Semogram Docs
Reference

Write policies

Mutation, identity, and safety fields with policy examples.

A write policy is the rulebook on a destination or ontology write: what changes are allowed, how identity works, what happens on conflict, and what can never be deleted silently. Reads are free; writes answer to a policy.

Mutations

MutationEffectRequires
AppendAdd rows, never touch existingNothing — the safe default
UpsertInsert new, update knownIdentity keys
UpdateChange matched rows onlyIdentity keys
ReplaceSwap whole target for a snapshotSnapshot state + omission-delete, approved together
DeleteRemove matched rowsIdentity keys + physical-deletion permission
{
  "mutation": "append",
  "identity": { "keys": ["forecast_id", "run_id"] },
  "duplicates": "reject",
  "conflicts": "reject",
  "invalidRows": "reject"
}

A second example — reviewed nightly dimension upsert:

{
  "mutation": "upsert",
  "identity": { "keys": ["account_id"] },
  "duplicates": "last_write_wins",
  "conflicts": "overwrite",
  "omission": "preserve",
  "invalidRows": "quarantine",
  "atomicity": "run"
}

Identity, duplicates, conflicts, omission

FieldOptionsRule of thumb
Identity keysField list, unique, non-empty; nulls rejectedBusiness keys, never generated ones
DuplicatesReject / preserve / last-write-winsReject where money moves
ConflictsReject / overwriteUpdates must explicitly allow overwrite
OmissionPreserve / delete missing rowsDelete only with snapshot + replace, one decision

A full read is never implicit permission to delete missing rows.

Safety fields

FieldOptionsMeaning
Schema evolutionReject / create-only / additive / rebuildAdditive is the usual truce
RetentionMinimum days + physical-delete flagDeletion paths need the flag set deliberately
Invalid rowsReject batch / quarantine rowsQuarantine at volume, reject where critical
AtomicityRow / object / file / runHow much commits together — never half-apply
Empty snapshotAlways rejectedAn empty read never wipes a target
ConcurrencyReject / destination-managedWho serializes simultaneous writes

Destructive combinations

Any of these raises the approval bar: replace, update, delete, or upsert mutations; omission-delete; relationship cascade; rebuild-level schema evolution; physical deletion; compaction. Append-only with none of these is comparatively safe.

Image: write policy summary on a destination node with the destructive flags highlighted for approval.

Next