▸ Agent Skills
3 min read

Division of Responsibility

Which guarantees belong to Casita, object formats, physical backends, higher-level tools, and deployments.

Casita is a repository backbone, not the complete product above it. Its generic contract is strongest when each layer owns only the guarantees it can actually enforce.

Responsibility map

ConcernCasita ownsAnother layer owns
Logical identityA namespace-qualified ObjectKey, canonical ObjectRecord, and immutable key-to-record bindingThe format defines its native identifier and canonical payload
RelationshipsStored, verifier-produced forward links used by traversal and retentionThe format decides which payload references are true retaining links
PublicationPayload durability, namespace verification, bounded staging, and atomic logical commitThe calling workflow decides what should be published and under which destination-owned names
RetentionNamed roots, complete closure checks, and reachability-based collectionThe application decides why a graph matters and when to repoint or remove its root
TransferOne stable source revision, additive batches, receiver verification, and final root publicationDiscovery, scheduling, authorization, topology, and destination policy
Physical storageComplete plaintext BlobId contract and safe collection orderingA BlobStore chooses chunking, compression, tiers, request behavior, and durability guarantees
Logical stateAtomic revisioned records and roots through MetadataStoreA deployment decides whether a backend and its backup procedures meet operational requirements
GitNative immutable objects, ref views, checkout, and read-only fetchAuthoring, branches as mutable collaboration state, review, merge, push, and hosting administration
IPLDRegistered codec verification, CID identity, and exact linksSelectors, content routing, discovery, and network policy
SecurityBounds, receiver verification, safe filesystem containment, typed failure categories, and consumption of already-resolved process credentialsSecretSpec resolves deployment secrets; the deployment owns authentication, multi-tenancy, access control, confidentiality, key management, and audit policy

For a shared physical payload service, Casita’s logical collection removes only the records in one repository. The deployment owns the aggregate cross-tenant payload ledger, write leases, physical reclamation, and every authorization check. See Shared Payload Services.

Trust boundaries

  • Remote senders are untrusted discovery sources. A destination reruns its own namespace verifier and publishes a requested root only after its complete closure succeeds.
  • The logical state backend is trusted infrastructure. Casita detects many inconsistencies with fsck, but applications should not mutate database rows outside the MetadataStore contract.
  • OpenSSH owns SSH-channel security. Casita does not weaken host-key verification or replace credential and proxy configuration.
  • Stored content is not automatically confidential. The standard local profile does not promise encryption at rest or access-pattern hiding.
  • SecretSpec is outside the repository boundary. The optional S3 profile consumes standard AWS environment variables that secretspec run may populate. Casita does not invoke provider vaults or persist resolved values, and does not provide client-side encryption for that profile.
  • A valid claim is not accepted policy. Evidence formats preserve exact inputs and outputs; the application decides which issuer, time window, or decision is trusted.

Why the boundary matters

Moving product policy into the generic repository would make object meaning depend on deployment state and would force unrelated formats through one semantic model. Moving repository correctness into each application would duplicate publication, transfer, collection, and recovery logic. The split keeps immutable meaning format-owned and reusable lifecycle machinery generic.

Continue with Repository for the concrete composition or Verification for the checks performed at each boundary.


Last updated Oct 08, 2026