Operate
Scale the engine without hiding the evidence path.
Fidacy's request path is stateless across application instances and tenant-scoped at the database boundary. Capacity is workload-dependent: establish your own latency and throughput targets with a representative load test before relying on a production limit.
What runs on the request path
| Stage | Purpose |
|---|---|
auth + scope | Authenticate the organization and reject unauthorized access before the decision pipeline. |
validation | Validate the payment or action envelope and any attached protocol binding. |
decision | Evaluate policy, identity and risk conditions within the tenant transaction. |
sign | Return a JWS-bearing result when a signing key and dependencies are available. |
persist | Retain the decision record and the references needed for later evidence. |
The engine emits Server-Timing and x-fidacy-server-timing response headers for the assessment path. Use those measurements together with your infrastructure metrics, not a documentation example, to set an operational SLO.
Work deliberately kept off the decision path
- ·Audit-chain draining and external checkpoint work occur after the decision record is retained.
- ·Webhook delivery is retried outside the assessment response path.
- ·Optional analysis and reporting must not turn a valid deny into an allow when an auxiliary dependency is unavailable.
Rate limits and backpressure
The assessment route applies organization and API-key rate limits. The defaults are configurable through the runtime environment. When the current limit is exceeded, the API returns 429 with aRetry-After header and a JSON body containing the scope and retry interval.
Treat rate limiting as a control signal. Queue or back off the caller; never retry a consequential side effect by bypassing the decision or executor boundary.
Evidence retention is a separate capacity concern
Decisions, action receipts, grants, coverage signals and audit records have different cardinality and retention characteristics. Before a regulated deployment, define the retention period, export cadence and reporting window with the customer. A Control Coverage Report discloses its retained window instead of implying unbounded history.
Production validation checklist
- ·Load test the specific mandate/action mix and database region you will use.
- ·Exercise 429, signing-key and database-unavailable behavior. Confirm the executor does not proceed after an unavailable decision.
- ·Test grant redemption under concurrency and confirm a duplicate claim is refused.
- ·Alert on stale control heartbeats, truncated sessions and growing evidence gaps.