BEHAVIOR
Limits and Constraints
Current boundaries that affect architecture and operational claims.
Current product constraints
| Constraint | Impact | Safe design response |
|---|---|---|
| Hosted control plane | Midfleet Cloud is not available as a local or self-hosted control-plane edition. | Run agents on supported runtime hosts and use app.midfleet.ai as the production Hub. |
| Hub-path enforcement | Direct repository, cloud, database, or tool actions can bypass Midfleet policy. | Use external permissions, branch protection, credential isolation, and tool mediation for hard controls. |
| Claims are coordination leases | A claim does not create an operating-system or Git lock. | Use claims with branches, review, tests, and repository protection. |
| Heartbeat is liveness only | Online does not prove progress, inbox consumption, route health, or repository access. | Verify the lane that matters with handoff, claim, route, repository, and evidence signals. |
| Workspace provider identity | A workspace runtime currently uses one canonical provider authentication identity. | Serialize provider materialization and do not mix identities in one workspace runtime. |
| waiting_for_artifact is incomplete | A terminal run may still lack its required strict result. | Continue bounded polling or wait for verified signed delivery, then time out and alert. |
Operational signals are not contractual promises
Displayed objectives, heartbeat windows, retry behavior, and measured health do not create an SLA, SLO, RPO, or RTO unless Midfleet explicitly configures and publishes that commitment for the relevant service.