Applications and Module Boundaries
Responsibilities of API, web, admin, worker, and future mobile clients.
Keep business logic in the API and use clients as consumers of versioned contracts.
Source boundary
Source boundary: AutoCore current main 7a504f6e430c16d4fcb03ebdea3cc3fb7816df60, checked against immutable v1.0.0-rc.1 at 9edfb109f44cc80385784c694b96392cfc04e70f.
The API owns domain behavior, web and admin consume the API, and the worker handles background processing. Native mobile remains a future client of shared contracts rather than a reason to leak web-only UI into the API.
| Check | Source-backed expectation |
|---|---|
| Scope | Boundary violations are architecture defects even when the local build passes. |
| Evidence | Use placeholders, timestamps, release identity, route, status, and request ID where relevant. |
| Safe action | pnpm typecheck |
| Stop condition | Unknown authorization, destructive impact, secret exposure, or conflicting evidence. |
Verification
Run the safe check, record its result, and compare the outcome with the documented contract. If the result depends on external configuration or provider availability, mark it as configuration-dependent rather than claiming a product guarantee.
pnpm typecheck
Safety boundary
Examples are non-production and use placeholders. Do not deploy, reset, force a migration, create secrets, activate providers, replay sensitive work, or expose private data from this page.