner, purpose/data class, authenticating roles, processor/region, actual limits/quotas, spend ceiling, operating/incident owner, validated gates/evidence, approved decision, exit/portability and open conditions. Sanity/Drizzle remain candidates; document completeness is not vendor selection. ## Acceptance Later review requires each table contract resolved into selected-tool details without weakening trust/source-of-truth/failure invariants; isolated gate evidence followed by integrated outage/retry/replay/recovery tests; costs/privacy/location and minimal operating ownership confirmed before reliance. This current candidate is provider-neutral, not an implemented adapter system or completed gate.