{
  "schemaVersion": 1,
  "generatedAt": "2026-08-12T23:40:47.485Z",
  "generationKey": "1f0aa93ec63f8fb8ee94c75406e491398650bad9e7ce9e78d21a92498d766597",
  "metadataPayloadSha256": "ce8abc80f0d993ff7107ebbd5c85e2e797dfe3451c043155238b4a511009e050",
  "diagram": {
    "id": "plugin-host-security-boundary-2e4efe1b",
    "title": "Plugin host security boundary",
    "description": "A plugin declares statically and binds implementations in setup(). The host owns resolution, per-workspace authority, the permission intersection, containment and audit. Every data path the plugin can reach runs through the same withWorkspace() boundary the UI and REST surfaces use, so RLS applies identically — a plugin is not a way around tenancy.",
    "status": "current",
    "canonicalAppearanceKey": "tsx:src/app/(docs)/docs/concepts/plugins/page.tsx:hostChart#1"
  },
  "aliases": [],
  "concepts": [
    "the host runtime — src/server/plugins/",
    "Plugins",
    "Host",
    "a plugin — one in-process TypeScript module"
  ],
  "keywords": [
    "Postgres · FORCE RLS",
    "ctx.data facade",
    "plugin.* rows in audit_log",
    "transaction-local app.workspace_id",
    "every tenant table",
    "event bus",
    "id · semver · apiVersion",
    "permissions · subscribes · contributes",
    "binds implementations to declared names",
    "resolve → validate → register → freeze",
    "per-workspace enable · grant · config",
    "declared ∩ granted ∩ principal",
    "timeout · breaker · concurrency",
    "withWorkspace(workspaceId, tx =>)",
    "outbox → deliveries → worker drain",
    "Intake · Atlas · Warrant · Lineage",
    "Conduit · Lens · Crucible · Ports",
    "typed calls only — no pool, no Tx, no SQL",
    "manifest",
    "setup(reg)",
    "registry",
    "installations",
    "permissions",
    "contain",
    "audit"
  ],
  "mermaid": {
    "type": "flowchart",
    "direction": "TB",
    "sourceSha256": "2e4efe1be81b5ec26c132244200edd15b8bbc02f1faf4f1d3535bb998bb444be"
  },
  "provenance": [
    {
      "appearanceKey": "tsx:src/app/(docs)/docs/concepts/plugins/page.tsx:hostChart#1",
      "surface": "route",
      "sourcePath": "src/app/(docs)/docs/concepts/plugins/page.tsx",
      "line": 34,
      "route": "/docs/concepts/plugins",
      "symbol": "hostChart",
      "caption": "A plugin declares statically and binds implementations in setup(). The host owns resolution, per-workspace authority, the permission intersection, containment and audit. Every data path the plugin can reach runs through the same withWorkspace() boundary the UI and REST surfaces use, so RLS applies identically — a plugin is not a way around tenancy."
    }
  ],
  "embeddedMetadata": [
    {
      "sourcePath": "src/app/(docs)/docs/concepts/plugins/page.tsx",
      "caption": "A plugin declares statically and binds implementations in setup(). The host owns resolution, per-workspace authority, the permission intersection, containment and audit. Every data path the plugin can reach runs through the same withWorkspace() boundary the UI and REST surfaces use, so RLS applies identically — a plugin is not a way around tenancy."
    }
  ],
  "generation": {
    "application": {
      "name": "eli-ai",
      "version": "0.1.0"
    },
    "environment": {
      "node": "v26.3.1",
      "yarn": "4.17.1",
      "platform": "linux",
      "architecture": "x64",
      "containerImage": "playwright:v1.62.1-noble@sha256:c091b21d9fae78c76e85cd4356431e9b018402f172a214fc7d7a5e9a7e29d8ac+node:26.3.1-bookworm-slim@sha256:209558c3e5e40e8adff68959d3c2ba7cd73723e716d89196878a0c362fa1e109"
    },
    "packages": {
      "mermaid": "11.16.0",
      "mermaidCli": "11.16.0",
      "playwright": "1.62.1",
      "playwrightCore": "1.62.1",
      "puppeteer": "25.6.0",
      "puppeteerCore": "25.6.0"
    },
    "renderer": {
      "mermaidConfigSha256": "68c10966fe84406ee626034d58bfabd555df9f65f691204b7c46db24038da101",
      "themeCssSha256": "c80287a78d80ad63d27bd5ca348b2ef9a7e2f44da289e436be6484ea28a1b033",
      "browser": {
        "name": "chromium",
        "revision": "1234",
        "version": "151.0.7922.34",
        "executableSha256": "0b20b130e7edd9dd51873be867761295fe0cfad490c2b9a64f95bd3cfc08fa71"
      },
      "font": {
        "family": "Eli Diagram Inter Variable",
        "fileSha256": "3100e775e8616cd2611beecfa23a4263d7037586789b43f035236a2e6fbd4c62",
        "licenseSha256": "3b0a5fca3d17942cde889069889dedbbbd075e9b599968c82a95f4d944e9b345"
      }
    },
    "adapterVersions": {
      "diagramGenerator": "2",
      "drawioFlowchart": "1",
      "drawioSequence": "1",
      "drawioState": "1",
      "drawioGantt": "1"
    }
  },
  "artifacts": {
    "mmd": "/diagrams/plugin-host-security-boundary-2e4efe1b/plugin-host-security-boundary-2e4efe1b.mmd",
    "svg": "/diagrams/plugin-host-security-boundary-2e4efe1b/plugin-host-security-boundary-2e4efe1b.svg",
    "png": "/diagrams/plugin-host-security-boundary-2e4efe1b/plugin-host-security-boundary-2e4efe1b.png",
    "drawio": "/diagrams/plugin-host-security-boundary-2e4efe1b/plugin-host-security-boundary-2e4efe1b.drawio",
    "json": "/diagrams/plugin-host-security-boundary-2e4efe1b/plugin-host-security-boundary-2e4efe1b.json"
  },
  "artifactSha256": {
    "mmd": "107dd762090334dc6d5577c70e367ec9f8856884054181b19272ca448e4e8251",
    "svg": "44fa5c57db866a263391143b7d868535e925fd954349de214ca984149c17f7dc",
    "png": "b68929d6f5bb2a74fb4b009ead036c678998ec5926286aaf41c3d2156447c231",
    "drawio": "9bcddff1d4b2d77f50fe614e92a2fc751e47bf25ed75760f663a9c56b0eafa79"
  }
}
