Skip to main content

ADR 0009: Single Send Egress Boundary


Context​

The product promise is: nothing intimate leaves the machine except what the user explicitly sends. If Agent, UI, plugins, or AI tools each open network sockets, sovereignty collapses and audits become impossible.

Alternatives considered:

OptionProsCons
Single packages/send egressAuditable, enforceableAll channels must plug in here
Each feature calls fetchFast demosPrivacy defects; unknown success states
Agent owns apply tools“Autonomous” marketingViolates agent-as-belt; non-goal

Decision​

All career-data egress goes through packages/send.

  • Channels (board submit, mail, export) register as send adapters / extension send channels.
  • Flow: Queue (+ preferences approval) → send → honest Send.Succeeded|Failed|Unknown → Timeline Privacy.EgressRecorded.
  • agent, ai, renderer, and plugins must not call egress directly; they may only enqueue or request intents under policy.
  • Approval-before-send defaults on for high-stakes outbound.

Consequences​

Positive​

  • Clear code review hotspot for privacy.
  • Honest completion semantics centralized.
  • Matches brand review ritual and microcopy.

Negative / tradeoffs​

  • New outbound destinations require send-channel work — intentional friction.
  • Misplaced fetch in other packages is a defect; needs lint/tests.

Follow-ups​

  • Contract tests: approval gate + unknown≠success (ADR 0007).
  • Extension send façade must wrap this package (ADR 0012).