Canonical home for Moira's product architecture decisions. These were previously
authored under an ai-sdlc working copy whose git index still tracked an unrelated
project's ADRs; they now live with the code they govern (ADR-005/006 P5 hygiene fix).
| ADR | Decision | Status |
|---|---|---|
| 000 | ADR template | — |
| 001 | Desktop shell on Tauri | Accepted |
| 002 | Orchestration engine | Superseded for v0.2 runtime by ADR-006 (custom DAG engine; LangGraph deferred) |
| 003 | Model routing via LiteLLM | Accepted |
| 004 | Dev execution is delegated to agent backends | Accepted (amended by ADR-006) |
| 005 | Pluggable persistence (SQLite/Postgres + git sink) | Accepted (amended by ADR-006) |
| 006 | Durable runner execution model (one model, two hosting modes) | Accepted |
| 007 | Governance packs as enforceable controls (repo-only, deterministic-first) | Accepted (MVP) |
| 008 | API identity (JWT, local/oidc) + default-deny RBAC (5 roles) | Accepted (backend MVP) |
| 009 | System-generated rework feedback on gate reject (closed quality loop, part 1) | Accepted (implemented) |
| 010 | Bounded rework loop — max_loop caps system rejects, audit-derived counter (closed quality loop, part 2) |
Accepted (implemented) |
| 011 | Informed backend retry — previous errors in the retry prompt + linear backoff (closed quality loop, part 3) | Accepted (implemented) |
| 012 | Backend install/login probes + fail-fast launch gating (asymmetric-TTL cache, unknown never blocks) | Accepted (implemented) |
| 013 | "Retry" as the third decision on an escalated failed node; approve-the-gap becomes explicit | Accepted (implemented) |
| 014 | Closed test-fix loop — failing check output feeds the rework prompt (opt-in per gate, audit-derived) | Accepted (implemented) |
| 015 | Fail-loud model identity — litellm has no silent default model; validation at save/launch | Accepted (implemented) |
| 016 | Escalating, verified process termination — group SIGTERM→SIGKILL, reader unblock, visible verdict | Accepted (implemented) |
| 017 | Server-enforced cost budgets (run + workspace-month) — settings store, pause-not-kill, governed continue | Accepted (implemented) |
| 018 | Prompt & metering hygiene — [UNTRUSTED DATA] framing, fail-loud skills + references delivery, cache-aware tokens | Accepted (implemented) |
| 019 | Auth on by default, end-to-end — process default local, Tauri token handshake, CORS narrowing, one-command onboarding |
Proposed (TODO) |
| 020 | Run isolation via git worktrees — code_path only, fail-closed, branch as deliverable; unblocks multi-run and ×N variants |
Proposed (design settled) |
ADR-007-agentic-engineering-workflowwas left in theai-sdlcframework repo — it describes the engineering workflow, not the Moira product, so its ownership is intentionally triaged separately.