Project Graph
Track persistent identity, dependencies, derivations and drift without turning identity into permission.
Project Graph records how project assets relate: which input produced an output, which revision was observed and which dependent results may have become stale. Stored identity is not permission to read or mutate the underlying application.
Separate durable identity from a live reference
Section titled “Separate durable identity from a live reference”A logical asset can outlive a broker session. A live application handle or reference is session- and generation-bound. A matching filename or object name does not prove native identity.
Scoped queries preserve visibility boundaries. Missing or hidden dependencies remain an unknown frontier; they are not counted as globally complete evidence.
Observe through the normal broker
Section titled “Observe through the normal broker”The documented project.* routes enter schema validation, policy, audit, cancellation and output validation. Reading requires the named filesystem grant. Managing private graph state also needs explicit project.manage authority; a file-read grant cannot create or rebind project state.
Trusted revision adapters admit observations for a specific resource and evidence source. Client-supplied JSON cannot create a trusted receipt or choose durable ownership.
Keep rebuilding explicit
Section titled “Keep rebuilding explicit”Graph can help prepare a bounded rebuild and identify affected work. It is not a scheduler or permission to replay arbitrary commands. The integration documentation explicitly does not expose a project.rebuild.execute route.
An interrupted external mutation may have an unknown outcome. Reconcile it using fresh application evidence rather than silently retrying the operation.
Source: Project Graph integration and evidence boundaries, source references checked 7 October 2026. Historical checkpoints in that document retain their original source revisions.