Skip to main content
Lucia converts external signals into structured decisions. Architecture doctrine is durable; deployment identity, routing, model posture, and readiness claims are current only inside the evidence boundary and date stated here.

Durable system flow

External signalOwned intakeNormalizationEngine intelligenceWorkspace contextOperator reviewExplicit executionSaved truth
Calendar remains Lucia’s temporal spine. Arrivals, departures, stay windows, and booking identity ground operational context. Core doctrine:

Current surface boundaries

Guest-facing operational signals remain privacy-safe and structured:
guest conversationidentity orientation / claim collectionsigned operational_signal v0Engine guest-signal normalizationAdmin Signal Stream review / linkageFocus Ops context when safe
Guest verification proves booking linkage. It does not grant unrestricted mutation access. Verification email delivery must target the booking email already on file, never an untrusted guest-entered destination.

Environment posture

Development is the active Admin and Engine integration environment. The verified Engine Development source and live identity are:
Staging exists for both Admin and Engine, but it is an older, manually promoted environment. A reachable Staging service does not prove that current Development source has been promoted, and Canon must not describe Staging as automatically current. See Domains and Live Routing and Render for the dated service-level receipts.

Model ownership

Matching configured names do not create shared ownership or inherited proof. Each direct-model service owns its configuration, deployment, request path, and provider evidence. A configured default is not the same claim as a provider-returned model identifier.

Eval and provenance flow

Eval Labs productionEngine Development evaluation routestable response contractruntime and model provenance when capturedEval Labs evidence record
Engine responses keep operational output separate from provenance metadata. Eval Labs may persist captured evidence for a run, but it must label historical runs without captured provenance instead of manufacturing a current runtime claim.

Payment truth boundary

property policy truthcalendar / booking timingStripe movement truthEngine durable ledgerLIEA financial judgmentAdmin read-only rendering
This separation is doctrine. Each implementation or readiness claim still requires its own current source, datastore, and runtime evidence. Admin presentation never becomes the owner of payment truth by rendering it.

Build identity rule

Admin and Engine expose separate build identities. Admin identity is injected at Admin build time; Engine identity is served by the Engine root endpoint. Those identifiers can prove the deployed pair only when read from the relevant services. Package versions, configured model names, and documentation dates are not substitutes for commit and deployment identity. See Current System State for the cross-repository evidence ledger.