draftDraft
Inputs, schema, coordinate system, ownership, and processing intent are declared but not accepted.
Ingest versioned data, validate and publish it, execute reproducible analysis, review lineage, and share a governed decision layer.
A state is not a UI label. It determines which actor may act, what evidence exists, what may be retried, and how recovery proceeds.
draftInputs, schema, coordinate system, ownership, and processing intent are declared but not accepted.
validatingFormat, schema, geometry, coordinate reference, limits, and policy are being checked.
publishedAn immutable dataset version is queryable with explicit workspace access and lineage.
processingAn analysis job references fixed input versions, parameters, runtime, and output ownership.
readyOutputs, quality metrics, logs, lineage, and visualization metadata are complete.
sharedA governed audience can view or embed a selected output version under explicit policy.
failedterminalValidation or processing stopped with typed, attributable diagnostics and retained inputs.
Commands express intent. The aggregate validates current state and invariants, commits one new version, and emits a fact in the same transaction.
create_dataset_versionData engineerdataset.version_createdKey by workspace, logical dataset, source hash, and intended version.
validateSpatial analystdraftdataset.validation_startedReuse the same validation attempt for identical content and policy.
publishWorkspace administratorvalidatingdataset.publishedCommit immutable version and permissions atomically.
run_analysisSpatial analystpublishedreadyanalysis.startedHash input versions, parameters, runtime, and output owner.
complete_analysisSpatial processing serviceprocessinganalysis.completedOne attempt identity can publish one immutable output manifest.
create_shareWorkspace administratorreadyshare.createdKey by output version, audience, policy, and expiry.
Keep provider responses, business identity, state, events, and side-effect delivery distinct so each can be reconciled safely.
Immutable source or derived spatial asset.
datasetIdversioncontentHashcrsschemaownerReproducible execution and typed status.
analysisIdattemptinputsparametersruntimestatusAuditable graph from source versions to outputs and shares.
outputVersioninputVersionsoperationgeneratedAtqualityAudience, expiry, export, embedding, and revocation controls.
shareIdresourceVersionaudiencepermissionsexpiresAtPublished input and output versions are immutable.
Every output records exact input versions, parameters, runtime, and actor.
Workspace authorization applies separately to source, job, output, visualization, and share.
A retry is linked to its previous attempt and never overwrites it.
Revoking a share does not destroy dataset or analysis lineage.
Recovery changes durable truth only through the same rules as normal operation. A timeout is an unknown outcome, not evidence that nothing happened.
The client upload ID has incomplete acknowledged parts.
Resume only missing parts and verify the final content hash before validation.
Extent, geometry validity, or known control points conflict with the declaration.
Fail validation with actionable diagnostics; require an explicit corrected version.
Lease expires without a terminal attempt record.
Resume from supported checkpoint or create a linked retry under the same analysis identity.
Resource policy version or expiry no longer authorizes the audience.
Deny access immediately, record the decision, and require a newly authorized share.
Measure state age, event health, retries, reconciliation, and sensitive-data access alongside latency and error rate.
Only explicitly indexed evidence is linked. Empty sections are not backfilled with invented endpoints or package names.
8 labs · 5 hostile scenariosmapmyindia-mgis-apismapmyindia-mgis-librariesmappls-insight-sdk8 verified tests