Architecture Decision Records¶
Settled designs (including the D1–D20 register) are revisited by proposing a new ADR, never a drive-by PR. Structure and authoring rules: .agents/skills/docs-spec/SKILL.md.
- 0001 — Open-Standard Agent Collaboration Platform - build exclusively on open protocols and OSS; every layer swappable
- 0002 — Matrix as the Human↔Agent Collaboration Fabric - federated Matrix rooms as the shared collaboration surface
- 0003 — Synapse + MAS + Element via ESS Community - reference homeserver profile, with governed fallback triggers
- 0004 — A2A Delegation, Non-Streaming, via a2a-go - original non-streaming delegation decision on the official SDK; task polling added later
- 0005 — Bridge as a mautrix/go Appservice - plain appservice, not bridgev2
- 0006 — agentgateway as the Egress Chokepoint - no agent holds a model credential
- 0007 — Shared CloudNativePG, Database-per-Service - one cluster, scoped database + role per service
- 0008 — Agent Rooms Unencrypted, Enforced Server-Side - superseded by ADR 0026's per-room decision
- 0009 — Agent Authorization Through Managed Room Membership - invocation access through room membership, not a parallel invocation ACL
- 0010 — Defer SPIFFE Workload Identity - until both protocol endpoints can consume it
- 0011 — Coexist with Microsoft Teams; No Production Bridge - coexistence over a fragile bridge promise
- 0012 — Bridge Decomposition and Surface Budget - cap what the bridge core may grow
- 0013 — Federation Lab as the Permanent Acceptance Rig - provider-free lab gates cross-org changes
- 0014 — ActivityPub as a Second Federation Transport - additive AP transport in a self-contained app, Proposed (M18)
- 0015 — Federated Agent Rooms Remain Unencrypted for v1 - current plaintext-room controls retained while ADR 0026's crypto stages remain unproven
- 0016 — Durable Delegation Ledger with At-Most-Once A2A Recovery - pre-ACK jobs, fenced recovery, explicit A2A ambiguity, and deterministic Matrix projection
- 0017 — Permission-Aware Retrieval Identity Binding - gateway-projected identity and complete output-audience ACL prefiltering
- 0018 — Content-Bounded Matrix Identity Audit - opt-in authentication/event evidence from exact pinned source records, never generic logs
- 0019 — Snapshot-Backed Synapse Media PVC - retained local PVC and explicit CSI snapshot recovery for the GKE reference
- 0020 — Retain Bash Acceptance Rigs Until a Measured Pilot Trigger - keep ShellCheck-gated rigs until one bounded Go pilot meets explicit evidence thresholds
- 0021 — Out-of-Band Pinned Key Resolution for the ActivityPub Border - verify operator-pinned in-cluster signers without a network fetch; unpinned actors stay on the unchanged SSRF guard
- 0022 — Evaluate AGNTCY for Cross-Org Agent Identity and Discovery - track AGNTCY Identity/OASF/Directory as candidate federation identity/discovery, Proposed; reject SLIM as a transport
- 0023 — Governed User-Agent Memory Requires Explicit Consent and Exact Erasure - keep semantic memory disabled until every user can inspect, bound, and erase one exact scope
- 0024 — Authenticated Query-Embedding Egress for Permission-Aware Retrieval - one authenticated retrieval→agentgateway embeddings edge to unblock #333, Proposed (M25)
- 0025 — Static Repository Checkers Are Written in Go, Acceptance Rigs Stay Bash - narrow ADR 0020 to the rigs it measured; stop the checker class growing in shell
- 0026 — Agent-Room Encryption Is a Per-Room Decision - remove the blanket prohibition and stage Level 1 bridge crypto participation