Operate

Scale the engine without hiding the evidence path.

Fidacy's request path is stateless across application instances and tenant-scoped at the database boundary. Capacity is workload-dependent: establish your own latency and throughput targets with a representative load test before relying on a production limit.

What runs on the request path

StagePurpose
auth + scopeAuthenticate the organization and reject unauthorized access before the decision pipeline.
validationValidate the payment or action envelope and any attached protocol binding.
decisionEvaluate policy, identity and risk conditions within the tenant transaction.
signReturn a JWS-bearing result when a signing key and dependencies are available.
persistRetain the decision record and the references needed for later evidence.

The engine emits Server-Timing and x-fidacy-server-timing response headers for the assessment path. Use those measurements together with your infrastructure metrics, not a documentation example, to set an operational SLO.

Work deliberately kept off the decision path

  • ·Audit-chain draining and external checkpoint work occur after the decision record is retained.
  • ·Webhook delivery is retried outside the assessment response path.
  • ·Optional analysis and reporting must not turn a valid deny into an allow when an auxiliary dependency is unavailable.
A fast response is not evidence of availability. Monitor readiness, dependency health, delivery backlog, signing-key state and the Control Coverage boundary separately.

Rate limits and backpressure

The assessment route applies organization and API-key rate limits. The defaults are configurable through the runtime environment. When the current limit is exceeded, the API returns 429 with aRetry-After header and a JSON body containing the scope and retry interval.

Treat rate limiting as a control signal. Queue or back off the caller; never retry a consequential side effect by bypassing the decision or executor boundary.

Evidence retention is a separate capacity concern

Decisions, action receipts, grants, coverage signals and audit records have different cardinality and retention characteristics. Before a regulated deployment, define the retention period, export cadence and reporting window with the customer. A Control Coverage Report discloses its retained window instead of implying unbounded history.

Production validation checklist

  • ·Load test the specific mandate/action mix and database region you will use.
  • ·Exercise 429, signing-key and database-unavailable behavior. Confirm the executor does not proceed after an unavailable decision.
  • ·Test grant redemption under concurrency and confirm a duplicate claim is refused.
  • ·Alert on stale control heartbeats, truncated sessions and growing evidence gaps.