- 01
ingest live OpenAPI and discover server-owned action profiles, trigger schemas, and workspace policy
- 02
register an SSRF-safe HTTPS callback endpoint when signed outcome delivery is required and secure its one-time secret
- 03
create a DRAFT automation with one typed trigger, approved action profile, secret-free bindings, callback reference, and bounded execution policy
- 04
validate configuration and bindings without invoking the domain action
- 05
activate or resume only after current trigger, endpoint, workspace, action-profile, and domain-policy checks pass
- 06
for manual EXECUTE, obtain a fresh purpose-bound authorization from the owning domain and bind the request to one exact automation version
- 07
distinguish run admission, domain outcome, callback attempt, and receiver acknowledgement as separate states
- 08
rotate endpoint signing epochs, retry only eligible failed deliveries without re-running the business action, and retire endpoints or automations with retained evidence