Skip to content

v17: retire the overloaded managedBy: 'system' bucket — move the 8 admin/user-writable objects to a dedicated bucket #3355

Description

@os-zhuang

Deferred breaking cleanup from the ADR-0103 addendum (v16 enum split, merged in #3352 / objectui#2739). Not urgent — this is a v17 major-only change.

Background

ADR-0103 (v16) split the overloaded managedBy: 'system' bucket additively: the 20 engine-owned objects moved to the new explicit engine-owned value, while the 8 admin/user-writable objects kept managedBy: 'system' — which now means "engine-managed schema, writable via userActions". That leaves system as a residual, still-overloaded value: its name says "system" but it now specifically labels writable platform DATA.

The addendum recorded the end state as a v17 change:

Removing the overloaded system entirely — moving the 8 writable objects to a dedicated writable-platform-data bucket (or config) and retiring system — is a genuinely breaking rename deferred to v17.

Scope — the 8 objects still on managedBy: 'system'

All declare userActions: { create: true, edit: true, delete: true } (or a subset). Authz is the DelegatedAdminGate / RLS / permission sets — the userActions is an affordance declaration only.

Object Home Kind
sys_user_preference platform-objects/identity User-owned preferences
sys_approval_delegation plugin-approvals Admin-authored delegation
sys_user_position plugin-security RBAC link table (DelegatedAdminGate)
sys_position_permission_set plugin-security RBAC link table
sys_user_permission_set plugin-security RBAC link table
sys_notification_subscription service-messaging Messaging config grid
sys_notification_template service-messaging Messaging config grid
sys_notification_preference service-messaging Messaging config grid

The design decision (resolve first)

What bucket do these move to? Two candidates:

  1. A new platform-data value — "platform-defined schema holding admin/user-writable data; authz via delegated administration / RLS." Cleanest fit; keeps them distinct from admin-authored config and from user-owned platform. The affordance default would be writable (create/edit/delete: true, so most drop their userActions), or stay locked-by-default with userActions — TBD.
  2. config — reuse the existing admin-authored bucket. Simpler (no new value) but semantically loose: several of these are user-owned (sys_user_preference) or governed by delegated admin / RLS, not "admin authored," and config suppresses CSV import which some may want.

Recommend option 1 (a dedicated value) unless the affordance semantics of config prove an exact match.

Blast radius (mirrors the v16 split)

  • framework — spec enum + CRUD_AFFORDANCE_DEFAULTS (packages/spec/src/data/object.zod.ts); remove 'system' and its default row; guard sets (ENGINE_OWNED_BUCKETS, GUARDED_WRITE_BUCKETS) if the new bucket needs listing; the 8 object declarations; tests; ADR update; objects.mdx + regenerated references.
  • objectui — ManagedByBucket union + MANAGED_BY_BUCKETS (@object-ui/types); resolveCrudAffordances DEFAULTS (@object-ui/core); ManagedByBadge variant + resolveManagedByEmptyState (@object-ui/app-shell).

Why v17 (breaking)

  • Removes an enum value (system) — any downstream app or package declaring managedBy: 'system' becomes invalid (a type error against the closed union, and unknown at runtime → platform fallthrough).
  • Unlike the v16 addition, this is not additive: it changes the meaning of existing declarations.

Not in scope / already handled

  • Enforcement is unaffected either way — resolveCrudAffordances + the engine write guard drive the policy off resolved affordances, not the bucket literal (verified: no code branches on === 'system'). This is purely a taxonomy/self-documentation cleanup.
  • The v16 engine-owned split, dogfood verification, and the userActions de-dup are done (feat(spec): explicit engine-owned managedBy bucket (ADR-0103 addendum, #3343) #3352, objectui#2739, objectui#2724).

Related

#3343 (parent tracking issue) · #3352 · objectui#2739 · objectui#2724 · ADR-0103 (+ its v16 addendum)

Activity

  1. os-zhuang commented on Aug 2, 2026

    @os-zhuang
    ContributorAuthor

    裁决(维护者 2026-08-02 委托,按四轴评估:长远合理性 / 防 AI 静默犯错 / 实际业务 / 不扩边界):选项 1 —— 新增 platform-data 枚举值,退役 system。

    • 长远:config 语义不匹配——sys_user_preference 是用户自有数据而非 admin-authored,且 config 抑制 CSV 导入。留一个语义含混的桶,是给未来每个新对象的归类制造二义。
    • 防 AI 犯错:枚举值语义精确、affordance 默认清晰,作者(尤其 AI)才能选对;闭合 union 移除 'system' 让存量声明在编译期就红,不会静默 fall through 到 platform。
    • 边界:这不是新功能,是完成 v16 已出货的 split 的收尾;一个枚举值 + 一行默认,不扩大产品面。

    附带决策(正文标 TBD 的 affordance 默认):platform-data 默认可写(create/edit/delete: true),与桶名语义一致,8 个对象大多可删掉重复的 userActions;需要更窄的用 userActions 收窄。授权继续由 DelegatedAdminGate / RLS / permission sets 承担,不变。

    v17 内落地,blast radius 按正文 framework/objectui 清单执行。


    Generated by Claude Code

  2. os-zhuang commented on Aug 2, 2026

    @os-zhuang
    ContributorAuthor

    裁决修订(2026-08-02,维护者质询后,替代上一条评论的命名部分):新值定名 system-data,不用 platform-data。

    维护者点名了上一条裁决的一个真实缺陷:枚举里已经有 platform(用户业务数据、完整 CRUD、且是缺省值,object.zod.ts:849 / CRUD_AFFORDANCE_DEFAULTS),再添一个语义不相干的 platform-data 是在同一个闭合枚举里制造相邻混淆——恰恰违反「防 AI 作者犯错」这条权重最高的评估轴。且这 8 个对象全部在 sys_* 命名空间,桶名归入 "system" 词族与命名现实一致。

    system-data 语义定义

    • schema 归系统:平台/插件定义、随版本演进,租户不可改 —— 与 platform(租户业务建模)的分界;
    • 数据归 admin/用户:经治理路径写入,authz = DelegatedAdminGate / RLS / permission sets,不变 —— 与 engine-owned(数据也归引擎、零用户写)的分界;
    • 默认 affordance 可写(create/edit/delete/import/exportCsv: true),8 个对象大多可删掉重复的 userActions;需更窄用 userActions 收窄(RBAC 关联表等的实际写入权仍由授权层把守,affordance 只是 UI 呈现)。

    收官叙事:v16 把过载的 system 拆出 engine-owned(加法);v17 把剩余一半改名 system-data、退役裸 system(减法,major)。因 v16 已抽干引擎侧,存量 'system' → 'system-data' 是一对一机械替换——升级处方零判断成本,suggestKey 别名表加 system → system-data,报错即给出正确拼法。

    考虑并放弃的备选

    • platform-data(上条裁决)—— 与既有 platform 相邻混淆,否;
    • 复用 config —— 语义错位 + 抑制 CSV 导入(上条评论已述),否;
    • 保留 system 仅改文档(零破坏)—— 名不副实继续教坏作者,"system vs engine-owned" 的选择歧义留存,且 ADR-0103 附录已把退役记为 v17 目标,错过要等 v18,否。

    其余(blast radius 清单、跨仓拆分、v17 major 窗口)维持上一条裁决不变。


    Generated by Claude Code

  3. self-assigned this
    on Aug 2, 2026
  4. os-zhuang commented on Aug 2, 2026

    @os-zhuang
    ContributorAuthor

    🔒 CLAIM — pm-dispatch round 8(v17 协议优先批)
    branch: claude/issue-3355-retire-managedby-system
    worktree: objectstack-issue-3355

    维护者已指示 v17 发布在即、协议变更类优先。本条是 ADR-0103 附录白纸黑字记为 v17-only 的 breaking 改名(把 8 个可写平台对象移出语义被掏空的 managedBy: 'system'),错过这个 major 窗口就要再等一个大版本,故排在 v17 协议清单首位。


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions